{
  "append_only": true,
  "archive_version": "v0.1",
  "archived_cve_count": 2357,
  "cves": [
    {
      "affected_label": "ftp / ftp",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-1999-0082/",
      "current_public_safe_latest": false,
      "cvss_score": 10.0,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.94039,
      "epss_score": 0.08027,
      "first_observed_at": "2026-06-20T08:39:58.440157+00:00",
      "id": "CVE-1999-0082",
      "impact_tags": [
        "admin privilege risk"
      ],
      "kev": false,
      "last_observed_at": "2026-06-20T08:39:58.440157+00:00",
      "latest_item_url": null,
      "product": "ftp",
      "public_safe_summary": "NVD: CWD ~root command in ftpd allows root access.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260703T085042Z/items/CVE-1999-0082.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "noindex_removal_allowed": false,
        "noindex_required": true,
        "patch_allowed": false,
        "public_launch_allowed": false,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: ftp / ftp",
      "source_published_impact": "Source describes admin privilege risk. Possible impact: An attacker may gain root or administrative-level privileges on affected systems.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: CWD ~root command in ftpd allows root access.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-1999-0082/timeline.json",
      "vendor": "ftp"
    },
    {
      "affected_label": "sun / nfs",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-1999-0084/",
      "current_public_safe_latest": false,
      "cvss_score": 8.4,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.33011,
      "epss_score": 0.00415,
      "first_observed_at": "2026-06-20T08:39:58.440157+00:00",
      "id": "CVE-1999-0084",
      "impact_tags": [
        "admin privilege risk",
        "privilege boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-06-20T08:39:58.440157+00:00",
      "latest_item_url": null,
      "product": "nfs",
      "public_safe_summary": "NVD: Certain NFS servers allow users to use mknod to gain privileges by creating a writable kmem device and setting the UID to 0.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260703T085042Z/items/CVE-1999-0084.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "noindex_removal_allowed": false,
        "noindex_required": true,
        "patch_allowed": false,
        "public_launch_allowed": false,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: sun / nfs",
      "source_published_impact": "Source describes admin privilege risk · privilege escalation risk. Possible impact: An attacker may gain root or administrative-level privileges on affected systems.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Certain NFS servers allow users to use mknod to gain privileges by creating a writable kmem device and setting the UID to 0.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-1999-0084/timeline.json",
      "vendor": "sun"
    },
    {
      "affected_label": "eric_allman / sendmail",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-1999-0095/",
      "current_public_safe_latest": false,
      "cvss_score": 10.0,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.96581,
      "epss_score": 0.16446,
      "first_observed_at": "2026-06-20T08:39:58.440157+00:00",
      "id": "CVE-1999-0095",
      "impact_tags": [
        "command execution review",
        "admin privilege risk"
      ],
      "kev": false,
      "last_observed_at": "2026-06-20T08:39:58.440157+00:00",
      "latest_item_url": null,
      "product": "sendmail",
      "public_safe_summary": "NVD: The debug command in Sendmail is enabled, allowing attackers to execute commands as root.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260703T085042Z/items/CVE-1999-0095.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "noindex_removal_allowed": false,
        "noindex_required": true,
        "patch_allowed": false,
        "public_launch_allowed": false,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: eric_allman / sendmail; affected version context: 5.58",
      "source_published_impact": "Source describes command execution risk · admin privilege risk. Possible impact: An attacker may gain root or administrative-level privileges on affected systems.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The debug command in Sendmail is enabled, allowing attackers to execute commands as root.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-1999-0095/timeline.json",
      "vendor": "eric_allman"
    },
    {
      "affected_label": "sun / sunos",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-1999-0209/",
      "current_public_safe_latest": false,
      "cvss_score": 5.0,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.98702,
      "epss_score": 0.47779,
      "first_observed_at": "2026-06-20T08:39:58.440157+00:00",
      "id": "CVE-1999-0209",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-06-20T08:39:58.440157+00:00",
      "latest_item_url": null,
      "product": "sunos",
      "public_safe_summary": "NVD: The SunView (SunTools) selection_svc facility allows remote users to read files.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260703T085042Z/items/CVE-1999-0209.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "noindex_removal_allowed": false,
        "noindex_required": true,
        "patch_allowed": false,
        "public_launch_allowed": false,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: sun / sunos; affected version context: 3.5, 4.0, 4.0.1, 4.0.2, 4.0.3",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The SunView (SunTools) selection_svc facility allows remote users to read files.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-1999-0209/timeline.json",
      "vendor": "sun"
    },
    {
      "affected_label": "digital / vms",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-1999-1057/",
      "current_public_safe_latest": false,
      "cvss_score": 4.6,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.28465,
      "epss_score": 0.00368,
      "first_observed_at": "2026-06-20T08:39:58.440157+00:00",
      "id": "CVE-1999-1057",
      "impact_tags": [
        "privilege boundary review",
        "local exposure relevant"
      ],
      "kev": false,
      "last_observed_at": "2026-06-20T08:39:58.440157+00:00",
      "latest_item_url": null,
      "product": "vms",
      "public_safe_summary": "NVD: VMS 4.0 through 5.3 allows local users to gain privileges via the ANALYZE/PROCESS_DUMP dcl command.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260703T085042Z/items/CVE-1999-1057.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "noindex_removal_allowed": false,
        "noindex_required": true,
        "patch_allowed": false,
        "public_launch_allowed": false,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: digital / vms",
      "source_published_impact": "Source describes privilege escalation risk · local exposure. Possible impact: A local user may cross a privilege boundary and gain more access than intended.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: VMS 4.0 through 5.3 allows local users to gain privileges via the ANALYZE/PROCESS_DUMP dcl command.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-1999-1057/timeline.json",
      "vendor": "digital"
    },
    {
      "affected_label": "hp / apollo_domain_os",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-1999-1115/",
      "current_public_safe_latest": false,
      "cvss_score": 7.2,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.42195,
      "epss_score": 0.00561,
      "first_observed_at": "2026-06-20T08:39:58.440157+00:00",
      "id": "CVE-1999-1115",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-06-20T08:39:58.440157+00:00",
      "latest_item_url": null,
      "product": "apollo_domain_os",
      "public_safe_summary": "NVD: Vulnerability in the /etc/suid_exec program in HP Apollo Domain/OS sr10.2 and sr10.3 beta, related to the Korn Shell (ksh).",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260703T085042Z/items/CVE-1999-1115.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "noindex_removal_allowed": false,
        "noindex_required": true,
        "patch_allowed": false,
        "public_launch_allowed": false,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: hp / apollo_domain_os; affected version context: sr10.2",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Vulnerability in the /etc/suid_exec program in HP Apollo Domain/OS sr10.2 and sr10.3 beta, related to the Korn Shell (ksh).",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-1999-1115/timeline.json",
      "vendor": "hp"
    },
    {
      "affected_label": "sun / sunos",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-1999-1122/",
      "current_public_safe_latest": false,
      "cvss_score": 4.6,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.28465,
      "epss_score": 0.00368,
      "first_observed_at": "2026-06-20T08:39:58.440157+00:00",
      "id": "CVE-1999-1122",
      "impact_tags": [
        "privilege boundary review",
        "local exposure relevant"
      ],
      "kev": false,
      "last_observed_at": "2026-06-20T08:39:58.440157+00:00",
      "latest_item_url": null,
      "product": "sunos",
      "public_safe_summary": "NVD: Vulnerability in restore in SunOS 4.0.3 and earlier allows local users to gain privileges.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260703T085042Z/items/CVE-1999-1122.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "noindex_removal_allowed": false,
        "noindex_required": true,
        "patch_allowed": false,
        "public_launch_allowed": false,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: sun / sunos; affected version context: 4.0, 4.0.1",
      "source_published_impact": "Source describes privilege escalation risk · local exposure. Possible impact: A local user may cross a privilege boundary and gain more access than intended.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Vulnerability in restore in SunOS 4.0.3 and earlier allows local users to gain privileges.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-1999-1122/timeline.json",
      "vendor": "sun"
    },
    {
      "affected_label": "sun / sunos",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-1999-1197/",
      "current_public_safe_latest": false,
      "cvss_score": 7.2,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.30594,
      "epss_score": 0.00389,
      "first_observed_at": "2026-06-20T08:39:58.440157+00:00",
      "id": "CVE-1999-1197",
      "impact_tags": [
        "privilege boundary review",
        "local exposure relevant"
      ],
      "kev": false,
      "last_observed_at": "2026-06-20T08:39:58.440157+00:00",
      "latest_item_url": null,
      "product": "sunos",
      "public_safe_summary": "NVD: TIOCCONS in SunOS 4.1.1 does not properly check the permissions of a user who tries to redirect console output and input, which could allow a local user to gain privileges.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260703T085042Z/items/CVE-1999-1197.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "noindex_removal_allowed": false,
        "noindex_required": true,
        "patch_allowed": false,
        "public_launch_allowed": false,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: sun / sunos; affected version context: 4.1.1",
      "source_published_impact": "Source describes privilege escalation risk · local exposure. Possible impact: A local user may cross a privilege boundary and gain more access than intended.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: TIOCCONS in SunOS 4.1.1 does not properly check the permissions of a user who tries to redirect console output and input, which could allow a local user to gain privileges.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-1999-1197/timeline.json",
      "vendor": "sun"
    },
    {
      "affected_label": "next / next",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-1999-1198/",
      "current_public_safe_latest": false,
      "cvss_score": 7.2,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.32942,
      "epss_score": 0.00414,
      "first_observed_at": "2026-06-20T08:39:58.440157+00:00",
      "id": "CVE-1999-1198",
      "impact_tags": [
        "admin privilege risk",
        "privilege boundary review",
        "local exposure relevant"
      ],
      "kev": false,
      "last_observed_at": "2026-06-20T08:39:58.440157+00:00",
      "latest_item_url": null,
      "product": "next",
      "public_safe_summary": "NVD: BuildDisk program on NeXT systems before 2.0 does not prompt users for the root password, which allows local users to gain root privileges.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260703T085042Z/items/CVE-1999-1198.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "noindex_removal_allowed": false,
        "noindex_required": true,
        "patch_allowed": false,
        "public_launch_allowed": false,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: next / next",
      "source_published_impact": "Source describes admin privilege risk · privilege escalation risk · local exposure. Possible impact: A local user may gain root or administrative-level privileges on affected systems.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: BuildDisk program on NeXT systems before 2.0 does not prompt users for the root password, which allows local users to gain root privileges.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-1999-1198/timeline.json",
      "vendor": "next"
    },
    {
      "affected_label": "sun / sunos",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-1999-1211/",
      "current_public_safe_latest": false,
      "cvss_score": 7.2,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.26539,
      "epss_score": 0.00348,
      "first_observed_at": "2026-06-20T08:39:58.440157+00:00",
      "id": "CVE-1999-1211",
      "impact_tags": [
        "admin privilege risk",
        "privilege boundary review",
        "local exposure relevant"
      ],
      "kev": false,
      "last_observed_at": "2026-06-20T08:39:58.440157+00:00",
      "latest_item_url": null,
      "product": "sunos",
      "public_safe_summary": "NVD: Vulnerability in in.telnetd in SunOS 4.1.1 and earlier allows local users to gain root privileges.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260703T085042Z/items/CVE-1999-1211.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "noindex_removal_allowed": false,
        "noindex_required": true,
        "patch_allowed": false,
        "public_launch_allowed": false,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: sun / sunos",
      "source_published_impact": "Source describes admin privilege risk · privilege escalation risk · local exposure. Possible impact: A local user may gain root or administrative-level privileges on affected systems.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Vulnerability in in.telnetd in SunOS 4.1.1 and earlier allows local users to gain root privileges.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-1999-1211/timeline.json",
      "vendor": "sun"
    },
    {
      "affected_label": "sun / sunos",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-1999-1212/",
      "current_public_safe_latest": false,
      "cvss_score": 7.2,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.26539,
      "epss_score": 0.00348,
      "first_observed_at": "2026-06-20T08:39:58.440157+00:00",
      "id": "CVE-1999-1212",
      "impact_tags": [
        "admin privilege risk",
        "privilege boundary review",
        "local exposure relevant"
      ],
      "kev": false,
      "last_observed_at": "2026-06-20T08:39:58.440157+00:00",
      "latest_item_url": null,
      "product": "sunos",
      "public_safe_summary": "NVD: Vulnerability in in.rlogind in SunOS 4.0.3 and 4.0.3c allows local users to gain root privileges.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260703T085042Z/items/CVE-1999-1212.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "noindex_removal_allowed": false,
        "noindex_required": true,
        "patch_allowed": false,
        "public_launch_allowed": false,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: sun / sunos; affected version context: 4.0.3, 4.0.3c",
      "source_published_impact": "Source describes admin privilege risk · privilege escalation risk · local exposure. Possible impact: A local user may gain root or administrative-level privileges on affected systems.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Vulnerability in in.rlogind in SunOS 4.0.3 and 4.0.3c allows local users to gain root privileges.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-1999-1212/timeline.json",
      "vendor": "sun"
    },
    {
      "affected_label": "sun / sunos",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-1999-1258/",
      "current_public_safe_latest": false,
      "cvss_score": 5.0,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.68001,
      "epss_score": 0.01355,
      "first_observed_at": "2026-06-20T08:39:58.440157+00:00",
      "id": "CVE-1999-1258",
      "impact_tags": [
        "remote exposure relevant"
      ],
      "kev": false,
      "last_observed_at": "2026-06-20T08:39:58.440157+00:00",
      "latest_item_url": null,
      "product": "sunos",
      "public_safe_summary": "NVD: rpc.pwdauthd in SunOS 4.1.1 and earlier does not properly prevent remote access to the daemon, which allows remote attackers to obtain sensitive system information.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260703T085042Z/items/CVE-1999-1258.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "noindex_removal_allowed": false,
        "noindex_required": true,
        "patch_allowed": false,
        "public_launch_allowed": false,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: sun / sunos; affected version context: 4.1",
      "source_published_impact": "Source describes remote exposure. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: rpc.pwdauthd in SunOS 4.1.1 and earlier does not properly prevent remote access to the daemon, which allows remote attackers to obtain sensitive system information.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-1999-1258/timeline.json",
      "vendor": "sun"
    },
    {
      "affected_label": "next / next",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-1999-1391/",
      "current_public_safe_latest": false,
      "cvss_score": 7.2,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.32622,
      "epss_score": 0.00411,
      "first_observed_at": "2026-06-20T08:39:58.440157+00:00",
      "id": "CVE-1999-1391",
      "impact_tags": [
        "privilege boundary review",
        "local exposure relevant"
      ],
      "kev": false,
      "last_observed_at": "2026-06-20T08:39:58.440157+00:00",
      "latest_item_url": null,
      "product": "next",
      "public_safe_summary": "NVD: Vulnerability in NeXT 1.0a and 1.0 with publicly accessible printers allows local users to gain privileges via a combination of the npd program and weak directory permissions.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260703T085042Z/items/CVE-1999-1391.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "noindex_removal_allowed": false,
        "noindex_required": true,
        "patch_allowed": false,
        "public_launch_allowed": false,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: next / next; affected version context: 1.0, 1.0a",
      "source_published_impact": "Source describes privilege escalation risk · local exposure. Possible impact: A local user may cross a privilege boundary and gain more access than intended.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Vulnerability in NeXT 1.0a and 1.0 with publicly accessible printers allows local users to gain privileges via a combination of the npd program and weak directory permissions.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-1999-1391/timeline.json",
      "vendor": "next"
    },
    {
      "affected_label": "next / nex",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-1999-1392/",
      "current_public_safe_latest": false,
      "cvss_score": 7.2,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.33878,
      "epss_score": 0.00425,
      "first_observed_at": "2026-06-20T08:39:58.440157+00:00",
      "id": "CVE-1999-1392",
      "impact_tags": [
        "admin privilege risk",
        "privilege boundary review",
        "local exposure relevant"
      ],
      "kev": false,
      "last_observed_at": "2026-06-20T08:39:58.440157+00:00",
      "latest_item_url": null,
      "product": "nex",
      "public_safe_summary": "NVD: Vulnerability in restore0.9 installation script in NeXT 1.0a and 1.0 allows local users to gain root privileges.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260703T085042Z/items/CVE-1999-1392.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "noindex_removal_allowed": false,
        "noindex_required": true,
        "patch_allowed": false,
        "public_launch_allowed": false,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: next / nex; affected version context: 1.0, 1.0a",
      "source_published_impact": "Source describes admin privilege risk · privilege escalation risk · local exposure. Possible impact: A local user may gain root or administrative-level privileges on affected systems.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Vulnerability in restore0.9 installation script in NeXT 1.0a and 1.0 allows local users to gain root privileges.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-1999-1392/timeline.json",
      "vendor": "next"
    },
    {
      "affected_label": "sun / sunos",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-1999-1438/",
      "current_public_safe_latest": false,
      "cvss_score": 7.2,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.32239,
      "epss_score": 0.00406,
      "first_observed_at": "2026-06-20T08:39:58.440157+00:00",
      "id": "CVE-1999-1438",
      "impact_tags": [
        "admin privilege risk",
        "privilege boundary review",
        "local exposure relevant"
      ],
      "kev": false,
      "last_observed_at": "2026-06-20T08:39:58.440157+00:00",
      "latest_item_url": null,
      "product": "sunos",
      "public_safe_summary": "NVD: Vulnerability in /bin/mail in SunOS 4.1.1 and earlier allows local users to gain root privileges via certain command line arguments.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260703T085042Z/items/CVE-1999-1438.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "noindex_removal_allowed": false,
        "noindex_required": true,
        "patch_allowed": false,
        "public_launch_allowed": false,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: sun / sunos; affected version context: 4.0.3, 4.1",
      "source_published_impact": "Source describes admin privilege risk · privilege escalation risk · local exposure. Possible impact: A local user may gain root or administrative-level privileges on affected systems.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Vulnerability in /bin/mail in SunOS 4.1.1 and earlier allows local users to gain root privileges via certain command line arguments.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-1999-1438/timeline.json",
      "vendor": "sun"
    },
    {
      "affected_label": "sun / sunos",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-1999-1467/",
      "current_public_safe_latest": false,
      "cvss_score": 10.0,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.95082,
      "epss_score": 0.10226,
      "first_observed_at": "2026-06-20T08:39:58.440157+00:00",
      "id": "CVE-1999-1467",
      "impact_tags": [
        "admin privilege risk",
        "remote exposure relevant"
      ],
      "kev": false,
      "last_observed_at": "2026-06-20T08:39:58.440157+00:00",
      "latest_item_url": null,
      "product": "sunos",
      "public_safe_summary": "NVD: Vulnerability in rcp on SunOS 4.0.x allows remote attackers from trusted hosts to execute arbitrary commands as root, possibly related to the configuration of the nobody user.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260703T085042Z/items/CVE-1999-1467.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "noindex_removal_allowed": false,
        "noindex_required": true,
        "patch_allowed": false,
        "public_launch_allowed": false,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: sun / sunos; affected version context: 4.0, 4.0.1, 4.0.2, 4.0.3, 4.0.3c",
      "source_published_impact": "Source describes admin privilege risk · remote exposure. Possible impact: A remote attacker may gain root or administrative-level privileges on affected systems.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Vulnerability in rcp on SunOS 4.0.x allows remote attackers from trusted hosts to execute arbitrary commands as root, possibly related to the configuration of the nobody user.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-1999-1467/timeline.json",
      "vendor": "sun"
    },
    {
      "affected_label": "bsd / bsd",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-1999-1471/",
      "current_public_safe_latest": false,
      "cvss_score": 7.2,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.39225,
      "epss_score": 0.00507,
      "first_observed_at": "2026-06-20T08:39:58.440157+00:00",
      "id": "CVE-1999-1471",
      "impact_tags": [
        "admin privilege risk",
        "privilege boundary review",
        "memory safety review",
        "local exposure relevant"
      ],
      "kev": false,
      "last_observed_at": "2026-06-20T08:39:58.440157+00:00",
      "latest_item_url": null,
      "product": "bsd",
      "public_safe_summary": "NVD: Buffer overflow in passwd in BSD based operating systems 4.3 and earlier allows local users to gain root privileges by specifying a long shell or GECOS field.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260703T085042Z/items/CVE-1999-1471.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "noindex_removal_allowed": false,
        "noindex_required": true,
        "patch_allowed": false,
        "public_launch_allowed": false,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: bsd / bsd; affected version context: 4.2, 4.3",
      "source_published_impact": "Source describes admin privilege risk · privilege escalation risk · memory safety review. Possible impact: A local user may gain root or administrative-level privileges on affected systems.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Buffer overflow in passwd in BSD based operating systems 4.3 and earlier allows local users to gain root privileges by specifying a long shell or GECOS field.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-1999-1471/timeline.json",
      "vendor": "bsd"
    },
    {
      "affected_label": "sun / sunos",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-1999-1506/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.83359,
      "epss_score": 0.02604,
      "first_observed_at": "2026-06-20T08:39:58.440157+00:00",
      "id": "CVE-1999-1506",
      "impact_tags": [
        "unauthorized access risk",
        "remote exposure relevant"
      ],
      "kev": false,
      "last_observed_at": "2026-06-20T08:39:58.440157+00:00",
      "latest_item_url": null,
      "product": "sunos",
      "public_safe_summary": "NVD: Vulnerability in SMI Sendmail 4.0 and earlier, on SunOS up to 4.0.3, allows remote attackers to access user bin.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260703T085042Z/items/CVE-1999-1506.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "noindex_removal_allowed": false,
        "noindex_required": true,
        "patch_allowed": false,
        "public_launch_allowed": false,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: sun / sunos; affected version context: 3.5, 4.0, 4.0.1, 4.0.2, 4.0.3",
      "source_published_impact": "Source describes unauthorized access risk · remote exposure. Possible impact: A remote attacker may access resources that should require stronger authorization.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Vulnerability in SMI Sendmail 4.0 and earlier, on SunOS up to 4.0.3, allows remote attackers to access user bin.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-1999-1506/timeline.json",
      "vendor": "sun"
    },
    {
      "affected_label": "sgi / irix",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-1999-1554/",
      "current_public_safe_latest": false,
      "cvss_score": 2.1,
      "cvss_severity": "LOW",
      "epss_percentile": 0.33574,
      "epss_score": 0.00421,
      "first_observed_at": "2026-06-20T08:39:58.440157+00:00",
      "id": "CVE-1999-1554",
      "impact_tags": [
        "local exposure relevant"
      ],
      "kev": false,
      "last_observed_at": "2026-06-20T08:39:58.440157+00:00",
      "latest_item_url": null,
      "product": "irix",
      "public_safe_summary": "NVD: /usr/sbin/Mail on SGI IRIX 3.3 and 3.3.1 does not properly set the group ID to the group ID of the user who started Mail, which allows local users to read the mail of other users.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260703T085042Z/items/CVE-1999-1554.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "noindex_removal_allowed": false,
        "noindex_required": true,
        "patch_allowed": false,
        "public_launch_allowed": false,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: sgi / irix; affected version context: 3.3, 3.3.1",
      "source_published_impact": "Source describes local exposure. Possible impact: This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for local exposure.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: /usr/sbin/Mail on SGI IRIX 3.3 and 3.3.1 does not properly set the group ID to the group ID of the user who started Mail, which allows local users to read the mail of other users.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-1999-1554/timeline.json",
      "vendor": "sgi"
    },
    {
      "affected_label": "freebsd / freebsd",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2000-0388/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.76782,
      "epss_score": 0.01883,
      "first_observed_at": "2026-06-20T08:39:58.440157+00:00",
      "id": "CVE-2000-0388",
      "impact_tags": [
        "command execution review",
        "memory safety review",
        "local exposure relevant"
      ],
      "kev": false,
      "last_observed_at": "2026-06-20T08:39:58.440157+00:00",
      "latest_item_url": null,
      "product": "freebsd",
      "public_safe_summary": "NVD: Buffer overflow in FreeBSD libmytinfo library allows local users to execute commands via a long TERMCAP environmental variable.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260703T085042Z/items/CVE-2000-0388.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "noindex_removal_allowed": false,
        "noindex_required": true,
        "patch_allowed": false,
        "public_launch_allowed": false,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: freebsd / freebsd; affected version context: 3.0, 3.1, 3.2, 3.3, 3.4",
      "source_published_impact": "Source describes command execution risk · memory safety review · local exposure. Possible impact: A local user may be able to run code or commands on affected systems.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Buffer overflow in FreeBSD libmytinfo library allows local users to execute commands via a long TERMCAP environmental variable.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2000-0388/timeline.json",
      "vendor": "freebsd"
    },
    {
      "affected_label": "vmware / ace",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2005-4459/",
      "current_public_safe_latest": false,
      "cvss_score": 10.0,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.96133,
      "epss_score": 0.14123,
      "first_observed_at": "2026-07-08T03:39:09.814067+00:00",
      "id": "CVE-2005-4459",
      "impact_tags": [
        "code execution review",
        "memory safety review",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-09T07:02:07.404036+00:00",
      "latest_item_url": null,
      "product": "ace",
      "public_safe_summary": "NVD: Heap-based buffer overflow in the NAT networking components vmnat.exe and vmnet-natd in VMWare Workstation 5.5, GSX Server 3.2, ACE 1.0.1, and Player 1.0 allows remote authenticated attackers, including guests, to execute arbitrary code via crafted (1) EPRT...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260709T070253Z/items/CVE-2005-4459.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 6,
      "source_published_affected": "vendor/product: vmware / ace; affected version context: 1.0.0, 1.0.1, 2.0, 2.0.1_build_2129, 2.5.1",
      "source_published_impact": "Source describes code execution review · memory safety review · authenticated boundary. Possible impact: An attacker may be able to run code or commands on affected systems.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Heap-based buffer overflow in the NAT networking components vmnat.exe and vmnet-natd in VMWare Workstation 5.5, GSX Server 3.2, ACE 1.0.1, and Player 1.0 allows remote authenticated attackers, including guests, to execute arbitrary code via crafted (1) EPRT...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2005-4459/timeline.json",
      "vendor": "vmware"
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2011-10043/",
      "current_public_safe_latest": false,
      "cvss_score": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.34609,
      "epss_score": 0.00429,
      "first_observed_at": "2026-07-14T10:57:43.777280+00:00",
      "id": "CVE-2011-10043",
      "impact_tags": [
        "code execution review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-14T10:57:43.777280+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Module::Load versions before 0.22 for Perl allow arbitrary modules outside of @INC to be loaded. NVD: Module names starting with \"::\" could be passed to the load function to specify arbitrary module paths. NVD: Attackers able to influence module names passed to load could use that bug to execute arbitrary code.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260714T110007Z/items/CVE-2011-10043.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes code execution review. Possible impact: An attacker may be able to run code or commands on affected systems.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Module::Load versions before 0.22 for Perl allow arbitrary modules outside of @INC to be loaded. NVD: Module names starting with \"::\" could be passed to the load function to specify arbitrary module paths. NVD: Attackers able to influence module names passed to load could use that bug to execute arbitrary code.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2011-10043/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "craftercms / crafter_cms",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2017-15680/",
      "current_public_safe_latest": false,
      "cvss_score": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.50274,
      "epss_score": 0.00744,
      "first_observed_at": "2026-07-05T06:52:19.842940+00:00",
      "id": "CVE-2017-15680",
      "impact_tags": [
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-07T12:11:49.941771+00:00",
      "latest_item_url": null,
      "product": "crafter_cms",
      "public_safe_summary": "NVD: In Crafter CMS Crafter Studio 3.0.1 an IDOR vulnerability exists which allows unauthenticated attackers to view and modify administrative data. OSV: In Crafter CMS Crafter Studio 3.0.1 an IDOR vulnerability exists which allows unauthenticated attackers to view and modify administrative data.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260707T121320Z/items/CVE-2017-15680.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 10,
      "source_published_affected": "vendor/product: craftercms / crafter_cms",
      "source_published_impact": "Source describes remote exposure · authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: In Crafter CMS Crafter Studio 3.0.1 an IDOR vulnerability exists which allows unauthenticated attackers to view and modify administrative data. OSV: In Crafter CMS Crafter Studio 3.0.1 an IDOR vulnerability exists which allows unauthenticated attackers to view and modify administrative data.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2017-15680/timeline.json",
      "vendor": "craftercms"
    },
    {
      "affected_label": "vmware / spring_boot",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2017-8046/",
      "current_public_safe_latest": false,
      "cvss_score": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.99379,
      "epss_score": 0.72782,
      "first_observed_at": "2026-07-03T13:33:04.036864+00:00",
      "id": "CVE-2017-8046",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-03T16:47:59.544460+00:00",
      "latest_item_url": null,
      "product": "spring_boot",
      "public_safe_summary": "NVD: Malicious PATCH requests submitted to servers using Spring Data REST versions prior to 2.6.9 (Ingalls SR9), versions prior to 3.0.1 (Kay SR1) and Spring Boot versions prior to 1.5.9, 2.0 M6 can use specially crafted JSON data to run arbitrary Java code. OSV: Malicious PATCH requests submitted to servers using Spring Data REST versions prior to 2.6.9 (Ingalls SR9), versions prior to 3.0.1 (Kay SR1) and Spring Boot versions prior to 1.5.9, 2.0 M6 can use specially crafted JSON data to run arbitrary Java code.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260703T164824Z/items/CVE-2017-8046.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 5,
      "source_published_affected": "vendor/product: vmware / spring_boot; affected version context: 2.0.0, 3.0.0",
      "source_published_impact": "This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Malicious PATCH requests submitted to servers using Spring Data REST versions prior to 2.6.9 (Ingalls SR9), versions prior to 3.0.1 (Kay SR1) and Spring Boot versions prior to 1.5.9, 2.0 M6 can use specially crafted JSON data to run arbitrary Java code. OSV: Malicious PATCH requests submitted to servers using Spring Data REST versions prior to 2.6.9 (Ingalls SR9), versions prior to 3.0.1 (Kay SR1) and Spring Boot versions prior to 1.5.9, 2.0 M6 can use specially crafted JSON data to run arbitrary Java code.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2017-8046/timeline.json",
      "vendor": "vmware"
    },
    {
      "affected_label": "debian / debian_linux",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2018-10902/",
      "current_public_safe_latest": false,
      "cvss_score": 7.8,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.40576,
      "epss_score": 0.00523,
      "first_observed_at": "2026-07-08T03:39:09.814067+00:00",
      "id": "CVE-2018-10902",
      "impact_tags": [
        "privilege boundary review",
        "local exposure relevant"
      ],
      "kev": false,
      "last_observed_at": "2026-07-09T07:02:07.404036+00:00",
      "latest_item_url": null,
      "product": "debian_linux",
      "public_safe_summary": "NVD: It was found that the raw midi kernel driver does not protect against concurrent access which leads to a double realloc (double free) in snd_rawmidi_input_params() and snd_rawmidi_output_status() which are part of snd_rawmidi_ioctl() handler in rawmidi.c file. NVD: A malicious local attacker could possibly use this for privilege escalation. OSV: It was found that the raw midi kernel driver does not protect against concurrent access which leads to a double realloc (double free) in snd_rawmidi_input_params() and snd_rawmidi_output_status() which are part of snd_rawmidi_ioctl() handler in rawmidi.c file.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260709T070253Z/items/CVE-2018-10902.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 6,
      "source_published_affected": "vendor/product: debian / debian_linux; affected version context: -, 12.04, 14.04, 16.04, 18.04",
      "source_published_impact": "Source describes privilege escalation risk · local exposure. Possible impact: A local user may cross a privilege boundary and gain more access than intended.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: It was found that the raw midi kernel driver does not protect against concurrent access which leads to a double realloc (double free) in snd_rawmidi_input_params() and snd_rawmidi_output_status() which are part of snd_rawmidi_ioctl() handler in rawmidi.c file. NVD: A malicious local attacker could possibly use this for privilege escalation. OSV: It was found that the raw midi kernel driver does not protect against concurrent access which leads to a double realloc (double free) in snd_rawmidi_input_params() and snd_rawmidi_output_status() which are part of snd_rawmidi_ioctl() handler in rawmidi.c file.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2018-10902/timeline.json",
      "vendor": "debian"
    },
    {
      "affected_label": "broadcom / spring_data_commons",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2018-1259/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.91144,
      "epss_score": 0.0497,
      "first_observed_at": "2026-07-03T13:33:04.036864+00:00",
      "id": "CVE-2018-1259",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-03T16:47:59.544460+00:00",
      "latest_item_url": null,
      "product": "spring_data_commons",
      "public_safe_summary": "NVD: Spring Data Commons, versions 1.13 prior to 1.13.12 and 2.0 prior to 2.0.7, used in combination with XMLBeam 1.4.14 or earlier versions, contains a property binder vulnerability caused by improper restriction of XML external entity references as underlying... OSV: Spring Data Commons, versions 1.13 prior to 1.13.12 and 2.0 prior to 2.0.7, used in combination with XMLBeam 1.4.14 or earlier versions, contains a property binder vulnerability caused by improper restriction of XML external entity references as underlying...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260703T164824Z/items/CVE-2018-1259.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 5,
      "source_published_affected": "vendor/product: broadcom / spring_data_commons",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Spring Data Commons, versions 1.13 prior to 1.13.12 and 2.0 prior to 2.0.7, used in combination with XMLBeam 1.4.14 or earlier versions, contains a property binder vulnerability caused by improper restriction of XML external entity references as underlying... OSV: Spring Data Commons, versions 1.13 prior to 1.13.12 and 2.0 prior to 2.0.7, used in combination with XMLBeam 1.4.14 or earlier versions, contains a property binder vulnerability caused by improper restriction of XML external entity references as underlying...",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2018-1259/timeline.json",
      "vendor": "broadcom"
    },
    {
      "affected_label": "broadcom / spring_data_commons",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2018-1273/",
      "current_public_safe_latest": false,
      "cvss_score": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.99861,
      "epss_score": 0.95649,
      "first_observed_at": "2026-07-03T13:33:04.036864+00:00",
      "id": "CVE-2018-1273",
      "impact_tags": [],
      "kev": true,
      "last_observed_at": "2026-07-03T16:47:59.544460+00:00",
      "latest_item_url": null,
      "product": "spring_data_commons",
      "public_safe_summary": "NVD: Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property binder vulnerability caused by improper neutralization of special elements. CISA KEV: VMware Tanzu Spring Data Commons Property Binder Vulnerability OSV: Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property binder vulnerability caused by improper neutralization of special elements.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260703T164824Z/items/CVE-2018-1273.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 5,
      "source_published_affected": "vendor/product: broadcom / spring_data_commons; affected version context: 1.0.0, 8.0.8.2.0, 8.0.8.3.0",
      "source_published_impact": "This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for known exploited catalog listed.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property binder vulnerability caused by improper neutralization of special elements. CISA KEV: VMware Tanzu Spring Data Commons Property Binder Vulnerability OSV: Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property binder vulnerability caused by improper neutralization of special elements.",
      "sources": [
        "NVD",
        "OSV",
        "CISA KEV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2018-1273/timeline.json",
      "vendor": "broadcom"
    },
    {
      "affected_label": "broadcom / spring_data_commons",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2018-1274/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.77982,
      "epss_score": 0.01969,
      "first_observed_at": "2026-07-03T13:33:04.036864+00:00",
      "id": "CVE-2018-1274",
      "impact_tags": [
        "service availability review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-03T16:47:59.544460+00:00",
      "latest_item_url": null,
      "product": "spring_data_commons",
      "public_safe_summary": "NVD: Spring Data Commons, versions 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property path parser vulnerability caused by unlimited resource allocation. NVD: An unauthenticated remote malicious user (or attacker) can issue requests against Spring Data REST endpoints or endpoints using property path parsing which can cause a denial of service (CPU and memory consumption). OSV: Spring Data Commons, versions 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property path parser vulnerability caused by unlimited resource allocation.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260703T164824Z/items/CVE-2018-1274.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 5,
      "source_published_affected": "vendor/product: broadcom / spring_data_commons",
      "source_published_impact": "Source describes service availability risk. Possible impact: The affected service may become unavailable or unreliable.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Spring Data Commons, versions 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property path parser vulnerability caused by unlimited resource allocation. NVD: An unauthenticated remote malicious user (or attacker) can issue requests against Spring Data REST endpoints or endpoints using property path parsing which can cause a denial of service (CPU and memory consumption). OSV: Spring Data Commons, versions 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property path parser vulnerability caused by unlimited resource allocation.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2018-1274/timeline.json",
      "vendor": "broadcom"
    },
    {
      "affected_label": "zohocorp / manageengine_adselfservice_plus",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2018-5353/",
      "current_public_safe_latest": false,
      "cvss_score": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.9414,
      "epss_score": 0.08103,
      "first_observed_at": "2026-07-08T03:39:09.814067+00:00",
      "id": "CVE-2018-5353",
      "impact_tags": [
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-09T07:02:07.404036+00:00",
      "latest_item_url": null,
      "product": "manageengine_adselfservice_plus",
      "public_safe_summary": "NVD: The custom GINA/CP module in Zoho ManageEngine ADSelfService Plus before 5.5 build 5517 allows remote attackers to execute code and escalate privileges via spoofing. NVD: It does not authenticate the intended server before opening a browser window. NVD: An unauthenticated attacker capable of conducting a spoofing attack can redirect the browser to gain execution in the context of the WinLogon.exe process.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260709T070253Z/items/CVE-2018-5353.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 6,
      "source_published_affected": "vendor/product: zohocorp / manageengine_adselfservice_plus; affected version context: 5.5",
      "source_published_impact": "Source describes remote exposure · authenticated boundary. Possible impact: This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The custom GINA/CP module in Zoho ManageEngine ADSelfService Plus before 5.5 build 5517 allows remote attackers to execute code and escalate privileges via spoofing. NVD: It does not authenticate the intended server before opening a browser window. NVD: An unauthenticated attacker capable of conducting a spoofing attack can redirect the browser to gain execution in the context of the WinLogon.exe process.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2018-5353/timeline.json",
      "vendor": "zohocorp"
    },
    {
      "affected_label": "anixis / password_reset_client",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2018-5354/",
      "current_public_safe_latest": false,
      "cvss_score": 8.8,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.84,
      "epss_score": 0.02678,
      "first_observed_at": "2026-07-08T03:39:09.814067+00:00",
      "id": "CVE-2018-5354",
      "impact_tags": [
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-09T07:02:07.404036+00:00",
      "latest_item_url": null,
      "product": "password_reset_client",
      "public_safe_summary": "NVD: The custom GINA/CP module in ANIXIS Password Reset Client before version 3.22 allows remote attackers to execute code and escalate privileges via spoofing. NVD: When the client is configured to use HTTP, it does not authenticate the intended server before opening a browser window. NVD: An unauthenticated attacker capable of conducting a spoofing attack can redirect the browser to gain execution in the context of the WinLogon.exe process.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260709T070253Z/items/CVE-2018-5354.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 6,
      "source_published_affected": "vendor/product: anixis / password_reset_client",
      "source_published_impact": "Source describes remote exposure · authenticated boundary. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The custom GINA/CP module in ANIXIS Password Reset Client before version 3.22 allows remote attackers to execute code and escalate privileges via spoofing. NVD: When the client is configured to use HTTP, it does not authenticate the intended server before opening a browser window. NVD: An unauthenticated attacker capable of conducting a spoofing attack can redirect the browser to gain execution in the context of the WinLogon.exe process.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2018-5354/timeline.json",
      "vendor": "anixis"
    },
    {
      "affected_label": "verot_project / verot",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2019-19576/",
      "current_public_safe_latest": false,
      "cvss_score": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.97742,
      "epss_score": 0.26184,
      "first_observed_at": "2026-07-03T13:33:04.036864+00:00",
      "id": "CVE-2019-19576",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-03T13:33:04.036864+00:00",
      "latest_item_url": null,
      "product": "verot",
      "public_safe_summary": "NVD: class.upload.php in verot.net class.upload before 1.0.3 and 2.x before 2.0.4, as used in the K2 extension for Joomla! NVD: and other products, omits .phar from the set of dangerous file extensions. OSV: class.upload.php in verot.net class.upload before 1.0.3 and 2.x before 2.0.4, as used in the K2 extension for Joomla!",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260703T133800Z/items/CVE-2019-19576.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "noindex_removal_allowed": false,
        "noindex_required": true,
        "patch_allowed": false,
        "public_launch_allowed": false,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "vendor/product: verot_project / verot",
      "source_published_impact": "This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: class.upload.php in verot.net class.upload before 1.0.3 and 2.x before 2.0.4, as used in the K2 extension for Joomla! NVD: and other products, omits .phar from the set of dangerous file extensions. OSV: class.upload.php in verot.net class.upload before 1.0.3 and 2.x before 2.0.4, as used in the K2 extension for Joomla!",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2019-19576/timeline.json",
      "vendor": "verot_project"
    },
    {
      "affected_label": "verot_project / verot",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2019-19634/",
      "current_public_safe_latest": false,
      "cvss_score": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.89624,
      "epss_score": 0.04153,
      "first_observed_at": "2026-07-03T13:33:04.036864+00:00",
      "id": "CVE-2019-19634",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-03T13:33:04.036864+00:00",
      "latest_item_url": null,
      "product": "verot",
      "public_safe_summary": "NVD: class.upload.php in verot.net class.upload through 1.0.3 and 2.x through 2.0.4, as used in the K2 extension for Joomla! NVD: and other products, omits .pht from the set of dangerous file extensions, a similar issue to CVE-2019-19576. OSV: class.upload.php in verot.net class.upload through 1.0.3 and 2.x through 2.0.4, as used in the K2 extension for Joomla!",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260703T133800Z/items/CVE-2019-19634.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "noindex_removal_allowed": false,
        "noindex_required": true,
        "patch_allowed": false,
        "public_launch_allowed": false,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "vendor/product: verot_project / verot",
      "source_published_impact": "This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: class.upload.php in verot.net class.upload through 1.0.3 and 2.x through 2.0.4, as used in the K2 extension for Joomla! NVD: and other products, omits .pht from the set of dangerous file extensions, a similar issue to CVE-2019-19576. OSV: class.upload.php in verot.net class.upload through 1.0.3 and 2.x through 2.0.4, as used in the K2 extension for Joomla!",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2019-19634/timeline.json",
      "vendor": "verot_project"
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2019-25764/",
      "current_public_safe_latest": false,
      "cvss_score": 7.3,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.00561,
      "epss_score": 0.0009,
      "first_observed_at": "2026-07-24T06:06:41.160911+00:00",
      "id": "CVE-2019-25764",
      "impact_tags": [
        "privilege boundary review",
        "local exposure relevant"
      ],
      "kev": false,
      "last_observed_at": "2026-07-24T06:06:41.160911+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: **UNSUPPORTED WHEN ASSIGNED** Exposed IOCTL with Insufficient Access Control in the ASUS AURA SYNC driver allows a local user to bypass the driver's verification and invoke arbitrary IOCTLs, resulting in privilege escalation. NVD: Refer to the 'End-of-Life Notice and Driver Update for Legacy ASUS Drivers ' section on the ASUS Security Advisory for more information.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260724T061150Z/items/CVE-2019-25764.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes privilege escalation risk · local exposure. Possible impact: A local user may cross a privilege boundary and gain more access than intended.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: **UNSUPPORTED WHEN ASSIGNED** Exposed IOCTL with Insufficient Access Control in the ASUS AURA SYNC driver allows a local user to bypass the driver's verification and invoke arbitrary IOCTLs, resulting in privilege escalation. NVD: Refer to the 'End-of-Life Notice and Driver Update for Legacy ASUS Drivers ' section on the ASUS Security Advisory for more information.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2019-25764/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "gazie_project / gazie",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2020-21731/",
      "current_public_safe_latest": false,
      "cvss_score": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.54242,
      "epss_score": 0.00864,
      "first_observed_at": "2026-07-08T03:39:09.814067+00:00",
      "id": "CVE-2020-21731",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-09T07:02:07.404036+00:00",
      "latest_item_url": null,
      "product": "gazie",
      "public_safe_summary": "NVD: Gazie 7.29 is affected by: Cross Site Scripting (XSS) via An attacker can inject JavaScript code, and the webapplication stores the injected code.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260709T070253Z/items/CVE-2020-21731.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 6,
      "source_published_affected": "vendor/product: gazie_project / gazie; affected version context: 7.29",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Gazie 7.29 is affected by: Cross Site Scripting (XSS) via An attacker can inject JavaScript code, and the webapplication stores the injected code.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2020-21731/timeline.json",
      "vendor": "gazie_project"
    },
    {
      "affected_label": "rukovoditel / rukovoditel",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2020-21732/",
      "current_public_safe_latest": false,
      "cvss_score": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.54243,
      "epss_score": 0.00864,
      "first_observed_at": "2026-07-08T03:39:09.814067+00:00",
      "id": "CVE-2020-21732",
      "impact_tags": [
        "XSS risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-09T07:02:07.404036+00:00",
      "latest_item_url": null,
      "product": "rukovoditel",
      "public_safe_summary": "NVD: Rukovoditel Project Management app 2.6 is affected by: Cross Site Scripting (XSS). NVD: An attacker can add JavaScript code to the filename.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260709T070253Z/items/CVE-2020-21732.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 6,
      "source_published_affected": "vendor/product: rukovoditel / rukovoditel; affected version context: 2.6",
      "source_published_impact": "Source describes XSS risk. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Rukovoditel Project Management app 2.6 is affected by: Cross Site Scripting (XSS). NVD: An attacker can add JavaScript code to the filename.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2020-21732/timeline.json",
      "vendor": "rukovoditel"
    },
    {
      "affected_label": "sagemcom / f\\@st_3686_firmware",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2020-21733/",
      "current_public_safe_latest": false,
      "cvss_score": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.58433,
      "epss_score": 0.00995,
      "first_observed_at": "2026-07-08T03:39:09.814067+00:00",
      "id": "CVE-2020-21733",
      "impact_tags": [
        "XSS risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-09T07:02:07.404036+00:00",
      "latest_item_url": null,
      "product": "f\\@st_3686_firmware",
      "public_safe_summary": "NVD: Sagemcom F@ST3686 v1.0 HUN 3.97.0 has XSS via RgDiagnostics.asp, RgDdns.asp, RgFirewallEL.asp, RgVpnL2tpPptp.asp.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260709T070253Z/items/CVE-2020-21733.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 6,
      "source_published_affected": "vendor/product: sagemcom / f\\@st_3686_firmware; affected version context: -, 1.0_hun_3.97.0",
      "source_published_impact": "Source describes XSS risk. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Sagemcom F@ST3686 v1.0 HUN 3.97.0 has XSS via RgDiagnostics.asp, RgDdns.asp, RgFirewallEL.asp, RgVpnL2tpPptp.asp.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2020-21733/timeline.json",
      "vendor": "sagemcom"
    },
    {
      "affected_label": "snap7_project / snap7",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2020-22552/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.78532,
      "epss_score": 0.02011,
      "first_observed_at": "2026-07-08T03:39:09.814067+00:00",
      "id": "CVE-2020-22552",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-09T07:02:07.404036+00:00",
      "latest_item_url": null,
      "product": "snap7",
      "public_safe_summary": "NVD: The Snap7 server component in version 1.4.1, when an attacker sends a crafted packet with COTP protocol the last-data-unit flag set to No and S7 writes a var function, the Snap7 server will be crashed.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260709T070253Z/items/CVE-2020-22552.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 6,
      "source_published_affected": "vendor/product: snap7_project / snap7; affected version context: 1.4.1",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Snap7 server component in version 1.4.1, when an attacker sends a crafted packet with COTP protocol the last-data-unit flag set to No and S7 writes a var function, the Snap7 server will be crashed.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2020-22552/timeline.json",
      "vendor": "snap7_project"
    },
    {
      "affected_label": "microweber / microweber",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2020-23136/",
      "current_public_safe_latest": false,
      "cvss_score": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.2469,
      "epss_score": 0.00328,
      "first_observed_at": "2026-07-08T03:39:09.814067+00:00",
      "id": "CVE-2020-23136",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-09T07:02:07.404036+00:00",
      "latest_item_url": null,
      "product": "microweber",
      "public_safe_summary": "NVD: Microweber v1.1.18 is affected by no session expiry after log-out.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260709T070253Z/items/CVE-2020-23136.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 6,
      "source_published_affected": "vendor/product: microweber / microweber; affected version context: 1.1.18",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Microweber v1.1.18 is affected by no session expiry after log-out.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2020-23136/timeline.json",
      "vendor": "microweber"
    },
    {
      "affected_label": "verint / workforce_optimization",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2020-23446/",
      "current_public_safe_latest": false,
      "cvss_score": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.70426,
      "epss_score": 0.0146,
      "first_observed_at": "2026-07-08T03:39:09.814067+00:00",
      "id": "CVE-2020-23446",
      "impact_tags": [
        "information exposure review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-09T07:02:07.404036+00:00",
      "latest_item_url": null,
      "product": "workforce_optimization",
      "public_safe_summary": "NVD: Verint Workforce Optimization suite 15.1 (15.1.0.37634) has Unauthenticated Information Disclosure via API",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260709T070253Z/items/CVE-2020-23446.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 6,
      "source_published_affected": "vendor/product: verint / workforce_optimization; affected version context: 15.1.0.37634",
      "source_published_impact": "Source describes information exposure review. Possible impact: An attacker may be able to access information that should not be exposed.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Verint Workforce Optimization suite 15.1 (15.1.0.37634) has Unauthenticated Information Disclosure via API",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2020-23446/timeline.json",
      "vendor": "verint"
    },
    {
      "affected_label": "spiceworks / spiceworks",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2020-23450/",
      "current_public_safe_latest": false,
      "cvss_score": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.51586,
      "epss_score": 0.00783,
      "first_observed_at": "2026-07-08T03:39:09.814067+00:00",
      "id": "CVE-2020-23450",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-09T07:02:07.404036+00:00",
      "latest_item_url": null,
      "product": "spiceworks",
      "public_safe_summary": "NVD: Spiceworks Version <= 7.5.00107 is affected by XSS. NVD: Any name typed on Custom Groups function is vulnerable to stored XSS as they displayed on without output sanitization.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260709T070253Z/items/CVE-2020-23450.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 6,
      "source_published_affected": "vendor/product: spiceworks / spiceworks",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Spiceworks Version <= 7.5.00107 is affected by XSS. NVD: Any name typed on Custom Groups function is vulnerable to stored XSS as they displayed on without output sanitization.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2020-23450/timeline.json",
      "vendor": "spiceworks"
    },
    {
      "affected_label": "spiceworks / spiceworks",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2020-23451/",
      "current_public_safe_latest": false,
      "cvss_score": 8.8,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.44496,
      "epss_score": 0.00601,
      "first_observed_at": "2026-07-08T03:39:09.814067+00:00",
      "id": "CVE-2020-23451",
      "impact_tags": [
        "privilege boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-09T07:02:07.404036+00:00",
      "latest_item_url": null,
      "product": "spiceworks",
      "public_safe_summary": "NVD: Spiceworks Version <= 7.5.00107 is affected by CSRF which can lead to privilege escalation via \"/settings/v1/users\" function.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260709T070253Z/items/CVE-2020-23451.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 6,
      "source_published_affected": "vendor/product: spiceworks / spiceworks",
      "source_published_impact": "Source describes privilege escalation risk. Possible impact: An attacker may cross a privilege boundary and gain more access than intended.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Spiceworks Version <= 7.5.00107 is affected by CSRF which can lead to privilege escalation via \"/settings/v1/users\" function.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2020-23451/timeline.json",
      "vendor": "spiceworks"
    },
    {
      "affected_label": "ilex / international_sign\\&go",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2020-23968/",
      "current_public_safe_latest": false,
      "cvss_score": 7.8,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.55055,
      "epss_score": 0.00891,
      "first_observed_at": "2026-07-08T03:39:09.814067+00:00",
      "id": "CVE-2020-23968",
      "impact_tags": [
        "privilege boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-09T07:02:07.404036+00:00",
      "latest_item_url": null,
      "product": "international_sign\\&go",
      "public_safe_summary": "NVD: Ilex International Sign&go Workstation Security Suite 7.1 allows elevation of privileges via a symlink attack on ProgramData\\Ilex\\S&G\\Logs\\000-sngWSService1.log.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260709T070253Z/items/CVE-2020-23968.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 6,
      "source_published_affected": "vendor/product: ilex / international_sign\\&go; affected version context: 7.1",
      "source_published_impact": "Source describes privilege escalation risk. Possible impact: An attacker may cross a privilege boundary and gain more access than intended.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Ilex International Sign&go Workstation Security Suite 7.1 allows elevation of privileges via a symlink attack on ProgramData\\Ilex\\S&G\\Logs\\000-sngWSService1.log.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2020-23968/timeline.json",
      "vendor": "ilex"
    },
    {
      "affected_label": "daily_tracker_system_project / daily_tracker_system",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2020-24193/",
      "current_public_safe_latest": false,
      "cvss_score": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.84564,
      "epss_score": 0.0277,
      "first_observed_at": "2026-07-08T03:39:09.814067+00:00",
      "id": "CVE-2020-24193",
      "impact_tags": [
        "authentication boundary review",
        "SQL injection risk",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-09T07:02:07.404036+00:00",
      "latest_item_url": null,
      "product": "daily_tracker_system",
      "public_safe_summary": "NVD: A SQL injection vulnerability in login in Sourcecodetester Daily Tracker System 1.0 allows unauthenticated user to execute authentication bypass with SQL injection via the email parameter.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260709T070253Z/items/CVE-2020-24193.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 6,
      "source_published_affected": "vendor/product: daily_tracker_system_project / daily_tracker_system; affected version context: 1.0",
      "source_published_impact": "Source describes authentication boundary review · SQL injection risk · authenticated boundary. Possible impact: An attacker may be able to read or change database-backed application data.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A SQL injection vulnerability in login in Sourcecodetester Daily Tracker System 1.0 allows unauthenticated user to execute authentication bypass with SQL injection via the email parameter.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2020-24193/timeline.json",
      "vendor": "daily_tracker_system_project"
    },
    {
      "affected_label": "daily_tracker_system_project / daily_tracker_system",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2020-24194/",
      "current_public_safe_latest": false,
      "cvss_score": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.53296,
      "epss_score": 0.00835,
      "first_observed_at": "2026-07-08T03:39:09.814067+00:00",
      "id": "CVE-2020-24194",
      "impact_tags": [
        "XSS risk",
        "remote exposure relevant"
      ],
      "kev": false,
      "last_observed_at": "2026-07-09T07:02:07.404036+00:00",
      "latest_item_url": null,
      "product": "daily_tracker_system",
      "public_safe_summary": "NVD: A Cross-site scripting (XSS) vulnerability in 'user-profile.php' in SourceCodester Daily Tracker System v1.0 allows remote attackers to inject arbitrary web script or HTML via the 'fullname' parameter.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260709T070253Z/items/CVE-2020-24194.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 6,
      "source_published_affected": "vendor/product: daily_tracker_system_project / daily_tracker_system; affected version context: 1.0",
      "source_published_impact": "Source describes XSS risk · remote exposure. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk · remote exposure.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A Cross-site scripting (XSS) vulnerability in 'user-profile.php' in SourceCodester Daily Tracker System v1.0 allows remote attackers to inject arbitrary web script or HTML via the 'fullname' parameter.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2020-24194/timeline.json",
      "vendor": "daily_tracker_system_project"
    },
    {
      "affected_label": "microstrategy / microstrategy",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2020-24815/",
      "current_public_safe_latest": false,
      "cvss_score": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.79049,
      "epss_score": 0.02061,
      "first_observed_at": "2026-07-05T06:52:19.842940+00:00",
      "id": "CVE-2020-24815",
      "impact_tags": [
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-07T17:28:10.703016+00:00",
      "latest_item_url": null,
      "product": "microstrategy",
      "public_safe_summary": "NVD: A Server-Side Request Forgery (SSRF) affecting the PDF generation in MicroStrategy 10.4, 2019 before Update 6, and 2020 before Update 2 allows authenticated users to access the content of internal network resources or leak files from the local system via HTML... NVD: NOTE: 10.4., no fix will be released as version will reach end-of-life on 31/12/2020.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260707T172914Z/items/CVE-2020-24815.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 11,
      "source_published_affected": "vendor/product: microstrategy / microstrategy; affected version context: 10.4, 2019, 2020",
      "source_published_impact": "Source describes authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A Server-Side Request Forgery (SSRF) affecting the PDF generation in MicroStrategy 10.4, 2019 before Update 6, and 2020 before Update 2 allows authenticated users to access the content of internal network resources or leak files from the local system via HTML... NVD: NOTE: 10.4., no fix will be released as version will reach end-of-life on 31/12/2020.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2020-24815/timeline.json",
      "vendor": "microstrategy"
    },
    {
      "affected_label": "crmeb / crmeb",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2020-25466/",
      "current_public_safe_latest": false,
      "cvss_score": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.85898,
      "epss_score": 0.03033,
      "first_observed_at": "2026-07-08T03:39:09.814067+00:00",
      "id": "CVE-2020-25466",
      "impact_tags": [
        "code execution review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-09T07:02:07.404036+00:00",
      "latest_item_url": null,
      "product": "crmeb",
      "public_safe_summary": "NVD: A SSRF vulnerability exists in the downloadimage interface of CRMEB 3.0, which can remotely download arbitrary files on the server and remotely execute arbitrary code. OSV: A SSRF vulnerability exists in the downloadimage interface of CRMEB 3.0, which can remotely download arbitrary files on the server and remotely execute arbitrary code.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260709T070253Z/items/CVE-2020-25466.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 6,
      "source_published_affected": "vendor/product: crmeb / crmeb; affected version context: 3.0",
      "source_published_impact": "Source describes code execution review. Possible impact: An attacker may be able to run code or commands on affected systems.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A SSRF vulnerability exists in the downloadimage interface of CRMEB 3.0, which can remotely download arbitrary files on the server and remotely execute arbitrary code. OSV: A SSRF vulnerability exists in the downloadimage interface of CRMEB 3.0, which can remotely download arbitrary files on the server and remotely execute arbitrary code.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2020-25466/timeline.json",
      "vendor": "crmeb"
    },
    {
      "affected_label": "phpgurukul / zoo_management_system",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2020-25487/",
      "current_public_safe_latest": false,
      "cvss_score": 7.8,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.42209,
      "epss_score": 0.00553,
      "first_observed_at": "2026-07-08T03:39:09.814067+00:00",
      "id": "CVE-2020-25487",
      "impact_tags": [
        "SQL injection risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-09T07:02:07.404036+00:00",
      "latest_item_url": null,
      "product": "zoo_management_system",
      "public_safe_summary": "NVD: PHPGURUKUL Zoo Management System Using PHP and MySQL version 1.0 is affected by: SQL Injection via zms/animal-detail.php.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260709T070253Z/items/CVE-2020-25487.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 6,
      "source_published_affected": "vendor/product: phpgurukul / zoo_management_system; affected version context: 1.0",
      "source_published_impact": "Source describes SQL injection risk. Possible impact: An attacker may be able to read or change database-backed application data.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: PHPGURUKUL Zoo Management System Using PHP and MySQL version 1.0 is affected by: SQL Injection via zms/animal-detail.php.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2020-25487/timeline.json",
      "vendor": "phpgurukul"
    },
    {
      "affected_label": "simple_library_management_system_project / simple_library_management_system",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2020-25514/",
      "current_public_safe_latest": false,
      "cvss_score": 8.4,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.45783,
      "epss_score": 0.00629,
      "first_observed_at": "2026-07-08T03:39:09.814067+00:00",
      "id": "CVE-2020-25514",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-09T07:02:07.404036+00:00",
      "latest_item_url": null,
      "product": "simple_library_management_system",
      "public_safe_summary": "NVD: Sourcecodester Simple Library Management System 1.0 is affected by Incorrect Access Control via the Login Panel,",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260709T070253Z/items/CVE-2020-25514.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 6,
      "source_published_affected": "vendor/product: simple_library_management_system_project / simple_library_management_system; affected version context: 1.0",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Sourcecodester Simple Library Management System 1.0 is affected by Incorrect Access Control via the Login Panel,",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2020-25514/timeline.json",
      "vendor": "simple_library_management_system_project"
    },
    {
      "affected_label": "simple_library_management_system_project / simple_library_management_system",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2020-25515/",
      "current_public_safe_latest": false,
      "cvss_score": 7.8,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.41568,
      "epss_score": 0.00541,
      "first_observed_at": "2026-07-08T03:39:09.814067+00:00",
      "id": "CVE-2020-25515",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-09T07:02:07.404036+00:00",
      "latest_item_url": null,
      "product": "simple_library_management_system",
      "public_safe_summary": "NVD: Sourcecodester Simple Library Management System 1.0 is affected by Insecure Permissions via Books > New Book ,",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260709T070253Z/items/CVE-2020-25515.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 6,
      "source_published_affected": "vendor/product: simple_library_management_system_project / simple_library_management_system; affected version context: 1.0",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Sourcecodester Simple Library Management System 1.0 is affected by Insecure Permissions via Books > New Book ,",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2020-25515/timeline.json",
      "vendor": "simple_library_management_system_project"
    },
    {
      "affected_label": "yourls / yourls",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2020-27388/",
      "current_public_safe_latest": false,
      "cvss_score": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.50617,
      "epss_score": 0.00754,
      "first_observed_at": "2026-07-08T03:39:09.814067+00:00",
      "id": "CVE-2020-27388",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-09T07:02:07.404036+00:00",
      "latest_item_url": null,
      "product": "yourls",
      "public_safe_summary": "NVD: Multiple Stored Cross Site Scripting (XSS) vulnerabilities exist in the YOURLS Admin Panel, Versions 1.5 - 1.7.10.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260709T070253Z/items/CVE-2020-27388.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 6,
      "source_published_affected": "vendor/product: yourls / yourls",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Multiple Stored Cross Site Scripting (XSS) vulnerabilities exist in the YOURLS Admin Panel, Versions 1.5 - 1.7.10.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2020-27388/timeline.json",
      "vendor": "yourls"
    },
    {
      "affected_label": "schneider-electric / easergy_t300_firmware",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2021-22769/",
      "current_public_safe_latest": false,
      "cvss_score": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.46496,
      "epss_score": 0.00646,
      "first_observed_at": "2026-07-03T13:33:04.036864+00:00",
      "id": "CVE-2021-22769",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-04T22:14:25.791334+00:00",
      "latest_item_url": null,
      "product": "easergy_t300_firmware",
      "public_safe_summary": "NVD: A CWE-552: Files or Directories Accessible to External Parties vulnerability exists in Easergy T300 with firmware V2.7.1 and older that could expose files or directory content when access from an attacker is not restricted or incorrectly restricted.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260704T221450Z/items/CVE-2021-22769.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 11,
      "source_published_affected": "vendor/product: schneider-electric / easergy_t300_firmware; affected version context: -",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A CWE-552: Files or Directories Accessible to External Parties vulnerability exists in Easergy T300 with firmware V2.7.1 and older that could expose files or directory content when access from an attacker is not restricted or incorrectly restricted.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2021-22769/timeline.json",
      "vendor": "schneider-electric"
    },
    {
      "affected_label": "nsasoft / spotauditor",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2021-27722/",
      "current_public_safe_latest": false,
      "cvss_score": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.48449,
      "epss_score": 0.00694,
      "first_observed_at": "2026-07-03T13:33:04.036864+00:00",
      "id": "CVE-2021-27722",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-04T22:14:25.791334+00:00",
      "latest_item_url": null,
      "product": "spotauditor",
      "public_safe_summary": "NVD: An issue was discovered in Nsasoft US LLC SpotAuditor 5.3.5. NVD: The program can be crashed by entering 300 bytes char data into the \"Key\" or \"Name\" field while registering.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260704T221450Z/items/CVE-2021-27722.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 11,
      "source_published_affected": "vendor/product: nsasoft / spotauditor; affected version context: 5.3.5",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: An issue was discovered in Nsasoft US LLC SpotAuditor 5.3.5. NVD: The program can be crashed by entering 300 bytes char data into the \"Key\" or \"Name\" field while registering.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2021-27722/timeline.json",
      "vendor": "nsasoft"
    },
    {
      "affected_label": "eclipse / mosquitto",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2021-34432/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.65728,
      "epss_score": 0.01247,
      "first_observed_at": "2026-07-03T13:33:04.036864+00:00",
      "id": "CVE-2021-34432",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-04T22:14:25.791334+00:00",
      "latest_item_url": null,
      "product": "mosquitto",
      "public_safe_summary": "NVD: In Eclipse Mosquitto versions 2.0.7 and earlier, the server will crash if the client tries to send a PUBLISH packet with topic length = 0. OSV: In Eclipse Mosquitto versions 2.07 and earlier, the server will crash if the client tries to send a PUBLISH packet with topic length = 0.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260704T221450Z/items/CVE-2021-34432.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 11,
      "source_published_affected": "vendor/product: eclipse / mosquitto",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: In Eclipse Mosquitto versions 2.0.7 and earlier, the server will crash if the client tries to send a PUBLISH packet with topic length = 0. OSV: In Eclipse Mosquitto versions 2.07 and earlier, the server will crash if the client tries to send a PUBLISH packet with topic length = 0.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2021-34432/timeline.json",
      "vendor": "eclipse"
    },
    {
      "affected_label": "strapi / strapi",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2022-32114/",
      "current_public_safe_latest": false,
      "cvss_score": 8.8,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.7252,
      "epss_score": 0.01578,
      "first_observed_at": "2026-07-03T13:33:04.036864+00:00",
      "id": "CVE-2022-32114",
      "impact_tags": [
        "XSS risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-04T22:14:25.791334+00:00",
      "latest_item_url": null,
      "product": "strapi",
      "public_safe_summary": "NVD: An unrestricted file upload vulnerability in the Add New Assets function of Strapi 4.1.12 allows attackers to conduct XSS attacks via a crafted PDF file. NVD: NOTE: the project documentation suggests that a user with the Media Library \"Create (upload)\" permission is supposed to be able to upload PDF files containing JavaScript, and that all files in a public assets folder are accessible to the outside world (unless... NVD: The administrator can choose to allow only image, video, and audio files (i.e., not PDF) if desired.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260704T221450Z/items/CVE-2022-32114.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 11,
      "source_published_affected": "vendor/product: strapi / strapi; affected version context: 4.1.12",
      "source_published_impact": "Source describes XSS risk. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: An unrestricted file upload vulnerability in the Add New Assets function of Strapi 4.1.12 allows attackers to conduct XSS attacks via a crafted PDF file. NVD: NOTE: the project documentation suggests that a user with the Media Library \"Create (upload)\" permission is supposed to be able to upload PDF files containing JavaScript, and that all files in a public assets folder are accessible to the outside world (unless... NVD: The administrator can choose to allow only image, video, and audio files (i.e., not PDF) if desired.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2022-32114/timeline.json",
      "vendor": "strapi"
    },
    {
      "affected_label": "sangoma / asterisk",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2022-37325/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.61644,
      "epss_score": 0.01099,
      "first_observed_at": "2026-07-03T13:33:04.036864+00:00",
      "id": "CVE-2022-37325",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-04T22:14:25.791334+00:00",
      "latest_item_url": null,
      "product": "asterisk",
      "public_safe_summary": "NVD: In Sangoma Asterisk through 16.28.0, 17.x and 18.x through 18.14.0, and 19.x through 19.6.0, an incoming Setup message to addons/ooh323c/src/ooq931.c with a malformed Calling or Called Party IE can cause a crash. OSV: In Sangoma Asterisk through 16.28.0, 17.x and 18.x through 18.14.0, and 19.x through 19.6.0, an incoming Setup message to addons/ooh323c/src/ooq931.c with a malformed Calling or Called Party IE can cause a crash.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260704T221450Z/items/CVE-2022-37325.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 11,
      "source_published_affected": "vendor/product: sangoma / asterisk; affected version context: 20.0.0",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: In Sangoma Asterisk through 16.28.0, 17.x and 18.x through 18.14.0, and 19.x through 19.6.0, an incoming Setup message to addons/ooh323c/src/ooq931.c with a malformed Calling or Called Party IE can cause a crash. OSV: In Sangoma Asterisk through 16.28.0, 17.x and 18.x through 18.14.0, and 19.x through 19.6.0, an incoming Setup message to addons/ooh323c/src/ooq931.c with a malformed Calling or Called Party IE can cause a crash.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2022-37325/timeline.json",
      "vendor": "sangoma"
    },
    {
      "affected_label": "libjxl_project / libjxl",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2023-0645/",
      "current_public_safe_latest": false,
      "cvss_score": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.52213,
      "epss_score": 0.00802,
      "first_observed_at": "2026-07-03T13:33:04.036864+00:00",
      "id": "CVE-2023-0645",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-04T22:14:25.791334+00:00",
      "latest_item_url": null,
      "product": "libjxl",
      "public_safe_summary": "NVD: An out of bounds read exists in libjxl. NVD: An attacker using a specifically crafted file could cause an out of bounds read in the exif handler. NVD: We recommend upgrading to version 0.8.1 or past commit",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260704T221450Z/items/CVE-2023-0645.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 11,
      "source_published_affected": "vendor/product: libjxl_project / libjxl",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: An out of bounds read exists in libjxl. NVD: An attacker using a specifically crafted file could cause an out of bounds read in the exif handler. NVD: We recommend upgrading to version 0.8.1 or past commit",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2023-0645/timeline.json",
      "vendor": "libjxl_project"
    },
    {
      "affected_label": "fetlife / rollout-ui",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2023-25309/",
      "current_public_safe_latest": false,
      "cvss_score": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.48539,
      "epss_score": 0.00697,
      "first_observed_at": "2026-07-04T22:14:25.791334+00:00",
      "id": "CVE-2023-25309",
      "impact_tags": [
        "code execution review",
        "XSS risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-04T22:14:25.791334+00:00",
      "latest_item_url": null,
      "product": "rollout-ui",
      "public_safe_summary": "NVD: Cross Site Scripting (XSS) Vulnerability in Fetlife rollout-ui version 0.5, allows attackers to execute arbitrary code via a crafted url to the delete a feature functionality.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260704T221450Z/items/CVE-2023-25309.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: fetlife / rollout-ui",
      "source_published_impact": "Source describes code execution review · XSS risk. Possible impact: An attacker may be able to run code or commands on affected systems.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Cross Site Scripting (XSS) Vulnerability in Fetlife rollout-ui version 0.5, allows attackers to execute arbitrary code via a crafted url to the delete a feature functionality.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2023-25309/timeline.json",
      "vendor": "fetlife"
    },
    {
      "affected_label": "prometheus / blackbox_exporter",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2023-26735/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.568,
      "epss_score": 0.00946,
      "first_observed_at": "2026-07-04T22:14:25.791334+00:00",
      "id": "CVE-2023-26735",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-04T22:14:25.791334+00:00",
      "latest_item_url": null,
      "product": "blackbox_exporter",
      "public_safe_summary": "NVD: blackbox_exporter v0.23.0 was discovered to contain an access control issue in its probe interface. NVD: This vulnerability allows attackers to detect intranet ports and services, as well as download resources. NVD: NOTE: this is disputed by third parties because authentication can be configured.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260704T221450Z/items/CVE-2023-26735.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: prometheus / blackbox_exporter; affected version context: 0.23.0",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: blackbox_exporter v0.23.0 was discovered to contain an access control issue in its probe interface. NVD: This vulnerability allows attackers to detect intranet ports and services, as well as download resources. NVD: NOTE: this is disputed by third parties because authentication can be configured.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2023-26735/timeline.json",
      "vendor": "prometheus"
    },
    {
      "affected_label": "apache / apache-airflow-providers-cncf-kubernetes",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2023-33234/",
      "current_public_safe_latest": false,
      "cvss_score": 7.2,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.71712,
      "epss_score": 0.01531,
      "first_observed_at": "2026-07-03T13:33:04.036864+00:00",
      "id": "CVE-2023-33234",
      "impact_tags": [
        "code execution review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-04T22:14:25.791334+00:00",
      "latest_item_url": null,
      "product": "apache-airflow-providers-cncf-kubernetes",
      "public_safe_summary": "NVD: Arbitrary code execution in Apache Airflow CNCF Kubernetes provider version 5.0.0 allows user to change xcom sidecar image and resources via Airflow connection. NVD: In order to exploit this weakness, a user would already need elevated permissions (Op or Admin) to change the connection object in this manner. NVD: Operators should upgrade to provider version 7.0.0 which has removed the vulnerability.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260704T221450Z/items/CVE-2023-33234.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 11,
      "source_published_affected": "vendor/product: apache / apache-airflow-providers-cncf-kubernetes",
      "source_published_impact": "Source describes code execution review. Possible impact: An attacker may be able to run code or commands on affected systems.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: provider.",
      "source_published_summary": "NVD: Arbitrary code execution in Apache Airflow CNCF Kubernetes provider version 5.0.0 allows user to change xcom sidecar image and resources via Airflow connection. NVD: In order to exploit this weakness, a user would already need elevated permissions (Op or Admin) to change the connection object in this manner. NVD: Operators should upgrade to provider version 7.0.0 which has removed the vulnerability.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2023-33234/timeline.json",
      "vendor": "apache"
    },
    {
      "affected_label": "oretnom23 / lost_and_found_information_system",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2023-33677/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.32399,
      "epss_score": 0.00404,
      "first_observed_at": "2026-07-04T22:14:25.791334+00:00",
      "id": "CVE-2023-33677",
      "impact_tags": [
        "SQL injection risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-04T22:14:25.791334+00:00",
      "latest_item_url": null,
      "product": "lost_and_found_information_system",
      "public_safe_summary": "NVD: Sourcecodester Lost and Found Information System's Version 1.0 is vulnerable to unauthenticated SQL Injection at \"?page=items/view&id=*\".",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260704T221450Z/items/CVE-2023-33677.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: oretnom23 / lost_and_found_information_system; affected version context: 1.0",
      "source_published_impact": "Source describes SQL injection risk. Possible impact: An attacker may be able to read or change database-backed application data.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Sourcecodester Lost and Found Information System's Version 1.0 is vulnerable to unauthenticated SQL Injection at \"?page=items/view&id=*\".",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2023-33677/timeline.json",
      "vendor": "oretnom23"
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2023-37507/",
      "current_public_safe_latest": false,
      "cvss_score": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.16743,
      "epss_score": 0.00253,
      "first_observed_at": "2026-07-28T06:05:50.269125+00:00",
      "id": "CVE-2023-37507",
      "impact_tags": [
        "information exposure review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-28T06:05:50.269125+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: HCL DevOps Plan is susceptible to an information disclosure that can allow an attacker to focus their attacks based upon the information revealed.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260728T060840Z/items/CVE-2023-37507.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes information exposure review. Possible impact: An attacker may be able to access information that should not be exposed.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: HCL DevOps Plan is susceptible to an information disclosure that can allow an attacker to focus their attacks based upon the information revealed.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2023-37507/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "milesight / ur5x_firmware",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2023-43261/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.99023,
      "epss_score": 0.60113,
      "first_observed_at": "2026-07-04T22:14:25.791334+00:00",
      "id": "CVE-2023-43261",
      "impact_tags": [
        "information exposure review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-04T22:14:25.791334+00:00",
      "latest_item_url": null,
      "product": "ur5x_firmware",
      "public_safe_summary": "NVD: An information disclosure in Milesight UR5X, UR32L, UR32, UR35, UR41 before v35.3.0.7 allows attackers to access sensitive router components.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260704T221450Z/items/CVE-2023-43261.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: milesight / ur5x_firmware; affected version context: -",
      "source_published_impact": "Source describes information exposure review. Possible impact: An attacker may be able to access information that should not be exposed.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: An information disclosure in Milesight UR5X, UR32L, UR32, UR35, UR41 before v35.3.0.7 allows attackers to access sensitive router components.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2023-43261/timeline.json",
      "vendor": "milesight"
    },
    {
      "affected_label": "apache / airflow",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2023-51702/",
      "current_public_safe_latest": false,
      "cvss_score": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.30108,
      "epss_score": 0.00381,
      "first_observed_at": "2026-07-03T13:33:04.036864+00:00",
      "id": "CVE-2023-51702",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-04T22:14:25.791334+00:00",
      "latest_item_url": null,
      "product": "airflow",
      "public_safe_summary": "NVD: Since version 5.2.0, when using deferrable mode with the path of a Kubernetes configuration file for authentication, the Airflow worker serializes this configuration file as a dictionary and sends it to the triggerer by storing it in metadata without any... NVD: Additionally, if used with an Airflow version between 2.3.0 and 2.6.0, the configuration dictionary will be logged as plain text in the triggerer service without masking. NVD: This allows anyone with access to the metadata or triggerer log to obtain the configuration file and use it to access the Kubernetes cluster.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260704T221450Z/items/CVE-2023-51702.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 11,
      "source_published_affected": "vendor/product: apache / airflow",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: Since version 5.2.0, when using deferrable mode with the path of a Kubernetes configuration file for authentication, the Airflow worker serializes this configuration file as a dictionary and sends it to the triggerer by storing it in metadata without any... NVD: Additionally, if used with an Airflow version between 2.3.0 and 2.6.0, the configuration dictionary will be logged as plain text in the triggerer service without masking. NVD: This allows anyone with access to the metadata or triggerer log to obtain the configuration file and use it to access the Kubernetes cluster.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2023-51702/timeline.json",
      "vendor": "apache"
    },
    {
      "affected_label": "jfree / jfreechart",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2023-52070/",
      "current_public_safe_latest": false,
      "cvss_score": 8.4,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.16555,
      "epss_score": 0.00253,
      "first_observed_at": "2026-07-04T22:14:25.791334+00:00",
      "id": "CVE-2023-52070",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-04T22:14:25.791334+00:00",
      "latest_item_url": null,
      "product": "jfreechart",
      "public_safe_summary": "NVD: JFreeChart v1.5.4 was discovered to be vulnerable to ArrayIndexOutOfBounds via the 'setSeriesNeedle(int index, int type)' method. NVD: NOTE: this is disputed by multiple third parties who believe there was not reasonable evidence to determine the existence of a vulnerability. NVD: The submission may have been based on a tool that is not sufficiently robust for vulnerability identification.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260704T221450Z/items/CVE-2023-52070.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: jfree / jfreechart; affected version context: 1.5.4",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: JFreeChart v1.5.4 was discovered to be vulnerable to ArrayIndexOutOfBounds via the 'setSeriesNeedle(int index, int type)' method. NVD: NOTE: this is disputed by multiple third parties who believe there was not reasonable evidence to determine the existence of a vulnerability. NVD: The submission may have been based on a tool that is not sufficiently robust for vulnerability identification.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2023-52070/timeline.json",
      "vendor": "jfree"
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2023-54366/",
      "current_public_safe_latest": false,
      "cvss_score": 8.7,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.1989,
      "epss_score": 0.00277,
      "first_observed_at": "2026-07-25T10:46:49.898242+00:00",
      "id": "CVE-2023-54366",
      "impact_tags": [
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-25T10:46:49.898242+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: SurrealDB before 1.0.1 sets default table permissions to FULL instead of NONE, allowing SELECT, CREATE, UPDATE, and DELETE operations on tables without explicit permissions. NVD: Attackers with database access or unauthenticated users on publicly exposed instances can perform unrestricted operations on unprotected tables within their authorization scope. OSV: SurrealDB before 1.0.1 Insecure Default Table Permissions",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260725T104916Z/items/CVE-2023-54366.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes authenticated boundary. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: SurrealDB before 1.0.1 sets default table permissions to FULL instead of NONE, allowing SELECT, CREATE, UPDATE, and DELETE operations on tables without explicit permissions. NVD: Attackers with database access or unauthenticated users on publicly exposed instances can perform unrestricted operations on unprotected tables within their authorization scope. OSV: SurrealDB before 1.0.1 Insecure Default Table Permissions",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2023-54366/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "wso2 / api_manager",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2024-1248/",
      "current_public_safe_latest": false,
      "cvss_score": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.08869,
      "epss_score": 0.00191,
      "first_observed_at": "2026-07-11T16:12:59.014043+00:00",
      "id": "CVE-2024-1248",
      "impact_tags": [
        "local exposure relevant"
      ],
      "kev": false,
      "last_observed_at": "2026-07-11T16:12:59.014043+00:00",
      "latest_item_url": null,
      "product": "api_manager",
      "public_safe_summary": "NVD: The silent Just-In-Time (JIT) provisioning feature in federated authentication implementations fails to properly segregate user roles during account creation when a federated user shares a username with a local user. NVD: This allows the provisioning process to overwrite existing roles of local users with roles assigned to the federated user. NVD: Exploitation requires a federated identity provider (IDP) with silent JIT provisioning enabled and an attacker's knowledge of a local user's username.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260711T161447Z/items/CVE-2024-1248.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: wso2 / api_manager",
      "source_published_impact": "Source describes local exposure. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for local exposure.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The silent Just-In-Time (JIT) provisioning feature in federated authentication implementations fails to properly segregate user roles during account creation when a federated user shares a username with a local user. NVD: This allows the provisioning process to overwrite existing roles of local users with roles assigned to the federated user. NVD: Exploitation requires a federated identity provider (IDP) with silent JIT provisioning enabled and an attacker's knowledge of a local user's username.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2024-1248/timeline.json",
      "vendor": "wso2"
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2024-14040/",
      "current_public_safe_latest": false,
      "cvss_score": 7.8,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.01507,
      "epss_score": 0.0011,
      "first_observed_at": "2026-08-01T10:51:40.555213+00:00",
      "id": "CVE-2024-14040",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-02T06:14:57.521051+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: In the Linux kernel, the following vulnerability has been resolved: net: nexthop: Increase weight to u16 In CLOS networks, as link failures occur at various points in the network, ECMP weights of the involved nodes are adjusted to compensate. NVD: With high fan-out of the involved nodes, and overall high number of nodes, a (non-)ECMP weight ratio that we would like to configure does not fit into 8 bits. NVD: Instead of, say, 255:254, we might like to configure something like 1000:999.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260802T061806Z/items/CVE-2024-14040.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 4,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: In the Linux kernel, the following vulnerability has been resolved: net: nexthop: Increase weight to u16 In CLOS networks, as link failures occur at various points in the network, ECMP weights of the involved nodes are adjusted to compensate. NVD: With high fan-out of the involved nodes, and overall high number of nodes, a (non-)ECMP weight ratio that we would like to configure does not fit into 8 bits. NVD: Instead of, say, 255:254, we might like to configure something like 1000:999.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2024-14040/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2024-14041/",
      "current_public_safe_latest": false,
      "cvss_score": 8.2,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.19701,
      "epss_score": 0.00275,
      "first_observed_at": "2026-08-04T06:07:04.591309+00:00",
      "id": "CVE-2024-14041",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-04T06:07:04.591309+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: In Bouncy Castle for Java from 1.73 to before 1.78, three ML-KEM (CRYSTALS-Kyber) routines divided secret-derived polynomial coefficients by the modulus q: Poly.toMsg, which decodes the decrypted message, and the ciphertext compression routines... NVD: An attacker able to measure the timing of a large number of decapsulations performed with the same long-term private key can recover that key. NVD: These are the KyberSlash1 (Poly.toMsg) and KyberSlash2 (ciphertext compression) divisions.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260804T061658Z/items/CVE-2024-14041.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: In Bouncy Castle for Java from 1.73 to before 1.78, three ML-KEM (CRYSTALS-Kyber) routines divided secret-derived polynomial coefficients by the modulus q: Poly.toMsg, which decodes the decrypted message, and the ciphertext compression routines... NVD: An attacker able to measure the timing of a large number of decapsulations performed with the same long-term private key can recover that key. NVD: These are the KyberSlash1 (Poly.toMsg) and KyberSlash2 (ciphertext compression) divisions.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2024-14041/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "forkhq / network",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2024-21488/",
      "current_public_safe_latest": false,
      "cvss_score": 7.3,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.86756,
      "epss_score": 0.03235,
      "first_observed_at": "2026-07-04T16:20:49.617073+00:00",
      "id": "CVE-2024-21488",
      "impact_tags": [
        "command injection risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-04T22:14:25.791334+00:00",
      "latest_item_url": null,
      "product": "network",
      "public_safe_summary": "NVD: Versions of the package network before 0.7.0 are vulnerable to Arbitrary Command Injection due to use of the child_process exec function without input sanitization. NVD: If (attacker-controlled) user input is given to the mac_address_for function of the package, it is possible for the attacker to execute arbitrary commands on the operating system that this package is being run on. OSV: Versions of the package network before 0.7.0 are vulnerable to Arbitrary Command Injection due to use of the child_process exec function without input sanitization.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260704T221450Z/items/CVE-2024-21488.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "vendor/product: forkhq / network",
      "source_published_impact": "Source describes command injection risk. Possible impact: An attacker may be able to run unintended system commands through the affected component.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Versions of the package network before 0.7.0 are vulnerable to Arbitrary Command Injection due to use of the child_process exec function without input sanitization. NVD: If (attacker-controlled) user input is given to the mac_address_for function of the package, it is possible for the attacker to execute arbitrary commands on the operating system that this package is being run on. OSV: Versions of the package network before 0.7.0 are vulnerable to Arbitrary Command Injection due to use of the child_process exec function without input sanitization.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2024-21488/timeline.json",
      "vendor": "forkhq"
    },
    {
      "affected_label": "angularjs / angular.js",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2024-21490/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.77067,
      "epss_score": 0.01891,
      "first_observed_at": "2026-07-03T13:33:04.036864+00:00",
      "id": "CVE-2024-21490",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-04T22:14:25.791334+00:00",
      "latest_item_url": null,
      "product": "angular.js",
      "public_safe_summary": "NVD: This affects versions of the package angular from 1.3.0; versions of the package angularjs from 1.3.0. NVD: A regular expression used to split the value of the ng-srcset directive is vulnerable to super-linear runtime due to backtracking. NVD: With large carefully-crafted input, this can result in catastrophic backtracking and cause a denial of service.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260704T221450Z/items/CVE-2024-21490.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 11,
      "source_published_affected": "vendor/product: angularjs / angular.js",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: This affects versions of the package angular from 1.3.0; versions of the package angularjs from 1.3.0. NVD: A regular expression used to split the value of the ng-srcset directive is vulnerable to super-linear runtime due to backtracking. NVD: With large carefully-crafted input, this can result in catastrophic backtracking and cause a denial of service.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2024-21490/timeline.json",
      "vendor": "angularjs"
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2024-21527/",
      "current_public_safe_latest": false,
      "cvss_score": 7.8,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.43195,
      "epss_score": 0.00574,
      "first_observed_at": "2026-07-03T13:33:04.036864+00:00",
      "id": "CVE-2024-21527",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-04T22:14:25.791334+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Versions of the package github.com/gotenberg/gotenberg/v8/pkg/gotenberg before 8.1.0; versions of the package github.com/gotenberg/gotenberg/v8/pkg/modules/chromium before 8.1.0; versions of the package github.com/gotenberg/gotenberg/v8/pkg/modules/webhook... NVD: By exploiting this vulnerability, an attacker can achieve local file inclusion, allowing of sensitive files read on the host system. NVD: Workaround An alternative is using either or both --chromium-deny-list and --chromium-allow-list flags.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260704T221450Z/items/CVE-2024-21527.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 11,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Versions of the package github.com/gotenberg/gotenberg/v8/pkg/gotenberg before 8.1.0; versions of the package github.com/gotenberg/gotenberg/v8/pkg/modules/chromium before 8.1.0; versions of the package github.com/gotenberg/gotenberg/v8/pkg/modules/webhook... NVD: By exploiting this vulnerability, an attacker can achieve local file inclusion, allowing of sensitive files read on the host system. NVD: Workaround An alternative is using either or both --chromium-deny-list and --chromium-allow-list flags.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2024-21527/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "linuxfoundation / runc",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2024-21626/",
      "current_public_safe_latest": false,
      "cvss_score": 8.6,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.96843,
      "epss_score": 0.18087,
      "first_observed_at": "2026-07-03T13:33:04.036864+00:00",
      "id": "CVE-2024-21626",
      "impact_tags": [
        "privilege boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-04T22:14:25.791334+00:00",
      "latest_item_url": null,
      "product": "runc",
      "public_safe_summary": "NVD: runc is a CLI tool for spawning and running containers on Linux according to the OCI specification. NVD: In runc 1.1.11 and earlier, due to an internal file descriptor leak, an attacker could cause a newly-spawned container process (from runc exec) to have a working directory in the host filesystem namespace, allowing for a container escape by giving access to... NVD: The same attack could be used by a malicious image to allow a container process to gain access to the host filesystem through runc run (\"attack 1\").",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260704T221450Z/items/CVE-2024-21626.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 11,
      "source_published_affected": "vendor/product: linuxfoundation / runc; affected version context: 39",
      "source_published_impact": "Source describes privilege escalation risk. Possible impact: An attacker may cross a privilege boundary and gain more access than intended.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: runc is a CLI tool for spawning and running containers on Linux according to the OCI specification. NVD: In runc 1.1.11 and earlier, due to an internal file descriptor leak, an attacker could cause a newly-spawned container process (from runc exec) to have a working directory in the host filesystem namespace, allowing for a container escape by giving access to... NVD: The same attack could be used by a malicious image to allow a container process to gain access to the host filesystem through runc run (\"attack 1\").",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2024-21626/timeline.json",
      "vendor": "linuxfoundation"
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2024-22257/",
      "current_public_safe_latest": false,
      "cvss_score": 8.2,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.56859,
      "epss_score": 0.00948,
      "first_observed_at": "2026-07-03T13:33:04.036864+00:00",
      "id": "CVE-2024-22257",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-04T22:14:25.791334+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: In Spring Security, versions 5.7.x prior to 5.7.12, 5.8.x prior to 5.8.11, versions 6.0.x prior to 6.0.9, versions 6.1.x prior to 6.1.8, versions 6.2.x prior to 6.2.3, an application is possible vulnerable to broken access control when it directly uses the...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260704T221450Z/items/CVE-2024-22257.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 11,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: In Spring Security, versions 5.7.x prior to 5.7.12, 5.8.x prior to 5.8.11, versions 6.0.x prior to 6.0.9, versions 6.1.x prior to 6.1.8, versions 6.2.x prior to 6.2.3, an application is possible vulnerable to broken access control when it directly uses the...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2024-22257/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2024-23564/",
      "current_public_safe_latest": false,
      "cvss_score": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.08674,
      "epss_score": 0.00188,
      "first_observed_at": "2026-07-24T11:14:35.780564+00:00",
      "id": "CVE-2024-23564",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-24T11:14:35.780564+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: HCL Aftermarket EPC is affected by Business Logic Vulnerability using which a non valid user of the application can obtain passwords from the server and redirect them to their own email address by manipulating the server's response. NVD: The application includes checks in the initial requests to verify the validity of the provided UserId, but similar validation is not applied to Email requests when sending passwords to user emails.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260724T111724Z/items/CVE-2024-23564.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: HCL Aftermarket EPC is affected by Business Logic Vulnerability using which a non valid user of the application can obtain passwords from the server and redirect them to their own email address by manipulating the server's response. NVD: The application includes checks in the initial requests to verify the validity of the provided UserId, but similar validation is not applied to Email requests when sending passwords to user emails.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2024-23564/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2024-23565/",
      "current_public_safe_latest": false,
      "cvss_score": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.14861,
      "epss_score": 0.00238,
      "first_observed_at": "2026-07-24T11:14:35.780564+00:00",
      "id": "CVE-2024-23565",
      "impact_tags": [
        "service availability review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-24T11:14:35.780564+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: HCL Aftermarket EPC is vulnerable to email flooding as the application does not have a proper mail limitation mechanism at Forget Password functionality. NVD: The actor could b e a human or an automated process such as a virus or bot. NVD: This could be used to cause a denial of service, compromise program logic or other consequences.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260724T111724Z/items/CVE-2024-23565.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes service availability risk. Possible impact: The affected service may become unavailable or unreliable.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: HCL Aftermarket EPC is vulnerable to email flooding as the application does not have a proper mail limitation mechanism at Forget Password functionality. NVD: The actor could b e a human or an automated process such as a virus or bot. NVD: This could be used to cause a denial of service, compromise program logic or other consequences.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2024-23565/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2024-23566/",
      "current_public_safe_latest": false,
      "cvss_score": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.05517,
      "epss_score": 0.00159,
      "first_observed_at": "2026-07-24T11:14:35.780564+00:00",
      "id": "CVE-2024-23566",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-24T11:14:35.780564+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: HCL Aftermarket EPC is vulnerable to brute force attacks since application doesn’t have captcha implemented. NVD: It can lead to various security issues like brute force , automated attacks & account enumeration",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260724T111724Z/items/CVE-2024-23566.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: HCL Aftermarket EPC is vulnerable to brute force attacks since application doesn’t have captcha implemented. NVD: It can lead to various security issues like brute force , automated attacks & account enumeration",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2024-23566/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2024-23567/",
      "current_public_safe_latest": false,
      "cvss_score": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.078,
      "epss_score": 0.0018,
      "first_observed_at": "2026-07-24T11:14:35.780564+00:00",
      "id": "CVE-2024-23567",
      "impact_tags": [
        "information exposure review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-24T11:14:35.780564+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: HCL Aftermarket EPC is affected by Sensitive Information in GET method & in URL which allows application to pass sensitive data via URL parameters during normal usage. NVD: Data passed in this manner can be exposed because it may end up stored in unintended locations, including server logs, local browser history and proxy logs.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260724T111724Z/items/CVE-2024-23567.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes information exposure review. Possible impact: An attacker may be able to access information that should not be exposed.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: HCL Aftermarket EPC is affected by Sensitive Information in GET method & in URL which allows application to pass sensitive data via URL parameters during normal usage. NVD: Data passed in this manner can be exposed because it may end up stored in unintended locations, including server logs, local browser history and proxy logs.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2024-23567/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2024-23568/",
      "current_public_safe_latest": false,
      "cvss_score": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.14861,
      "epss_score": 0.00238,
      "first_observed_at": "2026-07-24T11:14:35.780564+00:00",
      "id": "CVE-2024-23568",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-24T11:14:35.780564+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: HCL Aftermarket EPC is vulnerable to attacks since the server software version used by the application is revealed by the web server. NVD: Displaying version information of software could allow an attacker to determine which vulnerabilities are present in the software, particularly if an outdated software version is in use with published vulnerabilities.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260724T111724Z/items/CVE-2024-23568.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: HCL Aftermarket EPC is vulnerable to attacks since the server software version used by the application is revealed by the web server. NVD: Displaying version information of software could allow an attacker to determine which vulnerabilities are present in the software, particularly if an outdated software version is in use with published vulnerabilities.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2024-23568/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2024-23569/",
      "current_public_safe_latest": false,
      "cvss_score": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.07167,
      "epss_score": 0.00175,
      "first_observed_at": "2026-07-24T11:14:35.780564+00:00",
      "id": "CVE-2024-23569",
      "impact_tags": [
        "XSS risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-24T11:14:35.780564+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: HCL Aftermarket EPC is vulnerable to attack since the server is not configured with “X-XSS-Protection\" header",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260724T111724Z/items/CVE-2024-23569.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes XSS risk. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: HCL Aftermarket EPC is vulnerable to attack since the server is not configured with “X-XSS-Protection\" header",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2024-23569/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2024-28835/",
      "current_public_safe_latest": false,
      "cvss_score": 5.0,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.30569,
      "epss_score": 0.00386,
      "first_observed_at": "2026-07-03T13:33:04.036864+00:00",
      "id": "CVE-2024-28835",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-04T22:14:25.791334+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A flaw has been discovered in GnuTLS where an application crash can be induced when attempting to verify a specially crafted .pem bundle using the \"certtool --verify-chain\" command. OSV: A flaw has been discovered in GnuTLS where an application crash can be induced when attempting to verify a specially crafted .pem bundle using the \"certtool --verify-chain\" command.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260704T221450Z/items/CVE-2024-28835.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 11,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A flaw has been discovered in GnuTLS where an application crash can be induced when attempting to verify a specially crafted .pem bundle using the \"certtool --verify-chain\" command. OSV: A flaw has been discovered in GnuTLS where an application crash can be induced when attempting to verify a specially crafted .pem bundle using the \"certtool --verify-chain\" command.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2024-28835/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2024-3727/",
      "current_public_safe_latest": false,
      "cvss_score": 8.3,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.66483,
      "epss_score": 0.01279,
      "first_observed_at": "2026-07-03T13:33:04.036864+00:00",
      "id": "CVE-2024-3727",
      "impact_tags": [
        "path traversal review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-04T22:14:25.791334+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A flaw was found in the github.com/containers/image library. NVD: This flaw allows attackers to trigger unexpected authenticated registry accesses on behalf of a victim user, causing resource exhaustion, local path traversal, and other attacks. OSV: A flaw was found in the github.com/containers/image library.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260704T221450Z/items/CVE-2024-3727.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 11,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes path traversal review. Possible impact: An attacker may be able to reach files outside the intended application path.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A flaw was found in the github.com/containers/image library. NVD: This flaw allows attackers to trigger unexpected authenticated registry accesses on behalf of a victim user, causing resource exhaustion, local path traversal, and other attacks. OSV: A flaw was found in the github.com/containers/image library.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2024-3727/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "redhat / enterprise_linux",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2024-45615/",
      "current_public_safe_latest": false,
      "cvss_score": 3.9,
      "cvss_severity": "LOW",
      "epss_percentile": 0.27524,
      "epss_score": 0.00355,
      "first_observed_at": "2026-07-03T15:20:18.249701+00:00",
      "id": "CVE-2024-45615",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-04T16:20:49.617073+00:00",
      "latest_item_url": null,
      "product": "enterprise_linux",
      "public_safe_summary": "NVD: A vulnerability was found in OpenSC, OpenSC tools, PKCS#11 module, minidriver, and CTK. NVD: The problem is missing initialization of variables expected to be initialized (as arguments to other functions, etc.). OSV: A vulnerability was found in OpenSC, OpenSC tools, PKCS#11 module, minidriver, and CTK.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260704T162115Z/items/CVE-2024-45615.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 8,
      "source_published_affected": "vendor/product: redhat / enterprise_linux; affected version context: 7.0, 8.0, 9.0",
      "source_published_impact": "This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability was found in OpenSC, OpenSC tools, PKCS#11 module, minidriver, and CTK. NVD: The problem is missing initialization of variables expected to be initialized (as arguments to other functions, etc.). OSV: A vulnerability was found in OpenSC, OpenSC tools, PKCS#11 module, minidriver, and CTK.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2024-45615/timeline.json",
      "vendor": "redhat"
    },
    {
      "affected_label": "redhat / enterprise_linux",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2024-45616/",
      "current_public_safe_latest": false,
      "cvss_score": 3.9,
      "cvss_severity": "LOW",
      "epss_percentile": 0.27524,
      "epss_score": 0.00355,
      "first_observed_at": "2026-07-03T22:28:24.789613+00:00",
      "id": "CVE-2024-45616",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-04T16:20:49.617073+00:00",
      "latest_item_url": null,
      "product": "enterprise_linux",
      "public_safe_summary": "NVD: A vulnerability was found in OpenSC, OpenSC tools, PKCS#11 module, minidriver, and CTK. NVD: An attacker could use a crafted USB Device or Smart Card, which would present the system with a specially crafted response to APDUs. NVD: The following problems were caused by insufficient control of the response APDU buffer and its length when communicating with the card.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260704T162115Z/items/CVE-2024-45616.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 5,
      "source_published_affected": "vendor/product: redhat / enterprise_linux; affected version context: 7.0, 8.0, 9.0",
      "source_published_impact": "This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability was found in OpenSC, OpenSC tools, PKCS#11 module, minidriver, and CTK. NVD: An attacker could use a crafted USB Device or Smart Card, which would present the system with a specially crafted response to APDUs. NVD: The following problems were caused by insufficient control of the response APDU buffer and its length when communicating with the card.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2024-45616/timeline.json",
      "vendor": "redhat"
    },
    {
      "affected_label": "redhat / enterprise_linux",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2024-45617/",
      "current_public_safe_latest": false,
      "cvss_score": 3.9,
      "cvss_severity": "LOW",
      "epss_percentile": 0.21936,
      "epss_score": 0.00302,
      "first_observed_at": "2026-07-03T22:28:24.789613+00:00",
      "id": "CVE-2024-45617",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-04T16:20:49.617073+00:00",
      "latest_item_url": null,
      "product": "enterprise_linux",
      "public_safe_summary": "NVD: A vulnerability was found in OpenSC, OpenSC tools, PKCS#11 module, minidriver, and CTK. NVD: An attacker could use a crafted USB Device or Smart Card, which would present the system with a specially crafted response to APDUs. NVD: Insufficient or missing checking of return values of functions leads to unexpected work with variables that have not been initialized.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260704T162115Z/items/CVE-2024-45617.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 5,
      "source_published_affected": "vendor/product: redhat / enterprise_linux; affected version context: 7.0, 8.0, 9.0",
      "source_published_impact": "This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability was found in OpenSC, OpenSC tools, PKCS#11 module, minidriver, and CTK. NVD: An attacker could use a crafted USB Device or Smart Card, which would present the system with a specially crafted response to APDUs. NVD: Insufficient or missing checking of return values of functions leads to unexpected work with variables that have not been initialized.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2024-45617/timeline.json",
      "vendor": "redhat"
    },
    {
      "affected_label": "redhat / enterprise_linux",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2024-45618/",
      "current_public_safe_latest": false,
      "cvss_score": 3.9,
      "cvss_severity": "LOW",
      "epss_percentile": 0.20502,
      "epss_score": 0.00287,
      "first_observed_at": "2026-07-03T22:28:24.789613+00:00",
      "id": "CVE-2024-45618",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-04T16:20:49.617073+00:00",
      "latest_item_url": null,
      "product": "enterprise_linux",
      "public_safe_summary": "NVD: A vulnerability was found in pkcs15-init in OpenSC. NVD: An attacker could use a crafted USB Device or Smart Card, which would present the system with a specially crafted response to APDUs. NVD: Insufficient or missing checking of return values of functions leads to unexpected work with variables that have not been initialized.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260704T162115Z/items/CVE-2024-45618.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 5,
      "source_published_affected": "vendor/product: redhat / enterprise_linux; affected version context: 7.0, 8.0, 9.0",
      "source_published_impact": "This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability was found in pkcs15-init in OpenSC. NVD: An attacker could use a crafted USB Device or Smart Card, which would present the system with a specially crafted response to APDUs. NVD: Insufficient or missing checking of return values of functions leads to unexpected work with variables that have not been initialized.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2024-45618/timeline.json",
      "vendor": "redhat"
    },
    {
      "affected_label": "redhat / enterprise_linux",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2024-45619/",
      "current_public_safe_latest": false,
      "cvss_score": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.21752,
      "epss_score": 0.003,
      "first_observed_at": "2026-07-03T22:28:24.789613+00:00",
      "id": "CVE-2024-45619",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-04T11:02:09.720619+00:00",
      "latest_item_url": null,
      "product": "enterprise_linux",
      "public_safe_summary": "NVD: A vulnerability was found in OpenSC, OpenSC tools, PKCS#11 module, minidriver, and CTK. NVD: An attacker could use a crafted USB Device or Smart Card, which would present the system with a specially crafted response to APDUs. NVD: When buffers are partially filled with data, initialized parts of the buffer can be incorrectly accessed.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260704T110241Z/items/CVE-2024-45619.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 4,
      "source_published_affected": "vendor/product: redhat / enterprise_linux; affected version context: 7.0, 8.0, 9.0",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability was found in OpenSC, OpenSC tools, PKCS#11 module, minidriver, and CTK. NVD: An attacker could use a crafted USB Device or Smart Card, which would present the system with a specially crafted response to APDUs. NVD: When buffers are partially filled with data, initialized parts of the buffer can be incorrectly accessed.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2024-45619/timeline.json",
      "vendor": "redhat"
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2024-58023/",
      "current_public_safe_latest": false,
      "cvss_score": 8.4,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.002,
      "epss_score": 0.00079,
      "first_observed_at": "2026-07-30T06:01:44.452906+00:00",
      "id": "CVE-2024-58023",
      "impact_tags": [
        "information exposure review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-30T06:01:44.452906+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Information disclosure in Bosch Configuration Manager in Version 7.72.0106 allows an attacker to access sensitive information.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260730T060504Z/items/CVE-2024-58023.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes information exposure review. Possible impact: An attacker may be able to access information that should not be exposed.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Information disclosure in Bosch Configuration Manager in Version 7.72.0106 allows an attacker to access sensitive information.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2024-58023/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2024-58330/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.21337,
      "epss_score": 0.00291,
      "first_observed_at": "2026-07-30T06:01:44.452906+00:00",
      "id": "CVE-2024-58330",
      "impact_tags": [
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-30T06:01:44.452906+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A missing authentication check in Bosch IP cameras of families CPP13 and CPP14 allows an unauthenticated attacker to retrieve video analytics event data.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260730T060504Z/items/CVE-2024-58330.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes remote exposure · authenticated boundary. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A missing authentication check in Bosch IP cameras of families CPP13 and CPP14 allows an unauthenticated attacker to retrieve video analytics event data.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2024-58330/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2024-58356/",
      "current_public_safe_latest": false,
      "cvss_score": 2.3,
      "cvss_severity": "LOW",
      "epss_percentile": 0.18224,
      "epss_score": 0.00265,
      "first_observed_at": "2026-07-25T10:46:49.898242+00:00",
      "id": "CVE-2024-58356",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-25T10:46:49.898242+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: SurrealDB before 2.1.4 silently fails to overwrite table definitions when the DEFINE TABLE ... NVD: OVERWRITE clause is used on tables defined with TYPE RELATION. NVD: Because table definitions include the PERMISSIONS clause, an attempt to tighten a table's permissions via OVERWRITE does not take effect, and the administrator may incorrectly believe the change was applied.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260725T104916Z/items/CVE-2024-58356.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: SurrealDB before 2.1.4 silently fails to overwrite table definitions when the DEFINE TABLE ... NVD: OVERWRITE clause is used on tables defined with TYPE RELATION. NVD: Because table definitions include the PERMISSIONS clause, an attempt to tighten a table's permissions via OVERWRITE does not take effect, and the administrator may incorrectly believe the change was applied.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2024-58356/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2024-58357/",
      "current_public_safe_latest": false,
      "cvss_score": 7.1,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.22855,
      "epss_score": 0.00307,
      "first_observed_at": "2026-07-25T10:46:49.898242+00:00",
      "id": "CVE-2024-58357",
      "impact_tags": [
        "service availability review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-25T10:46:49.898242+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: SurrealDB versions before 2.1.0 contain an uncaught exception vulnerability in the rand::time() function that panics when unwrap is called on a None result from timestamp_opt. NVD: Authorized clients can repeatedly invoke rand::time() to reliably trigger server panics and cause denial of service. OSV: SurrealDB before 2.1.0 Denial of Service via rand::time()",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260725T104916Z/items/CVE-2024-58357.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes service availability risk. Possible impact: The affected service may become unavailable or unreliable.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: SurrealDB versions before 2.1.0 contain an uncaught exception vulnerability in the rand::time() function that panics when unwrap is called on a None result from timestamp_opt. NVD: Authorized clients can repeatedly invoke rand::time() to reliably trigger server panics and cause denial of service. OSV: SurrealDB before 2.1.0 Denial of Service via rand::time()",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2024-58357/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2024-58358/",
      "current_public_safe_latest": false,
      "cvss_score": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.25225,
      "epss_score": 0.00329,
      "first_observed_at": "2026-07-25T10:46:49.898242+00:00",
      "id": "CVE-2024-58358",
      "impact_tags": [
        "service availability review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-25T10:46:49.898242+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: SurrealDB versions before 2.1.0 contain a denial of service vulnerability in role conversion that allows privileged owner users to define users with nonexistent roles. NVD: Attackers can trigger an uncaught panic by signing in with a user assigned an invalid role, crashing the server. OSV: SurrealDB before 2.1.0 Denial of Service via Nonexistent Role",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260725T104916Z/items/CVE-2024-58358.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes service availability risk. Possible impact: The affected service may become unavailable or unreliable.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: SurrealDB versions before 2.1.0 contain a denial of service vulnerability in role conversion that allows privileged owner users to define users with nonexistent roles. NVD: Attackers can trigger an uncaught panic by signing in with a user assigned an invalid role, crashing the server. OSV: SurrealDB before 2.1.0 Denial of Service via Nonexistent Role",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2024-58358/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2024-58359/",
      "current_public_safe_latest": false,
      "cvss_score": 7.1,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.22855,
      "epss_score": 0.00307,
      "first_observed_at": "2026-07-25T10:46:49.898242+00:00",
      "id": "CVE-2024-58359",
      "impact_tags": [
        "service availability review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-25T10:46:49.898242+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: SurrealDB versions before 2.1.0 contain a denial of service vulnerability in the sorting mechanism when using ORDER BY rand() clause. NVD: Authorized clients can execute queries with ORDER BY rand() to trigger a panic in the sorting function, crashing the server. OSV: SurrealDB before 2.1.0 Denial of Service via rand() Sorting",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260725T104916Z/items/CVE-2024-58359.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes service availability risk. Possible impact: The affected service may become unavailable or unreliable.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: SurrealDB versions before 2.1.0 contain a denial of service vulnerability in the sorting mechanism when using ORDER BY rand() clause. NVD: Authorized clients can execute queries with ORDER BY rand() to trigger a panic in the sorting function, crashing the server. OSV: SurrealDB before 2.1.0 Denial of Service via rand() Sorting",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2024-58359/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2024-58360/",
      "current_public_safe_latest": false,
      "cvss_score": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.1751,
      "epss_score": 0.00259,
      "first_observed_at": "2026-07-23T11:21:51.498947+00:00",
      "id": "CVE-2024-58360",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-23T11:21:51.498947+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: stoatchat versions before 0.7.8 fail to enforce account creation restrictions including invite-only mode, email verification, captcha, and shield verification. NVD: Attackers can create unlimited accounts with unverified email addresses, increasing denial-of-service risk and compromising service integrity. OSV: stoatchat before 0.7.8 Unrestricted Account Creation",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260723T112431Z/items/CVE-2024-58360.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: stoatchat versions before 0.7.8 fail to enforce account creation restrictions including invite-only mode, email verification, captcha, and shield verification. NVD: Attackers can create unlimited accounts with unverified email addresses, increasing denial-of-service risk and compromising service integrity. OSV: stoatchat before 0.7.8 Unrestricted Account Creation",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2024-58360/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2024-58361/",
      "current_public_safe_latest": false,
      "cvss_score": 7.1,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.16293,
      "epss_score": 0.00249,
      "first_observed_at": "2026-07-25T10:46:49.898242+00:00",
      "id": "CVE-2024-58361",
      "impact_tags": [
        "service availability review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-25T10:46:49.898242+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: SurrealDB versions before 2.0.4 contain an uncaught exception handling vulnerability in the parser error rendering code when processing empty strings. NVD: Authorized clients can execute malformed queries with empty string conversions to record, duration, or datetime types that cause a panic in error rendering, crashing the server. OSV: SurrealDB before 2.0.4 Denial of Service via Parser Exception",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260725T104916Z/items/CVE-2024-58361.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes service availability risk. Possible impact: The affected service may become unavailable or unreliable.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: SurrealDB versions before 2.0.4 contain an uncaught exception handling vulnerability in the parser error rendering code when processing empty strings. NVD: Authorized clients can execute malformed queries with empty string conversions to record, duration, or datetime types that cause a panic in error rendering, crashing the server. OSV: SurrealDB before 2.0.4 Denial of Service via Parser Exception",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2024-58361/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2024-58362/",
      "current_public_safe_latest": false,
      "cvss_score": 8.7,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.29242,
      "epss_score": 0.00367,
      "first_observed_at": "2026-07-25T10:46:49.898242+00:00",
      "id": "CVE-2024-58362",
      "impact_tags": [
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-25T10:46:49.898242+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: SurrealDB before 1.5.5 (and 2.0.0-beta before 2.0.0-beta.3) accepts an arbitrary object in the signin and signup operations of the RPC API without recursively validating it for non-computed values. NVD: When a record access method defines a SIGNIN or SIGNUP query and the RPC API is exposed to untrusted users, an unauthenticated attacker can encode a binary object containing a subquery using the bincode serialization format and supply it in place of... NVD: The subquery is then executed within the database owner's SIGNIN/SIGNUP query under a system user session with the editor role, allowing the attacker to select, create, update, and delete non-IAM resources (though not view the query results directly, and not...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260725T104916Z/items/CVE-2024-58362.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes remote exposure · authenticated boundary. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: SurrealDB before 1.5.5 (and 2.0.0-beta before 2.0.0-beta.3) accepts an arbitrary object in the signin and signup operations of the RPC API without recursively validating it for non-computed values. NVD: When a record access method defines a SIGNIN or SIGNUP query and the RPC API is exposed to untrusted users, an unauthenticated attacker can encode a binary object containing a subquery using the bincode serialization format and supply it in place of... NVD: The subquery is then executed within the database owner's SIGNIN/SIGNUP query under a system user session with the editor role, allowing the attacker to select, create, update, and delete non-IAM resources (though not view the query results directly, and not...",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2024-58362/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2024-58363/",
      "current_public_safe_latest": false,
      "cvss_score": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.09355,
      "epss_score": 0.00194,
      "first_observed_at": "2026-07-25T10:46:49.898242+00:00",
      "id": "CVE-2024-58363",
      "impact_tags": [
        "authentication boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-25T10:46:49.898242+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: SurrealDB before 1.5.4 fails to properly validate authentication when a scope user switches databases using the USE clause or use method. NVD: Attackers with an authenticated session can impersonate an unrelated user in a different database if a user record with an identical identifier exists, allowing unauthorized actions if permissions rely solely on the $auth parameter. OSV: SurrealDB before 1.5.4 Authentication Bypass via Database Switch",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260725T104916Z/items/CVE-2024-58363.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes authentication boundary review. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authentication boundary review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: SurrealDB before 1.5.4 fails to properly validate authentication when a scope user switches databases using the USE clause or use method. NVD: Attackers with an authenticated session can impersonate an unrelated user in a different database if a user record with an identical identifier exists, allowing unauthorized actions if permissions rely solely on the $auth parameter. OSV: SurrealDB before 1.5.4 Authentication Bypass via Database Switch",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2024-58363/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2024-58364/",
      "current_public_safe_latest": false,
      "cvss_score": 7.1,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.16291,
      "epss_score": 0.00249,
      "first_observed_at": "2026-07-25T10:46:49.898242+00:00",
      "id": "CVE-2024-58364",
      "impact_tags": [
        "service availability review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-25T10:46:49.898242+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: SurrealDB versions before 1.2.1 contain an uncaught exception handling vulnerability in span rendering when parsing queries with errors on line terminator characters. NVD: Authorized clients can submit malformed queries that trigger a panic in the span rendering code, crashing the server and causing denial of service. OSV: SurrealDB before 1.2.1 Denial of Service via Parsing Error",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260725T104916Z/items/CVE-2024-58364.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes service availability risk. Possible impact: The affected service may become unavailable or unreliable.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: SurrealDB versions before 1.2.1 contain an uncaught exception handling vulnerability in span rendering when parsing queries with errors on line terminator characters. NVD: Authorized clients can submit malformed queries that trigger a panic in the span rendering code, crashing the server and causing denial of service. OSV: SurrealDB before 1.2.1 Denial of Service via Parsing Error",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2024-58364/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2024-58365/",
      "current_public_safe_latest": false,
      "cvss_score": 7.1,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.16294,
      "epss_score": 0.00249,
      "first_observed_at": "2026-07-25T10:46:49.898242+00:00",
      "id": "CVE-2024-58365",
      "impact_tags": [
        "service availability review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-25T10:46:49.898242+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: SurrealDB versions before 1.2.0 contain an uncaught exception vulnerability in the query executor when processing calls to nonexistent built-in functions. NVD: Authorized clients can craft pre-parsed queries invoking nonexistent functions to trigger a panic that crashes the server. OSV: SurrealDB before 1.2.0 Denial of Service via Nonexistent Function",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260725T104916Z/items/CVE-2024-58365.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes service availability risk. Possible impact: The affected service may become unavailable or unreliable.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: SurrealDB versions before 1.2.0 contain an uncaught exception vulnerability in the query executor when processing calls to nonexistent built-in functions. NVD: Authorized clients can craft pre-parsed queries invoking nonexistent functions to trigger a panic that crashes the server. OSV: SurrealDB before 1.2.0 Denial of Service via Nonexistent Function",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2024-58365/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2024-58366/",
      "current_public_safe_latest": false,
      "cvss_score": 9.0,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.22096,
      "epss_score": 0.00299,
      "first_observed_at": "2026-07-25T10:46:49.898242+00:00",
      "id": "CVE-2024-58366",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-25T10:46:49.898242+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: SurrealDB before 1.1.1 contains a format string vulnerability in the rquickjs Exception::throw_type function when scripting is enabled. NVD: Attackers with scripting privileges can supply format string sequences in error inputs to read arbitrary memory or execute code with SurrealDB process privileges. OSV: SurrealDB before 1.1.1 Format String via Scripting Functions",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260725T104916Z/items/CVE-2024-58366.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: SurrealDB before 1.1.1 contains a format string vulnerability in the rquickjs Exception::throw_type function when scripting is enabled. NVD: Attackers with scripting privileges can supply format string sequences in error inputs to read arbitrary memory or execute code with SurrealDB process privileges. OSV: SurrealDB before 1.1.1 Format String via Scripting Functions",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2024-58366/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2024-58367/",
      "current_public_safe_latest": false,
      "cvss_score": 7.1,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.12017,
      "epss_score": 0.00215,
      "first_observed_at": "2026-07-25T10:46:49.898242+00:00",
      "id": "CVE-2024-58367",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-25T10:46:49.898242+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: SurrealDB versions before 2.0.4 fail to properly enforce field permissions during SELECT, UPDATE, and DELETE operations, allowing authorized users to access unauthorized field values through various query techniques. NVD: Attackers can exploit SELECT VALUE operations, field aliasing, function arguments, WHERE clause filtering, RETURN BEFORE clauses, and SET clause references to leak protected field contents despite lacking SELECT permissions. OSV: SurrealDB before 2.0.4 Improper Authorization via SELECT Permissions",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260725T104916Z/items/CVE-2024-58367.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: SurrealDB versions before 2.0.4 fail to properly enforce field permissions during SELECT, UPDATE, and DELETE operations, allowing authorized users to access unauthorized field values through various query techniques. NVD: Attackers can exploit SELECT VALUE operations, field aliasing, function arguments, WHERE clause filtering, RETURN BEFORE clauses, and SET clause references to leak protected field contents despite lacking SELECT permissions. OSV: SurrealDB before 2.0.4 Improper Authorization via SELECT Permissions",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2024-58367/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2024-58368/",
      "current_public_safe_latest": false,
      "cvss_score": 8.7,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.30149,
      "epss_score": 0.00376,
      "first_observed_at": "2026-07-25T10:46:49.898242+00:00",
      "id": "CVE-2024-58368",
      "impact_tags": [
        "service availability review",
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-25T10:46:49.898242+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: SurrealDB versions before 1.1.0 fail to properly parse the ID, DB, and NS headers in HTTP REST API requests containing special characters. NVD: Unauthenticated attackers can send crafted HTTP requests with malformed header values to trigger an uncaught exception that crashes the server. OSV: SurrealDB before 1.1.0 Denial of Service via HTTP Headers",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260725T104916Z/items/CVE-2024-58368.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes service availability risk · remote exposure · authenticated boundary. Possible impact: The affected service may become unavailable or unreliable.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: SurrealDB versions before 1.1.0 fail to properly parse the ID, DB, and NS headers in HTTP REST API requests containing special characters. NVD: Unauthenticated attackers can send crafted HTTP requests with malformed header values to trigger an uncaught exception that crashes the server. OSV: SurrealDB before 1.1.0 Denial of Service via HTTP Headers",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2024-58368/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2024-6228/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.23697,
      "epss_score": 0.00318,
      "first_observed_at": "2026-07-13T06:32:51.098771+00:00",
      "id": "CVE-2024-6228",
      "impact_tags": [
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-13T06:32:51.098771+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Notifications for Forms & WordPress Actions WordPress plugin before 2.6 does not validate a user-supplied value before using it to build a server-side file inclusion path, allowing authenticated users with subscriber-level access and above to include and...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260713T063521Z/items/CVE-2024-6228.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes authenticated boundary. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Notifications for Forms & WordPress Actions WordPress plugin before 2.6 does not validate a user-supplied value before using it to build a server-side file inclusion path, allowing authenticated users with subscriber-level access and above to include and...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2024-6228/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "eclipse / jetty",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2024-7708/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.1659,
      "epss_score": 0.00252,
      "first_observed_at": "2026-07-21T06:08:28.817138+00:00",
      "id": "CVE-2024-7708",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-21T06:08:28.817138+00:00",
      "latest_item_url": null,
      "product": "jetty",
      "public_safe_summary": "NVD: For requests that have a body, but reading the body may end up in reading 0 bytes, there is a buffer leak. NVD: This is particularly the case for 100-Continue, but any request where the network is slow can leak. OSV: For requests that have a body, but reading the body may end up in reading 0 bytes, there is a buffer leak.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260721T061518Z/items/CVE-2024-7708.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: eclipse / jetty",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: For requests that have a body, but reading the body may end up in reading 0 bytes, there is a buffer leak. NVD: This is particularly the case for 100-Continue, but any request where the network is slow can leak. OSV: For requests that have a body, but reading the body may end up in reading 0 bytes, there is a buffer leak.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2024-7708/timeline.json",
      "vendor": "eclipse"
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2024-8105/",
      "current_public_safe_latest": false,
      "cvss_score": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.15026,
      "epss_score": 0.0024,
      "first_observed_at": "2026-07-03T15:20:18.249701+00:00",
      "id": "CVE-2024-8105",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-04T16:20:49.617073+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A vulnerability exists in UEFI implementations that use a hard-coded software-based Platform Key (PK). NVD: An attacker in possession of the corresponding PK private key can sign arbitrary UEFI executables or firmware components, causing them to be trusted by affected systems and potentially bypassing UEFI Secure Boot trust validation.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260704T162115Z/items/CVE-2024-8105.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 8,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability exists in UEFI implementations that use a hard-coded software-based Platform Key (PK). NVD: An attacker in possession of the corresponding PK private key can sign arbitrary UEFI executables or firmware components, causing them to be trusted by affected systems and potentially bypassing UEFI Secure Boot trust validation.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2024-8105/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2025-11977/",
      "current_public_safe_latest": false,
      "cvss_score": 6.6,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.40429,
      "epss_score": 0.00516,
      "first_observed_at": "2026-07-17T05:58:07.763993+00:00",
      "id": "CVE-2025-11977",
      "impact_tags": [
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-17T05:58:07.763993+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Happyforms – Form Builder for WordPress: Drag & Drop Contact Forms, Surveys, Payments & Multipurpose Forms plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.26.12 via the happyforms_get_form_partial()... NVD: This makes it possible for authenticated attackers, with Administrator-level access and above, to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. NVD: This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where .php file types can be uploaded and included.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260717T060336Z/items/CVE-2025-11977.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Happyforms – Form Builder for WordPress: Drag & Drop Contact Forms, Surveys, Payments & Multipurpose Forms plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.26.12 via the happyforms_get_form_partial()... NVD: This makes it possible for authenticated attackers, with Administrator-level access and above, to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. NVD: This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where .php file types can be uploaded and included.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2025-11977/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2025-12799/",
      "current_public_safe_latest": false,
      "cvss_score": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.15833,
      "epss_score": 0.00246,
      "first_observed_at": "2026-07-14T16:41:04.043226+00:00",
      "id": "CVE-2025-12799",
      "impact_tags": [
        "XSS risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-14T16:41:04.043226+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A flaw was found in Jastow. NVD: Jastow is vulnerable to Cross-Site Scripting (XSS) attack. NVD: If using a set of combined configuration to allow unescaped characters in URL with embedded Undertow and Jastow, a server might be vulnerable to improper input handling.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260714T164406Z/items/CVE-2025-12799.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes XSS risk. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A flaw was found in Jastow. NVD: Jastow is vulnerable to Cross-Site Scripting (XSS) attack. NVD: If using a set of combined configuration to allow unescaped characters in URL with embedded Undertow and Jastow, a server might be vulnerable to improper input handling.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2025-12799/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2025-13146/",
      "current_public_safe_latest": false,
      "cvss_score": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.19645,
      "epss_score": 0.00275,
      "first_observed_at": "2026-07-29T06:10:00.110927+00:00",
      "id": "CVE-2025-13146",
      "impact_tags": [
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-29T11:36:18.065267+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The The Contact Form 7 – Dynamic Text Extension plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 5.0.6. NVD: This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. NVD: This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260729T114432Z/items/CVE-2025-13146.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes remote exposure · authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: The The Contact Form 7 – Dynamic Text Extension plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 5.0.6. NVD: This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. NVD: This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2025-13146/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "wso2 / api_manager",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2025-13475/",
      "current_public_safe_latest": false,
      "cvss_score": 3.5,
      "cvss_severity": "LOW",
      "epss_percentile": 0.05361,
      "epss_score": 0.00158,
      "first_observed_at": "2026-07-11T05:56:01.167453+00:00",
      "id": "CVE-2025-13475",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-11T10:36:25.311321+00:00",
      "latest_item_url": null,
      "product": "api_manager",
      "public_safe_summary": "NVD: In multi-tenanted deployments, the application consent management mechanism fails to correctly isolate consent scopes between tenants. NVD: Consent granted by a user for a specific SaaS application within one tenant can be incorrectly applied to SaaS applications with the same name in other tenants, leading to unintended cross-tenant consent sharing. NVD: This vulnerability may result in the exposure of user data across tenants, enabling SaaS applications in different tenants to access and modify information without explicit user authorization.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260711T103806Z/items/CVE-2025-13475.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "vendor/product: wso2 / api_manager",
      "source_published_impact": "This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: In multi-tenanted deployments, the application consent management mechanism fails to correctly isolate consent scopes between tenants. NVD: Consent granted by a user for a specific SaaS application within one tenant can be incorrectly applied to SaaS applications with the same name in other tenants, leading to unintended cross-tenant consent sharing. NVD: This vulnerability may result in the exposure of user data across tenants, enabling SaaS applications in different tenants to access and modify information without explicit user authorization.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2025-13475/timeline.json",
      "vendor": "wso2"
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2025-13968/",
      "current_public_safe_latest": false,
      "cvss_score": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.10104,
      "epss_score": 0.00201,
      "first_observed_at": "2026-07-18T05:13:28.850753+00:00",
      "id": "CVE-2025-13968",
      "impact_tags": [
        "XSS risk",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-18T05:13:28.850753+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Starboard Suite Reservation Calendars plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcode attributes in the [starboard-suite-lightbox] shortcode in all versions up to, and including, 3.1.4 due to insufficient input sanitization... NVD: This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260718T051545Z/items/CVE-2025-13968.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes XSS risk · authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Starboard Suite Reservation Calendars plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcode attributes in the [starboard-suite-lightbox] shortcode in all versions up to, and including, 3.1.4 due to insufficient input sanitization... NVD: This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2025-13968/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2025-14785/",
      "current_public_safe_latest": false,
      "cvss_score": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.05171,
      "epss_score": 0.00156,
      "first_observed_at": "2026-07-15T11:03:27.604769+00:00",
      "id": "CVE-2025-14785",
      "impact_tags": [
        "XSS risk",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-15T11:03:27.604769+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Website Builder by SeedProd - Theme Builder, Landing Page Builder, Coming Soon Page, Maintenance Mode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's seedprodnestedmenuwidget shortcode in all versions up to, and... NVD: This makes it possible for authenticated attackers, with contributor level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260715T110622Z/items/CVE-2025-14785.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes XSS risk · authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Website Builder by SeedProd - Theme Builder, Landing Page Builder, Coming Soon Page, Maintenance Mode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's seedprodnestedmenuwidget shortcode in all versions up to, and... NVD: This makes it possible for authenticated attackers, with contributor level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2025-14785/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2025-15662/",
      "current_public_safe_latest": false,
      "cvss_score": 8.6,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.17766,
      "epss_score": 0.00261,
      "first_observed_at": "2026-08-01T16:16:22.294010+00:00",
      "id": "CVE-2025-15662",
      "impact_tags": [
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-03T06:40:38.700520+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Printcart Web to Print Product Designer for WooCommerce WordPress plugin before 2.5.3 does not restrict a user-supplied URL before fetching it server-side and does not enforce a valid authorization check, allowing unauthenticated attackers to read...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260803T064356Z/items/CVE-2025-15662.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 7,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes remote exposure · authenticated boundary. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Printcart Web to Print Product Designer for WooCommerce WordPress plugin before 2.5.3 does not restrict a user-supplied URL before fetching it server-side and does not enforce a valid authorization check, allowing unauthenticated attackers to read...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2025-15662/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2025-15665/",
      "current_public_safe_latest": false,
      "cvss_score": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.03182,
      "epss_score": 0.00133,
      "first_observed_at": "2026-07-21T06:08:28.817138+00:00",
      "id": "CVE-2025-15665",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-21T06:08:28.817138+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Ultimate Before After Image Slider & Gallery WordPress plugin before 4.7.1 does not escape the value of the BEAF Slider widget's shortcode field before outputting it on the front end (the value is passed through do_shortcode, which echoes non-shortcode...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260721T061518Z/items/CVE-2025-15665.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Ultimate Before After Image Slider & Gallery WordPress plugin before 4.7.1 does not escape the value of the BEAF Slider widget's shortcode field before outputting it on the front end (the value is passed through do_shortcode, which echoes non-shortcode...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2025-15665/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2025-15669/",
      "current_public_safe_latest": false,
      "cvss_score": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.06943,
      "epss_score": 0.00173,
      "first_observed_at": "2026-08-08T04:31:15.594937+00:00",
      "id": "CVE-2025-15669",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-08T04:31:15.594937+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Bit Form WordPress plugin before 3.1.4 does not sanitise one of its conversational-form display settings before rendering it on the public-facing form, allowing high-privilege users (such as administrators, who do not hold the unfiltered_html capability...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260808T043750Z/items/CVE-2025-15669.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Bit Form WordPress plugin before 3.1.4 does not sanitise one of its conversational-form display settings before rendering it on the public-facing form, allowing high-privilege users (such as administrators, who do not hold the unfiltered_html capability...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2025-15669/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2025-15672/",
      "current_public_safe_latest": false,
      "cvss_score": 8.1,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.38234,
      "epss_score": 0.0047,
      "first_observed_at": "2026-08-10T04:58:31.923491+00:00",
      "id": "CVE-2025-15672",
      "impact_tags": [
        "code execution review",
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-10T04:58:31.923491+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The ChamaWP WordPress plugin before 1.0.13 does not properly validate user input before passing it to a PHP deserialization function, allowing unauthenticated attackers to inject arbitrary PHP objects, which could lead to remote code execution when a suitable...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260810T050414Z/items/CVE-2025-15672.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes code execution review · remote exposure · authenticated boundary. Possible impact: A remote attacker may be able to run code or commands on affected systems.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The ChamaWP WordPress plugin before 1.0.13 does not properly validate user input before passing it to a PHP deserialization function, allowing unauthenticated attackers to inject arbitrary PHP objects, which could lead to remote code execution when a suitable...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2025-15672/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2025-15673/",
      "current_public_safe_latest": false,
      "cvss_score": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.27882,
      "epss_score": 0.00352,
      "first_observed_at": "2026-08-10T04:58:31.923491+00:00",
      "id": "CVE-2025-15673",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-10T04:58:31.923491+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Import and export users and customers WordPress plugin before 2.4.3 does not restrict the path of a file it reads and displays during a CSV import, allowing high-privileged users to read arbitrary files on the server.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260810T050414Z/items/CVE-2025-15673.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Import and export users and customers WordPress plugin before 2.4.3 does not restrict the path of a file it reads and displays during a CSV import, allowing high-privileged users to read arbitrary files on the server.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2025-15673/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2025-15675/",
      "current_public_safe_latest": false,
      "cvss_score": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.06942,
      "epss_score": 0.00173,
      "first_observed_at": "2026-08-08T15:50:31.311576+00:00",
      "id": "CVE-2025-15675",
      "impact_tags": [
        "XSS risk"
      ],
      "kev": false,
      "last_observed_at": "2026-08-09T04:40:09.231782+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Charitable WordPress plugin before 1.8.5.3 does not sanitise and escape one of its campaign image text fields before outputting it in an HTML attribute, allowing users with a high-privilege campaign-management role to perform Stored Cross-Site Scripting...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260809T044412Z/items/CVE-2025-15675.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 3,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes XSS risk. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Charitable WordPress plugin before 1.8.5.3 does not sanitise and escape one of its campaign image text fields before outputting it in an HTML attribute, allowing users with a high-privilege campaign-management role to perform Stored Cross-Site Scripting...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2025-15675/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2025-27462/",
      "current_public_safe_latest": false,
      "cvss_score": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.05364,
      "epss_score": 0.00158,
      "first_observed_at": "2026-07-16T13:54:14.110513+00:00",
      "id": "CVE-2025-27462",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-16T13:54:14.110513+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] The Windows PV drivers expose various facilities to userspace. NVD: Several of these have no security descriptor, and are therefore fully accessible to unprivileged users. NVD: These are: 1.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260716T135621Z/items/CVE-2025-27462.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] The Windows PV drivers expose various facilities to userspace. NVD: Several of these have no security descriptor, and are therefore fully accessible to unprivileged users. NVD: These are: 1.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2025-27462/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2025-27463/",
      "current_public_safe_latest": false,
      "cvss_score": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.05363,
      "epss_score": 0.00158,
      "first_observed_at": "2026-07-16T13:54:14.110513+00:00",
      "id": "CVE-2025-27463",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-16T13:54:14.110513+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] The Windows PV drivers expose various facilities to userspace. NVD: Several of these have no security descriptor, and are therefore fully accessible to unprivileged users. NVD: These are: 1.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260716T135621Z/items/CVE-2025-27463.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] The Windows PV drivers expose various facilities to userspace. NVD: Several of these have no security descriptor, and are therefore fully accessible to unprivileged users. NVD: These are: 1.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2025-27463/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2025-27464/",
      "current_public_safe_latest": false,
      "cvss_score": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.05363,
      "epss_score": 0.00158,
      "first_observed_at": "2026-07-16T13:54:14.110513+00:00",
      "id": "CVE-2025-27464",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-16T13:54:14.110513+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] The Windows PV drivers expose various facilities to userspace. NVD: Several of these have no security descriptor, and are therefore fully accessible to unprivileged users. NVD: These are: 1.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260716T135621Z/items/CVE-2025-27464.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] The Windows PV drivers expose various facilities to userspace. NVD: Several of these have no security descriptor, and are therefore fully accessible to unprivileged users. NVD: These are: 1.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2025-27464/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "openvpn / openvpn_access_server",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2025-3110/",
      "current_public_safe_latest": false,
      "cvss_score": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.17386,
      "epss_score": 0.00259,
      "first_observed_at": "2026-07-15T16:47:57.605966+00:00",
      "id": "CVE-2025-3110",
      "impact_tags": [
        "remote exposure relevant"
      ],
      "kev": false,
      "last_observed_at": "2026-07-15T16:47:57.605966+00:00",
      "latest_item_url": null,
      "product": "openvpn_access_server",
      "public_safe_summary": "NVD: OpenVPN Access Server 2.7.2 through 3.1.0 accepts bare line-feed sequences inside HTTP header values, allowing remote attackers to perform HTTP request smuggling when deployed behind a reverse proxy",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260715T164957Z/items/CVE-2025-3110.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: openvpn / openvpn_access_server",
      "source_published_impact": "Source describes remote exposure. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: OpenVPN Access Server 2.7.2 through 3.1.0 accepts bare line-feed sequences inside HTTP header values, allowing remote attackers to perform HTTP request smuggling when deployed behind a reverse proxy",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2025-3110/timeline.json",
      "vendor": "openvpn"
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2025-32781/",
      "current_public_safe_latest": false,
      "cvss_score": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.33938,
      "epss_score": 0.00415,
      "first_observed_at": "2026-07-22T16:52:32.770874+00:00",
      "id": "CVE-2025-32781",
      "impact_tags": [
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-22T16:52:32.770874+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Apollo is a reliable configuration management system suitable for microservice configuration management scenarios. NVD: Prior to 2.5.0, Apollo Portal does not verify application and namespace permissions when an authenticated user requests a release by ID through GET /envs/{env}/releases/{releaseId} while configView.memberOnly.envs is enabled, allowing a low-privileged Portal... NVD: This issue is fixed in version 2.5.0.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260722T165509Z/items/CVE-2025-32781.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: Apollo is a reliable configuration management system suitable for microservice configuration management scenarios. NVD: Prior to 2.5.0, Apollo Portal does not verify application and namespace permissions when an authenticated user requests a release by ID through GET /envs/{env}/releases/{releaseId} while configView.memberOnly.envs is enabled, allowing a low-privileged Portal... NVD: This issue is fixed in version 2.5.0.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2025-32781/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2025-45870/",
      "current_public_safe_latest": false,
      "cvss_score": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.28752,
      "epss_score": 0.00362,
      "first_observed_at": "2026-07-23T16:53:12.033252+00:00",
      "id": "CVE-2025-45870",
      "impact_tags": [
        "unauthorized access risk",
        "path traversal review",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-23T16:53:12.033252+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: LogicalDOC Enterprise up to and for v9.1.1 is vulnerable to Local File Inclusion (LFI) in the OnlyOfficeEditor servlet class, allowing authenticated user to exploit path traversal flaws in the fileExt parameter, enabling unauthorized access to sensitive files...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260723T171217Z/items/CVE-2025-45870.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes unauthorized access risk · path traversal review · authenticated boundary. Possible impact: An attacker may be able to reach files outside the intended application path.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: LogicalDOC Enterprise up to and for v9.1.1 is vulnerable to Local File Inclusion (LFI) in the OnlyOfficeEditor servlet class, allowing authenticated user to exploit path traversal flaws in the fileExt parameter, enabling unauthorized access to sensitive files...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2025-45870/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2025-5017/",
      "current_public_safe_latest": false,
      "cvss_score": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.17251,
      "epss_score": 0.00258,
      "first_observed_at": "2026-07-18T05:13:28.850753+00:00",
      "id": "CVE-2025-5017",
      "impact_tags": [
        "information exposure review",
        "SQL injection risk",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-18T07:15:27.585758+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Catalyst Connect Zoho CRM Client Portal plugin for WordPress is vulnerable to time-based SQL Injection via the ‘uid’ parameter in all versions up to, and including, 2.2.0 due to insufficient escaping on the user supplied parameter and lack of sufficient... NVD: This makes it possible for authenticated attackers, with Administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260718T071858Z/items/CVE-2025-5017.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 3,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes information exposure review · SQL injection risk · authenticated boundary. Possible impact: An attacker may be able to read or change database-backed application data.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Catalyst Connect Zoho CRM Client Portal plugin for WordPress is vulnerable to time-based SQL Injection via the ‘uid’ parameter in all versions up to, and including, 2.2.0 due to insufficient escaping on the user supplied parameter and lack of sufficient... NVD: This makes it possible for authenticated attackers, with Administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2025-5017/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "csa-iot / matter",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2025-56361/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.32172,
      "epss_score": 0.00398,
      "first_observed_at": "2026-07-21T22:14:32.860584+00:00",
      "id": "CVE-2025-56361",
      "impact_tags": [
        "service availability review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-21T22:14:32.860584+00:00",
      "latest_item_url": null,
      "product": "matter",
      "public_safe_summary": "NVD: A reachable assertion vulnerability exists in the Matter SDK (connectedhomeip) 1.3 thru 1.4, specifically within the Level Control cluster's server tick logic (emberAfLevelControlClusterServerTickCallback). NVD: When a MoveToLevel command is executed and followed by a conflicting write to the OperationMode attribute (in the Pump Configuration and Control cluster), an invariant check (minLevel < currentLevel) fails and causes the device to abort. NVD: This leads to a denial of service condition.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260721T221655Z/items/CVE-2025-56361.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: csa-iot / matter; affected version context: 1.3.0.0, 1.4.0.0",
      "source_published_impact": "Source describes service availability risk. Possible impact: The affected service may become unavailable or unreliable.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A reachable assertion vulnerability exists in the Matter SDK (connectedhomeip) 1.3 thru 1.4, specifically within the Level Control cluster's server tick logic (emberAfLevelControlClusterServerTickCallback). NVD: When a MoveToLevel command is executed and followed by a conflicting write to the OperationMode attribute (in the Pump Configuration and Control cluster), an invariant check (minLevel < currentLevel) fails and causes the device to abort. NVD: This leads to a denial of service condition.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2025-56361/timeline.json",
      "vendor": "csa-iot"
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2025-58902/",
      "current_public_safe_latest": false,
      "cvss_score": 8.1,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.20052,
      "epss_score": 0.00282,
      "first_observed_at": "2026-07-09T11:52:04.215901+00:00",
      "id": "CVE-2025-58902",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-09T11:52:04.215901+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Unauthenticated Local File Inclusion in Lighthouse <= 1.2.12 versions.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260709T115259Z/items/CVE-2025-58902.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Unauthenticated Local File Inclusion in Lighthouse <= 1.2.12 versions.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2025-58902/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2025-60931/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.14112,
      "epss_score": 0.00232,
      "first_observed_at": "2026-08-05T16:55:08.588478+00:00",
      "id": "CVE-2025-60931",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-05T16:55:08.588478+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: An Insecure Direct Object Reference (IDOR) in the Employee Compensation View function of Infor Global HR v11.24.10.01.33 allows unauthorized attackers to arbitrarily view the compensation information of other employees via a crafted GET request.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260805T165944Z/items/CVE-2025-60931.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: An Insecure Direct Object Reference (IDOR) in the Employee Compensation View function of Infor Global HR v11.24.10.01.33 allows unauthorized attackers to arbitrarily view the compensation information of other employees via a crafted GET request.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2025-60931/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2025-62347/",
      "current_public_safe_latest": false,
      "cvss_score": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.08296,
      "epss_score": 0.00185,
      "first_observed_at": "2026-08-07T16:11:58.676122+00:00",
      "id": "CVE-2025-62347",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-07T16:11:58.676122+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: HCL iControl was affected by Improper Input Validation vulnerability. NVD: It is vulnerable to unexpected system behavior and potential security bypasses. NVD: This was caused by an implementation flaw in an architectural security tactic that fails to properly validate whether the received input matches the expected type.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260807T162046Z/items/CVE-2025-62347.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: HCL iControl was affected by Improper Input Validation vulnerability. NVD: It is vulnerable to unexpected system behavior and potential security bypasses. NVD: This was caused by an implementation flaw in an architectural security tactic that fails to properly validate whether the received input matches the expected type.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2025-62347/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2025-63913/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.18019,
      "epss_score": 0.00263,
      "first_observed_at": "2026-08-03T22:29:45.220405+00:00",
      "id": "CVE-2025-63913",
      "impact_tags": [
        "service availability review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-03T22:29:45.220405+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: An issue was discovered in OpenSBI 1.3 allowing attackers to cause a denial of service via crafted request to the SBI function #2 or the 'Find and configure a matching counter' function of SBI PMU extension.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260803T223322Z/items/CVE-2025-63913.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes service availability risk. Possible impact: The affected service may become unavailable or unreliable.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: An issue was discovered in OpenSBI 1.3 allowing attackers to cause a denial of service via crafted request to the SBI function #2 or the 'Find and configure a matching counter' function of SBI PMU extension.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2025-63913/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2025-66076/",
      "current_public_safe_latest": false,
      "cvss_score": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.11724,
      "epss_score": 0.00214,
      "first_observed_at": "2026-07-09T11:52:04.215901+00:00",
      "id": "CVE-2025-66076",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-09T11:52:04.215901+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Unauthenticated Broken Access Control in Woostify Sites Library <= 1.6.2 versions.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260709T115259Z/items/CVE-2025-66076.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Unauthenticated Broken Access Control in Woostify Sites Library <= 1.6.2 versions.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2025-66076/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2025-67649/",
      "current_public_safe_latest": false,
      "cvss_score": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.19459,
      "epss_score": 0.00274,
      "first_observed_at": "2026-08-07T10:13:53.604723+00:00",
      "id": "CVE-2025-67649",
      "impact_tags": [
        "SQL injection risk",
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-07T10:13:53.604723+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A SQL injection vulnerability has been identified in PHP Jabbers - Car Rental Script . NVD: Improper neutralization of input provided by user into parameters responsible for sorting functions allows an unauthenticated attacker to perform SQL Injection attacks. NVD: This issue was fixed in version 4.1.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260807T102646Z/items/CVE-2025-67649.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes SQL injection risk · remote exposure · authenticated boundary. Possible impact: A remote attacker may be able to read or change database-backed application data.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: A SQL injection vulnerability has been identified in PHP Jabbers - Car Rental Script . NVD: Improper neutralization of input provided by user into parameters responsible for sorting functions allows an unauthenticated attacker to perform SQL Injection attacks. NVD: This issue was fixed in version 4.1.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2025-67649/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2025-67650/",
      "current_public_safe_latest": false,
      "cvss_score": 8.6,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.20087,
      "epss_score": 0.00279,
      "first_observed_at": "2026-08-07T10:13:53.604723+00:00",
      "id": "CVE-2025-67650",
      "impact_tags": [
        "SQL injection risk",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-07T10:13:53.604723+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: An authenticated SQL injection vulnerability has been identified in multiple PHP Jabbers scripts. NVD: Improper neutralization of input provided by an authenticated user into parameters responsible for sorting functions allows an attacker to perform SQL Injection attacks. NVD: This issue was fixed in the versions specified in the affected products list.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260807T102646Z/items/CVE-2025-67650.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes SQL injection risk · authenticated boundary. Possible impact: An attacker may be able to read or change database-backed application data.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: the.",
      "source_published_summary": "NVD: An authenticated SQL injection vulnerability has been identified in multiple PHP Jabbers scripts. NVD: Improper neutralization of input provided by an authenticated user into parameters responsible for sorting functions allows an attacker to perform SQL Injection attacks. NVD: This issue was fixed in the versions specified in the affected products list.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2025-67650/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2025-67651/",
      "current_public_safe_latest": false,
      "cvss_score": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.06255,
      "epss_score": 0.00166,
      "first_observed_at": "2026-08-07T10:13:53.604723+00:00",
      "id": "CVE-2025-67651",
      "impact_tags": [
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-07T10:13:53.604723+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A Cross-Site Request Forgery (CSRF) vulnerability has been identified in multiple PHP Jabbers scripts. NVD: The lack of CSRF tokens or appropriate SameSite attributes allows an attacker to send unauthorized requests in the context of an authenticated user, leading to unauthorized administrative actions, such as creating new admin accounts. NVD: This issue was fixed in the versions specified in the affected products list.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260807T102646Z/items/CVE-2025-67651.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: the.",
      "source_published_summary": "NVD: A Cross-Site Request Forgery (CSRF) vulnerability has been identified in multiple PHP Jabbers scripts. NVD: The lack of CSRF tokens or appropriate SameSite attributes allows an attacker to send unauthorized requests in the context of an authenticated user, leading to unauthorized administrative actions, such as creating new admin accounts. NVD: This issue was fixed in the versions specified in the affected products list.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2025-67651/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2025-6784/",
      "current_public_safe_latest": false,
      "cvss_score": 8.8,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.38447,
      "epss_score": 0.00483,
      "first_observed_at": "2026-07-18T05:38:40.092323+00:00",
      "id": "CVE-2025-6784",
      "impact_tags": [
        "code execution review",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-18T07:15:27.585758+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Code Engine plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 0.3.5 via the 'code-engine' shortcode. NVD: This is due to the plugin not restricting access to the code injecting functionality of the plugin. NVD: This makes it possible for authenticated attackers, with Contributor-level access and above, to execute code on the server.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260718T071858Z/items/CVE-2025-6784.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes code execution review · authenticated boundary. Possible impact: An attacker may be able to run code or commands on affected systems.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Code Engine plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 0.3.5 via the 'code-engine' shortcode. NVD: This is due to the plugin not restricting access to the code injecting functionality of the plugin. NVD: This makes it possible for authenticated attackers, with Contributor-level access and above, to execute code on the server.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2025-6784/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2025-68081/",
      "current_public_safe_latest": false,
      "cvss_score": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.06868,
      "epss_score": 0.00172,
      "first_observed_at": "2026-07-30T11:23:25.389138+00:00",
      "id": "CVE-2025-68081",
      "impact_tags": [
        "XSS risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-30T11:23:25.389138+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Administrator Cross Site Scripting (XSS) in WP-Polls <= 2.77.3 versions.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260730T112643Z/items/CVE-2025-68081.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes XSS risk. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Administrator Cross Site Scripting (XSS) in WP-Polls <= 2.77.3 versions.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2025-68081/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2025-68640/",
      "current_public_safe_latest": false,
      "cvss_score": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.20578,
      "epss_score": 0.00283,
      "first_observed_at": "2026-07-28T16:54:01.667207+00:00",
      "id": "CVE-2025-68640",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-28T16:54:01.667207+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Apple Find My backend service through 2025-12-17 allows an attacker in possession of a valid PET (Private Endpoint Token) to enumerate devices and remove offline devices from an Apple ID account without triggering two-factor authentication or ownership... NVD: This may result in unauthorized removal of devices associated with the account.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260728T170314Z/items/CVE-2025-68640.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Apple Find My backend service through 2025-12-17 allows an attacker in possession of a valid PET (Private Endpoint Token) to enumerate devices and remove offline devices from an Apple ID account without triggering two-factor authentication or ownership... NVD: This may result in unauthorized removal of devices associated with the account.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2025-68640/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2025-69094/",
      "current_public_safe_latest": false,
      "cvss_score": 8.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.19574,
      "epss_score": 0.00278,
      "first_observed_at": "2026-07-09T11:52:04.215901+00:00",
      "id": "CVE-2025-69094",
      "impact_tags": [
        "SQL injection risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-09T11:52:04.215901+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Subscriber SQL Injection in Unicamp <= 2.2.2 versions.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260709T115259Z/items/CVE-2025-69094.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes SQL injection risk. Possible impact: An attacker may be able to read or change database-backed application data.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Subscriber SQL Injection in Unicamp <= 2.2.2 versions.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2025-69094/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2025-69132/",
      "current_public_safe_latest": false,
      "cvss_score": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.27591,
      "epss_score": 0.00355,
      "first_observed_at": "2026-07-09T11:52:04.215901+00:00",
      "id": "CVE-2025-69132",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-09T11:52:04.215901+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Subscriber Sensitive Data Exposure in Corpkit <= 1.0.5 versions.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260709T115259Z/items/CVE-2025-69132.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Subscriber Sensitive Data Exposure in Corpkit <= 1.0.5 versions.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2025-69132/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2025-69133/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.31992,
      "epss_score": 0.004,
      "first_observed_at": "2026-07-09T11:52:04.215901+00:00",
      "id": "CVE-2025-69133",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-09T11:52:04.215901+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Subscriber Local File Inclusion in Tourmaster <= 5.4.5 versions.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260709T115259Z/items/CVE-2025-69133.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Subscriber Local File Inclusion in Tourmaster <= 5.4.5 versions.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2025-69133/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2025-69134/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.21698,
      "epss_score": 0.003,
      "first_observed_at": "2026-07-09T11:52:04.215901+00:00",
      "id": "CVE-2025-69134",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-09T11:52:04.215901+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Unauthenticated Arbitrary Content Deletion in OpenAI Chatbot for WordPress – Helper <= 1.1.4 versions.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260709T115259Z/items/CVE-2025-69134.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Unauthenticated Arbitrary Content Deletion in OpenAI Chatbot for WordPress – Helper <= 1.1.4 versions.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2025-69134/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2025-69152/",
      "current_public_safe_latest": false,
      "cvss_score": 7.1,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.07704,
      "epss_score": 0.0018,
      "first_observed_at": "2026-07-09T11:52:04.215901+00:00",
      "id": "CVE-2025-69152",
      "impact_tags": [
        "XSS risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-09T11:52:04.215901+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Unauthenticated Cross Site Scripting (XSS) in Artale | Wedding Photography WordPress <= 2.2.2 versions.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260709T115259Z/items/CVE-2025-69152.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes XSS risk. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Unauthenticated Cross Site Scripting (XSS) in Artale | Wedding Photography WordPress <= 2.2.2 versions.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2025-69152/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2025-69153/",
      "current_public_safe_latest": false,
      "cvss_score": 7.1,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.07707,
      "epss_score": 0.0018,
      "first_observed_at": "2026-07-09T11:52:04.215901+00:00",
      "id": "CVE-2025-69153",
      "impact_tags": [
        "XSS risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-09T11:52:04.215901+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Unauthenticated Cross Site Scripting (XSS) in Trendy Travel <= 6.7 versions.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260709T115259Z/items/CVE-2025-69153.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes XSS risk. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Unauthenticated Cross Site Scripting (XSS) in Trendy Travel <= 6.7 versions.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2025-69153/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2025-69154/",
      "current_public_safe_latest": false,
      "cvss_score": 7.1,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.07712,
      "epss_score": 0.0018,
      "first_observed_at": "2026-07-09T11:52:04.215901+00:00",
      "id": "CVE-2025-69154",
      "impact_tags": [
        "XSS risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-09T11:52:04.215901+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Unauthenticated Cross Site Scripting (XSS) in SpaLab | Beauty Salon WordPress Theme <= 6.7 versions.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260709T115259Z/items/CVE-2025-69154.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes XSS risk. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Unauthenticated Cross Site Scripting (XSS) in SpaLab | Beauty Salon WordPress Theme <= 6.7 versions.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2025-69154/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2025-69155/",
      "current_public_safe_latest": false,
      "cvss_score": 7.1,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.07712,
      "epss_score": 0.0018,
      "first_observed_at": "2026-07-09T11:52:04.215901+00:00",
      "id": "CVE-2025-69155",
      "impact_tags": [
        "XSS risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-09T11:52:04.215901+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Unauthenticated Cross Site Scripting (XSS) in Fitness Zone WordPress Theme <= 5.7 versions.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260709T115259Z/items/CVE-2025-69155.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes XSS risk. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Unauthenticated Cross Site Scripting (XSS) in Fitness Zone WordPress Theme <= 5.7 versions.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2025-69155/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2025-69156/",
      "current_public_safe_latest": false,
      "cvss_score": 7.1,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.07711,
      "epss_score": 0.0018,
      "first_observed_at": "2026-07-09T11:52:04.215901+00:00",
      "id": "CVE-2025-69156",
      "impact_tags": [
        "XSS risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-09T11:52:04.215901+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Unauthenticated Cross Site Scripting (XSS) in Kids Zone - Children WordPress Theme <= 5.4 versions.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260709T115259Z/items/CVE-2025-69156.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes XSS risk. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Unauthenticated Cross Site Scripting (XSS) in Kids Zone - Children WordPress Theme <= 5.4 versions.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2025-69156/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2025-70796/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.4311,
      "epss_score": 0.00565,
      "first_observed_at": "2026-07-17T16:36:32.072333+00:00",
      "id": "CVE-2025-70796",
      "impact_tags": [
        "path traversal review",
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-17T16:36:32.072333+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: An unauthenticated path traversal vulnerability exists in the web management interface of WTI (Wireless Technology, Inc.) version 3.5.0.r 2024/05/24 00:00:00. NVD: An unauthenticated attacker can craft malicious HTTP requests containing traversal sequences to access files outside of the intended web root directory. NVD: This may allow disclosure of sensitive system files and configuration data",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260717T164048Z/items/CVE-2025-70796.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes path traversal review · remote exposure · authenticated boundary. Possible impact: A remote attacker may be able to reach files outside the intended application path.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: An unauthenticated path traversal vulnerability exists in the web management interface of WTI (Wireless Technology, Inc.) version 3.5.0.r 2024/05/24 00:00:00. NVD: An unauthenticated attacker can craft malicious HTTP requests containing traversal sequences to access files outside of the intended web root directory. NVD: This may allow disclosure of sensitive system files and configuration data",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2025-70796/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2025-71342/",
      "current_public_safe_latest": false,
      "cvss_score": 7.6,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.34478,
      "epss_score": 0.00427,
      "first_observed_at": "2026-07-10T22:27:53.208509+00:00",
      "id": "CVE-2025-71342",
      "impact_tags": [
        "code execution review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-11T02:07:59.132347+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: picklescan before 0.0.30 fails to detect malicious pickle files using idlelib.run.Executive.runcode in reduce methods. NVD: Attackers can embed undetected code in pickle files that executes during pickle.load, enabling remote code execution in PyTorch models and supply chain attacks. OSV: picklescan - Undetected Remote Code Execution via idlelib.run.Executive.runcode",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260711T020915Z/items/CVE-2025-71342.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes code execution review. Possible impact: An attacker may be able to run code or commands on affected systems.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: picklescan before 0.0.30 fails to detect malicious pickle files using idlelib.run.Executive.runcode in reduce methods. NVD: Attackers can embed undetected code in pickle files that executes during pickle.load, enabling remote code execution in PyTorch models and supply chain attacks. OSV: picklescan - Undetected Remote Code Execution via idlelib.run.Executive.runcode",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2025-71342/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2025-71343/",
      "current_public_safe_latest": false,
      "cvss_score": 7.6,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.2185,
      "epss_score": 0.003,
      "first_observed_at": "2026-07-10T22:27:53.208509+00:00",
      "id": "CVE-2025-71343",
      "impact_tags": [
        "code execution review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-11T02:07:59.132347+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: picklescan before 0.0.30 fails to detect malicious pickle files that exploit lib2to3.pgen2.pgen.ParserGenerator.make_label function in the reduce method. NVD: Attackers can craft malicious pickle files with embedded code that evades detection but executes arbitrary commands when pickle.load() is called. OSV: picklescan - Arbitrary Code Execution via lib2to3.pgen2.pgen.ParserGenerator.make_label Detection Bypass",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260711T020915Z/items/CVE-2025-71343.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes code execution review. Possible impact: An attacker may be able to run code or commands on affected systems.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: picklescan before 0.0.30 fails to detect malicious pickle files that exploit lib2to3.pgen2.pgen.ParserGenerator.make_label function in the reduce method. NVD: Attackers can craft malicious pickle files with embedded code that evades detection but executes arbitrary commands when pickle.load() is called. OSV: picklescan - Arbitrary Code Execution via lib2to3.pgen2.pgen.ParserGenerator.make_label Detection Bypass",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2025-71343/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2025-71345/",
      "current_public_safe_latest": false,
      "cvss_score": 7.6,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.34477,
      "epss_score": 0.00427,
      "first_observed_at": "2026-07-10T22:27:53.208509+00:00",
      "id": "CVE-2025-71345",
      "impact_tags": [
        "code execution review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-11T02:07:59.132347+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: picklescan before 0.0.30 fails to detect malicious pickle files that invoke torch.utils.bottleneck.__main__.run_autograd_prof function. NVD: Attackers can embed undetected code in pickle files that executes during deserialization, enabling remote code execution. OSV: picklescan - Arbitrary Code Execution via torch.utils.bottleneck.__main__.run_autograd_prof",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260711T020915Z/items/CVE-2025-71345.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes code execution review. Possible impact: An attacker may be able to run code or commands on affected systems.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: picklescan before 0.0.30 fails to detect malicious pickle files that invoke torch.utils.bottleneck.__main__.run_autograd_prof function. NVD: Attackers can embed undetected code in pickle files that executes during deserialization, enabling remote code execution. OSV: picklescan - Arbitrary Code Execution via torch.utils.bottleneck.__main__.run_autograd_prof",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2025-71345/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2025-71347/",
      "current_public_safe_latest": false,
      "cvss_score": 7.6,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.3577,
      "epss_score": 0.00445,
      "first_observed_at": "2026-07-10T22:27:53.208509+00:00",
      "id": "CVE-2025-71347",
      "impact_tags": [
        "code execution review",
        "remote exposure relevant"
      ],
      "kev": false,
      "last_observed_at": "2026-07-11T02:07:59.132347+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: picklescan before 0.0.33 fails to detect malicious pickle files using numpy.f2py.crackfortran.param_eval function in reduce methods, allowing attackers to bypass security checks. NVD: Remote attackers can embed undetected code in pickle files that executes during deserialization, enabling arbitrary code execution in applications loading untrusted pickle data. OSV: picklescan - Undetected Remote Code Execution via numpy.f2py.crackfortran.param_eval",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260711T020915Z/items/CVE-2025-71347.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes code execution review · remote exposure. Possible impact: A remote attacker may be able to run code or commands on affected systems.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: picklescan before 0.0.33 fails to detect malicious pickle files using numpy.f2py.crackfortran.param_eval function in reduce methods, allowing attackers to bypass security checks. NVD: Remote attackers can embed undetected code in pickle files that executes during deserialization, enabling arbitrary code execution in applications loading untrusted pickle data. OSV: picklescan - Undetected Remote Code Execution via numpy.f2py.crackfortran.param_eval",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2025-71347/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2025-71353/",
      "current_public_safe_latest": false,
      "cvss_score": 7.6,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.21851,
      "epss_score": 0.003,
      "first_observed_at": "2026-07-10T22:27:53.208509+00:00",
      "id": "CVE-2025-71353",
      "impact_tags": [
        "code execution review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-11T02:07:59.132347+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: picklescan before 0.0.28 fails to detect malicious pickle files that exploit torch._dynamo.guards.GuardBuilder.get function in reduce methods. NVD: Attackers can craft pickle files with embedded code that evades picklescan detection and executes arbitrary commands when loaded. OSV: picklescan - Remote Code Execution via torch._dynamo.guards.GuardBuilder.get",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260711T020915Z/items/CVE-2025-71353.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes code execution review. Possible impact: An attacker may be able to run code or commands on affected systems.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: picklescan before 0.0.28 fails to detect malicious pickle files that exploit torch._dynamo.guards.GuardBuilder.get function in reduce methods. NVD: Attackers can craft pickle files with embedded code that evades picklescan detection and executes arbitrary commands when loaded. OSV: picklescan - Remote Code Execution via torch._dynamo.guards.GuardBuilder.get",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2025-71353/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2025-71356/",
      "current_public_safe_latest": false,
      "cvss_score": 7.6,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.2185,
      "epss_score": 0.003,
      "first_observed_at": "2026-07-10T22:27:53.208509+00:00",
      "id": "CVE-2025-71356",
      "impact_tags": [
        "code execution review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-11T02:07:59.132347+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: picklescan before 0.0.28 fails to detect malicious torch.fx.experimental.symbolic_shapes.ShapeEnv.evaluate_guards_expression function calls in pickle files. NVD: Attackers can embed undetected code in pickle files that executes remote code when loaded by victims. OSV: picklescan - Arbitrary Code Execution via torch.fx.experimental.symbolic_shapes.ShapeEnv.evaluate_guards_expression",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260711T020915Z/items/CVE-2025-71356.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes code execution review. Possible impact: An attacker may be able to run code or commands on affected systems.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: picklescan before 0.0.28 fails to detect malicious torch.fx.experimental.symbolic_shapes.ShapeEnv.evaluate_guards_expression function calls in pickle files. NVD: Attackers can embed undetected code in pickle files that executes remote code when loaded by victims. OSV: picklescan - Arbitrary Code Execution via torch.fx.experimental.symbolic_shapes.ShapeEnv.evaluate_guards_expression",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2025-71356/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2025-71359/",
      "current_public_safe_latest": false,
      "cvss_score": 7.6,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.34478,
      "epss_score": 0.00427,
      "first_observed_at": "2026-07-10T22:27:53.208509+00:00",
      "id": "CVE-2025-71359",
      "impact_tags": [
        "code execution review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-11T02:07:59.132347+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: picklescan before 0.0.29 fails to detect malicious pickle payloads that utilize lib2to3.pgen2.grammar.Grammar.loads in the reduce method, allowing remote code execution. NVD: Attackers can craft pickle files embedding dangerous code that evades picklescan detection and executes during pickle.load() deserialization. OSV: picklescan - Unsafe Deserialization via lib2to3.pgen2.grammar.Grammar.loads",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260711T020915Z/items/CVE-2025-71359.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes code execution review. Possible impact: An attacker may be able to run code or commands on affected systems.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: picklescan before 0.0.29 fails to detect malicious pickle payloads that utilize lib2to3.pgen2.grammar.Grammar.loads in the reduce method, allowing remote code execution. NVD: Attackers can craft pickle files embedding dangerous code that evades picklescan detection and executes during pickle.load() deserialization. OSV: picklescan - Unsafe Deserialization via lib2to3.pgen2.grammar.Grammar.loads",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2025-71359/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2025-71360/",
      "current_public_safe_latest": false,
      "cvss_score": 7.6,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.2185,
      "epss_score": 0.003,
      "first_observed_at": "2026-07-10T22:27:53.208509+00:00",
      "id": "CVE-2025-71360",
      "impact_tags": [
        "code execution review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-11T02:07:59.132347+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: picklescan before 0.0.29 fails to detect malicious pickle files using idlelib.calltip.get_entity function in reduce methods. NVD: Attackers can embed undetected code in pickle files that executes remote commands when loaded by victims. OSV: picklescan - Remote Code Execution via Undetected idlelib.calltip.get_entity",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260711T020915Z/items/CVE-2025-71360.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes code execution review. Possible impact: An attacker may be able to run code or commands on affected systems.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: picklescan before 0.0.29 fails to detect malicious pickle files using idlelib.calltip.get_entity function in reduce methods. NVD: Attackers can embed undetected code in pickle files that executes remote commands when loaded by victims. OSV: picklescan - Remote Code Execution via Undetected idlelib.calltip.get_entity",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2025-71360/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2025-71362/",
      "current_public_safe_latest": false,
      "cvss_score": 7.6,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.21851,
      "epss_score": 0.003,
      "first_observed_at": "2026-07-10T22:27:53.208509+00:00",
      "id": "CVE-2025-71362",
      "impact_tags": [
        "code execution review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-11T02:07:59.132347+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: picklescan before 0.0.33 fails to detect unsafe deserialization when numpy.f2py.crackfortran functions call eval on arbitrary strings. NVD: Attackers can embed malicious code in pickle files that executes when loaded from untrusted sources. OSV: picklescan - Arbitrary Code Execution via Unsafe Deserialization in numpy.f2py.crackfortran",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260711T020915Z/items/CVE-2025-71362.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes code execution review. Possible impact: An attacker may be able to run code or commands on affected systems.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: picklescan before 0.0.33 fails to detect unsafe deserialization when numpy.f2py.crackfortran functions call eval on arbitrary strings. NVD: Attackers can embed malicious code in pickle files that executes when loaded from untrusted sources. OSV: picklescan - Arbitrary Code Execution via Unsafe Deserialization in numpy.f2py.crackfortran",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2025-71362/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2025-71364/",
      "current_public_safe_latest": false,
      "cvss_score": 7.6,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.42361,
      "epss_score": 0.00555,
      "first_observed_at": "2026-07-10T22:27:53.208509+00:00",
      "id": "CVE-2025-71364",
      "impact_tags": [
        "code execution review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-11T02:07:59.132347+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: picklescan before 0.0.30 fails to detect the asyncio.unix_events._UnixSubprocessTransport._start function in pickle reduce methods, allowing remote code execution. NVD: Attackers can craft malicious pickle files embedding this built-in function that evade detection but execute arbitrary commands when loaded. OSV: picklescan - Arbitrary Code Execution via Undetected asyncio.unix_events._UnixSubprocessTransport._start",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260711T020915Z/items/CVE-2025-71364.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes code execution review. Possible impact: An attacker may be able to run code or commands on affected systems.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: picklescan before 0.0.30 fails to detect the asyncio.unix_events._UnixSubprocessTransport._start function in pickle reduce methods, allowing remote code execution. NVD: Attackers can craft malicious pickle files embedding this built-in function that evade detection but execute arbitrary commands when loaded. OSV: picklescan - Arbitrary Code Execution via Undetected asyncio.unix_events._UnixSubprocessTransport._start",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2025-71364/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2025-71366/",
      "current_public_safe_latest": false,
      "cvss_score": 7.6,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.3577,
      "epss_score": 0.00445,
      "first_observed_at": "2026-07-10T22:27:53.208509+00:00",
      "id": "CVE-2025-71366",
      "impact_tags": [
        "code execution review",
        "remote exposure relevant"
      ],
      "kev": false,
      "last_observed_at": "2026-07-11T02:07:59.132347+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: picklescan before 0.0.28 fails to detect malicious torch.utils.bottleneck.__main__.run_cprofile function calls in pickle files, allowing attackers to bypass safety checks. NVD: Remote attackers can embed undetected code in pickle files to achieve arbitrary code execution when victims load the files. OSV: picklescan - Arbitrary Code Execution via torch.utils.bottleneck.__main__.run_cprofile",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260711T020915Z/items/CVE-2025-71366.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes code execution review · remote exposure. Possible impact: A remote attacker may be able to run code or commands on affected systems.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: picklescan before 0.0.28 fails to detect malicious torch.utils.bottleneck.__main__.run_cprofile function calls in pickle files, allowing attackers to bypass safety checks. NVD: Remote attackers can embed undetected code in pickle files to achieve arbitrary code execution when victims load the files. OSV: picklescan - Arbitrary Code Execution via torch.utils.bottleneck.__main__.run_cprofile",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2025-71366/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2025-71367/",
      "current_public_safe_latest": false,
      "cvss_score": 7.6,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.3577,
      "epss_score": 0.00445,
      "first_observed_at": "2026-07-10T22:27:53.208509+00:00",
      "id": "CVE-2025-71367",
      "impact_tags": [
        "code execution review",
        "remote exposure relevant"
      ],
      "kev": false,
      "last_observed_at": "2026-07-11T02:07:59.132347+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: picklescan before 0.0.34 fails to detect _operator.attrgetter function calls in pickle payloads, allowing attackers to bypass security checks. NVD: Remote attackers can craft malicious pickle files using _operator.attrgetter in reduce methods to execute arbitrary code when pickle.load() processes the file. OSV: picklescan - Remote Code Execution via _operator.attrgetter Detection Bypass",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260711T020915Z/items/CVE-2025-71367.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes code execution review · remote exposure. Possible impact: A remote attacker may be able to run code or commands on affected systems.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: picklescan before 0.0.34 fails to detect _operator.attrgetter function calls in pickle payloads, allowing attackers to bypass security checks. NVD: Remote attackers can craft malicious pickle files using _operator.attrgetter in reduce methods to execute arbitrary code when pickle.load() processes the file. OSV: picklescan - Remote Code Execution via _operator.attrgetter Detection Bypass",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2025-71367/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2025-71369/",
      "current_public_safe_latest": false,
      "cvss_score": 7.6,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.35769,
      "epss_score": 0.00445,
      "first_observed_at": "2026-07-10T22:27:53.208509+00:00",
      "id": "CVE-2025-71369",
      "impact_tags": [
        "code execution review",
        "remote exposure relevant"
      ],
      "kev": false,
      "last_observed_at": "2026-07-11T02:07:59.132347+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: picklescan before 0.0.28 fails to detect malicious pickle files that use torch.utils.data.datapipes.utils.decoder.basichandlers in reduce methods, allowing attackers to bypass safety checks. NVD: Remote attackers can embed undetected malicious code in pickle files that executes during deserialization, enabling remote code execution. OSV: picklescan - Unsafe Deserialization via torch.utils.data.datapipes.utils.decoder.basichandlers",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260711T020915Z/items/CVE-2025-71369.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes code execution review · remote exposure. Possible impact: A remote attacker may be able to run code or commands on affected systems.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: picklescan before 0.0.28 fails to detect malicious pickle files that use torch.utils.data.datapipes.utils.decoder.basichandlers in reduce methods, allowing attackers to bypass safety checks. NVD: Remote attackers can embed undetected malicious code in pickle files that executes during deserialization, enabling remote code execution. OSV: picklescan - Unsafe Deserialization via torch.utils.data.datapipes.utils.decoder.basichandlers",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2025-71369/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2025-71372/",
      "current_public_safe_latest": false,
      "cvss_score": 7.6,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.30025,
      "epss_score": 0.00379,
      "first_observed_at": "2026-07-10T22:27:53.208509+00:00",
      "id": "CVE-2025-71372",
      "impact_tags": [
        "code execution review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-11T02:07:59.132347+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Picklescan before 0.0.33 fails to detect the numpy.f2py.crackfortran.getlincoef gadget in pickle __reduce__ methods, allowing arbitrary code execution. NVD: Attackers can craft malicious pickle files that execute arbitrary Python code when loaded, bypassing Picklescan's safety checks and enabling supply-chain poisoning of shared model files. OSV: Picklescan - Arbitrary Code Execution via numpy.f2py.crackfortran.getlincoef Gadget",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260711T020915Z/items/CVE-2025-71372.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes code execution review. Possible impact: An attacker may be able to run code or commands on affected systems.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Picklescan before 0.0.33 fails to detect the numpy.f2py.crackfortran.getlincoef gadget in pickle __reduce__ methods, allowing arbitrary code execution. NVD: Attackers can craft malicious pickle files that execute arbitrary Python code when loaded, bypassing Picklescan's safety checks and enabling supply-chain poisoning of shared model files. OSV: Picklescan - Arbitrary Code Execution via numpy.f2py.crackfortran.getlincoef Gadget",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2025-71372/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2025-71373/",
      "current_public_safe_latest": false,
      "cvss_score": 7.6,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.35729,
      "epss_score": 0.00444,
      "first_observed_at": "2026-07-10T22:27:53.208509+00:00",
      "id": "CVE-2025-71373",
      "impact_tags": [
        "code execution review",
        "remote exposure relevant"
      ],
      "kev": false,
      "last_observed_at": "2026-07-11T02:07:59.132347+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: picklescan before 0.0.33 fails to detect operator.methodcaller function calls in pickle files, allowing attackers to bypass security checks. NVD: Remote attackers can craft malicious pickle payloads using operator.methodcaller that execute arbitrary code when loaded, compromising systems relying on picklescan for validation. OSV: picklescan - Remote Code Execution via operator.methodcaller Detection Bypass",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260711T020915Z/items/CVE-2025-71373.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes code execution review · remote exposure. Possible impact: A remote attacker may be able to run code or commands on affected systems.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: picklescan before 0.0.33 fails to detect operator.methodcaller function calls in pickle files, allowing attackers to bypass security checks. NVD: Remote attackers can craft malicious pickle payloads using operator.methodcaller that execute arbitrary code when loaded, compromising systems relying on picklescan for validation. OSV: picklescan - Remote Code Execution via operator.methodcaller Detection Bypass",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2025-71373/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2025-71375/",
      "current_public_safe_latest": false,
      "cvss_score": 7.6,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.28573,
      "epss_score": 0.00365,
      "first_observed_at": "2026-07-10T22:27:53.208509+00:00",
      "id": "CVE-2025-71375",
      "impact_tags": [
        "code execution review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-11T02:07:59.132347+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: picklescan before 0.0.34 fails to detect the _operator.methodcaller built-in function when scanning pickle files for malicious code. NVD: Attackers can craft malicious pickle payloads using _operator.methodcaller that evade detection and execute arbitrary code when loaded by pickle.load(). OSV: picklescan - Undetected Remote Code Execution via _operator.methodcaller",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260711T020915Z/items/CVE-2025-71375.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes code execution review. Possible impact: An attacker may be able to run code or commands on affected systems.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: picklescan before 0.0.34 fails to detect the _operator.methodcaller built-in function when scanning pickle files for malicious code. NVD: Attackers can craft malicious pickle payloads using _operator.methodcaller that evade detection and execute arbitrary code when loaded by pickle.load(). OSV: picklescan - Undetected Remote Code Execution via _operator.methodcaller",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2025-71375/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2025-71377/",
      "current_public_safe_latest": false,
      "cvss_score": 8.7,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.30843,
      "epss_score": 0.00383,
      "first_observed_at": "2026-07-23T11:21:51.498947+00:00",
      "id": "CVE-2025-71377",
      "impact_tags": [
        "service availability review",
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-23T11:21:51.498947+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: stoatchat (delta) versions before 20250210-1 (0.8.2) contain a logic error in the query messages route. NVD: When fetching messages 'nearby' another message, the database query can be given a message limit of zero, which the database interprets as 'no limit'. NVD: A remote unauthenticated attacker can craft nearby message fetch requests to download an entire channel's message history in a single expensive request, and can send many such requests in parallel, resulting in denial of service through resource exhaustion.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260723T112431Z/items/CVE-2025-71377.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes service availability risk · remote exposure · authenticated boundary. Possible impact: The affected service may become unavailable or unreliable.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: stoatchat (delta) versions before 20250210-1 (0.8.2) contain a logic error in the query messages route. NVD: When fetching messages 'nearby' another message, the database query can be given a message limit of zero, which the database interprets as 'no limit'. NVD: A remote unauthenticated attacker can craft nearby message fetch requests to download an entire channel's message history in a single expensive request, and can send many such requests in parallel, resulting in denial of service through resource exhaustion.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2025-71377/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2025-71380/",
      "current_public_safe_latest": false,
      "cvss_score": 8.7,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.33268,
      "epss_score": 0.00413,
      "first_observed_at": "2026-07-10T22:27:53.208509+00:00",
      "id": "CVE-2025-71380",
      "impact_tags": [
        "command execution review",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-11T02:07:59.132347+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Execute Command node in n8n allows authenticated users to execute arbitrary commands on the host system where n8n runs. NVD: Attackers with user access or compromised credentials can exploit this node to run malicious commands, potentially leading to data exfiltration, service disruption, or complete system compromise. OSV: n8n - Arbitrary Command Execution via Execute Command Node",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260711T020915Z/items/CVE-2025-71380.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes command execution risk · authenticated boundary. Possible impact: An attacker may be able to run code or commands on affected systems.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Execute Command node in n8n allows authenticated users to execute arbitrary commands on the host system where n8n runs. NVD: Attackers with user access or compromised credentials can exploit this node to run malicious commands, potentially leading to data exfiltration, service disruption, or complete system compromise. OSV: n8n - Arbitrary Command Execution via Execute Command Node",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2025-71380/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2025-71388/",
      "current_public_safe_latest": false,
      "cvss_score": 7.6,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.19579,
      "epss_score": 0.00275,
      "first_observed_at": "2026-07-23T11:21:51.498947+00:00",
      "id": "CVE-2025-71388",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-23T11:21:51.498947+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: stoatchat (delta/Revolt) versions from 20241213-1 before 20250210-1 allow users with only ViewChannel (read) permission on a channel to fetch that channel's webhooks, including their tokens, because the webhook fetch endpoint checked for ViewChannel instead... NVD: Using a retrieved token, an attacker can send arbitrary messages to the channel, bypassing channel permissions and impersonating a bot or webhook. NVD: Fixed in 20250210-1 (0.8.2).",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260723T112431Z/items/CVE-2025-71388.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: 20250210-1.",
      "source_published_summary": "NVD: stoatchat (delta/Revolt) versions from 20241213-1 before 20250210-1 allow users with only ViewChannel (read) permission on a channel to fetch that channel's webhooks, including their tokens, because the webhook fetch endpoint checked for ViewChannel instead... NVD: Using a retrieved token, an attacker can send arbitrary messages to the channel, bypassing channel permissions and impersonating a bot or webhook. NVD: Fixed in 20250210-1 (0.8.2).",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2025-71388/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2025-71399/",
      "current_public_safe_latest": false,
      "cvss_score": 8.8,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.22871,
      "epss_score": 0.00306,
      "first_observed_at": "2026-08-09T09:59:30.349754+00:00",
      "id": "CVE-2025-71399",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-09T09:59:30.349754+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Better Auth relies on better-call, which uses the rou3 router library. NVD: In affected versions of rou3, paths are normalized by removing empty segments, so /path, //path, and ///path resolve to the same route. NVD: In Better Auth versions prior to 1.4.5 (which bundles the fixed rou3), this can allow attackers to bypass disabledPaths configuration and path-based rate limits by submitting requests with extra slashes in the URL path.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260809T101323Z/items/CVE-2025-71399.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Better Auth relies on better-call, which uses the rou3 router library. NVD: In affected versions of rou3, paths are normalized by removing empty segments, so /path, //path, and ///path resolve to the same route. NVD: In Better Auth versions prior to 1.4.5 (which bundles the fixed rou3), this can allow attackers to bypass disabledPaths configuration and path-based rate limits by submitting requests with extra slashes in the URL path.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2025-71399/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2025-71400/",
      "current_public_safe_latest": false,
      "cvss_score": 7.1,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.10308,
      "epss_score": 0.00202,
      "first_observed_at": "2026-08-09T09:59:30.349754+00:00",
      "id": "CVE-2025-71400",
      "impact_tags": [
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-09T09:59:30.349754+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: better-auth passkey versions before 1.4.0 contain an insecure direct object reference vulnerability in the passkey deletion endpoint that allows authenticated users to delete arbitrary passkeys by ID. NVD: Attackers with valid sessions can submit crafted requests to the delete-passkey endpoint with enumerated passkey IDs to remove other users' passkeys. OSV: better-auth passkey before 1.4.0 IDOR via delete-passkey",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260809T101323Z/items/CVE-2025-71400.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes authenticated boundary. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: better-auth passkey versions before 1.4.0 contain an insecure direct object reference vulnerability in the passkey deletion endpoint that allows authenticated users to delete arbitrary passkeys by ID. NVD: Attackers with valid sessions can submit crafted requests to the delete-passkey endpoint with enumerated passkey IDs to remove other users' passkeys. OSV: better-auth passkey before 1.4.0 IDOR via delete-passkey",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2025-71400/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2025-71401/",
      "current_public_safe_latest": false,
      "cvss_score": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.17577,
      "epss_score": 0.0026,
      "first_observed_at": "2026-08-09T09:59:30.349754+00:00",
      "id": "CVE-2025-71401",
      "impact_tags": [
        "service availability review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-09T09:59:30.349754+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: better-auth (npm) before 1.4.2 allows an external request to configure baseURL when it is not otherwise defined (e.g., BETTER_AUTH_URL is unset). NVD: An attacker able to make the very first request to the server after startup can poison the router's base path, causing all routes to return 404 for all users (denial of service). NVD: The issue is not reachable when baseURL is explicitly configured or on typical managed hosting platforms.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260809T101323Z/items/CVE-2025-71401.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes service availability risk. Possible impact: The affected service may become unavailable or unreliable.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: better-auth (npm) before 1.4.2 allows an external request to configure baseURL when it is not otherwise defined (e.g., BETTER_AUTH_URL is unset). NVD: An attacker able to make the very first request to the server after startup can poison the router's base path, causing all routes to return 404 for all users (denial of service). NVD: The issue is not reachable when baseURL is explicitly configured or on typical managed hosting platforms.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2025-71401/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2025-71402/",
      "current_public_safe_latest": false,
      "cvss_score": 2.0,
      "cvss_severity": "LOW",
      "epss_percentile": 0.10841,
      "epss_score": 0.00206,
      "first_observed_at": "2026-08-08T09:56:53.105288+00:00",
      "id": "CVE-2025-71402",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-08T09:56:53.105288+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: better-auth versions greater than 1.3.34 and before 1.4.0 contain a vulnerability in the multi-session plugin's /sign-out after-hook, which trusts raw multi-session cookies and forwards extracted values to internalAdapter.deleteSessions without verifying the... NVD: An attacker can supply a forged _multi-* cookie to trigger deletion of arbitrary session tokens. OSV: better-auth before 1.4.0 Session Revocation via Forged Cookie",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260808T100051Z/items/CVE-2025-71402.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: better-auth versions greater than 1.3.34 and before 1.4.0 contain a vulnerability in the multi-session plugin's /sign-out after-hook, which trusts raw multi-session cookies and forwards extracted values to internalAdapter.deleteSessions without verifying the... NVD: An attacker can supply a forged _multi-* cookie to trigger deletion of arbitrary session tokens. OSV: better-auth before 1.4.0 Session Revocation via Forged Cookie",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2025-71402/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2025-71403/",
      "current_public_safe_latest": false,
      "cvss_score": 7.1,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.14865,
      "epss_score": 0.00238,
      "first_observed_at": "2026-08-08T09:56:53.105288+00:00",
      "id": "CVE-2025-71403",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-08T09:56:53.105288+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: better-auth versions before 1.1.20 contain a bypass vulnerability in trustedOrigins validation logic affecting absolute URLs and wildcard domains. NVD: Attackers can construct malicious callbackURL parameters that pass origin checks and trigger open redirects to steal sensitive tokens for account takeover. OSV: better-auth before 1.1.20 Open Redirect via trustedOrigins Bypass",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260808T100051Z/items/CVE-2025-71403.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: better-auth versions before 1.1.20 contain a bypass vulnerability in trustedOrigins validation logic affecting absolute URLs and wildcard domains. NVD: Attackers can construct malicious callbackURL parameters that pass origin checks and trigger open redirects to steal sensitive tokens for account takeover. OSV: better-auth before 1.1.20 Open Redirect via trustedOrigins Bypass",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2025-71403/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2025-71404/",
      "current_public_safe_latest": false,
      "cvss_score": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.32666,
      "epss_score": 0.00399,
      "first_observed_at": "2026-08-08T09:56:53.105288+00:00",
      "id": "CVE-2025-71404",
      "impact_tags": [
        "XSS risk"
      ],
      "kev": false,
      "last_observed_at": "2026-08-08T09:56:53.105288+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: better-auth versions after v0.0.2 and before 1.1.16 contain a reflected cross-site scripting (XSS) vulnerability on the /api/auth/error page, where the value of the 'error' URL parameter is reflected as HTML without proper neutralization. NVD: An attacker who coerces a user into visiting a specially-crafted URL can execute arbitrary JavaScript in the context of the user's browser. NVD: The issue is fixed in version 1.1.16.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260808T100051Z/items/CVE-2025-71404.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes XSS risk. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: better-auth versions after v0.0.2 and before 1.1.16 contain a reflected cross-site scripting (XSS) vulnerability on the /api/auth/error page, where the value of the 'error' URL parameter is reflected as HTML without proper neutralization. NVD: An attacker who coerces a user into visiting a specially-crafted URL can execute arbitrary JavaScript in the context of the user's browser. NVD: The issue is fixed in version 1.1.16.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2025-71404/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2025-8412/",
      "current_public_safe_latest": false,
      "cvss_score": 2.0,
      "cvss_severity": "LOW",
      "epss_percentile": 0.00568,
      "epss_score": 0.0009,
      "first_observed_at": "2026-07-21T06:08:28.817138+00:00",
      "id": "CVE-2025-8412",
      "impact_tags": [
        "memory safety review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-21T06:08:28.817138+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in SUSE Virtual Machine Driver Pack allows an attacker with the ability to modify the registry to affect the integrity of the driver. NVD: We're not aware of a feasible way to exploit this currently. NVD: This issue affects Virtual Machine Driver Pack: before e7a602ec232756ead019bdf19d6d3b9d010cc94b.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260721T061518Z/items/CVE-2025-8412.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes memory safety review. Possible impact: The affected component has memory-safety risk that may lead to crash, privilege, or code-execution impact depending on exposure.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in SUSE Virtual Machine Driver Pack allows an attacker with the ability to modify the registry to affect the integrity of the driver. NVD: We're not aware of a feasible way to exploit this currently. NVD: This issue affects Virtual Machine Driver Pack: before e7a602ec232756ead019bdf19d6d3b9d010cc94b.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2025-8412/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2025-9205/",
      "current_public_safe_latest": false,
      "cvss_score": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.08591,
      "epss_score": 0.00187,
      "first_observed_at": "2026-07-30T22:30:38.166118+00:00",
      "id": "CVE-2025-9205",
      "impact_tags": [
        "XSS risk",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-30T22:30:38.166118+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The MapSVG plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 8.14.0. NVD: This is due to insufficient input sanitization and output escaping on user supplied attributes within the map options. NVD: This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260730T224832Z/items/CVE-2025-9205.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes XSS risk · authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The MapSVG plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 8.14.0. NVD: This is due to insufficient input sanitization and output escaping on user supplied attributes within the map options. NVD: This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2025-9205/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-0667/",
      "current_public_safe_latest": false,
      "cvss_score": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.29569,
      "epss_score": 0.00369,
      "first_observed_at": "2026-08-05T11:32:09.387600+00:00",
      "id": "CVE-2026-0667",
      "impact_tags": [
        "code execution review",
        "service availability review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-05T11:32:09.387600+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability that could cause arbitrary code execution, denial of service and loss of confidentiality & integrity when communicating over the Modbus TCP protocol.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260805T113552Z/items/CVE-2026-0667.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes code execution review · service availability risk. Possible impact: An attacker may be able to run code or commands on affected systems.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability that could cause arbitrary code execution, denial of service and loss of confidentiality & integrity when communicating over the Modbus TCP protocol.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-0667/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-10037/",
      "current_public_safe_latest": false,
      "cvss_score": 8.8,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.02157,
      "epss_score": 0.0012,
      "first_observed_at": "2026-07-15T22:16:59.245057+00:00",
      "id": "CVE-2026-10037",
      "impact_tags": [
        "code execution review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-15T22:16:59.245057+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A sandbox escape vulnerability exists in the OpenJDK packages provided in Ubuntu. NVD: The .jar MIME handlers installed by these packages execute files marked as executable when the mailcap package is installed. NVD: A compromised or malicious sandboxed application with access to the OpenURI portal via xdg-desktop-portal-gtk can write a malicious .jar file to the host file system, set its executable bit, and trigger the handler to execute arbitrary code outside of the...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260715T221956Z/items/CVE-2026-10037.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes code execution review. Possible impact: An attacker may be able to run code or commands on affected systems.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A sandbox escape vulnerability exists in the OpenJDK packages provided in Ubuntu. NVD: The .jar MIME handlers installed by these packages execute files marked as executable when the mailcap package is installed. NVD: A compromised or malicious sandboxed application with access to the OpenURI portal via xdg-desktop-portal-gtk can write a malicious .jar file to the host file system, set its executable bit, and trigger the handler to execute arbitrary code outside of the...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-10037/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-10041/",
      "current_public_safe_latest": false,
      "cvss_score": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.16322,
      "epss_score": 0.0025,
      "first_observed_at": "2026-07-18T05:38:40.092323+00:00",
      "id": "CVE-2026-10041",
      "impact_tags": [
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-18T07:15:27.585758+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The WCFM – Frontend Manager for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 6.7.27 via the wcfm_product_archive due to missing validation on a user controlled key. NVD: This makes it possible for authenticated attackers, with subscriber-level access and above, to archive arbitrary vendors' products, toggle the featured status on arbitrary listings, mark arbitrary WooCommerce orders as completed, and permanently delete...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260718T071858Z/items/CVE-2026-10041.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The WCFM – Frontend Manager for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 6.7.27 via the wcfm_product_archive due to missing validation on a user controlled key. NVD: This makes it possible for authenticated attackers, with subscriber-level access and above, to archive arbitrary vendors' products, toggle the featured status on arbitrary listings, mark arbitrary WooCommerce orders as completed, and permanently delete...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-10041/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "eclipse / jetty",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-10050/",
      "current_public_safe_latest": false,
      "cvss_score": 8.7,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.38242,
      "epss_score": 0.0047,
      "first_observed_at": "2026-08-11T10:14:04.199465+00:00",
      "id": "CVE-2026-10050",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-11T10:14:04.199465+00:00",
      "latest_item_url": null,
      "product": "jetty",
      "public_safe_summary": "NVD: In Eclipse Jetty, the Digest authentication server-side component uses ISO-8859-1 to encode the password as bytes. NVD: This was done because the initial specification for HTTP did not specify explicitly a charset, and it was assumed to be ISO-8859-1 for historical reasons. NVD: If the password contains characters that cannot be represented in ISO-8859-1, they are silently replaced by ?.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260811T102539Z/items/CVE-2026-10050.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: eclipse / jetty",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: In Eclipse Jetty, the Digest authentication server-side component uses ISO-8859-1 to encode the password as bytes. NVD: This was done because the initial specification for HTTP did not specify explicitly a charset, and it was assumed to be ISO-8859-1 for historical reasons. NVD: If the password contains characters that cannot be represented in ISO-8859-1, they are silently replaced by ?.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-10050/timeline.json",
      "vendor": "eclipse"
    },
    {
      "affected_label": "eclipse / jetty",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-10051/",
      "current_public_safe_latest": false,
      "cvss_score": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.16786,
      "epss_score": 0.00253,
      "first_observed_at": "2026-07-21T06:08:28.817138+00:00",
      "id": "CVE-2026-10051",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-21T06:08:28.817138+00:00",
      "latest_item_url": null,
      "product": "jetty",
      "public_safe_summary": "NVD: In Eclipse Jetty, a first HTTP/1.1 request with trailers causes the server to retain the trailers in subsequent requests performed over the same connection. NVD: Subsequent request that do not have trailers report the trailers of the first request. NVD: Subsequent request that do have trailers report the union of trailers of the first request and the current request.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260721T061518Z/items/CVE-2026-10051.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: eclipse / jetty",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: In Eclipse Jetty, a first HTTP/1.1 request with trailers causes the server to retain the trailers in subsequent requests performed over the same connection. NVD: Subsequent request that do not have trailers report the trailers of the first request. NVD: Subsequent request that do have trailers report the union of trailers of the first request and the current request.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-10051/timeline.json",
      "vendor": "eclipse"
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-10079/",
      "current_public_safe_latest": false,
      "cvss_score": 8.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.06144,
      "epss_score": 0.00165,
      "first_observed_at": "2026-08-07T10:13:53.604723+00:00",
      "id": "CVE-2026-10079",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-07T10:13:53.604723+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A flaw was found in Red Hat Advanced Cluster Security for Kubernetes (RHACS). NVD: When processing Kubernetes Deployments, ACS replaces deployment identity metadata based on the openshift.io/encoded-deployment-config label. NVD: A user with permission to create Deployments can set this label to \"null\", causing ACS to treat the workload as having empty UID, name and labels and namespace \"default\".",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260807T102646Z/items/CVE-2026-10079.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A flaw was found in Red Hat Advanced Cluster Security for Kubernetes (RHACS). NVD: When processing Kubernetes Deployments, ACS replaces deployment identity metadata based on the openshift.io/encoded-deployment-config label. NVD: A user with permission to create Deployments can set this label to \"null\", causing ACS to treat the workload as having empty UID, name and labels and namespace \"default\".",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-10079/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-10081/",
      "current_public_safe_latest": false,
      "cvss_score": 8.8,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.21355,
      "epss_score": 0.00292,
      "first_observed_at": "2026-07-26T22:15:56.881440+00:00",
      "id": "CVE-2026-10081",
      "impact_tags": [
        "XSS risk",
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-27T06:45:51.031460+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Unlimited Elements For Elementor WordPress plugin before 2.0.11 does not sanitize or escape Google review content fetched from the Serp API before rendering it in the Google Reviews widget output, allowing unauthenticated attackers who submit a malicious...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260727T065126Z/items/CVE-2026-10081.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes XSS risk · remote exposure · authenticated boundary. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk · remote exposure · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Unlimited Elements For Elementor WordPress plugin before 2.0.11 does not sanitize or escape Google review content fetched from the Serp API before rendering it in the Google Reviews widget output, allowing unauthenticated attackers who submit a malicious...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-10081/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-10082/",
      "current_public_safe_latest": false,
      "cvss_score": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.04585,
      "epss_score": 0.00149,
      "first_observed_at": "2026-08-01T16:16:22.294010+00:00",
      "id": "CVE-2026-10082",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-03T06:40:38.700520+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Advanced Ads WordPress plugin before 2.0.23 does not sanitize and escape a shortcode parameter before outputting it in the page, allowing users with the Contributor role and above to inject arbitrary web scripts that execute when the affected content is...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260803T064356Z/items/CVE-2026-10082.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 7,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Advanced Ads WordPress plugin before 2.0.23 does not sanitize and escape a shortcode parameter before outputting it in the page, allowing users with the Contributor role and above to inject arbitrary web scripts that execute when the affected content is...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-10082/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-10130/",
      "current_public_safe_latest": false,
      "cvss_score": 8.8,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.29208,
      "epss_score": 0.00366,
      "first_observed_at": "2026-07-25T22:13:31.040742+00:00",
      "id": "CVE-2026-10130",
      "impact_tags": [
        "authentication boundary review",
        "remote exposure relevant",
        "authenticated boundary review",
        "user interaction review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-25T22:13:31.040742+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: QueryWeaver contains an authentication bypass vulnerability that allows unauthenticated attackers to obtain valid session tokens for existing accounts by submitting a signup request with a known victim email address. NVD: The signup route unconditionally creates and links a new token to the matching Identity via a Cypher MERGE operation before checking whether the email belongs to an existing account, causing the server to return a valid authenticated session token for the... OSV: QueryWeaver Authentication Bypass via Email Signup Token Issuance for Existing Accounts",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260725T221848Z/items/CVE-2026-10130.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes authentication boundary review · remote exposure · authenticated boundary. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authentication boundary review · remote exposure · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: QueryWeaver contains an authentication bypass vulnerability that allows unauthenticated attackers to obtain valid session tokens for existing accounts by submitting a signup request with a known victim email address. NVD: The signup route unconditionally creates and links a new token to the matching Identity via a Cypher MERGE operation before checking whether the email belongs to an existing account, causing the server to return a valid authenticated session token for the... OSV: QueryWeaver Authentication Bypass via Email Signup Token Issuance for Existing Accounts",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-10130/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-10525/",
      "current_public_safe_latest": false,
      "cvss_score": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.19618,
      "epss_score": 0.00275,
      "first_observed_at": "2026-07-24T06:06:41.160911+00:00",
      "id": "CVE-2026-10525",
      "impact_tags": [
        "XSS risk",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-24T06:06:41.160911+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The NEX-Forms WordPress plugin before 9.2.3 does not sanitise and escape some submitted form data before storing it and outputting it back in the admin dashboard, leading to a Stored Cross-Site Scripting vulnerability which could allow unauthenticated users...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260724T061150Z/items/CVE-2026-10525.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes XSS risk · authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The NEX-Forms WordPress plugin before 9.2.3 does not sanitise and escape some submitted form data before storing it and outputting it back in the admin dashboard, leading to a Stored Cross-Site Scripting vulnerability which could allow unauthenticated users...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-10525/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-10526/",
      "current_public_safe_latest": false,
      "cvss_score": 5.8,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.13587,
      "epss_score": 0.00228,
      "first_observed_at": "2026-08-11T04:43:10.985977+00:00",
      "id": "CVE-2026-10526",
      "impact_tags": [
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-11T04:43:10.985977+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The EmbedPress WordPress plugin before 4.6.1 does not validate user-supplied URLs before making server-side requests through unauthenticated endpoints, allowing unauthenticated attackers to induce the site to send HTTP requests to internal hosts and services...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260811T044729Z/items/CVE-2026-10526.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes remote exposure · authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The EmbedPress WordPress plugin before 4.6.1 does not validate user-supplied URLs before making server-side requests through unauthenticated endpoints, allowing unauthenticated attackers to induce the site to send HTTP requests to internal hosts and services...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-10526/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "haxx / curl",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-10536/",
      "current_public_safe_latest": false,
      "cvss_score": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.55139,
      "epss_score": 0.00891,
      "first_observed_at": "2026-07-10T06:57:55.339390+00:00",
      "id": "CVE-2026-10536",
      "impact_tags": [
        "memory safety review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-10T06:57:55.339390+00:00",
      "latest_item_url": null,
      "product": "curl",
      "public_safe_summary": "NVD: A use-after-free vulnerability exists in libcurl when an application configures an HTTP/2 stream-dependency tree via CURLOPT_STREAM_DEPENDS or CURLOPT_STREAM_DEPENDS_E, subsequently invokes curl_easy_reset(), and finally terminates the handle with... NVD: During this final cleanup phase, libcurl attempts to access and modify an internal structure that was already freed during the reset operation. OSV: HTTP/2 stream-dependency tree UAF",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260710T070012Z/items/CVE-2026-10536.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: haxx / curl",
      "source_published_impact": "Source describes memory safety review. Possible impact: The affected component has memory-safety risk that may lead to crash, privilege, or code-execution impact depending on exposure.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A use-after-free vulnerability exists in libcurl when an application configures an HTTP/2 stream-dependency tree via CURLOPT_STREAM_DEPENDS or CURLOPT_STREAM_DEPENDS_E, subsequently invokes curl_easy_reset(), and finally terminates the handle with... NVD: During this final cleanup phase, libcurl attempts to access and modify an internal structure that was already freed during the reset operation. OSV: HTTP/2 stream-dependency tree UAF",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-10536/timeline.json",
      "vendor": "haxx"
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-10551/",
      "current_public_safe_latest": false,
      "cvss_score": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.04512,
      "epss_score": 0.00149,
      "first_observed_at": "2026-07-20T06:28:37.060083+00:00",
      "id": "CVE-2026-10551",
      "impact_tags": [
        "XSS risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-20T06:28:37.060083+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Breeze Cache WordPress plugin before 2.5.6 is vulnerable to unauthenticated Stored Cross-Site Scripting (XSS) due to a predictable replacement hash used during the HTML minification process and abusing a regular expression. NVD: This allows an attacker to inject arbitrary HTML attributes in the final HTML output by anticipating the placeholder format.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260720T063049Z/items/CVE-2026-10551.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes XSS risk. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Breeze Cache WordPress plugin before 2.5.6 is vulnerable to unauthenticated Stored Cross-Site Scripting (XSS) due to a predictable replacement hash used during the HTML minification process and abusing a regular expression. NVD: This allows an attacker to inject arbitrary HTML attributes in the final HTML output by anticipating the placeholder format.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-10551/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-10570/",
      "current_public_safe_latest": false,
      "cvss_score": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.08462,
      "epss_score": 0.00187,
      "first_observed_at": "2026-07-15T05:43:30.245469+00:00",
      "id": "CVE-2026-10570",
      "impact_tags": [
        "XSS risk",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-15T05:43:30.245469+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Sympl Repeater for ACF and Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via ACF repeater field values in all versions up to, and including, 2.3. NVD: This is due to insufficient input sanitization and output escaping in the symp_arfe_replace_content() function, which uses str_replace() to substitute raw ACF field values (retrieved via get_field()) directly into Elementor-rendered HTML without any escaping. NVD: This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260715T054459Z/items/CVE-2026-10570.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes XSS risk · authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Sympl Repeater for ACF and Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via ACF repeater field values in all versions up to, and including, 2.3. NVD: This is due to insufficient input sanitization and output escaping in the symp_arfe_replace_content() function, which uses str_replace() to substitute raw ACF field values (retrieved via get_field()) directly into Elementor-rendered HTML without any escaping. NVD: This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-10570/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-10577/",
      "current_public_safe_latest": false,
      "cvss_score": 10.0,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.168,
      "epss_score": 0.00253,
      "first_observed_at": "2026-07-21T11:20:19.325173+00:00",
      "id": "CVE-2026-10577",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-21T11:20:19.325173+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A security issue exists within the 1715-AENTR EtherNet/IP Adapter. NVD: The affected product exposes a network-accessible debug port that does not enforce proper privilege controls, allowing unauthenticated remote access to intrusive command-line interface (CLI) commands. NVD: If exploited, a threat actor could read or delete files, stop tasks, modify memory, and change I/O states, potentially impacting the confidentiality, integrity, and availability of the device.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260721T112231Z/items/CVE-2026-10577.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A security issue exists within the 1715-AENTR EtherNet/IP Adapter. NVD: The affected product exposes a network-accessible debug port that does not enforce proper privilege controls, allowing unauthenticated remote access to intrusive command-line interface (CLI) commands. NVD: If exploited, a threat actor could read or delete files, stop tasks, modify memory, and change I/O states, potentially impacting the confidentiality, integrity, and availability of the device.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-10577/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-10587/",
      "current_public_safe_latest": false,
      "cvss_score": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.04396,
      "epss_score": 0.00147,
      "first_observed_at": "2026-07-23T16:53:12.033252+00:00",
      "id": "CVE-2026-10587",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-23T16:53:12.033252+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A potential out-of-bounds write vulnerability could allow a local privileged attacker to modify power management settings in System Management Mode.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260723T171217Z/items/CVE-2026-10587.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A potential out-of-bounds write vulnerability could allow a local privileged attacker to modify power management settings in System Management Mode.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-10587/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-10588/",
      "current_public_safe_latest": false,
      "cvss_score": 6.7,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.05011,
      "epss_score": 0.00154,
      "first_observed_at": "2026-07-23T16:53:12.033252+00:00",
      "id": "CVE-2026-10588",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-23T16:53:12.033252+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A potential vulnerability could allow a local privileged attacker to disclose the address of protected System Management Mode memory.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260723T171217Z/items/CVE-2026-10588.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A potential vulnerability could allow a local privileged attacker to disclose the address of protected System Management Mode memory.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-10588/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-10589/",
      "current_public_safe_latest": false,
      "cvss_score": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.05702,
      "epss_score": 0.00161,
      "first_observed_at": "2026-07-23T16:53:12.033252+00:00",
      "id": "CVE-2026-10589",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-23T16:53:12.033252+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A potential out of bounds write vulnerability could allow a local privileged attacker to execute code in System Management Mode.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260723T171217Z/items/CVE-2026-10589.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A potential out of bounds write vulnerability could allow a local privileged attacker to execute code in System Management Mode.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-10589/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-10590/",
      "current_public_safe_latest": false,
      "cvss_score": 6.7,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.06162,
      "epss_score": 0.00166,
      "first_observed_at": "2026-07-23T16:53:12.033252+00:00",
      "id": "CVE-2026-10590",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-23T16:53:12.033252+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A potential missing authentication vulnerability could allow a local privileged attacker to use WMI commands to arbitrarily trigger a System Management Interrupt handler.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260723T171217Z/items/CVE-2026-10590.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A potential missing authentication vulnerability could allow a local privileged attacker to use WMI commands to arbitrarily trigger a System Management Interrupt handler.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-10590/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-10610/",
      "current_public_safe_latest": false,
      "cvss_score": 8.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.04028,
      "epss_score": 0.00143,
      "first_observed_at": "2026-07-31T11:36:05.167842+00:00",
      "id": "CVE-2026-10610",
      "impact_tags": [
        "code execution review",
        "privilege boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-31T11:36:05.167842+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Local privilege escalation potentially allowed an attacker to execute arbitrary code as a privileged user.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260731T115001Z/items/CVE-2026-10610.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes code execution review · privilege escalation risk. Possible impact: An attacker may be able to run code or commands on affected systems.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Local privilege escalation potentially allowed an attacker to execute arbitrary code as a privileged user.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-10610/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "zephyrproject / zephyr",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-10656/",
      "current_public_safe_latest": false,
      "cvss_score": 4.6,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.08903,
      "epss_score": 0.00191,
      "first_observed_at": "2026-07-12T16:15:44.451858+00:00",
      "id": "CVE-2026-10656",
      "impact_tags": [
        "service availability review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-12T22:10:37.281882+00:00",
      "latest_item_url": null,
      "product": "zephyr",
      "public_safe_summary": "NVD: The MAX32xxx USB device controller driver (drivers/usb/udc/udc_max32.c, compatible adi_max32_usbhs) dereferenced an endpoint buffer in its OUT and IN transfer-completion handlers without checking it for NULL. NVD: udc_event_xfer_out_done() called net_buf_add(buf, ep_request->actlen) immediately after buf = udc_buf_get(ep_cfg), where udc_buf_get() returns NULL when the endpoint FIFO is empty. NVD: A transfer-completion event is queued from interrupt context and processed asynchronously by the driver thread; between queuing and processing, the endpoint FIFO can be drained by host-controlled control flow — in particular udc_setup_received() drains the...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260712T221257Z/items/CVE-2026-10656.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "vendor/product: zephyrproject / zephyr",
      "source_published_impact": "Source describes service availability risk. Possible impact: The affected service may become unavailable or unreliable.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The MAX32xxx USB device controller driver (drivers/usb/udc/udc_max32.c, compatible adi_max32_usbhs) dereferenced an endpoint buffer in its OUT and IN transfer-completion handlers without checking it for NULL. NVD: udc_event_xfer_out_done() called net_buf_add(buf, ep_request->actlen) immediately after buf = udc_buf_get(ep_cfg), where udc_buf_get() returns NULL when the endpoint FIFO is empty. NVD: A transfer-completion event is queued from interrupt context and processed asynchronously by the driver thread; between queuing and processing, the endpoint FIFO can be drained by host-controlled control flow — in particular udc_setup_received() drains the...",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-10656/timeline.json",
      "vendor": "zephyrproject"
    },
    {
      "affected_label": "zephyrproject / zephyr",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-10657/",
      "current_public_safe_latest": false,
      "cvss_score": 3.7,
      "cvss_severity": "LOW",
      "epss_percentile": 0.15377,
      "epss_score": 0.00243,
      "first_observed_at": "2026-07-12T16:15:44.451858+00:00",
      "id": "CVE-2026-10657",
      "impact_tags": [
        "information exposure review",
        "service availability review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-12T22:10:37.281882+00:00",
      "latest_item_url": null,
      "product": "zephyr",
      "public_safe_summary": "NVD: Zephyr's DNS resolver detects mDNS (.local) queries in dns_resolve_name_internal() (subsys/net/lib/dns/resolve.c) with memcmp(strrchr(query, '.'), \".local\", 7), which always reads a fixed 7 bytes from the suffix pointer. NVD: When the resolved hostname's final label is shorter than 7 bytes (e.g. NVD: names ending in .org, .com, .net, .io, or a trailing dot), the comparison reads 1-2 bytes past the string's NUL terminator.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260712T221257Z/items/CVE-2026-10657.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "vendor/product: zephyrproject / zephyr",
      "source_published_impact": "Source describes information exposure review · service availability risk. Possible impact: An attacker may be able to access information that should not be exposed.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Zephyr's DNS resolver detects mDNS (.local) queries in dns_resolve_name_internal() (subsys/net/lib/dns/resolve.c) with memcmp(strrchr(query, '.'), \".local\", 7), which always reads a fixed 7 bytes from the suffix pointer. NVD: When the resolved hostname's final label is shorter than 7 bytes (e.g. NVD: names ending in .org, .com, .net, .io, or a trailing dot), the comparison reads 1-2 bytes past the string's NUL terminator.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-10657/timeline.json",
      "vendor": "zephyrproject"
    },
    {
      "affected_label": "zephyrproject / zephyr",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-10659/",
      "current_public_safe_latest": false,
      "cvss_score": 4.7,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.00933,
      "epss_score": 0.00098,
      "first_observed_at": "2026-07-14T10:57:43.777280+00:00",
      "id": "CVE-2026-10659",
      "impact_tags": [
        "service availability review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-14T10:57:43.777280+00:00",
      "latest_item_url": null,
      "product": "zephyr",
      "public_safe_summary": "NVD: The Dhara flash translation layer disk driver (drivers/disk/ftl_dhara.c) implemented the dhara_nand_ callbacks so that, on a flash error, the error code was written unconditionally through the caller-supplied dhara_error_t err pointer (e.g. NVD: *err = DHARA_E_ECC in dhara_nand_read, and similar in dhara_nand_erase/prog/copy). NVD: The upstream Dhara library calls these callbacks with err == NULL along its journal-resume binary search: find_last_checkblock() invokes find_checkblock(j, mid, &found, NULL), which forwards the NULL pointer into dhara_nand_read().",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260714T110007Z/items/CVE-2026-10659.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: zephyrproject / zephyr; affected version context: 4.4.0",
      "source_published_impact": "Source describes service availability risk. Possible impact: The affected service may become unavailable or unreliable.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Dhara flash translation layer disk driver (drivers/disk/ftl_dhara.c) implemented the dhara_nand_ callbacks so that, on a flash error, the error code was written unconditionally through the caller-supplied dhara_error_t err pointer (e.g. NVD: *err = DHARA_E_ECC in dhara_nand_read, and similar in dhara_nand_erase/prog/copy). NVD: The upstream Dhara library calls these callbacks with err == NULL along its journal-resume binary search: find_last_checkblock() invokes find_checkblock(j, mid, &found, NULL), which forwards the NULL pointer into dhara_nand_read().",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-10659/timeline.json",
      "vendor": "zephyrproject"
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-10660/",
      "current_public_safe_latest": false,
      "cvss_score": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.05481,
      "epss_score": 0.00159,
      "first_observed_at": "2026-07-18T16:13:43.366233+00:00",
      "id": "CVE-2026-10660",
      "impact_tags": [
        "service availability review",
        "memory safety review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-18T16:13:43.366233+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Bluetooth BAP Broadcast Assistant GATT client in subsys/bluetooth/audio/bap_broadcast_assistant.c reassembled remote Broadcast Receive State data into a single file-static net_buf_simple (att_buf, BT_ATT_MAX_ATTRIBUTE_LEN = 512 bytes) shared by all... NVD: When the device acts as a Broadcast Assistant connected to multiple Scan Delegator peripherals, notification and long-read callbacks from different connections interleave on the shared buffer: the append in notify_handler (net_buf_simple_add_mem at the... NVD: Even below the overflow threshold, one connection's net_buf_simple_reset zeroes the shared length while another connection's reassembly and GATT read offset are in flight, mixing one peer's data into another's parse.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260718T161545Z/items/CVE-2026-10660.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes service availability risk · memory safety review. Possible impact: The affected service may become unavailable or unreliable.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Bluetooth BAP Broadcast Assistant GATT client in subsys/bluetooth/audio/bap_broadcast_assistant.c reassembled remote Broadcast Receive State data into a single file-static net_buf_simple (att_buf, BT_ATT_MAX_ATTRIBUTE_LEN = 512 bytes) shared by all... NVD: When the device acts as a Broadcast Assistant connected to multiple Scan Delegator peripherals, notification and long-read callbacks from different connections interleave on the shared buffer: the append in notify_handler (net_buf_simple_add_mem at the... NVD: Even below the overflow threshold, one connection's net_buf_simple_reset zeroes the shared length while another connection's reassembly and GATT read offset are in flight, mixing one peer's data into another's parse.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-10660/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "zephyrproject / zephyr",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-10663/",
      "current_public_safe_latest": false,
      "cvss_score": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.05412,
      "epss_score": 0.00159,
      "first_observed_at": "2026-07-19T16:14:19.593713+00:00",
      "id": "CVE-2026-10663",
      "impact_tags": [
        "service availability review",
        "memory safety review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-19T16:14:19.593713+00:00",
      "latest_item_url": null,
      "product": "zephyr",
      "public_safe_summary": "NVD: In Zephyr's experimental USB host stack (CONFIG_USB_HOST_STACK), usbh_device_disconnect() (subsys/usb/host/usbh_device.c) freed the root usb_device slab object without clearing the cached pointer ctx->root. NVD: The bus removal handler dev_removed_handler() (subsys/usb/host/usbh_core.c) decides what to tear down solely from ctx->root, checking only that it is non-NULL. NVD: Because UHC controller drivers (e.g.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260719T161618Z/items/CVE-2026-10663.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: zephyrproject / zephyr",
      "source_published_impact": "Source describes service availability risk · memory safety review. Possible impact: The affected service may become unavailable or unreliable.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: In Zephyr's experimental USB host stack (CONFIG_USB_HOST_STACK), usbh_device_disconnect() (subsys/usb/host/usbh_device.c) freed the root usb_device slab object without clearing the cached pointer ctx->root. NVD: The bus removal handler dev_removed_handler() (subsys/usb/host/usbh_core.c) decides what to tear down solely from ctx->root, checking only that it is non-NULL. NVD: Because UHC controller drivers (e.g.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-10663/timeline.json",
      "vendor": "zephyrproject"
    },
    {
      "affected_label": "zephyrproject / zephyr",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-10664/",
      "current_public_safe_latest": false,
      "cvss_score": 5.0,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.04456,
      "epss_score": 0.00148,
      "first_observed_at": "2026-07-19T16:14:19.593713+00:00",
      "id": "CVE-2026-10664",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-19T16:14:19.593713+00:00",
      "latest_item_url": null,
      "product": "zephyr",
      "public_safe_summary": "NVD: The nRF70 Wi-Fi driver's power-save event handler nrf_wifi_event_proc_get_power_save_info() in drivers/wifi/nrf_wifi/src/wifi_mgmt.c copied TWT (Target Wake Time) flow entries from an nrf_wifi_umac_event_power_save_info event into the fixed-size... NVD: When num_twt_flows exceeds 8, the handler writes past the destination array (which is typically on the caller's stack, e.g. NVD: the wifi ps shell command) -- an out-of-bounds write of ~40-byte TWT entries -- and reads twt_flow_info[i] past the event buffer.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260719T161618Z/items/CVE-2026-10664.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: zephyrproject / zephyr",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The nRF70 Wi-Fi driver's power-save event handler nrf_wifi_event_proc_get_power_save_info() in drivers/wifi/nrf_wifi/src/wifi_mgmt.c copied TWT (Target Wake Time) flow entries from an nrf_wifi_umac_event_power_save_info event into the fixed-size... NVD: When num_twt_flows exceeds 8, the handler writes past the destination array (which is typically on the caller's stack, e.g. NVD: the wifi ps shell command) -- an out-of-bounds write of ~40-byte TWT entries -- and reads twt_flow_info[i] past the event buffer.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-10664/timeline.json",
      "vendor": "zephyrproject"
    },
    {
      "affected_label": "zephyrproject / zephyr",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-10665/",
      "current_public_safe_latest": false,
      "cvss_score": 7.4,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.3043,
      "epss_score": 0.00382,
      "first_observed_at": "2026-07-19T16:14:19.593713+00:00",
      "id": "CVE-2026-10665",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-19T16:14:19.593713+00:00",
      "latest_item_url": null,
      "product": "zephyr",
      "public_safe_summary": "NVD: The call net_buf_linearize(buf->data, data_len, pkt->buffer, ..., data_len) passed the attacker-derived data_len as both the destination capacity and the copy length, defeating the function's internal len = min(len, dst_len) bound. NVD: data_len is derived from the received UDP datagram length and is only lower-bounded by wg_ctrl_recv() (no upper bound). NVD: When data_len exceeds CONFIG_WIREGUARD_BUF_LEN — e.g.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260719T161618Z/items/CVE-2026-10665.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: zephyrproject / zephyr; affected version context: 4.4.0",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The call net_buf_linearize(buf->data, data_len, pkt->buffer, ..., data_len) passed the attacker-derived data_len as both the destination capacity and the copy length, defeating the function's internal len = min(len, dst_len) bound. NVD: data_len is derived from the received UDP datagram length and is only lower-bounded by wg_ctrl_recv() (no upper bound). NVD: When data_len exceeds CONFIG_WIREGUARD_BUF_LEN — e.g.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-10665/timeline.json",
      "vendor": "zephyrproject"
    },
    {
      "affected_label": "zephyrproject / zephyr",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-10666/",
      "current_public_safe_latest": false,
      "cvss_score": 8.1,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.30496,
      "epss_score": 0.00382,
      "first_observed_at": "2026-07-19T16:14:19.593713+00:00",
      "id": "CVE-2026-10666",
      "impact_tags": [
        "service availability review",
        "memory safety review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-19T16:14:19.593713+00:00",
      "latest_item_url": null,
      "product": "zephyr",
      "public_safe_summary": "NVD: parse_ipv4() in subsys/net/ip/utils.c (reached via net_ipaddr_parse() for strings of the form \"a.b.c.d:port\") copies the port substring into a fixed 17-byte stack buffer (char ipaddr[NET_IPV4_ADDR_LEN + 1]) using a length of str_len - end - 1, where str_len... NVD: Because the destination size is never consulted, a crafted address string with a long suffix after the colon (e.g. NVD: \"1.2.3.4:\" followed by hundreds of bytes) causes an out-of-bounds stack write whose length and contents are fully attacker-controlled (memcpy of the suffix plus a trailing NUL), enabling memory corruption and at minimum a denial of service, and potentially...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260719T161618Z/items/CVE-2026-10666.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: zephyrproject / zephyr",
      "source_published_impact": "Source describes service availability risk · memory safety review. Possible impact: The affected service may become unavailable or unreliable.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: parse_ipv4() in subsys/net/ip/utils.c (reached via net_ipaddr_parse() for strings of the form \"a.b.c.d:port\") copies the port substring into a fixed 17-byte stack buffer (char ipaddr[NET_IPV4_ADDR_LEN + 1]) using a length of str_len - end - 1, where str_len... NVD: Because the destination size is never consulted, a crafted address string with a long suffix after the colon (e.g. NVD: \"1.2.3.4:\" followed by hundreds of bytes) causes an out-of-bounds stack write whose length and contents are fully attacker-controlled (memcpy of the suffix plus a trailing NUL), enabling memory corruption and at minimum a denial of service, and potentially...",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-10666/timeline.json",
      "vendor": "zephyrproject"
    },
    {
      "affected_label": "zephyrproject / zephyr",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-10667/",
      "current_public_safe_latest": false,
      "cvss_score": 7.8,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.01446,
      "epss_score": 0.00109,
      "first_observed_at": "2026-07-19T16:14:19.593713+00:00",
      "id": "CVE-2026-10667",
      "impact_tags": [
        "privilege boundary review",
        "service availability review",
        "memory safety review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-19T16:14:19.593713+00:00",
      "latest_item_url": null,
      "product": "zephyr",
      "public_safe_summary": "NVD: Zephyr's dynamic kernel-object tracking (kernel/userspace/userspace.c, formerly kernel/userspace.c) maintains a doubly-linked list (obj_list) of dynamically allocated kernel objects. NVD: Iteration over this list in k_object_wordlist_foreach() was performed under lists_lock using the SAFE iterator (which caches the next node), but list removal and freeing of nodes was performed under different, disjoint spinlocks: objfree_lock in... NVD: On an SMP system, while one CPU iterated obj_list under lists_lock, another CPU could unlink and k_free() the dyn_obj node that the iterator had cached as its next pointer, causing the iterator to dereference freed kernel memory (use-after-free / dangling...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260719T161618Z/items/CVE-2026-10667.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: zephyrproject / zephyr",
      "source_published_impact": "Source describes privilege escalation risk · service availability risk · memory safety review. Possible impact: The affected service may become unavailable or unreliable.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Zephyr's dynamic kernel-object tracking (kernel/userspace/userspace.c, formerly kernel/userspace.c) maintains a doubly-linked list (obj_list) of dynamically allocated kernel objects. NVD: Iteration over this list in k_object_wordlist_foreach() was performed under lists_lock using the SAFE iterator (which caches the next node), but list removal and freeing of nodes was performed under different, disjoint spinlocks: objfree_lock in... NVD: On an SMP system, while one CPU iterated obj_list under lists_lock, another CPU could unlink and k_free() the dyn_obj node that the iterator had cached as its next pointer, causing the iterator to dereference freed kernel memory (use-after-free / dangling...",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-10667/timeline.json",
      "vendor": "zephyrproject"
    },
    {
      "affected_label": "zephyrproject / zephyr",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-10668/",
      "current_public_safe_latest": false,
      "cvss_score": 2.4,
      "cvss_severity": "LOW",
      "epss_percentile": 0.05412,
      "epss_score": 0.00159,
      "first_observed_at": "2026-07-19T16:14:19.593713+00:00",
      "id": "CVE-2026-10668",
      "impact_tags": [
        "information exposure review",
        "service availability review",
        "memory safety review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-19T16:14:19.593713+00:00",
      "latest_item_url": null,
      "product": "zephyr",
      "public_safe_summary": "NVD: The Nuvoton NuMaker HSUSBD USB device-controller driver (drivers/usb/udc/udc_numaker.c) armed the control Data IN stage unconditionally (base->CEPTXCNT = len in numaker_hsusbd_ep_trigger). NVD: Because the HSUSBD hardware cannot disarm a control Data IN already armed for a previous transfer, a USB host that cancels an in-flight control transfer (timeout) and then issues a new SETUP packet can drive the driver out of sync: stale data may be... NVD: A malicious or buggy host (physical/adjacent attacker driving the bus) can repeatedly cancel-and-re-SETUP to wedge the device's USB control endpoint, denying service to the device's USB function (the device stops enumerating/responding on the control pipe)...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260719T161618Z/items/CVE-2026-10668.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: zephyrproject / zephyr",
      "source_published_impact": "Source describes information exposure review · service availability risk · memory safety review. Possible impact: An attacker may be able to access information that should not be exposed.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Nuvoton NuMaker HSUSBD USB device-controller driver (drivers/usb/udc/udc_numaker.c) armed the control Data IN stage unconditionally (base->CEPTXCNT = len in numaker_hsusbd_ep_trigger). NVD: Because the HSUSBD hardware cannot disarm a control Data IN already armed for a previous transfer, a USB host that cancels an in-flight control transfer (timeout) and then issues a new SETUP packet can drive the driver out of sync: stale data may be... NVD: A malicious or buggy host (physical/adjacent attacker driving the bus) can repeatedly cancel-and-re-SETUP to wedge the device's USB control endpoint, denying service to the device's USB function (the device stops enumerating/responding on the control pipe)...",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-10668/timeline.json",
      "vendor": "zephyrproject"
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-10681/",
      "current_public_safe_latest": false,
      "cvss_score": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.00198,
      "epss_score": 0.00079,
      "first_observed_at": "2026-08-01T10:51:40.555213+00:00",
      "id": "CVE-2026-10681",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-01T10:51:40.555213+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: In Zephyr's userspace dynamic-objects subsystem, thread_idx_alloc() in kernel/userspace/userspace.c allocated a new thread permission index from the global _thread_idx_map[] bitmap without holding lists_lock. NVD: On SMP systems, two user-mode threads invoking the k_object_alloc(K_OBJ_THREAD) syscall concurrently can both observe the same low free bit, perform the same non-atomic RMW to clear it, and return the identical tidx. NVD: The two newly created K_OBJ_THREAD objects are then assigned the same thread_id, so the two user threads alias a single bit position in every kernel object's perms[] bitfield: any subsequent grant of access on a kernel object to one thread is implicitly a...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260801T105618Z/items/CVE-2026-10681.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: In Zephyr's userspace dynamic-objects subsystem, thread_idx_alloc() in kernel/userspace/userspace.c allocated a new thread permission index from the global _thread_idx_map[] bitmap without holding lists_lock. NVD: On SMP systems, two user-mode threads invoking the k_object_alloc(K_OBJ_THREAD) syscall concurrently can both observe the same low free bit, perform the same non-atomic RMW to clear it, and return the identical tidx. NVD: The two newly created K_OBJ_THREAD objects are then assigned the same thread_id, so the two user threads alias a single bit position in every kernel object's perms[] bitfield: any subsequent grant of access on a kernel object to one thread is implicitly a...",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-10681/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-10686/",
      "current_public_safe_latest": false,
      "cvss_score": 5.8,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.15971,
      "epss_score": 0.00247,
      "first_observed_at": "2026-08-07T16:11:58.676122+00:00",
      "id": "CVE-2026-10686",
      "impact_tags": [
        "service availability review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-07T16:11:58.676122+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Zephyr's IPv6 forwarding path re-sent routed unicast packets without ever decrementing the IPv6 hop limit. NVD: Both routing branches of ipv6_route_packet() (subsys/net/ip) were affected: the explicit-route path (net_route_packet()) and the on-link cross-interface path (net_route_packet_if()). NVD: Each set the packet forwarding flag and called net_send_data() with the hop limit untouched and no expiry check.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260807T162046Z/items/CVE-2026-10686.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes service availability risk. Possible impact: The affected service may become unavailable or unreliable.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Zephyr's IPv6 forwarding path re-sent routed unicast packets without ever decrementing the IPv6 hop limit. NVD: Both routing branches of ipv6_route_packet() (subsys/net/ip) were affected: the explicit-route path (net_route_packet()) and the on-link cross-interface path (net_route_packet_if()). NVD: Each set the packet forwarding flag and called net_send_data() with the hop limit untouched and no expiry check.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-10686/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-10709/",
      "current_public_safe_latest": false,
      "cvss_score": 7.8,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.04284,
      "epss_score": 0.00145,
      "first_observed_at": "2026-08-11T10:14:04.199465+00:00",
      "id": "CVE-2026-10709",
      "impact_tags": [
        "code execution review",
        "memory safety review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-11T10:14:04.199465+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A maliciously crafted FBX file, when parsed through Autodesk FBX SDK, can trigger a stack-based buffer overflow vulnerability in fbxsdk::FbxIO::BinaryReadSectionHeader. NVD: A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260811T102539Z/items/CVE-2026-10709.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes code execution review · memory safety review. Possible impact: An attacker may be able to run code or commands on affected systems.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A maliciously crafted FBX file, when parsed through Autodesk FBX SDK, can trigger a stack-based buffer overflow vulnerability in fbxsdk::FbxIO::BinaryReadSectionHeader. NVD: A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-10709/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-10710/",
      "current_public_safe_latest": false,
      "cvss_score": 7.8,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.04285,
      "epss_score": 0.00145,
      "first_observed_at": "2026-08-11T10:14:04.199465+00:00",
      "id": "CVE-2026-10710",
      "impact_tags": [
        "code execution review",
        "memory safety review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-11T10:14:04.199465+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A maliciously crafted FBX file, when parsed through Autodesk FBX SDK, can trigger a stack-based buffer overflow vulnerability in fbxsdk::ExtractDrive. NVD: A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260811T102539Z/items/CVE-2026-10710.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes code execution review · memory safety review. Possible impact: An attacker may be able to run code or commands on affected systems.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A maliciously crafted FBX file, when parsed through Autodesk FBX SDK, can trigger a stack-based buffer overflow vulnerability in fbxsdk::ExtractDrive. NVD: A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-10710/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-10724/",
      "current_public_safe_latest": false,
      "cvss_score": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.00632,
      "epss_score": 0.00092,
      "first_observed_at": "2026-07-26T22:15:56.881440+00:00",
      "id": "CVE-2026-10724",
      "impact_tags": [
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-27T06:45:51.031460+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Reviews Feed WordPress plugin before 2.6.5 does not neutralize WordPress shortcodes contained in third-party review content before rendering it through its dynamic block, allowing unauthenticated attackers to execute arbitrary shortcodes on pages that...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260727T065126Z/items/CVE-2026-10724.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes remote exposure · authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Reviews Feed WordPress plugin before 2.6.5 does not neutralize WordPress shortcodes contained in third-party review content before rendering it through its dynamic block, allowing unauthenticated attackers to execute arbitrary shortcodes on pages that...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-10724/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-10755/",
      "current_public_safe_latest": false,
      "cvss_score": 2.7,
      "cvss_severity": "LOW",
      "epss_percentile": 0.06486,
      "epss_score": 0.00168,
      "first_observed_at": "2026-07-26T22:15:56.881440+00:00",
      "id": "CVE-2026-10755",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-27T06:45:51.031460+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The All in One SEO WordPress plugin before 4.9.9 does not correctly restrict access to some of its AI integration REST API endpoints, allowing users with low-level privileges such as Contributors to overwrite or reset the site-wide AI integration state.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260727T065126Z/items/CVE-2026-10755.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The All in One SEO WordPress plugin before 4.9.9 does not correctly restrict access to some of its AI integration REST API endpoints, allowing users with low-level privileges such as Contributors to overwrite or reset the site-wide AI integration state.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-10755/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-10768/",
      "current_public_safe_latest": false,
      "cvss_score": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.25228,
      "epss_score": 0.00331,
      "first_observed_at": "2026-07-17T22:09:03.821896+00:00",
      "id": "CVE-2026-10768",
      "impact_tags": [
        "information exposure review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-17T22:09:03.821896+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Missing Authorization vulnerability in Drupal LocalGov Workflows allows Forceful Browsing. NVD: This issue affects LocalGov Workflows versions: from 0.0.0 to 1.6.0. OSV: LocalGov Workflows - Moderately critical - Information disclosure - SA-CONTRIB-2026-039",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260717T221101Z/items/CVE-2026-10768.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes information exposure review. Possible impact: An attacker may be able to access information that should not be exposed.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Missing Authorization vulnerability in Drupal LocalGov Workflows allows Forceful Browsing. NVD: This issue affects LocalGov Workflows versions: from 0.0.0 to 1.6.0. OSV: LocalGov Workflows - Moderately critical - Information disclosure - SA-CONTRIB-2026-039",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-10768/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-10769/",
      "current_public_safe_latest": false,
      "cvss_score": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.05756,
      "epss_score": 0.00162,
      "first_observed_at": "2026-07-17T22:09:03.821896+00:00",
      "id": "CVE-2026-10769",
      "impact_tags": [
        "XSS risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-17T22:09:03.821896+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Improper Neutralization of Input During Web Page Generation (\"Cross-site Scripting\") vulnerability in Drupal Commerce Core allows Stored XSS. NVD: This issue affects Commerce Core versions: from 3.3.0 to 3.3.6. OSV: Commerce Core - Moderately critical - Cross site scripting - SA-CONTRIB-2026-041",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260717T221101Z/items/CVE-2026-10769.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes XSS risk. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Improper Neutralization of Input During Web Page Generation (\"Cross-site Scripting\") vulnerability in Drupal Commerce Core allows Stored XSS. NVD: This issue affects Commerce Core versions: from 3.3.0 to 3.3.6. OSV: Commerce Core - Moderately critical - Cross site scripting - SA-CONTRIB-2026-041",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-10769/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-10770/",
      "current_public_safe_latest": false,
      "cvss_score": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.07847,
      "epss_score": 0.00181,
      "first_observed_at": "2026-07-17T22:09:03.821896+00:00",
      "id": "CVE-2026-10770",
      "impact_tags": [
        "XSS risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-17T22:09:03.821896+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Improper Neutralization of Input During Web Page Generation (\"Cross-site Scripting\") vulnerability in Drupal Anti-Spam by CleanTalk allows Reflected XSS. NVD: This issue affects Anti-Spam by CleanTalk versions: from 0.0.0 to 9.7.1. OSV: Anti-Spam by CleanTalk - Moderately critical - Cross site scripting - SA-CONTRIB-2026-042",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260717T221101Z/items/CVE-2026-10770.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes XSS risk. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Improper Neutralization of Input During Web Page Generation (\"Cross-site Scripting\") vulnerability in Drupal Anti-Spam by CleanTalk allows Reflected XSS. NVD: This issue affects Anti-Spam by CleanTalk versions: from 0.0.0 to 9.7.1. OSV: Anti-Spam by CleanTalk - Moderately critical - Cross site scripting - SA-CONTRIB-2026-042",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-10770/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "zephyrproject / zephyr",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-10773/",
      "current_public_safe_latest": false,
      "cvss_score": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.0722,
      "epss_score": 0.00175,
      "first_observed_at": "2026-08-08T09:56:53.105288+00:00",
      "id": "CVE-2026-10773",
      "impact_tags": [
        "service availability review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-08T09:56:53.105288+00:00",
      "latest_item_url": null,
      "product": "zephyr",
      "public_safe_summary": "NVD: The DHCPv4 client helper net_dhcpv4_msg_type_name() in subsys/net/lib/dhcpv4/dhcpv4.c indexes a static 8-element const char * name table after a faulty bounds check. NVD: The guard used msg_type <= sizeof(name) instead of msg_type <= ARRAY_SIZE(name); sizeof returns the byte size of the pointer array (32 on 32-bit, 64 on 64-bit targets) rather than the element count of 8, so message-type values from 9 up to that byte size pass... NVD: The msg_type value originates from the DHCP MESSAGE TYPE option, which is read as an unchecked raw byte from a received packet (net_pkt_read_u8) and passed unmodified into the lookup.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260808T100051Z/items/CVE-2026-10773.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: zephyrproject / zephyr",
      "source_published_impact": "Source describes service availability risk. Possible impact: The affected service may become unavailable or unreliable.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The DHCPv4 client helper net_dhcpv4_msg_type_name() in subsys/net/lib/dhcpv4/dhcpv4.c indexes a static 8-element const char * name table after a faulty bounds check. NVD: The guard used msg_type <= sizeof(name) instead of msg_type <= ARRAY_SIZE(name); sizeof returns the byte size of the pointer array (32 on 32-bit, 64 on 64-bit targets) rather than the element count of 8, so message-type values from 9 up to that byte size pass... NVD: The msg_type value originates from the DHCP MESSAGE TYPE option, which is read as an unchecked raw byte from a received packet (net_pkt_read_u8) and passed unmodified into the lookup.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-10773/timeline.json",
      "vendor": "zephyrproject"
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-10774/",
      "current_public_safe_latest": false,
      "cvss_score": 2.4,
      "cvss_severity": "LOW",
      "epss_percentile": 0.04835,
      "epss_score": 0.00152,
      "first_observed_at": "2026-08-09T09:59:30.349754+00:00",
      "id": "CVE-2026-10774",
      "impact_tags": [
        "service availability review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-09T09:59:30.349754+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Zephyr's Bluetooth Mesh subnet key management leaks one PSA Crypto key slot on every subnet-key teardown. NVD: In subsys/bluetooth/mesh/subnet.c, net_keys_create() imports the Private Beacon Key into a PSA key slot under CONFIG_BT_MESH_PRIV_BEACONS (enabled by default), but subnet_keys_destroy() guarded the matching psa_destroy_key() with CONFIG_BT_MESH_V1d1. NVD: That Kconfig symbol was removed when explicit Mesh 1.0.1 support was dropped, so the destroy branch became permanently dead code and the import is never balanced by a destroy.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260809T101323Z/items/CVE-2026-10774.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes service availability risk. Possible impact: The affected service may become unavailable or unreliable.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Zephyr's Bluetooth Mesh subnet key management leaks one PSA Crypto key slot on every subnet-key teardown. NVD: In subsys/bluetooth/mesh/subnet.c, net_keys_create() imports the Private Beacon Key into a PSA key slot under CONFIG_BT_MESH_PRIV_BEACONS (enabled by default), but subnet_keys_destroy() guarded the matching psa_destroy_key() with CONFIG_BT_MESH_V1d1. NVD: That Kconfig symbol was removed when explicit Mesh 1.0.1 support was dropped, so the destroy branch became permanently dead code and the import is never balanced by a destroy.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-10774/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-10818/",
      "current_public_safe_latest": false,
      "cvss_score": 8.1,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.34614,
      "epss_score": 0.0042,
      "first_observed_at": "2026-07-31T22:17:39.455090+00:00",
      "id": "CVE-2026-10818",
      "impact_tags": [
        "code execution review",
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-01T06:11:07.668739+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The WPForms Pro plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.10.1.1 via the ajax_chunk_upload_finalize function. NVD: This is due to the file type validation occurring after chunk metadata and file contents have already been written to disk, and the assembled file not being deleted upon validation failure. NVD: This makes it possible for unauthenticated attackers to upload files that may be executable, which makes remote code execution possible.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260801T061801Z/items/CVE-2026-10818.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes code execution review · remote exposure · authenticated boundary. Possible impact: A remote attacker may be able to run code or commands on affected systems.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The WPForms Pro plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.10.1.1 via the ajax_chunk_upload_finalize function. NVD: This is due to the file type validation occurring after chunk metadata and file contents have already been written to disk, and the assembled file not being deleted upon validation failure. NVD: This makes it possible for unauthenticated attackers to upload files that may be executable, which makes remote code execution possible.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-10818/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-10827/",
      "current_public_safe_latest": false,
      "cvss_score": 3.5,
      "cvss_severity": "LOW",
      "epss_percentile": 0.01271,
      "epss_score": 0.00106,
      "first_observed_at": "2026-08-08T04:31:15.594937+00:00",
      "id": "CVE-2026-10827",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-08T04:31:15.594937+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Spectra Legacy WordPress plugin before 2.20.0 does not validate or escape several block style attributes before using them to build the CSS it outputs on the front end, allowing users with the Contributor role and above to inject arbitrary CSS into the... NVD: The injected styles are served to anonymous visitors of those pages and can force external resource loads, deface/redress the page, or exfiltrate data via CSS attribute selectors. NVD: JavaScript execution is not possible at this role (the script-tag breakout is removed by KSES), so the impact is limited to CSS injection.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260808T043750Z/items/CVE-2026-10827.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Spectra Legacy WordPress plugin before 2.20.0 does not validate or escape several block style attributes before using them to build the CSS it outputs on the front end, allowing users with the Contributor role and above to inject arbitrary CSS into the... NVD: The injected styles are served to anonymous visitors of those pages and can force external resource loads, deface/redress the page, or exfiltrate data via CSS attribute selectors. NVD: JavaScript execution is not possible at this role (the script-tag breakout is removed by KSES), so the impact is limited to CSS injection.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-10827/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-10830/",
      "current_public_safe_latest": false,
      "cvss_score": 8.8,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.17074,
      "epss_score": 0.00257,
      "first_observed_at": "2026-07-13T06:32:51.098771+00:00",
      "id": "CVE-2026-10830",
      "impact_tags": [
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-13T06:32:51.098771+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The AllCoach WordPress plugin before 1.0.2 does not verify that an email address submitted to a public account-registration endpoint is not already associated with an existing user before overwriting that user's password, allowing unauthenticated attackers to...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260713T063521Z/items/CVE-2026-10830.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes remote exposure · authenticated boundary. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The AllCoach WordPress plugin before 1.0.2 does not verify that an email address submitted to a public account-registration endpoint is not already associated with an existing user before overwriting that user's password, allowing unauthenticated attackers to...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-10830/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-10834/",
      "current_public_safe_latest": false,
      "cvss_score": 4.6,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.03948,
      "epss_score": 0.00142,
      "first_observed_at": "2026-07-14T05:42:23.241208+00:00",
      "id": "CVE-2026-10834",
      "impact_tags": [
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-14T05:42:23.241208+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The WP Travel Engine WordPress plugin before 6.8.1 does not properly validate the source of a user-supplied profile image path before moving the file, allowing authenticated users with subscriber-level access and above to relocate arbitrary files within the... NVD: This removes the targeted media from its original location and can break content across the site.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260714T054512Z/items/CVE-2026-10834.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The WP Travel Engine WordPress plugin before 6.8.1 does not properly validate the source of a user-supplied profile image path before moving the file, allowing authenticated users with subscriber-level access and above to relocate arbitrary files within the... NVD: This removes the targeted media from its original location and can break content across the site.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-10834/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-10848/",
      "current_public_safe_latest": false,
      "cvss_score": 7.0,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.09421,
      "epss_score": 0.00195,
      "first_observed_at": "2026-08-09T09:59:30.349754+00:00",
      "id": "CVE-2026-10848",
      "impact_tags": [
        "service availability review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-09T15:51:11.168346+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The OCPP 1.6 client in subsys/net/lib/ocpp parsed inbound WAMP RPC frames in parse_rpc_msg() (subsys/net/lib/ocpp/ocpp_j.c) using a hand-rolled helper, extract_string_field(), that copied the message's uid and action fields with strncpy(out_buf, token + 1... NVD: Because strncpy does not NUL-terminate the destination when the source is at least outlen - 1 (127) bytes long, the subsequent strchr reads past the 128-byte destination buffer into adjacent stack memory; if a \" byte is found beyond the buffer, a one-byte... NVD: A related defect in extract_payload() runs strchr/strrchr over the receive buffer, which may not be NUL-terminated when a maximal-length frame fills it.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260809T155523Z/items/CVE-2026-10848.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes service availability risk. Possible impact: The affected service may become unavailable or unreliable.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The OCPP 1.6 client in subsys/net/lib/ocpp parsed inbound WAMP RPC frames in parse_rpc_msg() (subsys/net/lib/ocpp/ocpp_j.c) using a hand-rolled helper, extract_string_field(), that copied the message's uid and action fields with strncpy(out_buf, token + 1... NVD: Because strncpy does not NUL-terminate the destination when the source is at least outlen - 1 (127) bytes long, the subsequent strchr reads past the 128-byte destination buffer into adjacent stack memory; if a \" byte is found beyond the buffer, a one-byte... NVD: A related defect in extract_payload() runs strchr/strrchr over the receive buffer, which may not be NUL-terminated when a maximal-length frame fills it.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-10848/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "zephyrproject / zephyr",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-10849/",
      "current_public_safe_latest": false,
      "cvss_score": 8.2,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.20198,
      "epss_score": 0.0028,
      "first_observed_at": "2026-08-10T22:01:27.436532+00:00",
      "id": "CVE-2026-10849",
      "impact_tags": [
        "service availability review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-10T22:01:27.436532+00:00",
      "latest_item_url": null,
      "product": "zephyr",
      "public_safe_summary": "NVD: The hawkBit device management client in subsys/mgmt/hawkbit accumulates the body of an HTTP response from the update server into a heap buffer in response_json_cb() (subsys/mgmt/hawkbit/hawkbit.c). NVD: The buffer is sized to hold the received body bytes but reserves no space for a terminating NUL. NVD: When the full response has arrived, the code writes response_data[downloaded_size] = '\\0' — and whenever the accumulated body length equals the allocation, that terminator lands one byte past the end of the heap object (a heap-based out-of-bounds write...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260810T220919Z/items/CVE-2026-10849.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: zephyrproject / zephyr",
      "source_published_impact": "Source describes service availability risk. Possible impact: The affected service may become unavailable or unreliable.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The hawkBit device management client in subsys/mgmt/hawkbit accumulates the body of an HTTP response from the update server into a heap buffer in response_json_cb() (subsys/mgmt/hawkbit/hawkbit.c). NVD: The buffer is sized to hold the received body bytes but reserves no space for a terminating NUL. NVD: When the full response has arrived, the code writes response_data[downloaded_size] = '\\0' — and whenever the accumulated body length equals the allocation, that terminator lands one byte past the end of the heap object (a heap-based out-of-bounds write...",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-10849/timeline.json",
      "vendor": "zephyrproject"
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-10865/",
      "current_public_safe_latest": false,
      "cvss_score": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.29272,
      "epss_score": 0.0037,
      "first_observed_at": "2026-07-18T05:38:40.092323+00:00",
      "id": "CVE-2026-10865",
      "impact_tags": [
        "information exposure review",
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-18T07:15:27.585758+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Cost Calculator Builder plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.0.11 via the (template body). NVD: This makes it possible for unauthenticated attackers to extract the plaintext Stripe secret key, Razorpay secret key, and PayPal client_secret embedded in the page source of any page containing a calculator, enabling full control of the merchant's payment... NVD: This exposure only occurs when the 'use in all calculators' option is enabled for one or more payment gateways in the plugin's global settings.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260718T071858Z/items/CVE-2026-10865.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes information exposure review · remote exposure · authenticated boundary. Possible impact: A remote attacker may be able to access information that should not be exposed.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Cost Calculator Builder plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.0.11 via the (template body). NVD: This makes it possible for unauthenticated attackers to extract the plaintext Stripe secret key, Razorpay secret key, and PayPal client_secret embedded in the page source of any page containing a calculator, enabling full control of the merchant's payment... NVD: This exposure only occurs when the 'use in all calculators' option is enabled for one or more payment gateways in the plugin's global settings.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-10865/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-11340/",
      "current_public_safe_latest": false,
      "cvss_score": 8.3,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.09322,
      "epss_score": 0.00195,
      "first_observed_at": "2026-07-14T10:57:43.777280+00:00",
      "id": "CVE-2026-11340",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-14T10:57:43.777280+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Missing Authorization vulnerability in HAVELSAN Inc. NVD: Liman MYS allows Accessing Functionality Not Properly Constrained by ACLs. NVD: This issue affects Liman MYS: before release.Master.1107.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260714T110007Z/items/CVE-2026-11340.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Missing Authorization vulnerability in HAVELSAN Inc. NVD: Liman MYS allows Accessing Functionality Not Properly Constrained by ACLs. NVD: This issue affects Liman MYS: before release.Master.1107.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-11340/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-11348/",
      "current_public_safe_latest": false,
      "cvss_score": 8.1,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.08261,
      "epss_score": 0.00185,
      "first_observed_at": "2026-07-14T10:57:43.777280+00:00",
      "id": "CVE-2026-11348",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-14T10:57:43.777280+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Improper verification of cryptographic signature vulnerability in HAVELSAN Inc. NVD: Liman MYS allows Fake the Source of Data. NVD: This issue affects Liman MYS: before release.Master.1107.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260714T110007Z/items/CVE-2026-11348.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Improper verification of cryptographic signature vulnerability in HAVELSAN Inc. NVD: Liman MYS allows Fake the Source of Data. NVD: This issue affects Liman MYS: before release.Master.1107.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-11348/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-11349/",
      "current_public_safe_latest": false,
      "cvss_score": 8.6,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.24499,
      "epss_score": 0.00321,
      "first_observed_at": "2026-07-26T22:15:56.881440+00:00",
      "id": "CVE-2026-11349",
      "impact_tags": [
        "SQL injection risk",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-27T06:45:51.031460+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Modern Event Calendar Pro WordPress plugin before 7.34.0, Modern Events Calendar Lite WordPress plugin before 7.34.0 do not sanitise and escape a request parameter before using it in a SQL statement, through an AJAX action available to unauthenticated...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260727T065126Z/items/CVE-2026-11349.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes SQL injection risk · authenticated boundary. Possible impact: An attacker may be able to read or change database-backed application data.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Modern Event Calendar Pro WordPress plugin before 7.34.0, Modern Events Calendar Lite WordPress plugin before 7.34.0 do not sanitise and escape a request parameter before using it in a SQL statement, through an AJAX action available to unauthenticated...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-11349/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-11351/",
      "current_public_safe_latest": false,
      "cvss_score": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.1084,
      "epss_score": 0.00206,
      "first_observed_at": "2026-08-05T06:03:49.171468+00:00",
      "id": "CVE-2026-11351",
      "impact_tags": [
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-05T06:03:49.171468+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The ShinyStat Analytics WordPress plugin before 1.0.17 does not perform any authorization check on one of its REST API endpoints, allowing unauthenticated users to retrieve information about non-published (e.g. NVD: draft, pending or private) WooCommerce products.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260805T061218Z/items/CVE-2026-11351.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The ShinyStat Analytics WordPress plugin before 1.0.17 does not perform any authorization check on one of its REST API endpoints, allowing unauthenticated users to retrieve information about non-published (e.g. NVD: draft, pending or private) WooCommerce products.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-11351/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "haxx / curl",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-11352/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.59013,
      "epss_score": 0.0101,
      "first_observed_at": "2026-07-10T06:57:55.339390+00:00",
      "id": "CVE-2026-11352",
      "impact_tags": [
        "service availability review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-10T06:57:55.339390+00:00",
      "latest_item_url": null,
      "product": "curl",
      "public_safe_summary": "NVD: An issue in curl’s QUIC UDP receive function allows a malicious HTTP/3 server to trigger a remote denial of service against a curl or libcurl client. NVD: Because the helper function discards zero-length UDP datagrams before counting them toward the per-call packet budget, a connected QUIC peer can continuously stream empty datagrams to indefinitely stall the client. OSV: QUIC zero-length UDP datagrams busy-loop",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260710T070012Z/items/CVE-2026-11352.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: haxx / curl",
      "source_published_impact": "Source describes service availability risk. Possible impact: The affected service may become unavailable or unreliable.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: An issue in curl’s QUIC UDP receive function allows a malicious HTTP/3 server to trigger a remote denial of service against a curl or libcurl client. NVD: Because the helper function discards zero-length UDP datagrams before counting them toward the per-call packet budget, a connected QUIC peer can continuously stream empty datagrams to indefinitely stall the client. OSV: QUIC zero-length UDP datagrams busy-loop",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-11352/timeline.json",
      "vendor": "haxx"
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-11354/",
      "current_public_safe_latest": false,
      "cvss_score": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.15181,
      "epss_score": 0.00239,
      "first_observed_at": "2026-07-30T22:30:38.166118+00:00",
      "id": "CVE-2026-11354",
      "impact_tags": [
        "information exposure review",
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-30T22:30:38.166118+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Participants Database plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.7.8.3 via the 'id' parameter. NVD: This makes it possible for unauthenticated attackers to overwrite arbitrary participant records by numeric ID and redirect the private_id-bearing record-access link to an attacker-controlled email address, granting full read and edit access to the victim's... NVD: An attacker can harvest a valid nonce with a plain unauthenticated GET request to any page rendering the public signup or record form, then POST action=update with an arbitrary id value to overwrite any record; chaining a subsequent action=retrieve then...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260730T224832Z/items/CVE-2026-11354.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes information exposure review · remote exposure · authenticated boundary. Possible impact: A remote attacker may be able to access information that should not be exposed.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Participants Database plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.7.8.3 via the 'id' parameter. NVD: This makes it possible for unauthenticated attackers to overwrite arbitrary participant records by numeric ID and redirect the private_id-bearing record-access link to an attacker-controlled email address, granting full read and edit access to the victim's... NVD: An attacker can harvest a valid nonce with a plain unauthenticated GET request to any page rendering the public signup or record form, then POST action=update with an arbitrary id value to overwrite any record; chaining a subsequent action=retrieve then...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-11354/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-11359/",
      "current_public_safe_latest": false,
      "cvss_score": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.15841,
      "epss_score": 0.00246,
      "first_observed_at": "2026-07-16T05:57:17.509937+00:00",
      "id": "CVE-2026-11359",
      "impact_tags": [
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-16T05:57:17.509937+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Memberships and User Profiles for WooCommerce – ProfileGrid WooCommerce Integration plugin for WordPress is vulnerable to unauthorized plugin installation and activation in versions up to, and including, 3.4. NVD: This is due to a missing capability check and missing nonce validation on the pg_install_profilegrid() AJAX handler registered via wp_ajax_pg_install_profilegrid. NVD: This makes it possible for authenticated attackers, with Subscriber-level access and above, to install and activate the ProfileGrid plugin from wordpress.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260716T055845Z/items/CVE-2026-11359.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Memberships and User Profiles for WooCommerce – ProfileGrid WooCommerce Integration plugin for WordPress is vulnerable to unauthorized plugin installation and activation in versions up to, and including, 3.4. NVD: This is due to a missing capability check and missing nonce validation on the pg_install_profilegrid() AJAX handler registered via wp_ajax_pg_install_profilegrid. NVD: This makes it possible for authenticated attackers, with Subscriber-level access and above, to install and activate the ProfileGrid plugin from wordpress.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-11359/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-11366/",
      "current_public_safe_latest": false,
      "cvss_score": 3.7,
      "cvss_severity": "LOW",
      "epss_percentile": 0.09087,
      "epss_score": 0.00192,
      "first_observed_at": "2026-08-11T04:43:10.985977+00:00",
      "id": "CVE-2026-11366",
      "impact_tags": [
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-11T04:43:10.985977+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The MonsterInsights WordPress plugin before 11.1.0 does not correctly validate the signature on one of its unauthenticated AJAX actions: when the MonsterInsights WordPress plugin before 11.1.0 is not connected to Google Analytics the HMAC signing key is...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260811T044729Z/items/CVE-2026-11366.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes remote exposure · authenticated boundary. Possible impact: This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The MonsterInsights WordPress plugin before 11.1.0 does not correctly validate the signature on one of its unauthenticated AJAX actions: when the MonsterInsights WordPress plugin before 11.1.0 is not connected to Google Analytics the HMAC signing key is...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-11366/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-11371/",
      "current_public_safe_latest": false,
      "cvss_score": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.05855,
      "epss_score": 0.00162,
      "first_observed_at": "2026-07-23T06:13:21.015514+00:00",
      "id": "CVE-2026-11371",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-23T06:13:21.015514+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "CVE-2026-11371: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review. Human-readable risk label: defensive exposure review. CVSS 6.1 (MEDIUM) helps set defensive review priority. EPSS percentile is 6. Official references are linked for patch or mitigation review.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260723T061547Z/items/CVE-2026-11371.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-11371/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-11386/",
      "current_public_safe_latest": false,
      "cvss_score": 9.0,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.23955,
      "epss_score": 0.00317,
      "first_observed_at": "2026-07-23T11:21:51.498947+00:00",
      "id": "CVE-2026-11386",
      "impact_tags": [
        "code execution review",
        "admin privilege risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-23T11:21:51.498947+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: An input validation and injection vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu-advantage-tools). NVD: The client constructs APT source files (such as /etc/apt/sources.list.d/ubuntu-.list or their DEB822 equivalents) using data received directly from the contract server response via the directives.suites[] and directives.aptURL fields. NVD: Because the client utilizes Python's str.format() to write these files without performing escaping, validation, or newline character filtering, a malicious or tampered contract response containing embedded newline (\\n) characters can successfully inject...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260723T112431Z/items/CVE-2026-11386.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes code execution review · admin privilege risk. Possible impact: An attacker may gain root or administrative-level privileges on affected systems.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: An input validation and injection vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu-advantage-tools). NVD: The client constructs APT source files (such as /etc/apt/sources.list.d/ubuntu-.list or their DEB822 equivalents) using data received directly from the contract server response via the directives.suites[] and directives.aptURL fields. NVD: Because the client utilizes Python's str.format() to write these files without performing escaping, validation, or newline character filtering, a malicious or tampered contract response containing embedded newline (\\n) characters can successfully inject...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-11386/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-11405/",
      "current_public_safe_latest": false,
      "cvss_score": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.47612,
      "epss_score": 0.00668,
      "first_observed_at": "2026-07-13T17:24:46.617207+00:00",
      "id": "CVE-2026-11405",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-13T17:24:46.617207+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The web server binary /bin/httpd contains a hidden backdoor authentication mechanism in the login() function at 004c88b8. NVD: - The function contains a normal authentication path using MD5/hash-based password verification (prod_encode64/PasswordToMd5/check_rand_key). NVD: - After normal authentication fails, it calls GetValue(\"sys.rzadmin.password\") to read a backdoor password from the device configuration.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260713T172750Z/items/CVE-2026-11405.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The web server binary /bin/httpd contains a hidden backdoor authentication mechanism in the login() function at 004c88b8. NVD: - The function contains a normal authentication path using MD5/hash-based password verification (prod_encode64/PasswordToMd5/check_rand_key). NVD: - After normal authentication fails, it calls GetValue(\"sys.rzadmin.password\") to read a backdoor password from the device configuration.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-11405/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-11421/",
      "current_public_safe_latest": false,
      "cvss_score": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.25421,
      "epss_score": 0.00328,
      "first_observed_at": "2026-08-12T05:08:50.991993+00:00",
      "id": "CVE-2026-11421",
      "impact_tags": [
        "information exposure review",
        "SQL injection risk",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-12T05:08:50.991993+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The ERP: Complete HR, Accounting & CRM Suite with WooCommerce CRM Support plugin for WordPress is vulnerable to SQL Injection via the 'erpadvancefilter' parameter in all versions up to, and including, 1.17.4 due to insufficient escaping on the user supplied... NVD: The handler runs the value through sanitize_text_field, which preserves single quotes, and the downstream erp_crm_contact_advance_filter() function interpolates it directly into a single-quoted SQL WHERE clause before execution via $wpdb->get_results(). NVD: This makes it possible for authenticated attackers, with the plugin-supplied CRM Agent role (or higher CRM Manager / WordPress admin) and the erp_crm_list_contact capability, to append additional SQL queries into already existing queries that can be used to...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260812T051428Z/items/CVE-2026-11421.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes information exposure review · SQL injection risk · authenticated boundary. Possible impact: An attacker may be able to read or change database-backed application data.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The ERP: Complete HR, Accounting & CRM Suite with WooCommerce CRM Support plugin for WordPress is vulnerable to SQL Injection via the 'erpadvancefilter' parameter in all versions up to, and including, 1.17.4 due to insufficient escaping on the user supplied... NVD: The handler runs the value through sanitize_text_field, which preserves single quotes, and the downstream erp_crm_contact_advance_filter() function interpolates it directly into a single-quoted SQL WHERE clause before execution via $wpdb->get_results(). NVD: This makes it possible for authenticated attackers, with the plugin-supplied CRM Agent role (or higher CRM Manager / WordPress admin) and the erp_crm_list_contact capability, to append additional SQL queries into already existing queries that can be used to...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-11421/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-11563/",
      "current_public_safe_latest": false,
      "cvss_score": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.06037,
      "epss_score": 0.00165,
      "first_observed_at": "2026-07-21T06:08:28.817138+00:00",
      "id": "CVE-2026-11563",
      "impact_tags": [
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-21T06:08:28.817138+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Word Count and Social Shares WordPress plugin through 1.0 does not validate a user-supplied file path before deletion, nor does it have proper authorization or CSRF checks, allowing any authenticated user, such as a Subscriber, to delete arbitrary files... NVD: by deleting wp-config.php).",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260721T061518Z/items/CVE-2026-11563.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes authenticated boundary. Possible impact: This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Word Count and Social Shares WordPress plugin through 1.0 does not validate a user-supplied file path before deletion, nor does it have proper authorization or CSRF checks, allowing any authenticated user, such as a Subscriber, to delete arbitrary files... NVD: by deleting wp-config.php).",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-11563/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "haxx / curl",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-11564/",
      "current_public_safe_latest": false,
      "cvss_score": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.44987,
      "epss_score": 0.0061,
      "first_observed_at": "2026-07-10T06:57:55.339390+00:00",
      "id": "CVE-2026-11564",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-10T06:57:55.339390+00:00",
      "latest_item_url": null,
      "product": "curl",
      "public_safe_summary": "NVD: libcurl keeps previously used connections in a connection pool for subsequent transfers to reuse if one of them matches the setup. NVD: An easy handle that first uses default native CA trust can continue trusting the native platform store after the application switches that same handle to custom CA material for a later transfer. OSV: Native CA trust persist",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260710T070012Z/items/CVE-2026-11564.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: haxx / curl",
      "source_published_impact": "This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: libcurl keeps previously used connections in a connection pool for subsequent transfers to reuse if one of them matches the setup. NVD: An easy handle that first uses default native CA trust can continue trusting the native platform store after the application switches that same handle to custom CA material for a later transfer. OSV: Native CA trust persist",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-11564/timeline.json",
      "vendor": "haxx"
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-11567/",
      "current_public_safe_latest": false,
      "cvss_score": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.0793,
      "epss_score": 0.00181,
      "first_observed_at": "2026-07-21T06:08:28.817138+00:00",
      "id": "CVE-2026-11567",
      "impact_tags": [
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-21T06:08:28.817138+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The SureForms WordPress plugin before 2.11.1 does not properly validate the payment amount on forms that use a dynamically-sourced (variable/hidden) payment amount, allowing unauthenticated users to underpay for the configured product or subscription. NVD: Forms using a fixed configured price are not affected.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260721T061518Z/items/CVE-2026-11567.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The SureForms WordPress plugin before 2.11.1 does not properly validate the payment amount on forms that use a dynamically-sourced (variable/hidden) payment amount, allowing unauthenticated users to underpay for the configured product or subscription. NVD: Forms using a fixed configured price are not affected.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-11567/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-11571/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.16986,
      "epss_score": 0.00256,
      "first_observed_at": "2026-07-16T05:57:17.509937+00:00",
      "id": "CVE-2026-11571",
      "impact_tags": [
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-16T05:57:17.509937+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Everest Forms WordPress plugin before 3.5.0 does not reliably delete temporary CSV files generated during email-notification processing and leaves them publicly accessible in the uploads directory, allowing unauthenticated attackers to retrieve other...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260716T055845Z/items/CVE-2026-11571.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes remote exposure · authenticated boundary. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Everest Forms WordPress plugin before 3.5.0 does not reliably delete temporary CSV files generated during email-notification processing and leaves them publicly accessible in the uploads directory, allowing unauthenticated attackers to retrieve other...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-11571/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-11575/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.11087,
      "epss_score": 0.00208,
      "first_observed_at": "2026-07-24T06:06:41.160911+00:00",
      "id": "CVE-2026-11575",
      "impact_tags": [
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-24T06:06:41.160911+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The PhonePe Payment Solutions WordPress plugin before 3.1.0 does not properly verify the authenticity of incoming payment callbacks: the secret used to validate the callback signature is empty on sites configured through the current setup flow, so the... NVD: This allows unauthenticated attackers to forge a payment-success notification and mark unpaid WooCommerce orders as paid without any payment being made.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260724T061150Z/items/CVE-2026-11575.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes remote exposure · authenticated boundary. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The PhonePe Payment Solutions WordPress plugin before 3.1.0 does not properly verify the authenticity of incoming payment callbacks: the secret used to validate the callback signature is empty on sites configured through the current setup flow, so the... NVD: This allows unauthenticated attackers to forge a payment-success notification and mark unpaid WooCommerce orders as paid without any payment being made.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-11575/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-11579/",
      "current_public_safe_latest": false,
      "cvss_score": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.14827,
      "epss_score": 0.00237,
      "first_observed_at": "2026-07-22T06:07:21.492959+00:00",
      "id": "CVE-2026-11579",
      "impact_tags": [
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-22T06:07:21.492959+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Kali Forms — Contact Form & Drag-and-Drop Builder WordPress plugin before 2.4.17 does not verify that a file upload is made against an existing form configured with a file-upload field, accepting uploads regardless of whether any such form exists, which...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260722T060931Z/items/CVE-2026-11579.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Kali Forms — Contact Form & Drag-and-Drop Builder WordPress plugin before 2.4.17 does not verify that a file upload is made against an existing form configured with a file-upload field, accepting uploads regardless of whether any such form exists, which...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-11579/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-11580/",
      "current_public_safe_latest": false,
      "cvss_score": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.08774,
      "epss_score": 0.00189,
      "first_observed_at": "2026-07-22T06:07:21.492959+00:00",
      "id": "CVE-2026-11580",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-22T06:07:21.492959+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Kali Forms — Contact Form & Drag-and-Drop Builder WordPress plugin before 2.4.17 does not perform a per-object capability check in its post-duplication AJAX action, allowing users with Contributor-level access or above to duplicate any post (regardless of...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260722T060931Z/items/CVE-2026-11580.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Kali Forms — Contact Form & Drag-and-Drop Builder WordPress plugin before 2.4.17 does not perform a per-object capability check in its post-duplication AJAX action, allowing users with Contributor-level access or above to duplicate any post (regardless of...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-11580/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "haxx / curl",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-11586/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.54186,
      "epss_score": 0.0086,
      "first_observed_at": "2026-07-10T06:57:55.339390+00:00",
      "id": "CVE-2026-11586",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-10T06:57:55.339390+00:00",
      "latest_item_url": null,
      "product": "curl",
      "public_safe_summary": "NVD: By default, curl automatically responds to WebSocket PING frames. NVD: Because curl lacks an upper bound on memory allocation for unacknowledged frames, a malicious server can exhaust all available memory by flooding curl with rapid, sequential PING messages. OSV: WS Auto-PONG memory exhaustion",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260710T070012Z/items/CVE-2026-11586.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: haxx / curl",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: By default, curl automatically responds to WebSocket PING frames. NVD: Because curl lacks an upper bound on memory allocation for unacknowledged frames, a malicious server can exhaust all available memory by flooding curl with rapid, sequential PING messages. OSV: WS Auto-PONG memory exhaustion",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-11586/timeline.json",
      "vendor": "haxx"
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-11591/",
      "current_public_safe_latest": false,
      "cvss_score": 4.4,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.1646,
      "epss_score": 0.00251,
      "first_observed_at": "2026-07-18T05:38:40.092323+00:00",
      "id": "CVE-2026-11591",
      "impact_tags": [
        "XSS risk",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-18T07:15:27.585758+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Widgets for Google Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 13.3 due to insufficient input sanitization and output escaping. NVD: This makes it possible for authenticated attackers, with editor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. NVD: This only affects multi-site installations and installations where unfiltered_html has been disabled.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260718T071858Z/items/CVE-2026-11591.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes XSS risk · authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Widgets for Google Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 13.3 due to insufficient input sanitization and output escaping. NVD: This makes it possible for authenticated attackers, with editor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. NVD: This only affects multi-site installations and installations where unfiltered_html has been disabled.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-11591/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-11610/",
      "current_public_safe_latest": false,
      "cvss_score": 8.8,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.45861,
      "epss_score": 0.00627,
      "first_observed_at": "2026-07-14T05:42:23.241208+00:00",
      "id": "CVE-2026-11610",
      "impact_tags": [
        "service availability review",
        "memory safety review",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-14T05:42:23.241208+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A heap buffer overflow flaw was found in the SASL I/O layer of 389 Directory Server (389-ds-base). NVD: After a successful SASL bind with integrity protection (SSF > 0), an authenticated attacker can send a specially crafted oversized LDAP UNBIND packet that is copied into a 512-byte heap receive buffer without a bounds check in sasl_io_recv() in sasl_io.c. NVD: This allows up to approximately 2 megabytes of attacker-controlled data to overflow the buffer, causing a denial of service (server crash).",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260714T054512Z/items/CVE-2026-11610.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes service availability risk · memory safety review · authenticated boundary. Possible impact: The affected service may become unavailable or unreliable.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A heap buffer overflow flaw was found in the SASL I/O layer of 389 Directory Server (389-ds-base). NVD: After a successful SASL bind with integrity protection (SSF > 0), an authenticated attacker can send a specially crafted oversized LDAP UNBIND packet that is copied into a 512-byte heap receive buffer without a bounds check in sasl_io_recv() in sasl_io.c. NVD: This allows up to approximately 2 megabytes of attacker-controlled data to overflow the buffer, causing a denial of service (server crash).",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-11610/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-11756/",
      "current_public_safe_latest": false,
      "cvss_score": 10.0,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.37047,
      "epss_score": 0.00452,
      "first_observed_at": "2026-08-04T06:07:04.591309+00:00",
      "id": "CVE-2026-11756",
      "impact_tags": [
        "code execution review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-04T06:07:04.591309+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A Deserialization of Untrusted Data vulnerability affecting Station Launcher App in 3DEXPERIENCE platform from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2026x could lead to an unauthenticated remote code execution.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260804T061658Z/items/CVE-2026-11756.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes code execution review. Possible impact: An attacker may be able to run code or commands on affected systems.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A Deserialization of Untrusted Data vulnerability affecting Station Launcher App in 3DEXPERIENCE platform from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2026x could lead to an unauthenticated remote code execution.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-11756/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-11763/",
      "current_public_safe_latest": false,
      "cvss_score": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.1798,
      "epss_score": 0.00263,
      "first_observed_at": "2026-07-24T16:59:54.170943+00:00",
      "id": "CVE-2026-11763",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-24T16:59:54.170943+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Authorization bypass through User-Controlled key vulnerability in Gis Informatics Engineering Consulting Laboratory R&D and Software Services Inc. NVD: GisLab Laboratory Management System allows Exploitation of Trusted Identifiers. NVD: This issue affects GisLab Laboratory Management System: from 1.4.03 through 08072026.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260724T170351Z/items/CVE-2026-11763.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Authorization bypass through User-Controlled key vulnerability in Gis Informatics Engineering Consulting Laboratory R&D and Software Services Inc. NVD: GisLab Laboratory Management System allows Exploitation of Trusted Identifiers. NVD: This issue affects GisLab Laboratory Management System: from 1.4.03 through 08072026.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-11763/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-11766/",
      "current_public_safe_latest": false,
      "cvss_score": 8.0,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.15832,
      "epss_score": 0.00247,
      "first_observed_at": "2026-07-13T06:32:51.098771+00:00",
      "id": "CVE-2026-11766",
      "impact_tags": [
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-13T06:32:51.098771+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Ultimate Member WordPress plugin before 2.12.0 does not properly sanitise and escape the value of custom textarea profile fields before outputting it on user profiles, allowing authenticated users with Subscriber-level access and above to store JavaScript...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260713T063521Z/items/CVE-2026-11766.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes authenticated boundary. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Ultimate Member WordPress plugin before 2.12.0 does not properly sanitise and escape the value of custom textarea profile fields before outputting it on user profiles, allowing authenticated users with Subscriber-level access and above to store JavaScript...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-11766/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-11767/",
      "current_public_safe_latest": false,
      "cvss_score": 8.8,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.19755,
      "epss_score": 0.00276,
      "first_observed_at": "2026-07-28T06:05:50.269125+00:00",
      "id": "CVE-2026-11767",
      "impact_tags": [
        "XSS risk",
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-28T06:05:50.269125+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Free Builder for Elementor WordPress plugin before 1.6.7 does not sanitise submitted contact form field values before storing them and outputting them in the admin dashboard, allowing unauthenticated attackers to perform Stored Cross-Site Scripting...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260728T060840Z/items/CVE-2026-11767.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes XSS risk · remote exposure · authenticated boundary. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk · remote exposure · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Free Builder for Elementor WordPress plugin before 1.6.7 does not sanitise submitted contact form field values before storing them and outputting them in the admin dashboard, allowing unauthenticated attackers to perform Stored Cross-Site Scripting...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-11767/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-11770/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.40447,
      "epss_score": 0.00506,
      "first_observed_at": "2026-08-07T10:13:53.604723+00:00",
      "id": "CVE-2026-11770",
      "impact_tags": [
        "remote exposure relevant"
      ],
      "kev": false,
      "last_observed_at": "2026-08-07T10:13:53.604723+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A flaw was found in 389 Directory Server. NVD: An unauthenticated remote attacker can inject LDAP search filters into the CleanAllRUV replication status-check extended operation. NVD: Because the handler performs the search against cn=config with elevated replication plugin privileges and returns a boolean match result, the attacker can extract sensitive server configuration metadata, including replication bind DNs and password storage...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260807T102646Z/items/CVE-2026-11770.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes remote exposure. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A flaw was found in 389 Directory Server. NVD: An unauthenticated remote attacker can inject LDAP search filters into the CleanAllRUV replication status-check extended operation. NVD: Because the handler performs the search against cn=config with elevated replication plugin privileges and returns a boolean match result, the attacker can extract sensitive server configuration metadata, including replication bind DNs and password storage...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-11770/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-11782/",
      "current_public_safe_latest": false,
      "cvss_score": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.12648,
      "epss_score": 0.00221,
      "first_observed_at": "2026-08-06T06:07:21.988664+00:00",
      "id": "CVE-2026-11782",
      "impact_tags": [
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-06T06:07:21.988664+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Points and Rewards for WooCommerce WordPress plugin before 2.10.1 does not have authorisation checks in place on a wallet and points update action that is available to unauthenticated users, and does not verify that the requester owns the account being... NVD: Modifying the wallet balance additionally requires the companion Wallet System for WooCommerce Points and Rewards for WooCommerce WordPress plugin before 2.10.1 to be active.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260806T061754Z/items/CVE-2026-11782.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes remote exposure · authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Points and Rewards for WooCommerce WordPress plugin before 2.10.1 does not have authorisation checks in place on a wallet and points update action that is available to unauthenticated users, and does not verify that the requester owns the account being... NVD: Modifying the wallet balance additionally requires the companion Wallet System for WooCommerce Points and Rewards for WooCommerce WordPress plugin before 2.10.1 to be active.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-11782/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-11798/",
      "current_public_safe_latest": false,
      "cvss_score": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.10454,
      "epss_score": 0.00204,
      "first_observed_at": "2026-07-15T05:43:30.245469+00:00",
      "id": "CVE-2026-11798",
      "impact_tags": [
        "XSS risk",
        "remote exposure relevant",
        "authenticated boundary review",
        "user interaction review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-15T05:43:30.245469+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Social Share, Social Login and Social Comments Plugin – Super Socializer plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'heateor_mastodon_share' parameter in all versions up to, and including, 7.14.5 due to insufficient input... NVD: This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260715T054459Z/items/CVE-2026-11798.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes XSS risk · remote exposure · authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk · remote exposure · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Social Share, Social Login and Social Comments Plugin – Super Socializer plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'heateor_mastodon_share' parameter in all versions up to, and including, 7.14.5 due to insufficient input... NVD: This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-11798/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-11855/",
      "current_public_safe_latest": false,
      "cvss_score": 8.8,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.21921,
      "epss_score": 0.00301,
      "first_observed_at": "2026-07-13T06:32:51.098771+00:00",
      "id": "CVE-2026-11855",
      "impact_tags": [
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-13T06:32:51.098771+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Simple Membership WordPress plugin before 4.7.5 does not verify the authenticity of Stripe webhook requests when no signing secret is configured, nor escape a value taken from them before outputting it in an administrator notice, allowing unauthenticated...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260713T063521Z/items/CVE-2026-11855.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes remote exposure · authenticated boundary. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Simple Membership WordPress plugin before 4.7.5 does not verify the authenticity of Stripe webhook requests when no signing secret is configured, nor escape a value taken from them before outputting it in an administrator notice, allowing unauthenticated...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-11855/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "haxx / curl",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-11856/",
      "current_public_safe_latest": false,
      "cvss_score": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.6067,
      "epss_score": 0.01064,
      "first_observed_at": "2026-07-10T06:57:55.339390+00:00",
      "id": "CVE-2026-11856",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-10T06:57:55.339390+00:00",
      "latest_item_url": null,
      "product": "curl",
      "public_safe_summary": "NVD: Successfully using libcurl to do a transfer to a specific HTTP origin (hostA) with **Digest** authentication and then changing the origin to a different one (hostB) for a second transfer, reusing the same handle, makes libcurl wrongly pass on the... OSV: cross-origin Digest auth state leak OSV: Successfully using libcurl to do a transfer to a specific HTTP origin (hostA) with **Digest** authentication and then changing the origin to a different one (hostB) for a second transfer, reusing the same handle, makes libcurl wrongly pass on the...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260710T070012Z/items/CVE-2026-11856.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: haxx / curl",
      "source_published_impact": "This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Successfully using libcurl to do a transfer to a specific HTTP origin (hostA) with **Digest** authentication and then changing the origin to a different one (hostB) for a second transfer, reusing the same handle, makes libcurl wrongly pass on the... OSV: cross-origin Digest auth state leak OSV: Successfully using libcurl to do a transfer to a specific HTTP origin (hostA) with **Digest** authentication and then changing the origin to a different one (hostB) for a second transfer, reusing the same handle, makes libcurl wrongly pass on the...",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-11856/timeline.json",
      "vendor": "haxx"
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-11866/",
      "current_public_safe_latest": false,
      "cvss_score": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.00813,
      "epss_score": 0.00095,
      "first_observed_at": "2026-07-23T06:13:21.015514+00:00",
      "id": "CVE-2026-11866",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-23T06:13:21.015514+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Appointment Booking Plugin WordPress plugin before 5.6.3 does not validate a CSRF nonce on several state-changing actions handled by its central request dispatcher, allowing attackers to perform privileged actions, such as overwriting the booking-form...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260723T061547Z/items/CVE-2026-11866.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Appointment Booking Plugin WordPress plugin before 5.6.3 does not validate a CSRF nonce on several state-changing actions handled by its central request dispatcher, allowing attackers to perform privileged actions, such as overwriting the booking-form...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-11866/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-11867/",
      "current_public_safe_latest": false,
      "cvss_score": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.11586,
      "epss_score": 0.00212,
      "first_observed_at": "2026-08-06T06:07:21.988664+00:00",
      "id": "CVE-2026-11867",
      "impact_tags": [
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-06T06:07:21.988664+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Frontend Admin by DynamiApps WordPress plugin before 3.29.7 does not perform capability checks on its taxonomy term creation, modification, and deletion operations, allowing authenticated users with low privileges (such as Subscribers) to create, rename...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260806T061754Z/items/CVE-2026-11867.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Frontend Admin by DynamiApps WordPress plugin before 3.29.7 does not perform capability checks on its taxonomy term creation, modification, and deletion operations, allowing authenticated users with low privileges (such as Subscribers) to create, rename...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-11867/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-11868/",
      "current_public_safe_latest": false,
      "cvss_score": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.08018,
      "epss_score": 0.00182,
      "first_observed_at": "2026-07-26T22:15:56.881440+00:00",
      "id": "CVE-2026-11868",
      "impact_tags": [
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-27T06:45:51.031460+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The WP Travel WordPress plugin before 11.7.1 does not perform capability or ownership checks on its booking cancellation action, which is also exposed to unauthenticated users, allowing them to cancel arbitrary bookings on the site.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260727T065126Z/items/CVE-2026-11868.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The WP Travel WordPress plugin before 11.7.1 does not perform capability or ownership checks on its booking cancellation action, which is also exposed to unauthenticated users, allowing them to cancel arbitrary bookings on the site.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-11868/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-11869/",
      "current_public_safe_latest": false,
      "cvss_score": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.0916,
      "epss_score": 0.00193,
      "first_observed_at": "2026-07-16T05:57:17.509937+00:00",
      "id": "CVE-2026-11869",
      "impact_tags": [
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-16T05:57:17.509937+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The WP DSGVO Tools (GDPR) WordPress plugin before 3.1.40 does not perform an authorization check on the immediate-processing path of its data subject access request feature, allowing unauthenticated attackers to generate and download the full personal-data...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260716T055845Z/items/CVE-2026-11869.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes remote exposure · authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The WP DSGVO Tools (GDPR) WordPress plugin before 3.1.40 does not perform an authorization check on the immediate-processing path of its data subject access request feature, allowing unauthenticated attackers to generate and download the full personal-data...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-11869/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-11870/",
      "current_public_safe_latest": false,
      "cvss_score": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.08609,
      "epss_score": 0.00188,
      "first_observed_at": "2026-08-06T06:07:21.988664+00:00",
      "id": "CVE-2026-11870",
      "impact_tags": [
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-06T06:07:21.988664+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The WP Ghost (Hide My WP Ghost) WordPress plugin before 7.0.05 does not verify that client IP information comes from a trusted proxy before trusting attacker-controllable HTTP headers, allowing unauthenticated attackers to spoof their IP address to bypass the...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260806T061754Z/items/CVE-2026-11870.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes remote exposure · authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The WP Ghost (Hide My WP Ghost) WordPress plugin before 7.0.05 does not verify that client IP information comes from a trusted proxy before trusting attacker-controllable HTTP headers, allowing unauthenticated attackers to spoof their IP address to bypass the...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-11870/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-11872/",
      "current_public_safe_latest": false,
      "cvss_score": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.08266,
      "epss_score": 0.00185,
      "first_observed_at": "2026-08-08T15:50:31.311576+00:00",
      "id": "CVE-2026-11872",
      "impact_tags": [
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-09T04:40:09.231782+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Clever Mega Menu for Visual Composer WordPress plugin through 1.0.1 does not perform a nonce or capability check in an AJAX action that updates navigation menu item metadata, allowing any authenticated user, including Subscribers, to overwrite menu item...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260809T044412Z/items/CVE-2026-11872.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 3,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Clever Mega Menu for Visual Composer WordPress plugin through 1.0.1 does not perform a nonce or capability check in an AJAX action that updates navigation menu item metadata, allowing any authenticated user, including Subscribers, to overwrite menu item...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-11872/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-11875/",
      "current_public_safe_latest": false,
      "cvss_score": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.09159,
      "epss_score": 0.00193,
      "first_observed_at": "2026-07-16T05:57:17.509937+00:00",
      "id": "CVE-2026-11875",
      "impact_tags": [
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-16T05:57:17.509937+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The WP Support Plus Responsive Ticket System WordPress plugin through 9.1.2 does not sign or verify its guest-session cookie, allowing unauthenticated attackers to forge it and impersonate any ticket owner (identified by email address) to read, reply to, and...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260716T055845Z/items/CVE-2026-11875.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes remote exposure · authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The WP Support Plus Responsive Ticket System WordPress plugin through 9.1.2 does not sign or verify its guest-session cookie, allowing unauthenticated attackers to forge it and impersonate any ticket owner (identified by email address) to read, reply to, and...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-11875/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-11881/",
      "current_public_safe_latest": false,
      "cvss_score": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.07858,
      "epss_score": 0.00181,
      "first_observed_at": "2026-08-06T06:07:21.988664+00:00",
      "id": "CVE-2026-11881",
      "impact_tags": [
        "XSS risk"
      ],
      "kev": false,
      "last_observed_at": "2026-08-06T06:07:21.988664+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Fluent Forms WordPress plugin before 6.2.6 does not sanitise and escape one of its form field configuration settings before outputting it inside an inline script when a form is rendered, which could allow users with a role as low as Contributor (with... NVD: in a multisite setup) to perform Stored Cross-Site Scripting attacks that execute in the browser of any visitor who loads the form, including administrators previewing it.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260806T061754Z/items/CVE-2026-11881.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes XSS risk. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Fluent Forms WordPress plugin before 6.2.6 does not sanitise and escape one of its form field configuration settings before outputting it inside an inline script when a form is rendered, which could allow users with a role as low as Contributor (with... NVD: in a multisite setup) to perform Stored Cross-Site Scripting attacks that execute in the browser of any visitor who loads the form, including administrators previewing it.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-11881/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-11882/",
      "current_public_safe_latest": false,
      "cvss_score": 3.7,
      "cvss_severity": "LOW",
      "epss_percentile": 0.09062,
      "epss_score": 0.00192,
      "first_observed_at": "2026-08-08T04:31:15.594937+00:00",
      "id": "CVE-2026-11882",
      "impact_tags": [
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-08T04:31:15.594937+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Builderall for WordPress plugin before 3.0.2 does not bind the state value of its public OAuth authentication routes to the initiating user session, allowing unauthenticated attackers to complete the connection flow and overwrite the stored third-party... NVD: A durable overwrite requires the site to already be connected to a paid account.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260808T043750Z/items/CVE-2026-11882.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes remote exposure · authenticated boundary. Possible impact: This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Builderall for WordPress plugin before 3.0.2 does not bind the state value of its public OAuth authentication routes to the initiating user session, allowing unauthenticated attackers to complete the connection flow and overwrite the stored third-party... NVD: A durable overwrite requires the site to already be connected to a paid account.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-11882/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-11898/",
      "current_public_safe_latest": false,
      "cvss_score": 4.4,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.15848,
      "epss_score": 0.00246,
      "first_observed_at": "2026-07-18T05:38:40.092323+00:00",
      "id": "CVE-2026-11898",
      "impact_tags": [
        "XSS risk",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-18T07:15:27.585758+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The White Label CMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.7.12 due to insufficient input sanitization and output escaping. NVD: This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. NVD: This only affects multi-site installations and installations where unfiltered_html has been disabled.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260718T071858Z/items/CVE-2026-11898.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes XSS risk · authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The White Label CMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.7.12 due to insufficient input sanitization and output escaping. NVD: This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. NVD: This only affects multi-site installations and installations where unfiltered_html has been disabled.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-11898/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-11901/",
      "current_public_safe_latest": false,
      "cvss_score": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.07447,
      "epss_score": 0.00177,
      "first_observed_at": "2026-07-18T05:38:40.092323+00:00",
      "id": "CVE-2026-11901",
      "impact_tags": [
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-18T07:15:27.585758+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The WP Hotel Booking plugin for WordPress is vulnerable to Insufficient Verification of Data Authenticity in all versions up to, and including, 2.3.1. NVD: This is due to the web_hook_process_paypal_standard() IPN handler selecting its PayPal validation endpoint from the attacker-controlled $_REQUEST['test_ipn'] parameter, force-upgrading any pending transaction to completed when test_ipn=1, and omitting... NVD: This makes it possible for unauthenticated attackers to mark arbitrary hotel bookings as fully paid without submitting genuine payment to the merchant — either by routing IPN validation through PayPal's sandbox using a free sandbox account, or by replaying a...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260718T071858Z/items/CVE-2026-11901.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes remote exposure · authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The WP Hotel Booking plugin for WordPress is vulnerable to Insufficient Verification of Data Authenticity in all versions up to, and including, 2.3.1. NVD: This is due to the web_hook_process_paypal_standard() IPN handler selecting its PayPal validation endpoint from the attacker-controlled $_REQUEST['test_ipn'] parameter, force-upgrading any pending transaction to completed when test_ipn=1, and omitting... NVD: This makes it possible for unauthenticated attackers to mark arbitrary hotel bookings as fully paid without submitting genuine payment to the merchant — either by routing IPN validation through PayPal's sandbox using a free sandbox account, or by replaying a...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-11901/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-11908/",
      "current_public_safe_latest": false,
      "cvss_score": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.05757,
      "epss_score": 0.00162,
      "first_observed_at": "2026-07-17T22:09:03.821896+00:00",
      "id": "CVE-2026-11908",
      "impact_tags": [
        "XSS risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-17T22:09:03.821896+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Improper Neutralization of Input During Web Page Generation (\"Cross-site Scripting\") vulnerability in Drupal Tagify allows Stored XSS. NVD: This issue affects Tagify versions: from 0.0.0 to 1.2.52. OSV: Tagify - Moderately critical - Cross-site scripting (XSS) - SA-CONTRIB-2026-043",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260717T221101Z/items/CVE-2026-11908.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes XSS risk. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Improper Neutralization of Input During Web Page Generation (\"Cross-site Scripting\") vulnerability in Drupal Tagify allows Stored XSS. NVD: This issue affects Tagify versions: from 0.0.0 to 1.2.52. OSV: Tagify - Moderately critical - Cross-site scripting (XSS) - SA-CONTRIB-2026-043",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-11908/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-11909/",
      "current_public_safe_latest": false,
      "cvss_score": 3.3,
      "cvss_severity": "LOW",
      "epss_percentile": 0.05648,
      "epss_score": 0.00161,
      "first_observed_at": "2026-07-17T22:09:03.821896+00:00",
      "id": "CVE-2026-11909",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-17T22:09:03.821896+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Missing Authorization vulnerability in Drupal Examples for Developers allows Forceful Browsing. NVD: This issue affects Examples for Developers versions: from 0.0.0 to 4.0.6. OSV: Examples for Developers - Moderately critical - Access bypass - SA-CONTRIB-2026-044",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260717T221101Z/items/CVE-2026-11909.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Missing Authorization vulnerability in Drupal Examples for Developers allows Forceful Browsing. NVD: This issue affects Examples for Developers versions: from 0.0.0 to 4.0.6. OSV: Examples for Developers - Moderately critical - Access bypass - SA-CONTRIB-2026-044",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-11909/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-11922/",
      "current_public_safe_latest": false,
      "cvss_score": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.07715,
      "epss_score": 0.00179,
      "first_observed_at": "2026-07-30T22:30:38.166118+00:00",
      "id": "CVE-2026-11922",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-30T22:30:38.166118+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A vulnerability in zenml-io/zenml versions 0.57.0 through 0.94.2 allows an attacker to bypass rate-limiting on the POST /api/v1/login and self password-change endpoints by rotating the X-Forwarded-For header. NVD: The rate limiter keys requests by request.client.host, which is derived from the X-Forwarded-For header when Uvicorn is launched with --proxy-headers --forwarded-allow-ips *. NVD: This configuration allows clients to control the value of request.client.host, effectively bypassing rate-limiting protections.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260730T224832Z/items/CVE-2026-11922.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability in zenml-io/zenml versions 0.57.0 through 0.94.2 allows an attacker to bypass rate-limiting on the POST /api/v1/login and self password-change endpoints by rotating the X-Forwarded-For header. NVD: The rate limiter keys requests by request.client.host, which is derived from the X-Forwarded-For header when Uvicorn is launched with --proxy-headers --forwarded-allow-ips *. NVD: This configuration allows clients to control the value of request.client.host, effectively bypassing rate-limiting protections.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-11922/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-11946/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.30629,
      "epss_score": 0.00386,
      "first_observed_at": "2026-07-09T11:52:04.215901+00:00",
      "id": "CVE-2026-11946",
      "impact_tags": [
        "remote exposure relevant"
      ],
      "kev": false,
      "last_observed_at": "2026-07-09T11:52:04.215901+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: An unauthenticated remote attacker can exhaust server memory via the GetEndpoints Discovery Service in open62541. NVD: The endpointUrl field of GetEndpointsRequest is not validated for length. NVD: An attacker can declare an arbitrarily large string (up to ~4.09 GB via the UInt32 length field) delivered across intermediate chunks without ever sending the final chunk.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260709T115259Z/items/CVE-2026-11946.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes remote exposure. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: An unauthenticated remote attacker can exhaust server memory via the GetEndpoints Discovery Service in open62541. NVD: The endpointUrl field of GetEndpointsRequest is not validated for length. NVD: An attacker can declare an arbitrarily large string (up to ~4.09 GB via the UInt32 length field) delivered across intermediate chunks without ever sending the final chunk.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-11946/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-11961/",
      "current_public_safe_latest": false,
      "cvss_score": 8.1,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.13429,
      "epss_score": 0.00226,
      "first_observed_at": "2026-07-24T06:06:41.160911+00:00",
      "id": "CVE-2026-11961",
      "impact_tags": [
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-24T06:06:41.160911+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The User Registration & Membership WordPress plugin before 5.2.3 does not validate that the membership tier submitted during public registration is one of the tiers allowed by the registration form before assigning that tier's associated user role, allowing...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260724T061150Z/items/CVE-2026-11961.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes authenticated boundary. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The User Registration & Membership WordPress plugin before 5.2.3 does not validate that the membership tier submitted during public registration is one of the tiers allowed by the registration form before assigning that tier's associated user role, allowing...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-11961/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-11962/",
      "current_public_safe_latest": false,
      "cvss_score": 8.8,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.35127,
      "epss_score": 0.00435,
      "first_observed_at": "2026-07-13T06:32:51.098771+00:00",
      "id": "CVE-2026-11962",
      "impact_tags": [
        "code execution review",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-13T06:32:51.098771+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The FileOrganizer WordPress plugin before 1.2.0 does not validate the file type on several of its file-management operations, allowing authenticated users who have been granted file-manager access — which its premium add-on can extend to sub-administrator... NVD: This is an incomplete fix of CVE-2024-7985, which only added file-type validation to the upload operation.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260713T063521Z/items/CVE-2026-11962.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes code execution review · authenticated boundary. Possible impact: An attacker may be able to run code or commands on affected systems.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The FileOrganizer WordPress plugin before 1.2.0 does not validate the file type on several of its file-management operations, allowing authenticated users who have been granted file-manager access — which its premium add-on can extend to sub-administrator... NVD: This is an incomplete fix of CVE-2024-7985, which only added file-type validation to the upload operation.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-11962/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-11963/",
      "current_public_safe_latest": false,
      "cvss_score": 8.1,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.1006,
      "epss_score": 0.00201,
      "first_observed_at": "2026-07-20T06:28:37.060083+00:00",
      "id": "CVE-2026-11963",
      "impact_tags": [
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-20T06:28:37.060083+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The User Registration & Membership WordPress plugin before 5.2.2 does not perform an authorization check on a membership-upgrade action and derives the user to modify from a caller-supplied identifier instead of the current user, allowing any authenticated...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260720T063049Z/items/CVE-2026-11963.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes authenticated boundary. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The User Registration & Membership WordPress plugin before 5.2.2 does not perform an authorization check on a membership-upgrade action and derives the user to modify from a caller-supplied identifier instead of the current user, allowing any authenticated...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-11963/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-11964/",
      "current_public_safe_latest": false,
      "cvss_score": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.17546,
      "epss_score": 0.00261,
      "first_observed_at": "2026-07-20T06:28:37.060083+00:00",
      "id": "CVE-2026-11964",
      "impact_tags": [
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-20T06:28:37.060083+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The User Registration & Membership WordPress plugin before 5.2.2 does not verify the authenticity of incoming payment-provider webhook notifications before acting on them, allowing unauthenticated attackers to forge a payment-approved event and activate a...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260720T063049Z/items/CVE-2026-11964.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes remote exposure · authenticated boundary. Possible impact: This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The User Registration & Membership WordPress plugin before 5.2.2 does not verify the authenticity of incoming payment-provider webhook notifications before acting on them, allowing unauthenticated attackers to forge a payment-approved event and activate a...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-11964/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-11966/",
      "current_public_safe_latest": false,
      "cvss_score": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.07972,
      "epss_score": 0.00182,
      "first_observed_at": "2026-07-24T06:06:41.160911+00:00",
      "id": "CVE-2026-11966",
      "impact_tags": [
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-24T06:06:41.160911+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The User Registration & Membership WordPress plugin before 5.2.3 does not perform a capability check for unauthenticated callers on one of its membership payment actions and acts on a caller-supplied user identifier, allowing unauthenticated attackers to...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260724T061150Z/items/CVE-2026-11966.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes remote exposure · authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The User Registration & Membership WordPress plugin before 5.2.3 does not perform a capability check for unauthenticated callers on one of its membership payment actions and acts on a caller-supplied user identifier, allowing unauthenticated attackers to...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-11966/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-11974/",
      "current_public_safe_latest": false,
      "cvss_score": 8.6,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.39418,
      "epss_score": 0.00489,
      "first_observed_at": "2026-08-05T06:03:49.171468+00:00",
      "id": "CVE-2026-11974",
      "impact_tags": [
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-05T06:03:49.171468+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The wp-media-folder-addon WordPress plugin through 4.1.6 does not validate a user-supplied parameter before using it in a file read operation in two AJAX actions available to unauthenticated users, leading to Arbitrary File Disclosure and Server-Side Request... NVD: This is an incomplete fix of CVE-2026-9690, whose patch hardened only one of the affected cloud-storage handlers and left the others unpatched.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260805T061218Z/items/CVE-2026-11974.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes authenticated boundary. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The wp-media-folder-addon WordPress plugin through 4.1.6 does not validate a user-supplied parameter before using it in a file read operation in two AJAX actions available to unauthenticated users, leading to Arbitrary File Disclosure and Server-Side Request... NVD: This is an incomplete fix of CVE-2026-9690, whose patch hardened only one of the affected cloud-storage handlers and left the others unpatched.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-11974/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-11992/",
      "current_public_safe_latest": false,
      "cvss_score": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.19989,
      "epss_score": 0.0028,
      "first_observed_at": "2026-07-17T05:58:07.763993+00:00",
      "id": "CVE-2026-11992",
      "impact_tags": [
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-17T05:58:07.763993+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Easy Appointments plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.12.27. NVD: This is due to the plugin not properly verifying that a user is authorized to perform an action. NVD: This makes it possible for authenticated attackers, with author-level access and above, to cancel all upcoming appointments site-wide by marking every future appointment stored by the plugin as abandoned.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260717T060336Z/items/CVE-2026-11992.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Easy Appointments plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.12.27. NVD: This is due to the plugin not properly verifying that a user is authorized to perform an action. NVD: This makes it possible for authenticated attackers, with author-level access and above, to cancel all upcoming appointments site-wide by marking every future appointment stored by the plugin as abandoned.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-11992/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-12002/",
      "current_public_safe_latest": false,
      "cvss_score": 4.7,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.01136,
      "epss_score": 0.00102,
      "first_observed_at": "2026-07-15T11:03:27.604769+00:00",
      "id": "CVE-2026-12002",
      "impact_tags": [
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-15T11:03:27.604769+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Smash Balloon Social Photo Feed – Easy Social Feeds Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.11.1. NVD: This is due to missing or incorrect nonce validation on the maybe_connection_data function. NVD: This makes it possible for unauthenticated attackers to overwrite the site's Instagram and Facebook oEmbed access tokens via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260715T110622Z/items/CVE-2026-12002.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes remote exposure · authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Smash Balloon Social Photo Feed – Easy Social Feeds Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.11.1. NVD: This is due to missing or incorrect nonce validation on the maybe_connection_data function. NVD: This makes it possible for unauthenticated attackers to overwrite the site's Instagram and Facebook oEmbed access tokens via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-12002/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-12041/",
      "current_public_safe_latest": false,
      "cvss_score": 4.4,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.09119,
      "epss_score": 0.00193,
      "first_observed_at": "2026-07-15T05:43:30.245469+00:00",
      "id": "CVE-2026-12041",
      "impact_tags": [
        "XSS risk",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-15T05:43:30.245469+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Chatra Live Chat + ChatBot + Cart Saver plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.0.12 due to insufficient input sanitization and output escaping. NVD: This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. NVD: This only affects multi-site installations and installations where unfiltered_html has been disabled.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260715T054459Z/items/CVE-2026-12041.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes XSS risk · authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Chatra Live Chat + ChatBot + Cart Saver plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.0.12 due to insufficient input sanitization and output escaping. NVD: This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. NVD: This only affects multi-site installations and installations where unfiltered_html has been disabled.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-12041/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "haxx / curl",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-12064/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.43299,
      "epss_score": 0.00574,
      "first_observed_at": "2026-07-10T06:57:55.339390+00:00",
      "id": "CVE-2026-12064",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-10T06:57:55.339390+00:00",
      "latest_item_url": null,
      "product": "curl",
      "public_safe_summary": "NVD: When a user invokes curl using a schemeless URL combined with --proto-default sftp (or scp), a disconnect occurs between the tool layer and libcurl. NVD: The tool layer incorrectly infers the URL scheme, which erroneously bypasses the initialization of critical SSH security options like CURLOPT_SSH_HOST_PUBLIC_KEY_SHA256 and CURLOPT_SSH_KNOWNHOSTS. NVD: Conversely, the libcurl runtime successfully honors CURLOPT_DEFAULT_PROTOCOL and establishes the connection via SFTP/SCP as specified.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260710T070012Z/items/CVE-2026-12064.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: haxx / curl",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: When a user invokes curl using a schemeless URL combined with --proto-default sftp (or scp), a disconnect occurs between the tool layer and libcurl. NVD: The tool layer incorrectly infers the URL scheme, which erroneously bypasses the initialization of critical SSH security options like CURLOPT_SSH_HOST_PUBLIC_KEY_SHA256 and CURLOPT_SSH_KNOWNHOSTS. NVD: Conversely, the libcurl runtime successfully honors CURLOPT_DEFAULT_PROTOCOL and establishes the connection via SFTP/SCP as specified.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-12064/timeline.json",
      "vendor": "haxx"
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-12080/",
      "current_public_safe_latest": false,
      "cvss_score": 7.3,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.03686,
      "epss_score": 0.00139,
      "first_observed_at": "2026-07-27T12:38:45.912501+00:00",
      "id": "CVE-2026-12080",
      "impact_tags": [
        "admin privilege risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-27T12:38:45.912501+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A flaw was found in the QEMU Guest Agent (qga). NVD: A local unprivileged user can exploit a vulnerability in the guest-ssh-add-authorized-keys command handler by manipulating symbolic links. NVD: This can occur either through a deterministic directory-symlink bypass or a Time-of-Check to Time-of-Use (TOCTOU) file-symlink race.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260727T124133Z/items/CVE-2026-12080.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes admin privilege risk. Possible impact: An attacker may gain root or administrative-level privileges on affected systems.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A flaw was found in the QEMU Guest Agent (qga). NVD: A local unprivileged user can exploit a vulnerability in the guest-ssh-add-authorized-keys command handler by manipulating symbolic links. NVD: This can occur either through a deterministic directory-symlink bypass or a Time-of-Check to Time-of-Use (TOCTOU) file-symlink race.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-12080/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-12081/",
      "current_public_safe_latest": false,
      "cvss_score": 5.0,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.03668,
      "epss_score": 0.00139,
      "first_observed_at": "2026-07-20T06:28:37.060083+00:00",
      "id": "CVE-2026-12081",
      "impact_tags": [
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-20T06:28:37.060083+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Database for Contact Form 7, WPforms, Elementor forms WordPress plugin before 1.5.2 does not restrict the PHP classes allowed when unserializing an attacker-supplied form-field value, allowing unauthenticated users to inject arbitrary PHP objects that are... NVD: This is an incomplete fix of CVE-2025-7384 and CVE-2026-2599, whose deserialization paths were hardened while the entry-editor file-field path was missed.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260720T063049Z/items/CVE-2026-12081.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Database for Contact Form 7, WPforms, Elementor forms WordPress plugin before 1.5.2 does not restrict the PHP classes allowed when unserializing an attacker-supplied form-field value, allowing unauthenticated users to inject arbitrary PHP objects that are... NVD: This is an incomplete fix of CVE-2025-7384 and CVE-2026-2599, whose deserialization paths were hardened while the entry-editor file-field path was missed.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-12081/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-12082/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.1521,
      "epss_score": 0.0024,
      "first_observed_at": "2026-07-30T06:01:44.452906+00:00",
      "id": "CVE-2026-12082",
      "impact_tags": [
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-30T06:01:44.452906+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Praison AI SEO WordPress plugin before 5.0.7 does not perform authorization checks on several of its REST API routes, allowing unauthenticated users to modify the permalink of any published post and to read Praison AI SEO WordPress plugin before 5.0.7...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260730T060504Z/items/CVE-2026-12082.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes authenticated boundary. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Praison AI SEO WordPress plugin before 5.0.7 does not perform authorization checks on several of its REST API routes, allowing unauthenticated users to modify the permalink of any published post and to read Praison AI SEO WordPress plugin before 5.0.7...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-12082/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-12083/",
      "current_public_safe_latest": false,
      "cvss_score": 8.1,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.21331,
      "epss_score": 0.00295,
      "first_observed_at": "2026-07-13T06:32:51.098771+00:00",
      "id": "CVE-2026-12083",
      "impact_tags": [
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-13T06:32:51.098771+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Admin and Site Enhancements (ASE) WordPress plugin before 8.8.4, admin-site-enhancements-pro WordPress plugin before 8.8.4 does not perform authentication, authorization, or nonce checks on a role-restoration request handler, allowing unauthenticated... NVD: This is an incomplete fix of CVE-2024-43333 / CVE-2025-24648, which closed the issue for only one of the demotion paths the WordPress role API exposes.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260713T063521Z/items/CVE-2026-12083.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes remote exposure · authenticated boundary. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Admin and Site Enhancements (ASE) WordPress plugin before 8.8.4, admin-site-enhancements-pro WordPress plugin before 8.8.4 does not perform authentication, authorization, or nonce checks on a role-restoration request handler, allowing unauthenticated... NVD: This is an incomplete fix of CVE-2024-43333 / CVE-2025-24648, which closed the issue for only one of the demotion paths the WordPress role API exposes.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-12083/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-12097/",
      "current_public_safe_latest": false,
      "cvss_score": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.16903,
      "epss_score": 0.00255,
      "first_observed_at": "2026-07-15T05:43:30.245469+00:00",
      "id": "CVE-2026-12097",
      "impact_tags": [
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-15T05:43:30.245469+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The User Management plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.2. NVD: This is due to the plugin not properly verifying that a user is authorized to perform an action. NVD: This makes it possible for unauthenticated attackers to modify the plugin's export field configuration stored in the uiewp_export_field option, controlling which user fields such as password hashes are included in CSV exports and how columns are mapped during...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260715T054459Z/items/CVE-2026-12097.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes remote exposure · authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The User Management plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.2. NVD: This is due to the plugin not properly verifying that a user is authorized to perform an action. NVD: This makes it possible for unauthenticated attackers to modify the plugin's export field configuration stored in the uiewp_export_field option, controlling which user fields such as password hashes are included in CSV exports and how columns are mapped during...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-12097/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-12103/",
      "current_public_safe_latest": false,
      "cvss_score": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.2063,
      "epss_score": 0.00286,
      "first_observed_at": "2026-07-18T05:38:40.092323+00:00",
      "id": "CVE-2026-12103",
      "impact_tags": [
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-18T07:15:27.585758+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Wallet for WooCommerce plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.6.4. NVD: This is due to the plugin not properly verifying that a user is authorized to perform an action. NVD: This makes it possible for authenticated attackers, with subscriber-level access and above, to enumerate the login name, email address, and user ID of all WordPress accounts — including administrators — by submitting arbitrary search terms to the AJAX handler.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260718T071858Z/items/CVE-2026-12103.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Wallet for WooCommerce plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.6.4. NVD: This is due to the plugin not properly verifying that a user is authorized to perform an action. NVD: This makes it possible for authenticated attackers, with subscriber-level access and above, to enumerate the login name, email address, and user ID of all WordPress accounts — including administrators — by submitting arbitrary search terms to the AJAX handler.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-12103/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-12108/",
      "current_public_safe_latest": false,
      "cvss_score": 4.4,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.10917,
      "epss_score": 0.00208,
      "first_observed_at": "2026-07-17T05:58:07.763993+00:00",
      "id": "CVE-2026-12108",
      "impact_tags": [
        "XSS risk",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-17T05:58:07.763993+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Highlighting Code Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.2.0 due to insufficient input sanitization and output escaping. NVD: This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. NVD: This only affects multi-site installations and installations where unfiltered_html has been disabled.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260717T060336Z/items/CVE-2026-12108.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes XSS risk · authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Highlighting Code Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.2.0 due to insufficient input sanitization and output escaping. NVD: This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. NVD: This only affects multi-site installations and installations where unfiltered_html has been disabled.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-12108/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-12116/",
      "current_public_safe_latest": false,
      "cvss_score": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.30216,
      "epss_score": 0.0038,
      "first_observed_at": "2026-07-16T13:54:14.110513+00:00",
      "id": "CVE-2026-12116",
      "impact_tags": [
        "code execution review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-16T13:54:14.110513+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A vulnerability in the Xerte Online Tools allows for RCE through the antivirus binary path in the tools server settings, which can be changed to a PHP interpreter, allowing an attacker to upload PHP data that will then be executed. OSV: CVE-2026-12116 OSV: A vulnerability in the Xerte Online Tools allows for RCE through the antivirus binary path in the tools server settings, which can be changed to a PHP interpreter, allowing an attacker to upload PHP data that will then be executed.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260716T135621Z/items/CVE-2026-12116.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes code execution review. Possible impact: An attacker may be able to run code or commands on affected systems.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability in the Xerte Online Tools allows for RCE through the antivirus binary path in the tools server settings, which can be changed to a PHP interpreter, allowing an attacker to upload PHP data that will then be executed. OSV: CVE-2026-12116 OSV: A vulnerability in the Xerte Online Tools allows for RCE through the antivirus binary path in the tools server settings, which can be changed to a PHP interpreter, allowing an attacker to upload PHP data that will then be executed.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-12116/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-12123/",
      "current_public_safe_latest": false,
      "cvss_score": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.15741,
      "epss_score": 0.00246,
      "first_observed_at": "2026-07-17T05:58:07.763993+00:00",
      "id": "CVE-2026-12123",
      "impact_tags": [
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-17T05:58:07.763993+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The All-in-One Video Gallery plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.8.5 via the 'vdl' parameter. NVD: This makes it possible for authenticated attackers, with subscriber-level access and above, to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services. NVD: A Subscriber-level attacker can plant an internal or loopback URL in the mp4 post meta of a newly created aiovg_videos post via XML-RPC wp.newPost, then trigger the unauthenticated ?vdl=<post_id> endpoint to force the server to fetch that URL and stream the...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260717T060336Z/items/CVE-2026-12123.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The All-in-One Video Gallery plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.8.5 via the 'vdl' parameter. NVD: This makes it possible for authenticated attackers, with subscriber-level access and above, to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services. NVD: A Subscriber-level attacker can plant an internal or loopback URL in the mp4 post meta of a newly created aiovg_videos post via XML-RPC wp.newPost, then trigger the unauthenticated ?vdl=<post_id> endpoint to force the server to fetch that URL and stream the...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-12123/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-12124/",
      "current_public_safe_latest": false,
      "cvss_score": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.11287,
      "epss_score": 0.00209,
      "first_observed_at": "2026-08-03T22:29:45.220405+00:00",
      "id": "CVE-2026-12124",
      "impact_tags": [
        "unauthorized access risk",
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-04T06:07:04.591309+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The PDFDraft – Drag & Drop PDF Builder, PDF Viewer, Embed & Download PDF, Certificate & Invoice Designer plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the serveTemplatePdfAjax() function and the... NVD: This makes it possible for unauthenticated attackers to download stored template PDFs — which may contain customer PII, invoice, order, and certificate data — by requesting the publicly registered admin-ajax action pdfdraft_embed_pdf or the REST endpoint...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260804T061658Z/items/CVE-2026-12124.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes unauthorized access risk · remote exposure · authenticated boundary. Possible impact: A remote attacker may access resources that should require stronger authorization.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The PDFDraft – Drag & Drop PDF Builder, PDF Viewer, Embed & Download PDF, Certificate & Invoice Designer plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the serveTemplatePdfAjax() function and the... NVD: This makes it possible for unauthenticated attackers to download stored template PDFs — which may contain customer PII, invoice, order, and certificate data — by requesting the publicly registered admin-ajax action pdfdraft_embed_pdf or the REST endpoint...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-12124/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-12126/",
      "current_public_safe_latest": false,
      "cvss_score": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.11234,
      "epss_score": 0.0021,
      "first_observed_at": "2026-07-18T05:38:40.092323+00:00",
      "id": "CVE-2026-12126",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-18T07:15:27.585758+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The WCFM Marketplace – Multivendor Marketplace for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Attachment 'post_title' in all versions up to, and including, 3.7.3 due to insufficient input sanitization and output escaping. NVD: This makes it possible for authenticated attackers, with Vendor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260718T071858Z/items/CVE-2026-12126.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The WCFM Marketplace – Multivendor Marketplace for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Attachment 'post_title' in all versions up to, and including, 3.7.3 due to insufficient input sanitization and output escaping. NVD: This makes it possible for authenticated attackers, with Vendor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-12126/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-12141/",
      "current_public_safe_latest": false,
      "cvss_score": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.09102,
      "epss_score": 0.00193,
      "first_observed_at": "2026-07-18T05:13:28.850753+00:00",
      "id": "CVE-2026-12141",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-18T05:13:28.850753+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Premium Addons for Elementor – Powerful Elementor Templates & Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'premium_tooltip_text' parameter in all versions up to, and including, 4.11.84 due to insufficient input... NVD: This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260718T051545Z/items/CVE-2026-12141.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Premium Addons for Elementor – Powerful Elementor Templates & Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'premium_tooltip_text' parameter in all versions up to, and including, 4.11.84 due to insufficient input... NVD: This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-12141/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-12144/",
      "current_public_safe_latest": false,
      "cvss_score": 8.8,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.29537,
      "epss_score": 0.00368,
      "first_observed_at": "2026-08-04T22:31:51.932237+00:00",
      "id": "CVE-2026-12144",
      "impact_tags": [
        "privilege boundary review",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-04T22:31:51.932237+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Wholesale for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.0.5. NVD: This is due to the save_requests_meta() function applying only sanitize_text_field() to the user_role_set POST parameter before passing it directly to WP_User::add_role(), with no allowlist validation against permitted wholesale roles and no capability check... NVD: This makes it possible for authenticated attackers with author-level access and above to escalate their privileges to administrator by supplying administrator as the user_role_set value in a crafted request.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260804T223546Z/items/CVE-2026-12144.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes privilege escalation risk · authenticated boundary. Possible impact: An attacker may cross a privilege boundary and gain more access than intended.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Wholesale for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.0.5. NVD: This is due to the save_requests_meta() function applying only sanitize_text_field() to the user_role_set POST parameter before passing it directly to WP_User::add_role(), with no allowlist validation against permitted wholesale roles and no capability check... NVD: This makes it possible for authenticated attackers with author-level access and above to escalate their privileges to administrator by supplying administrator as the user_role_set value in a crafted request.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-12144/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-12153/",
      "current_public_safe_latest": false,
      "cvss_score": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.28591,
      "epss_score": 0.00364,
      "first_observed_at": "2026-07-15T05:43:30.245469+00:00",
      "id": "CVE-2026-12153",
      "impact_tags": [
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-15T05:43:30.245469+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The WP Learn Manager plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.1.8. NVD: This is due to the plugin not properly verifying that a user is authorized to perform an action. NVD: This makes it possible for unauthenticated attackers to install and activate arbitrary plugins from the WordPress.org repository on the vulnerable site.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260715T054459Z/items/CVE-2026-12153.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes remote exposure · authenticated boundary. Possible impact: This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The WP Learn Manager plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.1.8. NVD: This is due to the plugin not properly verifying that a user is authorized to perform an action. NVD: This makes it possible for unauthenticated attackers to install and activate arbitrary plugins from the WordPress.org repository on the vulnerable site.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-12153/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-12154/",
      "current_public_safe_latest": false,
      "cvss_score": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.09154,
      "epss_score": 0.00193,
      "first_observed_at": "2026-07-13T17:24:46.617207+00:00",
      "id": "CVE-2026-12154",
      "impact_tags": [
        "XSS risk",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-13T17:24:46.617207+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Reviews Widgets for Google, Yelp & TripAdvisor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'page_id' shortcode attribute of the [fbrev] shortcode in versions up to and including 2.7.3. NVD: This is due to insufficient input sanitization and output escaping in the Feed_Shortcode::fbrev() method, which passes the raw shortcode attribute through Feed_Old::get_feed() into the View::render() method, where it is echoed directly into the data-id HTML... NVD: This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260713T172750Z/items/CVE-2026-12154.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes XSS risk · authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Reviews Widgets for Google, Yelp & TripAdvisor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'page_id' shortcode attribute of the [fbrev] shortcode in versions up to and including 2.7.3. NVD: This is due to insufficient input sanitization and output escaping in the Feed_Shortcode::fbrev() method, which passes the raw shortcode attribute through Feed_Old::get_feed() into the View::render() method, where it is echoed directly into the data-id HTML... NVD: This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-12154/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-12170/",
      "current_public_safe_latest": false,
      "cvss_score": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.16974,
      "epss_score": 0.00256,
      "first_observed_at": "2026-07-16T05:57:17.509937+00:00",
      "id": "CVE-2026-12170",
      "impact_tags": [
        "XSS risk",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-16T05:57:17.509937+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'alignment' attribute in all versions up to, and including, 10.10.2 due to insufficient... NVD: This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260716T055845Z/items/CVE-2026-12170.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes XSS risk · authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'alignment' attribute in all versions up to, and including, 10.10.2 due to insufficient... NVD: This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-12170/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-12185/",
      "current_public_safe_latest": false,
      "cvss_score": 7.1,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.17887,
      "epss_score": 0.00263,
      "first_observed_at": "2026-08-09T09:59:30.349754+00:00",
      "id": "CVE-2026-12185",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-09T21:51:57.260007+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: In Bouncy Castle for Java before 1.85, BKS/UBER keystore allocates from untrusted lengths before integrity check. NVD: This issue also affects Bouncy Castle for Java LTS before 2.73.12. OSV: BKS/UBER keystore allocates from untrusted lengths before integrity check",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260809T215750Z/items/CVE-2026-12185.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 3,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: In Bouncy Castle for Java before 1.85, BKS/UBER keystore allocates from untrusted lengths before integrity check. NVD: This issue also affects Bouncy Castle for Java LTS before 2.73.12. OSV: BKS/UBER keystore allocates from untrusted lengths before integrity check",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-12185/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-12194/",
      "current_public_safe_latest": false,
      "cvss_score": 2.3,
      "cvss_severity": "LOW",
      "epss_percentile": 0.29882,
      "epss_score": 0.00378,
      "first_observed_at": "2026-07-11T02:07:59.132347+00:00",
      "id": "CVE-2026-12194",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-11T05:56:01.167453+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: PHPIPAM is affected by an authenticated local file inclusion vulnerability that allows users with access to the API to execute/include arbitrary PHP files on the web server's file system. NVD: The API is not enabled by default on installations.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260711T055749Z/items/CVE-2026-12194.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: PHPIPAM is affected by an authenticated local file inclusion vulnerability that allows users with access to the API to execute/include arbitrary PHP files on the web server's file system. NVD: The API is not enabled by default on installations.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-12194/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-12195/",
      "current_public_safe_latest": false,
      "cvss_score": 8.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.47064,
      "epss_score": 0.00656,
      "first_observed_at": "2026-07-11T05:56:01.167453+00:00",
      "id": "CVE-2026-12195",
      "impact_tags": [
        "code execution review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-11T10:36:25.311321+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: myVesta is affected by an authenticated remote code execution vulnerability. NVD: Low privileged users can insert arbitrary commands as a part of the v_ftp_user parameter when deleting FTP usernames. NVD: This could result in the execution of commands as the admin user or takevoer of the admin user in myVesta.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260711T103806Z/items/CVE-2026-12195.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes code execution review. Possible impact: An attacker may be able to run code or commands on affected systems.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: myVesta is affected by an authenticated remote code execution vulnerability. NVD: Low privileged users can insert arbitrary commands as a part of the v_ftp_user parameter when deleting FTP usernames. NVD: This could result in the execution of commands as the admin user or takevoer of the admin user in myVesta.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-12195/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-12196/",
      "current_public_safe_latest": false,
      "cvss_score": 8.3,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.16931,
      "epss_score": 0.00256,
      "first_observed_at": "2026-07-11T05:56:01.167453+00:00",
      "id": "CVE-2026-12196",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-11T10:36:25.311321+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: HestiaCP panel cronjob feature is affected by a broken access control vulnerability. NVD: Low privilege users can modify the panel cronjob to execute scripts HestiaCP management scripts with passwordless sudo. NVD: This could result in the takeover of administrator users in the application and the underlying webserver.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260711T103806Z/items/CVE-2026-12196.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: HestiaCP panel cronjob feature is affected by a broken access control vulnerability. NVD: Low privilege users can modify the panel cronjob to execute scripts HestiaCP management scripts with passwordless sudo. NVD: This could result in the takeover of administrator users in the application and the underlying webserver.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-12196/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-12250/",
      "current_public_safe_latest": false,
      "cvss_score": 7.9,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.01332,
      "epss_score": 0.00106,
      "first_observed_at": "2026-07-12T10:46:01.700382+00:00",
      "id": "CVE-2026-12250",
      "impact_tags": [
        "information exposure review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-12T10:46:01.700382+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Invocation of process using visible sensitive information vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus Domain Joiner allows Excavation. NVD: This issue affects Pardus Domain Joiner: from 0.5.2 before 0.5.4.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260712T104758Z/items/CVE-2026-12250.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes information exposure review. Possible impact: An attacker may be able to access information that should not be exposed.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Invocation of process using visible sensitive information vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus Domain Joiner allows Excavation. NVD: This issue affects Pardus Domain Joiner: from 0.5.2 before 0.5.4.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-12250/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-12251/",
      "current_public_safe_latest": false,
      "cvss_score": 8.1,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.13379,
      "epss_score": 0.00226,
      "first_observed_at": "2026-08-07T05:06:11.845797+00:00",
      "id": "CVE-2026-12251",
      "impact_tags": [
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-07T05:06:11.845797+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Ultimate Member WordPress plugin before 2.12.1 does not filter administrator-level capabilities from the roles it makes selectable on its registration forms, and its post-registration safeguard against elevated accounts is disabled by default, allowing...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260807T051140Z/items/CVE-2026-12251.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes authenticated boundary. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Ultimate Member WordPress plugin before 2.12.1 does not filter administrator-level capabilities from the roles it makes selectable on its registration forms, and its post-registration safeguard against elevated accounts is disabled by default, allowing...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-12251/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "nltk / nltk",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-12252/",
      "current_public_safe_latest": false,
      "cvss_score": 7.8,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.05388,
      "epss_score": 0.00158,
      "first_observed_at": "2026-07-10T22:27:53.208509+00:00",
      "id": "CVE-2026-12252",
      "impact_tags": [
        "code execution review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-11T02:07:59.132347+00:00",
      "latest_item_url": null,
      "product": "nltk",
      "public_safe_summary": "NVD: In nltk/nltk versions 3.9.3 and earlier, five Stanford interface classes (StanfordPOSTagger, StanfordNERTagger, StanfordParser, StanfordDependencyParser, and StanfordNeuralDependencyParser) are vulnerable to untrusted JAR code execution. NVD: These classes accept user-controllable JAR paths and execute them via the java() function, which invokes subprocess.Popen() without integrity verification. NVD: This vulnerability is identical to CVE-2026-0848, which was fixed for StanfordSegmenter by adding SHA256 verification.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260711T020915Z/items/CVE-2026-12252.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "vendor/product: nltk / nltk",
      "source_published_impact": "Source describes code execution review. Possible impact: An attacker may be able to run code or commands on affected systems.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: In nltk/nltk versions 3.9.3 and earlier, five Stanford interface classes (StanfordPOSTagger, StanfordNERTagger, StanfordParser, StanfordDependencyParser, and StanfordNeuralDependencyParser) are vulnerable to untrusted JAR code execution. NVD: These classes accept user-controllable JAR paths and execute them via the java() function, which invokes subprocess.Popen() without integrity verification. NVD: This vulnerability is identical to CVE-2026-0848, which was fixed for StanfordSegmenter by adding SHA256 verification.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-12252/timeline.json",
      "vendor": "nltk"
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-12255/",
      "current_public_safe_latest": false,
      "cvss_score": 8.1,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.19701,
      "epss_score": 0.00275,
      "first_observed_at": "2026-08-02T06:14:57.521051+00:00",
      "id": "CVE-2026-12255",
      "impact_tags": [
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-03T06:40:38.700520+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The MainWP Child WordPress plugin before 6.1.2 does not verify the requester's identity in its site-registration request handler when password authentication has been disabled for the targeted account, allowing an unauthenticated attacker to obtain a valid...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260803T064356Z/items/CVE-2026-12255.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 5,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes remote exposure · authenticated boundary. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The MainWP Child WordPress plugin before 6.1.2 does not verify the requester's identity in its site-registration request handler when password authentication has been disabled for the targeted account, allowing an unauthenticated attacker to obtain a valid...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-12255/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-12257/",
      "current_public_safe_latest": false,
      "cvss_score": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.33282,
      "epss_score": 0.00411,
      "first_observed_at": "2026-07-20T11:59:42.107493+00:00",
      "id": "CVE-2026-12257",
      "impact_tags": [
        "code execution review",
        "remote exposure relevant"
      ],
      "kev": false,
      "last_observed_at": "2026-07-20T11:59:42.107493+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Versions of Mura CMS prior to 10.0.712 contain a critical remote code execution (RCE) vulnerability. NVD: The flaw is located in the endpoint “/index.cfm/_api/json/v1/default”, where the “method” parameter in POST requests is not properly validated or sanitised before being processed by the ColdFusion engine. NVD: As a result, a remote attacker could exploit this vulnerability to inject and execute arbitrary CFML (ColdFusion Markup Language) expressions and instantiate malicious Java objects, thereby compromising the system’s security.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260720T120206Z/items/CVE-2026-12257.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes code execution review · remote exposure. Possible impact: A remote attacker may be able to run code or commands on affected systems.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Versions of Mura CMS prior to 10.0.712 contain a critical remote code execution (RCE) vulnerability. NVD: The flaw is located in the endpoint “/index.cfm/_api/json/v1/default”, where the “method” parameter in POST requests is not properly validated or sanitised before being processed by the ColdFusion engine. NVD: As a result, a remote attacker could exploit this vulnerability to inject and execute arbitrary CFML (ColdFusion Markup Language) expressions and instantiate malicious Java objects, thereby compromising the system’s security.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-12257/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-12270/",
      "current_public_safe_latest": false,
      "cvss_score": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.07538,
      "epss_score": 0.00179,
      "first_observed_at": "2026-07-16T05:57:17.509937+00:00",
      "id": "CVE-2026-12270",
      "impact_tags": [
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-16T05:57:17.509937+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Everest Forms WordPress plugin before 3.5.0 does not correctly restrict access to several REST API endpoints belonging to its onboarding assistant: the capability check is only applied when an attacker-controllable request header holds a specific value... NVD: This makes it possible for unauthenticated attackers to read onboarding status information, modify the related Everest Forms WordPress plugin before 3.5.0 options, and trigger an email from the site to an arbitrary address.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260716T055845Z/items/CVE-2026-12270.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes remote exposure · authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Everest Forms WordPress plugin before 3.5.0 does not correctly restrict access to several REST API endpoints belonging to its onboarding assistant: the capability check is only applied when an attacker-controllable request header holds a specific value... NVD: This makes it possible for unauthenticated attackers to read onboarding status information, modify the related Everest Forms WordPress plugin before 3.5.0 options, and trigger an email from the site to an arbitrary address.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-12270/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-12271/",
      "current_public_safe_latest": false,
      "cvss_score": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.06589,
      "epss_score": 0.0017,
      "first_observed_at": "2026-07-20T06:28:37.060083+00:00",
      "id": "CVE-2026-12271",
      "impact_tags": [
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-20T06:28:37.060083+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Tutor LMS WordPress plugin before 3.9.13 does not verify ownership of the targeted quiz attempt before writing to it, allowing authenticated users with subscriber-level access and above to modify and force-complete other students' quiz attempts...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260720T063049Z/items/CVE-2026-12271.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Tutor LMS WordPress plugin before 3.9.13 does not verify ownership of the targeted quiz attempt before writing to it, allowing authenticated users with subscriber-level access and above to modify and force-complete other students' quiz attempts...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-12271/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-12273/",
      "current_public_safe_latest": false,
      "cvss_score": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.06624,
      "epss_score": 0.0017,
      "first_observed_at": "2026-07-20T06:28:37.060083+00:00",
      "id": "CVE-2026-12273",
      "impact_tags": [
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-20T06:28:37.060083+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Tutor LMS WordPress plugin before 3.9.13 does not perform any authorization or post-target validation before creating a comment in one of its handlers, and stores the comment pre-approved, allowing authenticated users with subscriber-level access and...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260720T063049Z/items/CVE-2026-12273.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Tutor LMS WordPress plugin before 3.9.13 does not perform any authorization or post-target validation before creating a comment in one of its handlers, and stores the comment pre-approved, allowing authenticated users with subscriber-level access and...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-12273/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-12274/",
      "current_public_safe_latest": false,
      "cvss_score": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.08187,
      "epss_score": 0.00184,
      "first_observed_at": "2026-07-20T06:28:37.060083+00:00",
      "id": "CVE-2026-12274",
      "impact_tags": [
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-20T06:28:37.060083+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Tutor LMS WordPress plugin before 3.9.13 does not verify that the requesting user is allowed to edit a target post before overwriting it in one of its content-builder save handlers, authorizing the request only against an unrelated identifier, allowing...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260720T063049Z/items/CVE-2026-12274.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Tutor LMS WordPress plugin before 3.9.13 does not verify that the requesting user is allowed to edit a target post before overwriting it in one of its content-builder save handlers, authorizing the request only against an unrelated identifier, allowing...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-12274/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-12275/",
      "current_public_safe_latest": false,
      "cvss_score": 7.1,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.06706,
      "epss_score": 0.00171,
      "first_observed_at": "2026-07-20T06:28:37.060083+00:00",
      "id": "CVE-2026-12275",
      "impact_tags": [
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-20T06:28:37.060083+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Tutor LMS WordPress plugin before 3.9.13 does not, in its Droip and Kirki page-builder integration, perform the enrollment, purchase, and private-course capability checks it enforces in its core course handler, allowing authenticated users with...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260720T063049Z/items/CVE-2026-12275.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes authenticated boundary. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Tutor LMS WordPress plugin before 3.9.13 does not, in its Droip and Kirki page-builder integration, perform the enrollment, purchase, and private-course capability checks it enforces in its core course handler, allowing authenticated users with...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-12275/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-12276/",
      "current_public_safe_latest": false,
      "cvss_score": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.07921,
      "epss_score": 0.00182,
      "first_observed_at": "2026-07-17T05:58:07.763993+00:00",
      "id": "CVE-2026-12276",
      "impact_tags": [
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-17T05:58:07.763993+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The LA-Studio Element Kit for Elementor WordPress plugin before 1.6.1 does not check whether user registration is enabled on the site before creating an account through one of its unauthenticated AJAX actions, allowing unauthenticated attackers to register...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260717T060336Z/items/CVE-2026-12276.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes remote exposure · authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The LA-Studio Element Kit for Elementor WordPress plugin before 1.6.1 does not check whether user registration is enabled on the site before creating an account through one of its unauthenticated AJAX actions, allowing unauthenticated attackers to register...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-12276/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-12277/",
      "current_public_safe_latest": false,
      "cvss_score": 8.7,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.13887,
      "epss_score": 0.00231,
      "first_observed_at": "2026-07-14T05:42:23.241208+00:00",
      "id": "CVE-2026-12277",
      "impact_tags": [
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-14T05:42:23.241208+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Frontend File Manager Plugin WordPress plugin through 23.6 does not validate a file path derived from user input before deleting the referenced file, allowing unauthenticated users to delete arbitrary files on the server (such as wp-config.php) when guest... NVD: Deleting wp-config.php forces the site into its setup routine, which can be leveraged toward a full site takeover.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260714T054512Z/items/CVE-2026-12277.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes authenticated boundary. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Frontend File Manager Plugin WordPress plugin through 23.6 does not validate a file path derived from user input before deleting the referenced file, allowing unauthenticated users to delete arbitrary files on the server (such as wp-config.php) when guest... NVD: Deleting wp-config.php forces the site into its setup routine, which can be leveraged toward a full site takeover.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-12277/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-12281/",
      "current_public_safe_latest": false,
      "cvss_score": 8.1,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.13993,
      "epss_score": 0.00231,
      "first_observed_at": "2026-07-22T06:07:21.492959+00:00",
      "id": "CVE-2026-12281",
      "impact_tags": [
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-22T06:07:21.492959+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Shibboleth WordPress plugin before 2.5.4 does not fail closed when its HTTP header identity mode is enabled without an anti-spoofing key, treating any request that carries identity headers as an authenticated session without verifying them. NVD: On a deployment where untrusted client headers reach the application, an unauthenticated attacker can log in with forged identity headers and, when automatic account creation and the default administrator role mapping are enabled, create and sign in as a new... NVD: Exploitation requires the non-default HTTP header attribute mode, an empty or absent spoof key, automatic account creation enabled, and a deployment that does not strip untrusted client headers before they reach the application.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260722T060931Z/items/CVE-2026-12281.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes remote exposure · authenticated boundary. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Shibboleth WordPress plugin before 2.5.4 does not fail closed when its HTTP header identity mode is enabled without an anti-spoofing key, treating any request that carries identity headers as an authenticated session without verifying them. NVD: On a deployment where untrusted client headers reach the application, an unauthenticated attacker can log in with forged identity headers and, when automatic account creation and the default administrator role mapping are enabled, create and sign in as a new... NVD: Exploitation requires the non-default HTTP header attribute mode, an empty or absent spoof key, automatic account creation enabled, and a deployment that does not strip untrusted client headers before they reach the application.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-12281/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-12352/",
      "current_public_safe_latest": false,
      "cvss_score": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.17316,
      "epss_score": 0.00259,
      "first_observed_at": "2026-07-14T10:57:43.777280+00:00",
      "id": "CVE-2026-12352",
      "impact_tags": [
        "privilege boundary review",
        "authentication boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-14T10:57:43.777280+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: This vulnerability allows an unauthenticated actor to bypass authentication and gain access to restricted resources on the device.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260714T110007Z/items/CVE-2026-12352.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes privilege escalation risk · authentication boundary review. Possible impact: An attacker may cross a privilege boundary and gain more access than intended.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: This vulnerability allows an unauthenticated actor to bypass authentication and gain access to restricted resources on the device.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-12352/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-12375/",
      "current_public_safe_latest": false,
      "cvss_score": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.22156,
      "epss_score": 0.00303,
      "first_observed_at": "2026-07-14T05:42:23.241208+00:00",
      "id": "CVE-2026-12375",
      "impact_tags": [
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-14T05:42:23.241208+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The uncanny-automator-pro WordPress plugin before 7.3.0.6 was distributed with malicious code after the vendor's uncanny-automator-pro WordPress plugin before 7.3.0.6 update/distribution infrastructure was compromised; the injected backdoor grants...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260714T054512Z/items/CVE-2026-12375.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes remote exposure · authenticated boundary. Possible impact: This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The uncanny-automator-pro WordPress plugin before 7.3.0.6 was distributed with malicious code after the vendor's uncanny-automator-pro WordPress plugin before 7.3.0.6 update/distribution infrastructure was compromised; the injected backdoor grants...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-12375/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-12376/",
      "current_public_safe_latest": false,
      "cvss_score": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.05808,
      "epss_score": 0.00162,
      "first_observed_at": "2026-08-07T05:06:11.845797+00:00",
      "id": "CVE-2026-12376",
      "impact_tags": [
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-07T05:06:11.845797+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Academy LMS WordPress plugin through 3.8.2 does not restrict access to quiz attempt records to their owner, allowing any authenticated user with subscriber-level access and above (enrolled in any single course) to read every user's quiz attempts across...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260807T051140Z/items/CVE-2026-12376.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Academy LMS WordPress plugin through 3.8.2 does not restrict access to quiz attempt records to their owner, allowing any authenticated user with subscriber-level access and above (enrolled in any single course) to read every user's quiz attempts across...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-12376/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-12378/",
      "current_public_safe_latest": false,
      "cvss_score": 8.1,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.31055,
      "epss_score": 0.00389,
      "first_observed_at": "2026-07-15T05:43:30.245469+00:00",
      "id": "CVE-2026-12378",
      "impact_tags": [
        "code execution review",
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-15T05:43:30.245469+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Appointment Booking Calendar Plugin and Scheduling Plugin WordPress plugin through 1.1.28 does not validate data before passing it to a PHP deserialization function, allowing unauthenticated attackers to inject arbitrary PHP objects; where a suitable...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260715T054459Z/items/CVE-2026-12378.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes code execution review · remote exposure · authenticated boundary. Possible impact: A remote attacker may be able to run code or commands on affected systems.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Appointment Booking Calendar Plugin and Scheduling Plugin WordPress plugin through 1.1.28 does not validate data before passing it to a PHP deserialization function, allowing unauthenticated attackers to inject arbitrary PHP objects; where a suitable...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-12378/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-12386/",
      "current_public_safe_latest": false,
      "cvss_score": 3.9,
      "cvss_severity": "LOW",
      "epss_percentile": 0.00866,
      "epss_score": 0.00096,
      "first_observed_at": "2026-07-12T10:46:01.700382+00:00",
      "id": "CVE-2026-12386",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-12T10:46:01.700382+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Improper null termination vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus Pen allows Overflow Buffers. NVD: This issue affects Pardus Pen: from <=4.1.5 before 4.2.1.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260712T104758Z/items/CVE-2026-12386.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Improper null termination vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus Pen allows Overflow Buffers. NVD: This issue affects Pardus Pen: from <=4.1.5 before 4.2.1.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-12386/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-12391/",
      "current_public_safe_latest": false,
      "cvss_score": 5.0,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.05147,
      "epss_score": 0.00155,
      "first_observed_at": "2026-07-23T11:21:51.498947+00:00",
      "id": "CVE-2026-12391",
      "impact_tags": [
        "information exposure review",
        "local exposure relevant"
      ],
      "kev": false,
      "last_observed_at": "2026-07-23T11:21:51.498947+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: An insecure symlink following vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu-advantage-tools) within the pro collect-logs command framework. NVD: The utility creates or utilizes predictable temporary file paths or user-accessible log directories when gathering diagnostic information without verifying the file type or ownership. NVD: An unprivileged local attacker can exploit this behavior by creating a symbolic link (symlink) at a predictable destination path pointing to an arbitrary, root-readable file (such as /etc/shadow or private files within /root).",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260723T112431Z/items/CVE-2026-12391.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes information exposure review · local exposure. Possible impact: A local user may be able to access information that should not be exposed.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: An insecure symlink following vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu-advantage-tools) within the pro collect-logs command framework. NVD: The utility creates or utilizes predictable temporary file paths or user-accessible log directories when gathering diagnostic information without verifying the file type or ownership. NVD: An unprivileged local attacker can exploit this behavior by creating a symbolic link (symlink) at a predictable destination path pointing to an arbitrary, root-readable file (such as /etc/shadow or private files within /root).",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-12391/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-12393/",
      "current_public_safe_latest": false,
      "cvss_score": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.06608,
      "epss_score": 0.0017,
      "first_observed_at": "2026-07-24T06:06:41.160911+00:00",
      "id": "CVE-2026-12393",
      "impact_tags": [
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-24T06:06:41.160911+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The WPS Bookings for WooCommerce WordPress plugin before 3.11.7 does not verify that a booking order belongs to the requesting user before cancelling it, allowing any authenticated user, such as a Subscriber or Customer, to cancel and void other customers'...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260724T061150Z/items/CVE-2026-12393.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The WPS Bookings for WooCommerce WordPress plugin before 3.11.7 does not verify that a booking order belongs to the requesting user before cancelling it, allowing any authenticated user, such as a Subscriber or Customer, to cancel and void other customers'...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-12393/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-12394/",
      "current_public_safe_latest": false,
      "cvss_score": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.19952,
      "epss_score": 0.00277,
      "first_observed_at": "2026-08-02T06:14:57.521051+00:00",
      "id": "CVE-2026-12394",
      "impact_tags": [
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-03T06:40:38.700520+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The MemberGlut WordPress plugin before 1.1.5 does not validate the role chosen during front-end registration, allowing unauthenticated users to register an account with an arbitrary role, including administrator, leading to full site compromise.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260803T064356Z/items/CVE-2026-12394.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 5,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes authenticated boundary. Possible impact: This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The MemberGlut WordPress plugin before 1.1.5 does not validate the role chosen during front-end registration, allowing unauthenticated users to register an account with an arbitrary role, including administrator, leading to full site compromise.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-12394/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-12395/",
      "current_public_safe_latest": false,
      "cvss_score": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.12556,
      "epss_score": 0.0022,
      "first_observed_at": "2026-07-23T06:13:21.015514+00:00",
      "id": "CVE-2026-12395",
      "impact_tags": [
        "SQL injection risk",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-23T06:13:21.015514+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The WP Job Portal WordPress plugin before 2.5.5 does not properly sanitize and escape a parameter before using it in a SQL query, allowing authenticated users with a subscriber-level (self-registerable) account to perform SQL injection attacks.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260723T061547Z/items/CVE-2026-12395.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes SQL injection risk · authenticated boundary. Possible impact: An attacker may be able to read or change database-backed application data.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The WP Job Portal WordPress plugin before 2.5.5 does not properly sanitize and escape a parameter before using it in a SQL query, allowing authenticated users with a subscriber-level (self-registerable) account to perform SQL injection attacks.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-12395/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-12396/",
      "current_public_safe_latest": false,
      "cvss_score": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.06586,
      "epss_score": 0.0017,
      "first_observed_at": "2026-07-20T06:28:37.060083+00:00",
      "id": "CVE-2026-12396",
      "impact_tags": [
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-20T06:28:37.060083+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The WP Job Portal WordPress plugin before 2.5.5 does not perform capability or ownership checks before allowing job moderation actions, allowing authenticated users with a subscriber-level (self-registerable) account to approve, feature, or reject arbitrary...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260720T063049Z/items/CVE-2026-12396.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The WP Job Portal WordPress plugin before 2.5.5 does not perform capability or ownership checks before allowing job moderation actions, allowing authenticated users with a subscriber-level (self-registerable) account to approve, feature, or reject arbitrary...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-12396/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-12397/",
      "current_public_safe_latest": false,
      "cvss_score": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.05747,
      "epss_score": 0.00162,
      "first_observed_at": "2026-07-20T06:28:37.060083+00:00",
      "id": "CVE-2026-12397",
      "impact_tags": [
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-20T06:28:37.060083+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The WP Job Portal WordPress plugin before 2.5.5 does not verify ownership when returning an employer's contact email for a given job, allowing authenticated users with a subscriber-level (self-registerable) account to read other employers' private account...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260720T063049Z/items/CVE-2026-12397.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The WP Job Portal WordPress plugin before 2.5.5 does not verify ownership when returning an employer's contact email for a given job, allowing authenticated users with a subscriber-level (self-registerable) account to read other employers' private account...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-12397/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-12400/",
      "current_public_safe_latest": false,
      "cvss_score": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.13214,
      "epss_score": 0.00226,
      "first_observed_at": "2026-07-17T05:58:07.763993+00:00",
      "id": "CVE-2026-12400",
      "impact_tags": [
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-17T05:58:07.763993+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The FlowForms – Conversational Form Builder plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.1.1 via the update_form due to missing validation on a user controlled key. NVD: This makes it possible for authenticated attackers, with contributor-level access and above, to modify the content, design, and settings of, as well as publish or revert, any form on the site — including forms owned by administrators — by supplying an...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260717T060336Z/items/CVE-2026-12400.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The FlowForms – Conversational Form Builder plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.1.1 via the update_form due to missing validation on a user controlled key. NVD: This makes it possible for authenticated attackers, with contributor-level access and above, to modify the content, design, and settings of, as well as publish or revert, any form on the site — including forms owned by administrators — by supplying an...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-12400/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-12406/",
      "current_public_safe_latest": false,
      "cvss_score": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.24381,
      "epss_score": 0.00323,
      "first_observed_at": "2026-07-16T05:57:17.509937+00:00",
      "id": "CVE-2026-12406",
      "impact_tags": [
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-16T05:57:17.509937+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.3.7. NVD: This is due to the plugin not properly verifying that a user is authorized to perform an action. NVD: This makes it possible for unauthenticated attackers to delete arbitrary media attachments whose post_author is 0, such as guest and registration-form uploads, via the wpuf_file_del AJAX action.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260716T055845Z/items/CVE-2026-12406.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes remote exposure · authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.3.7. NVD: This is due to the plugin not properly verifying that a user is authorized to perform an action. NVD: This makes it possible for unauthenticated attackers to delete arbitrary media attachments whose post_author is 0, such as guest and registration-form uploads, via the wpuf_file_del AJAX action.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-12406/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-12409/",
      "current_public_safe_latest": false,
      "cvss_score": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.0296,
      "epss_score": 0.00129,
      "first_observed_at": "2026-07-22T22:28:24.662524+00:00",
      "id": "CVE-2026-12409",
      "impact_tags": [
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-22T22:28:24.662524+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Landing Page Builder – Coming Soon page, Maintenance Mode, Lead Page, WordPress Landing Pages plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.5.3.6. NVD: This is due to missing or incorrect nonce validation on the ulpb_admin_ajax function. NVD: This makes it possible for unauthenticated attackers to create, update, retitle, or change the post status, slug, and type of arbitrary posts and write ULPB_DATA post meta via a forged request granted they can trick a site administrator into performing an...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260722T223443Z/items/CVE-2026-12409.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes remote exposure · authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Landing Page Builder – Coming Soon page, Maintenance Mode, Lead Page, WordPress Landing Pages plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.5.3.6. NVD: This is due to missing or incorrect nonce validation on the ulpb_admin_ajax function. NVD: This makes it possible for unauthenticated attackers to create, update, retitle, or change the post status, slug, and type of arbitrary posts and write ULPB_DATA post meta via a forged request granted they can trick a site administrator into performing an...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-12409/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-12418/",
      "current_public_safe_latest": false,
      "cvss_score": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.15444,
      "epss_score": 0.00243,
      "first_observed_at": "2026-07-16T05:57:17.509937+00:00",
      "id": "CVE-2026-12418",
      "impact_tags": [
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-16T05:57:17.509937+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.3.7 via the 'wpuf_files_data' parameter due... NVD: This makes it possible for unauthenticated attackers to overwrite the post_title, post_content, and post_excerpt of any arbitrary post on the site, including posts authored by administrators. NVD: Exploitation requires access to any WPUF post submission form; this is achievable by users with no WordPress role, as the wpuf_submit_post AJAX action is gated only by a nonce with no capability check for the downstream post-edit operation.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260716T055845Z/items/CVE-2026-12418.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes remote exposure · authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.3.7 via the 'wpuf_files_data' parameter due... NVD: This makes it possible for unauthenticated attackers to overwrite the post_title, post_content, and post_excerpt of any arbitrary post on the site, including posts authored by administrators. NVD: Exploitation requires access to any WPUF post submission form; this is achievable by users with no WordPress role, as the wpuf_submit_post AJAX action is gated only by a nonce with no capability check for the downstream post-edit operation.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-12418/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-12421/",
      "current_public_safe_latest": false,
      "cvss_score": 7.2,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.08965,
      "epss_score": 0.0019,
      "first_observed_at": "2026-07-30T06:01:44.452906+00:00",
      "id": "CVE-2026-12421",
      "impact_tags": [
        "XSS risk",
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-30T06:01:44.452906+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The ARforms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'password' Field Values in all versions up to, and including, 7.2.1 due to insufficient input sanitization and output escaping. NVD: This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260730T060504Z/items/CVE-2026-12421.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes XSS risk · remote exposure · authenticated boundary. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk · remote exposure · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The ARforms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'password' Field Values in all versions up to, and including, 7.2.1 due to insufficient input sanitization and output escaping. NVD: This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-12421/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-12428/",
      "current_public_safe_latest": false,
      "cvss_score": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.20433,
      "epss_score": 0.00285,
      "first_observed_at": "2026-07-16T11:14:01.223847+00:00",
      "id": "CVE-2026-12428",
      "impact_tags": [
        "unauthorized access risk",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-16T11:14:01.223847+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Blocks for ACF Fields plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the get_all_values() function in the /wp-json/acf-field-blocks/v1/values REST endpoint in versions up to, and including, 1.6.2. NVD: The permission_callback only verifies the generic publish_posts capability and the handler passes a user-supplied id parameter directly to get_field_objects() without verifying that the requesting user is authorized to read the target object. NVD: This makes it possible for authenticated attackers, with Author-level access and above, to read ACF field values from arbitrary posts (including private posts, drafts, posts by other users, and other ACF-supported objects) that they should not have access to.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260716T111601Z/items/CVE-2026-12428.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes unauthorized access risk · authenticated boundary. Possible impact: An attacker may access resources that should require stronger authorization.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Blocks for ACF Fields plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the get_all_values() function in the /wp-json/acf-field-blocks/v1/values REST endpoint in versions up to, and including, 1.6.2. NVD: The permission_callback only verifies the generic publish_posts capability and the handler passes a user-supplied id parameter directly to get_field_objects() without verifying that the requesting user is authorized to read the target object. NVD: This makes it possible for authenticated attackers, with Author-level access and above, to read ACF field values from arbitrary posts (including private posts, drafts, posts by other users, and other ACF-supported objects) that they should not have access to.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-12428/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-12434/",
      "current_public_safe_latest": false,
      "cvss_score": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.15028,
      "epss_score": 0.00239,
      "first_observed_at": "2026-07-22T22:28:24.662524+00:00",
      "id": "CVE-2026-12434",
      "impact_tags": [
        "information exposure review",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-22T22:28:24.662524+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The List category posts plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 0.95.0 via the sanitize_status. NVD: This makes it possible for authenticated attackers, with contributor-level access and above, to extract titles, full content, excerpts, dates, authors, and custom-field metadata of other users' pending-review, scheduled, and trashed posts by embedding a... NVD: This vulnerability is a bypass of the incomplete fix introduced for CVE-2025-11377 in version 0.93.0.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260722T223443Z/items/CVE-2026-12434.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes information exposure review · authenticated boundary. Possible impact: An attacker may be able to access information that should not be exposed.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The List category posts plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 0.95.0 via the sanitize_status. NVD: This makes it possible for authenticated attackers, with contributor-level access and above, to extract titles, full content, excerpts, dates, authors, and custom-field metadata of other users' pending-review, scheduled, and trashed posts by embedding a... NVD: This vulnerability is a bypass of the incomplete fix introduced for CVE-2025-11377 in version 0.93.0.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-12434/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-12482/",
      "current_public_safe_latest": false,
      "cvss_score": 3.1,
      "cvss_severity": "LOW",
      "epss_percentile": 0.22147,
      "epss_score": 0.00301,
      "first_observed_at": "2026-07-21T06:08:28.817138+00:00",
      "id": "CVE-2026-12482",
      "impact_tags": [
        "path traversal review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-21T06:08:28.817138+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A vulnerability in keras-team/keras version 3.12.0 allows an attacker to craft a malicious tar archive that bypasses the filter_safe_tarinfos validation in keras/src/utils/file_utils.py. NVD: Specifically, symlink entries are not subjected to the same is_path_in_dir validation as regular file entries, allowing symlinks to be created outside the intended extraction directory. NVD: This can lead to symlink-based file read, file overwrite, or directory escape attacks.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260721T061518Z/items/CVE-2026-12482.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes path traversal review. Possible impact: An attacker may be able to reach files outside the intended application path.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability in keras-team/keras version 3.12.0 allows an attacker to craft a malicious tar archive that bypasses the filter_safe_tarinfos validation in keras/src/utils/file_utils.py. NVD: Specifically, symlink entries are not subjected to the same is_path_in_dir validation as regular file entries, allowing symlinks to be created outside the intended extraction directory. NVD: This can lead to symlink-based file read, file overwrite, or directory escape attacks.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-12482/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-12492/",
      "current_public_safe_latest": false,
      "cvss_score": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.20446,
      "epss_score": 0.00283,
      "first_observed_at": "2026-07-23T06:13:21.015514+00:00",
      "id": "CVE-2026-12492",
      "impact_tags": [
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-23T06:13:21.015514+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Happy Coders OTP Login for WooCommerce WordPress plugin before 2.8 does not verify that a one-time password was actually validated before authenticating a user based on a supplied identifier, allowing unauthenticated attackers to log in as any existing...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260723T061547Z/items/CVE-2026-12492.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes remote exposure · authenticated boundary. Possible impact: This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Happy Coders OTP Login for WooCommerce WordPress plugin before 2.8 does not verify that a one-time password was actually validated before authenticating a user based on a supplied identifier, allowing unauthenticated attackers to log in as any existing...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-12492/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-12493/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.11122,
      "epss_score": 0.00208,
      "first_observed_at": "2026-08-02T06:14:57.521051+00:00",
      "id": "CVE-2026-12493",
      "impact_tags": [
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-03T06:40:38.700520+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Clover Payment Gateway by Zaytech for WooCommerce WordPress plugin before 1.3.6 does not verify that an approved external payment record actually belongs to the WooCommerce order being completed, nor that the paid amount matches the order total, allowing...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260803T064356Z/items/CVE-2026-12493.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 5,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes authenticated boundary. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Clover Payment Gateway by Zaytech for WooCommerce WordPress plugin before 1.3.6 does not verify that an approved external payment record actually belongs to the WooCommerce order being completed, nor that the paid amount matches the order total, allowing...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-12493/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-12497/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.14227,
      "epss_score": 0.00232,
      "first_observed_at": "2026-07-31T06:26:41.124454+00:00",
      "id": "CVE-2026-12497",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-31T06:26:41.124454+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content WordPress plugin before 4.16.18 does not consistently enforce the role restriction configured on its front-end registration role-selection field. NVD: The set of roles offered to the visitor and the set of roles the registration handler accepts are derived by two different parsers, and for some valid ways of configuring the offered roles the handler ignores the restriction and falls back to accepting any... NVD: Combined with the absence of a nonce on the public registration handler, this allows an unauthenticated visitor to register an account with a higher role, such as Editor or Author, than the form was configured to offer.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260731T063057Z/items/CVE-2026-12497.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content WordPress plugin before 4.16.18 does not consistently enforce the role restriction configured on its front-end registration role-selection field. NVD: The set of roles offered to the visitor and the set of roles the registration handler accepts are derived by two different parsers, and for some valid ways of configuring the offered roles the handler ignores the restriction and falls back to accepting any... NVD: Combined with the absence of a nonce on the public registration handler, this allows an unauthenticated visitor to register an account with a higher role, such as Editor or Author, than the form was configured to offer.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-12497/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-12500/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.16773,
      "epss_score": 0.00253,
      "first_observed_at": "2026-08-06T06:07:21.988664+00:00",
      "id": "CVE-2026-12500",
      "impact_tags": [
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-06T06:07:21.988664+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The WP Travel Engine WordPress plugin before 6.8.2 does not perform a capability check on an AJAX action that updates a WP Travel Engine WordPress plugin before 6.8.2 option, allowing unauthenticated users to overwrite a site-wide WP Travel Engine WordPress...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260806T061754Z/items/CVE-2026-12500.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes authenticated boundary. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The WP Travel Engine WordPress plugin before 6.8.2 does not perform a capability check on an AJAX action that updates a WP Travel Engine WordPress plugin before 6.8.2 option, allowing unauthenticated users to overwrite a site-wide WP Travel Engine WordPress...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-12500/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-12510/",
      "current_public_safe_latest": false,
      "cvss_score": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.04237,
      "epss_score": 0.00145,
      "first_observed_at": "2026-07-23T06:13:21.015514+00:00",
      "id": "CVE-2026-12510",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-23T06:13:21.015514+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The AI Engine WordPress plugin before 3.5.5 does not verify that a user owns the chatbot conversation referenced by a client-supplied identifier, allowing users with subscriber-level access to read other users' private conversations and take over their...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260723T061547Z/items/CVE-2026-12510.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The AI Engine WordPress plugin before 3.5.5 does not verify that a user owns the chatbot conversation referenced by a client-supplied identifier, allowing users with subscriber-level access to read other users' private conversations and take over their...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-12510/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-12511/",
      "current_public_safe_latest": false,
      "cvss_score": 8.1,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.22467,
      "epss_score": 0.00304,
      "first_observed_at": "2026-07-21T06:08:28.817138+00:00",
      "id": "CVE-2026-12511",
      "impact_tags": [
        "path traversal review",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-21T06:08:28.817138+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The AI Engine WordPress plugin before 3.5.5 does not sanitize a user-supplied filename before using it to write a downloaded file, allowing authenticated users with editor-level access to write attacker-controlled bytes to an arbitrary location on the server...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260721T061518Z/items/CVE-2026-12511.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes path traversal review · authenticated boundary. Possible impact: An attacker may be able to reach files outside the intended application path.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The AI Engine WordPress plugin before 3.5.5 does not sanitize a user-supplied filename before using it to write a downloaded file, allowing authenticated users with editor-level access to write attacker-controlled bytes to an arbitrary location on the server...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-12511/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-12512/",
      "current_public_safe_latest": false,
      "cvss_score": 8.6,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.18643,
      "epss_score": 0.00268,
      "first_observed_at": "2026-07-22T06:07:21.492959+00:00",
      "id": "CVE-2026-12512",
      "impact_tags": [
        "SQL injection risk",
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-22T06:07:21.492959+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Quotes llama WordPress plugin before 3.1.6 does not properly sanitize and escape a user-supplied parameter before using it in a SQL query, allowing unauthenticated attackers to perform UNION-based SQL injection and read arbitrary data from the database...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260722T060931Z/items/CVE-2026-12512.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes SQL injection risk · remote exposure · authenticated boundary. Possible impact: A remote attacker may be able to read or change database-backed application data.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Quotes llama WordPress plugin before 3.1.6 does not properly sanitize and escape a user-supplied parameter before using it in a SQL query, allowing unauthenticated attackers to perform UNION-based SQL injection and read arbitrary data from the database...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-12512/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-12516/",
      "current_public_safe_latest": false,
      "cvss_score": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.08476,
      "epss_score": 0.00187,
      "first_observed_at": "2026-07-16T05:57:17.509937+00:00",
      "id": "CVE-2026-12516",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-16T05:57:17.509937+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Fediverse Embeds WordPress plugin before 1.5.8 does not validate the destination of the server-side request performed by an unauthenticated media-proxying endpoint, allowing anonymous users to make the site fetch arbitrary URLs, including internal and... NVD: This results in a full-read Server-Side Request Forgery and open proxy.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260716T055845Z/items/CVE-2026-12516.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Fediverse Embeds WordPress plugin before 1.5.8 does not validate the destination of the server-side request performed by an unauthenticated media-proxying endpoint, allowing anonymous users to make the site fetch arbitrary URLs, including internal and... NVD: This results in a full-read Server-Side Request Forgery and open proxy.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-12516/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-12517/",
      "current_public_safe_latest": false,
      "cvss_score": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.0848,
      "epss_score": 0.00187,
      "first_observed_at": "2026-07-16T05:57:17.509937+00:00",
      "id": "CVE-2026-12517",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-16T05:57:17.509937+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Fediverse Embeds WordPress plugin before 1.5.8 does not validate the destination of the server-side request performed by an unauthenticated site-info endpoint before fetching it, allowing anonymous users (the gating nonce is exposed on public pages... NVD: This is a Server-Side Request Forgery.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260716T055845Z/items/CVE-2026-12517.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Fediverse Embeds WordPress plugin before 1.5.8 does not validate the destination of the server-side request performed by an unauthenticated site-info endpoint before fetching it, allowing anonymous users (the gating nonce is exposed on public pages... NVD: This is a Server-Side Request Forgery.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-12517/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-12525/",
      "current_public_safe_latest": false,
      "cvss_score": 8.8,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.14776,
      "epss_score": 0.00237,
      "first_observed_at": "2026-07-23T06:13:21.015514+00:00",
      "id": "CVE-2026-12525",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-23T06:13:21.015514+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Redux Framework WordPress plugin before 4.5.13 does not restrict which user meta keys can be written when saving custom profile fields, allowing users with at least the Subscriber role to escalate their privileges to Administrator by submitting a crafted...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260723T061547Z/items/CVE-2026-12525.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Redux Framework WordPress plugin before 4.5.13 does not restrict which user meta keys can be written when saving custom profile fields, allowing users with at least the Subscriber role to escalate their privileges to Administrator by submitting a crafted...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-12525/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-12535/",
      "current_public_safe_latest": false,
      "cvss_score": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.30913,
      "epss_score": 0.00386,
      "first_observed_at": "2026-07-17T22:09:03.821896+00:00",
      "id": "CVE-2026-12535",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-17T22:09:03.821896+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Formatter Field allows Object Injection. NVD: This issue affects Formatter Field versions: from 0.0.0 to 2.0.0. OSV: Formatter Field - Critical - PHP object injection - SA-CONTRIB-2026-048",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260717T221101Z/items/CVE-2026-12535.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Formatter Field allows Object Injection. NVD: This issue affects Formatter Field versions: from 0.0.0 to 2.0.0. OSV: Formatter Field - Critical - PHP object injection - SA-CONTRIB-2026-048",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-12535/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-12582/",
      "current_public_safe_latest": false,
      "cvss_score": 8.6,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.17749,
      "epss_score": 0.00262,
      "first_observed_at": "2026-07-20T06:28:37.060083+00:00",
      "id": "CVE-2026-12582",
      "impact_tags": [
        "SQL injection risk",
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-20T06:28:37.060083+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Library Management System WordPress plugin before 3.5.8 does not sanitize and escape a user-supplied parameter before using it in a SQL statement, allowing unauthenticated attackers to perform SQL injection and extract arbitrary data from the database...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260720T063049Z/items/CVE-2026-12582.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes SQL injection risk · remote exposure · authenticated boundary. Possible impact: A remote attacker may be able to read or change database-backed application data.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Library Management System WordPress plugin before 3.5.8 does not sanitize and escape a user-supplied parameter before using it in a SQL statement, allowing unauthenticated attackers to perform SQL injection and extract arbitrary data from the database...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-12582/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-12583/",
      "current_public_safe_latest": false,
      "cvss_score": 8.1,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.24807,
      "epss_score": 0.00326,
      "first_observed_at": "2026-07-21T06:08:28.817138+00:00",
      "id": "CVE-2026-12583",
      "impact_tags": [
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-21T06:08:28.817138+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Newsletters WordPress plugin before 4.15 does not prevent deserialization of untrusted input that is stored through a public form, allowing unauthenticated attackers to inject a PHP object and, via a property-oriented gadget chain bundled with the...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260721T061518Z/items/CVE-2026-12583.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes remote exposure · authenticated boundary. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Newsletters WordPress plugin before 4.15 does not prevent deserialization of untrusted input that is stored through a public form, allowing unauthenticated attackers to inject a PHP object and, via a property-oriented gadget chain bundled with the...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-12583/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-12585/",
      "current_public_safe_latest": false,
      "cvss_score": 8.1,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.13445,
      "epss_score": 0.00226,
      "first_observed_at": "2026-07-23T06:13:21.015514+00:00",
      "id": "CVE-2026-12585",
      "impact_tags": [
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-23T06:13:21.015514+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Abandoned Cart Lite for WooCommerce WordPress plugin before 6.8.2 does not protect the integrity of its cart-recovery tokens or bind them to the requesting account, allowing unauthenticated attackers to forge a recovery link that logs them in as another...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260723T061547Z/items/CVE-2026-12585.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes remote exposure · authenticated boundary. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Abandoned Cart Lite for WooCommerce WordPress plugin before 6.8.2 does not protect the integrity of its cart-recovery tokens or bind them to the requesting account, allowing unauthenticated attackers to forge a recovery link that logs them in as another...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-12585/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-12586/",
      "current_public_safe_latest": false,
      "cvss_score": 8.1,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.06095,
      "epss_score": 0.00165,
      "first_observed_at": "2026-08-08T15:50:31.311576+00:00",
      "id": "CVE-2026-12586",
      "impact_tags": [
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-09T04:40:09.231782+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Lenxel WP WordPress theme through 1.0.31 does not perform any authorization or ownership check on its password-reset action, validating only a CSRF nonce, allowing unauthenticated attackers to reset the password of any user (including an administrator)...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260809T044412Z/items/CVE-2026-12586.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 3,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes remote exposure · authenticated boundary. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Lenxel WP WordPress theme through 1.0.31 does not perform any authorization or ownership check on its password-reset action, validating only a CSRF nonce, allowing unauthenticated attackers to reset the password of any user (including an administrator)...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-12586/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-12588/",
      "current_public_safe_latest": false,
      "cvss_score": 6.0,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.11029,
      "epss_score": 0.00208,
      "first_observed_at": "2026-07-21T11:20:19.325173+00:00",
      "id": "CVE-2026-12588",
      "impact_tags": [
        "service availability review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-21T11:20:19.325173+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: An attacker with access to an HX 10.0.0 and previous versions, may send specially-crafted data to the HX console. NVD: The malicious detection would then trigger decompression of a large file that consumes an excessive amount of system resources thus causing a Denial of Service.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260721T112231Z/items/CVE-2026-12588.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes service availability risk. Possible impact: The affected service may become unavailable or unreliable.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: An attacker with access to an HX 10.0.0 and previous versions, may send specially-crafted data to the HX console. NVD: The malicious detection would then trigger decompression of a large file that consumes an excessive amount of system resources thus causing a Denial of Service.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-12588/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "openjsf / body-parser",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-12590/",
      "current_public_safe_latest": false,
      "cvss_score": 3.7,
      "cvss_severity": "LOW",
      "epss_percentile": 0.16292,
      "epss_score": 0.0025,
      "first_observed_at": "2026-07-16T11:14:01.223847+00:00",
      "id": "CVE-2026-12590",
      "impact_tags": [
        "service availability review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-16T11:14:01.223847+00:00",
      "latest_item_url": null,
      "product": "body-parser",
      "public_safe_summary": "NVD: Impact: In body-parser versions prior to 1.20.6 (1.x line) and 2.3.0 (2.x line), when the parser is configured with an invalid limit option value such as an unparseable string or NaN, bytes.parse returns null and the request body size check is silently... NVD: Applications that rely on limit as their primary safeguard against oversized request bodies will accept arbitrarily large payloads, leading to excessive memory and CPU usage and denial of service. NVD: Patches: This issue is fixed in body-parser 1.20.6 and 2.3.0.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260716T111601Z/items/CVE-2026-12590.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: openjsf / body-parser",
      "source_published_impact": "Source describes service availability risk. Possible impact: The affected service may become unavailable or unreliable.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: body-parser.",
      "source_published_summary": "NVD: Impact: In body-parser versions prior to 1.20.6 (1.x line) and 2.3.0 (2.x line), when the parser is configured with an invalid limit option value such as an unparseable string or NaN, bytes.parse returns null and the request body size check is silently... NVD: Applications that rely on limit as their primary safeguard against oversized request bodies will accept arbitrarily large payloads, leading to excessive memory and CPU usage and denial of service. NVD: Patches: This issue is fixed in body-parser 1.20.6 and 2.3.0.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-12590/timeline.json",
      "vendor": "openjsf"
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-12592/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.10644,
      "epss_score": 0.00204,
      "first_observed_at": "2026-07-26T22:15:56.881440+00:00",
      "id": "CVE-2026-12592",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-27T06:45:51.031460+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Exploitation requires the SlimStat Analytics WordPress plugin before 5.5.0 to be configured to use the Cloudflare geolocation provider.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260727T065126Z/items/CVE-2026-12592.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Exploitation requires the SlimStat Analytics WordPress plugin before 5.5.0 to be configured to use the Cloudflare geolocation provider.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-12592/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-12593/",
      "current_public_safe_latest": false,
      "cvss_score": 8.7,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.20039,
      "epss_score": 0.00281,
      "first_observed_at": "2026-07-16T13:54:14.110513+00:00",
      "id": "CVE-2026-12593",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-16T13:54:14.110513+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The implementation of an internal and undocumented Dashboard API endpoint (POST /api/users/~/{user}/tokens) forgot to ensure an HTTP request for creating an API Token for another user had sufficient permission to do so. NVD: Precondition for successful exploitation was a preexisting internal user (with more privileges than the attacker), the attacker knowing its login name and the attacker being able to authenticate to the Dashboard via OAuth/OIDC. NVD: The attacker would then have had to forge a token creation API request on behalf of the other user and could have authenticated and finalized the token creation with their own OAuth/OIDC credentials.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260716T135621Z/items/CVE-2026-12593.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The implementation of an internal and undocumented Dashboard API endpoint (POST /api/users/~/{user}/tokens) forgot to ensure an HTTP request for creating an API Token for another user had sufficient permission to do so. NVD: Precondition for successful exploitation was a preexisting internal user (with more privileges than the attacker), the attacker knowing its login name and the attacker being able to authenticate to the Dashboard via OAuth/OIDC. NVD: The attacker would then have had to forge a token creation API request on behalf of the other user and could have authenticated and finalized the token creation with their own OAuth/OIDC credentials.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-12593/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-12595/",
      "current_public_safe_latest": false,
      "cvss_score": 8.1,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.26876,
      "epss_score": 0.00347,
      "first_observed_at": "2026-07-16T22:18:24.817461+00:00",
      "id": "CVE-2026-12595",
      "impact_tags": [
        "authentication boundary review",
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-16T22:18:24.817461+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The LoginPress Pro plugin for WordPress is vulnerable to Authentication Bypass via Unverified OAuth Email in all versions up to and including 6.2.3. NVD: The vulnerability exists in the loginpress_on_discord_login() Discord OAuth callback handler, which accepts the email field returned by Discord's /users/@me endpoint without ever checking that the profile's verified flag is true, then directly maps that email... NVD: This makes it possible for unauthenticated attackers to take over any existing WordPress account — including administrator accounts — by registering a Discord account configured with an unverified email address that matches the target user's registered...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260716T222035Z/items/CVE-2026-12595.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes authentication boundary review · remote exposure · authenticated boundary. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authentication boundary review · remote exposure · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The LoginPress Pro plugin for WordPress is vulnerable to Authentication Bypass via Unverified OAuth Email in all versions up to and including 6.2.3. NVD: The vulnerability exists in the loginpress_on_discord_login() Discord OAuth callback handler, which accepts the email field returned by Discord's /users/@me endpoint without ever checking that the profile's verified flag is true, then directly maps that email... NVD: This makes it possible for unauthenticated attackers to take over any existing WordPress account — including administrator accounts — by registering a Discord account configured with an unverified email address that matches the target user's registered...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-12595/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-12597/",
      "current_public_safe_latest": false,
      "cvss_score": 8.1,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.34252,
      "epss_score": 0.00422,
      "first_observed_at": "2026-07-16T22:18:24.817461+00:00",
      "id": "CVE-2026-12597",
      "impact_tags": [
        "authentication boundary review",
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-16T22:18:24.817461+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The LoginPress Pro plugin for WordPress is vulnerable to Authentication Bypass via the GitHub OAuth callback in versions up to, and including, 6.2.3. NVD: The vulnerability exists in the loginpress_on_github_login() function, which blindly trusts the first element (profile[0]['email']) of the array returned by GitHub's /user/emails endpoint as an account-binding identifier without verifying that the email... NVD: This makes it possible for unauthenticated attackers to log in as any existing WordPress user, including administrators, by adding an unverified email address matching a local account to their GitHub profile and triggering the OAuth callback via a crafted...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260716T222035Z/items/CVE-2026-12597.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes authentication boundary review · remote exposure · authenticated boundary. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authentication boundary review · remote exposure · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The LoginPress Pro plugin for WordPress is vulnerable to Authentication Bypass via the GitHub OAuth callback in versions up to, and including, 6.2.3. NVD: The vulnerability exists in the loginpress_on_github_login() function, which blindly trusts the first element (profile[0]['email']) of the array returned by GitHub's /user/emails endpoint as an account-binding identifier without verifying that the email... NVD: This makes it possible for unauthenticated attackers to log in as any existing WordPress user, including administrators, by adding an unverified email address matching a local account to their GitHub profile and triggering the OAuth callback via a crafted...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-12597/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-12598/",
      "current_public_safe_latest": false,
      "cvss_score": 8.1,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.26876,
      "epss_score": 0.00347,
      "first_observed_at": "2026-07-16T22:18:24.817461+00:00",
      "id": "CVE-2026-12598",
      "impact_tags": [
        "authentication boundary review",
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-16T22:18:24.817461+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The LoginPress Pro plugin for WordPress is vulnerable to authentication bypass in versions up to and including 6.2.3 via the Spotify Social Login addon. NVD: This is due to the loginpress_on_spotify_login() function trusting the unverified 'email' field returned by Spotify's /v1/me endpoint and using it directly with get_user_by('email', $profile['email']) to identify and log in an existing WordPress account... NVD: This makes it possible for unauthenticated attackers to log in as any existing WordPress user, including Administrators, by registering a Spotify account using the targeted user's email address and authenticating via the Spotify provider.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260716T222035Z/items/CVE-2026-12598.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes authentication boundary review · remote exposure · authenticated boundary. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authentication boundary review · remote exposure · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The LoginPress Pro plugin for WordPress is vulnerable to authentication bypass in versions up to and including 6.2.3 via the Spotify Social Login addon. NVD: This is due to the loginpress_on_spotify_login() function trusting the unverified 'email' field returned by Spotify's /v1/me endpoint and using it directly with get_user_by('email', $profile['email']) to identify and log in an existing WordPress account... NVD: This makes it possible for unauthenticated attackers to log in as any existing WordPress user, including Administrators, by registering a Spotify account using the targeted user's email address and authenticating via the Spotify provider.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-12598/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "eclipse / grizzly",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-12606/",
      "current_public_safe_latest": false,
      "cvss_score": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.08627,
      "epss_score": 0.00188,
      "first_observed_at": "2026-07-21T06:08:28.817138+00:00",
      "id": "CVE-2026-12606",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-21T06:08:28.817138+00:00",
      "latest_item_url": null,
      "product": "grizzly",
      "public_safe_summary": "NVD: Eclipse Grizzly in versions before 5.0.2, cannot properly parse the trailer section in malformed trailer header's line, which can be leveraged to perform HTTP request smuggling. OSV: Eclipse Grizzly in versions before 5.0.2, cannot properly parse the trailer section in malformed trailer header's line, which can be leveraged to perform HTTP request smuggling.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260721T061518Z/items/CVE-2026-12606.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: eclipse / grizzly",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Eclipse Grizzly in versions before 5.0.2, cannot properly parse the trailer section in malformed trailer header's line, which can be leveraged to perform HTTP request smuggling. OSV: Eclipse Grizzly in versions before 5.0.2, cannot properly parse the trailer section in malformed trailer header's line, which can be leveraged to perform HTTP request smuggling.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-12606/timeline.json",
      "vendor": "eclipse"
    },
    {
      "affected_label": "eclipse / theia",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-12609/",
      "current_public_safe_latest": true,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.3374,
      "epss_score": 0.00409,
      "first_observed_at": "2026-08-12T10:29:37.194110+00:00",
      "id": "CVE-2026-12609",
      "impact_tags": [
        "remote exposure relevant"
      ],
      "kev": false,
      "last_observed_at": "2026-08-12T10:29:37.194110+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-12609.json",
      "product": "theia",
      "public_safe_summary": "NVD: In Eclipse Theia versions 1.66.0 and up until including 1.73.1, the @theia/plugin-ext backend exposes the /hostedPlugin/:pluginId/:path(*) HTTP endpoint, which resolves the requested file path with path.resolve(localPath, filePath) without verifying that the... NVD: An unauthenticated network attacker can send percent-encoded ../ sequences (%2e%2e%2f) that decode into the path parameter and escape the plugin directory, allowing arbitrary files readable by the Theia backend process to be retrieved. NVD: Plugin IDs are derived deterministically from a plugin's publisher and name, so built-in plugins serve as reliable anchors that require no prior knowledge of the target system.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260812T103932Z/items/CVE-2026-12609.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: eclipse / theia",
      "source_published_impact": "Source describes remote exposure. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: In Eclipse Theia versions 1.66.0 and up until including 1.73.1, the @theia/plugin-ext backend exposes the /hostedPlugin/:pluginId/:path(*) HTTP endpoint, which resolves the requested file path with path.resolve(localPath, filePath) without verifying that the... NVD: An unauthenticated network attacker can send percent-encoded ../ sequences (%2e%2e%2f) that decode into the path parameter and escape the plugin directory, allowing arbitrary files readable by the Theia backend process to be retrieved. NVD: Plugin IDs are derived deterministically from a plugin's publisher and name, so built-in plugins serve as reliable anchors that require no prior knowledge of the target system.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-12609/timeline.json",
      "vendor": "eclipse"
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-12654/",
      "current_public_safe_latest": false,
      "cvss_score": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.27844,
      "epss_score": 0.00352,
      "first_observed_at": "2026-07-31T06:26:41.124454+00:00",
      "id": "CVE-2026-12654",
      "impact_tags": [
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-31T06:26:41.124454+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Payment Plugins for Stripe WooCommerce plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.0.7. NVD: This is due to the plugin not properly verifying that a user is authorized to perform an action. NVD: This makes it possible for unauthenticated attackers to mark arbitrary pending asynchronous WooCommerce orders as paid by forging a charge.pending event with attacker-controlled metadata.order_id, metadata.gateway_id, and a charge object carrying...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260731T063057Z/items/CVE-2026-12654.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes remote exposure · authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Payment Plugins for Stripe WooCommerce plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.0.7. NVD: This is due to the plugin not properly verifying that a user is authorized to perform an action. NVD: This makes it possible for unauthenticated attackers to mark arbitrary pending asynchronous WooCommerce orders as paid by forging a charge.pending event with attacker-controlled metadata.order_id, metadata.gateway_id, and a charge object carrying...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-12654/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-12684/",
      "current_public_safe_latest": false,
      "cvss_score": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.16334,
      "epss_score": 0.00249,
      "first_observed_at": "2026-07-23T06:13:21.015514+00:00",
      "id": "CVE-2026-12684",
      "impact_tags": [
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-23T06:13:21.015514+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Customer Reviews for WooCommerce WordPress plugin before 5.113.0 does not perform authentication, capability, or nonce checks on one of its media upload AJAX actions when the review media attachment feature is enabled, allowing unauthenticated users to...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260723T061547Z/items/CVE-2026-12684.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Customer Reviews for WooCommerce WordPress plugin before 5.113.0 does not perform authentication, capability, or nonce checks on one of its media upload AJAX actions when the review media attachment feature is enabled, allowing unauthenticated users to...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-12684/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-12685/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.12793,
      "epss_score": 0.00222,
      "first_observed_at": "2026-07-17T05:58:07.763993+00:00",
      "id": "CVE-2026-12685",
      "impact_tags": [
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-17T05:58:07.763993+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The EscortWP escortwp WordPress theme through 3.6.2 was distributed with a vendor-authored, obfuscated backdoor that lets an unauthenticated attacker who supplies a hard-coded, per-build key permanently delete all of the site's content, and that covertly...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260717T060336Z/items/CVE-2026-12685.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes remote exposure · authenticated boundary. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The EscortWP escortwp WordPress theme through 3.6.2 was distributed with a vendor-authored, obfuscated backdoor that lets an unauthenticated attacker who supplies a hard-coded, per-build key permanently delete all of the site's content, and that covertly...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-12685/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-12687/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.21822,
      "epss_score": 0.00296,
      "first_observed_at": "2026-08-06T06:07:21.988664+00:00",
      "id": "CVE-2026-12687",
      "impact_tags": [
        "privilege boundary review",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-06T06:07:21.988664+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The ProfileGrid WordPress plugin before 5.9.9.8 does not restrict which group an anonymous visitor may register into through its front-end registration, allowing unauthenticated users to register directly into a privileged group and be granted that group's...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260806T061754Z/items/CVE-2026-12687.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes privilege escalation risk · authenticated boundary. Possible impact: An attacker may cross a privilege boundary and gain more access than intended.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The ProfileGrid WordPress plugin before 5.9.9.8 does not restrict which group an anonymous visitor may register into through its front-end registration, allowing unauthenticated users to register directly into a privileged group and be granted that group's...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-12687/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-12688/",
      "current_public_safe_latest": false,
      "cvss_score": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.06087,
      "epss_score": 0.00164,
      "first_observed_at": "2026-07-31T06:26:41.124454+00:00",
      "id": "CVE-2026-12688",
      "impact_tags": [
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-31T06:26:41.124454+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The ProfileGrid WordPress plugin before 5.9.9.7 does not verify PayPal IPN notifications before granting paid group membership, allowing unauthenticated attackers to forge a payment notification and mark any user as a paid member of any group without any...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260731T063057Z/items/CVE-2026-12688.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes remote exposure · authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The ProfileGrid WordPress plugin before 5.9.9.7 does not verify PayPal IPN notifications before granting paid group membership, allowing unauthenticated attackers to forge a payment notification and mark any user as a paid member of any group without any...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-12688/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-12689/",
      "current_public_safe_latest": false,
      "cvss_score": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.03624,
      "epss_score": 0.00138,
      "first_observed_at": "2026-07-31T06:26:41.124454+00:00",
      "id": "CVE-2026-12689",
      "impact_tags": [
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-31T06:26:41.124454+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The ProfileGrid WordPress plugin before 5.9.9.7 does not perform any authorization or ownership check on some of its private-message thread actions, allowing authenticated users with Subscriber-level access and above to soft-delete, tamper with the metadata...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260731T063057Z/items/CVE-2026-12689.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The ProfileGrid WordPress plugin before 5.9.9.7 does not perform any authorization or ownership check on some of its private-message thread actions, allowing authenticated users with Subscriber-level access and above to soft-delete, tamper with the metadata...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-12689/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-12690/",
      "current_public_safe_latest": false,
      "cvss_score": 3.8,
      "cvss_severity": "LOW",
      "epss_percentile": 0.04933,
      "epss_score": 0.00152,
      "first_observed_at": "2026-07-31T06:26:41.124454+00:00",
      "id": "CVE-2026-12690",
      "impact_tags": [
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-31T06:26:41.124454+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The ProfileGrid WordPress plugin before 5.9.9.7 does not perform a capability check on its license management actions, relying only on a nonce that is exposed to any logged-in user, allowing authenticated users with Subscriber-level access and above to...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260731T063057Z/items/CVE-2026-12690.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes authenticated boundary. Possible impact: This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The ProfileGrid WordPress plugin before 5.9.9.7 does not perform a capability check on its license management actions, relying only on a nonce that is exposed to any logged-in user, allowing authenticated users with Subscriber-level access and above to...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-12690/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-12691/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.22084,
      "epss_score": 0.00299,
      "first_observed_at": "2026-07-24T16:59:54.170943+00:00",
      "id": "CVE-2026-12691",
      "impact_tags": [
        "authentication boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-24T16:59:54.170943+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Missing authentication for critical function vulnerability in Vimesoft Inc. NVD: Enterprise Video Platform allows Authentication Bypass. NVD: This issue affects Enterprise Video Platform: from 3.11.0.0 before 3.25.0.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260724T170351Z/items/CVE-2026-12691.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes authentication boundary review. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authentication boundary review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Missing authentication for critical function vulnerability in Vimesoft Inc. NVD: Enterprise Video Platform allows Authentication Bypass. NVD: This issue affects Enterprise Video Platform: from 3.11.0.0 before 3.25.0.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-12691/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-12692/",
      "current_public_safe_latest": false,
      "cvss_score": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.27074,
      "epss_score": 0.00346,
      "first_observed_at": "2026-07-24T16:59:54.170943+00:00",
      "id": "CVE-2026-12692",
      "impact_tags": [
        "authentication boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-24T16:59:54.170943+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Unverified password change vulnerability in Vimesoft Inc. NVD: Enterprise Video Platform allows Authentication Bypass. NVD: This issue affects Enterprise Video Platform: from 3.11.0.0 before 3.25.0.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260724T170351Z/items/CVE-2026-12692.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes authentication boundary review. Possible impact: This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authentication boundary review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Unverified password change vulnerability in Vimesoft Inc. NVD: Enterprise Video Platform allows Authentication Bypass. NVD: This issue affects Enterprise Video Platform: from 3.11.0.0 before 3.25.0.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-12692/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-12693/",
      "current_public_safe_latest": false,
      "cvss_score": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.18074,
      "epss_score": 0.00264,
      "first_observed_at": "2026-07-24T16:59:54.170943+00:00",
      "id": "CVE-2026-12693",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-24T16:59:54.170943+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Authorization bypass through User-Controlled key vulnerability in Vimesoft Inc. NVD: Enterprise Video Platform allows Accessing Functionality Not Properly Constrained by ACLs. NVD: This issue affects Enterprise Video Platform: from 3.11.0.0 before 3.25.0.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260724T170351Z/items/CVE-2026-12693.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Authorization bypass through User-Controlled key vulnerability in Vimesoft Inc. NVD: Enterprise Video Platform allows Accessing Functionality Not Properly Constrained by ACLs. NVD: This issue affects Enterprise Video Platform: from 3.11.0.0 before 3.25.0.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-12693/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-12694/",
      "current_public_safe_latest": false,
      "cvss_score": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.15572,
      "epss_score": 0.00243,
      "first_observed_at": "2026-07-24T16:59:54.170943+00:00",
      "id": "CVE-2026-12694",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-24T16:59:54.170943+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Missing Authorization vulnerability in Vimesoft Inc. NVD: Enterprise Video Platform allows Accessing Functionality Not Properly Constrained by ACLs. NVD: This issue affects Enterprise Video Platform: from 3.11.0.0 before 3.25.0.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260724T170351Z/items/CVE-2026-12694.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Missing Authorization vulnerability in Vimesoft Inc. NVD: Enterprise Video Platform allows Accessing Functionality Not Properly Constrained by ACLs. NVD: This issue affects Enterprise Video Platform: from 3.11.0.0 before 3.25.0.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-12694/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-12695/",
      "current_public_safe_latest": false,
      "cvss_score": 8.1,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.21383,
      "epss_score": 0.00292,
      "first_observed_at": "2026-08-07T05:06:11.845797+00:00",
      "id": "CVE-2026-12695",
      "impact_tags": [
        "privilege boundary review",
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-07T05:06:11.845797+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The miniOrange 2FA WordPress plugin before 6.2.6 does not validate the submitted one-time password against the targeted user's stored secret, instead verifying it against an attacker-supplied value, allowing an unauthenticated attacker who knows a victim's...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260807T051140Z/items/CVE-2026-12695.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes privilege escalation risk · remote exposure · authenticated boundary. Possible impact: A remote attacker may cross a privilege boundary and gain more access than intended.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The miniOrange 2FA WordPress plugin before 6.2.6 does not validate the submitted one-time password against the targeted user's stored secret, instead verifying it against an attacker-supplied value, allowing an unauthenticated attacker who knows a victim's...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-12695/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-12696/",
      "current_public_safe_latest": false,
      "cvss_score": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.03218,
      "epss_score": 0.00133,
      "first_observed_at": "2026-08-08T04:31:15.594937+00:00",
      "id": "CVE-2026-12696",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-08T04:31:15.594937+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The wpForo Forum WordPress plugin before 3.1.2 does not sanitize and escape a user profile field before outputting it inside an HTML attribute on the public participant profile page, allowing users with a subscriber-level account to inject JavaScript that...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260808T043750Z/items/CVE-2026-12696.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The wpForo Forum WordPress plugin before 3.1.2 does not sanitize and escape a user profile field before outputting it inside an HTML attribute on the public participant profile page, allowing users with a subscriber-level account to inject JavaScript that...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-12696/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-12697/",
      "current_public_safe_latest": false,
      "cvss_score": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.06594,
      "epss_score": 0.0017,
      "first_observed_at": "2026-08-07T05:06:11.845797+00:00",
      "id": "CVE-2026-12697",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-07T05:06:11.845797+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The wpForo Forum WordPress plugin before 3.1.2 does not verify that an AI chat conversation belongs to the requesting user before deleting its messages, allowing users with a subscriber-level account to permanently delete the stored AI chat message history of...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260807T051140Z/items/CVE-2026-12697.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The wpForo Forum WordPress plugin before 3.1.2 does not verify that an AI chat conversation belongs to the requesting user before deleting its messages, allowing users with a subscriber-level account to permanently delete the stored AI chat message history of...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-12697/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-12698/",
      "current_public_safe_latest": false,
      "cvss_score": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.08268,
      "epss_score": 0.00185,
      "first_observed_at": "2026-08-11T04:43:10.985977+00:00",
      "id": "CVE-2026-12698",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-11T04:43:10.985977+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The wpForo Forum WordPress plugin before 3.1.3 does not restrict which profile fields a member may set when editing their own account, allowing users with a subscriber-level account to write administrator-controlled account-state and reputation fields on...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260811T044729Z/items/CVE-2026-12698.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The wpForo Forum WordPress plugin before 3.1.3 does not restrict which profile fields a member may set when editing their own account, allowing users with a subscriber-level account to write administrator-controlled account-state and reputation fields on...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-12698/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-12701/",
      "current_public_safe_latest": false,
      "cvss_score": 9.0,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.51448,
      "epss_score": 0.00759,
      "first_observed_at": "2026-07-27T12:38:45.912501+00:00",
      "id": "CVE-2026-12701",
      "impact_tags": [
        "path traversal review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-27T12:38:45.912501+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A path traversal vulnerability was found in pulpcore. NVD: The relative_path_validator function only verifies that content paths do not begin with \"/\" but fails to block directory traversal sequences such as \"../\" anywhere in the path. NVD: An authenticated administrator can craft a relative_path containing embedded traversal sequences (e.g., \"looking/normal/../../../../etc/shadow\") that escapes the intended export directory during FilesystemExport operations.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260727T124133Z/items/CVE-2026-12701.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes path traversal review. Possible impact: An attacker may be able to reach files outside the intended application path.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A path traversal vulnerability was found in pulpcore. NVD: The relative_path_validator function only verifies that content paths do not begin with \"/\" but fails to block directory traversal sequences such as \"../\" anywhere in the path. NVD: An authenticated administrator can craft a relative_path containing embedded traversal sequences (e.g., \"looking/normal/../../../../etc/shadow\") that escapes the intended export directory during FilesystemExport operations.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-12701/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-12702/",
      "current_public_safe_latest": false,
      "cvss_score": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.13854,
      "epss_score": 0.00229,
      "first_observed_at": "2026-07-31T06:26:41.124454+00:00",
      "id": "CVE-2026-12702",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-31T06:26:41.124454+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: In affected versions of Octopus Deploy Insufficient checks on the project trigger actions allows an unauthorized user to trigger a deployment.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260731T063057Z/items/CVE-2026-12702.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: In affected versions of Octopus Deploy Insufficient checks on the project trigger actions allows an unauthorized user to trigger a deployment.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-12702/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-12720/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.22744,
      "epss_score": 0.00304,
      "first_observed_at": "2026-08-07T05:06:11.845797+00:00",
      "id": "CVE-2026-12720",
      "impact_tags": [
        "code execution review",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-07T05:06:11.845797+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Kirki WordPress plugin before 6.0.13 does not restrict which classes may be instantiated when it deserialises data that unauthenticated users can store, leading to PHP Object Injection that is triggered when an administrator later reviews the stored data. NVD: With a suitable gadget chain present on the site (via another installed Kirki WordPress plugin before 6.0.13, , or an outdated WordPress version), this could be leveraged to perform a variety of attacks, such as remote code execution.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260807T051140Z/items/CVE-2026-12720.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes code execution review · authenticated boundary. Possible impact: An attacker may be able to run code or commands on affected systems.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Kirki WordPress plugin before 6.0.13 does not restrict which classes may be instantiated when it deserialises data that unauthenticated users can store, leading to PHP Object Injection that is triggered when an administrator later reviews the stored data. NVD: With a suitable gadget chain present on the site (via another installed Kirki WordPress plugin before 6.0.13, , or an outdated WordPress version), this could be leveraged to perform a variety of attacks, such as remote code execution.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-12720/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-12721/",
      "current_public_safe_latest": false,
      "cvss_score": 8.6,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.17865,
      "epss_score": 0.00262,
      "first_observed_at": "2026-08-07T05:06:11.845797+00:00",
      "id": "CVE-2026-12721",
      "impact_tags": [
        "SQL injection risk",
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-07T05:06:11.845797+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Kirki WordPress plugin before 6.0.13 does not properly sanitise and escape a value taken from the request before using it in a SQL statement, allowing unauthenticated attackers to perform SQL injection attacks.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260807T051140Z/items/CVE-2026-12721.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes SQL injection risk · remote exposure · authenticated boundary. Possible impact: A remote attacker may be able to read or change database-backed application data.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Kirki WordPress plugin before 6.0.13 does not properly sanitise and escape a value taken from the request before using it in a SQL statement, allowing unauthenticated attackers to perform SQL injection attacks.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-12721/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-12722/",
      "current_public_safe_latest": false,
      "cvss_score": 8.2,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.16945,
      "epss_score": 0.00255,
      "first_observed_at": "2026-08-06T11:35:20.545945+00:00",
      "id": "CVE-2026-12722",
      "impact_tags": [
        "authentication boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-06T11:35:20.545945+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Missing authentication for critical function vulnerability in FTC Software IT Services FTC E-Commerce Management Panel allows Authentication Bypass. NVD: This issue affects FTC E-Commerce Management Panel: before 1.0.2.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260806T114533Z/items/CVE-2026-12722.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes authentication boundary review. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authentication boundary review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Missing authentication for critical function vulnerability in FTC Software IT Services FTC E-Commerce Management Panel allows Authentication Bypass. NVD: This issue affects FTC E-Commerce Management Panel: before 1.0.2.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-12722/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-12723/",
      "current_public_safe_latest": false,
      "cvss_score": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.10498,
      "epss_score": 0.00203,
      "first_observed_at": "2026-07-26T22:15:56.881440+00:00",
      "id": "CVE-2026-12723",
      "impact_tags": [
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-27T06:45:51.031460+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Kirki WordPress plugin before 6.0.12 does not perform any authorisation check on one of its REST routes, allowing unauthenticated users to overwrite the content of arbitrary existing comments and to create pre-approved comments under a spoofed identity...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260727T065126Z/items/CVE-2026-12723.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Kirki WordPress plugin before 6.0.12 does not perform any authorisation check on one of its REST routes, allowing unauthenticated users to overwrite the content of arbitrary existing comments and to create pre-approved comments under a spoofed identity...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-12723/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-12724/",
      "current_public_safe_latest": false,
      "cvss_score": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.01081,
      "epss_score": 0.00101,
      "first_observed_at": "2026-07-26T22:15:56.881440+00:00",
      "id": "CVE-2026-12724",
      "impact_tags": [
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-27T06:45:51.031460+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Kirki WordPress plugin before 6.0.12 does not sanitise or escape the email subject and body values supplied in a request before including them in the password-reset email it sends as HTML, allowing unauthenticated users to inject arbitrary HTML into the...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260727T065126Z/items/CVE-2026-12724.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Kirki WordPress plugin before 6.0.12 does not sanitise or escape the email subject and body values supplied in a request before including them in the password-reset email it sends as HTML, allowing unauthenticated users to inject arbitrary HTML into the...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-12724/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-12736/",
      "current_public_safe_latest": false,
      "cvss_score": 8.0,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.26336,
      "epss_score": 0.00337,
      "first_observed_at": "2026-07-30T22:30:38.166118+00:00",
      "id": "CVE-2026-12736",
      "impact_tags": [
        "privilege boundary review",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-30T22:30:38.166118+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Wpify Woo plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 5.4.16. NVD: This is due to the SettingsApi::save_option() REST route (POST /wp-json/wpify-woo/v1/option) passing the request-supplied 'option' and 'data' parameters directly to update_option() without any option-name allowlist or value sanitization, while the... NVD: This makes it possible for authenticated attackers, with Shop Manager-level access and above, to elevate their privileges to Administrator by overwriting arbitrary WordPress options (for example setting default_role to administrator and users_can_register to...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260730T224832Z/items/CVE-2026-12736.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes privilege escalation risk · authenticated boundary. Possible impact: An attacker may cross a privilege boundary and gain more access than intended.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Wpify Woo plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 5.4.16. NVD: This is due to the SettingsApi::save_option() REST route (POST /wp-json/wpify-woo/v1/option) passing the request-supplied 'option' and 'data' parameters directly to update_option() without any option-name allowlist or value sanitization, while the... NVD: This makes it possible for authenticated attackers, with Shop Manager-level access and above, to elevate their privileges to Administrator by overwriting arbitrary WordPress options (for example setting default_role to administrator and users_can_register to...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-12736/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-12738/",
      "current_public_safe_latest": false,
      "cvss_score": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.11614,
      "epss_score": 0.00213,
      "first_observed_at": "2026-07-18T05:38:40.092323+00:00",
      "id": "CVE-2026-12738",
      "impact_tags": [
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-18T07:15:27.585758+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The WP Easy Pay – Payment and Donation form Builder for Square plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.5.0. NVD: This is due to the plugin not properly verifying that a user is authorized to perform an action. NVD: This makes it possible for authenticated attackers, with subscriber-level access and above, to set the status of arbitrary posts and pages to 'draft', effectively unpublishing arbitrary site content.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260718T071858Z/items/CVE-2026-12738.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The WP Easy Pay – Payment and Donation form Builder for Square plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.5.0. NVD: This is due to the plugin not properly verifying that a user is authorized to perform an action. NVD: This makes it possible for authenticated attackers, with subscriber-level access and above, to set the status of arbitrary posts and pages to 'draft', effectively unpublishing arbitrary site content.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-12738/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-12740/",
      "current_public_safe_latest": false,
      "cvss_score": 8.1,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.06796,
      "epss_score": 0.00172,
      "first_observed_at": "2026-07-11T16:12:59.014043+00:00",
      "id": "CVE-2026-12740",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-11T16:12:59.014043+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Plack::Middleware::OAuth versions through 0.10 for Perl do not support the OAuth 2.0 state parameter. NVD: RequestTokenV2 builds the provider authorization redirect without issuing a state value, and AccessTokenV2 exchanges the callback code and registers the resulting token into the session (register_session) without verifying that the callback corresponds to an... NVD: Any application that uses this middleware for OAuth 2.0 login is exposed to login cross-site request forgery: because the callback is not bound to the session that began the flow, an attacker who starts an authorization with their own provider account can...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260711T161447Z/items/CVE-2026-12740.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Plack::Middleware::OAuth versions through 0.10 for Perl do not support the OAuth 2.0 state parameter. NVD: RequestTokenV2 builds the provider authorization redirect without issuing a state value, and AccessTokenV2 exchanges the callback code and registers the resulting token into the session (register_session) without verifying that the callback corresponds to an... NVD: Any application that uses this middleware for OAuth 2.0 login is exposed to login cross-site request forgery: because the callback is not bound to the session that began the flow, an attacker who starts an authorization with their own provider account can...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-12740/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-12741/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.22808,
      "epss_score": 0.00304,
      "first_observed_at": "2026-08-04T06:07:04.591309+00:00",
      "id": "CVE-2026-12741",
      "impact_tags": [
        "information exposure review",
        "SQL injection risk",
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-04T06:07:04.591309+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The WP Fast Total Search – The Power of Indexed Search plugin for WordPress is vulnerable to generic SQL Injection via the 'form_data[s]' parameter in all versions up to, and including, 1.80.280 due to insufficient escaping on the user supplied parameter and... NVD: This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260804T061658Z/items/CVE-2026-12741.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes information exposure review · SQL injection risk · remote exposure. Possible impact: A remote attacker may be able to read or change database-backed application data.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The WP Fast Total Search – The Power of Indexed Search plugin for WordPress is vulnerable to generic SQL Injection via the 'form_data[s]' parameter in all versions up to, and including, 1.80.280 due to insufficient escaping on the user supplied parameter and... NVD: This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-12741/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-12746/",
      "current_public_safe_latest": false,
      "cvss_score": 8.1,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.08384,
      "epss_score": 0.00186,
      "first_observed_at": "2026-07-11T16:12:59.014043+00:00",
      "id": "CVE-2026-12746",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-11T16:12:59.014043+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Dancer2::Plugin::Auth::OAuth::Provider versions before 0.23 for Perl do not support the OAuth 2.0 state parameter. NVD: The authentication_url method builds the provider authorization redirect without issuing a state value, and the callback method exchanges the callback code and registers the resulting token into the session without verifying that the callback corresponds to... NVD: Any application that uses this plugin for OAuth 2.0 login is exposed to login cross-site request forgery: because the callback is not bound to the session that began the flow, an attacker who starts an authorization with their own provider account can deliver...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260711T161447Z/items/CVE-2026-12746.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Dancer2::Plugin::Auth::OAuth::Provider versions before 0.23 for Perl do not support the OAuth 2.0 state parameter. NVD: The authentication_url method builds the provider authorization redirect without issuing a state value, and the callback method exchanges the callback code and registers the resulting token into the session without verifying that the callback corresponds to... NVD: Any application that uses this plugin for OAuth 2.0 login is exposed to login cross-site request forgery: because the callback is not bound to the session that began the flow, an attacker who starts an authorization with their own provider account can deliver...",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-12746/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-12753/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.22627,
      "epss_score": 0.00304,
      "first_observed_at": "2026-07-22T22:28:24.662524+00:00",
      "id": "CVE-2026-12753",
      "impact_tags": [
        "information exposure review",
        "SQL injection risk",
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-22T22:28:24.662524+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Advance Product Search- Voice & Ajax Search for WooCommerce plugin for WordPress is vulnerable to generic SQL Injection via the 's' and 'match' parameter in all versions up to, and including, 1.4.4 due to insufficient escaping on the user supplied... NVD: This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260722T223443Z/items/CVE-2026-12753.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes information exposure review · SQL injection risk · remote exposure. Possible impact: A remote attacker may be able to read or change database-backed application data.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Advance Product Search- Voice & Ajax Search for WooCommerce plugin for WordPress is vulnerable to generic SQL Injection via the 's' and 'match' parameter in all versions up to, and including, 1.4.4 due to insufficient escaping on the user supplied... NVD: This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-12753/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-12869/",
      "current_public_safe_latest": false,
      "cvss_score": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.04562,
      "epss_score": 0.00149,
      "first_observed_at": "2026-07-23T06:13:21.015514+00:00",
      "id": "CVE-2026-12869",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-23T06:13:21.015514+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Header Footer Builder for Elementor WordPress plugin before 1.2.1 does not require an administrative capability for its dashboard template-import action (it allows any edit_posts user), so a Contributor can import a template containing an Elementor HTML...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260723T061547Z/items/CVE-2026-12869.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Header Footer Builder for Elementor WordPress plugin before 1.2.1 does not require an administrative capability for its dashboard template-import action (it allows any edit_posts user), so a Contributor can import a template containing an Elementor HTML...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-12869/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-12872/",
      "current_public_safe_latest": false,
      "cvss_score": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.49362,
      "epss_score": 0.0069,
      "first_observed_at": "2026-08-10T04:58:31.923491+00:00",
      "id": "CVE-2026-12872",
      "impact_tags": [
        "code execution review",
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-10T04:58:31.923491+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Webinfos WordPress plugin through 1.2 does not validate the type or name of uploaded files, nor restrict the upload action with any authentication, capability, or nonce check, allowing unauthenticated attackers to upload arbitrary files (including PHP) to...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260810T050414Z/items/CVE-2026-12872.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes code execution review · remote exposure · authenticated boundary. Possible impact: A remote attacker may be able to run code or commands on affected systems.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Webinfos WordPress plugin through 1.2 does not validate the type or name of uploaded files, nor restrict the upload action with any authentication, capability, or nonce check, allowing unauthenticated attackers to upload arbitrary files (including PHP) to...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-12872/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-12877/",
      "current_public_safe_latest": false,
      "cvss_score": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.14996,
      "epss_score": 0.00238,
      "first_observed_at": "2026-07-31T06:26:41.124454+00:00",
      "id": "CVE-2026-12877",
      "impact_tags": [
        "SQL injection risk",
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-31T06:26:41.124454+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Project Management, Bug and Issue Tracking Plugin WordPress plugin before 5.1.0 does not sanitise and escape user supplied input before using it in a SQL query, allowing unauthenticated attackers to perform SQL injection attacks. NVD: This is exploitable in the Project Management, Bug and Issue Tracking Plugin WordPress plugin before 5.1.0's standard front-end issue-tracker configuration.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260731T063057Z/items/CVE-2026-12877.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes SQL injection risk · remote exposure · authenticated boundary. Possible impact: A remote attacker may be able to read or change database-backed application data.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Project Management, Bug and Issue Tracking Plugin WordPress plugin before 5.1.0 does not sanitise and escape user supplied input before using it in a SQL query, allowing unauthenticated attackers to perform SQL injection attacks. NVD: This is exploitable in the Project Management, Bug and Issue Tracking Plugin WordPress plugin before 5.1.0's standard front-end issue-tracker configuration.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-12877/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-12879/",
      "current_public_safe_latest": false,
      "cvss_score": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.08577,
      "epss_score": 0.00188,
      "first_observed_at": "2026-07-16T13:54:14.110513+00:00",
      "id": "CVE-2026-12879",
      "impact_tags": [
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-16T13:54:14.110513+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: An Improper Input Validation vulnerability in BigQuery DAO in Google Cloud Apigee versions prior to 2026-06-12 on Google Cloud Platform allows an authenticated attacker to exfiltrate cross-tenant data. NVD: This vulnerability was patched on 12 June 2026 on the Apigee Servers, and no customer action is needed.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260716T135621Z/items/CVE-2026-12879.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: An Improper Input Validation vulnerability in BigQuery DAO in Google Cloud Apigee versions prior to 2026-06-12 on Google Cloud Platform allows an authenticated attacker to exfiltrate cross-tenant data. NVD: This vulnerability was patched on 12 June 2026 on the Apigee Servers, and no customer action is needed.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-12879/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-12898/",
      "current_public_safe_latest": false,
      "cvss_score": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.20587,
      "epss_score": 0.00284,
      "first_observed_at": "2026-07-26T22:15:56.881440+00:00",
      "id": "CVE-2026-12898",
      "impact_tags": [
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-27T06:45:51.031460+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The All-in-One WP Migration and Backup WordPress plugin before 7.106 does not properly sanitise a user-supplied value before using it to build a file path, allowing unauthenticated attackers to create or append a log file in arbitrary locations outside its...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260727T065126Z/items/CVE-2026-12898.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes remote exposure · authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The All-in-One WP Migration and Backup WordPress plugin before 7.106 does not properly sanitise a user-supplied value before using it to build a file path, allowing unauthenticated attackers to create or append a log file in arbitrary locations outside its...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-12898/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-12906/",
      "current_public_safe_latest": false,
      "cvss_score": 2.7,
      "cvss_severity": "LOW",
      "epss_percentile": 0.07671,
      "epss_score": 0.00179,
      "first_observed_at": "2026-07-23T06:13:21.015514+00:00",
      "id": "CVE-2026-12906",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-23T06:13:21.015514+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The RTMKit WordPress plugin before 2.0.9 does not perform a capability check in one of its AJAX actions and resolves a request-supplied post identifier directly, allowing users with at least the Contributor role to read the titles of other users' private...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260723T061547Z/items/CVE-2026-12906.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The RTMKit WordPress plugin before 2.0.9 does not perform a capability check in one of its AJAX actions and resolves a request-supplied post identifier directly, allowing users with at least the Contributor role to read the titles of other users' private...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-12906/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-12907/",
      "current_public_safe_latest": false,
      "cvss_score": 2.7,
      "cvss_severity": "LOW",
      "epss_percentile": 0.06517,
      "epss_score": 0.00168,
      "first_observed_at": "2026-07-23T06:13:21.015514+00:00",
      "id": "CVE-2026-12907",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-23T06:13:21.015514+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The RTMKit WordPress plugin before 2.0.9 does not perform a proper capability check on one of its -builder AJAX actions, allowing users with at least the Author role to create and activate a site-wide template that overrides the header, footer or other global...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260723T061547Z/items/CVE-2026-12907.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The RTMKit WordPress plugin before 2.0.9 does not perform a proper capability check on one of its -builder AJAX actions, allowing users with at least the Author role to create and activate a site-wide template that overrides the header, footer or other global...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-12907/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-12924/",
      "current_public_safe_latest": false,
      "cvss_score": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.10661,
      "epss_score": 0.00206,
      "first_observed_at": "2026-07-17T05:58:07.763993+00:00",
      "id": "CVE-2026-12924",
      "impact_tags": [
        "XSS risk",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-17T05:58:07.763993+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'etn_faq_content' parameter in all versions up to, and including, 4.1.15 due to insufficient input... NVD: This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260717T060336Z/items/CVE-2026-12924.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes XSS risk · authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'etn_faq_content' parameter in all versions up to, and including, 4.1.15 due to insufficient input... NVD: This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-12924/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-12927/",
      "current_public_safe_latest": false,
      "cvss_score": 8.4,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.1015,
      "epss_score": 0.00201,
      "first_observed_at": "2026-08-05T11:32:09.387600+00:00",
      "id": "CVE-2026-12927",
      "impact_tags": [
        "code execution review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-05T11:32:09.387600+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: CWE-787 Out-of-bounds write vulnerability exists that could cause loss of data or potentially risk arbitrary code execution when a malicious CGF file is imported to IGSS Definition.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260805T113552Z/items/CVE-2026-12927.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes code execution review. Possible impact: An attacker may be able to run code or commands on affected systems.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: CWE-787 Out-of-bounds write vulnerability exists that could cause loss of data or potentially risk arbitrary code execution when a malicious CGF file is imported to IGSS Definition.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-12927/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-12936/",
      "current_public_safe_latest": false,
      "cvss_score": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.18362,
      "epss_score": 0.00266,
      "first_observed_at": "2026-07-15T11:03:27.604769+00:00",
      "id": "CVE-2026-12936",
      "impact_tags": [
        "information exposure review",
        "SQL injection risk",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-15T11:03:27.604769+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Recurio – Ultimate Subscription for WooCommerce plugin for WordPress is vulnerable to generic SQL Injection via the 'data' parameter in all versions up to, and including, 1.1.3 due to insufficient escaping on the user supplied parameter and lack of... NVD: This makes it possible for authenticated attackers, with shop manager-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260715T110622Z/items/CVE-2026-12936.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes information exposure review · SQL injection risk · authenticated boundary. Possible impact: An attacker may be able to read or change database-backed application data.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Recurio – Ultimate Subscription for WooCommerce plugin for WordPress is vulnerable to generic SQL Injection via the 'data' parameter in all versions up to, and including, 1.1.3 due to insufficient escaping on the user supplied parameter and lack of... NVD: This makes it possible for authenticated attackers, with shop manager-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-12936/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-12938/",
      "current_public_safe_latest": false,
      "cvss_score": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.11632,
      "epss_score": 0.00212,
      "first_observed_at": "2026-08-04T22:31:51.932237+00:00",
      "id": "CVE-2026-12938",
      "impact_tags": [
        "XSS risk",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-04T22:31:51.932237+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Newsletters Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'target' attribute of the [newsletters_post] shortcode in versions up to and including 4.15. NVD: This is due to insufficient input sanitization and output escaping in the posts_single() function which propagates the attacker-controlled 'target' attribute into the global $wpml_target, and in the shortcode_posts() 'post_thumbnail' handler which... NVD: This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260804T223546Z/items/CVE-2026-12938.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes XSS risk · authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Newsletters Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'target' attribute of the [newsletters_post] shortcode in versions up to and including 4.15. NVD: This is due to insufficient input sanitization and output escaping in the posts_single() function which propagates the attacker-controlled 'target' attribute into the global $wpml_target, and in the shortcode_posts() 'post_thumbnail' handler which... NVD: This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-12938/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-12939/",
      "current_public_safe_latest": false,
      "cvss_score": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.11632,
      "epss_score": 0.00212,
      "first_observed_at": "2026-08-04T22:31:51.932237+00:00",
      "id": "CVE-2026-12939",
      "impact_tags": [
        "XSS risk",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-04T22:31:51.932237+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Newsletters Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'link' attribute of the post_thumbnail (and newsletters_post_thumbnail) shortcodes in versions up to and including 4.15. NVD: This is due to insufficient input sanitization and output escaping in the post_thumbnail() method in helpers/shortcode.php, which concatenates the user-controlled $link shortcode attribute directly into an href attribute without esc_url() or esc_attr(). NVD: This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260804T223546Z/items/CVE-2026-12939.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes XSS risk · authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Newsletters Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'link' attribute of the post_thumbnail (and newsletters_post_thumbnail) shortcodes in versions up to and including 4.15. NVD: This is due to insufficient input sanitization and output escaping in the post_thumbnail() method in helpers/shortcode.php, which concatenates the user-controlled $link shortcode attribute directly into an href attribute without esc_url() or esc_attr(). NVD: This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-12939/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-12941/",
      "current_public_safe_latest": false,
      "cvss_score": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.16933,
      "epss_score": 0.00254,
      "first_observed_at": "2026-07-22T22:28:24.662524+00:00",
      "id": "CVE-2026-12941",
      "impact_tags": [
        "information exposure review",
        "SQL injection risk",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-22T22:28:24.662524+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The MultiVendorX – WooCommerce Multivendor Marketplace AI Powered Solutions plugin for WordPress is vulnerable to generic SQL Injection via the 'order_by' parameter in all versions up to, and including, 5.0.9 due to insufficient escaping on the user supplied... NVD: This makes it possible for authenticated attackers, with subscriber-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. NVD: This vulnerability is exploitable by any authenticated subscriber-level user when the plugin's store approval setting is configured to automatically approve store owners (described as the default), as this allows any logged-in user to self-register as a...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260722T223443Z/items/CVE-2026-12941.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes information exposure review · SQL injection risk · authenticated boundary. Possible impact: An attacker may be able to read or change database-backed application data.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The MultiVendorX – WooCommerce Multivendor Marketplace AI Powered Solutions plugin for WordPress is vulnerable to generic SQL Injection via the 'order_by' parameter in all versions up to, and including, 5.0.9 due to insufficient escaping on the user supplied... NVD: This makes it possible for authenticated attackers, with subscriber-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. NVD: This vulnerability is exploitable by any authenticated subscriber-level user when the plugin's store approval setting is configured to automatically approve store owners (described as the default), as this allows any logged-in user to self-register as a...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-12941/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-12948/",
      "current_public_safe_latest": false,
      "cvss_score": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.18625,
      "epss_score": 0.00269,
      "first_observed_at": "2026-07-14T10:57:43.777280+00:00",
      "id": "CVE-2026-12948",
      "impact_tags": [
        "XSS risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-14T10:57:43.777280+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A stored cross-site scripting (XSS) vulnerability in the web management interface of the Digi PortServer TS, Digi One SP, Digi One SP IA, and Digi One IA allows a remote, authenticated administrator to inject script into certain system configuration fields. NVD: The script subsequently executes in the browser of a user who views the affected pages (CWE-79).",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260714T110007Z/items/CVE-2026-12948.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes XSS risk. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A stored cross-site scripting (XSS) vulnerability in the web management interface of the Digi PortServer TS, Digi One SP, Digi One SP IA, and Digi One IA allows a remote, authenticated administrator to inject script into certain system configuration fields. NVD: The script subsequently executes in the browser of a user who views the affected pages (CWE-79).",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-12948/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-12955/",
      "current_public_safe_latest": false,
      "cvss_score": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.09494,
      "epss_score": 0.00196,
      "first_observed_at": "2026-07-17T05:58:07.763993+00:00",
      "id": "CVE-2026-12955",
      "impact_tags": [
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-17T05:58:07.763993+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The GDPR Cookie Consent plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check and missing nonce verification on the gdpr_cookie_consent_ajax_save_schedule_scan() function (the wp_ajax_gcc_save_schedule_scan... NVD: This makes it possible for authenticated attackers, with Subscriber-level access and above, to modify the plugin's cookie scan schedule configuration stored in the gdpr_scan_schedule_data option, which is an administrative function intended to be limited to...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260717T060336Z/items/CVE-2026-12955.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The GDPR Cookie Consent plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check and missing nonce verification on the gdpr_cookie_consent_ajax_save_schedule_scan() function (the wp_ajax_gcc_save_schedule_scan... NVD: This makes it possible for authenticated attackers, with Subscriber-level access and above, to modify the plugin's cookie scan schedule configuration stored in the gdpr_scan_schedule_data option, which is an administrative function intended to be limited to...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-12955/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-12965/",
      "current_public_safe_latest": false,
      "cvss_score": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.24889,
      "epss_score": 0.00324,
      "first_observed_at": "2026-08-10T04:58:31.923491+00:00",
      "id": "CVE-2026-12965",
      "impact_tags": [
        "SQL injection risk",
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-10T04:58:31.923491+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Super Store Finder WordPress plugin through 7.8 does not sanitize a parameter of an unauthenticated AJAX action before using it in a SQL query, allowing unauthenticated attackers to perform SQL injection and extract data from the database.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260810T050414Z/items/CVE-2026-12965.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes SQL injection risk · remote exposure · authenticated boundary. Possible impact: A remote attacker may be able to read or change database-backed application data.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Super Store Finder WordPress plugin through 7.8 does not sanitize a parameter of an unauthenticated AJAX action before using it in a SQL query, allowing unauthenticated attackers to perform SQL injection and extract data from the database.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-12965/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-12966/",
      "current_public_safe_latest": false,
      "cvss_score": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.12664,
      "epss_score": 0.00221,
      "first_observed_at": "2026-08-08T04:31:15.594937+00:00",
      "id": "CVE-2026-12966",
      "impact_tags": [
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-08T04:31:15.594937+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Direct Payments for WooCommerce WordPress plugin before 2.5.3 does not verify that the requester owns the targeted WooCommerce order in several unauthenticated AJAX handlers before changing its status and overwriting its payment metadata, allowing...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260808T043750Z/items/CVE-2026-12966.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes remote exposure · authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Direct Payments for WooCommerce WordPress plugin before 2.5.3 does not verify that the requester owns the targeted WooCommerce order in several unauthenticated AJAX handlers before changing its status and overwriting its payment metadata, allowing...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-12966/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-12968/",
      "current_public_safe_latest": false,
      "cvss_score": 8.8,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.21391,
      "epss_score": 0.00292,
      "first_observed_at": "2026-07-29T06:10:00.110927+00:00",
      "id": "CVE-2026-12968",
      "impact_tags": [
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-29T06:10:00.110927+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Product Addons and Product Options With Custom Fields WordPress plugin before 1.6.15 does not restrict an unauthenticated file-upload endpoint and accepts SVG files that are stored and served inline, allowing an unauthenticated attacker to upload a...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260729T062752Z/items/CVE-2026-12968.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes remote exposure · authenticated boundary. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Product Addons and Product Options With Custom Fields WordPress plugin before 1.6.15 does not restrict an unauthenticated file-upload endpoint and accepts SVG files that are stored and served inline, allowing an unauthenticated attacker to upload a...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-12968/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-12970/",
      "current_public_safe_latest": false,
      "cvss_score": 7.1,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.043,
      "epss_score": 0.00146,
      "first_observed_at": "2026-07-26T22:15:56.881440+00:00",
      "id": "CVE-2026-12970",
      "impact_tags": [
        "XSS risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-27T06:45:51.031460+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The LearnPress WordPress plugin before 4.4.1 does not escape a search parameter before reflecting it into an HTML attribute, leading to Reflected Cross-Site Scripting that executes in the browser of a logged-in instructor or administrator who is tricked into...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260727T065126Z/items/CVE-2026-12970.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes XSS risk. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The LearnPress WordPress plugin before 4.4.1 does not escape a search parameter before reflecting it into an HTML attribute, leading to Reflected Cross-Site Scripting that executes in the browser of a logged-in instructor or administrator who is tricked into...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-12970/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-12972/",
      "current_public_safe_latest": false,
      "cvss_score": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.07423,
      "epss_score": 0.00176,
      "first_observed_at": "2026-07-26T22:15:56.881440+00:00",
      "id": "CVE-2026-12972",
      "impact_tags": [
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-27T06:45:51.031460+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The PayPlus Payment Gateway WordPress plugin before 8.2.2 does not perform authorization or order-ownership validation in one of its AJAX actions available to unauthenticated users, allowing them to tamper with the payment-related metadata of arbitrary...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260727T065126Z/items/CVE-2026-12972.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The PayPlus Payment Gateway WordPress plugin before 8.2.2 does not perform authorization or order-ownership validation in one of its AJAX actions available to unauthenticated users, allowing them to tamper with the payment-related metadata of arbitrary...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-12972/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-12973/",
      "current_public_safe_latest": false,
      "cvss_score": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.05569,
      "epss_score": 0.0016,
      "first_observed_at": "2026-07-26T22:15:56.881440+00:00",
      "id": "CVE-2026-12973",
      "impact_tags": [
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-27T06:45:51.031460+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The PayPlus Payment Gateway WordPress plugin before 8.2.2 does not perform authorization or order-ownership validation in one of its AJAX actions available to unauthenticated users, allowing them to disclose the secret order key of arbitrary WooCommerce...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260727T065126Z/items/CVE-2026-12973.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The PayPlus Payment Gateway WordPress plugin before 8.2.2 does not perform authorization or order-ownership validation in one of its AJAX actions available to unauthenticated users, allowing them to disclose the secret order key of arbitrary WooCommerce...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-12973/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-12978/",
      "current_public_safe_latest": false,
      "cvss_score": 7.1,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.05999,
      "epss_score": 0.00164,
      "first_observed_at": "2026-07-23T06:13:21.015514+00:00",
      "id": "CVE-2026-12978",
      "impact_tags": [
        "XSS risk",
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-23T06:13:21.015514+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The FunnelKit WordPress plugin before 3.15.0.6 does not escape a user-supplied parameter before reflecting it into the HTML response of one of its page-builder AJAX actions, allowing unauthenticated attackers to perform Reflected Cross-Site Scripting against... NVD: The affected action is only registered when the Divi /builder is active.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260723T061547Z/items/CVE-2026-12978.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes XSS risk · remote exposure · authenticated boundary. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk · remote exposure · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The FunnelKit WordPress plugin before 3.15.0.6 does not escape a user-supplied parameter before reflecting it into the HTML response of one of its page-builder AJAX actions, allowing unauthenticated attackers to perform Reflected Cross-Site Scripting against... NVD: The affected action is only registered when the Divi /builder is active.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-12978/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-12979/",
      "current_public_safe_latest": false,
      "cvss_score": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.09862,
      "epss_score": 0.00198,
      "first_observed_at": "2026-07-23T06:13:21.015514+00:00",
      "id": "CVE-2026-12979",
      "impact_tags": [
        "service availability review",
        "path traversal review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-23T06:13:21.015514+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The FunnelKit WordPress plugin before 3.15.0.6 does not validate a user-supplied path before deleting a file during a template-import operation, allowing users with administrator privileges to delete arbitrary .json files outside the intended directory...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260723T061547Z/items/CVE-2026-12979.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes service availability risk · path traversal review. Possible impact: An attacker may be able to reach files outside the intended application path.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The FunnelKit WordPress plugin before 3.15.0.6 does not validate a user-supplied path before deleting a file during a template-import operation, allowing users with administrator privileges to delete arbitrary .json files outside the intended directory...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-12979/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-12981/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.22836,
      "epss_score": 0.00305,
      "first_observed_at": "2026-07-31T06:26:41.124454+00:00",
      "id": "CVE-2026-12981",
      "impact_tags": [
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-31T06:26:41.124454+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The CAFEHAUS API WordPress plugin through 1.0.0 does not have any authentication or authorisation when updating user passwords, allowing unauthenticated attackers to set the password of any user, including administrators, and fully take over their accounts.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260731T063057Z/items/CVE-2026-12981.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes remote exposure · authenticated boundary. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The CAFEHAUS API WordPress plugin through 1.0.0 does not have any authentication or authorisation when updating user passwords, allowing unauthenticated attackers to set the password of any user, including administrators, and fully take over their accounts.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-12981/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-12982/",
      "current_public_safe_latest": false,
      "cvss_score": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.05865,
      "epss_score": 0.00162,
      "first_observed_at": "2026-08-02T06:14:57.521051+00:00",
      "id": "CVE-2026-12982",
      "impact_tags": [
        "XSS risk",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-03T06:40:38.700520+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Document Gallery WordPress plugin before 5.1.1 does not properly sanitise and escape user input before reflecting it back in the response of an unauthenticated AJAX action, leading to a Reflected Cross-Site Scripting vulnerability which can be exploited...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260803T064356Z/items/CVE-2026-12982.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 5,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes XSS risk · authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Document Gallery WordPress plugin before 5.1.1 does not properly sanitise and escape user input before reflecting it back in the response of an unauthenticated AJAX action, leading to a Reflected Cross-Site Scripting vulnerability which can be exploited...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-12982/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-12987/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.18679,
      "epss_score": 0.00267,
      "first_observed_at": "2026-07-29T06:10:00.110927+00:00",
      "id": "CVE-2026-12987",
      "impact_tags": [
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-29T06:10:00.110927+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Events Manager WordPress plugin before 7.3.7 does not safely handle booking-registration data on sites using No-User-Account Booking Mode: a booker-supplied registration field is stored as booking meta and later deserialized without restricting allowed... NVD: The resulting gadget chain reaches a database query that is built without parameterisation, so an unauthenticated attacker can read arbitrary database data (e.g. NVD: user password hashes, secret keys) when the booking is later loaded.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260729T062752Z/items/CVE-2026-12987.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes remote exposure · authenticated boundary. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Events Manager WordPress plugin before 7.3.7 does not safely handle booking-registration data on sites using No-User-Account Booking Mode: a booker-supplied registration field is stored as booking meta and later deserialized without restricting allowed... NVD: The resulting gadget chain reaches a database query that is built without parameterisation, so an unauthenticated attacker can read arbitrary database data (e.g. NVD: user password hashes, secret keys) when the booking is later loaded.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-12987/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-12988/",
      "current_public_safe_latest": false,
      "cvss_score": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.06546,
      "epss_score": 0.00169,
      "first_observed_at": "2026-07-21T06:08:28.817138+00:00",
      "id": "CVE-2026-12988",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-21T06:08:28.817138+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The WP 2FA WordPress plugin before 3.1.1.2 does not verify that the email address supplied during two-factor authentication setup belongs to the user, allowing an attacker who has obtained a user's credentials to redirect the setup verification code to an...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260721T061518Z/items/CVE-2026-12988.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The WP 2FA WordPress plugin before 3.1.1.2 does not verify that the email address supplied during two-factor authentication setup belongs to the user, allowing an attacker who has obtained a user's credentials to redirect the setup verification code to an...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-12988/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-12989/",
      "current_public_safe_latest": false,
      "cvss_score": 8.7,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.09477,
      "epss_score": 0.00195,
      "first_observed_at": "2026-08-03T12:38:03.310457+00:00",
      "id": "CVE-2026-12989",
      "impact_tags": [
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-03T12:38:03.310457+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A lack of authentication in the mobile app (APK v5.5.0) for Ghost Robotics' Vision 60 robot allows an unauthenticated attacker connected to the device's internal Wi-Fi network to gain unrestricted access to the web administration interface and the HTTP API. NVD: Due to the lack of authorization mechanisms, the attacker can view real-time camera feeds, control the robot’s movements, manage sensors (GPS, RTK, SAM, LIDAR), and execute critical operational commands (Play, Pause, Stop, E-Stop). NVD: Successful exploitation completely compromises the confidentiality, integrity, and physical security of the system.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260803T124716Z/items/CVE-2026-12989.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes remote exposure · authenticated boundary. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A lack of authentication in the mobile app (APK v5.5.0) for Ghost Robotics' Vision 60 robot allows an unauthenticated attacker connected to the device's internal Wi-Fi network to gain unrestricted access to the web administration interface and the HTTP API. NVD: Due to the lack of authorization mechanisms, the attacker can view real-time camera feeds, control the robot’s movements, manage sensors (GPS, RTK, SAM, LIDAR), and execute critical operational commands (Play, Pause, Stop, E-Stop). NVD: Successful exploitation completely compromises the confidentiality, integrity, and physical security of the system.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-12989/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-12990/",
      "current_public_safe_latest": false,
      "cvss_score": 7.7,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.03096,
      "epss_score": 0.00131,
      "first_observed_at": "2026-08-03T12:38:03.310457+00:00",
      "id": "CVE-2026-12990",
      "impact_tags": [
        "information exposure review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-03T12:38:03.310457+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: An access control vulnerability in the mobile app (APK v5.5.0) for Ghost Robotics' Vision 60 robot allows multiple simultaneous sessions to run without proper client validation or session integrity checks. NVD: An attacker with a modified version of the app can connect to the robot during an active, legitimate session. NVD: This allows the attacker to bypass control restrictions, intercept sensitive information (such as real-time video), and partially interact with the system unnoticed and without disconnecting the legitimate user, compromising confidentiality and operational...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260803T124716Z/items/CVE-2026-12990.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes information exposure review. Possible impact: An attacker may be able to access information that should not be exposed.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: An access control vulnerability in the mobile app (APK v5.5.0) for Ghost Robotics' Vision 60 robot allows multiple simultaneous sessions to run without proper client validation or session integrity checks. NVD: An attacker with a modified version of the app can connect to the robot during an active, legitimate session. NVD: This allows the attacker to bypass control restrictions, intercept sensitive information (such as real-time video), and partially interact with the system unnoticed and without disconnecting the legitimate user, compromising confidentiality and operational...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-12990/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-12991/",
      "current_public_safe_latest": false,
      "cvss_score": 8.7,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.03995,
      "epss_score": 0.00142,
      "first_observed_at": "2026-08-03T12:38:03.310457+00:00",
      "id": "CVE-2026-12991",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-03T12:38:03.310457+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The lack of cryptographic mechanisms to ensure the integrity and authenticity of communications in Ghost Robotics' Vision 60 robot (APK v5.5.0) exposes the system to man-in-the-middle attacks. NVD: An attacker located on the local network can use ARP spoofing and selective traffic blocking techniques to intercept and manipulate packets between the legitimate operator and the robot. NVD: This allows the attacker to disconnect the original controller, establish unauthorized communications, and prevent the operator from regaining control of the device, seriously compromising the confidentiality, integrity, and availability (CIA) of operations.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260803T124716Z/items/CVE-2026-12991.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The lack of cryptographic mechanisms to ensure the integrity and authenticity of communications in Ghost Robotics' Vision 60 robot (APK v5.5.0) exposes the system to man-in-the-middle attacks. NVD: An attacker located on the local network can use ARP spoofing and selective traffic blocking techniques to intercept and manipulate packets between the legitimate operator and the robot. NVD: This allows the attacker to disconnect the original controller, establish unauthorized communications, and prevent the operator from regaining control of the device, seriously compromising the confidentiality, integrity, and availability (CIA) of operations.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-12991/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-12994/",
      "current_public_safe_latest": false,
      "cvss_score": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.28347,
      "epss_score": 0.00361,
      "first_observed_at": "2026-07-18T05:38:40.092323+00:00",
      "id": "CVE-2026-12994",
      "impact_tags": [
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-18T07:15:27.585758+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The WCFM – Frontend Manager for WooCommerce plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 6.7.27. NVD: This is due to the plugin not properly verifying that a user is authorized to perform an action. NVD: This makes it possible for unauthenticated attackers to inject arbitrary reply content into any store inquiry, overwrite the main inquiry record in wp_wcfm_enquiries, and trigger unsolicited notification emails to customers and vendors.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260718T071858Z/items/CVE-2026-12994.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes remote exposure · authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The WCFM – Frontend Manager for WooCommerce plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 6.7.27. NVD: This is due to the plugin not properly verifying that a user is authorized to perform an action. NVD: This makes it possible for unauthenticated attackers to inject arbitrary reply content into any store inquiry, overwrite the main inquiry record in wp_wcfm_enquiries, and trigger unsolicited notification emails to customers and vendors.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-12994/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-13005/",
      "current_public_safe_latest": false,
      "cvss_score": 4.4,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.10982,
      "epss_score": 0.00207,
      "first_observed_at": "2026-07-22T22:28:24.662524+00:00",
      "id": "CVE-2026-13005",
      "impact_tags": [
        "XSS risk",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-22T22:28:24.662524+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The MxChat – AI Chatbot & Content Generation for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.2.10 due to insufficient input sanitization and output escaping. NVD: This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. NVD: This only affects multi-site installations and installations where unfiltered_html has been disabled.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260722T223443Z/items/CVE-2026-13005.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes XSS risk · authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The MxChat – AI Chatbot & Content Generation for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.2.10 due to insufficient input sanitization and output escaping. NVD: This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. NVD: This only affects multi-site installations and installations where unfiltered_html has been disabled.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-13005/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-13011/",
      "current_public_safe_latest": false,
      "cvss_score": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.18601,
      "epss_score": 0.00269,
      "first_observed_at": "2026-07-16T05:57:17.509937+00:00",
      "id": "CVE-2026-13011",
      "impact_tags": [
        "information exposure review",
        "SQL injection risk",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-16T05:57:17.509937+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The ERP: Complete HR, Accounting & CRM Suite with Recruitment and WooCommerce CRM Support plugin for WordPress is vulnerable to generic SQL Injection via the 'orderby' parameter in all versions up to, and including, 1.17.5 due to insufficient escaping on the... NVD: This makes it possible for authenticated attackers, with custom-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. NVD: Exploitation requires the erp_list_employee capability, which is granted to HR Manager-level users and above within the WP ERP plugin.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260716T055845Z/items/CVE-2026-13011.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes information exposure review · SQL injection risk · authenticated boundary. Possible impact: An attacker may be able to read or change database-backed application data.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The ERP: Complete HR, Accounting & CRM Suite with Recruitment and WooCommerce CRM Support plugin for WordPress is vulnerable to generic SQL Injection via the 'orderby' parameter in all versions up to, and including, 1.17.5 due to insufficient escaping on the... NVD: This makes it possible for authenticated attackers, with custom-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. NVD: Exploitation requires the erp_list_employee capability, which is granted to HR Manager-level users and above within the WP ERP plugin.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-13011/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "esri / portal_for_arcgis",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-13019/",
      "current_public_safe_latest": false,
      "cvss_score": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.33036,
      "epss_score": 0.0041,
      "first_observed_at": "2026-07-14T16:41:04.043226+00:00",
      "id": "CVE-2026-13019",
      "impact_tags": [
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-14T16:41:04.043226+00:00",
      "latest_item_url": null,
      "product": "portal_for_arcgis",
      "public_safe_summary": "NVD: Esri Portal for ArcGIS versions 12.1 and earlier on Windows, Linux and Kubernetes have a missing authentication for critical function vulnerability allows a remote, unauthenticated attacker to access an unprotected API.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260714T164406Z/items/CVE-2026-13019.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: esri / portal_for_arcgis; affected version context: -",
      "source_published_impact": "Source describes remote exposure · authenticated boundary. Possible impact: This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Esri Portal for ArcGIS versions 12.1 and earlier on Windows, Linux and Kubernetes have a missing authentication for critical function vulnerability allows a remote, unauthenticated attacker to access an unprotected API.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-13019/timeline.json",
      "vendor": "esri"
    },
    {
      "affected_label": "esri / portal_for_arcgis",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-13020/",
      "current_public_safe_latest": false,
      "cvss_score": 8.1,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.14242,
      "epss_score": 0.00234,
      "first_observed_at": "2026-07-14T16:41:04.043226+00:00",
      "id": "CVE-2026-13020",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-14T16:41:04.043226+00:00",
      "latest_item_url": null,
      "product": "portal_for_arcgis",
      "public_safe_summary": "NVD: A Weak Password Recovery Mechanism for Forgotten Password exists in Esri Portal for ArcGIS versions 12.1 and earlier on Windows, Linux and Kubernetes. NVD: A remote, unauthorized attacker may assume ownership of a user’s account by manipulating this mechanism. NVD: ArcGIS Administrators should configure an email server with ArcGIS Enterprise to facilitate user self-service password recovery.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260714T164406Z/items/CVE-2026-13020.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: esri / portal_for_arcgis; affected version context: -",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A Weak Password Recovery Mechanism for Forgotten Password exists in Esri Portal for ArcGIS versions 12.1 and earlier on Windows, Linux and Kubernetes. NVD: A remote, unauthorized attacker may assume ownership of a user’s account by manipulating this mechanism. NVD: ArcGIS Administrators should configure an email server with ArcGIS Enterprise to facilitate user self-service password recovery.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-13020/timeline.json",
      "vendor": "esri"
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-13042/",
      "current_public_safe_latest": false,
      "cvss_score": 7.2,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.1606,
      "epss_score": 0.00247,
      "first_observed_at": "2026-07-22T22:28:24.662524+00:00",
      "id": "CVE-2026-13042",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-22T22:28:24.662524+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The RPB Chessboard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content in all versions up to, and including, 8.1.2 due to insufficient input sanitization and output escaping. NVD: This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260722T223443Z/items/CVE-2026-13042.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The RPB Chessboard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content in all versions up to, and including, 8.1.2 due to insufficient input sanitization and output escaping. NVD: This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-13042/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-13050/",
      "current_public_safe_latest": false,
      "cvss_score": 8.6,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.3534,
      "epss_score": 0.00439,
      "first_observed_at": "2026-07-09T22:45:10.548837+00:00",
      "id": "CVE-2026-13050",
      "impact_tags": [
        "code execution review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-09T22:45:10.548837+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: An Out-of-bounds Write vulnerability in WatchGuard Fireware OS networkd process could allow an authenticated privileged user to execute arbitrary code via a specially crafted requests to the Management Web UI.This vulnerability affects Fireware OS 11.8 up to...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260709T224554Z/items/CVE-2026-13050.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes code execution review. Possible impact: An attacker may be able to run code or commands on affected systems.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: An Out-of-bounds Write vulnerability in WatchGuard Fireware OS networkd process could allow an authenticated privileged user to execute arbitrary code via a specially crafted requests to the Management Web UI.This vulnerability affects Fireware OS 11.8 up to...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-13050/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-13053/",
      "current_public_safe_latest": false,
      "cvss_score": 8.6,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.32044,
      "epss_score": 0.00399,
      "first_observed_at": "2026-07-09T22:45:10.548837+00:00",
      "id": "CVE-2026-13053",
      "impact_tags": [
        "code execution review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-09T22:45:10.548837+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: An Out-of-bounds Write vulnerability in WatchGuard Fireware OS's CLI could allow an authenticated privileged user to execute arbitrary code via a specially crafted CLI command. NVD: This vulnerability affects Fireware OS 11.0 up to and including 11.12.4_Update1, 12.0 up to and including 12.12 and 2025.1 up to and including 2026.2.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260709T224554Z/items/CVE-2026-13053.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes code execution review. Possible impact: An attacker may be able to run code or commands on affected systems.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: An Out-of-bounds Write vulnerability in WatchGuard Fireware OS's CLI could allow an authenticated privileged user to execute arbitrary code via a specially crafted CLI command. NVD: This vulnerability affects Fireware OS 11.0 up to and including 11.12.4_Update1, 12.0 up to and including 12.12 and 2025.1 up to and including 2026.2.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-13053/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-13054/",
      "current_public_safe_latest": false,
      "cvss_score": 8.6,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.30968,
      "epss_score": 0.00389,
      "first_observed_at": "2026-07-09T22:45:10.548837+00:00",
      "id": "CVE-2026-13054",
      "impact_tags": [
        "path traversal review",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-09T22:45:10.548837+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A path traversal vulnerability in the WatchGuard Fireware OS Management Web UI allows a privileged authenticated attacker to write arbitrary files on the Firebox's filesystem. NVD: This vulnerability affects Fireware OS 11.0 up to and including 11.12.4_Update1, 12.0 up to and including 12.12 and 2025.1 up to and including 2026.2.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260709T224554Z/items/CVE-2026-13054.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes path traversal review · authenticated boundary. Possible impact: An attacker may be able to reach files outside the intended application path.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A path traversal vulnerability in the WatchGuard Fireware OS Management Web UI allows a privileged authenticated attacker to write arbitrary files on the Firebox's filesystem. NVD: This vulnerability affects Fireware OS 11.0 up to and including 11.12.4_Update1, 12.0 up to and including 12.12 and 2025.1 up to and including 2026.2.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-13054/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-13055/",
      "current_public_safe_latest": false,
      "cvss_score": 7.1,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.21197,
      "epss_score": 0.0029,
      "first_observed_at": "2026-07-29T16:40:34.107276+00:00",
      "id": "CVE-2026-13055",
      "impact_tags": [
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-29T16:40:34.107276+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The $_internalIndexKey aggregation expression can be used by any authenticated user to crash a MongoDB server (mongod). NVD: The expression fails to handle compound wildcard index specifications, triggering an internal consistency check that aborts the server process. NVD: The user must be able to run an aggregation pipeline.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260729T164826Z/items/CVE-2026-13055.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes authenticated boundary. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The $_internalIndexKey aggregation expression can be used by any authenticated user to crash a MongoDB server (mongod). NVD: The expression fails to handle compound wildcard index specifications, triggering an internal consistency check that aborts the server process. NVD: The user must be able to run an aggregation pipeline.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-13055/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-13056/",
      "current_public_safe_latest": false,
      "cvss_score": 7.1,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.21171,
      "epss_score": 0.00289,
      "first_observed_at": "2026-07-29T16:40:34.107276+00:00",
      "id": "CVE-2026-13056",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-29T16:40:34.107276+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Using expressions that generate large arrays it is possible to craft a query that creates very large intermediate objects in memory, causing the server to crash with OOM error.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260729T164826Z/items/CVE-2026-13056.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Using expressions that generate large arrays it is possible to craft a query that creates very large intermediate objects in memory, causing the server to crash with OOM error.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-13056/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-13057/",
      "current_public_safe_latest": false,
      "cvss_score": 6.0,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.17878,
      "epss_score": 0.00262,
      "first_observed_at": "2026-07-29T16:40:34.107276+00:00",
      "id": "CVE-2026-13057",
      "impact_tags": [
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-29T16:40:34.107276+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: An issue in the server’s Atlas Search integration allows an authenticated user to bypass per-user access controls. NVD: In sharded topologies, the $search and $searchMeta aggregation stages use internal routing that is normally populated only by the trusted router during sharded search planning. NVD: Due to insufficient input validation, an authenticated client can supply these fields directly.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260729T164826Z/items/CVE-2026-13057.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: An issue in the server’s Atlas Search integration allows an authenticated user to bypass per-user access controls. NVD: In sharded topologies, the $search and $searchMeta aggregation stages use internal routing that is normally populated only by the trusted router during sharded search planning. NVD: Due to insufficient input validation, an authenticated client can supply these fields directly.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-13057/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-13058/",
      "current_public_safe_latest": false,
      "cvss_score": 7.1,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.13421,
      "epss_score": 0.00226,
      "first_observed_at": "2026-07-29T16:40:34.107276+00:00",
      "id": "CVE-2026-13058",
      "impact_tags": [
        "service availability review",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-29T16:40:34.107276+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: An authenticated user with basic write privileges can cause the mongod process to terminate abnormally by sending a crafted transaction command with an incomplete set of required fields. NVD: The issue stems from inconsistent validation across related transaction command parameters, resulting in a fatal internal invariant failure and denial of service.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260729T164826Z/items/CVE-2026-13058.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes service availability risk · authenticated boundary. Possible impact: The affected service may become unavailable or unreliable.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: An authenticated user with basic write privileges can cause the mongod process to terminate abnormally by sending a crafted transaction command with an incomplete set of required fields. NVD: The issue stems from inconsistent validation across related transaction command parameters, resulting in a fatal internal invariant failure and denial of service.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-13058/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-13079/",
      "current_public_safe_latest": false,
      "cvss_score": 7.3,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.01423,
      "epss_score": 0.00108,
      "first_observed_at": "2026-07-09T22:45:10.548837+00:00",
      "id": "CVE-2026-13079",
      "impact_tags": [
        "privilege boundary review",
        "local exposure relevant"
      ],
      "kev": false,
      "last_observed_at": "2026-07-09T22:45:10.548837+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A local privilege escalation vulnerability in the WatchGuard Mobile VPN with SSL client for Windows allows a local attacker to escalate their privileges to NT AUTHORITY\\SYSTEM on the machine where the client is installed. NVD: This issue affects the Mobile VPN with SSL client for Windows up to and including 2026.2.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260709T224554Z/items/CVE-2026-13079.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes privilege escalation risk · local exposure. Possible impact: A local user may cross a privilege boundary and gain more access than intended.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A local privilege escalation vulnerability in the WatchGuard Mobile VPN with SSL client for Windows allows a local attacker to escalate their privileges to NT AUTHORITY\\SYSTEM on the machine where the client is installed. NVD: This issue affects the Mobile VPN with SSL client for Windows up to and including 2026.2.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-13079/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-13080/",
      "current_public_safe_latest": false,
      "cvss_score": 6.6,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.4936,
      "epss_score": 0.0071,
      "first_observed_at": "2026-07-16T05:57:17.509937+00:00",
      "id": "CVE-2026-13080",
      "impact_tags": [
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-16T05:57:17.509937+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.12.7 via the 'logKey' parameter parameter. NVD: This makes it possible for authenticated attackers, with administrator-level access and above, to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. NVD: This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where .php file types can be uploaded and included.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260716T055845Z/items/CVE-2026-13080.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.12.7 via the 'logKey' parameter parameter. NVD: This makes it possible for authenticated attackers, with administrator-level access and above, to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. NVD: This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where .php file types can be uploaded and included.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-13080/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-13082/",
      "current_public_safe_latest": false,
      "cvss_score": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.12101,
      "epss_score": 0.00216,
      "first_observed_at": "2026-07-24T11:14:35.780564+00:00",
      "id": "CVE-2026-13082",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-24T11:14:35.780564+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: GD::SecurityImage versions through 1.75 for Perl use rand to generate secrets. NVD: The random method creates the challenge text used for the CAPTCHA by sampling characters from an array using Perl's built-in rand function, and generates a (by default) six-character string. NVD: The built-in rand function is unsuitable for security applications because it is predictable and reversible.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260724T111724Z/items/CVE-2026-13082.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: GD::SecurityImage versions through 1.75 for Perl use rand to generate secrets. NVD: The random method creates the challenge text used for the CAPTCHA by sampling characters from an array using Perl's built-in rand function, and generates a (by default) six-character string. NVD: The built-in rand function is unsuitable for security applications because it is predictable and reversible.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-13082/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-13084/",
      "current_public_safe_latest": false,
      "cvss_score": 8.7,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.38939,
      "epss_score": 0.00495,
      "first_observed_at": "2026-07-09T22:45:10.548837+00:00",
      "id": "CVE-2026-13084",
      "impact_tags": [
        "service availability review",
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-09T22:45:10.548837+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A null pointer dereference vulnerability in WatchGuard Fireware OS may allow a remote unauthenticated attacker to create a denial-of-service (DoS) condition by sending specially crafted IKEv2 messages. NVD: This vulnerability affects both the Mobile User VPN with IKEv2 and the Branch Office VPN using IKEv2 when configured with a dynamic gateway peer. NVD: This vulnerability affects Fireware OS 11.10.2 up to and including 11.12.4_Update1, 12.0 up to and including 12.12 and 2025.1 up to and including 2026.2",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260709T224554Z/items/CVE-2026-13084.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes service availability risk · remote exposure · authenticated boundary. Possible impact: The affected service may become unavailable or unreliable.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A null pointer dereference vulnerability in WatchGuard Fireware OS may allow a remote unauthenticated attacker to create a denial-of-service (DoS) condition by sending specially crafted IKEv2 messages. NVD: This vulnerability affects both the Mobile User VPN with IKEv2 and the Branch Office VPN using IKEv2 when configured with a dynamic gateway peer. NVD: This vulnerability affects Fireware OS 11.10.2 up to and including 11.12.4_Update1, 12.0 up to and including 12.12 and 2025.1 up to and including 2026.2",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-13084/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-13103/",
      "current_public_safe_latest": false,
      "cvss_score": 7.0,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.03191,
      "epss_score": 0.00132,
      "first_observed_at": "2026-07-23T16:53:12.033252+00:00",
      "id": "CVE-2026-13103",
      "impact_tags": [
        "code execution review",
        "path traversal review",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-23T16:53:12.033252+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A potential path traversal vulnerability was reported in Lenovo App Store, distributed exclusively in the Chinese market, that could allow a local authenticated user to execute arbitrary code.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260723T171217Z/items/CVE-2026-13103.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes code execution review · path traversal review · authenticated boundary. Possible impact: An attacker may be able to run code or commands on affected systems.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A potential path traversal vulnerability was reported in Lenovo App Store, distributed exclusively in the Chinese market, that could allow a local authenticated user to execute arbitrary code.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-13103/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-13104/",
      "current_public_safe_latest": false,
      "cvss_score": 7.0,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.01625,
      "epss_score": 0.00112,
      "first_observed_at": "2026-07-23T16:53:12.033252+00:00",
      "id": "CVE-2026-13104",
      "impact_tags": [
        "code execution review",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-23T16:53:12.033252+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A potential vulnerability was reported in Lenovo App Store, distributed exclusively in the Chinese market, that could allow a local authenticated user to execute arbitrary code with elevated privileges.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260723T171217Z/items/CVE-2026-13104.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes code execution review · authenticated boundary. Possible impact: An attacker may be able to run code or commands on affected systems.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A potential vulnerability was reported in Lenovo App Store, distributed exclusively in the Chinese market, that could allow a local authenticated user to execute arbitrary code with elevated privileges.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-13104/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-13110/",
      "current_public_safe_latest": false,
      "cvss_score": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.1454,
      "epss_score": 0.00235,
      "first_observed_at": "2026-08-04T11:35:47.800052+00:00",
      "id": "CVE-2026-13110",
      "impact_tags": [
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-04T11:35:47.800052+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Storegrowth Sales Booster plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 2.1.0. NVD: This is due to a missing capability check on the bogo_category_msg_create() AJAX handler, which is registered for both authenticated (wp_ajax_) and unauthenticated (wp_ajax_nopriv_) users and only validates a nonce ('ajd_protected') that is emitted publicly... NVD: This makes it possible for unauthenticated attackers to modify the plugin's BOGO category-message configuration stored in the spsg_bogo_general_settings option by reading the nonce from any public page and POSTing attacker-controlled data to admin-ajax.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260804T114328Z/items/CVE-2026-13110.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes remote exposure · authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Storegrowth Sales Booster plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 2.1.0. NVD: This is due to a missing capability check on the bogo_category_msg_create() AJAX handler, which is registered for both authenticated (wp_ajax_) and unauthenticated (wp_ajax_nopriv_) users and only validates a nonce ('ajd_protected') that is emitted publicly... NVD: This makes it possible for unauthenticated attackers to modify the plugin's BOGO category-message configuration stored in the spsg_bogo_general_settings option by reading the nonce from any public page and POSTing attacker-controlled data to admin-ajax.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-13110/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-13116/",
      "current_public_safe_latest": false,
      "cvss_score": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.12876,
      "epss_score": 0.00223,
      "first_observed_at": "2026-07-18T05:13:28.850753+00:00",
      "id": "CVE-2026-13116",
      "impact_tags": [
        "unauthorized access risk",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-18T05:13:28.850753+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The PDF Invoices & Packing Slips for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.14.0 via the generate_document_shortcode due to missing validation on a user controlled key. NVD: This makes it possible for authenticated attackers, with contributor-level access and above, to mint publicly accessible, session-free download links for arbitrary third-party orders, exposing customer names, billing and shipping addresses, email addresses... NVD: Exploitation requires the plugin's Document link access type setting to be configured to 'full'; with the default 'logged_in' value, generated URLs are signed with a per-session nonce rather than the order_key, making the shortcode path unexploitable for...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260718T051545Z/items/CVE-2026-13116.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes unauthorized access risk · authenticated boundary. Possible impact: An attacker may access resources that should require stronger authorization.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The PDF Invoices & Packing Slips for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.14.0 via the generate_document_shortcode due to missing validation on a user controlled key. NVD: This makes it possible for authenticated attackers, with contributor-level access and above, to mint publicly accessible, session-free download links for arbitrary third-party orders, exposing customer names, billing and shipping addresses, email addresses... NVD: Exploitation requires the plugin's Document link access type setting to be configured to 'full'; with the default 'logged_in' value, generated URLs are signed with a per-session nonce rather than the order_key, making the shortcode path unexploitable for...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-13116/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "foxit / pdf_editor",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-13126/",
      "current_public_safe_latest": false,
      "cvss_score": 7.8,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.0187,
      "epss_score": 0.00116,
      "first_observed_at": "2026-07-15T05:43:30.245469+00:00",
      "id": "CVE-2026-13126",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-15T05:43:30.245469+00:00",
      "latest_item_url": null,
      "product": "pdf_editor",
      "public_safe_summary": "NVD: The embedded JavaScript in the PDF deleted the pages, making the object invalid. NVD: The application attempted to perform a write operation on the invalid pop-up annotations, resulting in the program crashing.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260715T054459Z/items/CVE-2026-13126.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: foxit / pdf_editor; affected version context: -",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The embedded JavaScript in the PDF deleted the pages, making the object invalid. NVD: The application attempted to perform a write operation on the invalid pop-up annotations, resulting in the program crashing.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-13126/timeline.json",
      "vendor": "foxit"
    },
    {
      "affected_label": "foxit / pdf_editor",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-13127/",
      "current_public_safe_latest": false,
      "cvss_score": 7.8,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.01869,
      "epss_score": 0.00116,
      "first_observed_at": "2026-07-15T05:43:30.245469+00:00",
      "id": "CVE-2026-13127",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-15T05:43:30.245469+00:00",
      "latest_item_url": null,
      "product": "pdf_editor",
      "public_safe_summary": "NVD: The application opens the PDF file. NVD: JavaScript then rewrites the document to modify the page structure, resulting in the invalidation of the page objects. NVD: However, the thumbnails still use the invalid page objects, ultimately causing the application to crash.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260715T054459Z/items/CVE-2026-13127.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: foxit / pdf_editor; affected version context: -",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The application opens the PDF file. NVD: JavaScript then rewrites the document to modify the page structure, resulting in the invalidation of the page objects. NVD: However, the thumbnails still use the invalid page objects, ultimately causing the application to crash.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-13127/timeline.json",
      "vendor": "foxit"
    },
    {
      "affected_label": "foxit / pdf_editor",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-13128/",
      "current_public_safe_latest": false,
      "cvss_score": 7.8,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.01871,
      "epss_score": 0.00116,
      "first_observed_at": "2026-07-15T05:43:30.245469+00:00",
      "id": "CVE-2026-13128",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-15T05:43:30.245469+00:00",
      "latest_item_url": null,
      "product": "pdf_editor",
      "public_safe_summary": "NVD: Embedding JavaScript within a PDF file will cause the page to be deleted. NVD: Subsequent scripts will continue to access the relevant properties of the document view, eventually leading to the crash of the application.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260715T054459Z/items/CVE-2026-13128.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: foxit / pdf_editor; affected version context: -",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Embedding JavaScript within a PDF file will cause the page to be deleted. NVD: Subsequent scripts will continue to access the relevant properties of the document view, eventually leading to the crash of the application.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-13128/timeline.json",
      "vendor": "foxit"
    },
    {
      "affected_label": "foxit / pdf_editor",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-13129/",
      "current_public_safe_latest": false,
      "cvss_score": 7.8,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.01871,
      "epss_score": 0.00116,
      "first_observed_at": "2026-07-15T05:43:30.245469+00:00",
      "id": "CVE-2026-13129",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-15T05:43:30.245469+00:00",
      "latest_item_url": null,
      "product": "pdf_editor",
      "public_safe_summary": "NVD: When the application opens a PDF file, JavaScript uses the damaged field tree to trigger field traversal, resulting in the program holding an invalid form object when accessing the field property path. NVD: Eventually, the application crashes due to reading an invalid pointer.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260715T054459Z/items/CVE-2026-13129.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: foxit / pdf_editor; affected version context: -",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: When the application opens a PDF file, JavaScript uses the damaged field tree to trigger field traversal, resulting in the program holding an invalid form object when accessing the field property path. NVD: Eventually, the application crashes due to reading an invalid pointer.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-13129/timeline.json",
      "vendor": "foxit"
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-13142/",
      "current_public_safe_latest": false,
      "cvss_score": 8.1,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.13505,
      "epss_score": 0.00226,
      "first_observed_at": "2026-07-26T22:15:56.881440+00:00",
      "id": "CVE-2026-13142",
      "impact_tags": [
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-27T06:45:51.031460+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Social Login, Passkeys, Magic Link & Email OTP WordPress plugin before 1.4.1 does not enforce rate limiting or a working attempt lockout on its passwordless email one-time-password verification, and stores the short numeric codes in plaintext, allowing an...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260727T065126Z/items/CVE-2026-13142.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes remote exposure · authenticated boundary. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Social Login, Passkeys, Magic Link & Email OTP WordPress plugin before 1.4.1 does not enforce rate limiting or a working attempt lockout on its passwordless email one-time-password verification, and stores the short numeric codes in plaintext, allowing an...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-13142/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-13143/",
      "current_public_safe_latest": false,
      "cvss_score": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.12693,
      "epss_score": 0.00221,
      "first_observed_at": "2026-08-06T06:07:21.988664+00:00",
      "id": "CVE-2026-13143",
      "impact_tags": [
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-06T06:07:21.988664+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The WP Travel WordPress plugin before 11.8.1 does not verify PayPal Instant Payment Notifications through the PayPal post-back handshake before marking a booking paid, allowing unauthenticated attackers to forge a notification that flips an arbitrary pending...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260806T061754Z/items/CVE-2026-13143.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes remote exposure · authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The WP Travel WordPress plugin before 11.8.1 does not verify PayPal Instant Payment Notifications through the PayPal post-back handshake before marking a booking paid, allowing unauthenticated attackers to forge a notification that flips an arbitrary pending...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-13143/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-13145/",
      "current_public_safe_latest": false,
      "cvss_score": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.09625,
      "epss_score": 0.00197,
      "first_observed_at": "2026-08-06T06:07:21.988664+00:00",
      "id": "CVE-2026-13145",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-06T06:07:21.988664+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The WP Travel WordPress plugin before 11.8.1 does not verify that the booking requested on its customer account dashboard belongs to the current user, allowing any logged-in user to read another customer's booking details, including billing address...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260806T061754Z/items/CVE-2026-13145.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The WP Travel WordPress plugin before 11.8.1 does not verify that the booking requested on its customer account dashboard belongs to the current user, allowing any logged-in user to read another customer's booking details, including billing address...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-13145/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-13147/",
      "current_public_safe_latest": false,
      "cvss_score": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.16854,
      "epss_score": 0.00253,
      "first_observed_at": "2026-07-26T22:15:56.881440+00:00",
      "id": "CVE-2026-13147",
      "impact_tags": [
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-27T06:45:51.031460+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Kirki WordPress plugin before 6.0.12 does not validate a user-supplied URL before requesting it server-side, allowing unauthenticated attackers to make the site issue HTTP requests to arbitrary hosts (Server-Side Request Forgery).",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260727T065126Z/items/CVE-2026-13147.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes remote exposure · authenticated boundary. Possible impact: This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Kirki WordPress plugin before 6.0.12 does not validate a user-supplied URL before requesting it server-side, allowing unauthenticated attackers to make the site issue HTTP requests to arbitrary hosts (Server-Side Request Forgery).",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-13147/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-13152/",
      "current_public_safe_latest": false,
      "cvss_score": 8.1,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.13475,
      "epss_score": 0.00226,
      "first_observed_at": "2026-08-02T06:14:57.521051+00:00",
      "id": "CVE-2026-13152",
      "impact_tags": [
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-03T06:40:38.700520+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Custom Fields Account Registration For Woocommerce WordPress plugin before 1.4 does not prevent its custom registration fields from writing to the user capabilities meta key on sites that use a non-default database table prefix, so an unauthenticated user...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260803T064356Z/items/CVE-2026-13152.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 5,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes authenticated boundary. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Custom Fields Account Registration For Woocommerce WordPress plugin before 1.4 does not prevent its custom registration fields from writing to the user capabilities meta key on sites that use a non-default database table prefix, so an unauthenticated user...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-13152/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-13156/",
      "current_public_safe_latest": false,
      "cvss_score": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.02995,
      "epss_score": 0.0013,
      "first_observed_at": "2026-07-26T22:15:56.881440+00:00",
      "id": "CVE-2026-13156",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-27T06:45:51.031460+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The MailerSend WordPress plugin before 1.0.8 does not perform a nonce check on its configuration-delete action (it verifies the manage_options capability but ignores the nonce), so an attacker can trick a logged-in administrator into visiting a crafted page...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260727T065126Z/items/CVE-2026-13156.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The MailerSend WordPress plugin before 1.0.8 does not perform a nonce check on its configuration-delete action (it verifies the manage_options capability but ignores the nonce), so an attacker can trick a logged-in administrator into visiting a crafted page...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-13156/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-13157/",
      "current_public_safe_latest": false,
      "cvss_score": 7.2,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.19912,
      "epss_score": 0.00278,
      "first_observed_at": "2026-08-08T04:31:15.594937+00:00",
      "id": "CVE-2026-13157",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-08T04:31:15.594937+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Demo Import WordPress plugin through 1.1.3 does not validate the type of files uploaded during demo-content import (the WordPress file-type test is disabled), allowing high-privilege users (Administrator by default, including non-super-admin site...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260808T043750Z/items/CVE-2026-13157.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Demo Import WordPress plugin through 1.1.3 does not validate the type of files uploaded during demo-content import (the WordPress file-type test is disabled), allowing high-privilege users (Administrator by default, including non-super-admin site...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-13157/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-13158/",
      "current_public_safe_latest": false,
      "cvss_score": 7.2,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.19913,
      "epss_score": 0.00278,
      "first_observed_at": "2026-08-08T04:31:15.594937+00:00",
      "id": "CVE-2026-13158",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-08T04:31:15.594937+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Everest Toolkit WordPress plugin through 1.2.3 does not validate the type of files uploaded during demo-content import (the WordPress file-type test is disabled), allowing high-privilege users (Administrator by default, including non-super-admin site...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260808T043750Z/items/CVE-2026-13158.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Everest Toolkit WordPress plugin through 1.2.3 does not validate the type of files uploaded during demo-content import (the WordPress file-type test is disabled), allowing high-privilege users (Administrator by default, including non-super-admin site...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-13158/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-13178/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.16774,
      "epss_score": 0.00253,
      "first_observed_at": "2026-08-06T06:07:21.988664+00:00",
      "id": "CVE-2026-13178",
      "impact_tags": [
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-06T06:07:21.988664+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Eventin WordPress plugin before 4.1.16 does not properly authorize order creation and accepts an attacker-supplied order status, allowing unauthenticated users to create orders marked as paid without completing any payment.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260806T061754Z/items/CVE-2026-13178.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes authenticated boundary. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Eventin WordPress plugin before 4.1.16 does not properly authorize order creation and accepts an attacker-supplied order status, allowing unauthenticated users to create orders marked as paid without completing any payment.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-13178/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-13199/",
      "current_public_safe_latest": false,
      "cvss_score": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.01778,
      "epss_score": 0.00114,
      "first_observed_at": "2026-07-14T05:42:23.241208+00:00",
      "id": "CVE-2026-13199",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-14T05:42:23.241208+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: EEPROM firmware on Raspberry Pi 5 and Compute Module 5 devices produced non-random KASLR and RNG seed values. NVD: This resulted in consistent kernel addresses across boots and devices, potentially making it easier to exploit other vulnerabilities. NVD: Additionally, the low-quality RNG seed may affect the quality of random numbers or delay booting while sufficient entropy is accumulated from other sources.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260714T054512Z/items/CVE-2026-13199.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: EEPROM firmware on Raspberry Pi 5 and Compute Module 5 devices produced non-random KASLR and RNG seed values. NVD: This resulted in consistent kernel addresses across boots and devices, potentially making it easier to exploit other vulnerabilities. NVD: Additionally, the low-quality RNG seed may affect the quality of random numbers or delay booting while sufficient entropy is accumulated from other sources.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-13199/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "perl / perl",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-13221/",
      "current_public_safe_latest": false,
      "cvss_score": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.45034,
      "epss_score": 0.00606,
      "first_observed_at": "2026-07-20T11:59:42.107493+00:00",
      "id": "CVE-2026-13221",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-20T11:59:42.107493+00:00",
      "latest_item_url": null,
      "product": "perl",
      "public_safe_summary": "NVD: Perl versions through 5.43.9 produce silently incorrect regular expression matches when an alternation of more than 65535 fixed string branches is compiled into a trie in Perl_study_chunk. NVD: When such branches are combined into a trie, the delta between the first branch and the shared tail is stored in a 16-bit field. NVD: A branch count above 65535 overflows the field, and the trie's match decision table is truncated with no warning or error.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260720T120206Z/items/CVE-2026-13221.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: perl / perl",
      "source_published_impact": "This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Perl versions through 5.43.9 produce silently incorrect regular expression matches when an alternation of more than 65535 fixed string branches is compiled into a trie in Perl_study_chunk. NVD: When such branches are combined into a trie, the delta between the first branch and the shared tail is stored in a 16-bit field. NVD: A branch count above 65535 overflows the field, and the trie's match decision table is truncated with no warning or error.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-13221/timeline.json",
      "vendor": "perl"
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-13231/",
      "current_public_safe_latest": false,
      "cvss_score": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.07848,
      "epss_score": 0.00181,
      "first_observed_at": "2026-07-17T22:09:03.821896+00:00",
      "id": "CVE-2026-13231",
      "impact_tags": [
        "XSS risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-17T22:09:03.821896+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Improper Neutralization of Input During Web Page Generation (\"Cross-site Scripting\") vulnerability in Drupal Advanced Content Feedback (aka admin_feedback) allows Stored XSS. NVD: This issue affects Advanced Content Feedback (aka admin_feedback) versions: from 0.0.0 to 2.8.0.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260717T221101Z/items/CVE-2026-13231.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes XSS risk. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Improper Neutralization of Input During Web Page Generation (\"Cross-site Scripting\") vulnerability in Drupal Advanced Content Feedback (aka admin_feedback) allows Stored XSS. NVD: This issue affects Advanced Content Feedback (aka admin_feedback) versions: from 0.0.0 to 2.8.0.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-13231/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-13232/",
      "current_public_safe_latest": false,
      "cvss_score": 3.1,
      "cvss_severity": "LOW",
      "epss_percentile": 0.05771,
      "epss_score": 0.00162,
      "first_observed_at": "2026-07-17T22:09:03.821896+00:00",
      "id": "CVE-2026-13232",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-17T22:09:03.821896+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Incorrect Authorization vulnerability in Drupal Advanced Content Feedback (aka admin_feedback) allows Forceful Browsing. NVD: This issue affects Advanced Content Feedback (aka admin_feedback) versions: from 0.0.0 to 2.8.0.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260717T221101Z/items/CVE-2026-13232.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Incorrect Authorization vulnerability in Drupal Advanced Content Feedback (aka admin_feedback) allows Forceful Browsing. NVD: This issue affects Advanced Content Feedback (aka admin_feedback) versions: from 0.0.0 to 2.8.0.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-13232/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-13233/",
      "current_public_safe_latest": false,
      "cvss_score": 3.3,
      "cvss_severity": "LOW",
      "epss_percentile": 0.05648,
      "epss_score": 0.00161,
      "first_observed_at": "2026-07-17T22:09:03.821896+00:00",
      "id": "CVE-2026-13233",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-17T22:09:03.821896+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Server-Side Request Forgery (SSRF) vulnerability in Drupal OpenAI Provider allows Server Side Request Forgery. NVD: This issue affects OpenAI Provider versions: from 0.0.0 to 1.1.1, from 1.2.0 to 1.2.2. OSV: OpenAI Provider - Moderately critical - Server-side Request Forgery - SA-CONTRIB-2026-053",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260717T221101Z/items/CVE-2026-13233.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Server-Side Request Forgery (SSRF) vulnerability in Drupal OpenAI Provider allows Server Side Request Forgery. NVD: This issue affects OpenAI Provider versions: from 0.0.0 to 1.1.1, from 1.2.0 to 1.2.2. OSV: OpenAI Provider - Moderately critical - Server-side Request Forgery - SA-CONTRIB-2026-053",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-13233/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-13234/",
      "current_public_safe_latest": false,
      "cvss_score": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.07848,
      "epss_score": 0.00181,
      "first_observed_at": "2026-07-17T22:09:03.821896+00:00",
      "id": "CVE-2026-13234",
      "impact_tags": [
        "information exposure review",
        "XSS risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-17T22:09:03.821896+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Improper Neutralization of Input During Web Page Generation (\"Cross-site Scripting\") vulnerability in Drupal AI (Artificial Intelligence) allows Cross-Site Scripting (XSS). NVD: This issue affects AI (Artificial Intelligence) versions: from 0.0.0 to 1.2.17, from 1.3.0 to 1.3.8, from 1.4.0 to 1.4.3. OSV: AI (Artificial Intelligence) - Moderately critical - Information Disclosure / Cross-site Scripting - SA-CONTRIB-2026-054",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260717T221101Z/items/CVE-2026-13234.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes information exposure review · XSS risk. Possible impact: An attacker may be able to access information that should not be exposed.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Improper Neutralization of Input During Web Page Generation (\"Cross-site Scripting\") vulnerability in Drupal AI (Artificial Intelligence) allows Cross-Site Scripting (XSS). NVD: This issue affects AI (Artificial Intelligence) versions: from 0.0.0 to 1.2.17, from 1.3.0 to 1.3.8, from 1.4.0 to 1.4.3. OSV: AI (Artificial Intelligence) - Moderately critical - Information Disclosure / Cross-site Scripting - SA-CONTRIB-2026-054",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-13234/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "artificial_intelligence_project / artificial_intelligence",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-13235/",
      "current_public_safe_latest": false,
      "cvss_score": 3.3,
      "cvss_severity": "LOW",
      "epss_percentile": 0.05648,
      "epss_score": 0.00161,
      "first_observed_at": "2026-07-17T22:09:03.821896+00:00",
      "id": "CVE-2026-13235",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-17T22:09:03.821896+00:00",
      "latest_item_url": null,
      "product": "artificial_intelligence",
      "public_safe_summary": "NVD: Missing Authorization vulnerability in Drupal AI (Artificial Intelligence) allows Forceful Browsing. NVD: This issue affects AI (Artificial Intelligence) versions: from 0.0.0 to 1.2.17, from 1.3.0 to 1.3.8, from 1.4.0 to 1.4.3. OSV: AI (Artificial Intelligence) - Moderately critical - Access bypass - SA-CONTRIB-2026-055",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260717T221101Z/items/CVE-2026-13235.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: artificial_intelligence_project / artificial_intelligence",
      "source_published_impact": "This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Missing Authorization vulnerability in Drupal AI (Artificial Intelligence) allows Forceful Browsing. NVD: This issue affects AI (Artificial Intelligence) versions: from 0.0.0 to 1.2.17, from 1.3.0 to 1.3.8, from 1.4.0 to 1.4.3. OSV: AI (Artificial Intelligence) - Moderately critical - Access bypass - SA-CONTRIB-2026-055",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-13235/timeline.json",
      "vendor": "artificial_intelligence_project"
    },
    {
      "affected_label": "artificial_intelligence_project / artificial_intelligence",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-13236/",
      "current_public_safe_latest": false,
      "cvss_score": 4.2,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.04205,
      "epss_score": 0.00145,
      "first_observed_at": "2026-07-17T22:09:03.821896+00:00",
      "id": "CVE-2026-13236",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-17T22:09:03.821896+00:00",
      "latest_item_url": null,
      "product": "artificial_intelligence",
      "public_safe_summary": "NVD: Missing Authorization vulnerability in Drupal AI Agents allows Forceful Browsing. NVD: This issue affects AI Agents versions: from 0.0.0 to 1.1.4, from 1.2.0 to 1.2.5, from 1.3.0 to 1.3.1. OSV: AI Agents - Less critical - Access bypass - SA-CONTRIB-2026-056",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260717T221101Z/items/CVE-2026-13236.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: artificial_intelligence_project / artificial_intelligence",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Missing Authorization vulnerability in Drupal AI Agents allows Forceful Browsing. NVD: This issue affects AI Agents versions: from 0.0.0 to 1.1.4, from 1.2.0 to 1.2.5, from 1.3.0 to 1.3.1. OSV: AI Agents - Less critical - Access bypass - SA-CONTRIB-2026-056",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-13236/timeline.json",
      "vendor": "artificial_intelligence_project"
    },
    {
      "affected_label": "artificial_intelligence_project / artificial_intelligence",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-13237/",
      "current_public_safe_latest": false,
      "cvss_score": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.06405,
      "epss_score": 0.00168,
      "first_observed_at": "2026-07-17T22:09:03.821896+00:00",
      "id": "CVE-2026-13237",
      "impact_tags": [
        "information exposure review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-17T22:09:03.821896+00:00",
      "latest_item_url": null,
      "product": "artificial_intelligence",
      "public_safe_summary": "NVD: Incorrect Authorization vulnerability in Drupal AI Agents allows Forceful Browsing. NVD: This issue affects AI Agents versions: from 0.0.0 to 1.1.4, from 1.2.0 to 1.2.5, from 1.3.0 to 1.3.1. OSV: AI Agents - Moderately critical - Information disclosure, Access bypass - SA-CONTRIB-2026-057",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260717T221101Z/items/CVE-2026-13237.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: artificial_intelligence_project / artificial_intelligence",
      "source_published_impact": "Source describes information exposure review. Possible impact: An attacker may be able to access information that should not be exposed.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Incorrect Authorization vulnerability in Drupal AI Agents allows Forceful Browsing. NVD: This issue affects AI Agents versions: from 0.0.0 to 1.1.4, from 1.2.0 to 1.2.5, from 1.3.0 to 1.3.1. OSV: AI Agents - Moderately critical - Information disclosure, Access bypass - SA-CONTRIB-2026-057",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-13237/timeline.json",
      "vendor": "artificial_intelligence_project"
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-13238/",
      "current_public_safe_latest": false,
      "cvss_score": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.12145,
      "epss_score": 0.00217,
      "first_observed_at": "2026-07-17T22:09:03.821896+00:00",
      "id": "CVE-2026-13238",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-17T22:09:03.821896+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Incorrect Authorization vulnerability in Drupal Commerce Realex / Global Payments allows Forceful Browsing. NVD: This issue affects Commerce Realex / Global Payments versions: from 0.0.0 to 3.0.2. OSV: Commerce Realex / Global Payments - Moderately critical - Access Bypass - SA-CONTRIB-2026-058",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260717T221101Z/items/CVE-2026-13238.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Incorrect Authorization vulnerability in Drupal Commerce Realex / Global Payments allows Forceful Browsing. NVD: This issue affects Commerce Realex / Global Payments versions: from 0.0.0 to 3.0.2. OSV: Commerce Realex / Global Payments - Moderately critical - Access Bypass - SA-CONTRIB-2026-058",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-13238/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-13239/",
      "current_public_safe_latest": false,
      "cvss_score": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.05503,
      "epss_score": 0.00159,
      "first_observed_at": "2026-07-17T22:09:03.821896+00:00",
      "id": "CVE-2026-13239",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-17T22:09:03.821896+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Missing Authorization vulnerability in Drupal WissKI allows Forceful Browsing. NVD: This issue affects WissKI versions: from 0.0.0 to 4.2.0.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260717T221101Z/items/CVE-2026-13239.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Missing Authorization vulnerability in Drupal WissKI allows Forceful Browsing. NVD: This issue affects WissKI versions: from 0.0.0 to 4.2.0.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-13239/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-13240/",
      "current_public_safe_latest": false,
      "cvss_score": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.05503,
      "epss_score": 0.00159,
      "first_observed_at": "2026-07-17T22:09:03.821896+00:00",
      "id": "CVE-2026-13240",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-17T22:09:03.821896+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Missing Authorization vulnerability in Drupal Paragraphs allows Forceful Browsing. NVD: This issue affects Paragraphs versions: from 0.0.0 to 1.21.0.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260717T221101Z/items/CVE-2026-13240.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Missing Authorization vulnerability in Drupal Paragraphs allows Forceful Browsing. NVD: This issue affects Paragraphs versions: from 0.0.0 to 1.21.0.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-13240/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-13241/",
      "current_public_safe_latest": false,
      "cvss_score": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.05503,
      "epss_score": 0.00159,
      "first_observed_at": "2026-07-17T22:09:03.821896+00:00",
      "id": "CVE-2026-13241",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-17T22:09:03.821896+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Missing Authorization vulnerability in Drupal Paragraphs allows Forceful Browsing. NVD: This issue affects Paragraphs versions: from 0.0.0 to 1.21.0.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260717T221101Z/items/CVE-2026-13241.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Missing Authorization vulnerability in Drupal Paragraphs allows Forceful Browsing. NVD: This issue affects Paragraphs versions: from 0.0.0 to 1.21.0.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-13241/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-13242/",
      "current_public_safe_latest": false,
      "cvss_score": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.0611,
      "epss_score": 0.00165,
      "first_observed_at": "2026-07-17T22:09:03.821896+00:00",
      "id": "CVE-2026-13242",
      "impact_tags": [
        "SQL injection risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-17T22:09:03.821896+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Drupal Geolocation Field allows SQL Injection. NVD: This issue affects Geolocation Field versions: from 0.0.0 to 3.15.0.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260717T221101Z/items/CVE-2026-13242.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes SQL injection risk. Possible impact: An attacker may be able to read or change database-backed application data.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Drupal Geolocation Field allows SQL Injection. NVD: This issue affects Geolocation Field versions: from 0.0.0 to 3.15.0.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-13242/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-13243/",
      "current_public_safe_latest": false,
      "cvss_score": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.00561,
      "epss_score": 0.0009,
      "first_observed_at": "2026-07-17T22:09:03.821896+00:00",
      "id": "CVE-2026-13243",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-17T22:09:03.821896+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Cross-Site Request Forgery (CSRF) vulnerability in Drupal Salesforce Suite allows Cross Site Request Forgery. NVD: This issue affects Salesforce Suite versions: from 0.0.0 to 5.1.3. OSV: Salesforce Suite - Moderately critical - Cross-site request forgery - SA-CONTRIB-2026-063",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260717T221101Z/items/CVE-2026-13243.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Cross-Site Request Forgery (CSRF) vulnerability in Drupal Salesforce Suite allows Cross Site Request Forgery. NVD: This issue affects Salesforce Suite versions: from 0.0.0 to 5.1.3. OSV: Salesforce Suite - Moderately critical - Cross-site request forgery - SA-CONTRIB-2026-063",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-13243/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-13244/",
      "current_public_safe_latest": false,
      "cvss_score": 8.1,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.3436,
      "epss_score": 0.00423,
      "first_observed_at": "2026-07-17T22:09:03.821896+00:00",
      "id": "CVE-2026-13244",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-17T22:09:03.821896+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Tealium iQ Tag Management allows Object Injection. NVD: This issue affects Tealium iQ Tag Management versions: from 0.0.0 to 2.4.0.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260717T221101Z/items/CVE-2026-13244.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Tealium iQ Tag Management allows Object Injection. NVD: This issue affects Tealium iQ Tag Management versions: from 0.0.0 to 2.4.0.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-13244/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-13250/",
      "current_public_safe_latest": false,
      "cvss_score": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.1922,
      "epss_score": 0.00273,
      "first_observed_at": "2026-07-18T05:13:28.850753+00:00",
      "id": "CVE-2026-13250",
      "impact_tags": [
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-18T05:13:28.850753+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Solace Extra plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.5.3. NVD: This is due to the plugin not properly verifying that a user is authorized to perform an action. NVD: This makes it possible for unauthenticated attackers to permanently delete all content previously imported via the Starter Template feature, including posts, pages, media attachments, WooCommerce products, taxonomy terms, and sitebuilder templates.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260718T051545Z/items/CVE-2026-13250.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes remote exposure · authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Solace Extra plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.5.3. NVD: This is due to the plugin not properly verifying that a user is authorized to perform an action. NVD: This makes it possible for unauthenticated attackers to permanently delete all content previously imported via the Starter Template feature, including posts, pages, media attachments, WooCommerce products, taxonomy terms, and sitebuilder templates.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-13250/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-13329/",
      "current_public_safe_latest": false,
      "cvss_score": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.07092,
      "epss_score": 0.00174,
      "first_observed_at": "2026-08-08T04:31:15.594937+00:00",
      "id": "CVE-2026-13329",
      "impact_tags": [
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-08T04:31:15.594937+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Buckaroo Woocommerce Payments Plugin WordPress plugin before 4.9.0 does not perform any capability check or nonce validation on an AJAX action that processes payment capture refunds, allowing any authenticated user, including Subscribers, to trigger...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260808T043750Z/items/CVE-2026-13329.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Buckaroo Woocommerce Payments Plugin WordPress plugin before 4.9.0 does not perform any capability check or nonce validation on an AJAX action that processes payment capture refunds, allowing any authenticated user, including Subscribers, to trigger...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-13329/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-13330/",
      "current_public_safe_latest": false,
      "cvss_score": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.0786,
      "epss_score": 0.00181,
      "first_observed_at": "2026-08-06T06:07:21.988664+00:00",
      "id": "CVE-2026-13330",
      "impact_tags": [
        "XSS risk"
      ],
      "kev": false,
      "last_observed_at": "2026-08-06T06:07:21.988664+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Animation Addons for Elementor WordPress plugin before 2.7.0 does not sanitise uploaded SVG/SVGZ files, which it adds to the list of allowed upload types, allowing users with the upload_files capability (Author and above) to upload files containing...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260806T061754Z/items/CVE-2026-13330.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes XSS risk. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Animation Addons for Elementor WordPress plugin before 2.7.0 does not sanitise uploaded SVG/SVGZ files, which it adds to the list of allowed upload types, allowing users with the upload_files capability (Author and above) to upload files containing...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-13330/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-13332/",
      "current_public_safe_latest": false,
      "cvss_score": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.15209,
      "epss_score": 0.0024,
      "first_observed_at": "2026-08-02T10:52:32.597181+00:00",
      "id": "CVE-2026-13332",
      "impact_tags": [
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-03T06:40:38.700520+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Masteriyo LMS WordPress plugin before 2.3.1 does not correctly verify authorization on an unauthenticated AJAX action used to clear user sessions, allowing unauthenticated attackers to terminate the active sessions (force-logout) of any user on the site...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260803T064356Z/items/CVE-2026-13332.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 4,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes remote exposure · authenticated boundary. Possible impact: This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Masteriyo LMS WordPress plugin before 2.3.1 does not correctly verify authorization on an unauthenticated AJAX action used to clear user sessions, allowing unauthenticated attackers to terminate the active sessions (force-logout) of any user on the site...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-13332/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-13339/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.47326,
      "epss_score": 0.00641,
      "first_observed_at": "2026-08-08T15:50:31.311576+00:00",
      "id": "CVE-2026-13339",
      "impact_tags": [
        "information exposure review",
        "path traversal review",
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-08T21:49:51.726843+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The CubeWP Framework plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.1.30 via the 'cubewp_get_svg_content' function. NVD: This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information. NVD: This is exploitable by unauthenticated attackers because the required nonce is publicly emitted into the markup of any page rendering the CubeWP posts shortcode or widget with AJAX loading enabled, making it harvestable by any guest visitor before submitting...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260808T215635Z/items/CVE-2026-13339.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes information exposure review · path traversal review · remote exposure. Possible impact: A remote attacker may be able to reach files outside the intended application path.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The CubeWP Framework plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.1.30 via the 'cubewp_get_svg_content' function. NVD: This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information. NVD: This is exploitable by unauthenticated attackers because the required nonce is publicly emitted into the markup of any page rendering the CubeWP posts shortcode or widget with AJAX loading enabled, making it harvestable by any guest visitor before submitting...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-13339/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-13340/",
      "current_public_safe_latest": false,
      "cvss_score": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.07818,
      "epss_score": 0.00181,
      "first_observed_at": "2026-08-10T04:58:31.923491+00:00",
      "id": "CVE-2026-13340",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-10T04:58:31.923491+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The SVG Support WordPress plugin before 2.5.17 does not apply its SVG sanitisation to uploaded files using the .svgz extension, even though it registers and serves them as SVG, allowing a user permitted to upload SVGs (such as an Author once granted upload...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260810T050414Z/items/CVE-2026-13340.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The SVG Support WordPress plugin before 2.5.17 does not apply its SVG sanitisation to uploaded files using the .svgz extension, even though it registers and serves them as SVG, allowing a user permitted to upload SVGs (such as an Author once granted upload...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-13340/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-13344/",
      "current_public_safe_latest": false,
      "cvss_score": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.06959,
      "epss_score": 0.00173,
      "first_observed_at": "2026-08-06T06:07:21.988664+00:00",
      "id": "CVE-2026-13344",
      "impact_tags": [
        "XSS risk"
      ],
      "kev": false,
      "last_observed_at": "2026-08-06T06:07:21.988664+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Essential Addons for Elementor WordPress plugin before 6.6.10 does not validate the HTML tag name of the Pricing Table widget title before outputting it, allowing users with Contributor-level access and above to inject JavaScript that will be executed...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260806T061754Z/items/CVE-2026-13344.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes XSS risk. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Essential Addons for Elementor WordPress plugin before 6.6.10 does not validate the HTML tag name of the Pricing Table widget title before outputting it, allowing users with Contributor-level access and above to inject JavaScript that will be executed...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-13344/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-13345/",
      "current_public_safe_latest": false,
      "cvss_score": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.15782,
      "epss_score": 0.00245,
      "first_observed_at": "2026-08-06T06:07:21.988664+00:00",
      "id": "CVE-2026-13345",
      "impact_tags": [
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-06T06:07:21.988664+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Essential Addons for Elementor WordPress plugin before 6.6.10 does not perform authorization, status, or visibility checks when resolving WooCommerce products in its product-comparison feature, allowing unauthenticated users to disclose the title, price...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260806T061754Z/items/CVE-2026-13345.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Essential Addons for Elementor WordPress plugin before 6.6.10 does not perform authorization, status, or visibility checks when resolving WooCommerce products in its product-comparison feature, allowing unauthenticated users to disclose the title, price...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-13345/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-13347/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.40184,
      "epss_score": 0.00512,
      "first_observed_at": "2026-07-17T05:58:07.763993+00:00",
      "id": "CVE-2026-13347",
      "impact_tags": [
        "path traversal review",
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-17T05:58:07.763993+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Hide My WP Lite plugin for WordPress is vulnerable to Arbitrary File Read in versions up to and including 1.3 via the he_wrapper_js and he_wrapper_css query parameters processed by the elementor_assets_filter() function. NVD: This is due to the function concatenating user-supplied input directly onto ABSPATH and passing the result to file_get_contents() without any path traversal validation, allow-list, realpath containment, or extension check; the result is then echoed in the... NVD: Although the output is passed through wp_kses_post(), that function only filters HTML tags and does not prevent disclosure of arbitrary file contents.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260717T060336Z/items/CVE-2026-13347.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes path traversal review · remote exposure · authenticated boundary. Possible impact: A remote attacker may be able to reach files outside the intended application path.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Hide My WP Lite plugin for WordPress is vulnerable to Arbitrary File Read in versions up to and including 1.3 via the he_wrapper_js and he_wrapper_css query parameters processed by the elementor_assets_filter() function. NVD: This is due to the function concatenating user-supplied input directly onto ABSPATH and passing the result to file_get_contents() without any path traversal validation, allow-list, realpath containment, or extension check; the result is then echoed in the... NVD: Although the output is passed through wp_kses_post(), that function only filters HTML tags and does not prevent disclosure of arbitrary file contents.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-13347/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-13362/",
      "current_public_safe_latest": false,
      "cvss_score": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.10393,
      "epss_score": 0.00203,
      "first_observed_at": "2026-08-07T21:58:42.606809+00:00",
      "id": "CVE-2026-13362",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-07T21:58:42.606809+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The SendPulse Email Marketing Newsletter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via _sp_form_code Post Meta in all versions up to, and including, 2.2.5 due to insufficient input sanitization and output escaping. NVD: This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260807T220457Z/items/CVE-2026-13362.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The SendPulse Email Marketing Newsletter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via _sp_form_code Post Meta in all versions up to, and including, 2.2.5 due to insufficient input sanitization and output escaping. NVD: This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-13362/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-13368/",
      "current_public_safe_latest": false,
      "cvss_score": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.46585,
      "epss_score": 0.00646,
      "first_observed_at": "2026-07-09T22:45:10.548837+00:00",
      "id": "CVE-2026-13368",
      "impact_tags": [
        "code execution review",
        "memory safety review",
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-09T22:45:10.548837+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: WatchGuard Fireware OS contains a race condition leading to a use-after-free vulnerability in LDAP authentication for the Mobile User VPN with IKEv2. NVD: A remote unauthenticated attacker could exploit this vulnerability to execute arbitrary code in the context of the iked process on Fireboxes that have a Mobile VPN with IKEv2 configured to use an external LDAP authentication server. NVD: This vulnerability affects Fireware OS 11.0 up to and including 11.12.4_Update1, 12.0 up to and including 12.12 and 2025.1 up to and including 2026.2.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260709T224554Z/items/CVE-2026-13368.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes code execution review · memory safety review · remote exposure. Possible impact: A remote attacker may be able to run code or commands on affected systems.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: WatchGuard Fireware OS contains a race condition leading to a use-after-free vulnerability in LDAP authentication for the Mobile User VPN with IKEv2. NVD: A remote unauthenticated attacker could exploit this vulnerability to execute arbitrary code in the context of the iked process on Fireboxes that have a Mobile VPN with IKEv2 configured to use an external LDAP authentication server. NVD: This vulnerability affects Fireware OS 11.0 up to and including 11.12.4_Update1, 12.0 up to and including 12.12 and 2025.1 up to and including 2026.2.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-13368/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-13371/",
      "current_public_safe_latest": false,
      "cvss_score": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.22822,
      "epss_score": 0.0031,
      "first_observed_at": "2026-07-09T22:45:10.548837+00:00",
      "id": "CVE-2026-13371",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-09T22:45:10.548837+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: An authenticated administrator can trigger a denial-of-service condition in the Fireware Management Web UI by sending malformed or crafted data to the put_data endpoint, which performs unsafe deserialization of the attacker-supplied input.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260709T224554Z/items/CVE-2026-13371.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: An authenticated administrator can trigger a denial-of-service condition in the Fireware Management Web UI by sending malformed or crafted data to the put_data endpoint, which performs unsafe deserialization of the attacker-supplied input.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-13371/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "watchguard / fireware",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-13373/",
      "current_public_safe_latest": false,
      "cvss_score": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.21061,
      "epss_score": 0.00292,
      "first_observed_at": "2026-07-09T22:45:10.548837+00:00",
      "id": "CVE-2026-13373",
      "impact_tags": [
        "XSS risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-09T22:45:10.548837+00:00",
      "latest_item_url": null,
      "product": "fireware",
      "public_safe_summary": "NVD: Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Fireware OS (Tigerpaw Technology Integration module) allows Stored XSS. NVD: This vulnerability is an additional unmitigated attack path for CVE-2025-13936. NVD: This issue affects Fireware OS 12.4 up to and including 12.12, 12.5 up to and including 12.5.18, and 2025.1 up to and including 2026.2.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260709T224554Z/items/CVE-2026-13373.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: watchguard / fireware; affected version context: -",
      "source_published_impact": "Source describes XSS risk. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Fireware OS (Tigerpaw Technology Integration module) allows Stored XSS. NVD: This vulnerability is an additional unmitigated attack path for CVE-2025-13936. NVD: This issue affects Fireware OS 12.4 up to and including 12.12, 12.5 up to and including 12.5.18, and 2025.1 up to and including 2026.2.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-13373/timeline.json",
      "vendor": "watchguard"
    },
    {
      "affected_label": "watchguard / fireware",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-13374/",
      "current_public_safe_latest": false,
      "cvss_score": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.21061,
      "epss_score": 0.00292,
      "first_observed_at": "2026-07-09T22:45:10.548837+00:00",
      "id": "CVE-2026-13374",
      "impact_tags": [
        "XSS risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-09T22:45:10.548837+00:00",
      "latest_item_url": null,
      "product": "fireware",
      "public_safe_summary": "NVD: Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Fireware OS (ConnectWise Technology Integration module) allows Stored XSS. NVD: This vulnerability is an additional unmitigated attack path for CVE-2025-13937. NVD: This issue affects Fireware OS 12.4 up to and including 12.12, 12.5 up to and including 12.5.18, and 2025.1 up to and including 2026.2.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260709T224554Z/items/CVE-2026-13374.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: watchguard / fireware; affected version context: -",
      "source_published_impact": "Source describes XSS risk. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Fireware OS (ConnectWise Technology Integration module) allows Stored XSS. NVD: This vulnerability is an additional unmitigated attack path for CVE-2025-13937. NVD: This issue affects Fireware OS 12.4 up to and including 12.12, 12.5 up to and including 12.5.18, and 2025.1 up to and including 2026.2.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-13374/timeline.json",
      "vendor": "watchguard"
    },
    {
      "affected_label": "watchguard / fireware",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-13375/",
      "current_public_safe_latest": false,
      "cvss_score": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.21061,
      "epss_score": 0.00292,
      "first_observed_at": "2026-07-09T22:45:10.548837+00:00",
      "id": "CVE-2026-13375",
      "impact_tags": [
        "XSS risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-09T22:45:10.548837+00:00",
      "latest_item_url": null,
      "product": "fireware",
      "public_safe_summary": "NVD: Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Fireware OS (Autotask Technology Integration module) allows Stored XSS. NVD: This vulnerability is an additional unmitigated attack path for CVE-2025-13938. NVD: This issue affects Fireware OS 12.4 up to and including 12.12, 12.5 up to and including 12.5.18, and 2025.1 up to and including 2026.2.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260709T224554Z/items/CVE-2026-13375.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: watchguard / fireware; affected version context: -",
      "source_published_impact": "Source describes XSS risk. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Fireware OS (Autotask Technology Integration module) allows Stored XSS. NVD: This vulnerability is an additional unmitigated attack path for CVE-2025-13938. NVD: This issue affects Fireware OS 12.4 up to and including 12.12, 12.5 up to and including 12.5.18, and 2025.1 up to and including 2026.2.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-13375/timeline.json",
      "vendor": "watchguard"
    },
    {
      "affected_label": "watchguard / fireware",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-13376/",
      "current_public_safe_latest": false,
      "cvss_score": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.2106,
      "epss_score": 0.00292,
      "first_observed_at": "2026-07-09T22:45:10.548837+00:00",
      "id": "CVE-2026-13376",
      "impact_tags": [
        "XSS risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-09T22:45:10.548837+00:00",
      "latest_item_url": null,
      "product": "fireware",
      "public_safe_summary": "NVD: Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Fireware OS spamBlocker module allows Stored XSS. NVD: This vulnerability is an additional unmitigated attack path for CVE-2025-1071. NVD: This issue affects Fireware OS 12.0 up to and including 12.12, 12.5 up to and including 12.5.18, and 2025.1 up to and including 2026.2.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260709T224554Z/items/CVE-2026-13376.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: watchguard / fireware; affected version context: -",
      "source_published_impact": "Source describes XSS risk. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Fireware OS spamBlocker module allows Stored XSS. NVD: This vulnerability is an additional unmitigated attack path for CVE-2025-1071. NVD: This issue affects Fireware OS 12.0 up to and including 12.12, 12.5 up to and including 12.5.18, and 2025.1 up to and including 2026.2.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-13376/timeline.json",
      "vendor": "watchguard"
    },
    {
      "affected_label": "watchguard / fireware",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-13377/",
      "current_public_safe_latest": false,
      "cvss_score": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.2106,
      "epss_score": 0.00292,
      "first_observed_at": "2026-07-09T22:45:10.548837+00:00",
      "id": "CVE-2026-13377",
      "impact_tags": [
        "XSS risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-09T22:45:10.548837+00:00",
      "latest_item_url": null,
      "product": "fireware",
      "public_safe_summary": "NVD: Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Fireware OS SIP Proxy module allows Stored XSS. NVD: This vulnerability is an additional unmitigated attack path for CVE-2025-6947. NVD: This issue affects Fireware OS 12.0 up to and including 12.12, 12.5 up to and including 12.5.18, and 2025.1 up to and including 2026.2.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260709T224554Z/items/CVE-2026-13377.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: watchguard / fireware; affected version context: -",
      "source_published_impact": "Source describes XSS risk. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Fireware OS SIP Proxy module allows Stored XSS. NVD: This vulnerability is an additional unmitigated attack path for CVE-2025-6947. NVD: This issue affects Fireware OS 12.0 up to and including 12.12, 12.5 up to and including 12.5.18, and 2025.1 up to and including 2026.2.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-13377/timeline.json",
      "vendor": "watchguard"
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-13378/",
      "current_public_safe_latest": false,
      "cvss_score": 7.2,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.17356,
      "epss_score": 0.00259,
      "first_observed_at": "2026-07-18T05:13:28.850753+00:00",
      "id": "CVE-2026-13378",
      "impact_tags": [
        "XSS risk",
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-18T05:38:40.092323+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Form Vibes – Database Manager for Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Contact Form 7 Form Field in all versions up to, and including, 1.5.2 due to insufficient input sanitization and output escaping. NVD: This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260718T054021Z/items/CVE-2026-13378.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes XSS risk · remote exposure · authenticated boundary. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk · remote exposure · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Form Vibes – Database Manager for Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Contact Form 7 Form Field in all versions up to, and including, 1.5.2 due to insufficient input sanitization and output escaping. NVD: This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-13378/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "watchguard / fireware",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-13383/",
      "current_public_safe_latest": false,
      "cvss_score": 8.6,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.37174,
      "epss_score": 0.00466,
      "first_observed_at": "2026-07-09T22:45:10.548837+00:00",
      "id": "CVE-2026-13383",
      "impact_tags": [
        "code execution review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-09T22:45:10.548837+00:00",
      "latest_item_url": null,
      "product": "fireware",
      "public_safe_summary": "NVD: An Out-of-bounds Write vulnerability in WatchGuard Fireware OS ikestubd process could allow an authenticated privileged user to execute arbitrary code via a specially crafted requests to the Management Web UI.This vulnerability affects Fireware OS 12.1 up to...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260709T224554Z/items/CVE-2026-13383.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: watchguard / fireware; affected version context: -",
      "source_published_impact": "Source describes code execution review. Possible impact: An attacker may be able to run code or commands on affected systems.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: An Out-of-bounds Write vulnerability in WatchGuard Fireware OS ikestubd process could allow an authenticated privileged user to execute arbitrary code via a specially crafted requests to the Management Web UI.This vulnerability affects Fireware OS 12.1 up to...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-13383/timeline.json",
      "vendor": "watchguard"
    },
    {
      "affected_label": "watchguard / fireware",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-13384/",
      "current_public_safe_latest": false,
      "cvss_score": 8.6,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.37174,
      "epss_score": 0.00466,
      "first_observed_at": "2026-07-09T22:45:10.548837+00:00",
      "id": "CVE-2026-13384",
      "impact_tags": [
        "code execution review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-09T22:45:10.548837+00:00",
      "latest_item_url": null,
      "product": "fireware",
      "public_safe_summary": "NVD: An Out-of-bounds Write vulnerability in WatchGuard Fireware OS wgagent process could allow an authenticated privileged user to execute arbitrary code via a specially crafted requests to the Management Web UI.This vulnerability affects Fireware OS 12.1 up to...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260709T224554Z/items/CVE-2026-13384.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: watchguard / fireware; affected version context: -",
      "source_published_impact": "Source describes code execution review. Possible impact: An attacker may be able to run code or commands on affected systems.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: An Out-of-bounds Write vulnerability in WatchGuard Fireware OS wgagent process could allow an authenticated privileged user to execute arbitrary code via a specially crafted requests to the Management Web UI.This vulnerability affects Fireware OS 12.1 up to...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-13384/timeline.json",
      "vendor": "watchguard"
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-13389/",
      "current_public_safe_latest": false,
      "cvss_score": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.2172,
      "epss_score": 0.00295,
      "first_observed_at": "2026-08-08T15:50:31.311576+00:00",
      "id": "CVE-2026-13389",
      "impact_tags": [
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-09T04:40:09.231782+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The webtoffee-cookie-consent WordPress plugin before 3.5.3 does not perform authorization checks on several of its REST API routes, allowing unauthenticated attackers to export and delete stored visitor consent records, create posts, and modify the...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260809T044412Z/items/CVE-2026-13389.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 3,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes remote exposure · authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The webtoffee-cookie-consent WordPress plugin before 3.5.3 does not perform authorization checks on several of its REST API routes, allowing unauthenticated attackers to export and delete stored visitor consent records, create posts, and modify the...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-13389/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-13390/",
      "current_public_safe_latest": false,
      "cvss_score": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.07982,
      "epss_score": 0.00182,
      "first_observed_at": "2026-08-02T10:52:32.597181+00:00",
      "id": "CVE-2026-13390",
      "impact_tags": [
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-03T06:40:38.700520+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Events Calendar WordPress plugin before 6.16.5.1 does not perform an authorization check on one of its Event Aggregator import REST API routes and skips an integrity check for a particular status value, allowing unauthenticated attackers to mark existing...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260803T064356Z/items/CVE-2026-13390.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 4,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes remote exposure · authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Events Calendar WordPress plugin before 6.16.5.1 does not perform an authorization check on one of its Event Aggregator import REST API routes and skips an integrity check for a particular status value, allowing unauthenticated attackers to mark existing...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-13390/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-13392/",
      "current_public_safe_latest": false,
      "cvss_score": 7.2,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.29691,
      "epss_score": 0.0037,
      "first_observed_at": "2026-08-07T05:06:11.845797+00:00",
      "id": "CVE-2026-13392",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-07T05:06:11.845797+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The ElementsKit Elementor Addons WordPress plugin before 3.10.01 does not prevent a custom-widget definition saved by a user with administrative capabilities from being written verbatim into a generated PHP file that the ElementsKit Elementor Addons WordPress...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260807T051140Z/items/CVE-2026-13392.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The ElementsKit Elementor Addons WordPress plugin before 3.10.01 does not prevent a custom-widget definition saved by a user with administrative capabilities from being written verbatim into a generated PHP file that the ElementsKit Elementor Addons WordPress...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-13392/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-13393/",
      "current_public_safe_latest": false,
      "cvss_score": 3.5,
      "cvss_severity": "LOW",
      "epss_percentile": 0.0399,
      "epss_score": 0.00142,
      "first_observed_at": "2026-08-07T05:06:11.845797+00:00",
      "id": "CVE-2026-13393",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-07T05:06:11.845797+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "CVE-2026-13393: This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review. Human-readable risk label: defensive exposure review. CVSS 3.5 (LOW) helps set defensive review priority. EPSS percentile is 4. Official references are linked for patch or mitigation review.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260807T051140Z/items/CVE-2026-13393.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-13393/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-13395/",
      "current_public_safe_latest": false,
      "cvss_score": 8.6,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.26386,
      "epss_score": 0.00339,
      "first_observed_at": "2026-08-06T06:07:21.988664+00:00",
      "id": "CVE-2026-13395",
      "impact_tags": [
        "SQL injection risk",
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-06T06:07:21.988664+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Online Scheduling and Appointment Booking System WordPress plugin before 27.8 does not sanitize or properly cast a user-supplied parameter from its unauthenticated front-end booking requests before using it in a SQL query, allowing unauthenticated...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260806T061754Z/items/CVE-2026-13395.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes SQL injection risk · remote exposure · authenticated boundary. Possible impact: A remote attacker may be able to read or change database-backed application data.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Online Scheduling and Appointment Booking System WordPress plugin before 27.8 does not sanitize or properly cast a user-supplied parameter from its unauthenticated front-end booking requests before using it in a SQL query, allowing unauthenticated...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-13395/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-13397/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.3184,
      "epss_score": 0.00393,
      "first_observed_at": "2026-07-23T16:53:12.033252+00:00",
      "id": "CVE-2026-13397",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-23T16:53:12.033252+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: HTML::Bare versions through 0.04 for Perl will hang in an infinite loop when parsing malformed attributes. NVD: The parserc_parse function never advances the attribute-parse state cursor on certain malformed attribute forms, looping forever. NVD: Nameless attributes such as \"<a ='c'>\" or unbalanced quotes \"<a b='''''''c'>\" can trigger this condition.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260723T171217Z/items/CVE-2026-13397.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: HTML::Bare versions through 0.04 for Perl will hang in an infinite loop when parsing malformed attributes. NVD: The parserc_parse function never advances the attribute-parse state cursor on certain malformed attribute forms, looping forever. NVD: Nameless attributes such as \"<a ='c'>\" or unbalanced quotes \"<a b='''''''c'>\" can trigger this condition.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-13397/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-13400/",
      "current_public_safe_latest": false,
      "cvss_score": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.04586,
      "epss_score": 0.00149,
      "first_observed_at": "2026-08-02T10:52:32.597181+00:00",
      "id": "CVE-2026-13400",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-03T06:40:38.700520+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Simply Schedule Appointments is vulnerable to unauthenticated Stored Cross-Site Scripting in all versions up to and including 1.6.12.2.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260803T064356Z/items/CVE-2026-13400.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 4,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Simply Schedule Appointments is vulnerable to unauthenticated Stored Cross-Site Scripting in all versions up to and including 1.6.12.2.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-13400/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-13401/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.31366,
      "epss_score": 0.00388,
      "first_observed_at": "2026-07-23T16:53:12.033252+00:00",
      "id": "CVE-2026-13401",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-23T16:53:12.033252+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: XML::Bare versions through 0.53 for Perl will hang in an infinite loop when parsing malformed attributes. NVD: The parserc_parse function never advances the attribute-parse state cursor on certain malformed attribute forms, looping forever. NVD: Nameless attributes such as \"<a ='c'>\" or unbalanced quotes \"<a b='''''''c'>\" can trigger this condition.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260723T171217Z/items/CVE-2026-13401.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: XML::Bare versions through 0.53 for Perl will hang in an infinite loop when parsing malformed attributes. NVD: The parserc_parse function never advances the attribute-parse state cursor on certain malformed attribute forms, looping forever. NVD: Nameless attributes such as \"<a ='c'>\" or unbalanced quotes \"<a b='''''''c'>\" can trigger this condition.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-13401/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-13402/",
      "current_public_safe_latest": false,
      "cvss_score": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.10823,
      "epss_score": 0.00206,
      "first_observed_at": "2026-07-24T06:06:41.160911+00:00",
      "id": "CVE-2026-13402",
      "impact_tags": [
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-24T06:06:41.160911+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Royal Addons for Elementor WordPress plugin before 1.7.1063 does not check the post status of menu items or the templates they reference in one of its REST endpoints, allowing unauthenticated users to retrieve the rendered HTML content of private or draft...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260724T061150Z/items/CVE-2026-13402.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Royal Addons for Elementor WordPress plugin before 1.7.1063 does not check the post status of menu items or the templates they reference in one of its REST endpoints, allowing unauthenticated users to retrieve the rendered HTML content of private or draft...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-13402/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-13410/",
      "current_public_safe_latest": false,
      "cvss_score": 8.2,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.15467,
      "epss_score": 0.00242,
      "first_observed_at": "2026-07-24T11:14:35.780564+00:00",
      "id": "CVE-2026-13410",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-24T11:14:35.780564+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Dancer::Plugin::Auth::Google versions through 0.07 for Perl have TLS verification disabled. NVD: The default user agent is initialised with SSL_verify_mode explicitly disabled. NVD: An attacker with network man-in-the-middle (MITM) capability between the Dancer application and googleapis.com can intercept the OAuth2 token exchange and userinfo fetch, return a forged access_token and user profile, and be logged in to the Dancer...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260724T111724Z/items/CVE-2026-13410.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Dancer::Plugin::Auth::Google versions through 0.07 for Perl have TLS verification disabled. NVD: The default user agent is initialised with SSL_verify_mode explicitly disabled. NVD: An attacker with network man-in-the-middle (MITM) capability between the Dancer application and googleapis.com can intercept the OAuth2 token exchange and userinfo fetch, return a forged access_token and user profile, and be logged in to the Dancer...",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-13410/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-13423/",
      "current_public_safe_latest": false,
      "cvss_score": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.42164,
      "epss_score": 0.00536,
      "first_observed_at": "2026-08-05T06:03:49.171468+00:00",
      "id": "CVE-2026-13423",
      "impact_tags": [
        "code execution review",
        "privilege boundary review",
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-05T06:03:49.171468+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Streamit WordPress theme through 4.5.0 does not perform any authorization or nonce verification on one of its unauthenticated AJAX routes, which invokes an attacker-supplied PHP function with an attacker-supplied argument array, allowing unauthenticated...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260805T061218Z/items/CVE-2026-13423.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes code execution review · privilege escalation risk · remote exposure. Possible impact: A remote attacker may be able to run code or commands on affected systems.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Streamit WordPress theme through 4.5.0 does not perform any authorization or nonce verification on one of its unauthenticated AJAX routes, which invokes an attacker-supplied PHP function with an attacker-supplied argument array, allowing unauthenticated...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-13423/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-13432/",
      "current_public_safe_latest": false,
      "cvss_score": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.06623,
      "epss_score": 0.0017,
      "first_observed_at": "2026-07-26T22:15:56.881440+00:00",
      "id": "CVE-2026-13432",
      "impact_tags": [
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-27T06:45:51.031460+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The ThumbPress WordPress plugin before 6.2.2 does not perform a capability check on one of its AJAX actions, allowing authenticated users with subscriber-level access or higher to deactivate the ThumbPress WordPress plugin before 6.2.2, disrupting the site's...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260727T065126Z/items/CVE-2026-13432.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The ThumbPress WordPress plugin before 6.2.2 does not perform a capability check on one of its AJAX actions, allowing authenticated users with subscriber-level access or higher to deactivate the ThumbPress WordPress plugin before 6.2.2, disrupting the site's...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-13432/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-13439/",
      "current_public_safe_latest": false,
      "cvss_score": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.32778,
      "epss_score": 0.00401,
      "first_observed_at": "2026-07-28T06:05:50.269125+00:00",
      "id": "CVE-2026-13439",
      "impact_tags": [
        "privilege boundary review",
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-28T06:05:50.269125+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Easy Form Builder by WhiteStudio plugin for WordPress is vulnerable to Unauthenticated Privilege Escalation to Administrator in versions up to, and including, 4.0.11 This is due to the password recovery flow using the publicly-visible session identifier... NVD: This makes it possible for unauthenticated attackers to reset the password of any WordPress user — including administrators — by scraping the public sid from a published login form page, submitting a recovery request for any known user email via...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260728T060840Z/items/CVE-2026-13439.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes privilege escalation risk · remote exposure · authenticated boundary. Possible impact: A remote attacker may cross a privilege boundary and gain more access than intended.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Easy Form Builder by WhiteStudio plugin for WordPress is vulnerable to Unauthenticated Privilege Escalation to Administrator in versions up to, and including, 4.0.11 This is due to the password recovery flow using the publicly-visible session identifier... NVD: This makes it possible for unauthenticated attackers to reset the password of any WordPress user — including administrators — by scraping the public sid from a published login form page, submitting a recovery request for any known user email via...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-13439/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-13440/",
      "current_public_safe_latest": false,
      "cvss_score": 7.2,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.18292,
      "epss_score": 0.00265,
      "first_observed_at": "2026-08-04T11:35:47.800052+00:00",
      "id": "CVE-2026-13440",
      "impact_tags": [
        "XSS risk",
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-04T11:35:47.800052+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'message_popup' parameter in all versions up to, and including, 2.1.0 due to... NVD: This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. NVD: The exploit is possible because the 'ajd_protected' nonce required by the create_popup handler is exposed to all unauthenticated frontend visitors via wp_localize_script under bogo_save_url.ajd_nonce, effectively bypassing the nonce-only access control.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260804T114328Z/items/CVE-2026-13440.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes XSS risk · remote exposure · authenticated boundary. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk · remote exposure · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'message_popup' parameter in all versions up to, and including, 2.1.0 due to... NVD: This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. NVD: The exploit is possible because the 'ajd_protected' nonce required by the create_popup handler is exposed to all unauthenticated frontend visitors via wp_localize_script under bogo_save_url.ajd_nonce, effectively bypassing the nonce-only access control.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-13440/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-13441/",
      "current_public_safe_latest": false,
      "cvss_score": 7.2,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.15885,
      "epss_score": 0.00247,
      "first_observed_at": "2026-07-16T11:14:01.223847+00:00",
      "id": "CVE-2026-13441",
      "impact_tags": [
        "XSS risk",
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-16T11:14:01.223847+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'new_event_type_background_color' parameter in all versions up to, and including, 4.3.4.2 due to insufficient input sanitization... NVD: This makes it possible for authenticated attackers, with custom-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. NVD: This requires the plugin's Guest Submissions setting (allow_submission_by_anonymous_user) to be enabled, which allows unauthenticated attackers to submit event types via the frontend form; when that setting is disabled, exploitation requires at minimum a...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260716T111601Z/items/CVE-2026-13441.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes XSS risk · remote exposure · authenticated boundary. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk · remote exposure · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'new_event_type_background_color' parameter in all versions up to, and including, 4.3.4.2 due to insufficient input sanitization... NVD: This makes it possible for authenticated attackers, with custom-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. NVD: This requires the plugin's Guest Submissions setting (allow_submission_by_anonymous_user) to be enabled, which allows unauthenticated attackers to submit event types via the frontend form; when that setting is disabled, exploitation requires at minimum a...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-13441/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-13461/",
      "current_public_safe_latest": false,
      "cvss_score": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.26216,
      "epss_score": 0.0034,
      "first_observed_at": "2026-07-16T16:44:59.414444+00:00",
      "id": "CVE-2026-13461",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-16T16:44:59.414444+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: When coupled with the SSL bypass vulnerability, JavaScript can be injected into a WebView in the PayRange version 7.0.7 app. NVD: The injection of specific JavaScript function calls allows the attacker to escape the WebView sandbox and perform a number of dangerous actions on the user's device.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260716T164706Z/items/CVE-2026-13461.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: When coupled with the SSL bypass vulnerability, JavaScript can be injected into a WebView in the PayRange version 7.0.7 app. NVD: The injection of specific JavaScript function calls allows the attacker to escape the WebView sandbox and perform a number of dangerous actions on the user's device.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-13461/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-13462/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.13707,
      "epss_score": 0.00229,
      "first_observed_at": "2026-07-16T16:44:59.414444+00:00",
      "id": "CVE-2026-13462",
      "impact_tags": [
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-16T16:44:59.414444+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: PayRange Android app, version 7.0.7 and below, contains an SSL bypass vulnerability that allows invalid certificates to be accepted in application webviews. NVD: A remote and unauthenticated attacker can steal information that the user sends.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260716T164706Z/items/CVE-2026-13462.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes remote exposure · authenticated boundary. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: PayRange Android app, version 7.0.7 and below, contains an SSL bypass vulnerability that allows invalid certificates to be accepted in application webviews. NVD: A remote and unauthenticated attacker can steal information that the user sends.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-13462/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-1359/",
      "current_public_safe_latest": false,
      "cvss_score": 8.8,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.22762,
      "epss_score": 0.00308,
      "first_observed_at": "2026-07-18T07:15:27.585758+00:00",
      "id": "CVE-2026-1359",
      "impact_tags": [
        "privilege boundary review",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-18T08:45:22.939860+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Genolve – AI image AI video generation plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the genolve_setOpt() function in all versions up to, and including, 5.0.5. NVD: This makes it possible for authenticated attackers, with Contributor-level access and above, to update arbitrary WordPress options, including enabling user registration and setting the default role to administrator, resulting in privilege escalation.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260718T084855Z/items/CVE-2026-1359.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 3,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes privilege escalation risk · authenticated boundary. Possible impact: An attacker may cross a privilege boundary and gain more access than intended.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Genolve – AI image AI video generation plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the genolve_setOpt() function in all versions up to, and including, 5.0.5. NVD: This makes it possible for authenticated attackers, with Contributor-level access and above, to update arbitrary WordPress options, including enabling user registration and setting the default role to administrator, resulting in privilege escalation.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-1359/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-13596/",
      "current_public_safe_latest": false,
      "cvss_score": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.17873,
      "epss_score": 0.00262,
      "first_observed_at": "2026-08-08T04:31:15.594937+00:00",
      "id": "CVE-2026-13596",
      "impact_tags": [
        "SQL injection risk",
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-08T04:31:15.594937+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Participants Database WordPress plugin before 2.7.8.4 does not properly sanitize and escape a user-supplied parameter before using it in a SQL query, allowing unauthenticated attackers to perform SQL injection attacks.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260808T043750Z/items/CVE-2026-13596.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes SQL injection risk · remote exposure · authenticated boundary. Possible impact: A remote attacker may be able to read or change database-backed application data.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Participants Database WordPress plugin before 2.7.8.4 does not properly sanitize and escape a user-supplied parameter before using it in a SQL query, allowing unauthenticated attackers to perform SQL injection attacks.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-13596/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-13597/",
      "current_public_safe_latest": false,
      "cvss_score": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.17767,
      "epss_score": 0.00261,
      "first_observed_at": "2026-08-02T16:16:56.676027+00:00",
      "id": "CVE-2026-13597",
      "impact_tags": [
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-03T06:40:38.700520+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The 微信二维码登陆 WordPress plugin through 1.3 does not properly validate WeChat webhook requests, as its signature check always passes, and it discloses the generated login code in the webhook response. NVD: This allows an unauthenticated attacker to forge a login event for any existing username, read the login code, and redeem it through an unauthenticated AJAX action to log in as that user, including an administrator, without a password.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260803T064356Z/items/CVE-2026-13597.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 3,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes remote exposure · authenticated boundary. Possible impact: This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The 微信二维码登陆 WordPress plugin through 1.3 does not properly validate WeChat webhook requests, as its signature check always passes, and it discloses the generated login code in the webhook response. NVD: This allows an unauthenticated attacker to forge a login event for any existing username, read the login code, and redeem it through an unauthenticated AJAX action to log in as that user, including an administrator, without a password.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-13597/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-13604/",
      "current_public_safe_latest": false,
      "cvss_score": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.07271,
      "epss_score": 0.00176,
      "first_observed_at": "2026-08-08T04:31:15.594937+00:00",
      "id": "CVE-2026-13604",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-08T04:31:15.594937+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Pixelavo WordPress plugin before 1.5.4 registers an unauthenticated AJAX action, gated only by a nonce that it emits publicly on every front-end page, that forwards client-supplied event data to the configured Facebook Conversions API using the... NVD: This allows an unauthenticated visitor to inject arbitrary conversion events into the administrator's Facebook ads account and exhaust the configured API quota.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260808T043750Z/items/CVE-2026-13604.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Pixelavo WordPress plugin before 1.5.4 registers an unauthenticated AJAX action, gated only by a nonce that it emits publicly on every front-end page, that forwards client-supplied event data to the configured Facebook Conversions API using the... NVD: This allows an unauthenticated visitor to inject arbitrary conversion events into the administrator's Facebook ads account and exhaust the configured API quota.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-13604/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-13605/",
      "current_public_safe_latest": false,
      "cvss_score": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.14612,
      "epss_score": 0.00235,
      "first_observed_at": "2026-08-05T06:03:49.171468+00:00",
      "id": "CVE-2026-13605",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-05T06:03:49.171468+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The PhotoSwipe WordPress plugin through 4.1.1.1 uses the title attribute of author-supplied link markup as a lightbox caption that is written into the page DOM without escaping.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260805T061218Z/items/CVE-2026-13605.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The PhotoSwipe WordPress plugin through 4.1.1.1 uses the title attribute of author-supplied link markup as a lightbox caption that is written into the page DOM without escaping.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-13605/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-13609/",
      "current_public_safe_latest": false,
      "cvss_score": 8.8,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.15873,
      "epss_score": 0.00246,
      "first_observed_at": "2026-08-07T05:06:11.845797+00:00",
      "id": "CVE-2026-13609",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-07T05:06:11.845797+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Frontend Admin by DynamiApps WordPress plugin before 3.29.9 decodes HTML entities in a submitted form field value after sanitizing it, which restores HTML tags that the sanitizer had neutralized.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260807T051140Z/items/CVE-2026-13609.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Frontend Admin by DynamiApps WordPress plugin before 3.29.9 decodes HTML entities in a submitted form field value after sanitizing it, which restores HTML tags that the sanitizer had neutralized.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-13609/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-13690/",
      "current_public_safe_latest": false,
      "cvss_score": 7.4,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.16876,
      "epss_score": 0.00254,
      "first_observed_at": "2026-08-05T06:03:49.171468+00:00",
      "id": "CVE-2026-13690",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-05T06:03:49.171468+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The UsersWP WordPress plugin before 1.2.67 does not validate the selected authentication provider in its two-factor login handler, allowing an attacker who already knows a user's credentials to bypass the second authentication factor and log in as that user.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260805T061218Z/items/CVE-2026-13690.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The UsersWP WordPress plugin before 1.2.67 does not validate the selected authentication provider in its two-factor login handler, allowing an attacker who already knows a user's credentials to bypass the second authentication factor and log in as that user.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-13690/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-13692/",
      "current_public_safe_latest": false,
      "cvss_score": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.07958,
      "epss_score": 0.00182,
      "first_observed_at": "2026-08-05T06:03:49.171468+00:00",
      "id": "CVE-2026-13692",
      "impact_tags": [
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-05T06:03:49.171468+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The PayU CommercePro Plugin WordPress plugin through 3.8.9 does not verify the payment-gateway signature before applying order modifications, allowing unauthenticated attackers to tamper with the totals, shipping and metadata of arbitrary WooCommerce orders.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260805T061218Z/items/CVE-2026-13692.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes remote exposure · authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The PayU CommercePro Plugin WordPress plugin through 3.8.9 does not verify the payment-gateway signature before applying order modifications, allowing unauthenticated attackers to tamper with the totals, shipping and metadata of arbitrary WooCommerce orders.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-13692/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-13693/",
      "current_public_safe_latest": false,
      "cvss_score": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.20224,
      "epss_score": 0.0028,
      "first_observed_at": "2026-07-28T06:05:50.269125+00:00",
      "id": "CVE-2026-13693",
      "impact_tags": [
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-28T06:05:50.269125+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Bit Form WordPress plugin before 3.1.0 does not restrict a form file-field value to a safe path before reading the file and attaching it to a notification email, allowing unauthenticated attackers to read arbitrary server files such as the WordPress...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260728T060840Z/items/CVE-2026-13693.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes remote exposure · authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Bit Form WordPress plugin before 3.1.0 does not restrict a form file-field value to a safe path before reading the file and attaching it to a notification email, allowing unauthenticated attackers to read arbitrary server files such as the WordPress...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-13693/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-13694/",
      "current_public_safe_latest": false,
      "cvss_score": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.10426,
      "epss_score": 0.00203,
      "first_observed_at": "2026-07-28T06:05:50.269125+00:00",
      "id": "CVE-2026-13694",
      "impact_tags": [
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-28T06:05:50.269125+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Bit Form WordPress plugin before 3.1.0 does not properly validate its workflow-trigger token once the associated transient has expired, allowing unauthenticated attackers to re-trigger a form's configured workflow actions such as notification emails and...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260728T060840Z/items/CVE-2026-13694.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes remote exposure · authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Bit Form WordPress plugin before 3.1.0 does not properly validate its workflow-trigger token once the associated transient has expired, allowing unauthenticated attackers to re-trigger a form's configured workflow actions such as notification emails and...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-13694/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-13696/",
      "current_public_safe_latest": false,
      "cvss_score": 8.8,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.27651,
      "epss_score": 0.00355,
      "first_observed_at": "2026-07-14T10:57:43.777280+00:00",
      "id": "CVE-2026-13696",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-14T10:57:43.777280+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Improper neutralization of special elements used in an LDAP query ('LDAP injection') vulnerability in HAVELSAN Inc. NVD: Liman MYS allows LDAP Injection. NVD: This issue affects Liman MYS: before release.Master.1107.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260714T110007Z/items/CVE-2026-13696.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Improper neutralization of special elements used in an LDAP query ('LDAP injection') vulnerability in HAVELSAN Inc. NVD: Liman MYS allows LDAP Injection. NVD: This issue affects Liman MYS: before release.Master.1107.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-13696/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "nodejs / undici",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-13697/",
      "current_public_safe_latest": false,
      "cvss_score": 7.4,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.24989,
      "epss_score": 0.00325,
      "first_observed_at": "2026-08-05T16:55:08.588478+00:00",
      "id": "CVE-2026-13697",
      "impact_tags": [
        "information exposure review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-05T16:55:08.588478+00:00",
      "latest_item_url": null,
      "product": "undici",
      "public_safe_summary": "NVD: undici's cache interceptor mishandles malformed Cache-Control private directives. NVD: In undici 7.0.0 up to before 7.29.0 and 8.0.0 up to before 8.9.0, a response carrying a degenerate qualified private directive, such as private set to an empty value, can be stored in the default shared cache and later served to a different caller with the... NVD: Separately, a Cache-Control header that combines an unqualified private directive with a qualified one triggers an uncaught TypeError in the cache-control parser, which rejects the request and, depending on the consumer's error handling, can terminate the...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260805T165944Z/items/CVE-2026-13697.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: nodejs / undici",
      "source_published_impact": "Source describes information exposure review. Possible impact: An attacker may be able to access information that should not be exposed.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: undici.",
      "source_published_summary": "NVD: undici's cache interceptor mishandles malformed Cache-Control private directives. NVD: In undici 7.0.0 up to before 7.29.0 and 8.0.0 up to before 8.9.0, a response carrying a degenerate qualified private directive, such as private set to an empty value, can be stored in the default shared cache and later served to a different caller with the... NVD: Separately, a Cache-Control header that combines an unqualified private directive with a qualified one triggers an uncaught TypeError in the cache-control parser, which rejects the request and, depending on the consumer's error handling, can terminate the...",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-13697/timeline.json",
      "vendor": "nodejs"
    },
    {
      "affected_label": "eclipse / kuksa",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-13699/",
      "current_public_safe_latest": false,
      "cvss_score": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.1483,
      "epss_score": 0.00237,
      "first_observed_at": "2026-07-21T06:08:28.817138+00:00",
      "id": "CVE-2026-13699",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-21T06:08:28.817138+00:00",
      "latest_item_url": null,
      "product": "kuksa",
      "public_safe_summary": "NVD: In Eclipse KUKSA Databroker version 0.6.1, the kuksa.val.v2.VAL/PublishValue gRPC handler fails to validate the existence of the optional data_point field in PublishValueRequest. NVD: When a request contains a valid signal_id but omits data_point, the server directly calls unwrap() on request.data_point, triggering a panic in the Tokio worker thread. NVD: This issue can be triggered by any client holding a valid JWT token.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260721T061518Z/items/CVE-2026-13699.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: eclipse / kuksa; affected version context: 0.6.1",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: In Eclipse KUKSA Databroker version 0.6.1, the kuksa.val.v2.VAL/PublishValue gRPC handler fails to validate the existence of the optional data_point field in PublishValueRequest. NVD: When a request contains a valid signal_id but omits data_point, the server directly calls unwrap() on request.data_point, triggering a panic in the Tokio worker thread. NVD: This issue can be triggered by any client holding a valid JWT token.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-13699/timeline.json",
      "vendor": "eclipse"
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-13714/",
      "current_public_safe_latest": false,
      "cvss_score": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.37719,
      "epss_score": 0.00462,
      "first_observed_at": "2026-08-02T16:16:56.676027+00:00",
      "id": "CVE-2026-13714",
      "impact_tags": [
        "code execution review",
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-03T06:40:38.700520+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Realtyna Organic IDX plugin + WPL Real Estate WordPress plugin before 5.3.0 does not validate the type of uploaded files, and its file upload functionality is gated only by an API that is enabled by default and authenticated with hardcoded credentials... NVD: This makes it possible for unauthenticated attackers to upload arbitrary PHP files and achieve remote code execution.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260803T064356Z/items/CVE-2026-13714.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 3,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes code execution review · remote exposure · authenticated boundary. Possible impact: A remote attacker may be able to run code or commands on affected systems.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Realtyna Organic IDX plugin + WPL Real Estate WordPress plugin before 5.3.0 does not validate the type of uploaded files, and its file upload functionality is gated only by an API that is enabled by default and authenticated with hardcoded credentials... NVD: This makes it possible for unauthenticated attackers to upload arbitrary PHP files and achieve remote code execution.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-13714/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-1372/",
      "current_public_safe_latest": false,
      "cvss_score": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.10551,
      "epss_score": 0.00204,
      "first_observed_at": "2026-07-28T06:05:50.269125+00:00",
      "id": "CVE-2026-1372",
      "impact_tags": [
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-28T06:05:50.269125+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Tutor LMS Elementor Addons plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 4.0.0 This is due to missing capability checks on the activate_tutor_free() and activate_elementor_free() functions registered as... NVD: This makes it possible for authenticated attackers, with Subscriber-level access and above, to activate the Tutor LMS and Elementor plugins without proper authorization.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260728T060840Z/items/CVE-2026-1372.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Tutor LMS Elementor Addons plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 4.0.0 This is due to missing capability checks on the activate_tutor_free() and activate_elementor_free() functions registered as... NVD: This makes it possible for authenticated attackers, with Subscriber-level access and above, to activate the Tutor LMS and Elementor plugins without proper authorization.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-1372/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-13722/",
      "current_public_safe_latest": false,
      "cvss_score": 8.6,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.13966,
      "epss_score": 0.00232,
      "first_observed_at": "2026-07-09T22:45:10.548837+00:00",
      "id": "CVE-2026-13722",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-09T22:45:10.548837+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: WatchGuard Fireware OS contains a firmware validation bypass when processing a backup image via the backup/restore feature. NVD: An authenticated administrator can exploit this vulnerability to install a tampered firmware image.This vulnerability affects Fireware OS 11.0 up to and including 11.12.4_Update1, 12.0 up to and including 12.12 and 2025.1 up to and including 2025.6.2.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260709T224554Z/items/CVE-2026-13722.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: WatchGuard Fireware OS contains a firmware validation bypass when processing a backup image via the backup/restore feature. NVD: An authenticated administrator can exploit this vulnerability to install a tampered firmware image.This vulnerability affects Fireware OS 11.0 up to and including 11.12.4_Update1, 12.0 up to and including 12.12 and 2025.1 up to and including 2025.6.2.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-13722/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-13723/",
      "current_public_safe_latest": false,
      "cvss_score": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.25195,
      "epss_score": 0.00327,
      "first_observed_at": "2026-08-05T16:55:08.588478+00:00",
      "id": "CVE-2026-13723",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-05T16:55:08.588478+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A vulnerability in the zipx.Unzip extraction routine of Develar's app-builder allows an attacker to overwrite arbitrary files on macOS APFS by exploiting a Unicode Normalization Collision combined with symlink following behavior. NVD: APFS treats certain Unicode equivalent filenames as identical (e.g., ß ↔ ss), while app builder performs no canonical normalization before validating or writing paths. NVD: As a result, a crafted ZIP archive containing: • a symlink entry named ss pointing to a target file, and • a regular file named ß containing attacker controlled data, will cause the second write to follow the symlink and overwrite the target file.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260805T165944Z/items/CVE-2026-13723.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability in the zipx.Unzip extraction routine of Develar's app-builder allows an attacker to overwrite arbitrary files on macOS APFS by exploiting a Unicode Normalization Collision combined with symlink following behavior. NVD: APFS treats certain Unicode equivalent filenames as identical (e.g., ß ↔ ss), while app builder performs no canonical normalization before validating or writing paths. NVD: As a result, a crafted ZIP archive containing: • a symlink entry named ss pointing to a target file, and • a regular file named ß containing attacker controlled data, will cause the second write to follow the symlink and overwrite the target file.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-13723/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-13725/",
      "current_public_safe_latest": false,
      "cvss_score": 7.1,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.0597,
      "epss_score": 0.00164,
      "first_observed_at": "2026-08-08T04:31:15.594937+00:00",
      "id": "CVE-2026-13725",
      "impact_tags": [
        "XSS risk",
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-08T04:31:15.594937+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Dynamic Pricing With Discount Rules for WooCommerce WordPress plugin before 5.0.0 does not validate a nonce or user capabilities on one of its AJAX actions and reflects unsanitised user input in the response, allowing unauthenticated attackers to perform...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260808T043750Z/items/CVE-2026-13725.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes XSS risk · remote exposure · authenticated boundary. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk · remote exposure · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Dynamic Pricing With Discount Rules for WooCommerce WordPress plugin before 5.0.0 does not validate a nonce or user capabilities on one of its AJAX actions and reflects unsanitised user input in the response, allowing unauthenticated attackers to perform...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-13725/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-13726/",
      "current_public_safe_latest": false,
      "cvss_score": 7.1,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.06001,
      "epss_score": 0.00164,
      "first_observed_at": "2026-08-02T16:16:56.676027+00:00",
      "id": "CVE-2026-13726",
      "impact_tags": [
        "XSS risk",
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-03T06:40:38.700520+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The MPG WordPress plugin before 4.1.8 does not sanitise and escape a parameter before reflecting it back in the response, allowing unauthenticated attackers to perform Reflected Cross-Site Scripting against a victim who is induced to send a crafted request.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260803T064356Z/items/CVE-2026-13726.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 3,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes XSS risk · remote exposure · authenticated boundary. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk · remote exposure · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The MPG WordPress plugin before 4.1.8 does not sanitise and escape a parameter before reflecting it back in the response, allowing unauthenticated attackers to perform Reflected Cross-Site Scripting against a victim who is induced to send a crafted request.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-13726/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-13729/",
      "current_public_safe_latest": false,
      "cvss_score": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.00891,
      "epss_score": 0.00098,
      "first_observed_at": "2026-08-08T04:31:15.594937+00:00",
      "id": "CVE-2026-13729",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-08T04:31:15.594937+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Podlove Podcast Publisher WordPress plugin before 4.5.3 does not perform nonce validation on some of its administrative create and delete actions, allowing attackers to create rogue records or delete legitimate ones via a forged request (CSRF) when a...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260808T043750Z/items/CVE-2026-13729.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Podlove Podcast Publisher WordPress plugin before 4.5.3 does not perform nonce validation on some of its administrative create and delete actions, allowing attackers to create rogue records or delete legitimate ones via a forged request (CSRF) when a...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-13729/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-13741/",
      "current_public_safe_latest": false,
      "cvss_score": 8.8,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.15936,
      "epss_score": 0.00246,
      "first_observed_at": "2026-07-23T06:13:21.015514+00:00",
      "id": "CVE-2026-13741",
      "impact_tags": [
        "privilege boundary review",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-23T06:13:21.015514+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Digits: WordPress Mobile Number Signup and Login plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 9.1.0.5. NVD: This is due to missing authorization and role validation in the dig_update_wpwc_custom_fields() function. NVD: This makes it possible for authenticated attackers, with Subscriber-level access and above, to escalate their privileges to Administrator by submitting a forged digits_reg_userrole value during profile update, granted the site administrator has configured the...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260723T061547Z/items/CVE-2026-13741.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes privilege escalation risk · authenticated boundary. Possible impact: An attacker may cross a privilege boundary and gain more access than intended.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Digits: WordPress Mobile Number Signup and Login plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 9.1.0.5. NVD: This is due to missing authorization and role validation in the dig_update_wpwc_custom_fields() function. NVD: This makes it possible for authenticated attackers, with Subscriber-level access and above, to escalate their privileges to Administrator by submitting a forged digits_reg_userrole value during profile update, granted the site administrator has configured the...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-13741/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-13753/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.18788,
      "epss_score": 0.00271,
      "first_observed_at": "2026-07-13T17:24:46.617207+00:00",
      "id": "CVE-2026-13753",
      "impact_tags": [
        "information exposure review",
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-13T17:24:46.617207+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A missing authorization vulnerability exists in the embedded webserver of HP Deskjet 2800 Series Printers running firmware version <=TBP1CN2612AR. NVD: An unauthenticated attacker with network access can send GET requests to multiple exposed administrative API endpoints and retrieve sensitive configuration data such as plaintext Wi‑Fi Direct credentials, unique device identity information, and other... NVD: When accessed through the web interface, these setting pages explicitly require administrator credentials before sensitive information is displayed.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260713T172750Z/items/CVE-2026-13753.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes information exposure review · remote exposure · authenticated boundary. Possible impact: A remote attacker may be able to access information that should not be exposed.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A missing authorization vulnerability exists in the embedded webserver of HP Deskjet 2800 Series Printers running firmware version <=TBP1CN2612AR. NVD: An unauthenticated attacker with network access can send GET requests to multiple exposed administrative API endpoints and retrieve sensitive configuration data such as plaintext Wi‑Fi Direct credentials, unique device identity information, and other... NVD: When accessed through the web interface, these setting pages explicitly require administrator credentials before sensitive information is displayed.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-13753/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-13754/",
      "current_public_safe_latest": false,
      "cvss_score": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.16315,
      "epss_score": 0.00249,
      "first_observed_at": "2026-07-23T06:13:21.015514+00:00",
      "id": "CVE-2026-13754",
      "impact_tags": [
        "information exposure review",
        "SQL injection risk",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-23T06:13:21.015514+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Tickera – Sell Tickets & Manage Events plugin for WordPress is vulnerable to generic SQL Injection via the 's' parameter in all versions up to, and including, 3.6.0.0 due to insufficient escaping on the user supplied parameter and lack of sufficient... NVD: This makes it possible for authenticated attackers, with custom-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260723T061547Z/items/CVE-2026-13754.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes information exposure review · SQL injection risk · authenticated boundary. Possible impact: An attacker may be able to read or change database-backed application data.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Tickera – Sell Tickets & Manage Events plugin for WordPress is vulnerable to generic SQL Injection via the 's' parameter in all versions up to, and including, 3.6.0.0 due to insufficient escaping on the user supplied parameter and lack of sufficient... NVD: This makes it possible for authenticated attackers, with custom-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-13754/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-13755/",
      "current_public_safe_latest": false,
      "cvss_score": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.13187,
      "epss_score": 0.00225,
      "first_observed_at": "2026-07-23T06:13:21.015514+00:00",
      "id": "CVE-2026-13755",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-23T06:13:21.015514+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Tickera – Sell Tickets & Manage Events plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'price_wrapper' Shortcode Attribute in all versions up to, and including, 3.6.0.0 due to insufficient input sanitization and output escaping. NVD: This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260723T061547Z/items/CVE-2026-13755.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Tickera – Sell Tickets & Manage Events plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'price_wrapper' Shortcode Attribute in all versions up to, and including, 3.6.0.0 due to insufficient input sanitization and output escaping. NVD: This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-13755/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-13767/",
      "current_public_safe_latest": false,
      "cvss_score": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.16315,
      "epss_score": 0.00249,
      "first_observed_at": "2026-07-23T06:13:21.015514+00:00",
      "id": "CVE-2026-13767",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-23T06:13:21.015514+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Quiz Master Next plugin for WordPress is vulnerable to SQL Injection via stored quiz page data in versions up to, and including, 11.2.0. NVD: This is due to insufficient escaping on the user-supplied 'pages' parameter persisted by the qsm_ajax_save_pages() AJAX handler (sanitize_text_field only) and lack of sufficient preparation on the existing SQL query built in...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260723T061547Z/items/CVE-2026-13767.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Quiz Master Next plugin for WordPress is vulnerable to SQL Injection via stored quiz page data in versions up to, and including, 11.2.0. NVD: This is due to insufficient escaping on the user-supplied 'pages' parameter persisted by the qsm_ajax_save_pages() AJAX handler (sanitize_text_field only) and lack of sufficient preparation on the existing SQL query built in...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-13767/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-1382/",
      "current_public_safe_latest": false,
      "cvss_score": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.09189,
      "epss_score": 0.00193,
      "first_observed_at": "2026-07-18T05:38:40.092323+00:00",
      "id": "CVE-2026-1382",
      "impact_tags": [
        "XSS risk",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-18T07:15:27.585758+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The fresh Podcaster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'freshpodcaster' shortcode in all versions up to, and including, 1.0.7 due to insufficient input sanitization and output escaping on user supplied attributes. NVD: This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260718T071858Z/items/CVE-2026-1382.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes XSS risk · authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The fresh Podcaster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'freshpodcaster' shortcode in all versions up to, and including, 1.0.7 due to insufficient input sanitization and output escaping on user supplied attributes. NVD: This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-1382/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14165/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.15871,
      "epss_score": 0.00246,
      "first_observed_at": "2026-07-20T06:28:37.060083+00:00",
      "id": "CVE-2026-14165",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-20T06:28:37.060083+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: An Authorization Bypass Through User-Controlled Key vulnerability affecting Tuleap Enterprise Edition from 17.0 through 17.5 could allow an attacker to access data of other users without authorization.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260720T063049Z/items/CVE-2026-14165.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: An Authorization Bypass Through User-Controlled Key vulnerability affecting Tuleap Enterprise Edition from 17.0 through 17.5 could allow an attacker to access data of other users without authorization.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14165/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14172/",
      "current_public_safe_latest": false,
      "cvss_score": 7.8,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.01302,
      "epss_score": 0.00107,
      "first_observed_at": "2026-07-31T06:26:41.124454+00:00",
      "id": "CVE-2026-14172",
      "impact_tags": [
        "admin privilege risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-31T06:26:41.124454+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Rapid7 InsightVM, Nexpose, and the Insight Agent execute discovered executables during authenticated assessment without validating file ownership, allowing a local low-privileged user to run code as the scan credential (Scan Engine) or as root/SYSTEM (Insight... NVD: Fixed in Scan Engine content 1.1.3935 and Insight Agent content component 0.0.245.0.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260731T063057Z/items/CVE-2026-14172.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes admin privilege risk. Possible impact: An attacker may gain root or administrative-level privileges on affected systems.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: Scan.",
      "source_published_summary": "NVD: Rapid7 InsightVM, Nexpose, and the Insight Agent execute discovered executables during authenticated assessment without validating file ownership, allowing a local low-privileged user to run code as the scan credential (Scan Engine) or as root/SYSTEM (Insight... NVD: Fixed in Scan Engine content 1.1.3935 and Insight Agent content component 0.0.245.0.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14172/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14175/",
      "current_public_safe_latest": false,
      "cvss_score": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.32286,
      "epss_score": 0.00395,
      "first_observed_at": "2026-08-11T10:14:04.199465+00:00",
      "id": "CVE-2026-14175",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-11T10:14:04.199465+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Unrestricted upload of file with dangerous type vulnerability in Bilin Software and Informatics Consultancy Inc. NVD: HUMANIST Digital Human Resources allows Upload a Web Shell to a Web Server. NVD: This issue affects HUMANIST Digital Human Resources: from 26.0 before 26.1.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260811T102539Z/items/CVE-2026-14175.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Unrestricted upload of file with dangerous type vulnerability in Bilin Software and Informatics Consultancy Inc. NVD: HUMANIST Digital Human Resources allows Upload a Web Shell to a Web Server. NVD: This issue affects HUMANIST Digital Human Resources: from 26.0 before 26.1.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14175/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14183/",
      "current_public_safe_latest": false,
      "cvss_score": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.05776,
      "epss_score": 0.00162,
      "first_observed_at": "2026-07-28T06:05:50.269125+00:00",
      "id": "CVE-2026-14183",
      "impact_tags": [
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-28T06:05:50.269125+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Classified Listing WordPress plugin before 5.3.9 does not verify that the order targeted by its payment-receipt handler belongs to the requesting user, allowing authenticated users with subscriber-level access to read the payment receipt details of any...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260728T060840Z/items/CVE-2026-14183.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Classified Listing WordPress plugin before 5.3.9 does not verify that the order targeted by its payment-receipt handler belongs to the requesting user, allowing authenticated users with subscriber-level access to read the payment receipt details of any...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14183/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14184/",
      "current_public_safe_latest": false,
      "cvss_score": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.03593,
      "epss_score": 0.00138,
      "first_observed_at": "2026-07-28T06:05:50.269125+00:00",
      "id": "CVE-2026-14184",
      "impact_tags": [
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-28T06:05:50.269125+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Academy LMS WordPress plugin before 3.8.1 does not verify ownership of a user-supplied user identifier in several of its lesson AJAX handlers, allowing authenticated users with subscriber-level access to read and modify other users' lesson notes and mark...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260728T060840Z/items/CVE-2026-14184.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Academy LMS WordPress plugin before 3.8.1 does not verify ownership of a user-supplied user identifier in several of its lesson AJAX handlers, allowing authenticated users with subscriber-level access to read and modify other users' lesson notes and mark...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14184/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14185/",
      "current_public_safe_latest": false,
      "cvss_score": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.0485,
      "epss_score": 0.00152,
      "first_observed_at": "2026-07-28T06:05:50.269125+00:00",
      "id": "CVE-2026-14185",
      "impact_tags": [
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-28T06:05:50.269125+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The WPBot WordPress plugin before 8.2.0 does not perform a capability or nonce check in one of its retrieval-augmented-generation settings handlers, allowing authenticated users with subscriber-level access to modify the WPBot WordPress plugin before 8.2.0's...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260728T060840Z/items/CVE-2026-14185.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The WPBot WordPress plugin before 8.2.0 does not perform a capability or nonce check in one of its retrieval-augmented-generation settings handlers, allowing authenticated users with subscriber-level access to modify the WPBot WordPress plugin before 8.2.0's...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14185/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14188/",
      "current_public_safe_latest": false,
      "cvss_score": 2.7,
      "cvss_severity": "LOW",
      "epss_percentile": 0.15136,
      "epss_score": 0.0024,
      "first_observed_at": "2026-08-06T06:07:21.988664+00:00",
      "id": "CVE-2026-14188",
      "impact_tags": [
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-06T06:07:21.988664+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Easy Appointments WordPress plugin through 3.12.26 does not perform a per-request capability or nonce check on one of its customer-listing handlers, allowing authenticated users with contributor-level access to read every stored customer's personal...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260806T061754Z/items/CVE-2026-14188.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes authenticated boundary. Possible impact: This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Easy Appointments WordPress plugin through 3.12.26 does not perform a per-request capability or nonce check on one of its customer-listing handlers, allowing authenticated users with contributor-level access to read every stored customer's personal...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14188/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14189/",
      "current_public_safe_latest": false,
      "cvss_score": 3.8,
      "cvss_severity": "LOW",
      "epss_percentile": 0.05463,
      "epss_score": 0.00158,
      "first_observed_at": "2026-08-02T16:16:56.676027+00:00",
      "id": "CVE-2026-14189",
      "impact_tags": [
        "SQL injection risk"
      ],
      "kev": false,
      "last_observed_at": "2026-08-03T06:40:38.700520+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The WPBot WordPress plugin before 8.5.2 does not validate administrator-configured field identifiers before using them in a SQL query, allowing users with administrator access to perform SQL injection that executes when a visitor triggers a search.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260803T064356Z/items/CVE-2026-14189.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 3,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes SQL injection risk. Possible impact: An attacker may be able to read or change database-backed application data.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The WPBot WordPress plugin before 8.5.2 does not validate administrator-configured field identifiers before using them in a SQL query, allowing users with administrator access to perform SQL injection that executes when a visitor triggers a search.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14189/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14190/",
      "current_public_safe_latest": false,
      "cvss_score": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.05866,
      "epss_score": 0.00162,
      "first_observed_at": "2026-08-02T22:13:42.582353+00:00",
      "id": "CVE-2026-14190",
      "impact_tags": [
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-03T06:40:38.700520+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Sina Extension for Elementor WordPress plugin before 3.10.2 does not escape a value reconstructed from request input in one of its unauthenticated AJAX handlers before reflecting it into the HTML response, allowing unauthenticated attackers to execute...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260803T064356Z/items/CVE-2026-14190.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes remote exposure · authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Sina Extension for Elementor WordPress plugin before 3.10.2 does not escape a value reconstructed from request input in one of its unauthenticated AJAX handlers before reflecting it into the HTML response, allowing unauthenticated attackers to execute...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14190/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14192/",
      "current_public_safe_latest": false,
      "cvss_score": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.07117,
      "epss_score": 0.00175,
      "first_observed_at": "2026-08-11T10:14:04.199465+00:00",
      "id": "CVE-2026-14192",
      "impact_tags": [
        "XSS risk"
      ],
      "kev": false,
      "last_observed_at": "2026-08-11T10:14:04.199465+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Bilin Software and Informatics Consultancy Inc. NVD: HUMANIST Digital Human Resources allows Stored XSS. NVD: This issue affects HUMANIST Digital Human Resources: from 26.0 before 26.1.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260811T102539Z/items/CVE-2026-14192.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes XSS risk. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Bilin Software and Informatics Consultancy Inc. NVD: HUMANIST Digital Human Resources allows Stored XSS. NVD: This issue affects HUMANIST Digital Human Resources: from 26.0 before 26.1.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14192/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14194/",
      "current_public_safe_latest": false,
      "cvss_score": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.21801,
      "epss_score": 0.00295,
      "first_observed_at": "2026-08-11T10:14:04.199465+00:00",
      "id": "CVE-2026-14194",
      "impact_tags": [
        "path traversal review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-11T10:14:04.199465+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Bilin Software and Informatics Consultancy Inc. NVD: HUMANIST Digital Human Resources allows Path Traversal. NVD: This issue affects HUMANIST Digital Human Resources: from 26.0 before 26.1.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260811T102539Z/items/CVE-2026-14194.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes path traversal review. Possible impact: An attacker may be able to reach files outside the intended application path.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Bilin Software and Informatics Consultancy Inc. NVD: HUMANIST Digital Human Resources allows Path Traversal. NVD: This issue affects HUMANIST Digital Human Resources: from 26.0 before 26.1.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14194/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14195/",
      "current_public_safe_latest": false,
      "cvss_score": 2.7,
      "cvss_severity": "LOW",
      "epss_percentile": 0.07584,
      "epss_score": 0.00179,
      "first_observed_at": "2026-08-08T04:31:15.594937+00:00",
      "id": "CVE-2026-14195",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-08T04:31:15.594937+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Brizy WordPress plugin before 2.8.18 does not properly verify authorization on a request handler before returning post content, allowing users with the Contributor role or higher to read the content of arbitrary posts, including other users' private...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260808T043750Z/items/CVE-2026-14195.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Brizy WordPress plugin before 2.8.18 does not properly verify authorization on a request handler before returning post content, allowing users with the Contributor role or higher to read the content of arbitrary posts, including other users' private...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14195/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14197/",
      "current_public_safe_latest": false,
      "cvss_score": 3.8,
      "cvss_severity": "LOW",
      "epss_percentile": 0.0491,
      "epss_score": 0.00152,
      "first_observed_at": "2026-08-08T04:31:15.594937+00:00",
      "id": "CVE-2026-14197",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-08T04:31:15.594937+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Fluent Support WordPress plugin before 2.3.1 does not perform a per-ticket access check before reassigning a ticket's customer, allowing a restricted support agent to change the assigned customer of any ticket in the system, including tickets outside...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260808T043750Z/items/CVE-2026-14197.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Fluent Support WordPress plugin before 2.3.1 does not perform a per-ticket access check before reassigning a ticket's customer, allowing a restricted support agent to change the assigned customer of any ticket in the system, including tickets outside...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14197/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14202/",
      "current_public_safe_latest": false,
      "cvss_score": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.09691,
      "epss_score": 0.00197,
      "first_observed_at": "2026-08-11T10:14:04.199465+00:00",
      "id": "CVE-2026-14202",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-11T10:14:04.199465+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Observable response discrepancy vulnerability in Bilin Software and Informatics Consultancy Inc. NVD: HUMANIST Digital Human Resources allows Account Footprinting. NVD: This issue affects HUMANIST Digital Human Resources: from 26.0 before 26.1.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260811T102539Z/items/CVE-2026-14202.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Observable response discrepancy vulnerability in Bilin Software and Informatics Consultancy Inc. NVD: HUMANIST Digital Human Resources allows Account Footprinting. NVD: This issue affects HUMANIST Digital Human Resources: from 26.0 before 26.1.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14202/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14203/",
      "current_public_safe_latest": false,
      "cvss_score": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.04004,
      "epss_score": 0.00142,
      "first_observed_at": "2026-08-02T22:13:42.582353+00:00",
      "id": "CVE-2026-14203",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-03T06:40:38.700520+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Smart Manager WordPress plugin before 8.92.0 does not properly encode a post field before rendering it into an HTML attribute in its management grid, allowing users with the Contributor role or above to inject JavaScript that executes in the browser...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260803T064356Z/items/CVE-2026-14203.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Smart Manager WordPress plugin before 8.92.0 does not properly encode a post field before rendering it into an HTML attribute in its management grid, allowing users with the Contributor role or above to inject JavaScript that executes in the browser...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14203/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14207/",
      "current_public_safe_latest": false,
      "cvss_score": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.09112,
      "epss_score": 0.00192,
      "first_observed_at": "2026-08-06T06:07:21.988664+00:00",
      "id": "CVE-2026-14207",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-06T06:07:21.988664+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The LifterLMS WordPress plugin before 10.0.10 does not strip event-handler attributes from a course pricing field before storing and rendering it, allowing users with a course-editing role to inject JavaScript that executes in the session of an administrator...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260806T061754Z/items/CVE-2026-14207.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The LifterLMS WordPress plugin before 10.0.10 does not strip event-handler attributes from a course pricing field before storing and rendering it, allowing users with a course-editing role to inject JavaScript that executes in the session of an administrator...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14207/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14214/",
      "current_public_safe_latest": false,
      "cvss_score": 2.7,
      "cvss_severity": "LOW",
      "epss_percentile": 0.06458,
      "epss_score": 0.00168,
      "first_observed_at": "2026-08-08T04:31:15.594937+00:00",
      "id": "CVE-2026-14214",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-08T04:31:15.594937+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Booking for Appointments and Events Calendar WordPress plugin before 2.4.4 does not restrict which fields can be written through its customer import, allowing a user with the Amelia Manager role to modify arbitrary columns of any stored user record by...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260808T043750Z/items/CVE-2026-14214.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Booking for Appointments and Events Calendar WordPress plugin before 2.4.4 does not restrict which fields can be written through its customer import, allowing a user with the Amelia Manager role to modify arbitrary columns of any stored user record by...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14214/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14219/",
      "current_public_safe_latest": false,
      "cvss_score": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.05658,
      "epss_score": 0.0016,
      "first_observed_at": "2026-08-11T10:14:04.199465+00:00",
      "id": "CVE-2026-14219",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-11T10:14:04.199465+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: URL redirection to untrusted site ('open redirect') vulnerability in Bilin Software and Informatics Consultancy Inc. NVD: HUMANIST Digital Human Resources allows Phishing. NVD: This issue affects HUMANIST Digital Human Resources: from 26.0 before 26.1.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260811T102539Z/items/CVE-2026-14219.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: URL redirection to untrusted site ('open redirect') vulnerability in Bilin Software and Informatics Consultancy Inc. NVD: HUMANIST Digital Human Resources allows Phishing. NVD: This issue affects HUMANIST Digital Human Resources: from 26.0 before 26.1.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14219/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14221/",
      "current_public_safe_latest": false,
      "cvss_score": 3.8,
      "cvss_severity": "LOW",
      "epss_percentile": 0.09284,
      "epss_score": 0.00194,
      "first_observed_at": "2026-08-06T06:07:21.988664+00:00",
      "id": "CVE-2026-14221",
      "impact_tags": [
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-06T06:07:21.988664+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Easy Appointments WordPress plugin through 3.12.26 does not perform capability checks in several of its appointment-management actions, relying only on a nonce that any authenticated user can obtain, allowing users with contributor-level access to read...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260806T061754Z/items/CVE-2026-14221.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes authenticated boundary. Possible impact: This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Easy Appointments WordPress plugin through 3.12.26 does not perform capability checks in several of its appointment-management actions, relying only on a nonce that any authenticated user can obtain, allowing users with contributor-level access to read...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14221/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14222/",
      "current_public_safe_latest": false,
      "cvss_score": 3.8,
      "cvss_severity": "LOW",
      "epss_percentile": 0.15351,
      "epss_score": 0.00242,
      "first_observed_at": "2026-08-06T06:07:21.988664+00:00",
      "id": "CVE-2026-14222",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-06T06:07:21.988664+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Easy Appointments WordPress plugin through 3.12.26 does not perform any capability or nonce check in one of its connection-deletion actions, allowing users with contributor-level access to delete the booking configuration and disable the booking system.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260806T061754Z/items/CVE-2026-14222.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Easy Appointments WordPress plugin through 3.12.26 does not perform any capability or nonce check in one of its connection-deletion actions, allowing users with contributor-level access to delete the booking configuration and disable the booking system.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14222/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14223/",
      "current_public_safe_latest": false,
      "cvss_score": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.10717,
      "epss_score": 0.00206,
      "first_observed_at": "2026-08-06T06:07:21.988664+00:00",
      "id": "CVE-2026-14223",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-06T06:07:21.988664+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Easy Appointments WordPress plugin through 3.12.26 does not verify ownership or capability when returning stored customer details, allowing users with subscriber-level access to read any customer's personal information by iterating an identifier.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260806T061754Z/items/CVE-2026-14223.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Easy Appointments WordPress plugin through 3.12.26 does not verify ownership or capability when returning stored customer details, allowing users with subscriber-level access to read any customer's personal information by iterating an identifier.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14223/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14224/",
      "current_public_safe_latest": false,
      "cvss_score": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.04321,
      "epss_score": 0.00146,
      "first_observed_at": "2026-08-05T06:03:49.171468+00:00",
      "id": "CVE-2026-14224",
      "impact_tags": [
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-05T06:03:49.171468+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Easy Appointments WordPress plugin through 3.12.26 does not verify that the appointment targeted by its customer-data update action belongs to the current user; the action only checks a shared nonce that any authenticated user can obtain from their own... NVD: A subscriber-level user with an appointment of their own can therefore reuse that nonce to overwrite the customer metadata (email, name, phone, description) of another user's appointment. NVD: Because the Easy Appointments WordPress plugin through 3.12.26 then treats that metadata as the appointment's contact data, a subsequent administrator status change with customer notifications enabled delivers the victim's appointment notification to the...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260805T061218Z/items/CVE-2026-14224.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Easy Appointments WordPress plugin through 3.12.26 does not verify that the appointment targeted by its customer-data update action belongs to the current user; the action only checks a shared nonce that any authenticated user can obtain from their own... NVD: A subscriber-level user with an appointment of their own can therefore reuse that nonce to overwrite the customer metadata (email, name, phone, description) of another user's appointment. NVD: Because the Easy Appointments WordPress plugin through 3.12.26 then treats that metadata as the appointment's contact data, a subsequent administrator status change with customer notifications enabled delivers the victim's appointment notification to the...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14224/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14226/",
      "current_public_safe_latest": false,
      "cvss_score": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.13095,
      "epss_score": 0.00224,
      "first_observed_at": "2026-08-06T06:07:21.988664+00:00",
      "id": "CVE-2026-14226",
      "impact_tags": [
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-06T06:07:21.988664+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Easy Appointments WordPress plugin through 3.12.26 does not require a sufficient capability on one of its appointment-listing REST endpoints, restricting it only to a capability that every authenticated user holds, allowing users with subscriber-level...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260806T061754Z/items/CVE-2026-14226.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Easy Appointments WordPress plugin through 3.12.26 does not require a sufficient capability on one of its appointment-listing REST endpoints, restricting it only to a capability that every authenticated user holds, allowing users with subscriber-level...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14226/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14231/",
      "current_public_safe_latest": false,
      "cvss_score": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.13095,
      "epss_score": 0.00224,
      "first_observed_at": "2026-08-06T06:07:21.988664+00:00",
      "id": "CVE-2026-14231",
      "impact_tags": [
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-06T06:07:21.988664+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The LifterLMS WordPress plugin before 10.0.10 does not perform a capability check in one of its select2 query AJAX handlers, only verifying that the user is logged in, allowing any authenticated user with subscriber-level access to read the titles of internal...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260806T061754Z/items/CVE-2026-14231.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The LifterLMS WordPress plugin before 10.0.10 does not perform a capability check in one of its select2 query AJAX handlers, only verifying that the user is logged in, allowing any authenticated user with subscriber-level access to read the titles of internal...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14231/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14234/",
      "current_public_safe_latest": false,
      "cvss_score": 7.1,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.00977,
      "epss_score": 0.00099,
      "first_observed_at": "2026-08-05T06:03:49.171468+00:00",
      "id": "CVE-2026-14234",
      "impact_tags": [
        "XSS risk",
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-05T06:03:49.171468+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The WOLF WordPress plugin before 1.1.0 does not perform a nonce or capability check on one of its AJAX actions, allowing an unauthenticated attacker to trick a logged-in administrator into writing arbitrary content, including a malicious script, into a post...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260805T061218Z/items/CVE-2026-14234.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes XSS risk · remote exposure · authenticated boundary. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk · remote exposure · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The WOLF WordPress plugin before 1.1.0 does not perform a nonce or capability check on one of its AJAX actions, allowing an unauthenticated attacker to trick a logged-in administrator into writing arbitrary content, including a malicious script, into a post...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14234/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14235/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.14213,
      "epss_score": 0.00232,
      "first_observed_at": "2026-08-02T22:13:42.582353+00:00",
      "id": "CVE-2026-14235",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-03T06:40:38.700520+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Download Manager WordPress plugin before 3.3.62 does not bind its temporary download token to the requesting session nor expire it promptly, making the token a long-lived, multi-use, portable bearer token, so that an attacker who obtains one leaked...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260803T064356Z/items/CVE-2026-14235.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Download Manager WordPress plugin before 3.3.62 does not bind its temporary download token to the requesting session nor expire it promptly, making the token a long-lived, multi-use, portable bearer token, so that an attacker who obtains one leaked...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14235/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14236/",
      "current_public_safe_latest": false,
      "cvss_score": 4.7,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.06747,
      "epss_score": 0.00171,
      "first_observed_at": "2026-08-03T06:40:38.700520+00:00",
      "id": "CVE-2026-14236",
      "impact_tags": [
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-03T06:40:38.700520+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Contact Form 7 WordPress plugin before 2.5 does not validate the host of a user-supplied return URL before using it as the success and cancel redirect targets of a Stripe checkout, allowing an unauthenticated attacker to redirect a victim, via a crafted...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260803T064356Z/items/CVE-2026-14236.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes remote exposure · authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Contact Form 7 WordPress plugin before 2.5 does not validate the host of a user-supplied return URL before using it as the success and cancel redirect targets of a Stripe checkout, allowing an unauthenticated attacker to redirect a victim, via a crafted...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14236/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14250/",
      "current_public_safe_latest": false,
      "cvss_score": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.11094,
      "epss_score": 0.00209,
      "first_observed_at": "2026-07-15T11:03:27.604769+00:00",
      "id": "CVE-2026-14250",
      "impact_tags": [
        "privilege boundary review",
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-15T11:03:27.604769+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Themehunk Login Registration plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 1.0.2. NVD: This is due to the handle_frontend_register() function in the unauthenticated /thlogin/v1/register REST endpoint accepting a user-controlled 'role' parameter and validating it only against get_editable_roles() — which returns every defined editable site role... NVD: This makes it possible for unauthenticated attackers, when public user registration is enabled, to create new accounts with the editor role.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260715T110622Z/items/CVE-2026-14250.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes privilege escalation risk · remote exposure · authenticated boundary. Possible impact: A remote attacker may cross a privilege boundary and gain more access than intended.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Themehunk Login Registration plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 1.0.2. NVD: This is due to the handle_frontend_register() function in the unauthenticated /thlogin/v1/register REST endpoint accepting a user-controlled 'role' parameter and validating it only against get_editable_roles() — which returns every defined editable site role... NVD: This makes it possible for unauthenticated attackers, when public user registration is enabled, to create new accounts with the editor role.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14250/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14251/",
      "current_public_safe_latest": false,
      "cvss_score": 7.7,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.12913,
      "epss_score": 0.00223,
      "first_observed_at": "2026-07-22T06:07:21.492959+00:00",
      "id": "CVE-2026-14251",
      "impact_tags": [
        "service availability review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-22T06:07:21.492959+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A flaw was found in the OpenShift GitOps operator. NVD: The ClusterRole reconciler does not validate resource ownership when reconciling ClusterRole objects. NVD: A namespace-scoped Argo CD instance can trigger deletion of a ClusterRole owned by a cluster-scoped Argo CD instance by crafting a name collision, resulting in a denial of service.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260722T060931Z/items/CVE-2026-14251.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes service availability risk. Possible impact: The affected service may become unavailable or unreliable.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A flaw was found in the OpenShift GitOps operator. NVD: The ClusterRole reconciler does not validate resource ownership when reconciling ClusterRole objects. NVD: A namespace-scoped Argo CD instance can trigger deletion of a ClusterRole owned by a cluster-scoped Argo CD instance by crafting a name collision, resulting in a denial of service.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14251/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14261/",
      "current_public_safe_latest": false,
      "cvss_score": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.43385,
      "epss_score": 0.00571,
      "first_observed_at": "2026-07-16T13:54:14.110513+00:00",
      "id": "CVE-2026-14261",
      "impact_tags": [
        "code execution review",
        "authentication boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-16T13:54:14.110513+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A vulnerability in the Xerte Online Tools allows for authentication bypass and remote code execution via reinstallation through the /setup/ folder, enabling attackers to reinstall the service to a remote database they control. OSV: CVE-2026-14261 OSV: A vulnerability in the Xerte Online Tools allows for authentication bypass and remote code execution via reinstallation through the /setup/ folder, enabling attackers to reinstall the service to a remote database they control.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260716T135621Z/items/CVE-2026-14261.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes code execution review · authentication boundary review. Possible impact: An attacker may be able to run code or commands on affected systems.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability in the Xerte Online Tools allows for authentication bypass and remote code execution via reinstallation through the /setup/ folder, enabling attackers to reinstall the service to a remote database they control. OSV: CVE-2026-14261 OSV: A vulnerability in the Xerte Online Tools allows for authentication bypass and remote code execution via reinstallation through the /setup/ folder, enabling attackers to reinstall the service to a remote database they control.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14261/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14262/",
      "current_public_safe_latest": false,
      "cvss_score": 8.8,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.31584,
      "epss_score": 0.00393,
      "first_observed_at": "2026-07-18T05:13:28.850753+00:00",
      "id": "CVE-2026-14262",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-18T05:13:28.850753+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Simple JWT Login – Allows you to use JWT on REST endpoints.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260718T051545Z/items/CVE-2026-14262.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Simple JWT Login – Allows you to use JWT on REST endpoints.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14262/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14270/",
      "current_public_safe_latest": false,
      "cvss_score": 8.8,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.42799,
      "epss_score": 0.00548,
      "first_observed_at": "2026-08-05T11:32:09.387600+00:00",
      "id": "CVE-2026-14270",
      "impact_tags": [
        "code execution review",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-05T11:32:09.387600+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Extra Checkout Options (addon for Extra Product Options & Add-Ons for WooCommerce) plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 2.3.2. NVD: This is due to missing authorization and nonce validation in the eco_save_settings() function, which allows low-privileged authenticated users to modify the tc_eco_custom_file_types upload allowlist setting, combined with insufficient authorization on the... NVD: This makes it possible for authenticated attackers, with Subscriber-level access and above, to allow PHP uploads, upload a PHP file using the frontend upload nonce exposed on cart and checkout pages, and achieve remote code execution.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260805T113552Z/items/CVE-2026-14270.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes code execution review · authenticated boundary. Possible impact: An attacker may be able to run code or commands on affected systems.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: The Extra Checkout Options (addon for Extra Product Options & Add-Ons for WooCommerce) plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 2.3.2. NVD: This is due to missing authorization and nonce validation in the eco_save_settings() function, which allows low-privileged authenticated users to modify the tc_eco_custom_file_types upload allowlist setting, combined with insufficient authorization on the... NVD: This makes it possible for authenticated attackers, with Subscriber-level access and above, to allow PHP uploads, upload a PHP file using the frontend upload nonce exposed on cart and checkout pages, and achieve remote code execution.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14270/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14289/",
      "current_public_safe_latest": false,
      "cvss_score": 9.0,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.32425,
      "epss_score": 0.00396,
      "first_observed_at": "2026-08-03T06:40:38.700520+00:00",
      "id": "CVE-2026-14289",
      "impact_tags": [
        "code execution review",
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-03T06:40:38.700520+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The FacturaONE para WooCommerce con VeriFactu WordPress plugin before 5.37 does not authenticate one of its request handlers, whose only protection is derived from a cryptographic key that is empty in the default, unconfigured state, allowing unauthenticated...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260803T064356Z/items/CVE-2026-14289.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes code execution review · remote exposure · authenticated boundary. Possible impact: A remote attacker may be able to run code or commands on affected systems.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The FacturaONE para WooCommerce con VeriFactu WordPress plugin before 5.37 does not authenticate one of its request handlers, whose only protection is derived from a cryptographic key that is empty in the default, unconfigured state, allowing unauthenticated...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14289/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14291/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.25139,
      "epss_score": 0.00327,
      "first_observed_at": "2026-07-30T06:01:44.452906+00:00",
      "id": "CVE-2026-14291",
      "impact_tags": [
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-30T06:01:44.452906+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The security-ninja-premium WordPress plugin before 5.290 does not verify the second authentication factor in one of its two-factor authentication code paths, allowing an unauthenticated attacker who knows a user's password to complete authentication without... NVD: The affected two-factor module ships only in the premium build.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260730T060504Z/items/CVE-2026-14291.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes remote exposure · authenticated boundary. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The security-ninja-premium WordPress plugin before 5.290 does not verify the second authentication factor in one of its two-factor authentication code paths, allowing an unauthenticated attacker who knows a user's password to complete authentication without... NVD: The affected two-factor module ships only in the premium build.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14291/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14292/",
      "current_public_safe_latest": false,
      "cvss_score": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.05561,
      "epss_score": 0.00159,
      "first_observed_at": "2026-08-08T04:31:15.594937+00:00",
      "id": "CVE-2026-14292",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-08T04:31:15.594937+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Download Manager WordPress plugin before 3.3.66 does not properly escape a package's title before outputting it in the front-end package templates, allowing users with the Author role or above to store a title that results in arbitrary JavaScript...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260808T043750Z/items/CVE-2026-14292.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Download Manager WordPress plugin before 3.3.66 does not properly escape a package's title before outputting it in the front-end package templates, allowing users with the Author role or above to store a title that results in arbitrary JavaScript...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14292/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14300/",
      "current_public_safe_latest": false,
      "cvss_score": 8.1,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.15077,
      "epss_score": 0.00239,
      "first_observed_at": "2026-08-05T06:03:49.171468+00:00",
      "id": "CVE-2026-14300",
      "impact_tags": [
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-05T06:03:49.171468+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) WordPress plugin before 7.8.0 does not bind the one-time code used by its optional email-verification (Profile Completion) feature to the account it was issued for, allowing... NVD: Exploitation requires the Profile Completion feature to be enabled and social login to be configured.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260805T061218Z/items/CVE-2026-14300.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes remote exposure · authenticated boundary. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) WordPress plugin before 7.8.0 does not bind the one-time code used by its optional email-verification (Profile Completion) feature to the account it was issued for, allowing... NVD: Exploitation requires the Profile Completion feature to be enabled and social login to be configured.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14300/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "eclipse / accessibility_tools_framework",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14304/",
      "current_public_safe_latest": true,
      "cvss_score": 4.6,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.06863,
      "epss_score": 0.00172,
      "first_observed_at": "2026-08-12T10:29:37.194110+00:00",
      "id": "CVE-2026-14304",
      "impact_tags": [
        "privilege boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-12T10:29:37.194110+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-14304.json",
      "product": "accessibility_tools_framework",
      "public_safe_summary": "NVD: In Eclipse Accessibility Tools Framework (ACTF) versions up to 1.6.0 (including source code versions up to v20260630 and ACTF based application miChecker versions up to 3.1.0), it has been identified that an XML External Entity (XXE) vulnerability exists. NVD: If this vulnerability is exploited, a malicious third party could gain access to local resources or internal network resources via computer running applications that use Eclipse ACTF, including miChecker. OSV: In Eclipse Accessibility Tools Framework (ACTF) versions up to 1.6.0 (including source code versions up to v20260630 and ACTF based application miChecker versions up to 3.1.0), it has been identified that an XML External Entity (XXE) vulnerability exists.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260812T103932Z/items/CVE-2026-14304.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: eclipse / accessibility_tools_framework",
      "source_published_impact": "Source describes privilege escalation risk. Possible impact: An attacker may cross a privilege boundary and gain more access than intended.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: In Eclipse Accessibility Tools Framework (ACTF) versions up to 1.6.0 (including source code versions up to v20260630 and ACTF based application miChecker versions up to 3.1.0), it has been identified that an XML External Entity (XXE) vulnerability exists. NVD: If this vulnerability is exploited, a malicious third party could gain access to local resources or internal network resources via computer running applications that use Eclipse ACTF, including miChecker. OSV: In Eclipse Accessibility Tools Framework (ACTF) versions up to 1.6.0 (including source code versions up to v20260630 and ACTF based application miChecker versions up to 3.1.0), it has been identified that an XML External Entity (XXE) vulnerability exists.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14304/timeline.json",
      "vendor": "eclipse"
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14309/",
      "current_public_safe_latest": false,
      "cvss_score": 8.1,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.1336,
      "epss_score": 0.00226,
      "first_observed_at": "2026-08-08T04:31:15.594937+00:00",
      "id": "CVE-2026-14309",
      "impact_tags": [
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-08T04:31:15.594937+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Chat On Desk Order Notifications WordPress plugin before 1.0.9 does not verify that the one-time password has been validated before processing a password-reset request, allowing unauthenticated attackers to reset the password of arbitrary users, including...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260808T043750Z/items/CVE-2026-14309.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes remote exposure · authenticated boundary. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Chat On Desk Order Notifications WordPress plugin before 1.0.9 does not verify that the one-time password has been validated before processing a password-reset request, allowing unauthenticated attackers to reset the password of arbitrary users, including...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14309/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14315/",
      "current_public_safe_latest": false,
      "cvss_score": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.06054,
      "epss_score": 0.00164,
      "first_observed_at": "2026-08-08T04:31:15.594937+00:00",
      "id": "CVE-2026-14315",
      "impact_tags": [
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-08T04:31:15.594937+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Pixel Tag Manager for WooCommerce WordPress plugin before 2.2.1 does not perform an authorization check on one of its AJAX actions, allowing unauthenticated users to submit forged e-commerce conversion events to the site's configured server-side...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260808T043750Z/items/CVE-2026-14315.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Pixel Tag Manager for WooCommerce WordPress plugin before 2.2.1 does not perform an authorization check on one of its AJAX actions, allowing unauthenticated users to submit forged e-commerce conversion events to the site's configured server-side...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14315/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14317/",
      "current_public_safe_latest": false,
      "cvss_score": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.12683,
      "epss_score": 0.00221,
      "first_observed_at": "2026-08-07T05:06:11.845797+00:00",
      "id": "CVE-2026-14317",
      "impact_tags": [
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-07T05:06:11.845797+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The GiveWP WordPress plugin before 4.16.3 does not restrict the set of available payment gateways to those enabled by the administrator, deriving it in part from request input, which allows unauthenticated users to complete donations through a payment gateway...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260807T051140Z/items/CVE-2026-14317.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The GiveWP WordPress plugin before 4.16.3 does not restrict the set of available payment gateways to those enabled by the administrator, deriving it in part from request input, which allows unauthenticated users to complete donations through a payment gateway...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14317/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14319/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.23963,
      "epss_score": 0.00316,
      "first_observed_at": "2026-08-07T05:06:11.845797+00:00",
      "id": "CVE-2026-14319",
      "impact_tags": [
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-07T05:06:11.845797+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The GiveWP WordPress plugin before 4.16.3 does not properly restrict access to a REST API endpoint that returns recurring-donation records, allowing unauthenticated users to retrieve information about anonymous recurring donors, including their name and...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260807T051140Z/items/CVE-2026-14319.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes authenticated boundary. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The GiveWP WordPress plugin before 4.16.3 does not properly restrict access to a REST API endpoint that returns recurring-donation records, allowing unauthenticated users to retrieve information about anonymous recurring donors, including their name and...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14319/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14322/",
      "current_public_safe_latest": false,
      "cvss_score": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.08054,
      "epss_score": 0.00182,
      "first_observed_at": "2026-07-29T06:10:00.110927+00:00",
      "id": "CVE-2026-14322",
      "impact_tags": [
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-29T06:10:00.110927+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Timetics WordPress plugin before 1.0.57 does not enforce a pending or unpaid status for new bookings created through a payment method other than its recognised gateways, allowing unauthenticated users to create fully-approved bookings for priced...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260729T062752Z/items/CVE-2026-14322.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Timetics WordPress plugin before 1.0.57 does not enforce a pending or unpaid status for new bookings created through a payment method other than its recognised gateways, allowing unauthenticated users to create fully-approved bookings for priced...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14322/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-1433/",
      "current_public_safe_latest": false,
      "cvss_score": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.12134,
      "epss_score": 0.00217,
      "first_observed_at": "2026-07-13T06:32:51.098771+00:00",
      "id": "CVE-2026-1433",
      "impact_tags": [
        "admin privilege risk",
        "information exposure review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-13T06:32:51.098771+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: uniFLOW Universal Login Manager (ULM) Standalone contains an information disclosure vulnerability that may allow an authenticated administrator to access sensitive configuration information through the ULM Remote User Interface (RUI). NVD: Exploitation requires administrative privileges and may disclose configuration data associated with SMTP or LDAP integrations. NVD: ULM deployments connected to uniFLOW Server or uniFLOW Online are not affected.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260713T063521Z/items/CVE-2026-1433.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes admin privilege risk · information exposure review. Possible impact: An attacker may gain root or administrative-level privileges on affected systems.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: uniFLOW Universal Login Manager (ULM) Standalone contains an information disclosure vulnerability that may allow an authenticated administrator to access sensitive configuration information through the ULM Remote User Interface (RUI). NVD: Exploitation requires administrative privileges and may disclose configuration data associated with SMTP or LDAP integrations. NVD: ULM deployments connected to uniFLOW Server or uniFLOW Online are not affected.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-1433/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14333/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.21838,
      "epss_score": 0.00296,
      "first_observed_at": "2026-08-07T05:06:11.845797+00:00",
      "id": "CVE-2026-14333",
      "impact_tags": [
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-07T05:06:11.845797+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Demi WordPress plugin before 0.0.7 stores its full-site backup archives in a publicly accessible location under a predictable filename and without access protection, allowing unauthenticated attackers to download complete backups including the site...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260807T051140Z/items/CVE-2026-14333.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes remote exposure · authenticated boundary. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Demi WordPress plugin before 0.0.7 stores its full-site backup archives in a publicly accessible location under a predictable filename and without access protection, allowing unauthenticated attackers to download complete backups including the site...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14333/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14345/",
      "current_public_safe_latest": false,
      "cvss_score": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.5049,
      "epss_score": 0.00745,
      "first_observed_at": "2026-07-14T05:42:23.241208+00:00",
      "id": "CVE-2026-14345",
      "impact_tags": [
        "code execution review",
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-14T05:42:23.241208+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 3.12.7 via the 'postData' parameter parameter. NVD: This is due to unsanitized write of attacker-controlled postData values into a PHP-includeable .log file combined with the use of include_once to render that file in wpfnl_show_log. NVD: This makes it possible for unauthenticated attackers to execute code on the server.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260714T054512Z/items/CVE-2026-14345.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes code execution review · remote exposure · authenticated boundary. Possible impact: A remote attacker may be able to run code or commands on affected systems.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 3.12.7 via the 'postData' parameter parameter. NVD: This is due to unsanitized write of attacker-controlled postData values into a PHP-includeable .log file combined with the use of include_once to render that file in wpfnl_show_log. NVD: This makes it possible for unauthenticated attackers to execute code on the server.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14345/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14354/",
      "current_public_safe_latest": false,
      "cvss_score": 8.7,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.01912,
      "epss_score": 0.00117,
      "first_observed_at": "2026-08-05T11:32:09.387600+00:00",
      "id": "CVE-2026-14354",
      "impact_tags": [
        "authentication boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-05T11:32:09.387600+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: CWE-522 Insufficiently Protected Credentials vulnerability exists that could cause authentication bypass and unauthorized credential modification, potentially leading to compromise of managed devices, when a local privileged attacker leverages weaknesses in...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260805T113552Z/items/CVE-2026-14354.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes authentication boundary review. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authentication boundary review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: CWE-522 Insufficiently Protected Credentials vulnerability exists that could cause authentication bypass and unauthorized credential modification, potentially leading to compromise of managed devices, when a local privileged attacker leverages weaknesses in...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14354/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14371/",
      "current_public_safe_latest": false,
      "cvss_score": 8.8,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.51343,
      "epss_score": 0.00757,
      "first_observed_at": "2026-07-23T16:53:12.033252+00:00",
      "id": "CVE-2026-14371",
      "impact_tags": [
        "command injection risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-23T16:53:12.033252+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Lenovo XClarity Integrator for Windows Admin Center plugin version 5.1.1 and below running on the WAC Gateway is vulnerable to Powershell Command Injection when establishing remote PowerShell commands.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260723T171217Z/items/CVE-2026-14371.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes command injection risk. Possible impact: An attacker may be able to run unintended system commands through the affected component.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Lenovo XClarity Integrator for Windows Admin Center plugin version 5.1.1 and below running on the WAC Gateway is vulnerable to Powershell Command Injection when establishing remote PowerShell commands.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14371/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14372/",
      "current_public_safe_latest": false,
      "cvss_score": 7.1,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.48652,
      "epss_score": 0.00691,
      "first_observed_at": "2026-07-16T11:14:01.223847+00:00",
      "id": "CVE-2026-14372",
      "impact_tags": [
        "code execution review",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-16T11:14:01.223847+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Bit Form – Contact Form, Payment Forms, Multi Step Forms, Calculator & Custom Form Builder plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the deleteFiles function in all versions up to, and...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260716T111601Z/items/CVE-2026-14372.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes code execution review · authenticated boundary. Possible impact: An attacker may be able to run code or commands on affected systems.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Bit Form – Contact Form, Payment Forms, Multi Step Forms, Calculator & Custom Form Builder plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the deleteFiles function in all versions up to, and...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14372/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "perl / dbi",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14380/",
      "current_public_safe_latest": false,
      "cvss_score": 8.8,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.39232,
      "epss_score": 0.00498,
      "first_observed_at": "2026-07-14T22:16:58.989760+00:00",
      "id": "CVE-2026-14380",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-14T22:16:58.989760+00:00",
      "latest_item_url": null,
      "product": "dbi",
      "public_safe_summary": "NVD: DBI versions before 1.650 for Perl are vulnerable to code injection via caller-influenced Profile. NVD: When a string is assigned to a DBI handle's Profile attribute, DBI splits it into path, package and arguments, and interpolates the package part in a string eval with no validation of the package name. NVD: Any caller-influenced value that reaches the Profile attribute is therefore arbitrary Perl code execution, including calls to run system commands.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260714T222111Z/items/CVE-2026-14380.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: perl / dbi",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: DBI versions before 1.650 for Perl are vulnerable to code injection via caller-influenced Profile. NVD: When a string is assigned to a DBI handle's Profile attribute, DBI splits it into path, package and arguments, and interpolates the package part in a string eval with no validation of the package name. NVD: Any caller-influenced value that reaches the Profile attribute is therefore arbitrary Perl code execution, including calls to run system commands.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14380/timeline.json",
      "vendor": "perl"
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14449/",
      "current_public_safe_latest": false,
      "cvss_score": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.18547,
      "epss_score": 0.00269,
      "first_observed_at": "2026-07-09T11:52:04.215901+00:00",
      "id": "CVE-2026-14449",
      "impact_tags": [
        "XSS risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-09T11:52:04.215901+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: u5CMS through v12.8.8 is vulnerable to reflected XSS via the ‘thanks’ parameter in multiple form components OSV: POST-based reflected XSS via the thanks parameter in form components OSV: u5CMS through v12.8.8 is vulnerable to reflected XSS via the ‘thanks’ parameter in multiple form components",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260709T115259Z/items/CVE-2026-14449.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes XSS risk. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: u5CMS through v12.8.8 is vulnerable to reflected XSS via the ‘thanks’ parameter in multiple form components OSV: POST-based reflected XSS via the thanks parameter in form components OSV: u5CMS through v12.8.8 is vulnerable to reflected XSS via the ‘thanks’ parameter in multiple form components",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14449/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "tonycoz / imager",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14454/",
      "current_public_safe_latest": false,
      "cvss_score": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.31541,
      "epss_score": 0.00394,
      "first_observed_at": "2026-07-15T11:03:27.604769+00:00",
      "id": "CVE-2026-14454",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-15T11:03:27.604769+00:00",
      "latest_item_url": null,
      "product": "imager",
      "public_safe_summary": "NVD: Imager versions before 1.033 for Perl treat unsigned EXIF IFD entry counts as signed. NVD: Imager mishandled large EXIF IFD entry count values, treating them as negative numbers. NVD: This could lead to an attempt to allocate a block nearly the size of the address space, which fails and kills the process.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260715T110622Z/items/CVE-2026-14454.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: tonycoz / imager",
      "source_published_impact": "This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Imager versions before 1.033 for Perl treat unsigned EXIF IFD entry counts as signed. NVD: Imager mishandled large EXIF IFD entry count values, treating them as negative numbers. NVD: This could lead to an attempt to allocate a block nearly the size of the address space, which fails and kills the process.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14454/timeline.json",
      "vendor": "tonycoz"
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14459/",
      "current_public_safe_latest": false,
      "cvss_score": 8.8,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.0972,
      "epss_score": 0.00198,
      "first_observed_at": "2026-07-10T12:09:55.374028+00:00",
      "id": "CVE-2026-14459",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-10T12:09:55.374028+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Improper neutralization of argument delimiters in a command ('argument injection') vulnerability in TUBITAK BILGEM Software Technologies Research Institute pardus-software allows Argument Injection. NVD: This issue affects pardus-software: from <= 1.0.4 before 1.0.5.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260710T121119Z/items/CVE-2026-14459.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Improper neutralization of argument delimiters in a command ('argument injection') vulnerability in TUBITAK BILGEM Software Technologies Research Institute pardus-software allows Argument Injection. NVD: This issue affects pardus-software: from <= 1.0.4 before 1.0.5.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14459/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14460/",
      "current_public_safe_latest": false,
      "cvss_score": 8.8,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.05907,
      "epss_score": 0.00163,
      "first_observed_at": "2026-07-10T12:09:55.374028+00:00",
      "id": "CVE-2026-14460",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-10T12:09:55.374028+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Missing Authorization vulnerability in TUBITAK BILGEM Software Technologies Research Institute pardus-software allows Argument Injection. NVD: This issue affects pardus-software: from <= 1.0.4 before 1.0.5.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260710T121119Z/items/CVE-2026-14460.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Missing Authorization vulnerability in TUBITAK BILGEM Software Technologies Research Institute pardus-software allows Argument Injection. NVD: This issue affects pardus-software: from <= 1.0.4 before 1.0.5.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14460/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14461/",
      "current_public_safe_latest": false,
      "cvss_score": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.22277,
      "epss_score": 0.00303,
      "first_observed_at": "2026-07-17T10:59:18.822206+00:00",
      "id": "CVE-2026-14461",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-17T10:59:18.822206+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: mtr is vulnerable to Out-of-bound read vulnerability in ipinfo_lookup() function. NVD: An attacker who can influence the TXT response used for AS lookups can trigger this bug by returning a DNS response that is larger than 512 bytes and uses a crafted compression pointer in the answer NAME field. NVD: ipinfo_lookup() function uses the length of the response as the end-of-message boundary for dn_expand() function.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260717T110142Z/items/CVE-2026-14461.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: commit.",
      "source_published_summary": "NVD: mtr is vulnerable to Out-of-bound read vulnerability in ipinfo_lookup() function. NVD: An attacker who can influence the TXT response used for AS lookups can trigger this bug by returning a DNS response that is larger than 512 bytes and uses a crafted compression pointer in the answer NAME field. NVD: ipinfo_lookup() function uses the length of the response as the end-of-message boundary for dn_expand() function.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14461/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14465/",
      "current_public_safe_latest": false,
      "cvss_score": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.1894,
      "epss_score": 0.0027,
      "first_observed_at": "2026-08-11T10:14:04.199465+00:00",
      "id": "CVE-2026-14465",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-11T10:14:04.199465+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Insufficient session expiration vulnerability in Bilin Software and Informatics Consultancy Inc. NVD: HUMANIST Digital Human Resources allows Reusing Session IDs (aka Session Replay). NVD: This issue affects HUMANIST Digital Human Resources: from 26.0 before 26.1.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260811T102539Z/items/CVE-2026-14465.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Insufficient session expiration vulnerability in Bilin Software and Informatics Consultancy Inc. NVD: HUMANIST Digital Human Resources allows Reusing Session IDs (aka Session Replay). NVD: This issue affects HUMANIST Digital Human Resources: from 26.0 before 26.1.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14465/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14475/",
      "current_public_safe_latest": false,
      "cvss_score": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.21365,
      "epss_score": 0.00294,
      "first_observed_at": "2026-07-17T05:58:07.763993+00:00",
      "id": "CVE-2026-14475",
      "impact_tags": [
        "information exposure review",
        "SQL injection risk",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-17T05:58:07.763993+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Cookie Banner for GDPR / CCPA – WPLP Cookie Consent plugin for WordPress is vulnerable to generic SQL Injection via the 'scan_id' parameter in all versions up to, and including, 4.3.6 due to insufficient escaping on the user supplied parameter and lack of... NVD: This makes it possible for authenticated attackers, with administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260717T060336Z/items/CVE-2026-14475.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes information exposure review · SQL injection risk · authenticated boundary. Possible impact: An attacker may be able to read or change database-backed application data.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Cookie Banner for GDPR / CCPA – WPLP Cookie Consent plugin for WordPress is vulnerable to generic SQL Injection via the 'scan_id' parameter in all versions up to, and including, 4.3.6 due to insufficient escaping on the user supplied parameter and lack of... NVD: This makes it possible for authenticated attackers, with administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14475/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14483/",
      "current_public_safe_latest": false,
      "cvss_score": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.45858,
      "epss_score": 0.00611,
      "first_observed_at": "2026-08-07T05:06:11.845797+00:00",
      "id": "CVE-2026-14483",
      "impact_tags": [
        "code execution review",
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-07T05:06:11.845797+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Realtyna Organic IDX plugin + WPL Real Estate plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 5.2.0 via the upload function. NVD: This is due to missing file type validation in the upload function, combined with a publicly accessible I/O endpoint authenticated solely by static, plugin-seeded API credentials that are identical across all installations. NVD: This makes it possible for unauthenticated attackers to upload files that may be executable, which makes remote code execution possible.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260807T051140Z/items/CVE-2026-14483.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes code execution review · remote exposure · authenticated boundary. Possible impact: A remote attacker may be able to run code or commands on affected systems.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Realtyna Organic IDX plugin + WPL Real Estate plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 5.2.0 via the upload function. NVD: This is due to missing file type validation in the upload function, combined with a publicly accessible I/O endpoint authenticated solely by static, plugin-seeded API credentials that are identical across all installations. NVD: This makes it possible for unauthenticated attackers to upload files that may be executable, which makes remote code execution possible.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14483/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14489/",
      "current_public_safe_latest": false,
      "cvss_score": 8.8,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.42755,
      "epss_score": 0.00561,
      "first_observed_at": "2026-07-15T05:43:30.245469+00:00",
      "id": "CVE-2026-14489",
      "impact_tags": [
        "code execution review",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-15T05:43:30.245469+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The WHMCS Bridge plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the connect() function in all versions up to, and including, 6.9. NVD: This makes it possible for authenticated attackers, with Custom-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260715T054459Z/items/CVE-2026-14489.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes code execution review · authenticated boundary. Possible impact: An attacker may be able to run code or commands on affected systems.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The WHMCS Bridge plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the connect() function in all versions up to, and including, 6.9. NVD: This makes it possible for authenticated attackers, with Custom-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14489/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14490/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.40644,
      "epss_score": 0.00509,
      "first_observed_at": "2026-08-03T22:29:45.220405+00:00",
      "id": "CVE-2026-14490",
      "impact_tags": [
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-04T06:07:04.591309+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Demi – One Click Demo Import, WP Backup & Site Migration plugin for WordPress is vulnerable to Arbitrary Directory Deletion in all versions up to, and including, 0.0.7. NVD: The vulnerability exists because the plugin stores its HMAC signing key and per-step restore token as dotfiles inside a publicly accessible subdirectory of the WordPress uploads folder — without any .htaccess or index file protection — and the... NVD: This makes it possible for unauthenticated attackers to recursively delete arbitrary directories on the server.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260804T061658Z/items/CVE-2026-14490.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes remote exposure · authenticated boundary. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Demi – One Click Demo Import, WP Backup & Site Migration plugin for WordPress is vulnerable to Arbitrary Directory Deletion in all versions up to, and including, 0.0.7. NVD: The vulnerability exists because the plugin stores its HMAC signing key and per-step restore token as dotfiles inside a publicly accessible subdirectory of the WordPress uploads folder — without any .htaccess or index file protection — and the... NVD: This makes it possible for unauthenticated attackers to recursively delete arbitrary directories on the server.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14490/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14495/",
      "current_public_safe_latest": false,
      "cvss_score": 8.8,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.34385,
      "epss_score": 0.00425,
      "first_observed_at": "2026-07-15T05:43:30.245469+00:00",
      "id": "CVE-2026-14495",
      "impact_tags": [
        "authentication boundary review",
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-15T05:43:30.245469+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The DoLogin Security plugin for WordPress is vulnerable to Authentication Bypass via Insufficient Randomness in all versions up to, and including, 4.3. NVD: The vulnerability exists because dologin\\s::rrand() seeds the Mersenne Twister with mt_srand((double) microtime() * 1000000) — discarding the integer-seconds component of microtime() and constraining the seed to a range of approximately 10^6 values (~20 bits... NVD: Because Pswdless::try_login() is registered on the unauthenticated init hook, resolves the target account by the auto-increment numeric ID embedded in the ?dologin=<id>.<hash> parameter, performs the hash comparison using a non-constant-time != operator, and...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260715T054459Z/items/CVE-2026-14495.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes authentication boundary review · remote exposure · authenticated boundary. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authentication boundary review · remote exposure · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The DoLogin Security plugin for WordPress is vulnerable to Authentication Bypass via Insufficient Randomness in all versions up to, and including, 4.3. NVD: The vulnerability exists because dologin\\s::rrand() seeds the Mersenne Twister with mt_srand((double) microtime() * 1000000) — discarding the integer-seconds component of microtime() and constraining the seed to a range of approximately 10^6 values (~20 bits... NVD: Because Pswdless::try_login() is registered on the unauthenticated init hook, resolves the target account by the auto-increment numeric ID embedded in the ?dologin=<id>.<hash> parameter, performs the hash comparison using a non-constant-time != operator, and...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14495/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14500/",
      "current_public_safe_latest": false,
      "cvss_score": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.2531,
      "epss_score": 0.00333,
      "first_observed_at": "2026-07-15T05:43:30.245469+00:00",
      "id": "CVE-2026-14500",
      "impact_tags": [
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-15T05:43:30.245469+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Bulk Order Update for WooCommerce plugin for WordPress is vulnerable to Arbitrary File Read in versions up to, and including, 1.6. NVD: This is due to the bouw_fetch_csv_data() AJAX handler being registered on the wp_ajax_nopriv_ hook with no capability or nonce check, and passing the attacker-supplied csv_url POST parameter — filtered only by esc_url_raw() (which leaves absolute filesystem... NVD: This makes it possible for unauthenticated attackers to read the first line of arbitrary files on the server (such as /etc/passwd) and to use the handler as a file-existence oracle.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260715T054459Z/items/CVE-2026-14500.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes remote exposure · authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Bulk Order Update for WooCommerce plugin for WordPress is vulnerable to Arbitrary File Read in versions up to, and including, 1.6. NVD: This is due to the bouw_fetch_csv_data() AJAX handler being registered on the wp_ajax_nopriv_ hook with no capability or nonce check, and passing the attacker-supplied csv_url POST parameter — filtered only by esc_url_raw() (which leaves absolute filesystem... NVD: This makes it possible for unauthenticated attackers to read the first line of arbitrary files on the server (such as /etc/passwd) and to use the handler as a file-existence oracle.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14500/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "trailofbits / fickling",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14534/",
      "current_public_safe_latest": false,
      "cvss_score": 8.8,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.24806,
      "epss_score": 0.00328,
      "first_observed_at": "2026-07-11T05:56:01.167453+00:00",
      "id": "CVE-2026-14534",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-11T10:36:25.311321+00:00",
      "latest_item_url": null,
      "product": "fickling",
      "public_safe_summary": "NVD: Trail of Bits fickling versions up to and including 0.1.10 do not include the Python standard library modules _posixsubprocess, site, and atexit in the UNSAFE_IMPORTS denylist (fickle.py). NVD: Because these modules are absent from the denylist, fickling's check_safety() function returns LIKELY_SAFE with zero findings for pickle payloads that invoke dangerous functions including _posixsubprocess.fork_exec (C-level process spawner capable of... NVD: This shares the same root cause as CVE-2026-22607 (cProfile), CVE-2025-67748 (pty), and CVE-2025-67747 (marshal/types).",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260711T103806Z/items/CVE-2026-14534.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "vendor/product: trailofbits / fickling",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Trail of Bits fickling versions up to and including 0.1.10 do not include the Python standard library modules _posixsubprocess, site, and atexit in the UNSAFE_IMPORTS denylist (fickle.py). NVD: Because these modules are absent from the denylist, fickling's check_safety() function returns LIKELY_SAFE with zero findings for pickle payloads that invoke dangerous functions including _posixsubprocess.fork_exec (C-level process spawner capable of... NVD: This shares the same root cause as CVE-2026-22607 (cProfile), CVE-2025-67748 (pty), and CVE-2025-67747 (marshal/types).",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14534/timeline.json",
      "vendor": "trailofbits"
    },
    {
      "affected_label": "trailofbits / fickling",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14535/",
      "current_public_safe_latest": false,
      "cvss_score": 8.8,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.22236,
      "epss_score": 0.00304,
      "first_observed_at": "2026-07-11T05:56:01.167453+00:00",
      "id": "CVE-2026-14535",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-11T10:36:25.311321+00:00",
      "latest_item_url": null,
      "product": "fickling",
      "public_safe_summary": "NVD: In Trail of Bits fickling versions up to and including 0.1.11, the UnsafeImportsML analysis pass unconditionally calls AnalysisContext.shorten_code(node) on every import node it inspects, regardless of whether the import is flagged as unsafe. NVD: This call registers the shortened code representation in the shared AnalysisContext.reported_shortened_code set. NVD: When the MLAllowlist analysis pass subsequently runs, it calls the same shorten_code() method, receives already_reported=True for every import, and executes a continue statement that skips its allowlist check entirely.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260711T103806Z/items/CVE-2026-14535.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "vendor/product: trailofbits / fickling",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: In Trail of Bits fickling versions up to and including 0.1.11, the UnsafeImportsML analysis pass unconditionally calls AnalysisContext.shorten_code(node) on every import node it inspects, regardless of whether the import is flagged as unsafe. NVD: This call registers the shortened code representation in the shared AnalysisContext.reported_shortened_code set. NVD: When the MLAllowlist analysis pass subsequently runs, it calls the same shorten_code() method, receives already_reported=True for every import, and executes a continue statement that skips its allowlist check entirely.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14535/timeline.json",
      "vendor": "trailofbits"
    },
    {
      "affected_label": "devolutions / devolutions_server",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14536/",
      "current_public_safe_latest": false,
      "cvss_score": 8.8,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.13881,
      "epss_score": 0.00231,
      "first_observed_at": "2026-07-13T17:24:46.617207+00:00",
      "id": "CVE-2026-14536",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-13T17:24:46.617207+00:00",
      "latest_item_url": null,
      "product": "devolutions_server",
      "public_safe_summary": "NVD: Improper enforcement of a mandatory multi-factor authentication policy in Devolutions Server 2026.2.9.0 allows an attacker with valid user credentials to bypass the MFA Required policy and authenticate without completing multi-factor authentication. NVD: The problem occurs when DVLS encounters an invalid default MFA value.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260713T172750Z/items/CVE-2026-14536.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: devolutions / devolutions_server",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Improper enforcement of a mandatory multi-factor authentication policy in Devolutions Server 2026.2.9.0 allows an attacker with valid user credentials to bypass the MFA Required policy and authenticate without completing multi-factor authentication. NVD: The problem occurs when DVLS encounters an invalid default MFA value.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14536/timeline.json",
      "vendor": "devolutions"
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14544/",
      "current_public_safe_latest": false,
      "cvss_score": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.39908,
      "epss_score": 0.00511,
      "first_observed_at": "2026-07-10T06:57:55.339390+00:00",
      "id": "CVE-2026-14544",
      "impact_tags": [
        "code execution review",
        "remote exposure relevant"
      ],
      "kev": false,
      "last_observed_at": "2026-07-10T06:57:55.339390+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A flaw was found in HPLIP (HP Linux Imaging and Printing Software). NVD: This vulnerability, an incomplete fix for CVE-2026-8631, may allow a remote attacker to escalate privileges or achieve arbitrary code execution. NVD: This can occur through an integer overflow in the hpcups processing path when handling specially crafted print data.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260710T070012Z/items/CVE-2026-14544.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes code execution review · remote exposure. Possible impact: A remote attacker may be able to run code or commands on affected systems.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A flaw was found in HPLIP (HP Linux Imaging and Printing Software). NVD: This vulnerability, an incomplete fix for CVE-2026-8631, may allow a remote attacker to escalate privileges or achieve arbitrary code execution. NVD: This can occur through an integer overflow in the hpcups processing path when handling specially crafted print data.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14544/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14545/",
      "current_public_safe_latest": false,
      "cvss_score": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.19965,
      "epss_score": 0.00277,
      "first_observed_at": "2026-08-04T06:07:04.591309+00:00",
      "id": "CVE-2026-14545",
      "impact_tags": [
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-04T06:07:04.591309+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The TrueBooker WordPress plugin before 1.2.4 does not validate account ownership when resetting a user's password through one of its front-end account handlers, allowing unauthenticated attackers to set an arbitrary password on any account, including an...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260804T061658Z/items/CVE-2026-14545.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes remote exposure · authenticated boundary. Possible impact: This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The TrueBooker WordPress plugin before 1.2.4 does not validate account ownership when resetting a user's password through one of its front-end account handlers, allowing unauthenticated attackers to set an arbitrary password on any account, including an...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14545/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14551/",
      "current_public_safe_latest": false,
      "cvss_score": 8.8,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.03156,
      "epss_score": 0.00132,
      "first_observed_at": "2026-07-29T06:10:00.110927+00:00",
      "id": "CVE-2026-14551",
      "impact_tags": [
        "privilege boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-29T06:10:00.110927+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The servereye client (also known as sensorhub, technically ClientAgentContainerService) versions 20.15 and earlier are vulnerable to Local Privilege Escalation. NVD: The high-privileged service SE3Recovery (EmergencyRecoveryService.exe), running as SYSTEM, periodically monitors the directory %ProgramData%\\ServerEye3\\update\\ for a trigger file named \"update_available\". NVD: Due to insufficient access restrictions on this directory, a local standard user can create the trigger file and provide a path to a directory containing malicious JSON instructions.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260729T062752Z/items/CVE-2026-14551.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes privilege escalation risk. Possible impact: An attacker may cross a privilege boundary and gain more access than intended.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The servereye client (also known as sensorhub, technically ClientAgentContainerService) versions 20.15 and earlier are vulnerable to Local Privilege Escalation. NVD: The high-privileged service SE3Recovery (EmergencyRecoveryService.exe), running as SYSTEM, periodically monitors the directory %ProgramData%\\ServerEye3\\update\\ for a trigger file named \"update_available\". NVD: Due to insufficient access restrictions on this directory, a local standard user can create the trigger file and provide a path to a directory containing malicious JSON instructions.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14551/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14557/",
      "current_public_safe_latest": false,
      "cvss_score": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.28186,
      "epss_score": 0.00354,
      "first_observed_at": "2026-08-10T04:58:31.923491+00:00",
      "id": "CVE-2026-14557",
      "impact_tags": [
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-10T04:58:31.923491+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The SoftMarket — Digital Marketplace WordPress plugin through 1.0.0 does not properly validate an authentication token in one branch of its email-verification flow, allowing unauthenticated attackers to obtain a valid session as any verified user by supplying...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260810T050414Z/items/CVE-2026-14557.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes remote exposure · authenticated boundary. Possible impact: This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The SoftMarket — Digital Marketplace WordPress plugin through 1.0.0 does not properly validate an authentication token in one branch of its email-verification flow, allowing unauthenticated attackers to obtain a valid session as any verified user by supplying...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14557/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14561/",
      "current_public_safe_latest": false,
      "cvss_score": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.06052,
      "epss_score": 0.00164,
      "first_observed_at": "2026-08-08T04:31:15.594937+00:00",
      "id": "CVE-2026-14561",
      "impact_tags": [
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-08T04:31:15.594937+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Authora : Easy login with mobile number WordPress plugin before 1.7.7 does not keep its one-time login code confidential, returning the code and a valid verification token in the response of an unauthenticated action, allowing unauthenticated attackers to...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260808T043750Z/items/CVE-2026-14561.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes remote exposure · authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Authora : Easy login with mobile number WordPress plugin before 1.7.7 does not keep its one-time login code confidential, returning the code and a valid verification token in the response of an unauthenticated action, allowing unauthenticated attackers to...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14561/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14568/",
      "current_public_safe_latest": false,
      "cvss_score": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.10411,
      "epss_score": 0.00203,
      "first_observed_at": "2026-08-03T06:40:38.700520+00:00",
      "id": "CVE-2026-14568",
      "impact_tags": [
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-03T06:40:38.700520+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The User Frontend: AI Powered Frontend Post Submission, User Directory, User Profile, Membership & User Registration WordPress plugin before 4.3.8 does not correctly verify ownership before deleting an attachment, allowing unauthenticated attackers to...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260803T064356Z/items/CVE-2026-14568.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes remote exposure · authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The User Frontend: AI Powered Frontend Post Submission, User Directory, User Profile, Membership & User Registration WordPress plugin before 4.3.8 does not correctly verify ownership before deleting an attachment, allowing unauthenticated attackers to...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14568/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14570/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.39817,
      "epss_score": 0.00508,
      "first_observed_at": "2026-07-11T22:10:08.567004+00:00",
      "id": "CVE-2026-14570",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-11T22:10:08.567004+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Crypt::DSA versions before 1.22 for Perl draw the DSA signing nonce and private key from a biased random generator, leading to private-key recovery. NVD: \"Crypt::DSA::Util::makerandom forces the high bit of every value it returns to obtain an exactly N-bit integer for prime search. NVD: The signing nonce and the private key are drawn from makerandom.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260711T221257Z/items/CVE-2026-14570.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Crypt::DSA versions before 1.22 for Perl draw the DSA signing nonce and private key from a biased random generator, leading to private-key recovery. NVD: \"Crypt::DSA::Util::makerandom forces the high bit of every value it returns to obtain an exactly N-bit integer for prime search. NVD: The signing nonce and the private key are drawn from makerandom.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14570/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "eclipse / theia",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14574/",
      "current_public_safe_latest": true,
      "cvss_score": 5.7,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.20449,
      "epss_score": 0.00282,
      "first_observed_at": "2026-08-12T10:29:37.194110+00:00",
      "id": "CVE-2026-14574",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-12T10:29:37.194110+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-14574.json",
      "product": "theia",
      "public_safe_summary": "NVD: In Eclipse Theia versions 0.7.0 and up until including 1.73.1, the PreferenceUtils.merge function in @theia/core recursively merges preference values without rejecting prototype-related keys (__proto__, constructor, prototype). NVD: Because this function is invoked by PreferenceServiceImpl.doResolve for every preference resolution across scopes (default, user, workspace, folder), a crafted preference value in a workspace settings file (.theia/settings.json or .vscode/settings.json) can... OSV: In Eclipse Theia versions 0.7.0 and up until including 1.73.1, the PreferenceUtils.merge function in @theia/core recursively merges preference values without rejecting prototype-related keys (__proto__, constructor, prototype).",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260812T103932Z/items/CVE-2026-14574.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: eclipse / theia",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: In Eclipse Theia versions 0.7.0 and up until including 1.73.1, the PreferenceUtils.merge function in @theia/core recursively merges preference values without rejecting prototype-related keys (__proto__, constructor, prototype). NVD: Because this function is invoked by PreferenceServiceImpl.doResolve for every preference resolution across scopes (default, user, workspace, folder), a crafted preference value in a workspace settings file (.theia/settings.json or .vscode/settings.json) can... OSV: In Eclipse Theia versions 0.7.0 and up until including 1.73.1, the PreferenceUtils.merge function in @theia/core recursively merges preference values without rejecting prototype-related keys (__proto__, constructor, prototype).",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14574/timeline.json",
      "vendor": "eclipse"
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14603/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.15219,
      "epss_score": 0.0024,
      "first_observed_at": "2026-07-31T06:26:41.124454+00:00",
      "id": "CVE-2026-14603",
      "impact_tags": [
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-31T06:26:41.124454+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The WowOptin: Next-Gen Popup Maker WordPress plugin before 1.4.38 does not have proper authorization on a REST endpoint, allowing unauthenticated users to disable all of the site's opt-in forms and insert new template-based opt-in rows into the database.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260731T063057Z/items/CVE-2026-14603.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes authenticated boundary. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The WowOptin: Next-Gen Popup Maker WordPress plugin before 1.4.38 does not have proper authorization on a REST endpoint, allowing unauthenticated users to disable all of the site's opt-in forms and insert new template-based opt-in rows into the database.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14603/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14618/",
      "current_public_safe_latest": false,
      "cvss_score": 2.1,
      "cvss_severity": "LOW",
      "epss_percentile": 0.23515,
      "epss_score": 0.00316,
      "first_observed_at": "2026-07-10T22:27:53.208509+00:00",
      "id": "CVE-2026-14618",
      "impact_tags": [
        "service availability review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-11T05:56:01.167453+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A vulnerability was detected in Open5GS up to 2.7.7. NVD: Affected by this vulnerability is the function amf_nnrf_handle_nf_discover of the file src/amf/nnrf-handler.c of the component AMF. NVD: The manipulation results in denial of service.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260711T055749Z/items/CVE-2026-14618.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 3,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes service availability risk. Possible impact: The affected service may become unavailable or unreliable.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability was detected in Open5GS up to 2.7.7. NVD: Affected by this vulnerability is the function amf_nnrf_handle_nf_discover of the file src/amf/nnrf-handler.c of the component AMF. NVD: The manipulation results in denial of service.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14618/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14619/",
      "current_public_safe_latest": false,
      "cvss_score": 2.1,
      "cvss_severity": "LOW",
      "epss_percentile": 0.09988,
      "epss_score": 0.002,
      "first_observed_at": "2026-07-11T05:56:01.167453+00:00",
      "id": "CVE-2026-14619",
      "impact_tags": [
        "SQL injection risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-11T05:56:01.167453+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A flaw has been found in itsourcecode Hospital Management System 1.0. NVD: Affected by this issue is some unknown functionality of the file /medicine.php. NVD: This manipulation of the argument editid causes sql injection.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260711T055749Z/items/CVE-2026-14619.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes SQL injection risk. Possible impact: An attacker may be able to read or change database-backed application data.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A flaw has been found in itsourcecode Hospital Management System 1.0. NVD: Affected by this issue is some unknown functionality of the file /medicine.php. NVD: This manipulation of the argument editid causes sql injection.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14619/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14621/",
      "current_public_safe_latest": false,
      "cvss_score": 1.3,
      "cvss_severity": "LOW",
      "epss_percentile": 0.21732,
      "epss_score": 0.00299,
      "first_observed_at": "2026-07-11T05:56:01.167453+00:00",
      "id": "CVE-2026-14621",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-11T05:56:01.167453+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A vulnerability has been found in FederatedAI FATE up to 2.2.0. NVD: This affects the function QueuePushReqStreamObserver.initEggroll of the file java/osx/osx-broker/src/main/java/org/fedai/osx/broker/grpc/QueuePushReqStreamObserver.java of the component OSX Broker. NVD: Such manipulation of the argument rollSiteSessionId/dstRole/dstPartyId leads to exposure of data element to wrong session.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260711T055749Z/items/CVE-2026-14621.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability has been found in FederatedAI FATE up to 2.2.0. NVD: This affects the function QueuePushReqStreamObserver.initEggroll of the file java/osx/osx-broker/src/main/java/org/fedai/osx/broker/grpc/QueuePushReqStreamObserver.java of the component OSX Broker. NVD: Such manipulation of the argument rollSiteSessionId/dstRole/dstPartyId leads to exposure of data element to wrong session.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14621/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14622/",
      "current_public_safe_latest": false,
      "cvss_score": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.40314,
      "epss_score": 0.00517,
      "first_observed_at": "2026-07-11T05:56:01.167453+00:00",
      "id": "CVE-2026-14622",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-11T05:56:01.167453+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A vulnerability was found in jairiidriss restaurant-website-php-mysql up to 521428b5b612449df0cf4a5d15ee40cba67f3d35. NVD: This vulnerability affects unknown code of the file /admin/ajax_files of the component AJAX Endpoint. NVD: Performing a manipulation results in missing authentication.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260711T055749Z/items/CVE-2026-14622.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability was found in jairiidriss restaurant-website-php-mysql up to 521428b5b612449df0cf4a5d15ee40cba67f3d35. NVD: This vulnerability affects unknown code of the file /admin/ajax_files of the component AJAX Endpoint. NVD: Performing a manipulation results in missing authentication.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14622/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14623/",
      "current_public_safe_latest": false,
      "cvss_score": 2.1,
      "cvss_severity": "LOW",
      "epss_percentile": 0.40596,
      "epss_score": 0.00522,
      "first_observed_at": "2026-07-11T05:56:01.167453+00:00",
      "id": "CVE-2026-14623",
      "impact_tags": [
        "service availability review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-11T05:56:01.167453+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A vulnerability was determined in omec-project amf up to 2.1.1. NVD: This issue affects the function RRCInactiveTransitionReport of the component NGAP Message Handler. NVD: Executing a manipulation can lead to denial of service.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260711T055749Z/items/CVE-2026-14623.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes service availability risk. Possible impact: The affected service may become unavailable or unreliable.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability was determined in omec-project amf up to 2.1.1. NVD: This issue affects the function RRCInactiveTransitionReport of the component NGAP Message Handler. NVD: Executing a manipulation can lead to denial of service.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14623/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14624/",
      "current_public_safe_latest": false,
      "cvss_score": 2.1,
      "cvss_severity": "LOW",
      "epss_percentile": 0.23566,
      "epss_score": 0.00317,
      "first_observed_at": "2026-07-11T05:56:01.167453+00:00",
      "id": "CVE-2026-14624",
      "impact_tags": [
        "service availability review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-11T10:36:25.311321+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A vulnerability was identified in omec-project amf up to 2.0.2/2.1.1. NVD: Impacted is an unknown function of the file /go/src/amf/ngap/handler.go of the component NGSetupRequest Handler. NVD: The manipulation leads to denial of service.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260711T103806Z/items/CVE-2026-14624.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes service availability risk. Possible impact: The affected service may become unavailable or unreliable.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability was identified in omec-project amf up to 2.0.2/2.1.1. NVD: Impacted is an unknown function of the file /go/src/amf/ngap/handler.go of the component NGSetupRequest Handler. NVD: The manipulation leads to denial of service.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14624/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14625/",
      "current_public_safe_latest": false,
      "cvss_score": 2.1,
      "cvss_severity": "LOW",
      "epss_percentile": 0.13019,
      "epss_score": 0.00224,
      "first_observed_at": "2026-07-11T05:56:01.167453+00:00",
      "id": "CVE-2026-14625",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-11T10:36:25.311321+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A security flaw has been discovered in NousResearch hermes-agent up to 0.15.2. NVD: The affected element is the function shell.exec of the file tui_gateway/server.py. NVD: The manipulation results in protection mechanism failure.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260711T103806Z/items/CVE-2026-14625.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A security flaw has been discovered in NousResearch hermes-agent up to 0.15.2. NVD: The affected element is the function shell.exec of the file tui_gateway/server.py. NVD: The manipulation results in protection mechanism failure.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14625/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14626/",
      "current_public_safe_latest": false,
      "cvss_score": 2.1,
      "cvss_severity": "LOW",
      "epss_percentile": 0.19545,
      "epss_score": 0.00277,
      "first_observed_at": "2026-07-11T05:56:01.167453+00:00",
      "id": "CVE-2026-14626",
      "impact_tags": [
        "service availability review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-11T10:36:25.311321+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A weakness has been identified in NousResearch hermes-agent up to 2026.4.30. NVD: The impacted element is the function AIAgent.run_conversation of the file run_agent.py of the component HTTP API. NVD: This manipulation of the argument todos causes denial of service.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260711T103806Z/items/CVE-2026-14626.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes service availability risk. Possible impact: The affected service may become unavailable or unreliable.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A weakness has been identified in NousResearch hermes-agent up to 2026.4.30. NVD: The impacted element is the function AIAgent.run_conversation of the file run_agent.py of the component HTTP API. NVD: This manipulation of the argument todos causes denial of service.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14626/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14627/",
      "current_public_safe_latest": false,
      "cvss_score": 2.9,
      "cvss_severity": "LOW",
      "epss_percentile": 0.28927,
      "epss_score": 0.00369,
      "first_observed_at": "2026-07-11T05:56:01.167453+00:00",
      "id": "CVE-2026-14627",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-11T10:36:25.311321+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A security vulnerability has been detected in NousResearch hermes-agent up to 0.15.2. NVD: This affects the function DiscordAdapter._is_allowed_user of the file gateway/platforms/discord.py of the component Discord Platform Integration. NVD: Such manipulation leads to improper authentication.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260711T103806Z/items/CVE-2026-14627.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A security vulnerability has been detected in NousResearch hermes-agent up to 0.15.2. NVD: This affects the function DiscordAdapter._is_allowed_user of the file gateway/platforms/discord.py of the component Discord Platform Integration. NVD: Such manipulation leads to improper authentication.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14627/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14628/",
      "current_public_safe_latest": false,
      "cvss_score": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.42184,
      "epss_score": 0.00551,
      "first_observed_at": "2026-07-11T05:56:01.167453+00:00",
      "id": "CVE-2026-14628",
      "impact_tags": [
        "path traversal review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-11T10:36:25.311321+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A vulnerability was detected in NousResearch hermes-agent up to 2026.5.16. NVD: This impacts the function extract_media of the file gateway/platforms/base.py of the component Live Webhook Endpoint. NVD: Performing a manipulation results in path traversal.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260711T103806Z/items/CVE-2026-14628.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes path traversal review. Possible impact: An attacker may be able to reach files outside the intended application path.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability was detected in NousResearch hermes-agent up to 2026.5.16. NVD: This impacts the function extract_media of the file gateway/platforms/base.py of the component Live Webhook Endpoint. NVD: Performing a manipulation results in path traversal.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14628/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14629/",
      "current_public_safe_latest": false,
      "cvss_score": 2.1,
      "cvss_severity": "LOW",
      "epss_percentile": 0.22741,
      "epss_score": 0.00309,
      "first_observed_at": "2026-07-11T10:36:25.311321+00:00",
      "id": "CVE-2026-14629",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-11T10:36:25.311321+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A flaw has been found in RT-Thread up to 5.2.2. NVD: Affected is the function read/write/sys_ioctl of the file components/lwp/lwp_syscall.c of the component Parameter Handler. NVD: Executing a manipulation can lead to divide by zero.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260711T103806Z/items/CVE-2026-14629.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A flaw has been found in RT-Thread up to 5.2.2. NVD: Affected is the function read/write/sys_ioctl of the file components/lwp/lwp_syscall.c of the component Parameter Handler. NVD: Executing a manipulation can lead to divide by zero.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14629/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14630/",
      "current_public_safe_latest": false,
      "cvss_score": 1.3,
      "cvss_severity": "LOW",
      "epss_percentile": 0.05532,
      "epss_score": 0.0016,
      "first_observed_at": "2026-07-11T10:36:25.311321+00:00",
      "id": "CVE-2026-14630",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-11T10:36:25.311321+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A vulnerability has been found in ForceInjection AI-fundermentals 2.0/3.0. NVD: Affected by this vulnerability is the function get_conversation_history of the file 08_agentic_system/memory/langchain/code/smart_customer_service.py of the component Memory Recall Handler. NVD: The manipulation leads to use of weak hash.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260711T103806Z/items/CVE-2026-14630.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability has been found in ForceInjection AI-fundermentals 2.0/3.0. NVD: Affected by this vulnerability is the function get_conversation_history of the file 08_agentic_system/memory/langchain/code/smart_customer_service.py of the component Memory Recall Handler. NVD: The manipulation leads to use of weak hash.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14630/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14632/",
      "current_public_safe_latest": false,
      "cvss_score": 2.1,
      "cvss_severity": "LOW",
      "epss_percentile": 0.19096,
      "epss_score": 0.00273,
      "first_observed_at": "2026-07-11T10:36:25.311321+00:00",
      "id": "CVE-2026-14632",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-11T16:12:59.014043+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A vulnerability was found in kirilkirkov Ecommerce-CodeIgniter-Bootstrap up to 95dfa8cebbb87ab46ae450643a07241274a74dce. NVD: Affected by this issue is the function setReferrer of the file application/core/MY_Controller.php of the component Trusted Backend Interface. NVD: The manipulation of the argument href results in open redirect.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260711T161447Z/items/CVE-2026-14632.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability was found in kirilkirkov Ecommerce-CodeIgniter-Bootstrap up to 95dfa8cebbb87ab46ae450643a07241274a74dce. NVD: Affected by this issue is the function setReferrer of the file application/core/MY_Controller.php of the component Trusted Backend Interface. NVD: The manipulation of the argument href results in open redirect.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14632/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14633/",
      "current_public_safe_latest": false,
      "cvss_score": 2.1,
      "cvss_severity": "LOW",
      "epss_percentile": 0.20629,
      "epss_score": 0.00288,
      "first_observed_at": "2026-07-11T10:36:25.311321+00:00",
      "id": "CVE-2026-14633",
      "impact_tags": [
        "XSS risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-11T16:12:59.014043+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A vulnerability was determined in kirilkirkov Ecommerce-CodeIgniter-Bootstrap up to 49b20f53de2b7ec34e920b11c863f1491d911a04. NVD: This affects an unknown part of the file /index.php/api/product/set of the component Hidden REST API Endpoint. NVD: This manipulation of the argument title/description causes cross site scripting.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260711T161447Z/items/CVE-2026-14633.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes XSS risk. Possible impact: This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability was determined in kirilkirkov Ecommerce-CodeIgniter-Bootstrap up to 49b20f53de2b7ec34e920b11c863f1491d911a04. NVD: This affects an unknown part of the file /index.php/api/product/set of the component Hidden REST API Endpoint. NVD: This manipulation of the argument title/description causes cross site scripting.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14633/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14634/",
      "current_public_safe_latest": false,
      "cvss_score": 2.1,
      "cvss_severity": "LOW",
      "epss_percentile": 0.20629,
      "epss_score": 0.00288,
      "first_observed_at": "2026-07-11T10:36:25.311321+00:00",
      "id": "CVE-2026-14634",
      "impact_tags": [
        "XSS risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-11T16:12:59.014043+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A vulnerability was identified in kirilkirkov Ecommerce-CodeIgniter-Bootstrap up to 213babdbaa949e94557246414db0130e01394517. NVD: This vulnerability affects the function checkForPostRequests of the file application/core/MY_Controller.php of the component Subscribed Emails Admin Page. NVD: Such manipulation of the argument User-Agent leads to cross site scripting.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260711T161447Z/items/CVE-2026-14634.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes XSS risk. Possible impact: This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability was identified in kirilkirkov Ecommerce-CodeIgniter-Bootstrap up to 213babdbaa949e94557246414db0130e01394517. NVD: This vulnerability affects the function checkForPostRequests of the file application/core/MY_Controller.php of the component Subscribed Emails Admin Page. NVD: Such manipulation of the argument User-Agent leads to cross site scripting.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14634/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14635/",
      "current_public_safe_latest": false,
      "cvss_score": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.35287,
      "epss_score": 0.00437,
      "first_observed_at": "2026-07-11T10:36:25.311321+00:00",
      "id": "CVE-2026-14635",
      "impact_tags": [
        "path traversal review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-11T16:12:59.014043+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A security flaw has been discovered in kirilkirkov Ecommerce-CodeIgniter-Bootstrap up to 222ff31c06687b1c6d0e1ab63953f82c3674c52b. NVD: This issue affects some unknown processing of the file application/modules/vendor/controllers/AddProduct.php of the component Vendor Multi-Image Endpoint. NVD: Performing a manipulation of the argument folder results in path traversal.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260711T161447Z/items/CVE-2026-14635.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes path traversal review. Possible impact: An attacker may be able to reach files outside the intended application path.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A security flaw has been discovered in kirilkirkov Ecommerce-CodeIgniter-Bootstrap up to 222ff31c06687b1c6d0e1ab63953f82c3674c52b. NVD: This issue affects some unknown processing of the file application/modules/vendor/controllers/AddProduct.php of the component Vendor Multi-Image Endpoint. NVD: Performing a manipulation of the argument folder results in path traversal.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14635/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14636/",
      "current_public_safe_latest": false,
      "cvss_score": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.24297,
      "epss_score": 0.00323,
      "first_observed_at": "2026-07-11T16:12:59.014043+00:00",
      "id": "CVE-2026-14636",
      "impact_tags": [
        "path traversal review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-11T16:12:59.014043+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A weakness has been identified in kirilkirkov Ecommerce-CodeIgniter-Bootstrap up to 23105f25dadf57b4314fc015a63a7c6e910c89df. NVD: Impacted is the function do_upload_others_images of the file application/modules/vendor/controllers/AddProduct.php of the component Vendor Image Manager. NVD: Executing a manipulation of the argument folder can lead to path traversal.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260711T161447Z/items/CVE-2026-14636.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes path traversal review. Possible impact: An attacker may be able to reach files outside the intended application path.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A weakness has been identified in kirilkirkov Ecommerce-CodeIgniter-Bootstrap up to 23105f25dadf57b4314fc015a63a7c6e910c89df. NVD: Impacted is the function do_upload_others_images of the file application/modules/vendor/controllers/AddProduct.php of the component Vendor Image Manager. NVD: Executing a manipulation of the argument folder can lead to path traversal.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14636/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14637/",
      "current_public_safe_latest": false,
      "cvss_score": 7.8,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.44493,
      "epss_score": 0.00598,
      "first_observed_at": "2026-07-11T16:12:59.014043+00:00",
      "id": "CVE-2026-14637",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-11T16:12:59.014043+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A security vulnerability has been detected in kirilkirkov Ecommerce-CodeIgniter-Bootstrap up to 13fd582aaf49aeab7438acc0fc3eb973a1f5e6a7. NVD: The affected element is the function getCartItems in the library application/libraries/ShoppingCart.php. NVD: The manipulation of the argument shopping_cart leads to deserialization.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260711T161447Z/items/CVE-2026-14637.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A security vulnerability has been detected in kirilkirkov Ecommerce-CodeIgniter-Bootstrap up to 13fd582aaf49aeab7438acc0fc3eb973a1f5e6a7. NVD: The affected element is the function getCartItems in the library application/libraries/ShoppingCart.php. NVD: The manipulation of the argument shopping_cart leads to deserialization.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14637/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14638/",
      "current_public_safe_latest": false,
      "cvss_score": 2.1,
      "cvss_severity": "LOW",
      "epss_percentile": 0.09986,
      "epss_score": 0.002,
      "first_observed_at": "2026-07-11T16:12:59.014043+00:00",
      "id": "CVE-2026-14638",
      "impact_tags": [
        "SQL injection risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-11T16:12:59.014043+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A flaw has been found in itsourcecode Hospital Management System 1.0. NVD: This affects an unknown function of the file /patient.php. NVD: This manipulation of the argument editid causes sql injection.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260711T161447Z/items/CVE-2026-14638.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes SQL injection risk. Possible impact: An attacker may be able to read or change database-backed application data.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A flaw has been found in itsourcecode Hospital Management System 1.0. NVD: This affects an unknown function of the file /patient.php. NVD: This manipulation of the argument editid causes sql injection.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14638/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14639/",
      "current_public_safe_latest": false,
      "cvss_score": 2.1,
      "cvss_severity": "LOW",
      "epss_percentile": 0.09983,
      "epss_score": 0.002,
      "first_observed_at": "2026-07-11T16:12:59.014043+00:00",
      "id": "CVE-2026-14639",
      "impact_tags": [
        "SQL injection risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-11T16:12:59.014043+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A vulnerability has been found in CodeAstro Ecommerce Website 1.0. NVD: This impacts an unknown function of the file /ecommerce-website-php/customer/my_account.php?edit_account. NVD: Such manipulation of the argument c_name leads to sql injection.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260711T161447Z/items/CVE-2026-14639.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes SQL injection risk. Possible impact: An attacker may be able to read or change database-backed application data.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability has been found in CodeAstro Ecommerce Website 1.0. NVD: This impacts an unknown function of the file /ecommerce-website-php/customer/my_account.php?edit_account. NVD: Such manipulation of the argument c_name leads to sql injection.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14639/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14640/",
      "current_public_safe_latest": false,
      "cvss_score": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.17751,
      "epss_score": 0.00263,
      "first_observed_at": "2026-07-11T16:12:59.014043+00:00",
      "id": "CVE-2026-14640",
      "impact_tags": [
        "SQL injection risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-11T16:12:59.014043+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A vulnerability was found in CodeAstro Apartment Visitor Management System 1.0. NVD: Affected is an unknown function of the file /index.php of the component Login. NVD: Performing a manipulation of the argument Username results in sql injection.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260711T161447Z/items/CVE-2026-14640.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes SQL injection risk. Possible impact: An attacker may be able to read or change database-backed application data.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability was found in CodeAstro Apartment Visitor Management System 1.0. NVD: Affected is an unknown function of the file /index.php of the component Login. NVD: Performing a manipulation of the argument Username results in sql injection.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14640/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14641/",
      "current_public_safe_latest": false,
      "cvss_score": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.33617,
      "epss_score": 0.00416,
      "first_observed_at": "2026-07-11T16:12:59.014043+00:00",
      "id": "CVE-2026-14641",
      "impact_tags": [
        "SQL injection risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-11T16:12:59.014043+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A vulnerability was determined in SourceCodester Class and Exam Timetabling System 1.0. NVD: Affected by this vulnerability is an unknown functionality of the file /edit_course.php. NVD: Executing a manipulation of the argument ID can lead to sql injection.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260711T161447Z/items/CVE-2026-14641.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes SQL injection risk. Possible impact: An attacker may be able to read or change database-backed application data.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability was determined in SourceCodester Class and Exam Timetabling System 1.0. NVD: Affected by this vulnerability is an unknown functionality of the file /edit_course.php. NVD: Executing a manipulation of the argument ID can lead to sql injection.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14641/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14642/",
      "current_public_safe_latest": false,
      "cvss_score": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.33257,
      "epss_score": 0.00412,
      "first_observed_at": "2026-07-11T16:12:59.014043+00:00",
      "id": "CVE-2026-14642",
      "impact_tags": [
        "SQL injection risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-11T16:12:59.014043+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A vulnerability was identified in SourceCodester Class and Exam Timetabling System 1.0. NVD: Affected by this issue is some unknown functionality of the file /edit_class2.php. NVD: The manipulation of the argument ID leads to sql injection.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260711T161447Z/items/CVE-2026-14642.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes SQL injection risk. Possible impact: An attacker may be able to read or change database-backed application data.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability was identified in SourceCodester Class and Exam Timetabling System 1.0. NVD: Affected by this issue is some unknown functionality of the file /edit_class2.php. NVD: The manipulation of the argument ID leads to sql injection.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14642/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14645/",
      "current_public_safe_latest": false,
      "cvss_score": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.32081,
      "epss_score": 0.00397,
      "first_observed_at": "2026-07-21T16:48:32.557544+00:00",
      "id": "CVE-2026-14645",
      "impact_tags": [
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-21T16:48:32.557544+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Nexus Repository 3 does not validate the destination of the \"Webhook: Global\" capability's configured URL before making an outbound HTTP request, allowing a user holding the Capability Administration permission to cause the server to send requests to internal... NVD: This permission is granted by role assignment, independent of authentication status, so an unauthenticated user could also trigger this behavior if the anonymous role has been granted the permission.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260721T165442Z/items/CVE-2026-14645.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Nexus Repository 3 does not validate the destination of the \"Webhook: Global\" capability's configured URL before making an outbound HTTP request, allowing a user holding the Capability Administration permission to cause the server to send requests to internal... NVD: This permission is granted by role assignment, independent of authentication status, so an unauthenticated user could also trigger this behavior if the anonymous role has been granted the permission.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14645/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14646/",
      "current_public_safe_latest": false,
      "cvss_score": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.18157,
      "epss_score": 0.00265,
      "first_observed_at": "2026-07-21T16:48:32.557544+00:00",
      "id": "CVE-2026-14646",
      "impact_tags": [
        "information exposure review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-21T16:48:32.557544+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Nexus Repository 3 did not apply its existing Server-Side Request Forgery (SSRF) protections to HTTP redirect targets returned by proxy repository upstream servers. NVD: Any user with read access to a proxy repository backed by an attacker-controlled or compromised upstream server — including an anonymous user, if anonymous access is enabled — could receive a response from an internal network address or cloud metadata...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260721T165442Z/items/CVE-2026-14646.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes information exposure review. Possible impact: An attacker may be able to access information that should not be exposed.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Nexus Repository 3 did not apply its existing Server-Side Request Forgery (SSRF) protections to HTTP redirect targets returned by proxy repository upstream servers. NVD: Any user with read access to a proxy repository backed by an attacker-controlled or compromised upstream server — including an anonymous user, if anonymous access is enabled — could receive a response from an internal network address or cloud metadata...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14646/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14647/",
      "current_public_safe_latest": false,
      "cvss_score": 2.1,
      "cvss_severity": "LOW",
      "epss_percentile": 0.16583,
      "epss_score": 0.00253,
      "first_observed_at": "2026-07-11T16:12:59.014043+00:00",
      "id": "CVE-2026-14647",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-11T16:12:59.014043+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A weakness has been identified in onnx up to 1.21.x. NVD: This vulnerability affects the function convPoolShapeInference_opset19 of the file onnx/defs/nn/old.cc of the component onnxruntime. NVD: This manipulation causes out-of-bounds read.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260711T161447Z/items/CVE-2026-14647.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A weakness has been identified in onnx up to 1.21.x. NVD: This vulnerability affects the function convPoolShapeInference_opset19 of the file onnx/defs/nn/old.cc of the component onnxruntime. NVD: This manipulation causes out-of-bounds read.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14647/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14648/",
      "current_public_safe_latest": false,
      "cvss_score": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.2686,
      "epss_score": 0.00347,
      "first_observed_at": "2026-07-11T16:12:59.014043+00:00",
      "id": "CVE-2026-14648",
      "impact_tags": [
        "SQL injection risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-11T16:12:59.014043+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A security vulnerability has been detected in code-projects Online Voting System up to 0.x/1.0. NVD: This issue affects the function test_input of the file /authentication.php of the component Login. NVD: Such manipulation of the argument adminUserName/adminPassword leads to sql injection.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260711T161447Z/items/CVE-2026-14648.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes SQL injection risk. Possible impact: An attacker may be able to read or change database-backed application data.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A security vulnerability has been detected in code-projects Online Voting System up to 0.x/1.0. NVD: This issue affects the function test_input of the file /authentication.php of the component Login. NVD: Such manipulation of the argument adminUserName/adminPassword leads to sql injection.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14648/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14649/",
      "current_public_safe_latest": false,
      "cvss_score": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.18548,
      "epss_score": 0.00269,
      "first_observed_at": "2026-07-11T16:12:59.014043+00:00",
      "id": "CVE-2026-14649",
      "impact_tags": [
        "SQL injection risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-11T16:12:59.014043+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A vulnerability was detected in code-projects Online Voting System 1.0. NVD: Impacted is the function test_input of the file /saveVote.php. NVD: Performing a manipulation of the argument voterName/voterEmail/voterID/selectedCandidate results in sql injection.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260711T161447Z/items/CVE-2026-14649.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes SQL injection risk. Possible impact: An attacker may be able to read or change database-backed application data.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability was detected in code-projects Online Voting System 1.0. NVD: Impacted is the function test_input of the file /saveVote.php. NVD: Performing a manipulation of the argument voterName/voterEmail/voterID/selectedCandidate results in sql injection.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14649/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14650/",
      "current_public_safe_latest": false,
      "cvss_score": 1.9,
      "cvss_severity": "LOW",
      "epss_percentile": 0.01895,
      "epss_score": 0.00116,
      "first_observed_at": "2026-07-11T16:12:59.014043+00:00",
      "id": "CVE-2026-14650",
      "impact_tags": [
        "service availability review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-11T16:12:59.014043+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A flaw has been found in connorskees grass up to 0.13.4. NVD: The affected element is the function grass_compiler::raw_to_parse_error of the component UTF-8 Character Handler. NVD: Executing a manipulation can lead to denial of service.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260711T161447Z/items/CVE-2026-14650.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes service availability risk. Possible impact: The affected service may become unavailable or unreliable.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A flaw has been found in connorskees grass up to 0.13.4. NVD: The affected element is the function grass_compiler::raw_to_parse_error of the component UTF-8 Character Handler. NVD: Executing a manipulation can lead to denial of service.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14650/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14651/",
      "current_public_safe_latest": false,
      "cvss_score": 1.9,
      "cvss_severity": "LOW",
      "epss_percentile": 0.0183,
      "epss_score": 0.00115,
      "first_observed_at": "2026-07-11T16:12:59.014043+00:00",
      "id": "CVE-2026-14651",
      "impact_tags": [
        "service availability review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-11T16:12:59.014043+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A vulnerability has been found in connorskees grass up to 0.13.4. NVD: The impacted element is the function grass_compiler::selector::extend/grass_compiler::evaluate::visitor. NVD: The manipulation leads to denial of service.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260711T161447Z/items/CVE-2026-14651.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes service availability risk. Possible impact: The affected service may become unavailable or unreliable.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability has been found in connorskees grass up to 0.13.4. NVD: The impacted element is the function grass_compiler::selector::extend/grass_compiler::evaluate::visitor. NVD: The manipulation leads to denial of service.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14651/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14652/",
      "current_public_safe_latest": false,
      "cvss_score": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.33258,
      "epss_score": 0.00412,
      "first_observed_at": "2026-07-11T16:12:59.014043+00:00",
      "id": "CVE-2026-14652",
      "impact_tags": [
        "SQL injection risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-11T16:12:59.014043+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A vulnerability was found in SourceCodester Simple and Nice Shopping Cart Script 1.0. NVD: This affects an unknown function of the file /admin/login.php of the component Admin Login. NVD: The manipulation of the argument Username results in sql injection.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260711T161447Z/items/CVE-2026-14652.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes SQL injection risk. Possible impact: An attacker may be able to read or change database-backed application data.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability was found in SourceCodester Simple and Nice Shopping Cart Script 1.0. NVD: This affects an unknown function of the file /admin/login.php of the component Admin Login. NVD: The manipulation of the argument Username results in sql injection.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14652/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14655/",
      "current_public_safe_latest": false,
      "cvss_score": 1.9,
      "cvss_severity": "LOW",
      "epss_percentile": 0.26753,
      "epss_score": 0.00347,
      "first_observed_at": "2026-07-11T22:10:08.567004+00:00",
      "id": "CVE-2026-14655",
      "impact_tags": [
        "XSS risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-11T22:10:08.567004+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A weakness has been identified in code-projects Assessment Management 1.0. NVD: Affected by this issue is some unknown functionality of the file admin/view-users.php. NVD: Executing a manipulation of the argument User can lead to cross site scripting.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260711T221257Z/items/CVE-2026-14655.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes XSS risk. Possible impact: This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A weakness has been identified in code-projects Assessment Management 1.0. NVD: Affected by this issue is some unknown functionality of the file admin/view-users.php. NVD: Executing a manipulation of the argument User can lead to cross site scripting.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14655/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14656/",
      "current_public_safe_latest": false,
      "cvss_score": 2.1,
      "cvss_severity": "LOW",
      "epss_percentile": 0.3568,
      "epss_score": 0.00443,
      "first_observed_at": "2026-07-11T22:10:08.567004+00:00",
      "id": "CVE-2026-14656",
      "impact_tags": [
        "XSS risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-11T22:10:08.567004+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A security vulnerability has been detected in code-projects Assessment Management 1.0. NVD: This affects an unknown part of the file /admin/remove-user.php. NVD: The manipulation of the argument ID leads to cross site scripting.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260711T221257Z/items/CVE-2026-14656.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes XSS risk. Possible impact: This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A security vulnerability has been detected in code-projects Assessment Management 1.0. NVD: This affects an unknown part of the file /admin/remove-user.php. NVD: The manipulation of the argument ID leads to cross site scripting.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14656/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14657/",
      "current_public_safe_latest": false,
      "cvss_score": 2.1,
      "cvss_severity": "LOW",
      "epss_percentile": 0.23831,
      "epss_score": 0.00319,
      "first_observed_at": "2026-07-11T22:10:08.567004+00:00",
      "id": "CVE-2026-14657",
      "impact_tags": [
        "SQL injection risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-11T22:10:08.567004+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A flaw has been found in code-projects Assessment Management 1.0. NVD: This issue affects some unknown processing of the file /lecturer/marking-scheme.php of the component Database Query Handler. NVD: This manipulation of the argument squestions[] causes sql injection.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260711T221257Z/items/CVE-2026-14657.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes SQL injection risk. Possible impact: An attacker may be able to read or change database-backed application data.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A flaw has been found in code-projects Assessment Management 1.0. NVD: This issue affects some unknown processing of the file /lecturer/marking-scheme.php of the component Database Query Handler. NVD: This manipulation of the argument squestions[] causes sql injection.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14657/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14658/",
      "current_public_safe_latest": false,
      "cvss_score": 2.1,
      "cvss_severity": "LOW",
      "epss_percentile": 0.23831,
      "epss_score": 0.00319,
      "first_observed_at": "2026-07-11T22:10:08.567004+00:00",
      "id": "CVE-2026-14658",
      "impact_tags": [
        "SQL injection risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-11T22:10:08.567004+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A vulnerability was detected in code-projects Assessment Management 1.0. NVD: This vulnerability affects unknown code of the file /lecturer/marking-scheme.php. NVD: The manipulation of the argument smarksrange[] results in sql injection.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260711T221257Z/items/CVE-2026-14658.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes SQL injection risk. Possible impact: An attacker may be able to read or change database-backed application data.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability was detected in code-projects Assessment Management 1.0. NVD: This vulnerability affects unknown code of the file /lecturer/marking-scheme.php. NVD: The manipulation of the argument smarksrange[] results in sql injection.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14658/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14659/",
      "current_public_safe_latest": false,
      "cvss_score": 2.1,
      "cvss_severity": "LOW",
      "epss_percentile": 0.2383,
      "epss_score": 0.00319,
      "first_observed_at": "2026-07-11T22:10:08.567004+00:00",
      "id": "CVE-2026-14659",
      "impact_tags": [
        "SQL injection risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-11T22:10:08.567004+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A vulnerability has been found in itsourcecode Hospital Management System 1.0. NVD: Impacted is an unknown function of the file /patientappointment.php. NVD: Such manipulation of the argument patiente leads to sql injection.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260711T221257Z/items/CVE-2026-14659.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes SQL injection risk. Possible impact: An attacker may be able to read or change database-backed application data.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability has been found in itsourcecode Hospital Management System 1.0. NVD: Impacted is an unknown function of the file /patientappointment.php. NVD: Such manipulation of the argument patiente leads to sql injection.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14659/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14660/",
      "current_public_safe_latest": false,
      "cvss_score": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.33258,
      "epss_score": 0.00412,
      "first_observed_at": "2026-07-11T22:10:08.567004+00:00",
      "id": "CVE-2026-14660",
      "impact_tags": [
        "SQL injection risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-11T22:10:08.567004+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A vulnerability was found in code-projects Online Job Portal 1.0. NVD: The affected element is an unknown function of the file login.php. NVD: Performing a manipulation of the argument txtUser/txtPass results in sql injection.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260711T221257Z/items/CVE-2026-14660.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes SQL injection risk. Possible impact: An attacker may be able to read or change database-backed application data.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability was found in code-projects Online Job Portal 1.0. NVD: The affected element is an unknown function of the file login.php. NVD: Performing a manipulation of the argument txtUser/txtPass results in sql injection.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14660/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14683/",
      "current_public_safe_latest": false,
      "cvss_score": 1.9,
      "cvss_severity": "LOW",
      "epss_percentile": 0.01995,
      "epss_score": 0.00118,
      "first_observed_at": "2026-07-11T22:10:08.567004+00:00",
      "id": "CVE-2026-14683",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-11T22:10:08.567004+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A vulnerability was detected in HdrHistogram up to 2.2.2. NVD: Affected by this issue is the function org.HdrHistogram.AbstractHistogram.decodeFromCompressedByteBuffer of the file src/main/java/org/HdrHistogram/AbstractHistogram.java. NVD: The manipulation of the argument lengthOfCompressedContents results in uncontrolled memory allocation.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260711T221257Z/items/CVE-2026-14683.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability was detected in HdrHistogram up to 2.2.2. NVD: Affected by this issue is the function org.HdrHistogram.AbstractHistogram.decodeFromCompressedByteBuffer of the file src/main/java/org/HdrHistogram/AbstractHistogram.java. NVD: The manipulation of the argument lengthOfCompressedContents results in uncontrolled memory allocation.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14683/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14684/",
      "current_public_safe_latest": false,
      "cvss_score": 1.9,
      "cvss_severity": "LOW",
      "epss_percentile": 0.02153,
      "epss_score": 0.0012,
      "first_observed_at": "2026-07-11T22:10:08.567004+00:00",
      "id": "CVE-2026-14684",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-11T22:10:08.567004+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A flaw has been found in HdrHistogram up to 2.2.2. NVD: This affects the function org.HdrHistogram.AbstractHistogram.decodeFromByteBuffer of the file src/main/java/org/HdrHistogram/AbstractHistogram.java. NVD: This manipulation of the argument numberOfSignificantValueDigits causes uncontrolled memory allocation.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260711T221257Z/items/CVE-2026-14684.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A flaw has been found in HdrHistogram up to 2.2.2. NVD: This affects the function org.HdrHistogram.AbstractHistogram.decodeFromByteBuffer of the file src/main/java/org/HdrHistogram/AbstractHistogram.java. NVD: This manipulation of the argument numberOfSignificantValueDigits causes uncontrolled memory allocation.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14684/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14685/",
      "current_public_safe_latest": false,
      "cvss_score": 1.9,
      "cvss_severity": "LOW",
      "epss_percentile": 0.02004,
      "epss_score": 0.00118,
      "first_observed_at": "2026-07-11T22:10:08.567004+00:00",
      "id": "CVE-2026-14685",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-11T22:10:08.567004+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A vulnerability has been found in HdrHistogram up to 2.2.2. NVD: This vulnerability affects the function recordValueWithCount of the file src/main/java/org/HdrHistogram/AbstractHistogram.java of the component AbstractHistogram. NVD: Such manipulation of the argument Count leads to state issue.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260711T221257Z/items/CVE-2026-14685.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability has been found in HdrHistogram up to 2.2.2. NVD: This vulnerability affects the function recordValueWithCount of the file src/main/java/org/HdrHistogram/AbstractHistogram.java of the component AbstractHistogram. NVD: Such manipulation of the argument Count leads to state issue.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14685/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14686/",
      "current_public_safe_latest": false,
      "cvss_score": 1.9,
      "cvss_severity": "LOW",
      "epss_percentile": 0.15021,
      "epss_score": 0.0024,
      "first_observed_at": "2026-07-11T22:10:08.567004+00:00",
      "id": "CVE-2026-14686",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-11T22:10:08.567004+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A vulnerability was found in HdrHistogram up to 2.2.2. NVD: This issue affects the function org.HdrHistogram.DoubleHistogram.recordValue of the file src/main/java/org/HdrHistogram/DoubleHistogram.java of the component Range Check. NVD: Performing a manipulation results in incorrect comparison.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260711T221257Z/items/CVE-2026-14686.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability was found in HdrHistogram up to 2.2.2. NVD: This issue affects the function org.HdrHistogram.DoubleHistogram.recordValue of the file src/main/java/org/HdrHistogram/DoubleHistogram.java of the component Range Check. NVD: Performing a manipulation results in incorrect comparison.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14686/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14687/",
      "current_public_safe_latest": false,
      "cvss_score": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.25198,
      "epss_score": 0.00332,
      "first_observed_at": "2026-07-11T22:10:08.567004+00:00",
      "id": "CVE-2026-14687",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-11T22:10:08.567004+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A vulnerability was determined in 666ghj BettaFish up to 1.2.1. NVD: Impacted is the function _deduplicate_results of the file InsightEngine/agent.py of the component InsightEngine search-result Deduplication. NVD: Executing a manipulation can lead to partial string comparison.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260711T221257Z/items/CVE-2026-14687.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability was determined in 666ghj BettaFish up to 1.2.1. NVD: Impacted is the function _deduplicate_results of the file InsightEngine/agent.py of the component InsightEngine search-result Deduplication. NVD: Executing a manipulation can lead to partial string comparison.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14687/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14688/",
      "current_public_safe_latest": false,
      "cvss_score": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.19957,
      "epss_score": 0.00281,
      "first_observed_at": "2026-07-11T22:10:08.567004+00:00",
      "id": "CVE-2026-14688",
      "impact_tags": [
        "SQL injection risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-11T22:10:08.567004+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A vulnerability was identified in itsourcecode Online Hotel Management System 1.0. NVD: The affected element is an unknown function of the file /admin/login.php. NVD: The manipulation of the argument email leads to sql injection.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260711T221257Z/items/CVE-2026-14688.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes SQL injection risk. Possible impact: An attacker may be able to read or change database-backed application data.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability was identified in itsourcecode Online Hotel Management System 1.0. NVD: The affected element is an unknown function of the file /admin/login.php. NVD: The manipulation of the argument email leads to sql injection.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14688/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14689/",
      "current_public_safe_latest": false,
      "cvss_score": 2.1,
      "cvss_severity": "LOW",
      "epss_percentile": 0.09986,
      "epss_score": 0.002,
      "first_observed_at": "2026-07-11T22:10:08.567004+00:00",
      "id": "CVE-2026-14689",
      "impact_tags": [
        "SQL injection risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-11T22:10:08.567004+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A security flaw has been discovered in CodeAstro Apartment Visitor Management System 1.0. NVD: The impacted element is an unknown function of the file /apartment-visitor/add-apartment.php. NVD: The manipulation of the argument apartmentno results in sql injection.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260711T221257Z/items/CVE-2026-14689.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes SQL injection risk. Possible impact: An attacker may be able to read or change database-backed application data.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A security flaw has been discovered in CodeAstro Apartment Visitor Management System 1.0. NVD: The impacted element is an unknown function of the file /apartment-visitor/add-apartment.php. NVD: The manipulation of the argument apartmentno results in sql injection.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14689/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14690/",
      "current_public_safe_latest": false,
      "cvss_score": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.20685,
      "epss_score": 0.00288,
      "first_observed_at": "2026-07-11T22:10:08.567004+00:00",
      "id": "CVE-2026-14690",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-11T22:10:08.567004+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A weakness has been identified in SourceCodester Multi-Vendor Online Grocery Management System 1.0. NVD: This affects the function save_users of the file classes/Users.php. NVD: This manipulation causes improper authorization.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260711T221257Z/items/CVE-2026-14690.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A weakness has been identified in SourceCodester Multi-Vendor Online Grocery Management System 1.0. NVD: This affects the function save_users of the file classes/Users.php. NVD: This manipulation causes improper authorization.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14690/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14691/",
      "current_public_safe_latest": false,
      "cvss_score": 2.1,
      "cvss_severity": "LOW",
      "epss_percentile": 0.14609,
      "epss_score": 0.00237,
      "first_observed_at": "2026-07-11T22:10:08.567004+00:00",
      "id": "CVE-2026-14691",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-11T22:10:08.567004+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A security vulnerability has been detected in SourceCodester Multi-Vendor Online Grocery Management System 1.0. NVD: This impacts the function update_settings_info of the file classes/SystemSettings.php of the component Setting Handler. NVD: Such manipulation of the argument content[] leads to code injection.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260711T221257Z/items/CVE-2026-14691.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A security vulnerability has been detected in SourceCodester Multi-Vendor Online Grocery Management System 1.0. NVD: This impacts the function update_settings_info of the file classes/SystemSettings.php of the component Setting Handler. NVD: Such manipulation of the argument content[] leads to code injection.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14691/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14692/",
      "current_public_safe_latest": false,
      "cvss_score": 2.1,
      "cvss_severity": "LOW",
      "epss_percentile": 0.09991,
      "epss_score": 0.002,
      "first_observed_at": "2026-07-11T22:10:08.567004+00:00",
      "id": "CVE-2026-14692",
      "impact_tags": [
        "SQL injection risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-11T22:10:08.567004+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A vulnerability was detected in SourceCodester Multi-Vendor Online Grocery Management System 1.0/5.7.26. NVD: Affected is the function save_shop_type of the file classes/Master.php of the component POST Parameter Handler. NVD: Performing a manipulation results in sql injection.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260711T221257Z/items/CVE-2026-14692.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes SQL injection risk. Possible impact: An attacker may be able to read or change database-backed application data.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability was detected in SourceCodester Multi-Vendor Online Grocery Management System 1.0/5.7.26. NVD: Affected is the function save_shop_type of the file classes/Master.php of the component POST Parameter Handler. NVD: Performing a manipulation results in sql injection.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14692/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14693/",
      "current_public_safe_latest": false,
      "cvss_score": 2.1,
      "cvss_severity": "LOW",
      "epss_percentile": 0.1373,
      "epss_score": 0.0023,
      "first_observed_at": "2026-07-11T22:10:08.567004+00:00",
      "id": "CVE-2026-14693",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-11T22:10:08.567004+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A flaw has been found in SourceCodester Multi-Vendor Online Grocery Management System 1.0. NVD: Affected by this vulnerability is the function cancel_order of the file classes/Master.php. NVD: Executing a manipulation can lead to improper authorization.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260711T221257Z/items/CVE-2026-14693.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A flaw has been found in SourceCodester Multi-Vendor Online Grocery Management System 1.0. NVD: Affected by this vulnerability is the function cancel_order of the file classes/Master.php. NVD: Executing a manipulation can lead to improper authorization.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14693/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14694/",
      "current_public_safe_latest": false,
      "cvss_score": 2.1,
      "cvss_severity": "LOW",
      "epss_percentile": 0.09985,
      "epss_score": 0.002,
      "first_observed_at": "2026-07-11T22:10:08.567004+00:00",
      "id": "CVE-2026-14694",
      "impact_tags": [
        "SQL injection risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-11T22:10:08.567004+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A vulnerability has been found in SourceCodester Multi-Vendor Online Grocery Management System 1.0. NVD: Affected by this issue is the function cancel_order of the file classes/Master.php of the component POST Parameter Handler. NVD: The manipulation of the argument ID leads to sql injection.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260711T221257Z/items/CVE-2026-14694.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes SQL injection risk. Possible impact: An attacker may be able to read or change database-backed application data.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability has been found in SourceCodester Multi-Vendor Online Grocery Management System 1.0. NVD: Affected by this issue is the function cancel_order of the file classes/Master.php of the component POST Parameter Handler. NVD: The manipulation of the argument ID leads to sql injection.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14694/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14695/",
      "current_public_safe_latest": false,
      "cvss_score": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.17752,
      "epss_score": 0.00263,
      "first_observed_at": "2026-07-11T22:10:08.567004+00:00",
      "id": "CVE-2026-14695",
      "impact_tags": [
        "SQL injection risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-11T22:10:08.567004+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A vulnerability was found in SourceCodester Multi-Vendor Online Grocery Management System 1.0. NVD: This affects the function save_client of the file classes/Users.php of the component Registration Handler. NVD: The manipulation of the argument Name results in sql injection.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260711T221257Z/items/CVE-2026-14695.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes SQL injection risk. Possible impact: An attacker may be able to read or change database-backed application data.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability was found in SourceCodester Multi-Vendor Online Grocery Management System 1.0. NVD: This affects the function save_client of the file classes/Users.php of the component Registration Handler. NVD: The manipulation of the argument Name results in sql injection.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14695/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14704/",
      "current_public_safe_latest": false,
      "cvss_score": 2.1,
      "cvss_severity": "LOW",
      "epss_percentile": 0.20066,
      "epss_score": 0.00282,
      "first_observed_at": "2026-07-12T06:15:25.921412+00:00",
      "id": "CVE-2026-14704",
      "impact_tags": [
        "XSS risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-12T06:15:25.921412+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A vulnerability was found in stephen-kruger bluebox up to 4.5.12. NVD: Affected by this vulnerability is an unknown functionality. NVD: Performing a manipulation of the argument code results in cross site scripting.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260712T061643Z/items/CVE-2026-14704.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes XSS risk. Possible impact: This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability was found in stephen-kruger bluebox up to 4.5.12. NVD: Affected by this vulnerability is an unknown functionality. NVD: Performing a manipulation of the argument code results in cross site scripting.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14704/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14705/",
      "current_public_safe_latest": false,
      "cvss_score": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.17755,
      "epss_score": 0.00263,
      "first_observed_at": "2026-07-12T06:15:25.921412+00:00",
      "id": "CVE-2026-14705",
      "impact_tags": [
        "SQL injection risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-12T06:15:25.921412+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A vulnerability was determined in code-projects Online Examination 1.0. NVD: Affected by this issue is some unknown functionality of the file head.php. NVD: Executing a manipulation of the argument uname/password can lead to sql injection.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260712T061643Z/items/CVE-2026-14705.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes SQL injection risk. Possible impact: An attacker may be able to read or change database-backed application data.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability was determined in code-projects Online Examination 1.0. NVD: Affected by this issue is some unknown functionality of the file head.php. NVD: Executing a manipulation of the argument uname/password can lead to sql injection.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14705/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14706/",
      "current_public_safe_latest": false,
      "cvss_score": 2.1,
      "cvss_severity": "LOW",
      "epss_percentile": 0.09987,
      "epss_score": 0.002,
      "first_observed_at": "2026-07-12T06:15:25.921412+00:00",
      "id": "CVE-2026-14706",
      "impact_tags": [
        "SQL injection risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-12T06:15:25.921412+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A vulnerability was identified in code-projects Online Examination 1.0. NVD: This affects an unknown part of the file /update.php?q=addquiz of the component Quiz Creation Feature. NVD: The manipulation of the argument name/total/right/wrong/time/tag/desc leads to sql injection.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260712T061643Z/items/CVE-2026-14706.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes SQL injection risk. Possible impact: An attacker may be able to read or change database-backed application data.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability was identified in code-projects Online Examination 1.0. NVD: This affects an unknown part of the file /update.php?q=addquiz of the component Quiz Creation Feature. NVD: The manipulation of the argument name/total/right/wrong/time/tag/desc leads to sql injection.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14706/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14713/",
      "current_public_safe_latest": false,
      "cvss_score": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.17755,
      "epss_score": 0.00263,
      "first_observed_at": "2026-07-12T06:15:25.921412+00:00",
      "id": "CVE-2026-14713",
      "impact_tags": [
        "SQL injection risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-12T06:15:25.921412+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A security flaw has been discovered in SourceCodester Pizzafy E-Commerce System 1.0. NVD: This vulnerability affects unknown code of the file /admin/ajax.php?action=confirm_order. NVD: The manipulation of the argument ID results in sql injection.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260712T061643Z/items/CVE-2026-14713.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes SQL injection risk. Possible impact: An attacker may be able to read or change database-backed application data.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A security flaw has been discovered in SourceCodester Pizzafy E-Commerce System 1.0. NVD: This vulnerability affects unknown code of the file /admin/ajax.php?action=confirm_order. NVD: The manipulation of the argument ID results in sql injection.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14713/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14714/",
      "current_public_safe_latest": false,
      "cvss_score": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.36415,
      "epss_score": 0.00453,
      "first_observed_at": "2026-07-12T06:15:25.921412+00:00",
      "id": "CVE-2026-14714",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-12T06:15:25.921412+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A weakness has been identified in zhayujie chatgpt-on-wechat CowAgent 2.1.0. NVD: This issue affects the function verify_server of the file channel/wechatmp/common.py of the component wx Endpoint. NVD: This manipulation of the argument wechatmp_token causes missing authentication.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260712T061643Z/items/CVE-2026-14714.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A weakness has been identified in zhayujie chatgpt-on-wechat CowAgent 2.1.0. NVD: This issue affects the function verify_server of the file channel/wechatmp/common.py of the component wx Endpoint. NVD: This manipulation of the argument wechatmp_token causes missing authentication.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14714/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14716/",
      "current_public_safe_latest": false,
      "cvss_score": 2.1,
      "cvss_severity": "LOW",
      "epss_percentile": 0.13513,
      "epss_score": 0.00228,
      "first_observed_at": "2026-07-12T06:15:25.921412+00:00",
      "id": "CVE-2026-14716",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-12T06:15:25.921412+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A security vulnerability has been detected in nextlevelbuilder GoClaw up to 3.13.0-beta.2. NVD: Impacted is the function MethodRouter.Handle of the file internal/gateway/router.go of the component WebSocket RPC Handler. NVD: Such manipulation leads to incorrect authorization.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260712T061643Z/items/CVE-2026-14716.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A security vulnerability has been detected in nextlevelbuilder GoClaw up to 3.13.0-beta.2. NVD: Impacted is the function MethodRouter.Handle of the file internal/gateway/router.go of the component WebSocket RPC Handler. NVD: Such manipulation leads to incorrect authorization.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14716/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14717/",
      "current_public_safe_latest": false,
      "cvss_score": 2.1,
      "cvss_severity": "LOW",
      "epss_percentile": 0.09988,
      "epss_score": 0.002,
      "first_observed_at": "2026-07-12T06:15:25.921412+00:00",
      "id": "CVE-2026-14717",
      "impact_tags": [
        "SQL injection risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-12T06:15:25.921412+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A vulnerability was detected in itsourcecode Hospital Management System 1.0. NVD: The affected element is an unknown function of the file /patientlogin.php. NVD: Performing a manipulation of the argument loginid results in sql injection.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260712T061643Z/items/CVE-2026-14717.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes SQL injection risk. Possible impact: An attacker may be able to read or change database-backed application data.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability was detected in itsourcecode Hospital Management System 1.0. NVD: The affected element is an unknown function of the file /patientlogin.php. NVD: Performing a manipulation of the argument loginid results in sql injection.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14717/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14719/",
      "current_public_safe_latest": false,
      "cvss_score": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.20684,
      "epss_score": 0.00288,
      "first_observed_at": "2026-07-12T06:15:25.921412+00:00",
      "id": "CVE-2026-14719",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-12T06:15:25.921412+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A flaw has been found in SourceCodester Onlne Examination & Learning Management System 1.0. NVD: The impacted element is an unknown function of the file register.php of the component Registration Endpoint. NVD: Executing a manipulation of the argument role can lead to improper privilege management.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260712T061643Z/items/CVE-2026-14719.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A flaw has been found in SourceCodester Onlne Examination & Learning Management System 1.0. NVD: The impacted element is an unknown function of the file register.php of the component Registration Endpoint. NVD: Executing a manipulation of the argument role can lead to improper privilege management.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14719/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14721/",
      "current_public_safe_latest": false,
      "cvss_score": 7.4,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.35991,
      "epss_score": 0.00447,
      "first_observed_at": "2026-07-12T06:15:25.921412+00:00",
      "id": "CVE-2026-14721",
      "impact_tags": [
        "memory safety review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-12T06:15:25.921412+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A vulnerability has been found in UTT HiPER 1250GW up to 3.2.7-210907-180535. NVD: This affects an unknown function of the file /goform/ConfigWirelessBase_5g of the component Web Endpoint. NVD: The manipulation of the argument ssid leads to stack-based buffer overflow.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260712T061643Z/items/CVE-2026-14721.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes memory safety review. Possible impact: The affected component has memory-safety risk that may lead to crash, privilege, or code-execution impact depending on exposure.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability has been found in UTT HiPER 1250GW up to 3.2.7-210907-180535. NVD: This affects an unknown function of the file /goform/ConfigWirelessBase_5g of the component Web Endpoint. NVD: The manipulation of the argument ssid leads to stack-based buffer overflow.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14721/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14722/",
      "current_public_safe_latest": false,
      "cvss_score": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.23439,
      "epss_score": 0.00315,
      "first_observed_at": "2026-07-12T06:15:25.921412+00:00",
      "id": "CVE-2026-14722",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-12T06:15:25.921412+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A vulnerability was found in tiddly-gittly TidGi-Desktop up to 0.13.0. NVD: This impacts an unknown function of the file src/services/wiki/wikiWorker/loadWikiTiddlersWithSubWikis.ts of the component Git Repository Import. NVD: The manipulation results in code injection.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260712T061643Z/items/CVE-2026-14722.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability was found in tiddly-gittly TidGi-Desktop up to 0.13.0. NVD: This impacts an unknown function of the file src/services/wiki/wikiWorker/loadWikiTiddlersWithSubWikis.ts of the component Git Repository Import. NVD: The manipulation results in code injection.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14722/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14723/",
      "current_public_safe_latest": false,
      "cvss_score": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.0227,
      "epss_score": 0.00121,
      "first_observed_at": "2026-07-12T06:15:25.921412+00:00",
      "id": "CVE-2026-14723",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-12T06:15:25.921412+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A vulnerability was determined in AD-Security AD_Miner 1.9.0. NVD: Affected is the function request_a of the file ad_miner/scripts/analyse_cache.py of the component Cache Handler. NVD: This manipulation of the argument sys.argv[1] causes deserialization.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260712T061643Z/items/CVE-2026-14723.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability was determined in AD-Security AD_Miner 1.9.0. NVD: Affected is the function request_a of the file ad_miner/scripts/analyse_cache.py of the component Cache Handler. NVD: This manipulation of the argument sys.argv[1] causes deserialization.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14723/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14725/",
      "current_public_safe_latest": false,
      "cvss_score": 2.1,
      "cvss_severity": "LOW",
      "epss_percentile": 0.1113,
      "epss_score": 0.00209,
      "first_observed_at": "2026-07-12T06:15:25.921412+00:00",
      "id": "CVE-2026-14725",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-12T06:15:25.921412+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A vulnerability was identified in SourceCodester Online Boat Reservation System 1.0. NVD: Affected by this vulnerability is an unknown functionality. NVD: Such manipulation leads to session expiration.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260712T061643Z/items/CVE-2026-14725.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability was identified in SourceCodester Online Boat Reservation System 1.0. NVD: Affected by this vulnerability is an unknown functionality. NVD: Such manipulation leads to session expiration.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14725/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14730/",
      "current_public_safe_latest": false,
      "cvss_score": 2.1,
      "cvss_severity": "LOW",
      "epss_percentile": 0.09995,
      "epss_score": 0.002,
      "first_observed_at": "2026-07-12T06:15:25.921412+00:00",
      "id": "CVE-2026-14730",
      "impact_tags": [
        "SQL injection risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-12T06:15:25.921412+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A security flaw has been discovered in itsourcecode Hospital Management System 1.0. NVD: Affected by this issue is some unknown functionality of the file /patientprofile.php. NVD: Performing a manipulation of the argument patientname results in sql injection.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260712T061643Z/items/CVE-2026-14730.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes SQL injection risk. Possible impact: An attacker may be able to read or change database-backed application data.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A security flaw has been discovered in itsourcecode Hospital Management System 1.0. NVD: Affected by this issue is some unknown functionality of the file /patientprofile.php. NVD: Performing a manipulation of the argument patientname results in sql injection.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14730/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14731/",
      "current_public_safe_latest": false,
      "cvss_score": 2.1,
      "cvss_severity": "LOW",
      "epss_percentile": 0.09994,
      "epss_score": 0.002,
      "first_observed_at": "2026-07-12T06:15:25.921412+00:00",
      "id": "CVE-2026-14731",
      "impact_tags": [
        "SQL injection risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-12T06:15:25.921412+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A weakness has been identified in itsourcecode Hospital Management System 1.0. NVD: This affects an unknown part of the file /patientreport.php. NVD: Executing a manipulation of the argument editid can lead to sql injection.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260712T061643Z/items/CVE-2026-14731.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes SQL injection risk. Possible impact: An attacker may be able to read or change database-backed application data.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A weakness has been identified in itsourcecode Hospital Management System 1.0. NVD: This affects an unknown part of the file /patientreport.php. NVD: Executing a manipulation of the argument editid can lead to sql injection.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14731/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14732/",
      "current_public_safe_latest": false,
      "cvss_score": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.17754,
      "epss_score": 0.00263,
      "first_observed_at": "2026-07-12T06:15:25.921412+00:00",
      "id": "CVE-2026-14732",
      "impact_tags": [
        "SQL injection risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-12T06:15:25.921412+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A security vulnerability has been detected in SourceCodester Class and Exam Timetabling System 1.0. NVD: This vulnerability affects unknown code of the file /edit_exam.php. NVD: The manipulation of the argument ID leads to sql injection.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260712T061643Z/items/CVE-2026-14732.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes SQL injection risk. Possible impact: An attacker may be able to read or change database-backed application data.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A security vulnerability has been detected in SourceCodester Class and Exam Timetabling System 1.0. NVD: This vulnerability affects unknown code of the file /edit_exam.php. NVD: The manipulation of the argument ID leads to sql injection.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14732/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14733/",
      "current_public_safe_latest": false,
      "cvss_score": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.17753,
      "epss_score": 0.00263,
      "first_observed_at": "2026-07-12T06:15:25.921412+00:00",
      "id": "CVE-2026-14733",
      "impact_tags": [
        "SQL injection risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-12T06:15:25.921412+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A vulnerability was detected in SourceCodester Class and Exam Timetabling System 1.0. NVD: This issue affects some unknown processing of the file /edit_coursea.php. NVD: The manipulation of the argument ID results in sql injection.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260712T061643Z/items/CVE-2026-14733.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes SQL injection risk. Possible impact: An attacker may be able to read or change database-backed application data.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability was detected in SourceCodester Class and Exam Timetabling System 1.0. NVD: This issue affects some unknown processing of the file /edit_coursea.php. NVD: The manipulation of the argument ID results in sql injection.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14733/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14734/",
      "current_public_safe_latest": false,
      "cvss_score": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.33259,
      "epss_score": 0.00412,
      "first_observed_at": "2026-07-12T06:15:25.921412+00:00",
      "id": "CVE-2026-14734",
      "impact_tags": [
        "SQL injection risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-12T06:15:25.921412+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A flaw has been found in SourceCodester Class and Exam Timetabling System 1.0. NVD: Impacted is an unknown function of the file /edit_product.php. NVD: This manipulation of the argument ID causes sql injection.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260712T061643Z/items/CVE-2026-14734.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes SQL injection risk. Possible impact: An attacker may be able to read or change database-backed application data.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A flaw has been found in SourceCodester Class and Exam Timetabling System 1.0. NVD: Impacted is an unknown function of the file /edit_product.php. NVD: This manipulation of the argument ID causes sql injection.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14734/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14735/",
      "current_public_safe_latest": false,
      "cvss_score": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.33259,
      "epss_score": 0.00412,
      "first_observed_at": "2026-07-12T06:15:25.921412+00:00",
      "id": "CVE-2026-14735",
      "impact_tags": [
        "SQL injection risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-12T06:15:25.921412+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A vulnerability has been found in code-projects Smart Parking System 1.0. NVD: The affected element is an unknown function of the file /parkings/parkings.php. NVD: Such manipulation of the argument street/city/status leads to sql injection.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260712T061643Z/items/CVE-2026-14735.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes SQL injection risk. Possible impact: An attacker may be able to read or change database-backed application data.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability has been found in code-projects Smart Parking System 1.0. NVD: The affected element is an unknown function of the file /parkings/parkings.php. NVD: Such manipulation of the argument street/city/status leads to sql injection.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14735/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14736/",
      "current_public_safe_latest": false,
      "cvss_score": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.3632,
      "epss_score": 0.00452,
      "first_observed_at": "2026-07-12T06:15:25.921412+00:00",
      "id": "CVE-2026-14736",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-12T06:15:25.921412+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A vulnerability was found in Ruijie RG-UAC up to 1.0-R1.8.2.p5. NVD: The impacted element is an unknown function of the file user_auth_commit.php. NVD: Performing a manipulation of the argument upload_image results in unrestricted upload.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260712T061643Z/items/CVE-2026-14736.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability was found in Ruijie RG-UAC up to 1.0-R1.8.2.p5. NVD: The impacted element is an unknown function of the file user_auth_commit.php. NVD: Performing a manipulation of the argument upload_image results in unrestricted upload.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14736/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14737/",
      "current_public_safe_latest": false,
      "cvss_score": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.17325,
      "epss_score": 0.00259,
      "first_observed_at": "2026-07-12T10:46:01.700382+00:00",
      "id": "CVE-2026-14737",
      "impact_tags": [
        "SQL injection risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-12T10:46:01.700382+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A vulnerability was identified in Hanwang e-Face General Management Platform 6.3.5.4. NVD: This impacts an unknown function of the file /sysAuthStr/querySysAuthStr.do. NVD: The manipulation of the argument order leads to sql injection.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260712T104758Z/items/CVE-2026-14737.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes SQL injection risk. Possible impact: An attacker may be able to read or change database-backed application data.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability was identified in Hanwang e-Face General Management Platform 6.3.5.4. NVD: This impacts an unknown function of the file /sysAuthStr/querySysAuthStr.do. NVD: The manipulation of the argument order leads to sql injection.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14737/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14738/",
      "current_public_safe_latest": false,
      "cvss_score": 2.9,
      "cvss_severity": "LOW",
      "epss_percentile": 0.10951,
      "epss_score": 0.00208,
      "first_observed_at": "2026-07-12T10:46:01.700382+00:00",
      "id": "CVE-2026-14738",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-12T10:46:01.700382+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A security flaw has been discovered in exo-explore exo up to 1.0.71. NVD: Affected is the function _image_cache_key of the file src/exo/worker/engines/mlx/vision.py of the component Vision Feature Cache. NVD: The manipulation results in use of weak hash.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260712T104758Z/items/CVE-2026-14738.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A security flaw has been discovered in exo-explore exo up to 1.0.71. NVD: Affected is the function _image_cache_key of the file src/exo/worker/engines/mlx/vision.py of the component Vision Feature Cache. NVD: The manipulation results in use of weak hash.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14738/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "perl / dbi",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14739/",
      "current_public_safe_latest": false,
      "cvss_score": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.3181,
      "epss_score": 0.00396,
      "first_observed_at": "2026-07-14T22:16:58.989760+00:00",
      "id": "CVE-2026-14739",
      "impact_tags": [
        "memory safety review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-14T22:16:58.989760+00:00",
      "latest_item_url": null,
      "product": "dbi",
      "public_safe_summary": "NVD: DBI versions before 1.650 for Perl have a heap overflow when preparsing SQL statements with an extreme number of placeholders. NVD: The fix for CVE-2026-10879 did not allocate enough memory to handle approximately 1.2-million placeholders. NVD: DBI version 1.650 sets a hard limit of 99,999 placeholders.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260714T222111Z/items/CVE-2026-14739.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: perl / dbi",
      "source_published_impact": "Source describes memory safety review. Possible impact: The affected component has memory-safety risk that may lead to crash, privilege, or code-execution impact depending on exposure.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: DBI versions before 1.650 for Perl have a heap overflow when preparsing SQL statements with an extreme number of placeholders. NVD: The fix for CVE-2026-10879 did not allocate enough memory to handle approximately 1.2-million placeholders. NVD: DBI version 1.650 sets a hard limit of 99,999 placeholders.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14739/timeline.json",
      "vendor": "perl"
    },
    {
      "affected_label": "perl / dbi",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14740/",
      "current_public_safe_latest": false,
      "cvss_score": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.32847,
      "epss_score": 0.00407,
      "first_observed_at": "2026-07-14T22:16:58.989760+00:00",
      "id": "CVE-2026-14740",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-14T22:16:58.989760+00:00",
      "latest_item_url": null,
      "product": "dbi",
      "public_safe_summary": "NVD: DBI versions before 1.650 for Perl read one byte out-of-bounds in preparse when deleting an initial SQL comment. NVD: The preparse method normalises SQL and removes comments. NVD: When the SQL starts with a comment line, the deletion of that line during normalisation led to an out-of-bounds read by one byte.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260714T222111Z/items/CVE-2026-14740.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: perl / dbi",
      "source_published_impact": "This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: DBI versions before 1.650 for Perl read one byte out-of-bounds in preparse when deleting an initial SQL comment. NVD: The preparse method normalises SQL and removes comments. NVD: When the SQL starts with a comment line, the deletion of that line during normalisation led to an out-of-bounds read by one byte.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14740/timeline.json",
      "vendor": "perl"
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14742/",
      "current_public_safe_latest": false,
      "cvss_score": 1.3,
      "cvss_severity": "LOW",
      "epss_percentile": 0.05528,
      "epss_score": 0.0016,
      "first_observed_at": "2026-07-12T10:46:01.700382+00:00",
      "id": "CVE-2026-14742",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-12T10:46:01.700382+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A vulnerability was determined in langchain-ai langgraph up to 1.2.4. NVD: The affected element is the function _freeze of the file libs/langgraph/langgraph/_internal/_cache.py of the component Task Result Cache. NVD: This manipulation of the argument default_cache_key causes use of weak hash.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260712T104758Z/items/CVE-2026-14742.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability was determined in langchain-ai langgraph up to 1.2.4. NVD: The affected element is the function _freeze of the file libs/langgraph/langgraph/_internal/_cache.py of the component Task Result Cache. NVD: This manipulation of the argument default_cache_key causes use of weak hash.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14742/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14743/",
      "current_public_safe_latest": false,
      "cvss_score": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.17753,
      "epss_score": 0.00263,
      "first_observed_at": "2026-07-12T10:46:01.700382+00:00",
      "id": "CVE-2026-14743",
      "impact_tags": [
        "SQL injection risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-12T10:46:01.700382+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A vulnerability was identified in code-projects Real State Services 1.0. NVD: The impacted element is an unknown function of the file /normalHomeSale.php. NVD: Such manipulation of the argument loc leads to sql injection.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260712T104758Z/items/CVE-2026-14743.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes SQL injection risk. Possible impact: An attacker may be able to read or change database-backed application data.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability was identified in code-projects Real State Services 1.0. NVD: The impacted element is an unknown function of the file /normalHomeSale.php. NVD: Such manipulation of the argument loc leads to sql injection.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14743/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14744/",
      "current_public_safe_latest": false,
      "cvss_score": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.17753,
      "epss_score": 0.00263,
      "first_observed_at": "2026-07-12T10:46:01.700382+00:00",
      "id": "CVE-2026-14744",
      "impact_tags": [
        "SQL injection risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-12T10:46:01.700382+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A security flaw has been discovered in code-projects Real State Services 1.0. NVD: This affects an unknown function of the file /normalHomeRent.php. NVD: Performing a manipulation of the argument loc results in sql injection.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260712T104758Z/items/CVE-2026-14744.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes SQL injection risk. Possible impact: An attacker may be able to read or change database-backed application data.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A security flaw has been discovered in code-projects Real State Services 1.0. NVD: This affects an unknown function of the file /normalHomeRent.php. NVD: Performing a manipulation of the argument loc results in sql injection.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14744/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14745/",
      "current_public_safe_latest": false,
      "cvss_score": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.17756,
      "epss_score": 0.00263,
      "first_observed_at": "2026-07-12T10:46:01.700382+00:00",
      "id": "CVE-2026-14745",
      "impact_tags": [
        "SQL injection risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-12T10:46:01.700382+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A weakness has been identified in code-projects Real State Services 1.0. NVD: This impacts an unknown function of the file /single-list_rent.php. NVD: Executing a manipulation of the argument ID can lead to sql injection.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260712T104758Z/items/CVE-2026-14745.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes SQL injection risk. Possible impact: An attacker may be able to read or change database-backed application data.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A weakness has been identified in code-projects Real State Services 1.0. NVD: This impacts an unknown function of the file /single-list_rent.php. NVD: Executing a manipulation of the argument ID can lead to sql injection.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14745/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14746/",
      "current_public_safe_latest": false,
      "cvss_score": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.18548,
      "epss_score": 0.00269,
      "first_observed_at": "2026-07-12T10:46:01.700382+00:00",
      "id": "CVE-2026-14746",
      "impact_tags": [
        "SQL injection risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-12T10:46:01.700382+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A security vulnerability has been detected in code-projects Real State Services 1.0. NVD: Affected is an unknown function of the file /addprojectrent.php. NVD: The manipulation of the argument amen leads to sql injection.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260712T104758Z/items/CVE-2026-14746.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes SQL injection risk. Possible impact: An attacker may be able to read or change database-backed application data.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A security vulnerability has been detected in code-projects Real State Services 1.0. NVD: Affected is an unknown function of the file /addprojectrent.php. NVD: The manipulation of the argument amen leads to sql injection.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14746/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14747/",
      "current_public_safe_latest": false,
      "cvss_score": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.18549,
      "epss_score": 0.00269,
      "first_observed_at": "2026-07-12T10:46:01.700382+00:00",
      "id": "CVE-2026-14747",
      "impact_tags": [
        "SQL injection risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-12T10:46:01.700382+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A vulnerability was detected in code-projects Real State Services 1.0. NVD: Affected by this vulnerability is an unknown functionality of the file /addprojectsale.php. NVD: The manipulation of the argument amen results in sql injection.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260712T104758Z/items/CVE-2026-14747.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes SQL injection risk. Possible impact: An attacker may be able to read or change database-backed application data.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability was detected in code-projects Real State Services 1.0. NVD: Affected by this vulnerability is an unknown functionality of the file /addprojectsale.php. NVD: The manipulation of the argument amen results in sql injection.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14747/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14748/",
      "current_public_safe_latest": false,
      "cvss_score": 2.1,
      "cvss_severity": "LOW",
      "epss_percentile": 0.13941,
      "epss_score": 0.00231,
      "first_observed_at": "2026-07-12T10:46:01.700382+00:00",
      "id": "CVE-2026-14748",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-12T10:46:01.700382+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A flaw has been found in AIAnytime Awesome-MCP-Server up to a884bb51bcd99e08e14fd712c749d55d9d9a13ab. NVD: Affected by this issue is some unknown functionality of the file mcp-wiki/src/mcp_wiki/server.py of the component mcp-wiki/wiki-summary. NVD: This manipulation of the argument url causes server-side request forgery.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260712T104758Z/items/CVE-2026-14748.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A flaw has been found in AIAnytime Awesome-MCP-Server up to a884bb51bcd99e08e14fd712c749d55d9d9a13ab. NVD: Affected by this issue is some unknown functionality of the file mcp-wiki/src/mcp_wiki/server.py of the component mcp-wiki/wiki-summary. NVD: This manipulation of the argument url causes server-side request forgery.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14748/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14749/",
      "current_public_safe_latest": false,
      "cvss_score": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.24127,
      "epss_score": 0.00322,
      "first_observed_at": "2026-07-12T10:46:01.700382+00:00",
      "id": "CVE-2026-14749",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-12T10:46:01.700382+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A vulnerability was identified in mjperpinosa stumasy up to 327d1b0f2915ba79d7ef8ebb74553e987609d9be. NVD: Impacted is the function eval of the file application/pages/imba_calculator/calculate.php. NVD: The manipulation of the argument mathematical_sentence leads to code injection.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260712T104758Z/items/CVE-2026-14749.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability was identified in mjperpinosa stumasy up to 327d1b0f2915ba79d7ef8ebb74553e987609d9be. NVD: Impacted is the function eval of the file application/pages/imba_calculator/calculate.php. NVD: The manipulation of the argument mathematical_sentence leads to code injection.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14749/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14750/",
      "current_public_safe_latest": false,
      "cvss_score": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.18547,
      "epss_score": 0.00269,
      "first_observed_at": "2026-07-12T10:46:01.700382+00:00",
      "id": "CVE-2026-14750",
      "impact_tags": [
        "SQL injection risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-12T10:46:01.700382+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A security flaw has been discovered in mjperpinosa stumasy up to 327d1b0f2915ba79d7ef8ebb74553e987609d9be. NVD: The affected element is the function Notes_controller::accessing_dictionary_authorization of the file application/PHP/objects/notes/accessing_dictionary_authorization.php. NVD: The manipulation of the argument Password results in sql injection.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260712T104758Z/items/CVE-2026-14750.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes SQL injection risk. Possible impact: An attacker may be able to read or change database-backed application data.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A security flaw has been discovered in mjperpinosa stumasy up to 327d1b0f2915ba79d7ef8ebb74553e987609d9be. NVD: The affected element is the function Notes_controller::accessing_dictionary_authorization of the file application/PHP/objects/notes/accessing_dictionary_authorization.php. NVD: The manipulation of the argument Password results in sql injection.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14750/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14751/",
      "current_public_safe_latest": false,
      "cvss_score": 2.1,
      "cvss_severity": "LOW",
      "epss_percentile": 0.10482,
      "epss_score": 0.00204,
      "first_observed_at": "2026-07-12T10:46:01.700382+00:00",
      "id": "CVE-2026-14751",
      "impact_tags": [
        "SQL injection risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-12T10:46:01.700382+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A weakness has been identified in mjperpinosa stumasy up to 327d1b0f2915ba79d7ef8ebb74553e987609d9be. NVD: The impacted element is the function Notes_controller::search_scratch_data of the file application/PHP/objects/notes/search_scratch_data.php. NVD: This manipulation of the argument field_name causes sql injection.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260712T104758Z/items/CVE-2026-14751.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes SQL injection risk. Possible impact: An attacker may be able to read or change database-backed application data.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A weakness has been identified in mjperpinosa stumasy up to 327d1b0f2915ba79d7ef8ebb74553e987609d9be. NVD: The impacted element is the function Notes_controller::search_scratch_data of the file application/PHP/objects/notes/search_scratch_data.php. NVD: This manipulation of the argument field_name causes sql injection.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14751/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14752/",
      "current_public_safe_latest": false,
      "cvss_score": 2.0,
      "cvss_severity": "LOW",
      "epss_percentile": 0.10303,
      "epss_score": 0.00203,
      "first_observed_at": "2026-07-12T10:46:01.700382+00:00",
      "id": "CVE-2026-14752",
      "impact_tags": [
        "XSS risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-12T10:46:01.700382+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A security vulnerability has been detected in mjperpinosa stumasy up to 327d1b0f2915ba79d7ef8ebb74553e987609d9be. NVD: This affects the function add_definition of the file application/PHP/objects/notes/add_into_dictionary.php. NVD: Such manipulation of the argument reference leads to cross site scripting.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260712T104758Z/items/CVE-2026-14752.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes XSS risk. Possible impact: This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A security vulnerability has been detected in mjperpinosa stumasy up to 327d1b0f2915ba79d7ef8ebb74553e987609d9be. NVD: This affects the function add_definition of the file application/PHP/objects/notes/add_into_dictionary.php. NVD: Such manipulation of the argument reference leads to cross site scripting.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14752/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14753/",
      "current_public_safe_latest": false,
      "cvss_score": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.2274,
      "epss_score": 0.00309,
      "first_observed_at": "2026-07-12T10:46:01.700382+00:00",
      "id": "CVE-2026-14753",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-12T10:46:01.700382+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A vulnerability was detected in mjperpinosa stumasy up to 327d1b0f2915ba79d7ef8ebb74553e987609d9be. NVD: This impacts an unknown function of the file /PHP/objects/notes of the component Note Handler/Assignment Handler. NVD: Performing a manipulation of the argument assignment_item_id results in authorization bypass.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260712T104758Z/items/CVE-2026-14753.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability was detected in mjperpinosa stumasy up to 327d1b0f2915ba79d7ef8ebb74553e987609d9be. NVD: This impacts an unknown function of the file /PHP/objects/notes of the component Note Handler/Assignment Handler. NVD: Performing a manipulation of the argument assignment_item_id results in authorization bypass.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14753/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14754/",
      "current_public_safe_latest": false,
      "cvss_score": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.18547,
      "epss_score": 0.00269,
      "first_observed_at": "2026-07-12T10:46:01.700382+00:00",
      "id": "CVE-2026-14754",
      "impact_tags": [
        "SQL injection risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-12T10:46:01.700382+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A flaw has been found in code-projects Hotel and Tourism Reservation 1.0. NVD: Affected is an unknown function of the file /admin/add_room.php. NVD: Executing a manipulation of the argument delete_image/edit/description/number/price/rooms/type can lead to sql injection.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260712T104758Z/items/CVE-2026-14754.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes SQL injection risk. Possible impact: An attacker may be able to read or change database-backed application data.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A flaw has been found in code-projects Hotel and Tourism Reservation 1.0. NVD: Affected is an unknown function of the file /admin/add_room.php. NVD: Executing a manipulation of the argument delete_image/edit/description/number/price/rooms/type can lead to sql injection.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14754/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14755/",
      "current_public_safe_latest": false,
      "cvss_score": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.18547,
      "epss_score": 0.00269,
      "first_observed_at": "2026-07-12T10:46:01.700382+00:00",
      "id": "CVE-2026-14755",
      "impact_tags": [
        "SQL injection risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-12T10:46:01.700382+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A vulnerability has been found in code-projects Hotel and Tourism Reservation 1.0. NVD: Affected by this vulnerability is an unknown functionality of the file /admin/reservations.php of the component Reservations Management Page. NVD: The manipulation of the argument delete leads to sql injection.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260712T104758Z/items/CVE-2026-14755.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes SQL injection risk. Possible impact: An attacker may be able to read or change database-backed application data.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability has been found in code-projects Hotel and Tourism Reservation 1.0. NVD: Affected by this vulnerability is an unknown functionality of the file /admin/reservations.php of the component Reservations Management Page. NVD: The manipulation of the argument delete leads to sql injection.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14755/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14756/",
      "current_public_safe_latest": false,
      "cvss_score": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.18546,
      "epss_score": 0.00269,
      "first_observed_at": "2026-07-12T10:46:01.700382+00:00",
      "id": "CVE-2026-14756",
      "impact_tags": [
        "SQL injection risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-12T10:46:01.700382+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A vulnerability was found in code-projects Hotel and Tourism Reservation 1.0. NVD: Affected by this issue is some unknown functionality of the file /admin/add_tour.php of the component Tour Management Page. NVD: The manipulation of the argument delete_image results in sql injection.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260712T104758Z/items/CVE-2026-14756.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes SQL injection risk. Possible impact: An attacker may be able to read or change database-backed application data.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability was found in code-projects Hotel and Tourism Reservation 1.0. NVD: Affected by this issue is some unknown functionality of the file /admin/add_tour.php of the component Tour Management Page. NVD: The manipulation of the argument delete_image results in sql injection.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14756/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "radare / radare2",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14759/",
      "current_public_safe_latest": false,
      "cvss_score": 1.9,
      "cvss_severity": "LOW",
      "epss_percentile": 0.04874,
      "epss_score": 0.00153,
      "first_observed_at": "2026-07-12T16:15:44.451858+00:00",
      "id": "CVE-2026-14759",
      "impact_tags": [
        "memory safety review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-12T16:15:44.451858+00:00",
      "latest_item_url": null,
      "product": "radare2",
      "public_safe_summary": "NVD: A security flaw has been discovered in radareorg radare2 up to 6.1.6. NVD: This issue affects the function r_bin_java_inner_classes_attr_calc_size of the file shlr/java/class.c of the component RBinJava Line Number Table Parser. NVD: Performing a manipulation results in heap-based buffer overflow.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260712T161649Z/items/CVE-2026-14759.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: radare / radare2",
      "source_published_impact": "Source describes memory safety review. Possible impact: The affected component has memory-safety risk that may lead to crash, privilege, or code-execution impact depending on exposure.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A security flaw has been discovered in radareorg radare2 up to 6.1.6. NVD: This issue affects the function r_bin_java_inner_classes_attr_calc_size of the file shlr/java/class.c of the component RBinJava Line Number Table Parser. NVD: Performing a manipulation results in heap-based buffer overflow.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14759/timeline.json",
      "vendor": "radare"
    },
    {
      "affected_label": "radare / radare2",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14760/",
      "current_public_safe_latest": false,
      "cvss_score": 1.9,
      "cvss_severity": "LOW",
      "epss_percentile": 0.0332,
      "epss_score": 0.00135,
      "first_observed_at": "2026-07-12T16:15:44.451858+00:00",
      "id": "CVE-2026-14760",
      "impact_tags": [
        "memory safety review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-12T16:15:44.451858+00:00",
      "latest_item_url": null,
      "product": "radare2",
      "public_safe_summary": "NVD: A weakness has been identified in radareorg radare2 up to 6.1.6. NVD: Impacted is the function r_core_seek_arch_bits of the file libr/core/disasm.c of the component regprofile Handler. NVD: Executing a manipulation can lead to use after free.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260712T161649Z/items/CVE-2026-14760.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: radare / radare2",
      "source_published_impact": "Source describes memory safety review. Possible impact: The affected component has memory-safety risk that may lead to crash, privilege, or code-execution impact depending on exposure.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A weakness has been identified in radareorg radare2 up to 6.1.6. NVD: Impacted is the function r_core_seek_arch_bits of the file libr/core/disasm.c of the component regprofile Handler. NVD: Executing a manipulation can lead to use after free.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14760/timeline.json",
      "vendor": "radare"
    },
    {
      "affected_label": "radare / radare2",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14761/",
      "current_public_safe_latest": false,
      "cvss_score": 1.9,
      "cvss_severity": "LOW",
      "epss_percentile": 0.03096,
      "epss_score": 0.00131,
      "first_observed_at": "2026-07-12T16:15:44.451858+00:00",
      "id": "CVE-2026-14761",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-12T16:15:44.451858+00:00",
      "latest_item_url": null,
      "product": "radare2",
      "public_safe_summary": "NVD: A security vulnerability has been detected in radareorg radare2 up to 6.1.6. NVD: The affected element is the function r_str_ndup/r_str_append of the file libr/util/str.c. NVD: The manipulation leads to integer overflow.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260712T161649Z/items/CVE-2026-14761.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: radare / radare2",
      "source_published_impact": "This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A security vulnerability has been detected in radareorg radare2 up to 6.1.6. NVD: The affected element is the function r_str_ndup/r_str_append of the file libr/util/str.c. NVD: The manipulation leads to integer overflow.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14761/timeline.json",
      "vendor": "radare"
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14762/",
      "current_public_safe_latest": false,
      "cvss_score": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.18535,
      "epss_score": 0.00269,
      "first_observed_at": "2026-07-12T16:15:44.451858+00:00",
      "id": "CVE-2026-14762",
      "impact_tags": [
        "SQL injection risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-12T16:15:44.451858+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A vulnerability was detected in code-projects Hotel and Tourism Reservation 1.0. NVD: The impacted element is an unknown function of the file /admin/rooms.php of the component Room Management Page. NVD: The manipulation of the argument delete results in sql injection.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260712T161649Z/items/CVE-2026-14762.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes SQL injection risk. Possible impact: An attacker may be able to read or change database-backed application data.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability was detected in code-projects Hotel and Tourism Reservation 1.0. NVD: The impacted element is an unknown function of the file /admin/rooms.php of the component Room Management Page. NVD: The manipulation of the argument delete results in sql injection.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14762/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14763/",
      "current_public_safe_latest": false,
      "cvss_score": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.18537,
      "epss_score": 0.00269,
      "first_observed_at": "2026-07-12T16:15:44.451858+00:00",
      "id": "CVE-2026-14763",
      "impact_tags": [
        "SQL injection risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-12T16:15:44.451858+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A flaw has been found in code-projects Hotel and Tourism Reservation 1.0. NVD: This affects an unknown function of the file /admin/tour_reserves.php of the component Tour Reservations Page. NVD: This manipulation of the argument tour causes sql injection.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260712T161649Z/items/CVE-2026-14763.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes SQL injection risk. Possible impact: An attacker may be able to read or change database-backed application data.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A flaw has been found in code-projects Hotel and Tourism Reservation 1.0. NVD: This affects an unknown function of the file /admin/tour_reserves.php of the component Tour Reservations Page. NVD: This manipulation of the argument tour causes sql injection.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14763/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14764/",
      "current_public_safe_latest": false,
      "cvss_score": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.18535,
      "epss_score": 0.00269,
      "first_observed_at": "2026-07-12T16:15:44.451858+00:00",
      "id": "CVE-2026-14764",
      "impact_tags": [
        "SQL injection risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-12T16:15:44.451858+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A vulnerability has been found in code-projects Hotel and Tourism Reservation 1.0. NVD: This impacts an unknown function of the file /admin/add_event.php of the component Event Management Page. NVD: Such manipulation of the argument fdetails leads to sql injection.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260712T161649Z/items/CVE-2026-14764.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes SQL injection risk. Possible impact: An attacker may be able to read or change database-backed application data.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability has been found in code-projects Hotel and Tourism Reservation 1.0. NVD: This impacts an unknown function of the file /admin/add_event.php of the component Event Management Page. NVD: Such manipulation of the argument fdetails leads to sql injection.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14764/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14766/",
      "current_public_safe_latest": false,
      "cvss_score": 2.1,
      "cvss_severity": "LOW",
      "epss_percentile": 0.10473,
      "epss_score": 0.00204,
      "first_observed_at": "2026-07-12T16:15:44.451858+00:00",
      "id": "CVE-2026-14766",
      "impact_tags": [
        "SQL injection risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-12T16:15:44.451858+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A vulnerability was identified in CodeAstro Apartment Visitor Management System 1.0. NVD: Affected by this issue is some unknown functionality of the file /apartment-visitor/search-result.php of the component POST Parameter Handler. NVD: The manipulation of the argument searchdata leads to sql injection.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260712T161649Z/items/CVE-2026-14766.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes SQL injection risk. Possible impact: An attacker may be able to read or change database-backed application data.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability was identified in CodeAstro Apartment Visitor Management System 1.0. NVD: Affected by this issue is some unknown functionality of the file /apartment-visitor/search-result.php of the component POST Parameter Handler. NVD: The manipulation of the argument searchdata leads to sql injection.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14766/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14767/",
      "current_public_safe_latest": false,
      "cvss_score": 2.1,
      "cvss_severity": "LOW",
      "epss_percentile": 0.10472,
      "epss_score": 0.00204,
      "first_observed_at": "2026-07-12T16:15:44.451858+00:00",
      "id": "CVE-2026-14767",
      "impact_tags": [
        "SQL injection risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-12T16:15:44.451858+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A security flaw has been discovered in CodeAstro Ecommerce Website 1.0. NVD: This affects an unknown part of the file /ecommerce-website-php/customer/confirm.php of the component POST Parameter Handler. NVD: The manipulation of the argument invoice_no results in sql injection.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260712T161649Z/items/CVE-2026-14767.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes SQL injection risk. Possible impact: An attacker may be able to read or change database-backed application data.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A security flaw has been discovered in CodeAstro Ecommerce Website 1.0. NVD: This affects an unknown part of the file /ecommerce-website-php/customer/confirm.php of the component POST Parameter Handler. NVD: The manipulation of the argument invoice_no results in sql injection.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14767/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14768/",
      "current_public_safe_latest": false,
      "cvss_score": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.18534,
      "epss_score": 0.00269,
      "first_observed_at": "2026-07-12T16:15:44.451858+00:00",
      "id": "CVE-2026-14768",
      "impact_tags": [
        "SQL injection risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-12T16:15:44.451858+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A weakness has been identified in code-projects Real State Services 1.0. NVD: This vulnerability affects unknown code of the file /builderHome.php. NVD: This manipulation of the argument loc causes sql injection.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260712T161649Z/items/CVE-2026-14768.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes SQL injection risk. Possible impact: An attacker may be able to read or change database-backed application data.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A weakness has been identified in code-projects Real State Services 1.0. NVD: This vulnerability affects unknown code of the file /builderHome.php. NVD: This manipulation of the argument loc causes sql injection.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14768/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14769/",
      "current_public_safe_latest": false,
      "cvss_score": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.18534,
      "epss_score": 0.00269,
      "first_observed_at": "2026-07-12T16:15:44.451858+00:00",
      "id": "CVE-2026-14769",
      "impact_tags": [
        "SQL injection risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-12T16:15:44.451858+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A security vulnerability has been detected in code-projects Real State Services 1.0. NVD: This issue affects some unknown processing of the file /pay.php. NVD: Such manipulation of the argument Bankname leads to sql injection.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260712T161649Z/items/CVE-2026-14769.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes SQL injection risk. Possible impact: An attacker may be able to read or change database-backed application data.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A security vulnerability has been detected in code-projects Real State Services 1.0. NVD: This issue affects some unknown processing of the file /pay.php. NVD: Such manipulation of the argument Bankname leads to sql injection.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14769/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14770/",
      "current_public_safe_latest": false,
      "cvss_score": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.18532,
      "epss_score": 0.00269,
      "first_observed_at": "2026-07-12T16:15:44.451858+00:00",
      "id": "CVE-2026-14770",
      "impact_tags": [
        "SQL injection risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-12T16:15:44.451858+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A vulnerability was detected in SourceCodester Class and Exam Timetabling System 1.0. NVD: Impacted is an unknown function of the file /edit_room.php. NVD: Performing a manipulation of the argument ID results in sql injection.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260712T161649Z/items/CVE-2026-14770.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes SQL injection risk. Possible impact: An attacker may be able to read or change database-backed application data.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability was detected in SourceCodester Class and Exam Timetabling System 1.0. NVD: Impacted is an unknown function of the file /edit_room.php. NVD: Performing a manipulation of the argument ID results in sql injection.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14770/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14771/",
      "current_public_safe_latest": false,
      "cvss_score": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.18532,
      "epss_score": 0.00269,
      "first_observed_at": "2026-07-12T16:15:44.451858+00:00",
      "id": "CVE-2026-14771",
      "impact_tags": [
        "SQL injection risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-12T22:10:37.281882+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A flaw has been found in SourceCodester Class and Exam Timetabling System 1.0/1.php. NVD: The affected element is an unknown function of the file /edit_exam1.php. NVD: Executing a manipulation of the argument ID can lead to sql injection.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260712T221257Z/items/CVE-2026-14771.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes SQL injection risk. Possible impact: An attacker may be able to read or change database-backed application data.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A flaw has been found in SourceCodester Class and Exam Timetabling System 1.0/1.php. NVD: The affected element is an unknown function of the file /edit_exam1.php. NVD: Executing a manipulation of the argument ID can lead to sql injection.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14771/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14772/",
      "current_public_safe_latest": false,
      "cvss_score": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.18533,
      "epss_score": 0.00269,
      "first_observed_at": "2026-07-12T16:15:44.451858+00:00",
      "id": "CVE-2026-14772",
      "impact_tags": [
        "SQL injection risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-12T22:10:37.281882+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A vulnerability has been found in SourceCodester Class and Exam Timetabling System 1.0/1.php. NVD: The impacted element is an unknown function of the file /edit_course1.php. NVD: The manipulation of the argument ID leads to sql injection.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260712T221257Z/items/CVE-2026-14772.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes SQL injection risk. Possible impact: An attacker may be able to read or change database-backed application data.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability has been found in SourceCodester Class and Exam Timetabling System 1.0/1.php. NVD: The impacted element is an unknown function of the file /edit_course1.php. NVD: The manipulation of the argument ID leads to sql injection.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14772/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14773/",
      "current_public_safe_latest": false,
      "cvss_score": 2.1,
      "cvss_severity": "LOW",
      "epss_percentile": 0.10472,
      "epss_score": 0.00204,
      "first_observed_at": "2026-07-12T16:15:44.451858+00:00",
      "id": "CVE-2026-14773",
      "impact_tags": [
        "SQL injection risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-12T22:10:37.281882+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A vulnerability was found in itsourcecode Hospital Management System 1.0. NVD: This affects an unknown function of the file /payment.php. NVD: The manipulation of the argument patientid results in sql injection.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260712T221257Z/items/CVE-2026-14773.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes SQL injection risk. Possible impact: An attacker may be able to read or change database-backed application data.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability was found in itsourcecode Hospital Management System 1.0. NVD: This affects an unknown function of the file /payment.php. NVD: The manipulation of the argument patientid results in sql injection.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14773/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14774/",
      "current_public_safe_latest": false,
      "cvss_score": 2.1,
      "cvss_severity": "LOW",
      "epss_percentile": 0.10472,
      "epss_score": 0.00204,
      "first_observed_at": "2026-07-12T22:10:37.281882+00:00",
      "id": "CVE-2026-14774",
      "impact_tags": [
        "SQL injection risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-12T22:10:37.281882+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A vulnerability was determined in itsourcecode Hospital Management System 1.0. NVD: This impacts an unknown function of the file /paymentdischarge.php. NVD: This manipulation of the argument patientid causes sql injection.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260712T221257Z/items/CVE-2026-14774.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes SQL injection risk. Possible impact: An attacker may be able to read or change database-backed application data.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability was determined in itsourcecode Hospital Management System 1.0. NVD: This impacts an unknown function of the file /paymentdischarge.php. NVD: This manipulation of the argument patientid causes sql injection.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14774/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14775/",
      "current_public_safe_latest": false,
      "cvss_score": 2.1,
      "cvss_severity": "LOW",
      "epss_percentile": 0.11694,
      "epss_score": 0.00214,
      "first_observed_at": "2026-07-12T22:10:37.281882+00:00",
      "id": "CVE-2026-14775",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-12T22:10:37.281882+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A vulnerability was identified in SourceCodester Onlne Examination & Learning Management System 1.0. NVD: Affected is an unknown function of the file /process_lesson.php. NVD: Such manipulation of the argument user_id leads to unrestricted upload.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260712T221257Z/items/CVE-2026-14775.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability was identified in SourceCodester Onlne Examination & Learning Management System 1.0. NVD: Affected is an unknown function of the file /process_lesson.php. NVD: Such manipulation of the argument user_id leads to unrestricted upload.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14775/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14776/",
      "current_public_safe_latest": false,
      "cvss_score": 2.1,
      "cvss_severity": "LOW",
      "epss_percentile": 0.11693,
      "epss_score": 0.00214,
      "first_observed_at": "2026-07-12T22:10:37.281882+00:00",
      "id": "CVE-2026-14776",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-12T22:10:37.281882+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A security flaw has been discovered in SourceCodester Onlne Examination & Learning Management System 1.0. NVD: Affected by this vulnerability is the function pathinfo of the file /upload_files.php of the component Filename Extension. NVD: Performing a manipulation results in unrestricted upload.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260712T221257Z/items/CVE-2026-14776.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A security flaw has been discovered in SourceCodester Onlne Examination & Learning Management System 1.0. NVD: Affected by this vulnerability is the function pathinfo of the file /upload_files.php of the component Filename Extension. NVD: Performing a manipulation results in unrestricted upload.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14776/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14777/",
      "current_public_safe_latest": false,
      "cvss_score": 2.1,
      "cvss_severity": "LOW",
      "epss_percentile": 0.11694,
      "epss_score": 0.00214,
      "first_observed_at": "2026-07-12T22:10:37.281882+00:00",
      "id": "CVE-2026-14777",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-12T22:10:37.281882+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A weakness has been identified in SourceCodester Onlne Examination & Learning Management System 1.0. NVD: Affected by this issue is some unknown functionality of the file /announcements.php. NVD: Executing a manipulation can lead to unrestricted upload.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260712T221257Z/items/CVE-2026-14777.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A weakness has been identified in SourceCodester Onlne Examination & Learning Management System 1.0. NVD: Affected by this issue is some unknown functionality of the file /announcements.php. NVD: Executing a manipulation can lead to unrestricted upload.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14777/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14778/",
      "current_public_safe_latest": false,
      "cvss_score": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.21248,
      "epss_score": 0.00294,
      "first_observed_at": "2026-07-12T22:10:37.281882+00:00",
      "id": "CVE-2026-14778",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-12T22:10:37.281882+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A security vulnerability has been detected in SourceCodester Onlne Examination & Learning Management System 1.0. NVD: This affects an unknown part of the file /ajax_enroll.php of the component Enrollment Management. NVD: The manipulation of the argument student_id/schedule_id/action leads to improper authorization.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260712T221257Z/items/CVE-2026-14778.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A security vulnerability has been detected in SourceCodester Onlne Examination & Learning Management System 1.0. NVD: This affects an unknown part of the file /ajax_enroll.php of the component Enrollment Management. NVD: The manipulation of the argument student_id/schedule_id/action leads to improper authorization.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14778/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14781/",
      "current_public_safe_latest": false,
      "cvss_score": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.09547,
      "epss_score": 0.00196,
      "first_observed_at": "2026-07-12T06:15:25.921412+00:00",
      "id": "CVE-2026-14781",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-12T06:15:25.921412+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A flaw exists in the org.keycloak.broker.oidc package where the OIDC broker incorrectly synchronizes the email_verified claim. NVD: When an OIDC identity provider is configured with trustEmail=true and the userinfo endpoint is enabled, Keycloak retrieves the email address from the userinfo response but retrieves the email_verified status exclusively from the id_token. NVD: The root cause is a lack of validation ensuring that the email_verified claim in the id_token actually refers to the email address returned by the userinfo endpoint.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260712T061643Z/items/CVE-2026-14781.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A flaw exists in the org.keycloak.broker.oidc package where the OIDC broker incorrectly synchronizes the email_verified claim. NVD: When an OIDC identity provider is configured with trustEmail=true and the userinfo endpoint is enabled, Keycloak retrieves the email address from the userinfo response but retrieves the email_verified status exclusively from the id_token. NVD: The root cause is a lack of validation ensuring that the email_verified claim in the id_token actually refers to the email address returned by the userinfo endpoint.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14781/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14783/",
      "current_public_safe_latest": false,
      "cvss_score": 2.1,
      "cvss_severity": "LOW",
      "epss_percentile": 0.25348,
      "epss_score": 0.00333,
      "first_observed_at": "2026-07-12T22:10:37.281882+00:00",
      "id": "CVE-2026-14783",
      "impact_tags": [
        "path traversal review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-12T22:10:37.281882+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A vulnerability was determined in NousResearch hermes-agent 2026.5.29.2. NVD: The impacted element is the function skill_view of the file tools/skills_tool.py. NVD: Executing a manipulation of the argument Name can lead to path traversal.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260712T221257Z/items/CVE-2026-14783.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes path traversal review. Possible impact: An attacker may be able to reach files outside the intended application path.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability was determined in NousResearch hermes-agent 2026.5.29.2. NVD: The impacted element is the function skill_view of the file tools/skills_tool.py. NVD: Executing a manipulation of the argument Name can lead to path traversal.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14783/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14784/",
      "current_public_safe_latest": false,
      "cvss_score": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.13564,
      "epss_score": 0.00228,
      "first_observed_at": "2026-07-12T22:10:37.281882+00:00",
      "id": "CVE-2026-14784",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-12T22:10:37.281882+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A vulnerability was identified in vxcontrol PentAGI up to 2.1.0. NVD: This affects an unknown function of the file backend/pkg/docker/client.go of the component Docker API. NVD: The manipulation leads to sandbox issue.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260712T221257Z/items/CVE-2026-14784.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability was identified in vxcontrol PentAGI up to 2.1.0. NVD: This affects an unknown function of the file backend/pkg/docker/client.go of the component Docker API. NVD: The manipulation leads to sandbox issue.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14784/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "radare / radare2",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14786/",
      "current_public_safe_latest": false,
      "cvss_score": 1.9,
      "cvss_severity": "LOW",
      "epss_percentile": 0.02938,
      "epss_score": 0.00129,
      "first_observed_at": "2026-07-12T22:10:37.281882+00:00",
      "id": "CVE-2026-14786",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-12T22:10:37.281882+00:00",
      "latest_item_url": null,
      "product": "radare2",
      "public_safe_summary": "NVD: A security flaw has been discovered in radareorg radare2 up to 6.1.6. NVD: This impacts the function r_str_word_get0set of the file libr/util/str.c. NVD: The manipulation results in integer overflow.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260712T221257Z/items/CVE-2026-14786.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: radare / radare2",
      "source_published_impact": "This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A security flaw has been discovered in radareorg radare2 up to 6.1.6. NVD: This impacts the function r_str_word_get0set of the file libr/util/str.c. NVD: The manipulation results in integer overflow.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14786/timeline.json",
      "vendor": "radare"
    },
    {
      "affected_label": "radare / radare2",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14787/",
      "current_public_safe_latest": false,
      "cvss_score": 1.9,
      "cvss_severity": "LOW",
      "epss_percentile": 0.03408,
      "epss_score": 0.00136,
      "first_observed_at": "2026-07-12T22:10:37.281882+00:00",
      "id": "CVE-2026-14787",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-12T22:10:37.281882+00:00",
      "latest_item_url": null,
      "product": "radare2",
      "public_safe_summary": "NVD: A weakness has been identified in radareorg radare2 up to 6.1.6. NVD: Affected is the function cmd_print in the library libr/core/cmd_print.inc of the component pb Print Command Handler. NVD: This manipulation causes integer overflow.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260712T221257Z/items/CVE-2026-14787.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: radare / radare2",
      "source_published_impact": "This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A weakness has been identified in radareorg radare2 up to 6.1.6. NVD: Affected is the function cmd_print in the library libr/core/cmd_print.inc of the component pb Print Command Handler. NVD: This manipulation causes integer overflow.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14787/timeline.json",
      "vendor": "radare"
    },
    {
      "affected_label": "radare / radare2",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14788/",
      "current_public_safe_latest": false,
      "cvss_score": 1.9,
      "cvss_severity": "LOW",
      "epss_percentile": 0.0332,
      "epss_score": 0.00135,
      "first_observed_at": "2026-07-12T22:10:37.281882+00:00",
      "id": "CVE-2026-14788",
      "impact_tags": [
        "memory safety review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-12T22:10:37.281882+00:00",
      "latest_item_url": null,
      "product": "radare2",
      "public_safe_summary": "NVD: A security vulnerability has been detected in radareorg radare2 up to 6.1.6. NVD: Affected by this vulnerability is the function r_core_bin_load of the file libr/core/cfile.c. NVD: Such manipulation leads to use after free.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260712T221257Z/items/CVE-2026-14788.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: radare / radare2",
      "source_published_impact": "Source describes memory safety review. Possible impact: The affected component has memory-safety risk that may lead to crash, privilege, or code-execution impact depending on exposure.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A security vulnerability has been detected in radareorg radare2 up to 6.1.6. NVD: Affected by this vulnerability is the function r_core_bin_load of the file libr/core/cfile.c. NVD: Such manipulation leads to use after free.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14788/timeline.json",
      "vendor": "radare"
    },
    {
      "affected_label": "radare / radare2",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14789/",
      "current_public_safe_latest": false,
      "cvss_score": 1.9,
      "cvss_severity": "LOW",
      "epss_percentile": 0.04873,
      "epss_score": 0.00153,
      "first_observed_at": "2026-07-12T22:10:37.281882+00:00",
      "id": "CVE-2026-14789",
      "impact_tags": [
        "memory safety review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-12T22:10:37.281882+00:00",
      "latest_item_url": null,
      "product": "radare2",
      "public_safe_summary": "NVD: A vulnerability was detected in radareorg radare2 up to 6.1.6. NVD: Affected by this issue is some unknown functionality of the file libr/bin/format/mdmp/mdmp.c of the component Memory64ListStream Parser. NVD: Performing a manipulation results in stack-based buffer overflow.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260712T221257Z/items/CVE-2026-14789.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: radare / radare2",
      "source_published_impact": "Source describes memory safety review. Possible impact: The affected component has memory-safety risk that may lead to crash, privilege, or code-execution impact depending on exposure.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability was detected in radareorg radare2 up to 6.1.6. NVD: Affected by this issue is some unknown functionality of the file libr/bin/format/mdmp/mdmp.c of the component Memory64ListStream Parser. NVD: Performing a manipulation results in stack-based buffer overflow.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14789/timeline.json",
      "vendor": "radare"
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14800/",
      "current_public_safe_latest": false,
      "cvss_score": 2.1,
      "cvss_severity": "LOW",
      "epss_percentile": 0.05415,
      "epss_score": 0.00159,
      "first_observed_at": "2026-07-13T06:32:51.098771+00:00",
      "id": "CVE-2026-14800",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-13T06:32:51.098771+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A weakness has been identified in imhamzaazam ecommerceFlask up to cb7d9e24c30a99379651b7493b32048126ef402b. NVD: The affected element is an unknown function. NVD: This manipulation causes cross-site request forgery.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260713T063521Z/items/CVE-2026-14800.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A weakness has been identified in imhamzaazam ecommerceFlask up to cb7d9e24c30a99379651b7493b32048126ef402b. NVD: The affected element is an unknown function. NVD: This manipulation causes cross-site request forgery.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14800/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14801/",
      "current_public_safe_latest": false,
      "cvss_score": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.01639,
      "epss_score": 0.00112,
      "first_observed_at": "2026-07-13T06:32:51.098771+00:00",
      "id": "CVE-2026-14801",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-13T06:32:51.098771+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A security vulnerability has been detected in GPAC 26.03-DEV-rev342-g80071f700-master. NVD: The impacted element is the function txtin_probe_duration of the file src/filters/load_text.c of the component TeXML File Handler. NVD: Such manipulation of the argument txml_timescale leads to divide by zero.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260713T063521Z/items/CVE-2026-14801.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A security vulnerability has been detected in GPAC 26.03-DEV-rev342-g80071f700-master. NVD: The impacted element is the function txtin_probe_duration of the file src/filters/load_text.c of the component TeXML File Handler. NVD: Such manipulation of the argument txml_timescale leads to divide by zero.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14801/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14802/",
      "current_public_safe_latest": false,
      "cvss_score": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.6757,
      "epss_score": 0.01324,
      "first_observed_at": "2026-07-13T06:32:51.098771+00:00",
      "id": "CVE-2026-14802",
      "impact_tags": [
        "command injection risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-13T06:32:51.098771+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A vulnerability was detected in react create-react-app up to 5.0.1 on macOS. NVD: This affects the function startBrowserProcess of the file openBrowser.js of the component react-dev-utils. NVD: Performing a manipulation results in os command injection.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260713T063521Z/items/CVE-2026-14802.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes command injection risk. Possible impact: An attacker may be able to run unintended system commands through the affected component.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability was detected in react create-react-app up to 5.0.1 on macOS. NVD: This affects the function startBrowserProcess of the file openBrowser.js of the component react-dev-utils. NVD: Performing a manipulation results in os command injection.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14802/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14803/",
      "current_public_safe_latest": false,
      "cvss_score": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.25027,
      "epss_score": 0.0033,
      "first_observed_at": "2026-07-12T22:10:37.281882+00:00",
      "id": "CVE-2026-14803",
      "impact_tags": [
        "service availability review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-12T22:10:37.281882+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Mojo::JSON versions before 9.47 for Perl allow memory exhaustion via unbounded recursion in the pure-Perl decoder. NVD: The pure-Perl decode path (_decode_value dispatching to _decode_array and _decode_object) recurses with no depth limit, so a small deeply nested JSON document can consume excessive memory. NVD: This path is the default when Cpanel::JSON::XS is not installed or MOJO_NO_JSON_XS=1 is set; the Cpanel::JSON::XS fast path is not affected.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260712T221257Z/items/CVE-2026-14803.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes service availability risk. Possible impact: The affected service may become unavailable or unreliable.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Mojo::JSON versions before 9.47 for Perl allow memory exhaustion via unbounded recursion in the pure-Perl decoder. NVD: The pure-Perl decode path (_decode_value dispatching to _decode_array and _decode_object) recurses with no depth limit, so a small deeply nested JSON document can consume excessive memory. NVD: This path is the default when Cpanel::JSON::XS is not installed or MOJO_NO_JSON_XS=1 is set; the Cpanel::JSON::XS fast path is not affected.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14803/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14804/",
      "current_public_safe_latest": false,
      "cvss_score": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.22831,
      "epss_score": 0.00305,
      "first_observed_at": "2026-08-11T10:14:04.199465+00:00",
      "id": "CVE-2026-14804",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-11T10:14:04.199465+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Use of hard-coded cryptographic key vulnerability in Bilin Software and Informatics Consultancy Inc. NVD: HUMANIST Digital Human Resources allows Read Sensitive Constants Within an Executable. NVD: This issue affects HUMANIST Digital Human Resources: from 26.0 before 26.1.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260811T102539Z/items/CVE-2026-14804.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Use of hard-coded cryptographic key vulnerability in Bilin Software and Informatics Consultancy Inc. NVD: HUMANIST Digital Human Resources allows Read Sensitive Constants Within an Executable. NVD: This issue affects HUMANIST Digital Human Resources: from 26.0 before 26.1.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14804/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14807/",
      "current_public_safe_latest": false,
      "cvss_score": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.3705,
      "epss_score": 0.00463,
      "first_observed_at": "2026-07-13T06:32:51.098771+00:00",
      "id": "CVE-2026-14807",
      "impact_tags": [
        "remote exposure relevant"
      ],
      "kev": false,
      "last_observed_at": "2026-07-13T06:32:51.098771+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: ERP App developed by PROG MIS has a Use of Hard-coded Credentials vulnerability, allowing unauthenticated remote attackers to log in to view application code and obtain the database account and password.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260713T063521Z/items/CVE-2026-14807.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes remote exposure. Possible impact: This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: ERP App developed by PROG MIS has a Use of Hard-coded Credentials vulnerability, allowing unauthenticated remote attackers to log in to view application code and obtain the database account and password.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14807/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14808/",
      "current_public_safe_latest": false,
      "cvss_score": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.39712,
      "epss_score": 0.00507,
      "first_observed_at": "2026-07-13T06:32:51.098771+00:00",
      "id": "CVE-2026-14808",
      "impact_tags": [
        "remote exposure relevant"
      ],
      "kev": false,
      "last_observed_at": "2026-07-13T06:32:51.098771+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Prog Management System developed by PROG MIS has a Exposure of Sensitive Information vulnerability, allowing unauthenticated remote attackers to view a specific page and obtain the database account and password.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260713T063521Z/items/CVE-2026-14808.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes remote exposure. Possible impact: This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Prog Management System developed by PROG MIS has a Exposure of Sensitive Information vulnerability, allowing unauthenticated remote attackers to view a specific page and obtain the database account and password.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14808/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14809/",
      "current_public_safe_latest": false,
      "cvss_score": 8.7,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.35275,
      "epss_score": 0.00437,
      "first_observed_at": "2026-07-13T06:32:51.098771+00:00",
      "id": "CVE-2026-14809",
      "impact_tags": [
        "SQL injection risk",
        "remote exposure relevant"
      ],
      "kev": false,
      "last_observed_at": "2026-07-13T06:32:51.098771+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Prog Management System developed by PROG MIS has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read database contents.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260713T063521Z/items/CVE-2026-14809.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes SQL injection risk · remote exposure. Possible impact: A remote attacker may be able to read or change database-backed application data.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Prog Management System developed by PROG MIS has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read database contents.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14809/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14816/",
      "current_public_safe_latest": false,
      "cvss_score": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.16342,
      "epss_score": 0.0025,
      "first_observed_at": "2026-08-11T04:43:10.985977+00:00",
      "id": "CVE-2026-14816",
      "impact_tags": [
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-11T04:43:10.985977+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The GDPR Framework By Data443 WordPress plugin before 2.4.0 does not properly verify authorization or the identity of the data subject when recording cookie-consent choices and privacy requests, allowing unauthenticated attackers to forge consent records for...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260811T044729Z/items/CVE-2026-14816.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes remote exposure · authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The GDPR Framework By Data443 WordPress plugin before 2.4.0 does not properly verify authorization or the identity of the data subject when recording cookie-consent choices and privacy requests, allowing unauthenticated attackers to forge consent records for...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14816/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14817/",
      "current_public_safe_latest": false,
      "cvss_score": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.21218,
      "epss_score": 0.0029,
      "first_observed_at": "2026-08-08T15:50:31.311576+00:00",
      "id": "CVE-2026-14817",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-09T04:40:09.231782+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Element Pack Addons for Elementor WordPress plugin before 8.7.13 does not sanitize option values passed through certain data attributes before a bundled front-end library re-parses and renders them in the browser, allowing users with contributor-level...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260809T044412Z/items/CVE-2026-14817.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 3,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Element Pack Addons for Elementor WordPress plugin before 8.7.13 does not sanitize option values passed through certain data attributes before a bundled front-end library re-parses and renders them in the browser, allowing users with contributor-level...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14817/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14819/",
      "current_public_safe_latest": false,
      "cvss_score": 3.5,
      "cvss_severity": "LOW",
      "epss_percentile": 0.03999,
      "epss_score": 0.00142,
      "first_observed_at": "2026-08-04T06:07:04.591309+00:00",
      "id": "CVE-2026-14819",
      "impact_tags": [
        "XSS risk"
      ],
      "kev": false,
      "last_observed_at": "2026-08-04T06:07:04.591309+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Event Tickets and Registration WordPress plugin before 5.28.4 does not properly escape event titles before outputting them in a ticket history log, allowing users with the Editor role and above to perform Stored Cross-Site Scripting attacks that execute...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260804T061658Z/items/CVE-2026-14819.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes XSS risk. Possible impact: This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Event Tickets and Registration WordPress plugin before 5.28.4 does not properly escape event titles before outputting them in a ticket history log, allowing users with the Editor role and above to perform Stored Cross-Site Scripting attacks that execute...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14819/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14821/",
      "current_public_safe_latest": false,
      "cvss_score": 2.7,
      "cvss_severity": "LOW",
      "epss_percentile": 0.06494,
      "epss_score": 0.00168,
      "first_observed_at": "2026-08-04T06:07:04.591309+00:00",
      "id": "CVE-2026-14821",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-04T06:07:04.591309+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Quiz and Survey Master (QSM) WordPress plugin before 11.1.5 does not perform a capability check before deleting output templates, allowing users with contributor-level access and above to delete arbitrary templates.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260804T061658Z/items/CVE-2026-14821.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Quiz and Survey Master (QSM) WordPress plugin before 11.1.5 does not perform a capability check before deleting output templates, allowing users with contributor-level access and above to delete arbitrary templates.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14821/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14824/",
      "current_public_safe_latest": false,
      "cvss_score": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.06945,
      "epss_score": 0.00173,
      "first_observed_at": "2026-08-11T04:43:10.985977+00:00",
      "id": "CVE-2026-14824",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-11T04:43:10.985977+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Quiz and Survey Master (QSM) WordPress plugin before 11.2.2 does not properly escape a question setting before outputting it into an unquoted HTML attribute, allowing users with contributor-level access and above to inject arbitrary JavaScript that...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260811T044729Z/items/CVE-2026-14824.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Quiz and Survey Master (QSM) WordPress plugin before 11.2.2 does not properly escape a question setting before outputting it into an unquoted HTML attribute, allowing users with contributor-level access and above to inject arbitrary JavaScript that...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14824/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14838/",
      "current_public_safe_latest": false,
      "cvss_score": 7.4,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.17279,
      "epss_score": 0.00257,
      "first_observed_at": "2026-08-11T10:14:04.199465+00:00",
      "id": "CVE-2026-14838",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-11T10:14:04.199465+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Use of GET request method with sensitive query strings vulnerability in Bilin Software and Informatics Consultancy Inc. NVD: HUMANIST Digital Human Resources allows Session Hijacking. NVD: This issue affects HUMANIST Digital Human Resources: from 26.0 before 26.1.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260811T102539Z/items/CVE-2026-14838.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Use of GET request method with sensitive query strings vulnerability in Bilin Software and Informatics Consultancy Inc. NVD: HUMANIST Digital Human Resources allows Session Hijacking. NVD: This issue affects HUMANIST Digital Human Resources: from 26.0 before 26.1.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14838/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14841/",
      "current_public_safe_latest": false,
      "cvss_score": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.07824,
      "epss_score": 0.00181,
      "first_observed_at": "2026-08-08T15:50:31.311576+00:00",
      "id": "CVE-2026-14841",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-09T04:40:09.231782+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The King Addons for Elementor WordPress plugin before 51.1.76 does not escape a user-supplied grid setting before reflecting it into an HTML attribute in an unauthenticated AJAX response, allowing attackers to execute arbitrary JavaScript in the browser of a...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260809T044412Z/items/CVE-2026-14841.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 3,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The King Addons for Elementor WordPress plugin before 51.1.76 does not escape a user-supplied grid setting before reflecting it into an HTML attribute in an unauthenticated AJAX response, allowing attackers to execute arbitrary JavaScript in the browser of a...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14841/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14848/",
      "current_public_safe_latest": false,
      "cvss_score": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.06591,
      "epss_score": 0.0017,
      "first_observed_at": "2026-08-11T04:43:10.985977+00:00",
      "id": "CVE-2026-14848",
      "impact_tags": [
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-11T04:43:10.985977+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Paid Membership Subscriptions WordPress plugin before 3.0.8 does not verify that the subscription being modified through its change-subscription checkout belongs to the current user, allowing any authenticated user with Subscriber-level access and above...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260811T044729Z/items/CVE-2026-14848.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Paid Membership Subscriptions WordPress plugin before 3.0.8 does not verify that the subscription being modified through its change-subscription checkout belongs to the current user, allowing any authenticated user with Subscriber-level access and above...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14848/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14864/",
      "current_public_safe_latest": false,
      "cvss_score": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.03216,
      "epss_score": 0.00133,
      "first_observed_at": "2026-08-08T15:50:31.311576+00:00",
      "id": "CVE-2026-14864",
      "impact_tags": [
        "XSS risk"
      ],
      "kev": false,
      "last_observed_at": "2026-08-09T04:40:09.231782+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The JetEngine WordPress plugin before 3.8.12 does not escape a post meta value before outputting it through one of its shortcodes, allowing users with the Contributor role and above to perform Stored Cross-Site Scripting attacks that execute in the context of...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260809T044412Z/items/CVE-2026-14864.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 3,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes XSS risk. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The JetEngine WordPress plugin before 3.8.12 does not escape a post meta value before outputting it through one of its shortcodes, allowing users with the Contributor role and above to perform Stored Cross-Site Scripting attacks that execute in the context of...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14864/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14870/",
      "current_public_safe_latest": false,
      "cvss_score": 7.1,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.04344,
      "epss_score": 0.00146,
      "first_observed_at": "2026-08-04T06:07:04.591309+00:00",
      "id": "CVE-2026-14870",
      "impact_tags": [
        "XSS risk"
      ],
      "kev": false,
      "last_observed_at": "2026-08-04T06:07:04.591309+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Database for Contact Form 7, WPforms, Elementor forms WordPress plugin before 1.5.3 does not properly sanitise and escape a parameter before reflecting it back in an admin page, leading to a Reflected Cross-Site Scripting which could be used against high...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260804T061658Z/items/CVE-2026-14870.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes XSS risk. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Database for Contact Form 7, WPforms, Elementor forms WordPress plugin before 1.5.3 does not properly sanitise and escape a parameter before reflecting it back in an admin page, leading to a Reflected Cross-Site Scripting which could be used against high...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14870/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14872/",
      "current_public_safe_latest": false,
      "cvss_score": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.13884,
      "epss_score": 0.00231,
      "first_observed_at": "2026-08-11T04:43:10.985977+00:00",
      "id": "CVE-2026-14872",
      "impact_tags": [
        "SQL injection risk"
      ],
      "kev": false,
      "last_observed_at": "2026-08-11T04:43:10.985977+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Database for Contact Form 7, WPforms, Elementor forms WordPress plugin before 1.5.5 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL Injection exploitable by users granted a specific capability which...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260811T044729Z/items/CVE-2026-14872.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes SQL injection risk. Possible impact: An attacker may be able to read or change database-backed application data.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Database for Contact Form 7, WPforms, Elementor forms WordPress plugin before 1.5.5 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL Injection exploitable by users granted a specific capability which...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14872/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14895/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.31378,
      "epss_score": 0.00392,
      "first_observed_at": "2026-07-14T22:16:58.989760+00:00",
      "id": "CVE-2026-14895",
      "impact_tags": [
        "service availability review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-14T22:16:58.989760+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: String::Util versions before 1.36 for Perl are susceptible to a regular expression denial of service. NVD: The trim and rtrim functions stripped trailing whitespace with s/\\s*$//u. NVD: Because \\s* matches greedily and the $ anchor fails whenever a non-whitespace character follows the whitespace, the regex engine retries the match at each offset of a long whitespace run, producing quadratic backtracking.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260714T222111Z/items/CVE-2026-14895.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes service availability risk. Possible impact: The affected service may become unavailable or unreliable.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: String::Util versions before 1.36 for Perl are susceptible to a regular expression denial of service. NVD: The trim and rtrim functions stripped trailing whitespace with s/\\s*$//u. NVD: Because \\s* matches greedily and the $ anchor fails whenever a non-whitespace character follows the whitespace, the regex engine retries the match at each offset of a long whitespace run, producing quadratic backtracking.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14895/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14898/",
      "current_public_safe_latest": false,
      "cvss_score": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.12626,
      "epss_score": 0.00221,
      "first_observed_at": "2026-07-13T17:24:46.617207+00:00",
      "id": "CVE-2026-14898",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-13T17:24:46.617207+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The OpenAI Codex desktop app for macOS rendered remote images from Markdown in model responses. NVD: An attacker who could place an indirect prompt injection in content processed by Codex, such as a connected-tool result or another untrusted source, could induce the model to construct a remote image URL containing sensitive data. NVD: The app automatically fetched that URL when rendering the response, sending the embedded data to an attacker-controlled server without a separate user click.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260713T172750Z/items/CVE-2026-14898.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The OpenAI Codex desktop app for macOS rendered remote images from Markdown in model responses. NVD: An attacker who could place an indirect prompt injection in content processed by Codex, such as a connected-tool result or another untrusted source, could induce the model to construct a remote image URL containing sensitive data. NVD: The app automatically fetched that URL when rendering the response, sending the embedded data to an attacker-controlled server without a separate user click.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14898/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14904/",
      "current_public_safe_latest": false,
      "cvss_score": 7.1,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.30254,
      "epss_score": 0.00381,
      "first_observed_at": "2026-07-14T16:41:04.043226+00:00",
      "id": "CVE-2026-14904",
      "impact_tags": [
        "admin privilege risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-14T16:41:04.043226+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: AWS Research and Engineering Studio (RES) is an open-source solution that enables researchers and engineers to create and manage secure virtual desktops and computing resources on AWS. NVD: Improper link resolution before file access issue (CWE-59) in the Auth.GetUserPrivateKey API. NVD: An authenticated remote user could read arbitrary files on the cluster-manager EC2 instance by replacing their SSH private key file (~/.ssh/id_rsa) with a symbolic link targeting any file on the host.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260714T164406Z/items/CVE-2026-14904.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes admin privilege risk. Possible impact: An attacker may gain root or administrative-level privileges on affected systems.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: RES.",
      "source_published_summary": "NVD: AWS Research and Engineering Studio (RES) is an open-source solution that enables researchers and engineers to create and manage secure virtual desktops and computing resources on AWS. NVD: Improper link resolution before file access issue (CWE-59) in the Auth.GetUserPrivateKey API. NVD: An authenticated remote user could read arbitrary files on the cluster-manager EC2 instance by replacing their SSH private key file (~/.ssh/id_rsa) with a symbolic link targeting any file on the host.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14904/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14920/",
      "current_public_safe_latest": false,
      "cvss_score": 8.2,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.19535,
      "epss_score": 0.00274,
      "first_observed_at": "2026-08-08T15:50:31.311576+00:00",
      "id": "CVE-2026-14920",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-09T04:40:09.231782+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: ## Summary",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260809T044412Z/items/CVE-2026-14920.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 3,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: ## Summary",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14920/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14924/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.16839,
      "epss_score": 0.00253,
      "first_observed_at": "2026-08-04T06:07:04.591309+00:00",
      "id": "CVE-2026-14924",
      "impact_tags": [
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-04T06:07:04.591309+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Tablesome Table WordPress plugin before 1.1.31 does not perform any authentication, capability, or nonce checks in one of its AJAX actions, allowing unauthenticated users to create new published posts and to overwrite arbitrary existing posts and pages.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260804T061658Z/items/CVE-2026-14924.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes authenticated boundary. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Tablesome Table WordPress plugin before 1.1.31 does not perform any authentication, capability, or nonce checks in one of its AJAX actions, allowing unauthenticated users to create new published posts and to overwrite arbitrary existing posts and pages.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14924/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14926/",
      "current_public_safe_latest": false,
      "cvss_score": 4.2,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.04128,
      "epss_score": 0.00144,
      "first_observed_at": "2026-08-04T06:07:04.591309+00:00",
      "id": "CVE-2026-14926",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-04T06:07:04.591309+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The FluentCart A New Era of eCommerce WordPress plugin before 1.4.0 does not verify that a subscription belongs to the requesting customer in several of its payment-method endpoints, allowing any authenticated customer to act on another customer's...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260804T061658Z/items/CVE-2026-14926.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The FluentCart A New Era of eCommerce WordPress plugin before 1.4.0 does not verify that a subscription belongs to the requesting customer in several of its payment-method endpoints, allowing any authenticated customer to act on another customer's...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14926/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14935/",
      "current_public_safe_latest": false,
      "cvss_score": 3.7,
      "cvss_severity": "LOW",
      "epss_percentile": 0.04656,
      "epss_score": 0.0015,
      "first_observed_at": "2026-07-14T10:57:43.777280+00:00",
      "id": "CVE-2026-14935",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-14T10:57:43.777280+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A logic vulnerability was found in GStreamer's webrtcbin component. NVD: The _check_sdp_crypto() function contains an inverted boolean condition that causes it to accept remote SDP offers or answers that lack the required a=fingerprint attribute, while incorrectly rejecting those that include it. NVD: An attacker with the ability to intercept and modify WebRTC signaling messages could exploit this to bypass the SDP-level DTLS certificate fingerprint binding, weakening defenses against man-in-the-middle attacks on media streams.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260714T110007Z/items/CVE-2026-14935.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A logic vulnerability was found in GStreamer's webrtcbin component. NVD: The _check_sdp_crypto() function contains an inverted boolean condition that causes it to accept remote SDP offers or answers that lack the required a=fingerprint attribute, while incorrectly rejecting those that include it. NVD: An attacker with the ability to intercept and modify WebRTC signaling messages could exploit this to bypass the SDP-level DTLS certificate fingerprint binding, weakening defenses against man-in-the-middle attacks on media streams.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14935/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14938/",
      "current_public_safe_latest": false,
      "cvss_score": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.05798,
      "epss_score": 0.00162,
      "first_observed_at": "2026-08-08T15:50:31.311576+00:00",
      "id": "CVE-2026-14938",
      "impact_tags": [
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-09T04:40:09.231782+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The FluentBoards WordPress plugin before 1.95.3 does not verify that the items selected for a board import operation belong to a board the requesting user is authorized to access, allowing any authenticated user with member access to a single board to copy...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260809T044412Z/items/CVE-2026-14938.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 3,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The FluentBoards WordPress plugin before 1.95.3 does not verify that the items selected for a board import operation belong to a board the requesting user is authorized to access, allowing any authenticated user with member access to a single board to copy...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14938/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14939/",
      "current_public_safe_latest": false,
      "cvss_score": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.1441,
      "epss_score": 0.00235,
      "first_observed_at": "2026-08-11T04:43:10.985977+00:00",
      "id": "CVE-2026-14939",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-11T04:43:10.985977+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Visualizer WordPress plugin before 4.0.6 does not restrict a user-supplied URL to safe address ranges before fetching it server-side, allowing users with Contributor-level access and above to perform Server-Side Request Forgery against link-local... NVD: As the fetched response is returned in the reply, the attack is non-blind, enabling retrieval of cloud instance metadata (including IAM credentials) on cloud-hosted sites.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260811T044729Z/items/CVE-2026-14939.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Visualizer WordPress plugin before 4.0.6 does not restrict a user-supplied URL to safe address ranges before fetching it server-side, allowing users with Contributor-level access and above to perform Server-Side Request Forgery against link-local... NVD: As the fetched response is returned in the reply, the attack is non-blind, enabling retrieval of cloud instance metadata (including IAM credentials) on cloud-hosted sites.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14939/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "redhat / directory_server",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14940/",
      "current_public_safe_latest": false,
      "cvss_score": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.21217,
      "epss_score": 0.00294,
      "first_observed_at": "2026-07-14T10:57:43.777280+00:00",
      "id": "CVE-2026-14940",
      "impact_tags": [
        "service availability review",
        "remote exposure relevant"
      ],
      "kev": false,
      "last_observed_at": "2026-07-14T10:57:43.777280+00:00",
      "latest_item_url": null,
      "product": "directory_server",
      "public_safe_summary": "NVD: A heap-buffer-overflow flaw was found in 389 Directory Server (389-ds-base). NVD: When normalizing a Distinguished Name (DN) that contains a legacy-quoted value encoding a multivalued nested Relative Distinguished Name (RDN), the server can write past the end of a heap allocation while sorting RDN attribute-value pairs. NVD: An unauthenticated remote attacker can trigger this condition by sending an LDAP operation whose DN reaches the DN normalization routine, such as a search with a crafted base DN.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260714T110007Z/items/CVE-2026-14940.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: redhat / directory_server; affected version context: -, 10.0, 11.0, 12.0, 13.0",
      "source_published_impact": "Source describes service availability risk · remote exposure. Possible impact: The affected service may become unavailable or unreliable.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A heap-buffer-overflow flaw was found in 389 Directory Server (389-ds-base). NVD: When normalizing a Distinguished Name (DN) that contains a legacy-quoted value encoding a multivalued nested Relative Distinguished Name (RDN), the server can write past the end of a heap allocation while sorting RDN attribute-value pairs. NVD: An unauthenticated remote attacker can trigger this condition by sending an LDAP operation whose DN reaches the DN normalization routine, such as a search with a crafted base DN.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14940/timeline.json",
      "vendor": "redhat"
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14955/",
      "current_public_safe_latest": false,
      "cvss_score": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.41635,
      "epss_score": 0.00526,
      "first_observed_at": "2026-07-31T22:17:39.455090+00:00",
      "id": "CVE-2026-14955",
      "impact_tags": [
        "information exposure review",
        "path traversal review",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-01T06:11:07.668739+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Checkout Field Editor for WooCommerce (Pro) plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.7.7 via the 'thwcfe_legacy_file' parameter. NVD: This makes it possible for authenticated attackers, with subscriber-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260801T061801Z/items/CVE-2026-14955.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes information exposure review · path traversal review · authenticated boundary. Possible impact: An attacker may be able to reach files outside the intended application path.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Checkout Field Editor for WooCommerce (Pro) plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.7.7 via the 'thwcfe_legacy_file' parameter. NVD: This makes it possible for authenticated attackers, with subscriber-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14955/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14956/",
      "current_public_safe_latest": false,
      "cvss_score": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.27631,
      "epss_score": 0.00351,
      "first_observed_at": "2026-07-23T22:18:14.498937+00:00",
      "id": "CVE-2026-14956",
      "impact_tags": [
        "privilege boundary review",
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-23T22:18:14.498937+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Bricksforge plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.1.8.6. NVD: This is due to improper validation of the fieldIds parameter in the Pro Forms registration action, which allows attacker-supplied field IDs to be added to the trusted form-field whitelist. NVD: This makes it possible for unauthenticated attackers to register a new administrator account by submitting a crafted request to a publicly accessible Bricksforge Pro Forms registration form.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260723T222557Z/items/CVE-2026-14956.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes privilege escalation risk · remote exposure · authenticated boundary. Possible impact: A remote attacker may cross a privilege boundary and gain more access than intended.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Bricksforge plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.1.8.6. NVD: This is due to improper validation of the fieldIds parameter in the Pro Forms registration action, which allows attacker-supplied field IDs to be added to the trusted form-field whitelist. NVD: This makes it possible for unauthenticated attackers to register a new administrator account by submitting a crafted request to a publicly accessible Bricksforge Pro Forms registration form.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14956/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "redhat / directory_server",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14969/",
      "current_public_safe_latest": false,
      "cvss_score": 4.4,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.00157,
      "epss_score": 0.00077,
      "first_observed_at": "2026-07-14T10:57:43.777280+00:00",
      "id": "CVE-2026-14969",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-14T10:57:43.777280+00:00",
      "latest_item_url": null,
      "product": "directory_server",
      "public_safe_summary": "NVD: A flaw was found in 389-ds-base where the LDBM backend attribute encryption uses a hardcoded static initialization vector for AES-CBC and 3DES-CBC operations, allowing an attacker with privileged filesystem access to detect plaintext equality across encrypted...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260714T110007Z/items/CVE-2026-14969.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: redhat / directory_server; affected version context: -, 10.0, 11.0, 12.0, 13.0",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A flaw was found in 389-ds-base where the LDBM backend attribute encryption uses a hardcoded static initialization vector for AES-CBC and 3DES-CBC operations, allowing an attacker with privileged filesystem access to detect plaintext equality across encrypted...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14969/timeline.json",
      "vendor": "redhat"
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14987/",
      "current_public_safe_latest": false,
      "cvss_score": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.10778,
      "epss_score": 0.00206,
      "first_observed_at": "2026-07-22T22:28:24.662524+00:00",
      "id": "CVE-2026-14987",
      "impact_tags": [
        "XSS risk",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-22T22:28:24.662524+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'twitter_message' Sequoia Template Setting in all versions up to, and including, 4.16.3 due to insufficient input sanitization and... NVD: This makes it possible for authenticated attackers, with give worker-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. NVD: The injected script executes specifically when a donor clicks the Share on Twitter button on the Sequoia donation confirmation view, as that is when the unescaped twitter_message value is evaluated inside the JavaScript template literal.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260722T223443Z/items/CVE-2026-14987.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes XSS risk · authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'twitter_message' Sequoia Template Setting in all versions up to, and including, 4.16.3 due to insufficient input sanitization and... NVD: This makes it possible for authenticated attackers, with give worker-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. NVD: The injected script executes specifically when a donor clicks the Share on Twitter button on the Sequoia donation confirmation view, as that is when the unescaped twitter_message value is evaluated inside the JavaScript template literal.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14987/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15003/",
      "current_public_safe_latest": false,
      "cvss_score": 5.6,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.01285,
      "epss_score": 0.00106,
      "first_observed_at": "2026-08-03T12:38:03.310457+00:00",
      "id": "CVE-2026-15003",
      "impact_tags": [
        "information exposure review",
        "service availability review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-03T12:38:03.310457+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A flaw was found in the GNU Binutils (Binary Utilities) linker. NVD: This vulnerability, a heap-buffer-overflow read (CWE-125), occurs when the linker processes a specially crafted 32-bit XCOFF (Extended Common Object File Format) object file. NVD: An attacker could exploit this by providing a malicious file, leading to an out-of-bounds read of memory.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260803T124716Z/items/CVE-2026-15003.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes information exposure review · service availability risk. Possible impact: An attacker may be able to access information that should not be exposed.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A flaw was found in the GNU Binutils (Binary Utilities) linker. NVD: This vulnerability, a heap-buffer-overflow read (CWE-125), occurs when the linker processes a specially crafted 32-bit XCOFF (Extended Common Object File Format) object file. NVD: An attacker could exploit this by providing a malicious file, leading to an out-of-bounds read of memory.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15003/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15005/",
      "current_public_safe_latest": false,
      "cvss_score": 8.8,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.11529,
      "epss_score": 0.00211,
      "first_observed_at": "2026-07-23T06:13:21.015514+00:00",
      "id": "CVE-2026-15005",
      "impact_tags": [
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-23T06:13:21.015514+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Loco Translate plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.8.5. NVD: This is due to missing or incorrect nonce validation on the execTemplate function. NVD: This makes it possible for unauthenticated attackers to execute arbitrary PHP code on the server by supplying a php://filter stream wrapper URI as the 'template' parameter, which bypasses path validation and is passed directly to the include sink in...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260723T061547Z/items/CVE-2026-15005.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes remote exposure · authenticated boundary. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Loco Translate plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.8.5. NVD: This is due to missing or incorrect nonce validation on the execTemplate function. NVD: This makes it possible for unauthenticated attackers to execute arbitrary PHP code on the server by supplying a php://filter stream wrapper URI as the 'template' parameter, which bypasses path validation and is passed directly to the include sink in...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15005/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15006/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.54283,
      "epss_score": 0.00835,
      "first_observed_at": "2026-08-07T21:58:42.606809+00:00",
      "id": "CVE-2026-15006",
      "impact_tags": [
        "information exposure review",
        "path traversal review",
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-07T21:58:42.606809+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Bit integrations – Form Integration, Webhook, Spreadsheets, CRM, LMS & Email Automation plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.9.0 via the processAttachment function. NVD: This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260807T220457Z/items/CVE-2026-15006.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes information exposure review · path traversal review · remote exposure. Possible impact: A remote attacker may be able to reach files outside the intended application path.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Bit integrations – Form Integration, Webhook, Spreadsheets, CRM, LMS & Email Automation plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.9.0 via the processAttachment function. NVD: This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15006/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15010/",
      "current_public_safe_latest": false,
      "cvss_score": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.11026,
      "epss_score": 0.00208,
      "first_observed_at": "2026-07-18T05:38:40.092323+00:00",
      "id": "CVE-2026-15010",
      "impact_tags": [
        "XSS risk",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-18T07:15:27.585758+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The bbp Style Pack plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 6.4.5 via the Topic Form Additional Fields feature. NVD: This is due to insufficient input sanitization in bsp_topic_fields_form_save() (which writes $_POST['bsp_topic_fields_label{n}'] directly to post meta via update_post_meta() with no filtering) and missing output escaping in... NVD: This makes it possible for authenticated attackers, with Subscriber-level access and above (who have bbPress topic-creation privileges), to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page, including...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260718T071858Z/items/CVE-2026-15010.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes XSS risk · authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The bbp Style Pack plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 6.4.5 via the Topic Form Additional Fields feature. NVD: This is due to insufficient input sanitization in bsp_topic_fields_form_save() (which writes $_POST['bsp_topic_fields_label{n}'] directly to post meta via update_post_meta() with no filtering) and missing output escaping in... NVD: This makes it possible for authenticated attackers, with Subscriber-level access and above (who have bbPress topic-creation privileges), to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page, including...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15010/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15012/",
      "current_public_safe_latest": false,
      "cvss_score": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.24172,
      "epss_score": 0.00317,
      "first_observed_at": "2026-08-04T06:07:04.591309+00:00",
      "id": "CVE-2026-15012",
      "impact_tags": [
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-04T06:07:04.591309+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Demi – One Click Demo Import, WP Backup & Site Migration plugin for WordPress is vulnerable to Arbitrary Directory Copy in all versions up to, and including, 0.0.8 via the handle_restore_step function. NVD: This is due to missing HTTP access controls on the wp-content/uploads/demi-backup-state/ directory, which exposes the cryptographic restore key used to both authenticate the unauthenticated AJAX handler and forge signed restore-state envelopes. NVD: This makes it possible for unauthenticated attackers to copy arbitrary files to attacker-controlled destinations on the server.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260804T061658Z/items/CVE-2026-15012.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes remote exposure · authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Demi – One Click Demo Import, WP Backup & Site Migration plugin for WordPress is vulnerable to Arbitrary Directory Copy in all versions up to, and including, 0.0.8 via the handle_restore_step function. NVD: This is due to missing HTTP access controls on the wp-content/uploads/demi-backup-state/ directory, which exposes the cryptographic restore key used to both authenticate the unauthenticated AJAX handler and forge signed restore-state envelopes. NVD: This makes it possible for unauthenticated attackers to copy arbitrary files to attacker-controlled destinations on the server.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15012/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15013/",
      "current_public_safe_latest": false,
      "cvss_score": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.33877,
      "epss_score": 0.00414,
      "first_observed_at": "2026-07-22T22:28:24.662524+00:00",
      "id": "CVE-2026-15013",
      "impact_tags": [
        "authentication boundary review",
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-22T22:28:24.662524+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The SAML Single Sign On – SSO Login plugin for WordPress is vulnerable to Authentication Bypass via SAML Signature Algorithm Confusion in all versions up to, and including, 5.4.3. NVD: The vulnerability exists because Mo_SAML_Utilities::mo_saml_cast_key() reads the SignatureMethod Algorithm attribute directly from the attacker-controlled SAMLResponse parameter rather than enforcing the locally configured algorithm, causing the plugin to... NVD: This makes it possible for unauthenticated attackers to forge a SAML assertion targeting any WordPress account — including administrators — obtain valid WordPress authentication cookies, and achieve full administrator-level account takeover.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260722T223443Z/items/CVE-2026-15013.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes authentication boundary review · remote exposure · authenticated boundary. Possible impact: This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authentication boundary review · remote exposure · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The SAML Single Sign On – SSO Login plugin for WordPress is vulnerable to Authentication Bypass via SAML Signature Algorithm Confusion in all versions up to, and including, 5.4.3. NVD: The vulnerability exists because Mo_SAML_Utilities::mo_saml_cast_key() reads the SignatureMethod Algorithm attribute directly from the attacker-controlled SAMLResponse parameter rather than enforcing the locally configured algorithm, causing the plugin to... NVD: This makes it possible for unauthenticated attackers to forge a SAML assertion targeting any WordPress account — including administrators — obtain valid WordPress authentication cookies, and achieve full administrator-level account takeover.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15013/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15016/",
      "current_public_safe_latest": false,
      "cvss_score": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.05259,
      "epss_score": 0.00156,
      "first_observed_at": "2026-08-04T11:35:47.800052+00:00",
      "id": "CVE-2026-15016",
      "impact_tags": [
        "XSS risk",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-04T11:35:47.800052+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Readonly User Field via [pmpro_member_profile_edit] Shortcode in all versions up to, and including... NVD: This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260804T114328Z/items/CVE-2026-15016.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes XSS risk · authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Readonly User Field via [pmpro_member_profile_edit] Shortcode in all versions up to, and including... NVD: This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15016/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15025/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.40973,
      "epss_score": 0.00514,
      "first_observed_at": "2026-08-04T11:35:47.800052+00:00",
      "id": "CVE-2026-15025",
      "impact_tags": [
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-04T11:35:47.800052+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 7.3.2 via the automator_google_contacts_fetch_labels... NVD: This makes it possible for authenticated attackers, with Subscriber-level access and above, to enumerate sensitive Google Contacts groups/labels and Mautic segments, tags, and contact-field definitions retrieved via integration credentials configured by an...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260804T114328Z/items/CVE-2026-15025.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes authenticated boundary. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 7.3.2 via the automator_google_contacts_fetch_labels... NVD: This makes it possible for authenticated attackers, with Subscriber-level access and above, to enumerate sensitive Google Contacts groups/labels and Mautic segments, tags, and contact-field definitions retrieved via integration credentials configured by an...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15025/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15026/",
      "current_public_safe_latest": false,
      "cvss_score": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.1287,
      "epss_score": 0.00223,
      "first_observed_at": "2026-07-17T05:58:07.763993+00:00",
      "id": "CVE-2026-15026",
      "impact_tags": [
        "information exposure review",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-17T05:58:07.763993+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Import and export users and customers plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.4.0 via the email_template_selected. NVD: This makes it possible for authenticated attackers, with subscriber-level access and above, to extract the post_title and raw post_content of arbitrary posts regardless of status (draft, private, future, trash, password-protected) or post type (including... NVD: The required codection-security nonce is exposed as inline JavaScript on any wp-admin page when ?post_type=acui_email_template is appended to the URL, which is reachable by any authenticated user including Subscribers.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260717T060336Z/items/CVE-2026-15026.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes information exposure review · authenticated boundary. Possible impact: An attacker may be able to access information that should not be exposed.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Import and export users and customers plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.4.0 via the email_template_selected. NVD: This makes it possible for authenticated attackers, with subscriber-level access and above, to extract the post_title and raw post_content of arbitrary posts regardless of status (draft, private, future, trash, password-protected) or post type (including... NVD: The required codection-security nonce is exposed as inline JavaScript on any wp-admin page when ?post_type=acui_email_template is appended to the URL, which is reachable by any authenticated user including Subscribers.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15026/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "redhat / directory_server",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15041/",
      "current_public_safe_latest": false,
      "cvss_score": 3.7,
      "cvss_severity": "LOW",
      "epss_percentile": 0.21853,
      "epss_score": 0.003,
      "first_observed_at": "2026-07-15T11:03:27.604769+00:00",
      "id": "CVE-2026-15041",
      "impact_tags": [
        "remote exposure relevant"
      ],
      "kev": false,
      "last_observed_at": "2026-07-15T11:03:27.604769+00:00",
      "latest_item_url": null,
      "product": "directory_server",
      "public_safe_summary": "NVD: A flaw was found in 389 Directory Server. NVD: The PBKDF2-SHA256 password verification function uses standard memcmp() for comparing password hashes instead of a constant-time comparison function. NVD: A remote attacker could potentially use timing measurements of LDAP bind attempts to infer partial hash information, though practical exploitation is extremely difficult due to PBKDF2 computational overhead.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260715T110622Z/items/CVE-2026-15041.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: redhat / directory_server; affected version context: -, 10.0, 11.0, 12.0, 13.0",
      "source_published_impact": "Source describes remote exposure. Possible impact: This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A flaw was found in 389 Directory Server. NVD: The PBKDF2-SHA256 password verification function uses standard memcmp() for comparing password hashes instead of a constant-time comparison function. NVD: A remote attacker could potentially use timing measurements of LDAP bind attempts to infer partial hash information, though practical exploitation is extremely difficult due to PBKDF2 computational overhead.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15041/timeline.json",
      "vendor": "redhat"
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15055/",
      "current_public_safe_latest": false,
      "cvss_score": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.17884,
      "epss_score": 0.00263,
      "first_observed_at": "2026-08-09T09:59:30.349754+00:00",
      "id": "CVE-2026-15055",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-09T21:51:57.260007+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: In Bouncy Castle for Java before 1.85, PKCS#8 / PBES2 decryptors honour unbounded KDF cost from input. NVD: This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpkix-fips 1.0.12 (1.0.X series), 2.0.12 (2.0.X series) and 2.1.12 (2.1.X series). OSV: PKCS#8 / PBES2 decryptors honour unbounded KDF cost from input",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260809T215750Z/items/CVE-2026-15055.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 3,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: In Bouncy Castle for Java before 1.85, PKCS#8 / PBES2 decryptors honour unbounded KDF cost from input. NVD: This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpkix-fips 1.0.12 (1.0.X series), 2.0.12 (2.0.X series) and 2.1.12 (2.1.X series). OSV: PKCS#8 / PBES2 decryptors honour unbounded KDF cost from input",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15055/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15094/",
      "current_public_safe_latest": false,
      "cvss_score": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.32333,
      "epss_score": 0.00398,
      "first_observed_at": "2026-07-24T06:06:41.160911+00:00",
      "id": "CVE-2026-15094",
      "impact_tags": [
        "XSS risk",
        "remote exposure relevant",
        "authenticated boundary review",
        "user interaction review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-24T06:06:41.160911+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The WP Hotel Booking plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'check_in_date' parameter in all versions up to, and including, 2.3.2 due to insufficient input sanitization and output escaping. NVD: This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260724T061150Z/items/CVE-2026-15094.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes XSS risk · remote exposure · authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk · remote exposure · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The WP Hotel Booking plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'check_in_date' parameter in all versions up to, and including, 2.3.2 due to insufficient input sanitization and output escaping. NVD: This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15094/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15096/",
      "current_public_safe_latest": false,
      "cvss_score": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.09186,
      "epss_score": 0.00193,
      "first_observed_at": "2026-07-18T05:13:28.850753+00:00",
      "id": "CVE-2026-15096",
      "impact_tags": [
        "XSS risk",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-18T05:13:28.850753+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Themify Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Map Module 'b_width_map' Field in all versions up to, and including, 7.7.6 due to insufficient input sanitization and output escaping. NVD: This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260718T051545Z/items/CVE-2026-15096.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes XSS risk · authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Themify Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Map Module 'b_width_map' Field in all versions up to, and including, 7.7.6 due to insufficient input sanitization and output escaping. NVD: This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15096/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15097/",
      "current_public_safe_latest": false,
      "cvss_score": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.10104,
      "epss_score": 0.00201,
      "first_observed_at": "2026-07-18T05:13:28.850753+00:00",
      "id": "CVE-2026-15097",
      "impact_tags": [
        "XSS risk",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-18T05:13:28.850753+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Themify Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'height_slider' Slider Module Field in all versions up to, and including, 7.7.6 due to insufficient input sanitization and output escaping. NVD: This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260718T051545Z/items/CVE-2026-15097.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes XSS risk · authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Themify Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'height_slider' Slider Module Field in all versions up to, and including, 7.7.6 due to insufficient input sanitization and output escaping. NVD: This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15097/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15136/",
      "current_public_safe_latest": false,
      "cvss_score": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.02944,
      "epss_score": 0.00129,
      "first_observed_at": "2026-08-04T06:07:04.591309+00:00",
      "id": "CVE-2026-15136",
      "impact_tags": [
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-04T06:07:04.591309+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Cookie Banner for GDPR / CCPA – WPLP Cookie Consent plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.3.7. NVD: This is due to missing or incorrect nonce validation on the process_bulk_action function. NVD: This makes it possible for unauthenticated attackers to permanently delete or forcibly resolve arbitrary GDPR data request records stored in the wpl_data_req table via a forged request granted they can trick a site administrator into performing an action such...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260804T061658Z/items/CVE-2026-15136.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes remote exposure · authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Cookie Banner for GDPR / CCPA – WPLP Cookie Consent plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.3.7. NVD: This is due to missing or incorrect nonce validation on the process_bulk_action function. NVD: This makes it possible for unauthenticated attackers to permanently delete or forcibly resolve arbitrary GDPR data request records stored in the wpl_data_req table via a forged request granted they can trick a site administrator into performing an action such...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15136/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "fastify / fastify\\/rate-limit",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15144/",
      "current_public_safe_latest": false,
      "cvss_score": 7.3,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.16562,
      "epss_score": 0.00252,
      "first_observed_at": "2026-08-05T16:55:08.588478+00:00",
      "id": "CVE-2026-15144",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-05T16:55:08.588478+00:00",
      "latest_item_url": null,
      "product": "fastify\\/rate-limit",
      "public_safe_summary": "NVD: @fastify/rate-limit before 11.2.0 keys rate-limit buckets by the verbatim client IP string returned from request.ip. NVD: Because a single IPv6 client can control a large address range (a /64 holds 2^64 distinct addresses) and the same address has multiple valid textual representations, an IPv6 capable client can defeat the rate-limit boundary by rotating addresses or by... NVD: Applications that use @fastify/rate-limit to protect endpoints such as authentication, password reset, OTP delivery, or expensive API calls can be bypassed by IPv6 clients behind a proxy that surfaces IPv6 to the origin when trustProxy is enabled.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260805T165944Z/items/CVE-2026-15144.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: fastify / fastify\\/rate-limit",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: @fastify/rate-limit before 11.2.0 keys rate-limit buckets by the verbatim client IP string returned from request.ip. NVD: Because a single IPv6 client can control a large address range (a /64 holds 2^64 distinct addresses) and the same address has multiple valid textual representations, an IPv6 capable client can defeat the rate-limit boundary by rotating addresses or by... NVD: Applications that use @fastify/rate-limit to protect endpoints such as authentication, password reset, OTP delivery, or expensive API calls can be bypassed by IPv6 clients behind a proxy that surfaces IPv6 to the origin when trustProxy is enabled.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15144/timeline.json",
      "vendor": "fastify"
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15145/",
      "current_public_safe_latest": false,
      "cvss_score": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.1535,
      "epss_score": 0.00241,
      "first_observed_at": "2026-07-28T06:05:50.269125+00:00",
      "id": "CVE-2026-15145",
      "impact_tags": [
        "XSS risk",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-28T06:05:50.269125+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Fancy Text Widget in all versions up to, and including, 6.6.11 due to insufficient input sanitization and output... NVD: This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. OSV: Essential Addons for Elementor <= 6.6.11 - Authenticated (Contributor+) Stored Cross-Site Scripting via Fancy Text Widget",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260728T060840Z/items/CVE-2026-15145.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes XSS risk · authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Fancy Text Widget in all versions up to, and including, 6.6.11 due to insufficient input sanitization and output... NVD: This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. OSV: Essential Addons for Elementor <= 6.6.11 - Authenticated (Contributor+) Stored Cross-Site Scripting via Fancy Text Widget",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15145/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15151/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.14081,
      "epss_score": 0.00232,
      "first_observed_at": "2026-08-08T15:50:31.311576+00:00",
      "id": "CVE-2026-15151",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-09T04:40:09.231782+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Five Star Restaurant Reservations WordPress plugin before 2.7.23 does not perform a capability check on one of its AJAX actions, allowing users with the lowest booking-management role (which by default cannot access the Five Star Restaurant Reservations...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260809T044412Z/items/CVE-2026-15151.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 3,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Five Star Restaurant Reservations WordPress plugin before 2.7.23 does not perform a capability check on one of its AJAX actions, allowing users with the lowest booking-management role (which by default cannot access the Five Star Restaurant Reservations...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15151/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15155/",
      "current_public_safe_latest": false,
      "cvss_score": 8.8,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.28917,
      "epss_score": 0.00367,
      "first_observed_at": "2026-07-18T05:38:40.092323+00:00",
      "id": "CVE-2026-15155",
      "impact_tags": [
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-18T07:15:27.585758+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Authenticated Account Takeover via Email Header Injection in all versions up to, and including, 6.6.10 This is due to insufficient server-side... NVD: This makes it possible for authenticated attackers, with Contributor-level access and above, to inject an additional Bcc header into the WordPress administrator's password-reset notification email, receive a copy of a valid administrator password-reset link...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260718T071858Z/items/CVE-2026-15155.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes authenticated boundary. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Authenticated Account Takeover via Email Header Injection in all versions up to, and including, 6.6.10 This is due to insufficient server-side... NVD: This makes it possible for authenticated attackers, with Contributor-level access and above, to inject an additional Bcc header into the WordPress administrator's password-reset notification email, receive a copy of a valid administrator password-reset link...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15155/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "wireshark / wireshark",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15168/",
      "current_public_safe_latest": false,
      "cvss_score": 2.5,
      "cvss_severity": "LOW",
      "epss_percentile": 0.01151,
      "epss_score": 0.00102,
      "first_observed_at": "2026-07-15T22:16:59.245057+00:00",
      "id": "CVE-2026-15168",
      "impact_tags": [
        "information exposure review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-15T22:16:59.245057+00:00",
      "latest_item_url": null,
      "product": "wireshark",
      "public_safe_summary": "NVD: BLF file parser in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows possible information disclosure OSV: Use of Uninitialized Variable in Wireshark OSV: BLF file parser in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows possible information disclosure",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260715T221956Z/items/CVE-2026-15168.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: wireshark / wireshark",
      "source_published_impact": "Source describes information exposure review. Possible impact: An attacker may be able to access information that should not be exposed.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: BLF file parser in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows possible information disclosure OSV: Use of Uninitialized Variable in Wireshark OSV: BLF file parser in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows possible information disclosure",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15168/timeline.json",
      "vendor": "wireshark"
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15185/",
      "current_public_safe_latest": false,
      "cvss_score": 1.9,
      "cvss_severity": "LOW",
      "epss_percentile": 0.01641,
      "epss_score": 0.00112,
      "first_observed_at": "2026-07-16T13:54:14.110513+00:00",
      "id": "CVE-2026-15185",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-16T13:54:14.110513+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A vulnerability was determined in GPAC 26.03-DEV. NVD: This affects the function vobsub_read_idx of the file /src/media_tools/vobsub.c of the component MP4Box. NVD: Executing a manipulation of the argument num_langs can lead to out-of-bounds read.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260716T135621Z/items/CVE-2026-15185.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability was determined in GPAC 26.03-DEV. NVD: This affects the function vobsub_read_idx of the file /src/media_tools/vobsub.c of the component MP4Box. NVD: Executing a manipulation of the argument num_langs can lead to out-of-bounds read.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15185/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15186/",
      "current_public_safe_latest": false,
      "cvss_score": 2.1,
      "cvss_severity": "LOW",
      "epss_percentile": 0.14621,
      "epss_score": 0.00237,
      "first_observed_at": "2026-07-16T13:54:14.110513+00:00",
      "id": "CVE-2026-15186",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-16T13:54:14.110513+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A vulnerability was identified in macrozheng mall up to 1.0.3. NVD: This impacts an unknown function of the file /returnApply/create of the component Portal Endpoint. NVD: The manipulation of the argument orderId leads to improper control of resource identifiers.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260716T135621Z/items/CVE-2026-15186.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability was identified in macrozheng mall up to 1.0.3. NVD: This impacts an unknown function of the file /returnApply/create of the component Portal Endpoint. NVD: The manipulation of the argument orderId leads to improper control of resource identifiers.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15186/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15190/",
      "current_public_safe_latest": false,
      "cvss_score": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.24954,
      "epss_score": 0.00328,
      "first_observed_at": "2026-07-16T16:44:59.414444+00:00",
      "id": "CVE-2026-15190",
      "impact_tags": [
        "SQL injection risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-16T16:44:59.414444+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A vulnerability was detected in SourceCodester Simple and Nice Shopping Cart Script 1.0. NVD: This affects an unknown part of the file /login.php. NVD: Performing a manipulation of the argument Username results in sql injection.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260716T164706Z/items/CVE-2026-15190.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes SQL injection risk. Possible impact: An attacker may be able to read or change database-backed application data.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability was detected in SourceCodester Simple and Nice Shopping Cart Script 1.0. NVD: This affects an unknown part of the file /login.php. NVD: Performing a manipulation of the argument Username results in sql injection.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15190/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15191/",
      "current_public_safe_latest": false,
      "cvss_score": 2.1,
      "cvss_severity": "LOW",
      "epss_percentile": 0.12451,
      "epss_score": 0.0022,
      "first_observed_at": "2026-07-16T16:44:59.414444+00:00",
      "id": "CVE-2026-15191",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-16T16:44:59.414444+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A flaw has been found in mettle sendportal up to 3.0.1. NVD: This vulnerability affects unknown code of the file vendor/mettle/sendportal-core/src/Http/Requests/CampaignStoreRequest.php of the component Campaign Creation Endpoint. NVD: Executing a manipulation can lead to authorization bypass.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260716T164706Z/items/CVE-2026-15191.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A flaw has been found in mettle sendportal up to 3.0.1. NVD: This vulnerability affects unknown code of the file vendor/mettle/sendportal-core/src/Http/Requests/CampaignStoreRequest.php of the component Campaign Creation Endpoint. NVD: Executing a manipulation can lead to authorization bypass.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15191/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15192/",
      "current_public_safe_latest": false,
      "cvss_score": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.43449,
      "epss_score": 0.00572,
      "first_observed_at": "2026-07-16T16:44:59.414444+00:00",
      "id": "CVE-2026-15192",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-16T16:44:59.414444+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A vulnerability has been found in mettle sendportal up to 3.0.1. NVD: This issue affects the function sendgrid/postmark/postal/mailjet of the component APIv1 Webhooks. NVD: The manipulation leads to missing authentication.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260716T164706Z/items/CVE-2026-15192.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability has been found in mettle sendportal up to 3.0.1. NVD: This issue affects the function sendgrid/postmark/postal/mailjet of the component APIv1 Webhooks. NVD: The manipulation leads to missing authentication.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15192/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15193/",
      "current_public_safe_latest": false,
      "cvss_score": 1.9,
      "cvss_severity": "LOW",
      "epss_percentile": 0.48368,
      "epss_score": 0.00683,
      "first_observed_at": "2026-07-16T16:44:59.414444+00:00",
      "id": "CVE-2026-15193",
      "impact_tags": [
        "command injection risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-16T16:44:59.414444+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A vulnerability was determined in AidanPark openclaw-android up to 0.4.0. NVD: The affected element is an unknown function of the file android/app/src/main/java/com/openclaw/android/JsBridge.kt of the component Android WebView Bridge. NVD: This manipulation causes os command injection.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260716T164706Z/items/CVE-2026-15193.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes command injection risk. Possible impact: An attacker may be able to run unintended system commands through the affected component.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability was determined in AidanPark openclaw-android up to 0.4.0. NVD: The affected element is an unknown function of the file android/app/src/main/java/com/openclaw/android/JsBridge.kt of the component Android WebView Bridge. NVD: This manipulation causes os command injection.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15193/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15194/",
      "current_public_safe_latest": false,
      "cvss_score": 1.9,
      "cvss_severity": "LOW",
      "epss_percentile": 0.02274,
      "epss_score": 0.00121,
      "first_observed_at": "2026-07-16T16:44:59.414444+00:00",
      "id": "CVE-2026-15194",
      "impact_tags": [
        "memory safety review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-16T16:44:59.414444+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A security flaw has been discovered in Open5GS 2.7.7. NVD: This affects the function amf_context_final of the file src/amf/context.c of the component AMF. NVD: Performing a manipulation results in use after free.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260716T164706Z/items/CVE-2026-15194.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes memory safety review. Possible impact: The affected component has memory-safety risk that may lead to crash, privilege, or code-execution impact depending on exposure.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A security flaw has been discovered in Open5GS 2.7.7. NVD: This affects the function amf_context_final of the file src/amf/context.c of the component AMF. NVD: Performing a manipulation results in use after free.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15194/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15206/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.1782,
      "epss_score": 0.00262,
      "first_observed_at": "2026-08-08T21:49:51.726843+00:00",
      "id": "CVE-2026-15206",
      "impact_tags": [
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-09T04:40:09.231782+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The SMS Alert WordPress plugin before 3.9.8 does not bind its \"mobile verified\" session flag to the phone number that was actually verified: after an attacker verifies an OTP sent to their own phone, the signup/login handler reads a fresh, attacker-supplied... NVD: An unauthenticated attacker can therefore log in as any user, including an administrator, who has a billing phone on file.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260809T044412Z/items/CVE-2026-15206.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes remote exposure · authenticated boundary. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The SMS Alert WordPress plugin before 3.9.8 does not bind its \"mobile verified\" session flag to the phone number that was actually verified: after an attacker verifies an OTP sent to their own phone, the signup/login handler reads a fresh, attacker-supplied... NVD: An unauthenticated attacker can therefore log in as any user, including an administrator, who has a billing phone on file.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15206/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15227/",
      "current_public_safe_latest": false,
      "cvss_score": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.10903,
      "epss_score": 0.00207,
      "first_observed_at": "2026-08-07T10:13:53.604723+00:00",
      "id": "CVE-2026-15227",
      "impact_tags": [
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-07T10:13:53.604723+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Missing authorization in Checkmk <2.5.0p10, <2.4.0p35, <2.3.0p49, and 2.2.0 (EOL) allows an authenticated user lacking the \"Edit foreign Reports\" permission to modify reports owned by other users.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260807T102646Z/items/CVE-2026-15227.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Missing authorization in Checkmk <2.5.0p10, <2.4.0p35, <2.3.0p49, and 2.2.0 (EOL) allows an authenticated user lacking the \"Edit foreign Reports\" permission to modify reports owned by other users.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15227/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15231/",
      "current_public_safe_latest": false,
      "cvss_score": 2.7,
      "cvss_severity": "LOW",
      "epss_percentile": 0.12252,
      "epss_score": 0.00218,
      "first_observed_at": "2026-08-10T04:58:31.923491+00:00",
      "id": "CVE-2026-15231",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-10T04:58:31.923491+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Tag, Category, and Taxonomy Manager WordPress plugin before 3.51.0 does not verify that a user is authorized to access a referenced post before processing it and returning derived data, allowing users with contributor privileges to disclose data from...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260810T050414Z/items/CVE-2026-15231.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Tag, Category, and Taxonomy Manager WordPress plugin before 3.51.0 does not verify that a user is authorized to access a referenced post before processing it and returning derived data, allowing users with contributor privileges to disclose data from...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15231/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15233/",
      "current_public_safe_latest": false,
      "cvss_score": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.03997,
      "epss_score": 0.00142,
      "first_observed_at": "2026-08-11T04:43:10.985977+00:00",
      "id": "CVE-2026-15233",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-11T04:43:10.985977+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Nested Pages WordPress plugin before 3.2.15 does not properly escape post titles before outputting them into HTML attributes on an administrative listing screen, allowing users with the Editor role (or Contributor/Author when the Nested Pages WordPress...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260811T044729Z/items/CVE-2026-15233.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Nested Pages WordPress plugin before 3.2.15 does not properly escape post titles before outputting them into HTML attributes on an administrative listing screen, allowing users with the Editor role (or Contributor/Author when the Nested Pages WordPress...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15233/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15236/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.20149,
      "epss_score": 0.0028,
      "first_observed_at": "2026-08-08T21:49:51.726843+00:00",
      "id": "CVE-2026-15236",
      "impact_tags": [
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-09T04:40:09.231782+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Gallery for Google Photos WordPress plugin before 1.2.1 does not properly restrict access to the stored third-party OAuth credentials of the connected account, exposing the persistent access and refresh tokens to unauthenticated users and allowing...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260809T044412Z/items/CVE-2026-15236.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes authenticated boundary. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Gallery for Google Photos WordPress plugin before 1.2.1 does not properly restrict access to the stored third-party OAuth credentials of the connected account, exposing the persistent access and refresh tokens to unauthenticated users and allowing...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15236/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15241/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.1782,
      "epss_score": 0.00262,
      "first_observed_at": "2026-08-08T21:49:51.726843+00:00",
      "id": "CVE-2026-15241",
      "impact_tags": [
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-09T04:40:09.231782+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The AI ChatBot for WooCommerce WordPress plugin before 4.8.4 does not perform any authorization or nonce check on one of its AJAX actions, allowing unauthenticated users to abuse the site owner's stored third-party API key to send requests billed to the...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260809T044412Z/items/CVE-2026-15241.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes authenticated boundary. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The AI ChatBot for WooCommerce WordPress plugin before 4.8.4 does not perform any authorization or nonce check on one of its AJAX actions, allowing unauthenticated users to abuse the site owner's stored third-party API key to send requests billed to the...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15241/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15243/",
      "current_public_safe_latest": false,
      "cvss_score": 7.4,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.06632,
      "epss_score": 0.0017,
      "first_observed_at": "2026-07-31T11:36:05.167842+00:00",
      "id": "CVE-2026-15243",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-31T11:36:05.167842+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Apereo CAS Client accepts any CA-trusted certificate for any hostname, provided the URL the client is calling matches the configured allowlist or regex. NVD: An attacker with a MITM position (DNS poisoning, rogue Wi-Fi, malicious proxy, etc.) can provide any CA-signed certificate for a hostname that matches the configured allowlist or regex. NVD: This can lead to intercepting the CAS exchange, capturing the Ticket-Granting Ticket (TGT), and subsequently obtaining Service Tickets on behalf of the victim.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260731T115001Z/items/CVE-2026-15243.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Apereo CAS Client accepts any CA-trusted certificate for any hostname, provided the URL the client is calling matches the configured allowlist or regex. NVD: An attacker with a MITM position (DNS poisoning, rogue Wi-Fi, malicious proxy, etc.) can provide any CA-signed certificate for a hostname that matches the configured allowlist or regex. NVD: This can lead to intercepting the CAS exchange, capturing the Ticket-Granting Ticket (TGT), and subsequently obtaining Service Tickets on behalf of the victim.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15243/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15248/",
      "current_public_safe_latest": false,
      "cvss_score": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.20207,
      "epss_score": 0.0028,
      "first_observed_at": "2026-08-08T21:49:51.726843+00:00",
      "id": "CVE-2026-15248",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-09T04:40:09.231782+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Meta Box WordPress plugin before 5.13.1 does not verify that a user is authorized to delete the supplied attachment before deleting it, allowing users with a low-privilege role such as Contributor to permanently delete arbitrary media attachments...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260809T044412Z/items/CVE-2026-15248.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Meta Box WordPress plugin before 5.13.1 does not verify that a user is authorized to delete the supplied attachment before deleting it, allowing users with a low-privilege role such as Contributor to permanently delete arbitrary media attachments...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15248/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15254/",
      "current_public_safe_latest": false,
      "cvss_score": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.10086,
      "epss_score": 0.00201,
      "first_observed_at": "2026-08-10T04:58:31.923491+00:00",
      "id": "CVE-2026-15254",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-10T04:58:31.923491+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Simply Schedule Appointments WordPress plugin before 1.6.12.11 does not perform a capability check on an administrative appointment-listing shortcode, and its per-user result scoping fails open for non-staff users, allowing users with the Contributor role...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260810T050414Z/items/CVE-2026-15254.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Simply Schedule Appointments WordPress plugin before 1.6.12.11 does not perform a capability check on an administrative appointment-listing shortcode, and its per-user result scoping fails open for non-staff users, allowing users with the Contributor role...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15254/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15260/",
      "current_public_safe_latest": false,
      "cvss_score": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.04878,
      "epss_score": 0.00152,
      "first_observed_at": "2026-08-10T04:58:31.923491+00:00",
      "id": "CVE-2026-15260",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-10T04:58:31.923491+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The GEO my WP WordPress plugin before 4.5.5.3 does not perform any ownership or capability check on two of its logged-in AJAX actions, allowing users with subscriber-level access or above to modify or permanently delete other users' and posts' geolocation...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260810T050414Z/items/CVE-2026-15260.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The GEO my WP WordPress plugin before 4.5.5.3 does not perform any ownership or capability check on two of its logged-in AJAX actions, allowing users with subscriber-level access or above to modify or permanently delete other users' and posts' geolocation...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15260/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15305/",
      "current_public_safe_latest": false,
      "cvss_score": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.07084,
      "epss_score": 0.00174,
      "first_observed_at": "2026-07-21T11:20:19.325173+00:00",
      "id": "CVE-2026-15305",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-21T11:20:19.325173+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Users were able to upload files with arbitrary MIME types to forms using FileUpload or ImageUpload elements with allowedMimeTypes configured. NVD: The restriction was not enforced server-side because the MimeTypeValidator was registered during form building before concrete form definition properties were applied, resulting in the validator never being added to the processing pipeline. NVD: This issue affects TYPO3 CMS versions 14.2.0-14.3.4.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260721T112231Z/items/CVE-2026-15305.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Users were able to upload files with arbitrary MIME types to forms using FileUpload or ImageUpload elements with allowedMimeTypes configured. NVD: The restriction was not enforced server-side because the MimeTypeValidator was registered during form building before concrete form definition properties were applied, resulting in the validator never being added to the processing pipeline. NVD: This issue affects TYPO3 CMS versions 14.2.0-14.3.4.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15305/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15306/",
      "current_public_safe_latest": false,
      "cvss_score": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.12019,
      "epss_score": 0.00215,
      "first_observed_at": "2026-07-22T22:28:24.662524+00:00",
      "id": "CVE-2026-15306",
      "impact_tags": [
        "XSS risk",
        "remote exposure relevant",
        "authenticated boundary review",
        "user interaction review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-22T22:28:24.662524+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Product Feed Manager For WooCommerce – Sell on 200+ Online Marketplaces plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 's' Search Parameter in all versions up to, and including, 7.6.1 due to insufficient input sanitization and... NVD: This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260722T223443Z/items/CVE-2026-15306.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes XSS risk · remote exposure · authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk · remote exposure · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Product Feed Manager For WooCommerce – Sell on 200+ Online Marketplaces plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 's' Search Parameter in all versions up to, and including, 7.6.1 due to insufficient input sanitization and... NVD: This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15306/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "python / python",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15308/",
      "current_public_safe_latest": false,
      "cvss_score": 8.7,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.42447,
      "epss_score": 0.00553,
      "first_observed_at": "2026-07-16T16:44:59.414444+00:00",
      "id": "CVE-2026-15308",
      "impact_tags": [
        "service availability review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-16T16:44:59.414444+00:00",
      "latest_item_url": null,
      "product": "python",
      "public_safe_summary": "NVD: The incremental HTML parser (html.parser.HTMLParser) allows for CPU denial-of-service through repeated unterminated markup declarations when processing uncontrolled data. OSV: Incremental HTMLParser feed() allows CPU-exhaustion DoS via repeated unterminated markup declarations OSV: The incremental HTML parser (html.parser.HTMLParser) allows for CPU denial-of-service through repeated unterminated markup declarations when processing uncontrolled data.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260716T164706Z/items/CVE-2026-15308.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: python / python",
      "source_published_impact": "Source describes service availability risk. Possible impact: The affected service may become unavailable or unreliable.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The incremental HTML parser (html.parser.HTMLParser) allows for CPU denial-of-service through repeated unterminated markup declarations when processing uncontrolled data. OSV: Incremental HTMLParser feed() allows CPU-exhaustion DoS via repeated unterminated markup declarations OSV: The incremental HTML parser (html.parser.HTMLParser) allows for CPU denial-of-service through repeated unterminated markup declarations when processing uncontrolled data.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15308/timeline.json",
      "vendor": "python"
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15311/",
      "current_public_safe_latest": false,
      "cvss_score": 2.0,
      "cvss_severity": "LOW",
      "epss_percentile": 0.10371,
      "epss_score": 0.00203,
      "first_observed_at": "2026-07-16T22:18:24.817461+00:00",
      "id": "CVE-2026-15311",
      "impact_tags": [
        "XSS risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-16T22:18:24.817461+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A vulnerability was identified in NousResearch hermes-agent up to 2026.5.29.2. NVD: Affected by this issue is the function MatrixAdapter._markdown_to_html of the file gateway/platforms/matrix.py of the component Matrix Adapter. NVD: Such manipulation leads to cross site scripting.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260716T222035Z/items/CVE-2026-15311.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes XSS risk. Possible impact: This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability was identified in NousResearch hermes-agent up to 2026.5.29.2. NVD: Affected by this issue is the function MatrixAdapter._markdown_to_html of the file gateway/platforms/matrix.py of the component Matrix Adapter. NVD: Such manipulation leads to cross site scripting.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15311/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15317/",
      "current_public_safe_latest": false,
      "cvss_score": 2.1,
      "cvss_severity": "LOW",
      "epss_percentile": 0.15921,
      "epss_score": 0.00247,
      "first_observed_at": "2026-07-16T22:18:24.817461+00:00",
      "id": "CVE-2026-15317",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-16T22:18:24.817461+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A security flaw has been discovered in Sipeed PicoClaw up to 0.2.9. NVD: Affected by this vulnerability is the function WebFetchTool.Execute of the file pkg/tools/integration/web.go of the component Guarded Web Fetch Flow. NVD: The manipulation results in server-side request forgery.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260716T222035Z/items/CVE-2026-15317.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A security flaw has been discovered in Sipeed PicoClaw up to 0.2.9. NVD: Affected by this vulnerability is the function WebFetchTool.Execute of the file pkg/tools/integration/web.go of the component Guarded Web Fetch Flow. NVD: The manipulation results in server-side request forgery.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15317/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15333/",
      "current_public_safe_latest": false,
      "cvss_score": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.16529,
      "epss_score": 0.0025,
      "first_observed_at": "2026-07-31T06:26:41.124454+00:00",
      "id": "CVE-2026-15333",
      "impact_tags": [
        "XSS risk",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-31T06:26:41.124454+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 600+ Patterns, 58 Blocks & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'cozyCustomFont' Block Attribute in all versions up to, and including, 2.2.11 due to... NVD: This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260731T063057Z/items/CVE-2026-15333.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes XSS risk · authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 600+ Patterns, 58 Blocks & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'cozyCustomFont' Block Attribute in all versions up to, and including, 2.2.11 due to... NVD: This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15333/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15334/",
      "current_public_safe_latest": false,
      "cvss_score": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.1653,
      "epss_score": 0.0025,
      "first_observed_at": "2026-07-31T06:26:41.124454+00:00",
      "id": "CVE-2026-15334",
      "impact_tags": [
        "XSS risk",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-31T06:26:41.124454+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 600+ Patterns, 58 Blocks & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'icon.view' Block Attribute in all versions up to, and including, 2.2.11 due to... NVD: This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260731T063057Z/items/CVE-2026-15334.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes XSS risk · authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 600+ Patterns, 58 Blocks & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'icon.view' Block Attribute in all versions up to, and including, 2.2.11 due to... NVD: This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15334/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15335/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.38358,
      "epss_score": 0.00481,
      "first_observed_at": "2026-07-18T05:13:28.850753+00:00",
      "id": "CVE-2026-15335",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-18T05:13:28.850753+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Booking Package plugin for WordPress is vulnerable to generic SQL Injection via 'email' Form Parameter (form<N>) in all versions up to, and including, 1.7.20 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on... NVD: This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. NVD: The impact of this is severely limited as the vulnerable parameter goes through is_email.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260718T051545Z/items/CVE-2026-15335.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Booking Package plugin for WordPress is vulnerable to generic SQL Injection via 'email' Form Parameter (form<N>) in all versions up to, and including, 1.7.20 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on... NVD: This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. NVD: The impact of this is severely limited as the vulnerable parameter goes through is_email.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15335/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15336/",
      "current_public_safe_latest": false,
      "cvss_score": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.16485,
      "epss_score": 0.0025,
      "first_observed_at": "2026-07-22T22:28:24.662524+00:00",
      "id": "CVE-2026-15336",
      "impact_tags": [
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-22T22:28:24.662524+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Catch Themes Demo Import plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 3.3. NVD: This is due to the catch_themes_demo_import_activate_plugin() function, hooked on admin_init when the activate_plugin GET parameter is present, calling Plugin_Upgrader::install() to download and install a plugin from WordPress.org before performing the... NVD: This makes it possible for authenticated attackers, with subscriber-level access and above, to install the hardcoded 'essential-content-types' plugin from the WordPress.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260722T223443Z/items/CVE-2026-15336.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Catch Themes Demo Import plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 3.3. NVD: This is due to the catch_themes_demo_import_activate_plugin() function, hooked on admin_init when the activate_plugin GET parameter is present, calling Plugin_Upgrader::install() to download and install a plugin from WordPress.org before performing the... NVD: This makes it possible for authenticated attackers, with subscriber-level access and above, to install the hardcoded 'essential-content-types' plugin from the WordPress.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15336/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15342/",
      "current_public_safe_latest": false,
      "cvss_score": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.13402,
      "epss_score": 0.00225,
      "first_observed_at": "2026-07-28T16:54:01.667207+00:00",
      "id": "CVE-2026-15342",
      "impact_tags": [
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-28T16:54:01.667207+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Plane contains a multi‑tenant authorization flaw in its asset‑management API that allows authenticated users from one workspace to access, delete, or duplicate assets belonging to another workspace by providing only the victim workspace slug and asset ID. NVD: The affected endpoints return presigned file URLs and enable destructive or duplicative actions without verifying that the requester is a member of the targeted workspace. NVD: This enables cross‑tenant data exposure, data deletion, and persistent exfiltration of files into an attacker‑controlled workspace.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260728T170314Z/items/CVE-2026-15342.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Plane contains a multi‑tenant authorization flaw in its asset‑management API that allows authenticated users from one workspace to access, delete, or duplicate assets belonging to another workspace by providing only the victim workspace slug and asset ID. NVD: The affected endpoints return presigned file URLs and enable destructive or duplicative actions without verifying that the requester is a member of the targeted workspace. NVD: This enables cross‑tenant data exposure, data deletion, and persistent exfiltration of files into an attacker‑controlled workspace.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15342/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15346/",
      "current_public_safe_latest": false,
      "cvss_score": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.17782,
      "epss_score": 0.00261,
      "first_observed_at": "2026-07-31T06:26:41.124454+00:00",
      "id": "CVE-2026-15346",
      "impact_tags": [
        "XSS risk",
        "remote exposure relevant",
        "authenticated boundary review",
        "user interaction review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-31T06:26:41.124454+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'category_id' parameter in all versions up to, and including, 1.8.13 due to insufficient input sanitization and output escaping. NVD: This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. NVD: This is limited to browsers that support access keys as the injection is in a hidden element.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260731T063057Z/items/CVE-2026-15346.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes XSS risk · remote exposure · authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk · remote exposure · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'category_id' parameter in all versions up to, and including, 1.8.13 due to insufficient input sanitization and output escaping. NVD: This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. NVD: This is limited to browsers that support access keys as the injection is in a hidden element.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15346/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15370/",
      "current_public_safe_latest": false,
      "cvss_score": 6.7,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.04248,
      "epss_score": 0.00145,
      "first_observed_at": "2026-07-28T06:05:50.269125+00:00",
      "id": "CVE-2026-15370",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-28T06:05:50.269125+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A flaw was found in libssh. NVD: During SFTP server directory listing, the longname field is constructed with unsafe concatenation into a fixed-size stack buffer. NVD: When a client causes the server to list attacker-controlled filenames, sufficiently long names can overflow that stack buffer and may lead to crashes or possible code execution on the server.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260728T060840Z/items/CVE-2026-15370.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A flaw was found in libssh. NVD: During SFTP server directory listing, the longname field is constructed with unsafe concatenation into a fixed-size stack buffer. NVD: When a client causes the server to list attacker-controlled filenames, sufficiently long names can overflow that stack buffer and may lead to crashes or possible code execution on the server.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15370/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15376/",
      "current_public_safe_latest": false,
      "cvss_score": 2.1,
      "cvss_severity": "LOW",
      "epss_percentile": 0.17091,
      "epss_score": 0.00256,
      "first_observed_at": "2026-07-17T16:36:32.072333+00:00",
      "id": "CVE-2026-15376",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-17T16:36:32.072333+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A vulnerability was found in Eleveo Call Recording Software 9.7.0. NVD: Affected is an unknown function of the file /callrec/statisticReportAction.do. NVD: The manipulation results in improper authorization.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260717T164048Z/items/CVE-2026-15376.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability was found in Eleveo Call Recording Software 9.7.0. NVD: Affected is an unknown function of the file /callrec/statisticReportAction.do. NVD: The manipulation results in improper authorization.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15376/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15377/",
      "current_public_safe_latest": false,
      "cvss_score": 2.1,
      "cvss_severity": "LOW",
      "epss_percentile": 0.1696,
      "epss_score": 0.00255,
      "first_observed_at": "2026-07-17T16:36:32.072333+00:00",
      "id": "CVE-2026-15377",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-17T16:36:32.072333+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A vulnerability was determined in Eleveo Call Recording Software 9.7.0. NVD: Affected by this vulnerability is an unknown functionality of the file /callrec/sendlogfile. NVD: This manipulation causes improper authorization.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260717T164048Z/items/CVE-2026-15377.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability was determined in Eleveo Call Recording Software 9.7.0. NVD: Affected by this vulnerability is an unknown functionality of the file /callrec/sendlogfile. NVD: This manipulation causes improper authorization.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15377/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15379/",
      "current_public_safe_latest": false,
      "cvss_score": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.01128,
      "epss_score": 0.00102,
      "first_observed_at": "2026-07-24T06:06:41.160911+00:00",
      "id": "CVE-2026-15379",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-24T06:06:41.160911+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Altiris WMI provider exposes a class (AltirisAgent_Stream) that allows any local standard user to read the contents of any file accessible to the SYSTEM account, bypassing filesystem ACLs. NVD: No admin privileges required. NVD: The provider reverts to the LocalSystem context when servicing WMI queries without re-impersonating the caller.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260724T061150Z/items/CVE-2026-15379.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Altiris WMI provider exposes a class (AltirisAgent_Stream) that allows any local standard user to read the contents of any file accessible to the SYSTEM account, bypassing filesystem ACLs. NVD: No admin privileges required. NVD: The provider reverts to the LocalSystem context when servicing WMI queries without re-impersonating the caller.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15379/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15380/",
      "current_public_safe_latest": false,
      "cvss_score": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.0196,
      "epss_score": 0.00117,
      "first_observed_at": "2026-07-24T06:06:41.160911+00:00",
      "id": "CVE-2026-15380",
      "impact_tags": [
        "memory safety review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-24T06:06:41.160911+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A non-administrator interactive user can obtain full SYSTEM code execution through a DCOM/task scheduler logic chain — no network access, no memory corruption required (ITMS 8.7.3)",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260724T061150Z/items/CVE-2026-15380.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes memory safety review. Possible impact: The affected component has memory-safety risk that may lead to crash, privilege, or code-execution impact depending on exposure.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A non-administrator interactive user can obtain full SYSTEM code execution through a DCOM/task scheduler logic chain — no network access, no memory corruption required (ITMS 8.7.3)",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15380/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15383/",
      "current_public_safe_latest": false,
      "cvss_score": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.05834,
      "epss_score": 0.00162,
      "first_observed_at": "2026-08-10T04:58:31.923491+00:00",
      "id": "CVE-2026-15383",
      "impact_tags": [
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-10T04:58:31.923491+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Blog Floating Button WordPress plugin through 1.4.20 does not sanitize or escape the visitor User-Agent header, which it stores through an unauthenticated tracking REST endpoint and later renders unescaped in an administrator report page. NVD: This allows an unauthenticated attacker to store a malicious script that executes in the session of any administrator who views the access report, leading to site takeover.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260810T050414Z/items/CVE-2026-15383.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes remote exposure · authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Blog Floating Button WordPress plugin through 1.4.20 does not sanitize or escape the visitor User-Agent header, which it stores through an unauthenticated tracking REST endpoint and later renders unescaped in an administrator report page. NVD: This allows an unauthenticated attacker to store a malicious script that executes in the session of any administrator who views the access report, leading to site takeover.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15383/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15385/",
      "current_public_safe_latest": false,
      "cvss_score": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.03215,
      "epss_score": 0.00133,
      "first_observed_at": "2026-08-08T21:49:51.726843+00:00",
      "id": "CVE-2026-15385",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-09T04:40:09.231782+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The RT Mega Menu WordPress plugin before 1.5.2 does not perform a capability check on the AJAX action that saves mega-menu configuration and per-menu-item settings; its only gate is a nonce that any logged-in user can read from a standard admin page. NVD: A subscriber-level user can therefore enable the mega menu on a site menu and store a menu-item style value that is rendered, without output escaping, into a style attribute on the public navigation. NVD: By breaking out of that attribute the user persists a JavaScript event handler that executes for every visitor who hovers the navigation, including administrators, leading to session/site takeover.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260809T044412Z/items/CVE-2026-15385.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The RT Mega Menu WordPress plugin before 1.5.2 does not perform a capability check on the AJAX action that saves mega-menu configuration and per-menu-item settings; its only gate is a nonce that any logged-in user can read from a standard admin page. NVD: A subscriber-level user can therefore enable the mega menu on a site menu and store a menu-item style value that is rendered, without output escaping, into a style attribute on the public navigation. NVD: By breaking out of that attribute the user persists a JavaScript event handler that executes for every visitor who hovers the navigation, including administrators, leading to session/site takeover.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15385/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15393/",
      "current_public_safe_latest": false,
      "cvss_score": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.16527,
      "epss_score": 0.0025,
      "first_observed_at": "2026-08-04T11:35:47.800052+00:00",
      "id": "CVE-2026-15393",
      "impact_tags": [
        "XSS risk",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-04T11:35:47.800052+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 600+ Patterns, 58 Blocks & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'postMeta.font.size' Block Attribute in all versions up to, and including, 2.2.11 due to... NVD: This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260804T114328Z/items/CVE-2026-15393.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes XSS risk · authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 600+ Patterns, 58 Blocks & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'postMeta.font.size' Block Attribute in all versions up to, and including, 2.2.11 due to... NVD: This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15393/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15397/",
      "current_public_safe_latest": false,
      "cvss_score": 7.2,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.2371,
      "epss_score": 0.00314,
      "first_observed_at": "2026-08-06T11:35:20.545945+00:00",
      "id": "CVE-2026-15397",
      "impact_tags": [
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-06T11:35:20.545945+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Subscriptions for WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 2.0.0. NVD: This is due to the plugin not properly verifying that a user is authorized to perform an action via the wps_sfw_install_plugin_configuration AJAX handler. NVD: This makes it possible for authenticated attackers, with shop manager-level access and above, to install and activate arbitrary WordPress.org plugins.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260806T114533Z/items/CVE-2026-15397.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes authenticated boundary. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Subscriptions for WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 2.0.0. NVD: This is due to the plugin not properly verifying that a user is authorized to perform an action via the wps_sfw_install_plugin_configuration AJAX handler. NVD: This makes it possible for authenticated attackers, with shop manager-level access and above, to install and activate arbitrary WordPress.org plugins.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15397/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15403/",
      "current_public_safe_latest": false,
      "cvss_score": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.18568,
      "epss_score": 0.00266,
      "first_observed_at": "2026-08-07T21:58:42.606809+00:00",
      "id": "CVE-2026-15403",
      "impact_tags": [
        "information exposure review",
        "SQL injection risk",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-07T21:58:42.606809+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Pinpoint Booking System – Version 2 plugin for WordPress is vulnerable to blind SQL Injection via the 'field' parameter in all versions up to, and including, 2.9.9.6.9 due to insufficient escaping on the user supplied parameter and lack of sufficient... NVD: This makes it possible for authenticated attackers, with administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. NVD: The nonce required to reach the vulnerable endpoint is emitted on all plugin admin pages loaded under manage_options, making it trivially obtainable by any authenticated administrator.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260807T220457Z/items/CVE-2026-15403.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes information exposure review · SQL injection risk · authenticated boundary. Possible impact: An attacker may be able to read or change database-backed application data.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Pinpoint Booking System – Version 2 plugin for WordPress is vulnerable to blind SQL Injection via the 'field' parameter in all versions up to, and including, 2.9.9.6.9 due to insufficient escaping on the user supplied parameter and lack of sufficient... NVD: This makes it possible for authenticated attackers, with administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. NVD: The nonce required to reach the vulnerable endpoint is emitted on all plugin admin pages loaded under manage_options, making it trivially obtainable by any authenticated administrator.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15403/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15411/",
      "current_public_safe_latest": false,
      "cvss_score": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.17759,
      "epss_score": 0.0026,
      "first_observed_at": "2026-08-04T11:35:47.800052+00:00",
      "id": "CVE-2026-15411",
      "impact_tags": [
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-04T11:35:47.800052+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.1.0. NVD: This is due to the plugin not properly verifying that a user is authorized to perform an action. NVD: This makes it possible for unauthenticated attackers to overwrite the spsg_popup_products option with arbitrary attacker-controlled data.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260804T114328Z/items/CVE-2026-15411.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes remote exposure · authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.1.0. NVD: This is due to the plugin not properly verifying that a user is authorized to perform an action. NVD: This makes it possible for unauthenticated attackers to overwrite the spsg_popup_products option with arbitrary attacker-controlled data.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15411/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15414/",
      "current_public_safe_latest": false,
      "cvss_score": 8.8,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.26081,
      "epss_score": 0.00335,
      "first_observed_at": "2026-08-07T21:58:42.606809+00:00",
      "id": "CVE-2026-15414",
      "impact_tags": [
        "privilege boundary review",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-07T21:58:42.606809+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Subscriptions for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 2.0.0. NVD: This is due to the save_meta_boxes() function persisting the _wps_plan_user_role membership plan meta from $_POST without an allowlist that excludes privileged roles — the only validations applied, sanitize_key() and wp_roles()->is_role(), both accept... NVD: This makes it possible for authenticated attackers, with Contributor-level access and above, to escalate their privileges to Administrator by storing 'administrator' as the role granted on membership acquisition, which the Pro companion plugin then applies...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260807T220457Z/items/CVE-2026-15414.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes privilege escalation risk · authenticated boundary. Possible impact: An attacker may cross a privilege boundary and gain more access than intended.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Subscriptions for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 2.0.0. NVD: This is due to the save_meta_boxes() function persisting the _wps_plan_user_role membership plan meta from $_POST without an allowlist that excludes privileged roles — the only validations applied, sanitize_key() and wp_roles()->is_role(), both accept... NVD: This makes it possible for authenticated attackers, with Contributor-level access and above, to escalate their privileges to Administrator by storing 'administrator' as the role granted on membership acquisition, which the Pro companion plugin then applies...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15414/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15425/",
      "current_public_safe_latest": false,
      "cvss_score": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.10214,
      "epss_score": 0.00201,
      "first_observed_at": "2026-07-31T22:17:39.455090+00:00",
      "id": "CVE-2026-15425",
      "impact_tags": [
        "XSS risk",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-01T06:11:07.668739+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Yoast SEO – Advanced SEO with real-time guidance and built-in AI plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Post Slug (post_name) in all versions up to, and including, 28.0 due to insufficient input sanitization and output... NVD: This makes it possible for authenticated attackers, with author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. NVD: This requires pretty permalinks to be enabled, as the exploit chain depends on get_permalink() embedding the stored percent-encoded post_name in the generated URL.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260801T061801Z/items/CVE-2026-15425.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes XSS risk · authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Yoast SEO – Advanced SEO with real-time guidance and built-in AI plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Post Slug (post_name) in all versions up to, and including, 28.0 due to insufficient input sanitization and output... NVD: This makes it possible for authenticated attackers, with author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. NVD: This requires pretty permalinks to be enabled, as the exploit chain depends on get_permalink() embedding the stored percent-encoded post_name in the generated URL.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15425/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15427/",
      "current_public_safe_latest": false,
      "cvss_score": 8.6,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.39587,
      "epss_score": 0.005,
      "first_observed_at": "2026-07-21T16:48:32.557544+00:00",
      "id": "CVE-2026-15427",
      "impact_tags": [
        "command execution review",
        "admin privilege risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-21T16:48:32.557544+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: An OS command injection vulnerability exists in the TR-069 / CWMP management interface of Archer VX1800v v1 due to insufficient input validation and sanitization of parameters, allowing crafted input to be executed as system-level commands. NVD: Exploitation requires specific conditions such as TR-069 being enabled and ability to influence ACS-delivered commands, compromise or control an ACS server. NVD: Successful exploitation may allow arbitrary command execution with root privileges, resulting in complete compromise of the device.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260721T165442Z/items/CVE-2026-15427.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes command execution risk · admin privilege risk. Possible impact: An attacker may gain root or administrative-level privileges on affected systems.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: An OS command injection vulnerability exists in the TR-069 / CWMP management interface of Archer VX1800v v1 due to insufficient input validation and sanitization of parameters, allowing crafted input to be executed as system-level commands. NVD: Exploitation requires specific conditions such as TR-069 being enabled and ability to influence ACS-delivered commands, compromise or control an ACS server. NVD: Successful exploitation may allow arbitrary command execution with root privileges, resulting in complete compromise of the device.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15427/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15428/",
      "current_public_safe_latest": false,
      "cvss_score": 8.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.55273,
      "epss_score": 0.00885,
      "first_observed_at": "2026-07-21T16:48:32.557544+00:00",
      "id": "CVE-2026-15428",
      "impact_tags": [
        "code execution review",
        "admin privilege risk",
        "command injection risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-21T16:48:32.557544+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: An OS command injection vulnerability exists in Archer VX800v v1 due to insufficient input sanitization of the domain name parameter. NVD: An adjacent attacker who can access the relevant HTTP interface can modify the parameter to inject shell metacharacters, resulting in arbitrary code execution with root privileges. NVD: Successful exploitation may allow remote code execution and complete compromise of the device.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260721T165442Z/items/CVE-2026-15428.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes code execution review · admin privilege risk · command injection risk. Possible impact: An attacker may gain root or administrative-level privileges on affected systems.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: An OS command injection vulnerability exists in Archer VX800v v1 due to insufficient input sanitization of the domain name parameter. NVD: An adjacent attacker who can access the relevant HTTP interface can modify the parameter to inject shell metacharacters, resulting in arbitrary code execution with root privileges. NVD: Successful exploitation may allow remote code execution and complete compromise of the device.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15428/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15429/",
      "current_public_safe_latest": false,
      "cvss_score": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.31767,
      "epss_score": 0.00394,
      "first_observed_at": "2026-07-21T16:48:32.557544+00:00",
      "id": "CVE-2026-15429",
      "impact_tags": [
        "admin privilege risk",
        "privilege boundary review",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-21T16:48:32.557544+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A privilege escalation vulnerability exists in the HTTP authentication component in Archer VX1800v v1. NVD: Improper handling of user-controlled input may allow newline characters to be injected into internally constructed configuration data. NVD: An authenticated user with sufficient privileges may be able to modify account settings and gain elevated administrative privileges.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260721T165442Z/items/CVE-2026-15429.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes admin privilege risk · privilege escalation risk · authenticated boundary. Possible impact: An attacker may gain root or administrative-level privileges on affected systems.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A privilege escalation vulnerability exists in the HTTP authentication component in Archer VX1800v v1. NVD: Improper handling of user-controlled input may allow newline characters to be injected into internally constructed configuration data. NVD: An authenticated user with sufficient privileges may be able to modify account settings and gain elevated administrative privileges.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15429/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15430/",
      "current_public_safe_latest": false,
      "cvss_score": 6.2,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.01293,
      "epss_score": 0.00107,
      "first_observed_at": "2026-08-10T16:12:24.021737+00:00",
      "id": "CVE-2026-15430",
      "impact_tags": [
        "privilege boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-10T16:12:24.021737+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Improper access control in the IRP_MJ_WRITE command interface in Wellbia XIGNCODE3 xhunter2.sys, version 2026.6.1.192, allows a local, unprivileged attacker to achieve local privilege escalation to NT AUTHORITY\\SYSTEM, extract credentials from PPL-protected...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260810T162156Z/items/CVE-2026-15430.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes privilege escalation risk. Possible impact: An attacker may cross a privilege boundary and gain more access than intended.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Improper access control in the IRP_MJ_WRITE command interface in Wellbia XIGNCODE3 xhunter2.sys, version 2026.6.1.192, allows a local, unprivileged attacker to achieve local privilege escalation to NT AUTHORITY\\SYSTEM, extract credentials from PPL-protected...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15430/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15432/",
      "current_public_safe_latest": false,
      "cvss_score": 8.2,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.08416,
      "epss_score": 0.00185,
      "first_observed_at": "2026-07-28T16:54:01.667207+00:00",
      "id": "CVE-2026-15432",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-28T16:54:01.667207+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: When verifying a mac with a ChunkedMacVerification object, Tink compares the resulting tag with non constant time comparison. NVD: This potentially allows an attacker to use timinig information as a side channel in order to get information how many bytes of a given tag match the correct tag. NVD: This in turn could allow to find a correct tag bytewise.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260728T170314Z/items/CVE-2026-15432.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: When verifying a mac with a ChunkedMacVerification object, Tink compares the resulting tag with non constant time comparison. NVD: This potentially allows an attacker to use timinig information as a side channel in order to get information how many bytes of a given tag match the correct tag. NVD: This in turn could allow to find a correct tag bytewise.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15432/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15444/",
      "current_public_safe_latest": false,
      "cvss_score": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.21072,
      "epss_score": 0.00288,
      "first_observed_at": "2026-08-04T11:35:47.800052+00:00",
      "id": "CVE-2026-15444",
      "impact_tags": [
        "information exposure review",
        "SQL injection risk",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-04T11:35:47.800052+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to generic SQL Injection via the 'coupon_code' parameter in all versions up to, and including, 4.0.1 due to insufficient escaping on the user supplied parameter and lack... NVD: This makes it possible for authenticated attackers, with administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260804T114328Z/items/CVE-2026-15444.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes information exposure review · SQL injection risk · authenticated boundary. Possible impact: An attacker may be able to read or change database-backed application data.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to generic SQL Injection via the 'coupon_code' parameter in all versions up to, and including, 4.0.1 due to insufficient escaping on the user supplied parameter and lack... NVD: This makes it possible for authenticated attackers, with administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15444/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15445/",
      "current_public_safe_latest": false,
      "cvss_score": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.19306,
      "epss_score": 0.00272,
      "first_observed_at": "2026-07-22T22:28:24.662524+00:00",
      "id": "CVE-2026-15445",
      "impact_tags": [
        "information exposure review",
        "SQL injection risk",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-22T22:28:24.662524+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The SEO Booster plugin for WordPress is vulnerable to time-based SQL Injection via the 'orderby' parameter in all versions up to, and including, 7.3.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the... NVD: This makes it possible for authenticated attackers, with administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. NVD: Although esc_sql() and sanitize_text_field() are applied, neither neutralizes SQL keywords, commas, parentheses, or subquery syntax in an unquoted ORDER BY context, leaving the clause fully attacker-controlled.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260722T223443Z/items/CVE-2026-15445.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes information exposure review · SQL injection risk · authenticated boundary. Possible impact: An attacker may be able to read or change database-backed application data.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The SEO Booster plugin for WordPress is vulnerable to time-based SQL Injection via the 'orderby' parameter in all versions up to, and including, 7.3.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the... NVD: This makes it possible for authenticated attackers, with administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. NVD: Although esc_sql() and sanitize_text_field() are applied, neither neutralizes SQL keywords, commas, parentheses, or subquery syntax in an unquoted ORDER BY context, leaving the clause fully attacker-controlled.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15445/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15458/",
      "current_public_safe_latest": false,
      "cvss_score": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.19306,
      "epss_score": 0.00272,
      "first_observed_at": "2026-07-22T22:28:24.662524+00:00",
      "id": "CVE-2026-15458",
      "impact_tags": [
        "information exposure review",
        "SQL injection risk",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-22T22:28:24.662524+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The SEO Booster plugin for WordPress is vulnerable to generic SQL Injection via the 'sort_field' parameter in all versions up to, and including, 7.3.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the... NVD: This makes it possible for authenticated attackers, with administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260722T223443Z/items/CVE-2026-15458.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes information exposure review · SQL injection risk · authenticated boundary. Possible impact: An attacker may be able to read or change database-backed application data.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The SEO Booster plugin for WordPress is vulnerable to generic SQL Injection via the 'sort_field' parameter in all versions up to, and including, 7.3.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the... NVD: This makes it possible for authenticated attackers, with administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15458/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15464/",
      "current_public_safe_latest": false,
      "cvss_score": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.09307,
      "epss_score": 0.00193,
      "first_observed_at": "2026-07-31T06:26:41.124454+00:00",
      "id": "CVE-2026-15464",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-31T06:26:41.124454+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The WP Hotel Booking plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'widget_search' Shortcode Attribute in all versions up to, and including, 2.3.2 due to insufficient input sanitization and output escaping. NVD: This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260731T063057Z/items/CVE-2026-15464.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The WP Hotel Booking plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'widget_search' Shortcode Attribute in all versions up to, and including, 2.3.2 due to insufficient input sanitization and output escaping. NVD: This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15464/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15470/",
      "current_public_safe_latest": false,
      "cvss_score": 2.1,
      "cvss_severity": "LOW",
      "epss_percentile": 0.10875,
      "epss_score": 0.00207,
      "first_observed_at": "2026-07-18T16:13:43.366233+00:00",
      "id": "CVE-2026-15470",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-18T22:10:31.831314+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A vulnerability has been found in Eleveo Call Recording Software 9.7.0. NVD: Affected by this issue is some unknown functionality of the file /callrec/group.jsp. NVD: Such manipulation leads to improper authorization.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260718T221235Z/items/CVE-2026-15470.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability has been found in Eleveo Call Recording Software 9.7.0. NVD: Affected by this issue is some unknown functionality of the file /callrec/group.jsp. NVD: Such manipulation leads to improper authorization.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15470/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15471/",
      "current_public_safe_latest": false,
      "cvss_score": 2.1,
      "cvss_severity": "LOW",
      "epss_percentile": 0.10875,
      "epss_score": 0.00207,
      "first_observed_at": "2026-07-18T16:13:43.366233+00:00",
      "id": "CVE-2026-15471",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-18T22:10:31.831314+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A vulnerability was found in Eleveo Call Recording Software 9.7.0. NVD: This affects an unknown part of the file /callrec/pci_dss_status.jsp. NVD: Performing a manipulation results in improper authorization.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260718T221235Z/items/CVE-2026-15471.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability was found in Eleveo Call Recording Software 9.7.0. NVD: This affects an unknown part of the file /callrec/pci_dss_status.jsp. NVD: Performing a manipulation results in improper authorization.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15471/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15472/",
      "current_public_safe_latest": false,
      "cvss_score": 2.1,
      "cvss_severity": "LOW",
      "epss_percentile": 0.10876,
      "epss_score": 0.00207,
      "first_observed_at": "2026-07-18T16:13:43.366233+00:00",
      "id": "CVE-2026-15472",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-18T22:10:31.831314+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A vulnerability was determined in Eleveo Call Recording Software 9.7.0. NVD: This vulnerability affects unknown code of the file /callrec/composeEmailAction.do. NVD: Executing a manipulation can lead to improper authorization.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260718T221235Z/items/CVE-2026-15472.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability was determined in Eleveo Call Recording Software 9.7.0. NVD: This vulnerability affects unknown code of the file /callrec/composeEmailAction.do. NVD: Executing a manipulation can lead to improper authorization.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15472/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15473/",
      "current_public_safe_latest": false,
      "cvss_score": 2.1,
      "cvss_severity": "LOW",
      "epss_percentile": 0.10158,
      "epss_score": 0.00201,
      "first_observed_at": "2026-07-18T16:13:43.366233+00:00",
      "id": "CVE-2026-15473",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-18T22:10:31.831314+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A vulnerability was identified in Eleveo Call Recording Software 9.7.0. NVD: This issue affects some unknown processing of the file /callrec/restoreCallAction.do of the component Recorded Calls Page. NVD: The manipulation leads to improper authorization.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260718T221235Z/items/CVE-2026-15473.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability was identified in Eleveo Call Recording Software 9.7.0. NVD: This issue affects some unknown processing of the file /callrec/restoreCallAction.do of the component Recorded Calls Page. NVD: The manipulation leads to improper authorization.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15473/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15474/",
      "current_public_safe_latest": false,
      "cvss_score": 2.1,
      "cvss_severity": "LOW",
      "epss_percentile": 0.10875,
      "epss_score": 0.00207,
      "first_observed_at": "2026-07-18T16:13:43.366233+00:00",
      "id": "CVE-2026-15474",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-18T22:10:31.831314+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A security flaw has been discovered in Eleveo Call Recording Software 9.7.0. NVD: Impacted is an unknown function of the file /callrec/audio.jsp of the component Call Recording Handler. NVD: The manipulation of the argument callId results in improper authorization.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260718T221235Z/items/CVE-2026-15474.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A security flaw has been discovered in Eleveo Call Recording Software 9.7.0. NVD: Impacted is an unknown function of the file /callrec/audio.jsp of the component Call Recording Handler. NVD: The manipulation of the argument callId results in improper authorization.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15474/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15475/",
      "current_public_safe_latest": false,
      "cvss_score": 1.9,
      "cvss_severity": "LOW",
      "epss_percentile": 0.01285,
      "epss_score": 0.00105,
      "first_observed_at": "2026-07-18T16:13:43.366233+00:00",
      "id": "CVE-2026-15475",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-18T22:10:31.831314+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A weakness has been identified in MiniTool Partition Wizard up to 13.6. NVD: The affected element is an unknown function in the library pwdrvio.sys of the component Signed Kernel Driver. NVD: This manipulation causes improper access controls.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260718T221235Z/items/CVE-2026-15475.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A weakness has been identified in MiniTool Partition Wizard up to 13.6. NVD: The affected element is an unknown function in the library pwdrvio.sys of the component Signed Kernel Driver. NVD: This manipulation causes improper access controls.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15475/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15476/",
      "current_public_safe_latest": false,
      "cvss_score": 1.9,
      "cvss_severity": "LOW",
      "epss_percentile": 0.01197,
      "epss_score": 0.00103,
      "first_observed_at": "2026-07-18T16:13:43.366233+00:00",
      "id": "CVE-2026-15476",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-18T22:10:31.831314+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A security vulnerability has been detected in QILING Disk Master 6.0.0.0. NVD: The impacted element is an unknown function in the library diskbckp.sys of the component Kernel Driver. NVD: Such manipulation leads to improper access controls.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260718T221235Z/items/CVE-2026-15476.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A security vulnerability has been detected in QILING Disk Master 6.0.0.0. NVD: The impacted element is an unknown function in the library diskbckp.sys of the component Kernel Driver. NVD: Such manipulation leads to improper access controls.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15476/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15477/",
      "current_public_safe_latest": false,
      "cvss_score": 2.1,
      "cvss_severity": "LOW",
      "epss_percentile": 0.23981,
      "epss_score": 0.00319,
      "first_observed_at": "2026-07-18T16:13:43.366233+00:00",
      "id": "CVE-2026-15477",
      "impact_tags": [
        "SQL injection risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-18T22:10:31.831314+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A vulnerability was detected in Bahmni bahmnicore up to 0.93. NVD: This affects the function additionalParams of the file /openmrs/ws/rest/v1/bahmnicore/sql of the component Search Endpoint. NVD: Performing a manipulation of the argument test results in sql injection.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260718T221235Z/items/CVE-2026-15477.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes SQL injection risk. Possible impact: An attacker may be able to read or change database-backed application data.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability was detected in Bahmni bahmnicore up to 0.93. NVD: This affects the function additionalParams of the file /openmrs/ws/rest/v1/bahmnicore/sql of the component Search Endpoint. NVD: Performing a manipulation of the argument test results in sql injection.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15477/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15478/",
      "current_public_safe_latest": false,
      "cvss_score": 2.1,
      "cvss_severity": "LOW",
      "epss_percentile": 0.09079,
      "epss_score": 0.00192,
      "first_observed_at": "2026-07-18T16:13:43.366233+00:00",
      "id": "CVE-2026-15478",
      "impact_tags": [
        "SQL injection risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-18T22:10:31.831314+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A flaw has been found in IceHRM up to 35.0.1. NVD: This impacts an unknown function of the file core/src/Reports/User/Reports/EmployeeAttendanceReport.php of the component UserReport Endpoint. NVD: Executing a manipulation of the argument employeeList can lead to sql injection.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260718T221235Z/items/CVE-2026-15478.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes SQL injection risk. Possible impact: An attacker may be able to read or change database-backed application data.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A flaw has been found in IceHRM up to 35.0.1. NVD: This impacts an unknown function of the file core/src/Reports/User/Reports/EmployeeAttendanceReport.php of the component UserReport Endpoint. NVD: Executing a manipulation of the argument employeeList can lead to sql injection.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15478/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15479/",
      "current_public_safe_latest": false,
      "cvss_score": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.19787,
      "epss_score": 0.00278,
      "first_observed_at": "2026-07-18T16:13:43.366233+00:00",
      "id": "CVE-2026-15479",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-19T06:10:26.167406+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A vulnerability was found in H3C NX15 V100R017. NVD: Affected by this vulnerability is the function change_passwd of the file /api/login/modify of the component Administrator Password Modification Endpoint. NVD: The manipulation of the argument newPass results in weak password recovery.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260719T061221Z/items/CVE-2026-15479.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 3,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability was found in H3C NX15 V100R017. NVD: Affected by this vulnerability is the function change_passwd of the file /api/login/modify of the component Administrator Password Modification Endpoint. NVD: The manipulation of the argument newPass results in weak password recovery.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15479/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15480/",
      "current_public_safe_latest": false,
      "cvss_score": 7.4,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.3722,
      "epss_score": 0.00463,
      "first_observed_at": "2026-07-18T16:13:43.366233+00:00",
      "id": "CVE-2026-15480",
      "impact_tags": [
        "memory safety review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-19T06:10:26.167406+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A vulnerability was identified in Trendnet TEW-635BRM up to 1.00.03. NVD: This affects the function start_httpd of the file /sbin/rc of the component Web Service. NVD: Such manipulation of the argument device_name leads to stack-based buffer overflow.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260719T061221Z/items/CVE-2026-15480.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 3,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes memory safety review. Possible impact: The affected component has memory-safety risk that may lead to crash, privilege, or code-execution impact depending on exposure.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability was identified in Trendnet TEW-635BRM up to 1.00.03. NVD: This affects the function start_httpd of the file /sbin/rc of the component Web Service. NVD: Such manipulation of the argument device_name leads to stack-based buffer overflow.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15480/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15481/",
      "current_public_safe_latest": false,
      "cvss_score": 7.4,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.71669,
      "epss_score": 0.01514,
      "first_observed_at": "2026-07-18T16:13:43.366233+00:00",
      "id": "CVE-2026-15481",
      "impact_tags": [
        "command injection risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-19T06:10:26.167406+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A security flaw has been discovered in Trendnet TEW-635BRM up to 1.00.03. NVD: This vulnerability affects the function ipoa_test of the file /sbin/rc of the component IPoA WAN Connection Setup. NVD: Performing a manipulation of the argument ipoa_ipaddr results in command injection.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260719T061221Z/items/CVE-2026-15481.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 3,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes command injection risk. Possible impact: An attacker may be able to run unintended system commands through the affected component.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A security flaw has been discovered in Trendnet TEW-635BRM up to 1.00.03. NVD: This vulnerability affects the function ipoa_test of the file /sbin/rc of the component IPoA WAN Connection Setup. NVD: Performing a manipulation of the argument ipoa_ipaddr results in command injection.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15481/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15482/",
      "current_public_safe_latest": false,
      "cvss_score": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.168,
      "epss_score": 0.00254,
      "first_observed_at": "2026-07-18T16:13:43.366233+00:00",
      "id": "CVE-2026-15482",
      "impact_tags": [
        "SQL injection risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-19T06:10:26.167406+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A weakness has been identified in Aster Telecom Azcall 10/11. NVD: This issue affects some unknown processing of the file /azcall/adm/gestao_loja/sis.php?t=consultar of the component HTTP Handler. NVD: Executing a manipulation of the argument nome/perfil/status can lead to sql injection.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260719T061221Z/items/CVE-2026-15482.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 3,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes SQL injection risk. Possible impact: An attacker may be able to read or change database-backed application data.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A weakness has been identified in Aster Telecom Azcall 10/11. NVD: This issue affects some unknown processing of the file /azcall/adm/gestao_loja/sis.php?t=consultar of the component HTTP Handler. NVD: Executing a manipulation of the argument nome/perfil/status can lead to sql injection.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15482/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15483/",
      "current_public_safe_latest": false,
      "cvss_score": 8.7,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.37221,
      "epss_score": 0.00463,
      "first_observed_at": "2026-07-18T16:13:43.366233+00:00",
      "id": "CVE-2026-15483",
      "impact_tags": [
        "memory safety review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-19T06:10:26.167406+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A security vulnerability has been detected in TRENDnet TEW-821DAP 1.12B01. NVD: Impacted is the function sub_41EC14 of the file /goform/tools_nslookup of the component ssi. NVD: The manipulation of the argument nslookup_target leads to buffer overflow.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260719T061221Z/items/CVE-2026-15483.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 3,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes memory safety review. Possible impact: The affected component has memory-safety risk that may lead to crash, privilege, or code-execution impact depending on exposure.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A security vulnerability has been detected in TRENDnet TEW-821DAP 1.12B01. NVD: Impacted is the function sub_41EC14 of the file /goform/tools_nslookup of the component ssi. NVD: The manipulation of the argument nslookup_target leads to buffer overflow.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15483/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15484/",
      "current_public_safe_latest": false,
      "cvss_score": 8.7,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.3722,
      "epss_score": 0.00463,
      "first_observed_at": "2026-07-18T16:13:43.366233+00:00",
      "id": "CVE-2026-15484",
      "impact_tags": [
        "memory safety review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-19T06:10:26.167406+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A vulnerability was detected in TRENDnet TEW-821DAP 1.12B01. NVD: The affected element is the function sub_41EC14 of the file /goform/tools_nslookup of the component ssi. NVD: The manipulation results in buffer overflow.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260719T061221Z/items/CVE-2026-15484.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 3,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes memory safety review. Possible impact: The affected component has memory-safety risk that may lead to crash, privilege, or code-execution impact depending on exposure.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability was detected in TRENDnet TEW-821DAP 1.12B01. NVD: The affected element is the function sub_41EC14 of the file /goform/tools_nslookup of the component ssi. NVD: The manipulation results in buffer overflow.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15484/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15485/",
      "current_public_safe_latest": false,
      "cvss_score": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.60448,
      "epss_score": 0.0105,
      "first_observed_at": "2026-07-18T16:13:43.366233+00:00",
      "id": "CVE-2026-15485",
      "impact_tags": [
        "command injection risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-19T06:10:26.167406+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A flaw has been found in TRENDnet TEW-821DAP 1.11B03. NVD: The impacted element is the function sub_43F2C4 of the file /goform/tools_nslookup of the component DNS Lookup Handler. NVD: This manipulation of the argument nslookup_target/dns_server causes os command injection.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260719T061221Z/items/CVE-2026-15485.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 3,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes command injection risk. Possible impact: An attacker may be able to run unintended system commands through the affected component.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A flaw has been found in TRENDnet TEW-821DAP 1.11B03. NVD: The impacted element is the function sub_43F2C4 of the file /goform/tools_nslookup of the component DNS Lookup Handler. NVD: This manipulation of the argument nslookup_target/dns_server causes os command injection.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15485/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15486/",
      "current_public_safe_latest": false,
      "cvss_score": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.60446,
      "epss_score": 0.0105,
      "first_observed_at": "2026-07-18T16:13:43.366233+00:00",
      "id": "CVE-2026-15486",
      "impact_tags": [
        "command injection risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-19T06:10:26.167406+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A vulnerability has been found in TRENDnet TEW-821DAP 1.11B03. NVD: This affects the function sub_42026C of the file /goform/tools_ddns of the component Firmware Update Handler. NVD: Such manipulation of the argument hostname/username/password leads to os command injection.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260719T061221Z/items/CVE-2026-15486.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 3,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes command injection risk. Possible impact: An attacker may be able to run unintended system commands through the affected component.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability has been found in TRENDnet TEW-821DAP 1.11B03. NVD: This affects the function sub_42026C of the file /goform/tools_ddns of the component Firmware Update Handler. NVD: Such manipulation of the argument hostname/username/password leads to os command injection.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15486/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15487/",
      "current_public_safe_latest": false,
      "cvss_score": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.60448,
      "epss_score": 0.0105,
      "first_observed_at": "2026-07-18T16:13:43.366233+00:00",
      "id": "CVE-2026-15487",
      "impact_tags": [
        "command injection risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-19T06:10:26.167406+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A vulnerability was found in TRENDnet TEW-821DAP 1.11B03. NVD: This impacts the function sub_41FBD0 of the file /goform/system_ntp of the component Firmware Update Handler. NVD: Performing a manipulation of the argument Hostname results in os command injection.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260719T061221Z/items/CVE-2026-15487.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 3,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes command injection risk. Possible impact: An attacker may be able to run unintended system commands through the affected component.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability was found in TRENDnet TEW-821DAP 1.11B03. NVD: This impacts the function sub_41FBD0 of the file /goform/system_ntp of the component Firmware Update Handler. NVD: Performing a manipulation of the argument Hostname results in os command injection.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15487/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15488/",
      "current_public_safe_latest": false,
      "cvss_score": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.21028,
      "epss_score": 0.00291,
      "first_observed_at": "2026-07-18T22:10:31.831314+00:00",
      "id": "CVE-2026-15488",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-19T06:10:26.167406+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A vulnerability was determined in hcr707305003 shiroiAdmin 1.1/1.3. NVD: Affected is the function FileController::upload of the file app/common/controller/FileController.php. NVD: Executing a manipulation of the argument File can lead to unrestricted upload.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260719T061221Z/items/CVE-2026-15488.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability was determined in hcr707305003 shiroiAdmin 1.1/1.3. NVD: Affected is the function FileController::upload of the file app/common/controller/FileController.php. NVD: Executing a manipulation of the argument File can lead to unrestricted upload.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15488/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15489/",
      "current_public_safe_latest": false,
      "cvss_score": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.16807,
      "epss_score": 0.00254,
      "first_observed_at": "2026-07-18T22:10:31.831314+00:00",
      "id": "CVE-2026-15489",
      "impact_tags": [
        "SQL injection risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-19T06:10:26.167406+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A vulnerability was identified in RafyMrX TOKO-ONLINE-ROTI up to ddfe1cd587be0a0b5135d8b6e85cce2ec3aece99. NVD: Affected by this vulnerability is an unknown functionality of the file proses/login.php. NVD: The manipulation of the argument Username leads to sql injection.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260719T061221Z/items/CVE-2026-15489.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes SQL injection risk. Possible impact: An attacker may be able to read or change database-backed application data.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability was identified in RafyMrX TOKO-ONLINE-ROTI up to ddfe1cd587be0a0b5135d8b6e85cce2ec3aece99. NVD: Affected by this vulnerability is an unknown functionality of the file proses/login.php. NVD: The manipulation of the argument Username leads to sql injection.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15489/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15490/",
      "current_public_safe_latest": false,
      "cvss_score": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.31615,
      "epss_score": 0.00393,
      "first_observed_at": "2026-07-19T06:10:26.167406+00:00",
      "id": "CVE-2026-15490",
      "impact_tags": [
        "SQL injection risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-19T06:10:26.167406+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A security flaw has been discovered in RafyMrX TOKO-ONLINE-ROTI up to ddfe1cd587be0a0b5135d8b6e85cce2ec3aece99. NVD: Affected by this issue is some unknown functionality of the file proses/add.php. NVD: The manipulation of the argument kode_produk/kd_cs results in sql injection.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260719T061221Z/items/CVE-2026-15490.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes SQL injection risk. Possible impact: An attacker may be able to read or change database-backed application data.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A security flaw has been discovered in RafyMrX TOKO-ONLINE-ROTI up to ddfe1cd587be0a0b5135d8b6e85cce2ec3aece99. NVD: Affected by this issue is some unknown functionality of the file proses/add.php. NVD: The manipulation of the argument kode_produk/kd_cs results in sql injection.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15490/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15491/",
      "current_public_safe_latest": false,
      "cvss_score": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.46008,
      "epss_score": 0.00627,
      "first_observed_at": "2026-07-19T06:10:26.167406+00:00",
      "id": "CVE-2026-15491",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-19T06:10:26.167406+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A weakness has been identified in RafyMrX TOKO-ONLINE-ROTI up to ddfe1cd587be0a0b5135d8b6e85cce2ec3aece99. NVD: This affects an unknown part. NVD: This manipulation causes missing authentication.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260719T061221Z/items/CVE-2026-15491.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A weakness has been identified in RafyMrX TOKO-ONLINE-ROTI up to ddfe1cd587be0a0b5135d8b6e85cce2ec3aece99. NVD: This affects an unknown part. NVD: This manipulation causes missing authentication.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15491/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15492/",
      "current_public_safe_latest": false,
      "cvss_score": 2.1,
      "cvss_severity": "LOW",
      "epss_percentile": 0.34298,
      "epss_score": 0.00422,
      "first_observed_at": "2026-07-19T06:10:26.167406+00:00",
      "id": "CVE-2026-15492",
      "impact_tags": [
        "XSS risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-19T10:46:12.896763+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A security vulnerability has been detected in igweze wizgrade up to b1d55f22b90cd7e7a6e5002f006d7c649e8086d6. NVD: This vulnerability affects unknown code of the file dashboard/studentConductManager.php. NVD: Such manipulation leads to cross site scripting.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260719T105023Z/items/CVE-2026-15492.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes XSS risk. Possible impact: This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A security vulnerability has been detected in igweze wizgrade up to b1d55f22b90cd7e7a6e5002f006d7c649e8086d6. NVD: This vulnerability affects unknown code of the file dashboard/studentConductManager.php. NVD: Such manipulation leads to cross site scripting.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15492/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15493/",
      "current_public_safe_latest": false,
      "cvss_score": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.08909,
      "epss_score": 0.00191,
      "first_observed_at": "2026-07-19T06:10:26.167406+00:00",
      "id": "CVE-2026-15493",
      "impact_tags": [
        "XSS risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-19T10:46:12.896763+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A vulnerability was detected in Akpali9 Attendance-Management-System up to 70b91fe38f4195b701a45f0edcd4f42d5f64aeee. NVD: This issue affects some unknown processing of the file absent.php. NVD: Performing a manipulation of the argument export_date results in cross site scripting.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260719T105023Z/items/CVE-2026-15493.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes XSS risk. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability was detected in Akpali9 Attendance-Management-System up to 70b91fe38f4195b701a45f0edcd4f42d5f64aeee. NVD: This issue affects some unknown processing of the file absent.php. NVD: Performing a manipulation of the argument export_date results in cross site scripting.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15493/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15494/",
      "current_public_safe_latest": false,
      "cvss_score": 2.0,
      "cvss_severity": "LOW",
      "epss_percentile": 0.10209,
      "epss_score": 0.00202,
      "first_observed_at": "2026-07-19T06:10:26.167406+00:00",
      "id": "CVE-2026-15494",
      "impact_tags": [
        "SQL injection risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-19T10:46:12.896763+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A flaw has been found in AMTT Hotel Broadband Operation System 1.0. NVD: Impacted is an unknown function of the file manager/network/switch_status.php. NVD: Executing a manipulation of the argument ID can lead to sql injection.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260719T105023Z/items/CVE-2026-15494.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes SQL injection risk. Possible impact: An attacker may be able to read or change database-backed application data.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A flaw has been found in AMTT Hotel Broadband Operation System 1.0. NVD: Impacted is an unknown function of the file manager/network/switch_status.php. NVD: Executing a manipulation of the argument ID can lead to sql injection.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15494/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15495/",
      "current_public_safe_latest": false,
      "cvss_score": 2.1,
      "cvss_severity": "LOW",
      "epss_percentile": 0.72173,
      "epss_score": 0.01543,
      "first_observed_at": "2026-07-19T06:10:26.167406+00:00",
      "id": "CVE-2026-15495",
      "impact_tags": [
        "command injection risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-19T10:46:12.896763+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A vulnerability has been found in SonicCloudOrg sonic-agent up to 2.7.2. NVD: The affected element is an unknown function of the file AndroidWSServer.java of the component Android WebSocket Server. NVD: The manipulation of the argument path leads to os command injection.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260719T105023Z/items/CVE-2026-15495.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes command injection risk. Possible impact: An attacker may be able to run unintended system commands through the affected component.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability has been found in SonicCloudOrg sonic-agent up to 2.7.2. NVD: The affected element is an unknown function of the file AndroidWSServer.java of the component Android WebSocket Server. NVD: The manipulation of the argument path leads to os command injection.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15495/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15496/",
      "current_public_safe_latest": false,
      "cvss_score": 2.1,
      "cvss_severity": "LOW",
      "epss_percentile": 0.63528,
      "epss_score": 0.01158,
      "first_observed_at": "2026-07-19T06:10:26.167406+00:00",
      "id": "CVE-2026-15496",
      "impact_tags": [
        "command injection risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-19T10:46:12.896763+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A vulnerability was found in SonicCloudOrg sonic-agent up to 2.7.2. NVD: The impacted element is the function evalIsFailed of the file sonic-agent/src/main/java/org/cloud/sonic/agent/tests/script/GroovyScriptImpl.java of the component Groovy Script Handler. NVD: The manipulation results in os command injection.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260719T105023Z/items/CVE-2026-15496.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes command injection risk. Possible impact: An attacker may be able to run unintended system commands through the affected component.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability was found in SonicCloudOrg sonic-agent up to 2.7.2. NVD: The impacted element is the function evalIsFailed of the file sonic-agent/src/main/java/org/cloud/sonic/agent/tests/script/GroovyScriptImpl.java of the component Groovy Script Handler. NVD: The manipulation results in os command injection.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15496/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15497/",
      "current_public_safe_latest": false,
      "cvss_score": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.31653,
      "epss_score": 0.00394,
      "first_observed_at": "2026-07-19T06:10:26.167406+00:00",
      "id": "CVE-2026-15497",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-19T10:46:12.896763+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A vulnerability was determined in SonicCloudOrg sonic-agent up to 2.7.2. NVD: This affects an unknown function of the file sonic-server-controller/src/main/java/org/cloud/sonic/controller/controller/ExchangeController.java of the component JWT Authentication Filter. NVD: This manipulation causes code injection.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260719T105023Z/items/CVE-2026-15497.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability was determined in SonicCloudOrg sonic-agent up to 2.7.2. NVD: This affects an unknown function of the file sonic-server-controller/src/main/java/org/cloud/sonic/controller/controller/ExchangeController.java of the component JWT Authentication Filter. NVD: This manipulation causes code injection.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15497/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15498/",
      "current_public_safe_latest": false,
      "cvss_score": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.16796,
      "epss_score": 0.00254,
      "first_observed_at": "2026-07-19T06:10:26.167406+00:00",
      "id": "CVE-2026-15498",
      "impact_tags": [
        "SQL injection risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-19T10:46:12.896763+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A vulnerability was identified in sergomanov SmartHomeAdatum up to cf495353d81b680675eb8d9aa14a318aa45ce12c. NVD: This impacts an unknown function of the file users.php of the component Login. NVD: Such manipulation of the argument Login leads to sql injection.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260719T105023Z/items/CVE-2026-15498.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes SQL injection risk. Possible impact: An attacker may be able to read or change database-backed application data.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability was identified in sergomanov SmartHomeAdatum up to cf495353d81b680675eb8d9aa14a318aa45ce12c. NVD: This impacts an unknown function of the file users.php of the component Login. NVD: Such manipulation of the argument Login leads to sql injection.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15498/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15499/",
      "current_public_safe_latest": false,
      "cvss_score": 2.1,
      "cvss_severity": "LOW",
      "epss_percentile": 0.10158,
      "epss_score": 0.00201,
      "first_observed_at": "2026-07-19T10:46:12.896763+00:00",
      "id": "CVE-2026-15499",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-19T10:46:12.896763+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A security flaw has been discovered in AstrBotDevs AstrBot up to 4.25.2. NVD: Affected is the function FutureTaskTool.call of the file astrbot/core/tools/cron_tools.py of the component Scheduled Task Handler. NVD: Remote exploitation of the attack is possible.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260719T105023Z/items/CVE-2026-15499.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A security flaw has been discovered in AstrBotDevs AstrBot up to 4.25.2. NVD: Affected is the function FutureTaskTool.call of the file astrbot/core/tools/cron_tools.py of the component Scheduled Task Handler. NVD: Remote exploitation of the attack is possible.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15499/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15500/",
      "current_public_safe_latest": false,
      "cvss_score": 2.1,
      "cvss_severity": "LOW",
      "epss_percentile": 0.11153,
      "epss_score": 0.00209,
      "first_observed_at": "2026-07-19T10:46:12.896763+00:00",
      "id": "CVE-2026-15500",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-19T10:46:12.896763+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A weakness has been identified in AstrBotDevs AstrBot up to 4.25.2. NVD: Affected by this vulnerability is the function get_online_plugins of the file astrbot/dashboard/routes/plugin.py of the component market_list Endpoint. NVD: Executing a manipulation of the argument custom_registry can lead to server-side request forgery.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260719T105023Z/items/CVE-2026-15500.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A weakness has been identified in AstrBotDevs AstrBot up to 4.25.2. NVD: Affected by this vulnerability is the function get_online_plugins of the file astrbot/dashboard/routes/plugin.py of the component market_list Endpoint. NVD: Executing a manipulation of the argument custom_registry can lead to server-side request forgery.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15500/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15505/",
      "current_public_safe_latest": false,
      "cvss_score": 2.0,
      "cvss_severity": "LOW",
      "epss_percentile": 0.09365,
      "epss_score": 0.00195,
      "first_observed_at": "2026-07-19T16:14:19.593713+00:00",
      "id": "CVE-2026-15505",
      "impact_tags": [
        "XSS risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-19T16:14:19.593713+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A weakness has been identified in vnotex vnote up to 3.20.1. NVD: Impacted is an unknown function of the file /src/data/extra/web/js/markdownit.js of the component YAML Frontmatter. NVD: This manipulation of the argument p_metaData causes cross site scripting.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260719T161618Z/items/CVE-2026-15505.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes XSS risk. Possible impact: This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A weakness has been identified in vnotex vnote up to 3.20.1. NVD: Impacted is an unknown function of the file /src/data/extra/web/js/markdownit.js of the component YAML Frontmatter. NVD: This manipulation of the argument p_metaData causes cross site scripting.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15505/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15506/",
      "current_public_safe_latest": false,
      "cvss_score": 7.1,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.08137,
      "epss_score": 0.00184,
      "first_observed_at": "2026-07-19T16:14:19.593713+00:00",
      "id": "CVE-2026-15506",
      "impact_tags": [
        "memory safety review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-19T22:12:13.502361+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A security vulnerability has been detected in SecureAge CatchPulse up to 10.9.3. NVD: The affected element is an unknown function in the library saappctl.sys of the component Driver. NVD: Such manipulation leads to heap-based buffer overflow.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260719T221823Z/items/CVE-2026-15506.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes memory safety review. Possible impact: The affected component has memory-safety risk that may lead to crash, privilege, or code-execution impact depending on exposure.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A security vulnerability has been detected in SecureAge CatchPulse up to 10.9.3. NVD: The affected element is an unknown function in the library saappctl.sys of the component Driver. NVD: Such manipulation leads to heap-based buffer overflow.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15506/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15507/",
      "current_public_safe_latest": false,
      "cvss_score": 2.1,
      "cvss_severity": "LOW",
      "epss_percentile": 0.2544,
      "epss_score": 0.00333,
      "first_observed_at": "2026-07-19T16:14:19.593713+00:00",
      "id": "CVE-2026-15507",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-19T22:12:13.502361+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A vulnerability was detected in coollabsio Coolify up to 4.1.1. NVD: The impacted element is an unknown function of the file /app/Policies/ of the component Policy Handler. NVD: Performing a manipulation results in missing authorization.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260719T221823Z/items/CVE-2026-15507.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability was detected in coollabsio Coolify up to 4.1.1. NVD: The impacted element is an unknown function of the file /app/Policies/ of the component Policy Handler. NVD: Performing a manipulation results in missing authorization.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15507/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15508/",
      "current_public_safe_latest": false,
      "cvss_score": 2.1,
      "cvss_severity": "LOW",
      "epss_percentile": 0.25441,
      "epss_score": 0.00333,
      "first_observed_at": "2026-07-19T16:14:19.593713+00:00",
      "id": "CVE-2026-15508",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-19T22:12:13.502361+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A flaw has been found in Helicone ai-gateway up to 0.2.0-beta.30. NVD: This affects the function build_target_url of the file ai-gateway/src/dispatcher/service.rs of the component AWS Metadata Service. NVD: Executing a manipulation of the argument extracted_path_and_query can lead to server-side request forgery.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260719T221823Z/items/CVE-2026-15508.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A flaw has been found in Helicone ai-gateway up to 0.2.0-beta.30. NVD: This affects the function build_target_url of the file ai-gateway/src/dispatcher/service.rs of the component AWS Metadata Service. NVD: Executing a manipulation of the argument extracted_path_and_query can lead to server-side request forgery.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15508/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15509/",
      "current_public_safe_latest": false,
      "cvss_score": 2.1,
      "cvss_severity": "LOW",
      "epss_percentile": 0.25441,
      "epss_score": 0.00333,
      "first_observed_at": "2026-07-19T16:14:19.593713+00:00",
      "id": "CVE-2026-15509",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-19T22:12:13.502361+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A vulnerability has been found in Leantime up to 3.8.0. NVD: This impacts the function editUser/addUser of the component JSON-RPC Endpoint. NVD: The manipulation of the argument role leads to improper authorization.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260719T221823Z/items/CVE-2026-15509.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability has been found in Leantime up to 3.8.0. NVD: This impacts the function editUser/addUser of the component JSON-RPC Endpoint. NVD: The manipulation of the argument role leads to improper authorization.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15509/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15510/",
      "current_public_safe_latest": false,
      "cvss_score": 2.1,
      "cvss_severity": "LOW",
      "epss_percentile": 0.2544,
      "epss_score": 0.00333,
      "first_observed_at": "2026-07-19T16:14:19.593713+00:00",
      "id": "CVE-2026-15510",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-19T22:12:13.502361+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A vulnerability was found in Leantime up to 3.8.0. NVD: Affected is the function Setting::saveSetting of the component API. NVD: The manipulation results in improper authorization.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260719T221823Z/items/CVE-2026-15510.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability was found in Leantime up to 3.8.0. NVD: Affected is the function Setting::saveSetting of the component API. NVD: The manipulation results in improper authorization.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15510/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15511/",
      "current_public_safe_latest": false,
      "cvss_score": 8.9,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.842,
      "epss_score": 0.0269,
      "first_observed_at": "2026-07-19T16:14:19.593713+00:00",
      "id": "CVE-2026-15511",
      "impact_tags": [
        "command injection risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-19T22:12:13.502361+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A vulnerability was determined in Comfast CF-WR631AX V3 up to 2.7.0.8. NVD: Affected by this vulnerability is the function system_wl_upload_pic_file of the file /usr/bin/webmgnt of the component FastCGI Backend. NVD: This manipulation of the argument filename causes os command injection.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260719T221823Z/items/CVE-2026-15511.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes command injection risk. Possible impact: An attacker may be able to run unintended system commands through the affected component.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability was determined in Comfast CF-WR631AX V3 up to 2.7.0.8. NVD: Affected by this vulnerability is the function system_wl_upload_pic_file of the file /usr/bin/webmgnt of the component FastCGI Backend. NVD: This manipulation of the argument filename causes os command injection.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15511/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15512/",
      "current_public_safe_latest": false,
      "cvss_score": 2.1,
      "cvss_severity": "LOW",
      "epss_percentile": 0.29867,
      "epss_score": 0.00376,
      "first_observed_at": "2026-07-19T16:14:19.593713+00:00",
      "id": "CVE-2026-15512",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-19T22:12:13.502361+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A vulnerability was identified in pig-mesh Pig up to 3.9.2. NVD: Affected by this issue is some unknown functionality of the file \\pig-master\\pig-visual\\pig-codegen\\src\\main\\java\\com\\pig4cloud\\pig\\codegen\\service\\impl\\GeneratorServiceImpl.java of the component pig-codegen. NVD: Such manipulation leads to code injection.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260719T221823Z/items/CVE-2026-15512.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability was identified in pig-mesh Pig up to 3.9.2. NVD: Affected by this issue is some unknown functionality of the file \\pig-master\\pig-visual\\pig-codegen\\src\\main\\java\\com\\pig4cloud\\pig\\codegen\\service\\impl\\GeneratorServiceImpl.java of the component pig-codegen. NVD: Such manipulation leads to code injection.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15512/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15513/",
      "current_public_safe_latest": false,
      "cvss_score": 2.1,
      "cvss_severity": "LOW",
      "epss_percentile": 0.69884,
      "epss_score": 0.01422,
      "first_observed_at": "2026-07-19T16:14:19.593713+00:00",
      "id": "CVE-2026-15513",
      "impact_tags": [
        "command injection risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-19T22:12:13.502361+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A security flaw has been discovered in Wavlink WL-NU516U1 260515. NVD: This affects the function wlink_uci_set_value of the file /cgi-bin/adm.cgi. NVD: Performing a manipulation of the argument lan_ip results in os command injection.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260719T221823Z/items/CVE-2026-15513.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes command injection risk. Possible impact: An attacker may be able to run unintended system commands through the affected component.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: of.",
      "source_published_summary": "NVD: A security flaw has been discovered in Wavlink WL-NU516U1 260515. NVD: This affects the function wlink_uci_set_value of the file /cgi-bin/adm.cgi. NVD: Performing a manipulation of the argument lan_ip results in os command injection.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15513/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15514/",
      "current_public_safe_latest": false,
      "cvss_score": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.16804,
      "epss_score": 0.00254,
      "first_observed_at": "2026-07-19T16:14:19.593713+00:00",
      "id": "CVE-2026-15514",
      "impact_tags": [
        "SQL injection risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-19T22:12:13.502361+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A weakness has been identified in Metasoft 美特软件 MetaCRM up to 6.4.0 Beta06. NVD: This vulnerability affects the function RPCService.query of the file /customizemt/xkq/rpc.jsp of the component PHPRPC Remote Call Interface. NVD: Executing a manipulation of the argument phprpc_args can lead to sql injection.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260719T221823Z/items/CVE-2026-15514.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes SQL injection risk. Possible impact: An attacker may be able to read or change database-backed application data.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A weakness has been identified in Metasoft 美特软件 MetaCRM up to 6.4.0 Beta06. NVD: This vulnerability affects the function RPCService.query of the file /customizemt/xkq/rpc.jsp of the component PHPRPC Remote Call Interface. NVD: Executing a manipulation of the argument phprpc_args can lead to sql injection.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15514/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15515/",
      "current_public_safe_latest": false,
      "cvss_score": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.01924,
      "epss_score": 0.00116,
      "first_observed_at": "2026-07-19T16:14:19.593713+00:00",
      "id": "CVE-2026-15515",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-19T22:12:13.502361+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A security vulnerability has been detected in Tencent PC Manager 18.1.30242.301. NVD: This issue affects some unknown processing in the library qmudisk64.sys of the component QMUDisk Driver. NVD: The manipulation leads to uncontrolled search path.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260719T221823Z/items/CVE-2026-15515.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A security vulnerability has been detected in Tencent PC Manager 18.1.30242.301. NVD: This issue affects some unknown processing in the library qmudisk64.sys of the component QMUDisk Driver. NVD: The manipulation leads to uncontrolled search path.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15515/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15516/",
      "current_public_safe_latest": false,
      "cvss_score": 2.9,
      "cvss_severity": "LOW",
      "epss_percentile": 0.19366,
      "epss_score": 0.00274,
      "first_observed_at": "2026-07-19T16:14:19.593713+00:00",
      "id": "CVE-2026-15516",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-19T22:12:13.502361+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A vulnerability was detected in MacCMS Pro up to 2022.1000.3005. NVD: Impacted is the function step5 of the file application/install/controller/Index.php of the component Installation Module. NVD: The manipulation results in authorization bypass.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260719T221823Z/items/CVE-2026-15516.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability was detected in MacCMS Pro up to 2022.1000.3005. NVD: Impacted is the function step5 of the file application/install/controller/Index.php of the component Installation Module. NVD: The manipulation results in authorization bypass.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15516/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15517/",
      "current_public_safe_latest": false,
      "cvss_score": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.16801,
      "epss_score": 0.00254,
      "first_observed_at": "2026-07-19T16:14:19.593713+00:00",
      "id": "CVE-2026-15517",
      "impact_tags": [
        "SQL injection risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-19T22:12:13.502361+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A flaw has been found in Jinher OA 1.0. NVD: The affected element is an unknown function of the file /C6/JHSoft.Web.PlanSummarize/PlanGiveOut.aspx. NVD: This manipulation of the argument httpOID causes sql injection.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260719T221823Z/items/CVE-2026-15517.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes SQL injection risk. Possible impact: An attacker may be able to read or change database-backed application data.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A flaw has been found in Jinher OA 1.0. NVD: The affected element is an unknown function of the file /C6/JHSoft.Web.PlanSummarize/PlanGiveOut.aspx. NVD: This manipulation of the argument httpOID causes sql injection.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15517/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15518/",
      "current_public_safe_latest": false,
      "cvss_score": 2.0,
      "cvss_severity": "LOW",
      "epss_percentile": 0.16079,
      "epss_score": 0.00248,
      "first_observed_at": "2026-07-19T22:12:13.502361+00:00",
      "id": "CVE-2026-15518",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-19T22:12:13.502361+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A vulnerability has been found in AREA 17 Twill CMS up to 3.6.0. NVD: The impacted element is the function FileLibraryController::storeFile of the file src/Http/Controllers/Admin/FileLibraryController.php of the component Media Library Insert Page. NVD: Such manipulation of the argument qqfilename leads to unrestricted upload.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260719T221823Z/items/CVE-2026-15518.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability has been found in AREA 17 Twill CMS up to 3.6.0. NVD: The impacted element is the function FileLibraryController::storeFile of the file src/Http/Controllers/Admin/FileLibraryController.php of the component Media Library Insert Page. NVD: Such manipulation of the argument qqfilename leads to unrestricted upload.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15518/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15519/",
      "current_public_safe_latest": false,
      "cvss_score": 1.3,
      "cvss_severity": "LOW",
      "epss_percentile": 0.14832,
      "epss_score": 0.00238,
      "first_observed_at": "2026-07-19T22:12:13.502361+00:00",
      "id": "CVE-2026-15519",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-19T22:12:13.502361+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A vulnerability was found in usestrix strix up to 1.0.2. NVD: This affects an unknown function of the file system_prompt.jinja of the component PyPI Handler. NVD: Performing a manipulation results in inclusion of functionality from untrusted control sphere.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260719T221823Z/items/CVE-2026-15519.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability was found in usestrix strix up to 1.0.2. NVD: This affects an unknown function of the file system_prompt.jinja of the component PyPI Handler. NVD: Performing a manipulation results in inclusion of functionality from untrusted control sphere.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15519/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15520/",
      "current_public_safe_latest": false,
      "cvss_score": 1.9,
      "cvss_severity": "LOW",
      "epss_percentile": 0.03451,
      "epss_score": 0.00136,
      "first_observed_at": "2026-07-19T22:12:13.502361+00:00",
      "id": "CVE-2026-15520",
      "impact_tags": [
        "memory safety review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-19T22:12:13.502361+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A vulnerability was determined in GNU LibreDWG 0.13.4-154-g0b573035. NVD: This impacts the function decompress_R2004_section of the file src/decode.c of the component R2004 Section Decompression. NVD: Executing a manipulation can lead to heap-based buffer overflow.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260719T221823Z/items/CVE-2026-15520.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes memory safety review. Possible impact: The affected component has memory-safety risk that may lead to crash, privilege, or code-execution impact depending on exposure.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability was determined in GNU LibreDWG 0.13.4-154-g0b573035. NVD: This impacts the function decompress_R2004_section of the file src/decode.c of the component R2004 Section Decompression. NVD: Executing a manipulation can lead to heap-based buffer overflow.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15520/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15521/",
      "current_public_safe_latest": false,
      "cvss_score": 1.9,
      "cvss_severity": "LOW",
      "epss_percentile": 0.03509,
      "epss_score": 0.00137,
      "first_observed_at": "2026-07-19T22:12:13.502361+00:00",
      "id": "CVE-2026-15521",
      "impact_tags": [
        "path traversal review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-19T22:12:13.502361+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A vulnerability was identified in makafeli n8n-workflow-builder up to 0.11.0. NVD: Affected is an unknown function of the file build/server.cjs of the component update_node_from_file. NVD: The manipulation of the argument filePath leads to path traversal.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260719T221823Z/items/CVE-2026-15521.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes path traversal review. Possible impact: An attacker may be able to reach files outside the intended application path.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability was identified in makafeli n8n-workflow-builder up to 0.11.0. NVD: Affected is an unknown function of the file build/server.cjs of the component update_node_from_file. NVD: The manipulation of the argument filePath leads to path traversal.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15521/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15522/",
      "current_public_safe_latest": false,
      "cvss_score": 1.9,
      "cvss_severity": "LOW",
      "epss_percentile": 0.03508,
      "epss_score": 0.00137,
      "first_observed_at": "2026-07-19T22:12:13.502361+00:00",
      "id": "CVE-2026-15522",
      "impact_tags": [
        "path traversal review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-19T22:12:13.502361+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A security flaw has been discovered in tugcantopaloglu godot-mcp 2.0.0. NVD: Affected by this vulnerability is the function validatePath of the file build/index.js of the component run_project. NVD: The manipulation of the argument projectPath results in path traversal.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260719T221823Z/items/CVE-2026-15522.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes path traversal review. Possible impact: An attacker may be able to reach files outside the intended application path.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A security flaw has been discovered in tugcantopaloglu godot-mcp 2.0.0. NVD: Affected by this vulnerability is the function validatePath of the file build/index.js of the component run_project. NVD: The manipulation of the argument projectPath results in path traversal.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15522/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15523/",
      "current_public_safe_latest": false,
      "cvss_score": 2.1,
      "cvss_severity": "LOW",
      "epss_percentile": 0.09986,
      "epss_score": 0.002,
      "first_observed_at": "2026-07-19T22:12:13.502361+00:00",
      "id": "CVE-2026-15523",
      "impact_tags": [
        "SQL injection risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-19T22:12:13.502361+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A weakness has been identified in CodeAstro Simple Online Leave Management System 1.0. NVD: Affected by this issue is some unknown functionality of the file /SimpleOnlineLeave/admin/dashboard.php. NVD: This manipulation of the argument Name causes sql injection.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260719T221823Z/items/CVE-2026-15523.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes SQL injection risk. Possible impact: An attacker may be able to read or change database-backed application data.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A weakness has been identified in CodeAstro Simple Online Leave Management System 1.0. NVD: Affected by this issue is some unknown functionality of the file /SimpleOnlineLeave/admin/dashboard.php. NVD: This manipulation of the argument Name causes sql injection.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15523/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15524/",
      "current_public_safe_latest": false,
      "cvss_score": 1.9,
      "cvss_severity": "LOW",
      "epss_percentile": 0.03508,
      "epss_score": 0.00137,
      "first_observed_at": "2026-07-19T22:12:13.502361+00:00",
      "id": "CVE-2026-15524",
      "impact_tags": [
        "path traversal review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-19T22:12:13.502361+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A security vulnerability has been detected in alioshr memory-bank-mcp up to 0.2.1/3.1. NVD: This affects an unknown part of the file list-project-files-validation-factory.ts. NVD: Such manipulation of the argument projectName leads to path traversal.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260719T221823Z/items/CVE-2026-15524.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes path traversal review. Possible impact: An attacker may be able to reach files outside the intended application path.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A security vulnerability has been detected in alioshr memory-bank-mcp up to 0.2.1/3.1. NVD: This affects an unknown part of the file list-project-files-validation-factory.ts. NVD: Such manipulation of the argument projectName leads to path traversal.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15524/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15536/",
      "current_public_safe_latest": false,
      "cvss_score": 2.1,
      "cvss_severity": "LOW",
      "epss_percentile": 0.09992,
      "epss_score": 0.002,
      "first_observed_at": "2026-07-20T06:28:37.060083+00:00",
      "id": "CVE-2026-15536",
      "impact_tags": [
        "SQL injection risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-20T06:28:37.060083+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A vulnerability was identified in itsourcecode Hospital Management System 1.0. NVD: This affects an unknown part of the file /patviewprescription.php. NVD: The manipulation of the argument delid leads to sql injection.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260720T063049Z/items/CVE-2026-15536.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes SQL injection risk. Possible impact: An attacker may be able to read or change database-backed application data.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability was identified in itsourcecode Hospital Management System 1.0. NVD: This affects an unknown part of the file /patviewprescription.php. NVD: The manipulation of the argument delid leads to sql injection.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15536/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15537/",
      "current_public_safe_latest": false,
      "cvss_score": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.17824,
      "epss_score": 0.00263,
      "first_observed_at": "2026-07-20T06:28:37.060083+00:00",
      "id": "CVE-2026-15537",
      "impact_tags": [
        "SQL injection risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-20T06:28:37.060083+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A security flaw has been discovered in SourceCodester Online Book Store System 1.0. NVD: This vulnerability affects unknown code of the file admin/login.php. NVD: The manipulation of the argument Username results in sql injection.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260720T063049Z/items/CVE-2026-15537.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes SQL injection risk. Possible impact: An attacker may be able to read or change database-backed application data.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A security flaw has been discovered in SourceCodester Online Book Store System 1.0. NVD: This vulnerability affects unknown code of the file admin/login.php. NVD: The manipulation of the argument Username results in sql injection.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15537/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15538/",
      "current_public_safe_latest": false,
      "cvss_score": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.1702,
      "epss_score": 0.00256,
      "first_observed_at": "2026-07-20T06:28:37.060083+00:00",
      "id": "CVE-2026-15538",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-20T06:28:37.060083+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A weakness has been identified in primefaces primereact up to 10.9.8. NVD: This issue affects the function ObjectUtils.mutateFieldData of the component API. NVD: This manipulation of the argument Field causes improperly controlled modification of object prototype attributes.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260720T063049Z/items/CVE-2026-15538.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A weakness has been identified in primefaces primereact up to 10.9.8. NVD: This issue affects the function ObjectUtils.mutateFieldData of the component API. NVD: This manipulation of the argument Field causes improperly controlled modification of object prototype attributes.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15538/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15539/",
      "current_public_safe_latest": false,
      "cvss_score": 2.0,
      "cvss_severity": "LOW",
      "epss_percentile": 0.13389,
      "epss_score": 0.00227,
      "first_observed_at": "2026-07-20T06:28:37.060083+00:00",
      "id": "CVE-2026-15539",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-20T06:28:37.060083+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A security vulnerability has been detected in SourceCodester Online Book Store System 1.0. NVD: Impacted is an unknown function of the file /admin/index.php?page=books of the component Book Image Upload Feature. NVD: Such manipulation leads to unrestricted upload.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260720T063049Z/items/CVE-2026-15539.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A security vulnerability has been detected in SourceCodester Online Book Store System 1.0. NVD: Impacted is an unknown function of the file /admin/index.php?page=books of the component Book Image Upload Feature. NVD: Such manipulation leads to unrestricted upload.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15539/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15540/",
      "current_public_safe_latest": false,
      "cvss_score": 2.1,
      "cvss_severity": "LOW",
      "epss_percentile": 0.15293,
      "epss_score": 0.00242,
      "first_observed_at": "2026-07-20T06:28:37.060083+00:00",
      "id": "CVE-2026-15540",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-20T06:28:37.060083+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A vulnerability was detected in SourceCodester Online Book Store System 1.0. NVD: The affected element is an unknown function of the file /admin/index.php of the component Administrative Interface. NVD: Performing a manipulation of the argument page results in improper control of filename for include/require statement in php program.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260720T063049Z/items/CVE-2026-15540.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability was detected in SourceCodester Online Book Store System 1.0. NVD: The affected element is an unknown function of the file /admin/index.php of the component Administrative Interface. NVD: Performing a manipulation of the argument page results in improper control of filename for include/require statement in php program.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15540/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15541/",
      "current_public_safe_latest": false,
      "cvss_score": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.23672,
      "epss_score": 0.00316,
      "first_observed_at": "2026-07-20T06:28:37.060083+00:00",
      "id": "CVE-2026-15541",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-20T06:28:37.060083+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A flaw has been found in will-moss Isaiah up to 1.36.9. NVD: The impacted element is the function Server.Handle of the file app/server/server/server.go of the component Master Websocket Handler. NVD: Executing a manipulation of the argument Agent can lead to missing authorization.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260720T063049Z/items/CVE-2026-15541.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A flaw has been found in will-moss Isaiah up to 1.36.9. NVD: The impacted element is the function Server.Handle of the file app/server/server/server.go of the component Master Websocket Handler. NVD: Executing a manipulation of the argument Agent can lead to missing authorization.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15541/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15542/",
      "current_public_safe_latest": false,
      "cvss_score": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.32603,
      "epss_score": 0.00403,
      "first_observed_at": "2026-07-20T06:28:37.060083+00:00",
      "id": "CVE-2026-15542",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-20T06:28:37.060083+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A vulnerability has been found in will-moss Isaiah up to 1.36.9. NVD: This affects an unknown function of the file app/main.go of the component Websocket Connection Authentication. NVD: The manipulation leads to improper authentication.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260720T063049Z/items/CVE-2026-15542.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability has been found in will-moss Isaiah up to 1.36.9. NVD: This affects an unknown function of the file app/main.go of the component Websocket Connection Authentication. NVD: The manipulation leads to improper authentication.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15542/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15543/",
      "current_public_safe_latest": false,
      "cvss_score": 7.4,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.37456,
      "epss_score": 0.00466,
      "first_observed_at": "2026-07-20T06:28:37.060083+00:00",
      "id": "CVE-2026-15543",
      "impact_tags": [
        "memory safety review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-20T06:28:37.060083+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A vulnerability was found in Tenda CH22 1.0.0.1. NVD: This impacts the function formCertListInfo of the file /goform/CertListInfo. NVD: The manipulation of the argument Name results in buffer overflow.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260720T063049Z/items/CVE-2026-15543.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes memory safety review. Possible impact: The affected component has memory-safety risk that may lead to crash, privilege, or code-execution impact depending on exposure.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability was found in Tenda CH22 1.0.0.1. NVD: This impacts the function formCertListInfo of the file /goform/CertListInfo. NVD: The manipulation of the argument Name results in buffer overflow.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15543/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15551/",
      "current_public_safe_latest": false,
      "cvss_score": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.00259,
      "epss_score": 0.00081,
      "first_observed_at": "2026-07-19T22:12:13.502361+00:00",
      "id": "CVE-2026-15551",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-19T22:12:13.502361+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Integer overflow or wraparound vulnerability in Samsung Open Source rlottie allows Overflow Buffers. NVD: This issue affects .",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260719T221823Z/items/CVE-2026-15551.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Integer overflow or wraparound vulnerability in Samsung Open Source rlottie allows Overflow Buffers. NVD: This issue affects .",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15551/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15558/",
      "current_public_safe_latest": false,
      "cvss_score": 2.1,
      "cvss_severity": "LOW",
      "epss_percentile": 0.0999,
      "epss_score": 0.002,
      "first_observed_at": "2026-07-20T11:59:42.107493+00:00",
      "id": "CVE-2026-15558",
      "impact_tags": [
        "SQL injection risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-20T11:59:42.107493+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A security vulnerability has been detected in CodeAstro Simple Online Leave Management System 1.0. NVD: Affected by this issue is some unknown functionality of the file /SimpleOnlineLeave/admin/deletemp.php. NVD: Such manipulation of the argument ID leads to sql injection.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260720T120206Z/items/CVE-2026-15558.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes SQL injection risk. Possible impact: An attacker may be able to read or change database-backed application data.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A security vulnerability has been detected in CodeAstro Simple Online Leave Management System 1.0. NVD: Affected by this issue is some unknown functionality of the file /SimpleOnlineLeave/admin/deletemp.php. NVD: Such manipulation of the argument ID leads to sql injection.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15558/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15559/",
      "current_public_safe_latest": false,
      "cvss_score": 2.1,
      "cvss_severity": "LOW",
      "epss_percentile": 0.0999,
      "epss_score": 0.002,
      "first_observed_at": "2026-07-20T11:59:42.107493+00:00",
      "id": "CVE-2026-15559",
      "impact_tags": [
        "SQL injection risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-20T11:59:42.107493+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A vulnerability was detected in CodeAstro Simple Online Leave Management System 1.0. NVD: This affects an unknown part of the file /SimpleOnlineLeave/admin/accept.php of the component POST Handler. NVD: Performing a manipulation of the argument appid results in sql injection.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260720T120206Z/items/CVE-2026-15559.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes SQL injection risk. Possible impact: An attacker may be able to read or change database-backed application data.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability was detected in CodeAstro Simple Online Leave Management System 1.0. NVD: This affects an unknown part of the file /SimpleOnlineLeave/admin/accept.php of the component POST Handler. NVD: Performing a manipulation of the argument appid results in sql injection.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15559/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15583/",
      "current_public_safe_latest": false,
      "cvss_score": 8.6,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.2331,
      "epss_score": 0.00312,
      "first_observed_at": "2026-07-22T06:07:21.492959+00:00",
      "id": "CVE-2026-15583",
      "impact_tags": [
        "remote exposure relevant"
      ],
      "kev": false,
      "last_observed_at": "2026-07-22T06:07:21.492959+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A confused-deputy flaw in Grafana MCP Server allows an unauthenticated remote attacker to exfiltrate the server's environment-configured Grafana service-account token by supplying a crafted X-Grafana-URL request header. NVD: This also enables SSRF against arbitrary internal services, including cloud metadata endpoints.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260722T060931Z/items/CVE-2026-15583.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes remote exposure. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A confused-deputy flaw in Grafana MCP Server allows an unauthenticated remote attacker to exfiltrate the server's environment-configured Grafana service-account token by supplying a crafted X-Grafana-URL request header. NVD: This also enables SSRF against arbitrary internal services, including cloud metadata endpoints.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15583/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15584/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.15777,
      "epss_score": 0.00246,
      "first_observed_at": "2026-07-20T11:59:42.107493+00:00",
      "id": "CVE-2026-15584",
      "impact_tags": [
        "admin privilege risk",
        "privilege boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-20T11:59:42.107493+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A privilege escalation vulnerability was found in the incluster-checks tool for OpenShift. NVD: The tool creates privileged debug pods with host filesystem access in the shared default namespace, where any user with the standard edit role can exec into them and obtain root access on cluster nodes.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260720T120206Z/items/CVE-2026-15584.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes admin privilege risk · privilege escalation risk. Possible impact: An attacker may gain root or administrative-level privileges on affected systems.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A privilege escalation vulnerability was found in the incluster-checks tool for OpenShift. NVD: The tool creates privileged debug pods with host filesystem access in the shared default namespace, where any user with the standard edit role can exec into them and obtain root access on cluster nodes.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15584/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15596/",
      "current_public_safe_latest": false,
      "cvss_score": 2.1,
      "cvss_severity": "LOW",
      "epss_percentile": 0.27037,
      "epss_score": 0.00347,
      "first_observed_at": "2026-07-20T22:16:32.807845+00:00",
      "id": "CVE-2026-15596",
      "impact_tags": [
        "XSS risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-20T22:16:32.807845+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A vulnerability was identified in SourceCodester Class and Exam Timetabling System 1.0. NVD: The impacted element is an unknown function of the file /subject.php. NVD: Such manipulation of the argument subject leads to cross site scripting.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260720T222315Z/items/CVE-2026-15596.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes XSS risk. Possible impact: This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability was identified in SourceCodester Class and Exam Timetabling System 1.0. NVD: The impacted element is an unknown function of the file /subject.php. NVD: Such manipulation of the argument subject leads to cross site scripting.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15596/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15597/",
      "current_public_safe_latest": false,
      "cvss_score": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.25063,
      "epss_score": 0.00328,
      "first_observed_at": "2026-07-20T22:16:32.807845+00:00",
      "id": "CVE-2026-15597",
      "impact_tags": [
        "SQL injection risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-20T22:16:32.807845+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A security flaw has been discovered in SourceCodester Class and Exam Timetabling System 1.0/2.php. NVD: This affects an unknown function of the file /edit_exam2.php. NVD: Performing a manipulation of the argument ID results in sql injection.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260720T222315Z/items/CVE-2026-15597.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes SQL injection risk. Possible impact: An attacker may be able to read or change database-backed application data.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A security flaw has been discovered in SourceCodester Class and Exam Timetabling System 1.0/2.php. NVD: This affects an unknown function of the file /edit_exam2.php. NVD: Performing a manipulation of the argument ID results in sql injection.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15597/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15598/",
      "current_public_safe_latest": false,
      "cvss_score": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.23459,
      "epss_score": 0.00313,
      "first_observed_at": "2026-07-20T22:16:32.807845+00:00",
      "id": "CVE-2026-15598",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-20T22:16:32.807845+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A weakness has been identified in antv layout 2.0.0. NVD: This impacts the function setNestedValue in the library lib/util/object.js. NVD: Executing a manipulation of the argument path can lead to improperly controlled modification of object prototype attributes.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260720T222315Z/items/CVE-2026-15598.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A weakness has been identified in antv layout 2.0.0. NVD: This impacts the function setNestedValue in the library lib/util/object.js. NVD: Executing a manipulation of the argument path can lead to improperly controlled modification of object prototype attributes.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15598/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "pega / pega_platform",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-1562/",
      "current_public_safe_latest": false,
      "cvss_score": 4.6,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.07041,
      "epss_score": 0.00173,
      "first_observed_at": "2026-07-22T16:52:32.770874+00:00",
      "id": "CVE-2026-1562",
      "impact_tags": [
        "XSS risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-22T16:52:32.770874+00:00",
      "latest_item_url": null,
      "product": "pega_platform",
      "public_safe_summary": "NVD: Pega Platform versions 8.1.0 through 25.1.2 are affected by an Stored Cross-site scripting (XSS) vulnerability in a user interface component. NVD: Requires a high privileged user with a developer role.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260722T165509Z/items/CVE-2026-1562.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: pega / pega_platform",
      "source_published_impact": "Source describes XSS risk. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Pega Platform versions 8.1.0 through 25.1.2 are affected by an Stored Cross-site scripting (XSS) vulnerability in a user interface component. NVD: Requires a high privileged user with a developer role.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-1562/timeline.json",
      "vendor": "pega"
    },
    {
      "affected_label": "pega / pega_platform",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-1563/",
      "current_public_safe_latest": false,
      "cvss_score": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.07041,
      "epss_score": 0.00173,
      "first_observed_at": "2026-07-22T16:52:32.770874+00:00",
      "id": "CVE-2026-1563",
      "impact_tags": [
        "XSS risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-22T16:52:32.770874+00:00",
      "latest_item_url": null,
      "product": "pega_platform",
      "public_safe_summary": "NVD: Pega Platform versions 8.1.0 through 25.1.2 are affected by an Reflected Cross-site scripting (XSS) vulnerability in a user interface component. NVD: Requires a high privileged user with a developer role.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260722T165509Z/items/CVE-2026-1563.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: pega / pega_platform",
      "source_published_impact": "Source describes XSS risk. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Pega Platform versions 8.1.0 through 25.1.2 are affected by an Reflected Cross-site scripting (XSS) vulnerability in a user interface component. NVD: Requires a high privileged user with a developer role.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-1563/timeline.json",
      "vendor": "pega"
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15631/",
      "current_public_safe_latest": false,
      "cvss_score": 8.7,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.21962,
      "epss_score": 0.00298,
      "first_observed_at": "2026-07-25T05:58:56.044661+00:00",
      "id": "CVE-2026-15631",
      "impact_tags": [
        "path traversal review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-25T10:46:49.898242+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Impact: @fastify/http-proxy versions from 9.4.0 up to and including 11.5.0 fail to validate the resolved WebSocket destination path against the configured rewrite prefix. NVD: The WebSocket routing path in WebSocketProxy.findUpstream resolves the destination via the WHATWG URL constructor, which collapses dot segments, so a crafted upgrade request with path traversal sequences can escape the rewrite prefix and reach upstream... NVD: This is a variant of CVE-2021-21322 in a code path that never went through the HTTP fix in fastify/reply-from.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260725T104916Z/items/CVE-2026-15631.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes path traversal review. Possible impact: An attacker may be able to reach files outside the intended application path.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Impact: @fastify/http-proxy versions from 9.4.0 up to and including 11.5.0 fail to validate the resolved WebSocket destination path against the configured rewrite prefix. NVD: The WebSocket routing path in WebSocketProxy.findUpstream resolves the destination via the WHATWG URL constructor, which collapses dot segments, so a crafted upgrade request with path traversal sequences can escape the rewrite prefix and reach upstream... NVD: This is a variant of CVE-2021-21322 in a code path that never went through the HTTP fix in fastify/reply-from.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15631/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15648/",
      "current_public_safe_latest": false,
      "cvss_score": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.09302,
      "epss_score": 0.00193,
      "first_observed_at": "2026-07-31T06:26:41.124454+00:00",
      "id": "CVE-2026-15648",
      "impact_tags": [
        "XSS risk",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-31T06:26:41.124454+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Brands for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'width' Shortcode Attribute in all versions up to, and including, 3.8.8 due to insufficient input sanitization and output escaping. NVD: This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260731T063057Z/items/CVE-2026-15648.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes XSS risk · authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Brands for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'width' Shortcode Attribute in all versions up to, and including, 3.8.8 due to insufficient input sanitization and output escaping. NVD: This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15648/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15652/",
      "current_public_safe_latest": false,
      "cvss_score": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.09751,
      "epss_score": 0.00197,
      "first_observed_at": "2026-07-22T22:28:24.662524+00:00",
      "id": "CVE-2026-15652",
      "impact_tags": [
        "XSS risk",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-22T22:28:24.662524+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Easy Accordion – AI-Powered FAQ & Accordion Blocks, Product FAQ plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'align' Block Attribute in all versions up to, and including, 3.1.6 due to insufficient input sanitization and output... NVD: This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260722T223443Z/items/CVE-2026-15652.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes XSS risk · authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Easy Accordion – AI-Powered FAQ & Accordion Blocks, Product FAQ plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'align' Block Attribute in all versions up to, and including, 3.1.6 due to insufficient input sanitization and output... NVD: This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15652/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15653/",
      "current_public_safe_latest": false,
      "cvss_score": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.09305,
      "epss_score": 0.00193,
      "first_observed_at": "2026-07-31T06:26:41.124454+00:00",
      "id": "CVE-2026-15653",
      "impact_tags": [
        "XSS risk",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-31T06:26:41.124454+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Visualizer – Tables & Charts Manager with Built-in AI Generator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'backend-title' parameter in all versions up to, and including, 4.0.5 due to insufficient input sanitization and... NVD: This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260731T063057Z/items/CVE-2026-15653.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes XSS risk · authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Visualizer – Tables & Charts Manager with Built-in AI Generator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'backend-title' parameter in all versions up to, and including, 4.0.5 due to insufficient input sanitization and... NVD: This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15653/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15665/",
      "current_public_safe_latest": false,
      "cvss_score": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.09828,
      "epss_score": 0.00198,
      "first_observed_at": "2026-07-31T06:26:41.124454+00:00",
      "id": "CVE-2026-15665",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-31T06:26:41.124454+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Fluent Support – Helpdesk & Customer Support Ticket System plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'redirect-to' Shortcode Attribute in all versions up to, and including, 2.3.0 due to insufficient input sanitization and... NVD: This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260731T063057Z/items/CVE-2026-15665.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Fluent Support – Helpdesk & Customer Support Ticket System plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'redirect-to' Shortcode Attribute in all versions up to, and including, 2.3.0 due to insufficient input sanitization and... NVD: This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15665/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15669/",
      "current_public_safe_latest": false,
      "cvss_score": 1.9,
      "cvss_severity": "LOW",
      "epss_percentile": 0.45871,
      "epss_score": 0.00622,
      "first_observed_at": "2026-07-21T06:08:28.817138+00:00",
      "id": "CVE-2026-15669",
      "impact_tags": [
        "command injection risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-21T06:08:28.817138+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A vulnerability was found in louisho5 picobot up to 0.2.0. NVD: This issue affects the function ExecTool.Execute of the file internal/agent/tools/exec.go of the component exec Tool. NVD: The manipulation results in os command injection.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260721T061518Z/items/CVE-2026-15669.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes command injection risk. Possible impact: An attacker may be able to run unintended system commands through the affected component.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability was found in louisho5 picobot up to 0.2.0. NVD: This issue affects the function ExecTool.Execute of the file internal/agent/tools/exec.go of the component exec Tool. NVD: The manipulation results in os command injection.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15669/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15672/",
      "current_public_safe_latest": false,
      "cvss_score": 2.1,
      "cvss_severity": "LOW",
      "epss_percentile": 0.10084,
      "epss_score": 0.002,
      "first_observed_at": "2026-07-21T06:08:28.817138+00:00",
      "id": "CVE-2026-15672",
      "impact_tags": [
        "SQL injection risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-21T06:08:28.817138+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A vulnerability was determined in itsourcecode Electronic Judging System 1.0. NVD: Impacted is an unknown function of the file /intrams/admin/add_judges.php. NVD: This manipulation of the argument fname causes sql injection.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260721T061518Z/items/CVE-2026-15672.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes SQL injection risk. Possible impact: An attacker may be able to read or change database-backed application data.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability was determined in itsourcecode Electronic Judging System 1.0. NVD: Impacted is an unknown function of the file /intrams/admin/add_judges.php. NVD: This manipulation of the argument fname causes sql injection.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15672/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15675/",
      "current_public_safe_latest": false,
      "cvss_score": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.17918,
      "epss_score": 0.00263,
      "first_observed_at": "2026-07-21T06:08:28.817138+00:00",
      "id": "CVE-2026-15675",
      "impact_tags": [
        "SQL injection risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-21T06:08:28.817138+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A vulnerability was identified in code-projects Online Job Portal 1.0. NVD: The affected element is an unknown function of the file /Admin/EditUser.php. NVD: Such manipulation of the argument UserId leads to sql injection.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260721T061518Z/items/CVE-2026-15675.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes SQL injection risk. Possible impact: An attacker may be able to read or change database-backed application data.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability was identified in code-projects Online Job Portal 1.0. NVD: The affected element is an unknown function of the file /Admin/EditUser.php. NVD: Such manipulation of the argument UserId leads to sql injection.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15675/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15676/",
      "current_public_safe_latest": false,
      "cvss_score": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.17914,
      "epss_score": 0.00263,
      "first_observed_at": "2026-07-21T06:08:28.817138+00:00",
      "id": "CVE-2026-15676",
      "impact_tags": [
        "SQL injection risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-21T06:08:28.817138+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A security flaw has been discovered in code-projects Online Job Portal up to 1.0. NVD: The impacted element is an unknown function of the file /Admin/DeleteUser.php. NVD: Performing a manipulation results in sql injection.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260721T061518Z/items/CVE-2026-15676.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes SQL injection risk. Possible impact: An attacker may be able to read or change database-backed application data.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A security flaw has been discovered in code-projects Online Job Portal up to 1.0. NVD: The impacted element is an unknown function of the file /Admin/DeleteUser.php. NVD: Performing a manipulation results in sql injection.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15676/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15677/",
      "current_public_safe_latest": false,
      "cvss_score": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.20868,
      "epss_score": 0.00288,
      "first_observed_at": "2026-07-21T06:08:28.817138+00:00",
      "id": "CVE-2026-15677",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-21T06:08:28.817138+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A weakness has been identified in code-projects Online Job Portal 1.0. NVD: This affects an unknown function of the file /JobSeekerInsert.php. NVD: Executing a manipulation of the argument txtFile can lead to unrestricted upload.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260721T061518Z/items/CVE-2026-15677.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A weakness has been identified in code-projects Online Job Portal 1.0. NVD: This affects an unknown function of the file /JobSeekerInsert.php. NVD: Executing a manipulation of the argument txtFile can lead to unrestricted upload.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15677/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15678/",
      "current_public_safe_latest": false,
      "cvss_score": 2.0,
      "cvss_severity": "LOW",
      "epss_percentile": 0.09883,
      "epss_score": 0.00199,
      "first_observed_at": "2026-07-21T06:08:28.817138+00:00",
      "id": "CVE-2026-15678",
      "impact_tags": [
        "XSS risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-21T06:08:28.817138+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A security vulnerability has been detected in code-projects Online Job Portal 1.0. NVD: This impacts an unknown function of the file /Admin/DetailJob.php. NVD: The manipulation leads to cross site scripting.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260721T061518Z/items/CVE-2026-15678.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes XSS risk. Possible impact: This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A security vulnerability has been detected in code-projects Online Job Portal 1.0. NVD: This impacts an unknown function of the file /Admin/DetailJob.php. NVD: The manipulation leads to cross site scripting.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15678/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15680/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.17569,
      "epss_score": 0.0026,
      "first_observed_at": "2026-07-20T22:16:32.807845+00:00",
      "id": "CVE-2026-15680",
      "impact_tags": [
        "code execution review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-20T22:16:32.807845+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Lorex 2K Indoor Wi-Fi Security Camera CDeviceOperator Format String Remote Code Execution Vulnerability. NVD: This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Lorex 2K Indoor Wi-Fi Security Cameras. NVD: Authentication is not required to exploit this vulnerability.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260720T222315Z/items/CVE-2026-15680.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes code execution review. Possible impact: An attacker may be able to run code or commands on affected systems.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Lorex 2K Indoor Wi-Fi Security Camera CDeviceOperator Format String Remote Code Execution Vulnerability. NVD: This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Lorex 2K Indoor Wi-Fi Security Cameras. NVD: Authentication is not required to exploit this vulnerability.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15680/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "anydesk / anydesk",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15681/",
      "current_public_safe_latest": false,
      "cvss_score": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.01243,
      "epss_score": 0.00104,
      "first_observed_at": "2026-07-20T22:16:32.807845+00:00",
      "id": "CVE-2026-15681",
      "impact_tags": [
        "local exposure relevant"
      ],
      "kev": false,
      "last_observed_at": "2026-07-20T22:16:32.807845+00:00",
      "latest_item_url": null,
      "product": "anydesk",
      "public_safe_summary": "NVD: AnyDesk Screen Recording Link Following Denial-of-Service Vulnerability. NVD: This vulnerability allows local attackers to create a denial-of-service condition on affected installations of AnyDesk. NVD: An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260720T222315Z/items/CVE-2026-15681.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: anydesk / anydesk; affected version context: 9.0.4",
      "source_published_impact": "Source describes local exposure. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for local exposure.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: AnyDesk Screen Recording Link Following Denial-of-Service Vulnerability. NVD: This vulnerability allows local attackers to create a denial-of-service condition on affected installations of AnyDesk. NVD: An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15681/timeline.json",
      "vendor": "anydesk"
    },
    {
      "affected_label": "anydesk / anydesk",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15682/",
      "current_public_safe_latest": false,
      "cvss_score": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.01243,
      "epss_score": 0.00104,
      "first_observed_at": "2026-07-20T22:16:32.807845+00:00",
      "id": "CVE-2026-15682",
      "impact_tags": [
        "local exposure relevant"
      ],
      "kev": false,
      "last_observed_at": "2026-07-20T22:16:32.807845+00:00",
      "latest_item_url": null,
      "product": "anydesk",
      "public_safe_summary": "NVD: AnyDesk Support Information Link Following Denial-of-Service Vulnerability. NVD: This vulnerability allows local attackers to create a denial-of-service condition on affected installations of AnyDesk. NVD: An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260720T222315Z/items/CVE-2026-15682.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: anydesk / anydesk; affected version context: 9.0.4",
      "source_published_impact": "Source describes local exposure. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for local exposure.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: AnyDesk Support Information Link Following Denial-of-Service Vulnerability. NVD: This vulnerability allows local attackers to create a denial-of-service condition on affected installations of AnyDesk. NVD: An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15682/timeline.json",
      "vendor": "anydesk"
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15683/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.00875,
      "epss_score": 0.00096,
      "first_observed_at": "2026-07-20T22:16:32.807845+00:00",
      "id": "CVE-2026-15683",
      "impact_tags": [
        "code execution review",
        "user interaction review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-20T22:16:32.807845+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Lorex 2K Indoor Wi-Fi Security Camera Device Management Server Improper Certificate Validation Vulnerability. NVD: This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Lorex 2K Indoor Wi-Fi Security Cameras. NVD: User interaction is not required to exploit this vulnerability.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260720T222315Z/items/CVE-2026-15683.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes code execution review · user interaction required. Possible impact: An attacker may be able to run code or commands on affected systems.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Lorex 2K Indoor Wi-Fi Security Camera Device Management Server Improper Certificate Validation Vulnerability. NVD: This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Lorex 2K Indoor Wi-Fi Security Cameras. NVD: User interaction is not required to exploit this vulnerability.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15683/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15684/",
      "current_public_safe_latest": false,
      "cvss_score": 7.3,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.03885,
      "epss_score": 0.00142,
      "first_observed_at": "2026-07-20T22:16:32.807845+00:00",
      "id": "CVE-2026-15684",
      "impact_tags": [
        "code execution review",
        "privilege boundary review",
        "local exposure relevant"
      ],
      "kev": false,
      "last_observed_at": "2026-07-20T22:16:32.807845+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Glarysoft Glary Utilities Link Following Local Privilege Escalation Vulnerability. NVD: This vulnerability allows local attackers to escalate privileges on affected installations of Glarysoft Glary Utilities. NVD: An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260720T222315Z/items/CVE-2026-15684.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes code execution review · privilege escalation risk · local exposure. Possible impact: A local user may be able to run code or commands on affected systems.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Glarysoft Glary Utilities Link Following Local Privilege Escalation Vulnerability. NVD: This vulnerability allows local attackers to escalate privileges on affected installations of Glarysoft Glary Utilities. NVD: An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15684/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "ollama / ollama",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15685/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.31455,
      "epss_score": 0.00391,
      "first_observed_at": "2026-07-20T22:16:32.807845+00:00",
      "id": "CVE-2026-15685",
      "impact_tags": [
        "remote exposure relevant"
      ],
      "kev": false,
      "last_observed_at": "2026-07-20T22:16:32.807845+00:00",
      "latest_item_url": null,
      "product": "ollama",
      "public_safe_summary": "NVD: Ollama downloadBlob Improper Validation of Array Index Denial-of-Service Vulnerability. NVD: This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of Ollama. NVD: Authentication is not required to exploit this vulnerability.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260720T222315Z/items/CVE-2026-15685.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: ollama / ollama; affected version context: 0.7.1",
      "source_published_impact": "Source describes remote exposure. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Ollama downloadBlob Improper Validation of Array Index Denial-of-Service Vulnerability. NVD: This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of Ollama. NVD: Authentication is not required to exploit this vulnerability.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15685/timeline.json",
      "vendor": "ollama"
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15690/",
      "current_public_safe_latest": false,
      "cvss_score": 1.3,
      "cvss_severity": "LOW",
      "epss_percentile": 0.34111,
      "epss_score": 0.00419,
      "first_observed_at": "2026-07-21T11:20:19.325173+00:00",
      "id": "CVE-2026-15690",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-21T11:20:19.325173+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A vulnerability was identified in open62541 up to 1.5.5. NVD: Affected by this issue is the function responseReadNamespacesArray of the file src/client/ua_client_connect.c of the component Shared Client Library. NVD: Such manipulation of the argument Server_NamespaceArray leads to null pointer dereference.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260721T112231Z/items/CVE-2026-15690.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability was identified in open62541 up to 1.5.5. NVD: Affected by this issue is the function responseReadNamespacesArray of the file src/client/ua_client_connect.c of the component Shared Client Library. NVD: Such manipulation of the argument Server_NamespaceArray leads to null pointer dereference.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15690/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15691/",
      "current_public_safe_latest": false,
      "cvss_score": 7.4,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.52408,
      "epss_score": 0.00796,
      "first_observed_at": "2026-07-21T11:20:19.325173+00:00",
      "id": "CVE-2026-15691",
      "impact_tags": [
        "memory safety review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-21T11:20:19.325173+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A security flaw has been discovered in Tenda BE12 Pro 16.03.66.23. NVD: This affects the function fromSafeClientFilter of the file /goform/SafeClientFilter. NVD: Performing a manipulation of the argument page results in stack-based buffer overflow.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260721T112231Z/items/CVE-2026-15691.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes memory safety review. Possible impact: The affected component has memory-safety risk that may lead to crash, privilege, or code-execution impact depending on exposure.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A security flaw has been discovered in Tenda BE12 Pro 16.03.66.23. NVD: This affects the function fromSafeClientFilter of the file /goform/SafeClientFilter. NVD: Performing a manipulation of the argument page results in stack-based buffer overflow.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15691/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15692/",
      "current_public_safe_latest": false,
      "cvss_score": 7.4,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.52407,
      "epss_score": 0.00796,
      "first_observed_at": "2026-07-21T11:20:19.325173+00:00",
      "id": "CVE-2026-15692",
      "impact_tags": [
        "memory safety review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-21T11:20:19.325173+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A weakness has been identified in Tenda BE12 Pro 16.03.66.23. NVD: This vulnerability affects the function fromSafeUrlFilter of the file /goform/SafeUrlFilter. NVD: Executing a manipulation of the argument page can lead to stack-based buffer overflow.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260721T112231Z/items/CVE-2026-15692.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes memory safety review. Possible impact: The affected component has memory-safety risk that may lead to crash, privilege, or code-execution impact depending on exposure.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A weakness has been identified in Tenda BE12 Pro 16.03.66.23. NVD: This vulnerability affects the function fromSafeUrlFilter of the file /goform/SafeUrlFilter. NVD: Executing a manipulation of the argument page can lead to stack-based buffer overflow.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15692/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15693/",
      "current_public_safe_latest": false,
      "cvss_score": 7.4,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.37531,
      "epss_score": 0.00466,
      "first_observed_at": "2026-07-21T11:20:19.325173+00:00",
      "id": "CVE-2026-15693",
      "impact_tags": [
        "memory safety review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-21T11:20:19.325173+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A security vulnerability has been detected in Tenda BE12 Pro 16.03.66.23. NVD: This issue affects the function fromSafeMacFilter of the file /goform/SafeMacFilter. NVD: The manipulation of the argument page leads to stack-based buffer overflow.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260721T112231Z/items/CVE-2026-15693.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes memory safety review. Possible impact: The affected component has memory-safety risk that may lead to crash, privilege, or code-execution impact depending on exposure.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A security vulnerability has been detected in Tenda BE12 Pro 16.03.66.23. NVD: This issue affects the function fromSafeMacFilter of the file /goform/SafeMacFilter. NVD: The manipulation of the argument page leads to stack-based buffer overflow.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15693/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15700/",
      "current_public_safe_latest": false,
      "cvss_score": 2.0,
      "cvss_severity": "LOW",
      "epss_percentile": 0.28702,
      "epss_score": 0.00363,
      "first_observed_at": "2026-07-21T16:48:32.557544+00:00",
      "id": "CVE-2026-15700",
      "impact_tags": [
        "path traversal review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-21T16:48:32.557544+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A security flaw has been discovered in DedeCMS 5.7.118. NVD: Affected by this vulnerability is the function ExtractFile of the file include/zip.class.php of the component Album Publishing Feature. NVD: The manipulation of the argument filename results in path traversal.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260721T165442Z/items/CVE-2026-15700.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes path traversal review. Possible impact: An attacker may be able to reach files outside the intended application path.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A security flaw has been discovered in DedeCMS 5.7.118. NVD: Affected by this vulnerability is the function ExtractFile of the file include/zip.class.php of the component Album Publishing Feature. NVD: The manipulation of the argument filename results in path traversal.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15700/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15701/",
      "current_public_safe_latest": false,
      "cvss_score": 8.9,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.52067,
      "epss_score": 0.00785,
      "first_observed_at": "2026-07-21T16:48:32.557544+00:00",
      "id": "CVE-2026-15701",
      "impact_tags": [
        "memory safety review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-21T16:48:32.557544+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A weakness has been identified in Totolink NR1800X 9.1.0u.6279_B20210910. NVD: Affected by this issue is the function Form_Logout of the file /formLogout.htm of the component lighttpd. NVD: This manipulation of the argument Host causes stack-based buffer overflow.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260721T165442Z/items/CVE-2026-15701.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes memory safety review. Possible impact: The affected component has memory-safety risk that may lead to crash, privilege, or code-execution impact depending on exposure.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A weakness has been identified in Totolink NR1800X 9.1.0u.6279_B20210910. NVD: Affected by this issue is the function Form_Logout of the file /formLogout.htm of the component lighttpd. NVD: This manipulation of the argument Host causes stack-based buffer overflow.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15701/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15702/",
      "current_public_safe_latest": false,
      "cvss_score": 2.1,
      "cvss_severity": "LOW",
      "epss_percentile": 0.26015,
      "epss_score": 0.00337,
      "first_observed_at": "2026-07-21T16:48:32.557544+00:00",
      "id": "CVE-2026-15702",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-21T16:48:32.557544+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A security vulnerability has been detected in tamagui up to 2.3.0. NVD: This affects the function updateConfig of the file code/core/web/src/config.ts. NVD: Such manipulation leads to improperly controlled modification of object prototype attributes.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260721T165442Z/items/CVE-2026-15702.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A security vulnerability has been detected in tamagui up to 2.3.0. NVD: This affects the function updateConfig of the file code/core/web/src/config.ts. NVD: Such manipulation leads to improperly controlled modification of object prototype attributes.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15702/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15703/",
      "current_public_safe_latest": false,
      "cvss_score": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.25067,
      "epss_score": 0.00328,
      "first_observed_at": "2026-07-21T16:48:32.557544+00:00",
      "id": "CVE-2026-15703",
      "impact_tags": [
        "SQL injection risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-21T16:48:32.557544+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A vulnerability was detected in SourceCodester Simple and Nice Shopping Cart Script 1.0. NVD: This vulnerability affects unknown code of the file /admin/userproductdeletequery.php. NVD: Performing a manipulation of the argument user_id results in sql injection.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260721T165442Z/items/CVE-2026-15703.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes SQL injection risk. Possible impact: An attacker may be able to read or change database-backed application data.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability was detected in SourceCodester Simple and Nice Shopping Cart Script 1.0. NVD: This vulnerability affects unknown code of the file /admin/userproductdeletequery.php. NVD: Performing a manipulation of the argument user_id results in sql injection.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15703/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "mozilla / firefox",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15718/",
      "current_public_safe_latest": false,
      "cvss_score": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.05224,
      "epss_score": 0.00156,
      "first_observed_at": "2026-07-21T11:20:19.325173+00:00",
      "id": "CVE-2026-15718",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-21T11:20:19.325173+00:00",
      "latest_item_url": null,
      "product": "firefox",
      "public_safe_summary": "NVD: We are aware that exploit code for this is public however we are not aware of any attacks in the wild abusing this flaw. NVD: This vulnerability was fixed in Firefox 152.0.6.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260721T112231Z/items/CVE-2026-15718.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: mozilla / firefox",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: Firefox.",
      "source_published_summary": "NVD: We are aware that exploit code for this is public however we are not aware of any attacks in the wild abusing this flaw. NVD: This vulnerability was fixed in Firefox 152.0.6.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15718/timeline.json",
      "vendor": "mozilla"
    },
    {
      "affected_label": "mozilla / firefox",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15719/",
      "current_public_safe_latest": false,
      "cvss_score": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.03214,
      "epss_score": 0.00133,
      "first_observed_at": "2026-07-21T11:20:19.325173+00:00",
      "id": "CVE-2026-15719",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-21T11:20:19.325173+00:00",
      "latest_item_url": null,
      "product": "firefox",
      "public_safe_summary": "NVD: We are aware that exploit code for this is public however we are not aware of any attacks in the wild abusing this flaw. NVD: This vulnerability was fixed in Firefox 152.0.6.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260721T112231Z/items/CVE-2026-15719.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: mozilla / firefox",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: Firefox.",
      "source_published_summary": "NVD: We are aware that exploit code for this is public however we are not aware of any attacks in the wild abusing this flaw. NVD: This vulnerability was fixed in Firefox 152.0.6.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15719/timeline.json",
      "vendor": "mozilla"
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15721/",
      "current_public_safe_latest": false,
      "cvss_score": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.13986,
      "epss_score": 0.00231,
      "first_observed_at": "2026-08-11T10:14:04.199465+00:00",
      "id": "CVE-2026-15721",
      "impact_tags": [
        "information exposure review",
        "SQL injection risk"
      ],
      "kev": false,
      "last_observed_at": "2026-08-11T10:14:04.199465+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Cleartext storage of sensitive information vulnerability in Bilin Software and Informatics Consultancy Inc. NVD: HUMANIST Digital Human Resources allows SQL Injection. NVD: This issue affects HUMANIST Digital Human Resources: from 26.0 before 26.1.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260811T102539Z/items/CVE-2026-15721.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes information exposure review · SQL injection risk. Possible impact: An attacker may be able to read or change database-backed application data.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Cleartext storage of sensitive information vulnerability in Bilin Software and Informatics Consultancy Inc. NVD: HUMANIST Digital Human Resources allows SQL Injection. NVD: This issue affects HUMANIST Digital Human Resources: from 26.0 before 26.1.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15721/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15722/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.40738,
      "epss_score": 0.0051,
      "first_observed_at": "2026-08-07T10:13:53.604723+00:00",
      "id": "CVE-2026-15722",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-07T10:13:53.604723+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A stack buffer overflow flaw was found in 389 Directory Server (389-ds-base). NVD: The get_ruvelement_from_berval() function in repl5_ruv.c copies digit characters from a network-supplied RUV berval into a fixed 16-byte stack buffer without bounds checking. NVD: A remote unauthenticated attacker can crash the LDAP server by sending a crafted StartNSDS50ReplicationRequest extended operation containing a replica ID field with more than 16 digit characters.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260807T102646Z/items/CVE-2026-15722.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A stack buffer overflow flaw was found in 389 Directory Server (389-ds-base). NVD: The get_ruvelement_from_berval() function in repl5_ruv.c copies digit characters from a network-supplied RUV berval into a fixed 16-byte stack buffer without bounds checking. NVD: A remote unauthenticated attacker can crash the LDAP server by sending a crafted StartNSDS50ReplicationRequest extended operation containing a replica ID field with more than 16 digit characters.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15722/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15724/",
      "current_public_safe_latest": false,
      "cvss_score": 8.7,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.26561,
      "epss_score": 0.0034,
      "first_observed_at": "2026-07-28T16:54:01.667207+00:00",
      "id": "CVE-2026-15724",
      "impact_tags": [
        "path traversal review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-28T16:54:01.667207+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: In Progress ShareFile Storage Zones Controller versions prior to 5.12.5 and 6.0.2, an authenticated administrative user can exploit a path traversal vulnerability to read arbitrary files from the server filesystem, write files to arbitrary directories, or...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260728T170314Z/items/CVE-2026-15724.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes path traversal review. Possible impact: An attacker may be able to reach files outside the intended application path.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: In Progress ShareFile Storage Zones Controller versions prior to 5.12.5 and 6.0.2, an authenticated administrative user can exploit a path traversal vulnerability to read arbitrary files from the server filesystem, write files to arbitrary directories, or...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15724/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15735/",
      "current_public_safe_latest": false,
      "cvss_score": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.09238,
      "epss_score": 0.00193,
      "first_observed_at": "2026-08-04T22:31:51.932237+00:00",
      "id": "CVE-2026-15735",
      "impact_tags": [
        "XSS risk",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-04T22:31:51.932237+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Contact Form to Any API plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'cf7anyapi_form_field' Post Meta in all versions up to, and including, 3.0.6 due to insufficient input sanitization and output escaping. NVD: This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260804T223546Z/items/CVE-2026-15735.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes XSS risk · authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Contact Form to Any API plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'cf7anyapi_form_field' Post Meta in all versions up to, and including, 3.0.6 due to insufficient input sanitization and output escaping. NVD: This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15735/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15750/",
      "current_public_safe_latest": false,
      "cvss_score": 2.1,
      "cvss_severity": "LOW",
      "epss_percentile": 0.13479,
      "epss_score": 0.00227,
      "first_observed_at": "2026-07-21T22:14:32.860584+00:00",
      "id": "CVE-2026-15750",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-21T22:14:32.860584+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A weakness has been identified in mastergo-design mastergo-magic-mcp up to 0.2.0. NVD: Impacted is the function z.string of the file src/tools/get-component-link.ts of the component mcp__getComponentLink. NVD: Executing a manipulation of the argument url can lead to server-side request forgery.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260721T221655Z/items/CVE-2026-15750.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A weakness has been identified in mastergo-design mastergo-magic-mcp up to 0.2.0. NVD: Impacted is the function z.string of the file src/tools/get-component-link.ts of the component mcp__getComponentLink. NVD: Executing a manipulation of the argument url can lead to server-side request forgery.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15750/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15755/",
      "current_public_safe_latest": false,
      "cvss_score": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.15398,
      "epss_score": 0.00241,
      "first_observed_at": "2026-07-31T06:26:41.124454+00:00",
      "id": "CVE-2026-15755",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-31T06:26:41.124454+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Open User Map – Interactive Leaflet Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Attributes in all versions up to, and including, 1.4.45 due to insufficient input sanitization and output escaping. NVD: This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260731T063057Z/items/CVE-2026-15755.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Open User Map – Interactive Leaflet Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Attributes in all versions up to, and including, 1.4.45 due to insufficient input sanitization and output escaping. NVD: This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15755/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15782/",
      "current_public_safe_latest": false,
      "cvss_score": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.08068,
      "epss_score": 0.00182,
      "first_observed_at": "2026-07-28T06:05:50.269125+00:00",
      "id": "CVE-2026-15782",
      "impact_tags": [
        "XSS risk",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-28T06:05:50.269125+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The WPForms – AI Form Builder for WordPress – Contact Forms, Payment Forms, Survey Form, Quiz & More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via OptinMonster Integration data-sitekey Attribute in Post Content in all versions up to... NVD: This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. NVD: Exploitation requires the OptinMonster plugin to be installed and configured with an active inline campaign that outputs matching #om-{id} markup on the target page, as the WPForms handler only fires when OptinMonster emits its 'om.Campaign.load' event.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260728T060840Z/items/CVE-2026-15782.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes XSS risk · authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The WPForms – AI Form Builder for WordPress – Contact Forms, Payment Forms, Survey Form, Quiz & More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via OptinMonster Integration data-sitekey Attribute in Post Content in all versions up to... NVD: This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. NVD: Exploitation requires the OptinMonster plugin to be installed and configured with an active inline campaign that outputs matching #om-{id} markup on the target page, as the WPForms handler only fires when OptinMonster emits its 'om.Campaign.load' event.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15782/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15787/",
      "current_public_safe_latest": false,
      "cvss_score": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.15402,
      "epss_score": 0.00241,
      "first_observed_at": "2026-07-29T06:10:00.110927+00:00",
      "id": "CVE-2026-15787",
      "impact_tags": [
        "XSS risk",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-29T06:10:00.110927+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Ultimate Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Navigation Menu Widget data-toggle-icon/data-close-icon Attributes in all versions up to, and including, 2.9.1 due to insufficient input sanitization and... NVD: This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. NVD: wp_kses_post, applied on save for users without unfiltered_html, does not neutralize HTML-entity-encoded payloads stored inside data-* attributes on kses-allowed elements, as the browser decodes these values client-side before jQuery .html() renders them as...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260729T062752Z/items/CVE-2026-15787.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes XSS risk · authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Ultimate Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Navigation Menu Widget data-toggle-icon/data-close-icon Attributes in all versions up to, and including, 2.9.1 due to insufficient input sanitization and... NVD: This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. NVD: wp_kses_post, applied on save for users without unfiltered_html, does not neutralize HTML-entity-encoded payloads stored inside data-* attributes on kses-allowed elements, as the browser decodes these values client-side before jQuery .html() renders them as...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15787/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15789/",
      "current_public_safe_latest": false,
      "cvss_score": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.05863,
      "epss_score": 0.00162,
      "first_observed_at": "2026-07-28T16:54:01.667207+00:00",
      "id": "CVE-2026-15789",
      "impact_tags": [
        "authentication boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-28T16:54:01.667207+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A custom client can produce such an upload request to the BuildKit daemon that files can escape from the BuildKit-controlled state directory. NVD: The client needs to have valid permissions to access the BuildKit control API to issue builds, e.g., bypass authentication, etc. OSV: Malicious client can bypass destination directory validation on local sources upload",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260728T170314Z/items/CVE-2026-15789.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes authentication boundary review. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authentication boundary review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A custom client can produce such an upload request to the BuildKit daemon that files can escape from the BuildKit-controlled state directory. NVD: The client needs to have valid permissions to access the BuildKit control API to issue builds, e.g., bypass authentication, etc. OSV: Malicious client can bypass destination directory validation on local sources upload",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15789/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15791/",
      "current_public_safe_latest": false,
      "cvss_score": 1.8,
      "cvss_severity": "LOW",
      "epss_percentile": 0.04228,
      "epss_score": 0.00145,
      "first_observed_at": "2026-07-28T16:54:01.667207+00:00",
      "id": "CVE-2026-15791",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-28T16:54:01.667207+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A crafted message in the BuildKit low-level build API can be used to remove the contents of the /tmp directory. NVD: The action that can normally be used to delete files inside the build container rootfs can escape into the real host temp directory. OSV: LLB file operation can be tricked to remove /tmp directory contents",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260728T170314Z/items/CVE-2026-15791.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A crafted message in the BuildKit low-level build API can be used to remove the contents of the /tmp directory. NVD: The action that can normally be used to delete files inside the build container rootfs can escape into the real host temp directory. OSV: LLB file operation can be tricked to remove /tmp directory contents",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15791/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15792/",
      "current_public_safe_latest": false,
      "cvss_score": 6.0,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.13436,
      "epss_score": 0.00226,
      "first_observed_at": "2026-07-28T16:54:01.667207+00:00",
      "id": "CVE-2026-15792",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-28T16:54:01.667207+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A malicious BuildKit client or frontend could craft a request that could lead to BuildKit daemon crashing with a panic. OSV: Possible panic when incorrect parameters sent from frontend OSV: A malicious BuildKit client or frontend could craft a request that could lead to BuildKit daemon crashing with a panic.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260728T170314Z/items/CVE-2026-15792.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A malicious BuildKit client or frontend could craft a request that could lead to BuildKit daemon crashing with a panic. OSV: Possible panic when incorrect parameters sent from frontend OSV: A malicious BuildKit client or frontend could craft a request that could lead to BuildKit daemon crashing with a panic.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15792/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15793/",
      "current_public_safe_latest": false,
      "cvss_score": 7.3,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.14458,
      "epss_score": 0.00234,
      "first_observed_at": "2026-07-28T16:54:01.667207+00:00",
      "id": "CVE-2026-15793",
      "impact_tags": [
        "command injection risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-28T16:54:01.667207+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: BuildKit custom frontends or clients using the raw low-level API can set git.checkoutbundle=true when checking out Git sources. NVD: If the Git source is malicious, this could lead to a crafted command invocation on the host. OSV: Git source checkout from a bundle file could lead to command injection",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260728T170314Z/items/CVE-2026-15793.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes command injection risk. Possible impact: An attacker may be able to run unintended system commands through the affected component.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: BuildKit custom frontends or clients using the raw low-level API can set git.checkoutbundle=true when checking out Git sources. NVD: If the Git source is malicious, this could lead to a crafted command invocation on the host. OSV: Git source checkout from a bundle file could lead to command injection",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15793/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15804/",
      "current_public_safe_latest": false,
      "cvss_score": 8.7,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.22273,
      "epss_score": 0.00302,
      "first_observed_at": "2026-07-22T06:07:21.492959+00:00",
      "id": "CVE-2026-15804",
      "impact_tags": [
        "SQL injection risk",
        "remote exposure relevant"
      ],
      "kev": false,
      "last_observed_at": "2026-07-22T06:07:21.492959+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The HCM developed by MetaGuru has a SQL Injection vulnerability. NVD: Authenticated remote attackers can inject SQL commands via specific parameters, thereby compromising the confidentiality, integrity, and availability of database data.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260722T060931Z/items/CVE-2026-15804.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes SQL injection risk · remote exposure. Possible impact: A remote attacker may be able to read or change database-backed application data.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The HCM developed by MetaGuru has a SQL Injection vulnerability. NVD: Authenticated remote attackers can inject SQL commands via specific parameters, thereby compromising the confidentiality, integrity, and availability of database data.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15804/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15810/",
      "current_public_safe_latest": false,
      "cvss_score": 8.7,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.18792,
      "epss_score": 0.00268,
      "first_observed_at": "2026-07-31T11:36:05.167842+00:00",
      "id": "CVE-2026-15810",
      "impact_tags": [
        "XSS risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-31T11:36:05.167842+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A Cross-Site Scripting (XSS) vulnerability in Google Cloud Looker versions prior to 25.6.103, 25.12.65, 25.18.68, 26.0.66, 26.2.47, 26.4.36, 26.6.28, and 26.8.7 on Looker-hosted and Self-hosted allows an attacker to execute arbitrary JavaScript leading to... NVD: Looker-hosted and Self-hosted were found to be vulnerable. NVD: This issue has already been mitigated for Looker-hosted instances.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260731T115001Z/items/CVE-2026-15810.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes XSS risk. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A Cross-Site Scripting (XSS) vulnerability in Google Cloud Looker versions prior to 25.6.103, 25.12.65, 25.18.68, 26.0.66, 26.2.47, 26.4.36, 26.6.28, and 26.8.7 on Looker-hosted and Self-hosted allows an attacker to execute arbitrary JavaScript leading to... NVD: Looker-hosted and Self-hosted were found to be vulnerable. NVD: This issue has already been mitigated for Looker-hosted instances.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15810/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15811/",
      "current_public_safe_latest": false,
      "cvss_score": 5.8,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.00015,
      "epss_score": 0.00062,
      "first_observed_at": "2026-07-28T06:05:50.269125+00:00",
      "id": "CVE-2026-15811",
      "impact_tags": [
        "local exposure relevant"
      ],
      "kev": false,
      "last_observed_at": "2026-07-28T06:05:50.269125+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A vulnerability was found in kronosnet's (version <=1.34) cryptographic configuration management. NVD: The framework does not correctly zero-out or wipe sensitive memory segments after executing changes to its cryptographic configuration. NVD: This omission leaves raw encryption keys resident in memory after the associated structures are freed.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260728T060840Z/items/CVE-2026-15811.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes local exposure. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for local exposure.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability was found in kronosnet's (version <=1.34) cryptographic configuration management. NVD: The framework does not correctly zero-out or wipe sensitive memory segments after executing changes to its cryptographic configuration. NVD: This omission leaves raw encryption keys resident in memory after the associated structures are freed.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15811/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15812/",
      "current_public_safe_latest": false,
      "cvss_score": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.06117,
      "epss_score": 0.00165,
      "first_observed_at": "2026-07-28T06:05:50.269125+00:00",
      "id": "CVE-2026-15812",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-28T06:05:50.269125+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A vulnerability was found in the internal Access Control List (ACL) subsystem of kronosnet (Version affected: <= 1.34). NVD: A remote, unauthenticated attacker can exploit this lack of validation by spoofing a legitimate link ID inside crafted network frames. NVD: This allows the attacker to fully bypass the ACL framework and inject arbitrary data packets into the application layer, potentially leading to data corruption or service instabilities.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260728T060840Z/items/CVE-2026-15812.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability was found in the internal Access Control List (ACL) subsystem of kronosnet (Version affected: <= 1.34). NVD: A remote, unauthenticated attacker can exploit this lack of validation by spoofing a legitimate link ID inside crafted network frames. NVD: This allows the attacker to fully bypass the ACL framework and inject arbitrary data packets into the application layer, potentially leading to data corruption or service instabilities.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15812/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15829/",
      "current_public_safe_latest": false,
      "cvss_score": 8.6,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.0731,
      "epss_score": 0.00175,
      "first_observed_at": "2026-07-28T16:54:01.667207+00:00",
      "id": "CVE-2026-15829",
      "impact_tags": [
        "SQL injection risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-28T16:54:01.667207+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A SQL injection (CWE-89) and security boundary bypass (CWE-863) vulnerability exists in the prebuilt BigQuery forecasting tool (bigquery-forecast) of googleapis/mcp-toolbox. NVD: The tool accepts client-controlled parameters (data_col, timestamp_col, and id_cols) as plain strings and interpolates them unescaped via fmt.Sprintf directly into a generated AI.FORECAST table-valued SELECT statement. NVD: While MCP Toolbox utilizes an allowedDatasets mechanism to restrict queries, this defense only validates the history_data parameter; the final assembled query is executed without re-validation.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260728T170314Z/items/CVE-2026-15829.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes SQL injection risk. Possible impact: An attacker may be able to read or change database-backed application data.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A SQL injection (CWE-89) and security boundary bypass (CWE-863) vulnerability exists in the prebuilt BigQuery forecasting tool (bigquery-forecast) of googleapis/mcp-toolbox. NVD: The tool accepts client-controlled parameters (data_col, timestamp_col, and id_cols) as plain strings and interpolates them unescaped via fmt.Sprintf directly into a generated AI.FORECAST table-valued SELECT statement. NVD: While MCP Toolbox utilizes an allowedDatasets mechanism to restrict queries, this defense only validates the history_data parameter; the final assembled query is executed without re-validation.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15829/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "google / chrome",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15899/",
      "current_public_safe_latest": false,
      "cvss_score": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.1741,
      "epss_score": 0.00258,
      "first_observed_at": "2026-07-27T22:30:18.664011+00:00",
      "id": "CVE-2026-15899",
      "impact_tags": [
        "memory safety review",
        "remote exposure relevant"
      ],
      "kev": false,
      "last_observed_at": "2026-07-27T22:30:18.664011+00:00",
      "latest_item_url": null,
      "product": "chrome",
      "public_safe_summary": "NVD: Use after free in CameraCapture in Google Chrome on Mac prior to 150.0.7871.128 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. NVD: (Chromium security severity: Critical)",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260727T223632Z/items/CVE-2026-15899.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: google / chrome; affected version context: -",
      "source_published_impact": "Source describes memory safety review · remote exposure. Possible impact: The affected component has memory-safety risk that may lead to crash, privilege, or code-execution impact depending on exposure.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Use after free in CameraCapture in Google Chrome on Mac prior to 150.0.7871.128 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. NVD: (Chromium security severity: Critical)",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15899/timeline.json",
      "vendor": "google"
    },
    {
      "affected_label": "google / chrome",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15900/",
      "current_public_safe_latest": false,
      "cvss_score": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.14749,
      "epss_score": 0.00236,
      "first_observed_at": "2026-07-27T22:30:18.664011+00:00",
      "id": "CVE-2026-15900",
      "impact_tags": [
        "memory safety review",
        "remote exposure relevant"
      ],
      "kev": false,
      "last_observed_at": "2026-07-27T22:30:18.664011+00:00",
      "latest_item_url": null,
      "product": "chrome",
      "public_safe_summary": "NVD: Use after free in GPU in Google Chrome on Android prior to 150.0.7871.128 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. NVD: (Chromium security severity: Critical)",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260727T223632Z/items/CVE-2026-15900.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: google / chrome; affected version context: -",
      "source_published_impact": "Source describes memory safety review · remote exposure. Possible impact: The affected component has memory-safety risk that may lead to crash, privilege, or code-execution impact depending on exposure.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Use after free in GPU in Google Chrome on Android prior to 150.0.7871.128 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. NVD: (Chromium security severity: Critical)",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15900/timeline.json",
      "vendor": "google"
    },
    {
      "affected_label": "google / chrome",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15901/",
      "current_public_safe_latest": false,
      "cvss_score": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.17909,
      "epss_score": 0.00263,
      "first_observed_at": "2026-07-27T22:30:18.664011+00:00",
      "id": "CVE-2026-15901",
      "impact_tags": [
        "memory safety review",
        "remote exposure relevant"
      ],
      "kev": false,
      "last_observed_at": "2026-07-27T22:30:18.664011+00:00",
      "latest_item_url": null,
      "product": "chrome",
      "public_safe_summary": "NVD: Use after free in Network in Google Chrome prior to 150.0.7871.128 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. NVD: (Chromium security severity: Critical)",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260727T223632Z/items/CVE-2026-15901.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: google / chrome",
      "source_published_impact": "Source describes memory safety review · remote exposure. Possible impact: The affected component has memory-safety risk that may lead to crash, privilege, or code-execution impact depending on exposure.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Use after free in Network in Google Chrome prior to 150.0.7871.128 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. NVD: (Chromium security severity: Critical)",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15901/timeline.json",
      "vendor": "google"
    },
    {
      "affected_label": "google / chrome",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15902/",
      "current_public_safe_latest": false,
      "cvss_score": 8.8,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.20511,
      "epss_score": 0.00283,
      "first_observed_at": "2026-07-27T22:30:18.664011+00:00",
      "id": "CVE-2026-15902",
      "impact_tags": [
        "code execution review",
        "memory safety review",
        "remote exposure relevant"
      ],
      "kev": false,
      "last_observed_at": "2026-07-27T22:30:18.664011+00:00",
      "latest_item_url": null,
      "product": "chrome",
      "public_safe_summary": "NVD: Use after free in Cast in Google Chrome prior to 150.0.7871.128 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. NVD: (Chromium security severity: High)",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260727T223632Z/items/CVE-2026-15902.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: google / chrome",
      "source_published_impact": "Source describes code execution review · memory safety review · remote exposure. Possible impact: A remote attacker may be able to run code or commands on affected systems.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Use after free in Cast in Google Chrome prior to 150.0.7871.128 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. NVD: (Chromium security severity: High)",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15902/timeline.json",
      "vendor": "google"
    },
    {
      "affected_label": "google / chrome",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15903/",
      "current_public_safe_latest": false,
      "cvss_score": 8.8,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.2375,
      "epss_score": 0.00314,
      "first_observed_at": "2026-07-27T22:30:18.664011+00:00",
      "id": "CVE-2026-15903",
      "impact_tags": [
        "code execution review",
        "remote exposure relevant"
      ],
      "kev": false,
      "last_observed_at": "2026-07-27T22:30:18.664011+00:00",
      "latest_item_url": null,
      "product": "chrome",
      "public_safe_summary": "NVD: Out of bounds read and write in V8 in Google Chrome prior to 150.0.7871.128 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. NVD: (Chromium security severity: High)",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260727T223632Z/items/CVE-2026-15903.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: google / chrome",
      "source_published_impact": "Source describes code execution review · remote exposure. Possible impact: A remote attacker may be able to run code or commands on affected systems.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Out of bounds read and write in V8 in Google Chrome prior to 150.0.7871.128 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. NVD: (Chromium security severity: High)",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15903/timeline.json",
      "vendor": "google"
    },
    {
      "affected_label": "google / chrome",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15904/",
      "current_public_safe_latest": false,
      "cvss_score": 8.8,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.14749,
      "epss_score": 0.00236,
      "first_observed_at": "2026-07-27T22:30:18.664011+00:00",
      "id": "CVE-2026-15904",
      "impact_tags": [
        "memory safety review",
        "remote exposure relevant"
      ],
      "kev": false,
      "last_observed_at": "2026-07-27T22:30:18.664011+00:00",
      "latest_item_url": null,
      "product": "chrome",
      "public_safe_summary": "NVD: Use after free in Ozone in Google Chrome on Linux prior to 150.0.7871.128 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. NVD: (Chromium security severity: High)",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260727T223632Z/items/CVE-2026-15904.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: google / chrome; affected version context: -",
      "source_published_impact": "Source describes memory safety review · remote exposure. Possible impact: The affected component has memory-safety risk that may lead to crash, privilege, or code-execution impact depending on exposure.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Use after free in Ozone in Google Chrome on Linux prior to 150.0.7871.128 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. NVD: (Chromium security severity: High)",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15904/timeline.json",
      "vendor": "google"
    },
    {
      "affected_label": "google / chrome",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15905/",
      "current_public_safe_latest": false,
      "cvss_score": 7.8,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.01438,
      "epss_score": 0.00109,
      "first_observed_at": "2026-07-27T22:30:18.664011+00:00",
      "id": "CVE-2026-15905",
      "impact_tags": [
        "memory safety review",
        "local exposure relevant"
      ],
      "kev": false,
      "last_observed_at": "2026-07-27T22:30:18.664011+00:00",
      "latest_item_url": null,
      "product": "chrome",
      "public_safe_summary": "NVD: Use after free in Aura in Google Chrome prior to 150.0.7871.128 allowed a local attacker to potentially exploit heap corruption via a malicious file. NVD: (Chromium security severity: High)",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260727T223632Z/items/CVE-2026-15905.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: google / chrome",
      "source_published_impact": "Source describes memory safety review · local exposure. Possible impact: The affected component has memory-safety risk that may lead to crash, privilege, or code-execution impact depending on exposure.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Use after free in Aura in Google Chrome prior to 150.0.7871.128 allowed a local attacker to potentially exploit heap corruption via a malicious file. NVD: (Chromium security severity: High)",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15905/timeline.json",
      "vendor": "google"
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15907/",
      "current_public_safe_latest": false,
      "cvss_score": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.16953,
      "epss_score": 0.00254,
      "first_observed_at": "2026-07-22T22:28:24.662524+00:00",
      "id": "CVE-2026-15907",
      "impact_tags": [
        "SQL injection risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-22T22:28:24.662524+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A flaw has been found in H3C SecPath F1000-C8300 up to 20260522. NVD: This impacts an unknown function of the file /webui/?g=log_fw_nbc_mail_jsondata. NVD: Executing a manipulation of the argument subject can lead to sql injection.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260722T223443Z/items/CVE-2026-15907.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes SQL injection risk. Possible impact: An attacker may be able to read or change database-backed application data.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A flaw has been found in H3C SecPath F1000-C8300 up to 20260522. NVD: This impacts an unknown function of the file /webui/?g=log_fw_nbc_mail_jsondata. NVD: Executing a manipulation of the argument subject can lead to sql injection.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15907/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15909/",
      "current_public_safe_latest": false,
      "cvss_score": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.11546,
      "epss_score": 0.00211,
      "first_observed_at": "2026-07-22T22:28:24.662524+00:00",
      "id": "CVE-2026-15909",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-22T22:28:24.662524+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A vulnerability has been found in RafyMrX TOKO-ONLINE-ROTI up to ddfe1cd587be0a0b5135d8b6e85cce2ec3aece99. NVD: Affected is an unknown function of the file proses/add.php. NVD: The manipulation of the argument kd_cs leads to authorization bypass.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260722T223443Z/items/CVE-2026-15909.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability has been found in RafyMrX TOKO-ONLINE-ROTI up to ddfe1cd587be0a0b5135d8b6e85cce2ec3aece99. NVD: Affected is an unknown function of the file proses/add.php. NVD: The manipulation of the argument kd_cs leads to authorization bypass.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15909/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15918/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.31699,
      "epss_score": 0.00388,
      "first_observed_at": "2026-08-12T05:08:50.991993+00:00",
      "id": "CVE-2026-15918",
      "impact_tags": [
        "information exposure review",
        "SQL injection risk"
      ],
      "kev": false,
      "last_observed_at": "2026-08-12T05:08:50.991993+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: VikAppointments Service Booking Calendar wordpress plugin is vulnerable to unauthenticated SQL injection due to one of the parameters that controls how the public reviews list is sorted is taken from the incoming request and used to build a database query... NVD: Because this value is placed directly into the query, an attacker who is not logged in can inject arbitrary SQL through a normal booking page and read data from the site's database — including sensitive information such as WordPress user credentials. NVD: No authentication or special privileges are required",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260812T051428Z/items/CVE-2026-15918.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes information exposure review · SQL injection risk. Possible impact: An attacker may be able to read or change database-backed application data.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: VikAppointments Service Booking Calendar wordpress plugin is vulnerable to unauthenticated SQL injection due to one of the parameters that controls how the public reviews list is sorted is taken from the incoming request and used to build a database query... NVD: Because this value is placed directly into the query, an attacker who is not logged in can inject arbitrary SQL through a normal booking page and read data from the site's database — including sensitive information such as WordPress user credentials. NVD: No authentication or special privileges are required",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15918/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15925/",
      "current_public_safe_latest": false,
      "cvss_score": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.0747,
      "epss_score": 0.00177,
      "first_observed_at": "2026-07-23T06:13:21.015514+00:00",
      "id": "CVE-2026-15925",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-23T06:13:21.015514+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Improper TLS hostname verification in Snowflake Connector for Python versions prior to 4.7.1 and 3.18.1 may have allowed a network-positioned attacker to bypass certificate hostname validation on HTTPS connections made by the connector. NVD: An attacker with on-path network access could exploit this by intercepting or redirecting network traffic and presenting a certificate signed by any trusted CA for any domain, causing the connector to accept connections without validating that the certificate... NVD: Successful exploitation requires an on-path traffic interception capability (e.g.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260723T061547Z/items/CVE-2026-15925.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Improper TLS hostname verification in Snowflake Connector for Python versions prior to 4.7.1 and 3.18.1 may have allowed a network-positioned attacker to bypass certificate hostname validation on HTTPS connections made by the connector. NVD: An attacker with on-path network access could exploit this by intercepting or redirecting network traffic and presenting a certificate signed by any trusted CA for any domain, causing the connector to accept connections without validating that the certificate... NVD: Successful exploitation requires an on-path traffic interception capability (e.g.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15925/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15927/",
      "current_public_safe_latest": false,
      "cvss_score": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.14032,
      "epss_score": 0.00231,
      "first_observed_at": "2026-07-28T06:05:50.269125+00:00",
      "id": "CVE-2026-15927",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-28T06:05:50.269125+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A flaw was found in Red Hat Quay's repository-level mirror configuration feature. NVD: The POST and PUT handlers in endpoints/api/mirror.py accept an external_reference parameter without SSRF validation, unlike the organization-level mirror handlers which apply validate_external_registry_url(). NVD: A repository administrator can supply a crafted hostname that causes the Quay mirror worker to make requests via Skopeo to internal network services, cloud metadata endpoints, or other resources not intended to be reachable from the Quay application.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260728T060840Z/items/CVE-2026-15927.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A flaw was found in Red Hat Quay's repository-level mirror configuration feature. NVD: The POST and PUT handlers in endpoints/api/mirror.py accept an external_reference parameter without SSRF validation, unlike the organization-level mirror handlers which apply validate_external_registry_url(). NVD: A repository administrator can supply a crafted hostname that causes the Quay mirror worker to make requests via Skopeo to internal network services, cloud metadata endpoints, or other resources not intended to be reachable from the Quay application.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15927/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15928/",
      "current_public_safe_latest": false,
      "cvss_score": 8.2,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.188,
      "epss_score": 0.00268,
      "first_observed_at": "2026-08-01T16:16:22.294010+00:00",
      "id": "CVE-2026-15928",
      "impact_tags": [
        "XSS risk"
      ],
      "kev": false,
      "last_observed_at": "2026-08-02T22:13:42.582353+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: XMLRPC-C Library versions 1.07 through 1.67.01 are vulnerable to a reflected cross-site scripting (XSS) vulnerability in the error page component.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260802T221659Z/items/CVE-2026-15928.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 6,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes XSS risk. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: XMLRPC-C Library versions 1.07 through 1.67.01 are vulnerable to a reflected cross-site scripting (XSS) vulnerability in the error page component.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15928/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15930/",
      "current_public_safe_latest": false,
      "cvss_score": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.14113,
      "epss_score": 0.00233,
      "first_observed_at": "2026-08-10T04:58:31.923491+00:00",
      "id": "CVE-2026-15930",
      "impact_tags": [
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-10T04:58:31.923491+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Simple Membership WordPress plugin before 4.7.8 does not verify whether user creation failed during registration before using the returned value as a user ID to update an account, allowing unauthenticated attackers to overwrite the primary administrator's...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260810T050414Z/items/CVE-2026-15930.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes remote exposure · authenticated boundary. Possible impact: This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Simple Membership WordPress plugin before 4.7.8 does not verify whether user creation failed during registration before using the returned value as a user ID to update an account, allowing unauthenticated attackers to overwrite the primary administrator's...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15930/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15931/",
      "current_public_safe_latest": false,
      "cvss_score": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.05833,
      "epss_score": 0.00162,
      "first_observed_at": "2026-08-10T04:58:31.923491+00:00",
      "id": "CVE-2026-15931",
      "impact_tags": [
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-10T04:58:31.923491+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Simple Membership WordPress plugin before 4.7.8 does not sanitise a subscriber name value received from an unauthenticated payment approval request, nor escape it when displaying it in the administration dashboard, allowing unauthenticated attackers to...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260810T050414Z/items/CVE-2026-15931.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes remote exposure · authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Simple Membership WordPress plugin before 4.7.8 does not sanitise a subscriber name value received from an unauthenticated payment approval request, nor escape it when displaying it in the administration dashboard, allowing unauthenticated attackers to...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15931/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15939/",
      "current_public_safe_latest": false,
      "cvss_score": 2.7,
      "cvss_severity": "LOW",
      "epss_percentile": 0.07584,
      "epss_score": 0.00179,
      "first_observed_at": "2026-08-09T04:40:09.231782+00:00",
      "id": "CVE-2026-15939",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-09T04:40:09.231782+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Simple Restrict WordPress plugin before 1.2.9 does not enforce its content-restriction permission check on the REST API the way it does on the front end, relying there on a generic capability check instead of the Simple Restrict WordPress plugin before...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260809T044412Z/items/CVE-2026-15939.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Simple Restrict WordPress plugin before 1.2.9 does not enforce its content-restriction permission check on the REST API the way it does on the front end, relying there on a generic capability check instead of the Simple Restrict WordPress plugin before...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15939/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15941/",
      "current_public_safe_latest": false,
      "cvss_score": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.16307,
      "epss_score": 0.00249,
      "first_observed_at": "2026-08-12T05:08:50.991993+00:00",
      "id": "CVE-2026-15941",
      "impact_tags": [
        "SQL injection risk"
      ],
      "kev": false,
      "last_observed_at": "2026-08-12T05:08:50.991993+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The plugin provides an Admin Search page that allows users with the edit_posts capability to run Relevanssi searches from the WordPress dashboard. NVD: The AJAX handler accepts a URL-encoded args parameter, parses it into a WP_Query, and then passes user-controlled taxonomy query data into Relevanssi's taxonomy restriction builder. NVD: The taxonomy value is sanitized as text but is not parameterized for SQL before being interpolated into a term taxonomy lookup query.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260812T051428Z/items/CVE-2026-15941.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes SQL injection risk. Possible impact: An attacker may be able to read or change database-backed application data.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The plugin provides an Admin Search page that allows users with the edit_posts capability to run Relevanssi searches from the WordPress dashboard. NVD: The AJAX handler accepts a URL-encoded args parameter, parses it into a WP_Query, and then passes user-controlled taxonomy query data into Relevanssi's taxonomy restriction builder. NVD: The taxonomy value is sanitized as text but is not parameterized for SQL before being interpolated into a term taxonomy lookup query.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15941/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15943/",
      "current_public_safe_latest": false,
      "cvss_score": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.10967,
      "epss_score": 0.00207,
      "first_observed_at": "2026-07-24T11:14:35.780564+00:00",
      "id": "CVE-2026-15943",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-24T11:14:35.780564+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A flaw was found in the Keycloak keycloak-services component, which handles the management of identity providers. NVD: The issue occurs when a delegated administrator updates an OIDC identity provider using a masked client secret sentinel value. NVD: Due to improper validation, Keycloak reuses the existing real secret even if security-sensitive fields like the token URL have been changed, allowing an attacker to redirect and capture the secret.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260724T111724Z/items/CVE-2026-15943.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A flaw was found in the Keycloak keycloak-services component, which handles the management of identity providers. NVD: The issue occurs when a delegated administrator updates an OIDC identity provider using a masked client secret sentinel value. NVD: Due to improper validation, Keycloak reuses the existing real secret even if security-sensitive fields like the token URL have been changed, allowing an attacker to redirect and capture the secret.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15943/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15958/",
      "current_public_safe_latest": false,
      "cvss_score": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.10529,
      "epss_score": 0.00204,
      "first_observed_at": "2026-08-11T04:43:10.985977+00:00",
      "id": "CVE-2026-15958",
      "impact_tags": [
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-11T04:43:10.985977+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Easy Integration for Dropbox WordPress plugin before 2.2.0 does not perform authorization checks on several of its file-management AJAX actions that it also registers for unauthenticated users, allowing an unauthenticated attacker to list, download and...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260811T044729Z/items/CVE-2026-15958.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes remote exposure · authenticated boundary. Possible impact: This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Easy Integration for Dropbox WordPress plugin before 2.2.0 does not perform authorization checks on several of its file-management AJAX actions that it also registers for unauthenticated users, allowing an unauthenticated attacker to list, download and...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15958/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15962/",
      "current_public_safe_latest": false,
      "cvss_score": 8.8,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.30922,
      "epss_score": 0.00382,
      "first_observed_at": "2026-08-01T10:51:40.555213+00:00",
      "id": "CVE-2026-15962",
      "impact_tags": [
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-01T22:14:19.808804+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 6.2.6 via deserialization of untrusted input. NVD: This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject a PHP Object. NVD: The additional presence of a POP chain allows attackers to change user passwords and potentially take over administrator accounts.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260801T221753Z/items/CVE-2026-15962.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 3,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes authenticated boundary. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 6.2.6 via deserialization of untrusted input. NVD: This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject a PHP Object. NVD: The additional presence of a POP chain allows attackers to change user passwords and potentially take over administrator accounts.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15962/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15982/",
      "current_public_safe_latest": false,
      "cvss_score": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.21486,
      "epss_score": 0.00294,
      "first_observed_at": "2026-07-24T06:06:41.160911+00:00",
      "id": "CVE-2026-15982",
      "impact_tags": [
        "privilege boundary review",
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-24T06:06:41.160911+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Aimogen Pro - All-in-One AI Content Writer, Editor, ChatBot & Automation Toolkit plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.8.4. NVD: This is due to due to a missing capability check on the 'aiomatic_call_google_ai_function' function. NVD: This makes it possible for unauthenticated attackers to leverage the 'aimogen_wp_god_mode' tool to clear function blacklists and execute arbitrary PHP functions, such as creating administrator accounts.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260724T061150Z/items/CVE-2026-15982.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes privilege escalation risk · remote exposure · authenticated boundary. Possible impact: A remote attacker may cross a privilege boundary and gain more access than intended.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Aimogen Pro - All-in-One AI Content Writer, Editor, ChatBot & Automation Toolkit plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.8.4. NVD: This is due to due to a missing capability check on the 'aiomatic_call_google_ai_function' function. NVD: This makes it possible for unauthenticated attackers to leverage the 'aimogen_wp_god_mode' tool to clear function blacklists and execute arbitrary PHP functions, such as creating administrator accounts.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15982/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15997/",
      "current_public_safe_latest": false,
      "cvss_score": 1.7,
      "cvss_severity": "LOW",
      "epss_percentile": 0.0101,
      "epss_score": 0.001,
      "first_observed_at": "2026-07-23T22:18:14.498937+00:00",
      "id": "CVE-2026-15997",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-23T22:18:14.498937+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Out-of-bounds write vulnerability in Legion of the Bouncy Castle Inc. NVD: BC-LTS bcprov-lts8on on ARM allows Overflow Buffers. NVD: This vulnerability is associated with program files This issue affects BC-LTS: from 2.73.0 before 2.73.12.1.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260723T222557Z/items/CVE-2026-15997.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Out-of-bounds write vulnerability in Legion of the Bouncy Castle Inc. NVD: BC-LTS bcprov-lts8on on ARM allows Overflow Buffers. NVD: This vulnerability is associated with program files This issue affects BC-LTS: from 2.73.0 before 2.73.12.1.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15997/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-16008/",
      "current_public_safe_latest": false,
      "cvss_score": 2.1,
      "cvss_severity": "LOW",
      "epss_percentile": 0.17821,
      "epss_score": 0.00262,
      "first_observed_at": "2026-07-24T06:06:41.160911+00:00",
      "id": "CVE-2026-16008",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-24T11:14:35.780564+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A security vulnerability has been detected in sagold json-schema-library 11.5.0/11.5.1. NVD: This impacts the function parsePropertyDependencies of the file src/keywords/propertyDependencies.ts. NVD: The manipulation leads to improperly controlled modification of object prototype attributes.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260724T111724Z/items/CVE-2026-16008.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A security vulnerability has been detected in sagold json-schema-library 11.5.0/11.5.1. NVD: This impacts the function parsePropertyDependencies of the file src/keywords/propertyDependencies.ts. NVD: The manipulation leads to improperly controlled modification of object prototype attributes.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-16008/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-16009/",
      "current_public_safe_latest": false,
      "cvss_score": 2.1,
      "cvss_severity": "LOW",
      "epss_percentile": 0.10084,
      "epss_score": 0.002,
      "first_observed_at": "2026-07-24T11:14:35.780564+00:00",
      "id": "CVE-2026-16009",
      "impact_tags": [
        "SQL injection risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-24T11:14:35.780564+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A vulnerability was detected in itsourcecode Hospital Management System 1.0. NVD: Affected is an unknown function of the file /prescriptionorderdetail.php. NVD: The manipulation of the argument delid results in sql injection.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260724T111724Z/items/CVE-2026-16009.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes SQL injection risk. Possible impact: An attacker may be able to read or change database-backed application data.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability was detected in itsourcecode Hospital Management System 1.0. NVD: Affected is an unknown function of the file /prescriptionorderdetail.php. NVD: The manipulation of the argument delid results in sql injection.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-16009/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-16013/",
      "current_public_safe_latest": false,
      "cvss_score": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.49701,
      "epss_score": 0.0071,
      "first_observed_at": "2026-07-24T11:14:35.780564+00:00",
      "id": "CVE-2026-16013",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-24T11:14:35.780564+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A vulnerability has been found in liftoff-sr CIPster up to 632336d414ef708a542377c1aa8d6fdb7c70a760. NVD: Affected by this issue is the function CipAppPath::deserialize_symbolic of the file source/src/cip/cipepath.cc. NVD: Such manipulation leads to out-of-bounds read.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260724T111724Z/items/CVE-2026-16013.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability has been found in liftoff-sr CIPster up to 632336d414ef708a542377c1aa8d6fdb7c70a760. NVD: Affected by this issue is the function CipAppPath::deserialize_symbolic of the file source/src/cip/cipepath.cc. NVD: Such manipulation leads to out-of-bounds read.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-16013/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-16014/",
      "current_public_safe_latest": false,
      "cvss_score": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.1798,
      "epss_score": 0.00263,
      "first_observed_at": "2026-07-24T11:14:35.780564+00:00",
      "id": "CVE-2026-16014",
      "impact_tags": [
        "SQL injection risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-24T11:14:35.780564+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A vulnerability was found in code-projects Hospital Bed Management System 1.0. NVD: This affects an unknown part of the component Login Form. NVD: Performing a manipulation of the argument Username results in sql injection.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260724T111724Z/items/CVE-2026-16014.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes SQL injection risk. Possible impact: An attacker may be able to read or change database-backed application data.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability was found in code-projects Hospital Bed Management System 1.0. NVD: This affects an unknown part of the component Login Form. NVD: Performing a manipulation of the argument Username results in sql injection.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-16014/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-16035/",
      "current_public_safe_latest": false,
      "cvss_score": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.09344,
      "epss_score": 0.00195,
      "first_observed_at": "2026-08-11T04:43:10.985977+00:00",
      "id": "CVE-2026-16035",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-11T04:43:10.985977+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The miniOrange 2FA WordPress plugin before 6.2.7 does not restrict who can trigger its second-factor configuration OTP send, nor bind the OTP recipient to the enrolling user's own address, allowing a low-privileged user to send one-time-passcode emails to...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260811T044729Z/items/CVE-2026-16035.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The miniOrange 2FA WordPress plugin before 6.2.7 does not restrict who can trigger its second-factor configuration OTP send, nor bind the OTP recipient to the enrolling user's own address, allowing a low-privileged user to send one-time-passcode emails to...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-16035/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-16042/",
      "current_public_safe_latest": false,
      "cvss_score": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.09348,
      "epss_score": 0.00195,
      "first_observed_at": "2026-08-09T04:40:09.231782+00:00",
      "id": "CVE-2026-16042",
      "impact_tags": [
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-09T04:40:09.231782+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The LWS Optimize WordPress plugin before 3.4 does not perform a capability check on its cache-clearing actions, allowing any authenticated user, including Subscribers, to flush the site's caches and force repeated cache rebuilds.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260809T044412Z/items/CVE-2026-16042.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The LWS Optimize WordPress plugin before 3.4 does not perform a capability check on its cache-clearing actions, allowing any authenticated user, including Subscribers, to flush the site's caches and force repeated cache rebuilds.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-16042/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-16056/",
      "current_public_safe_latest": false,
      "cvss_score": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.05802,
      "epss_score": 0.00162,
      "first_observed_at": "2026-08-11T04:43:10.985977+00:00",
      "id": "CVE-2026-16056",
      "impact_tags": [
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-11T04:43:10.985977+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Contest Gallery WordPress plugin before 30.0.7 does not perform any capability or nonce check in one of its handlers, allowing any authenticated user down to Subscriber to read the site's entire stored OpenAI prompt history.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260811T044729Z/items/CVE-2026-16056.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Contest Gallery WordPress plugin before 30.0.7 does not perform any capability or nonce check in one of its handlers, allowing any authenticated user down to Subscriber to read the site's entire stored OpenAI prompt history.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-16056/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-16057/",
      "current_public_safe_latest": false,
      "cvss_score": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.14109,
      "epss_score": 0.00232,
      "first_observed_at": "2026-08-10T04:58:31.923491+00:00",
      "id": "CVE-2026-16057",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-10T04:58:31.923491+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Contest Gallery WordPress plugin before 30.0.7 does not perform per-object capability or nonce checks in one of its post-deletion handlers, gating it only by a coarse role-membership test, which allows any Author-level or higher user to permanently delete...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260810T050414Z/items/CVE-2026-16057.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Contest Gallery WordPress plugin before 30.0.7 does not perform per-object capability or nonce checks in one of its post-deletion handlers, gating it only by a coarse role-membership test, which allows any Author-level or higher user to permanently delete...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-16057/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-16060/",
      "current_public_safe_latest": false,
      "cvss_score": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.38192,
      "epss_score": 0.00469,
      "first_observed_at": "2026-08-10T04:58:31.923491+00:00",
      "id": "CVE-2026-16060",
      "impact_tags": [
        "code execution review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-10T04:58:31.923491+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Insert or Embed Articulate Content into WordPress plugin through 4.3000000027 does not correctly validate the contents of an uploaded archive, relying on a bypassable check that lets an Editor-level user upload a server-executable file into a public...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260810T050414Z/items/CVE-2026-16060.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes code execution review. Possible impact: An attacker may be able to run code or commands on affected systems.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Insert or Embed Articulate Content into WordPress plugin through 4.3000000027 does not correctly validate the contents of an uploaded archive, relying on a bypassable check that lets an Editor-level user upload a server-executable file into a public...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-16060/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-16062/",
      "current_public_safe_latest": false,
      "cvss_score": 6.6,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.27769,
      "epss_score": 0.00351,
      "first_observed_at": "2026-08-09T04:40:09.231782+00:00",
      "id": "CVE-2026-16062",
      "impact_tags": [
        "code execution review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-09T04:40:09.231782+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Event Booking Manager for WooCommerce WordPress plugin before 5.3.7 does not prevent the deserialization of user-controlled input in some of its event content fields, allowing users with Contributor-level access and above to inject PHP objects. NVD: No POP chain is present in the Event Booking Manager for WooCommerce WordPress plugin before 5.3.7 itself, but if one is present via another installed Event Booking Manager for WooCommerce WordPress plugin before 5.3.7 or , this could lead to actions such as... NVD: This is an incomplete fix of the Event Booking Manager for WooCommerce WordPress plugin before 5.3.7's earlier object-injection advisories.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260809T044412Z/items/CVE-2026-16062.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes code execution review. Possible impact: An attacker may be able to run code or commands on affected systems.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Event Booking Manager for WooCommerce WordPress plugin before 5.3.7 does not prevent the deserialization of user-controlled input in some of its event content fields, allowing users with Contributor-level access and above to inject PHP objects. NVD: No POP chain is present in the Event Booking Manager for WooCommerce WordPress plugin before 5.3.7 itself, but if one is present via another installed Event Booking Manager for WooCommerce WordPress plugin before 5.3.7 or , this could lead to actions such as... NVD: This is an incomplete fix of the Event Booking Manager for WooCommerce WordPress plugin before 5.3.7's earlier object-injection advisories.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-16062/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-16063/",
      "current_public_safe_latest": false,
      "cvss_score": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.0321,
      "epss_score": 0.00133,
      "first_observed_at": "2026-08-09T04:40:09.231782+00:00",
      "id": "CVE-2026-16063",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-09T04:40:09.231782+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Event Booking Manager for WooCommerce WordPress plugin before 5.3.7 does not sanitise or escape event timeline content submitted by users with post-editing access before storing it and rendering it on the public event page, allowing users with the Author...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260809T044412Z/items/CVE-2026-16063.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Event Booking Manager for WooCommerce WordPress plugin before 5.3.7 does not sanitise or escape event timeline content submitted by users with post-editing access before storing it and rendering it on the public event page, allowing users with the Author...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-16063/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-16068/",
      "current_public_safe_latest": false,
      "cvss_score": 3.5,
      "cvss_severity": "LOW",
      "epss_percentile": 0.03996,
      "epss_score": 0.00142,
      "first_observed_at": "2026-08-11T04:43:10.985977+00:00",
      "id": "CVE-2026-16068",
      "impact_tags": [
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-11T04:43:10.985977+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Brizy WordPress plugin before 2.8.19 does not properly restrict who can modify its site-global design data and does not sanitise part of that data before outputting it, allowing authenticated users with Author-level access and above to store arbitrary...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260811T044729Z/items/CVE-2026-16068.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes authenticated boundary. Possible impact: This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Brizy WordPress plugin before 2.8.19 does not properly restrict who can modify its site-global design data and does not sanitise part of that data before outputting it, allowing authenticated users with Author-level access and above to store arbitrary...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-16068/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-16069/",
      "current_public_safe_latest": false,
      "cvss_score": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.14522,
      "epss_score": 0.00235,
      "first_observed_at": "2026-08-11T04:43:10.985977+00:00",
      "id": "CVE-2026-16069",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-11T04:43:10.985977+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Brizy WordPress plugin before 2.8.19 does not sanitize or escape featured-image focal-point coordinates submitted through one of its AJAX actions before storing them and later echoing them into HTML attributes in the post editor's Featured Image meta box...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260811T044729Z/items/CVE-2026-16069.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Brizy WordPress plugin before 2.8.19 does not sanitize or escape featured-image focal-point coordinates submitted through one of its AJAX actions before storing them and later echoing them into HTML attributes in the post editor's Featured Image meta box...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-16069/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-16070/",
      "current_public_safe_latest": false,
      "cvss_score": 2.7,
      "cvss_severity": "LOW",
      "epss_percentile": 0.06458,
      "epss_score": 0.00168,
      "first_observed_at": "2026-08-11T04:43:10.985977+00:00",
      "id": "CVE-2026-16070",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-11T04:43:10.985977+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Brizy WordPress plugin before 2.8.19 does not properly verify authorization on the object being modified before updating a template's type meta, validating a request parameter that is different from the one used in the write operation, allowing users with...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260811T044729Z/items/CVE-2026-16070.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Brizy WordPress plugin before 2.8.19 does not properly verify authorization on the object being modified before updating a template's type meta, validating a request parameter that is different from the one used in the write operation, allowing users with...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-16070/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-16075/",
      "current_public_safe_latest": false,
      "cvss_score": 2.1,
      "cvss_severity": "LOW",
      "epss_percentile": 0.12347,
      "epss_score": 0.00218,
      "first_observed_at": "2026-07-24T22:30:22.773708+00:00",
      "id": "CVE-2026-16075",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-24T22:30:22.773708+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A flaw has been found in AstrBotDevs AstrBot up to 4.25.5. NVD: This vulnerability affects the function OpenApiRoute.get_chat_sessions of the file astrbot/dashboard/routes/open_api.py of the component session-listing Endpoint. NVD: This manipulation of the argument Username causes authorization bypass.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260724T223254Z/items/CVE-2026-16075.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A flaw has been found in AstrBotDevs AstrBot up to 4.25.5. NVD: This vulnerability affects the function OpenApiRoute.get_chat_sessions of the file astrbot/dashboard/routes/open_api.py of the component session-listing Endpoint. NVD: This manipulation of the argument Username causes authorization bypass.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-16075/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-16076/",
      "current_public_safe_latest": false,
      "cvss_score": 2.1,
      "cvss_severity": "LOW",
      "epss_percentile": 0.21263,
      "epss_score": 0.00291,
      "first_observed_at": "2026-07-24T22:30:22.773708+00:00",
      "id": "CVE-2026-16076",
      "impact_tags": [
        "authentication boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-25T05:58:56.044661+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A vulnerability has been found in AstrBotDevs AstrBot up to 4.25.5. NVD: This issue affects the function OpenApiRoute.chat_send of the file astrbot/dashboard/routes/open_api.py of the component API. NVD: Such manipulation of the argument Username leads to authentication bypass by spoofing.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260725T060125Z/items/CVE-2026-16076.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes authentication boundary review. Possible impact: This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authentication boundary review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability has been found in AstrBotDevs AstrBot up to 4.25.5. NVD: This issue affects the function OpenApiRoute.chat_send of the file astrbot/dashboard/routes/open_api.py of the component API. NVD: Such manipulation of the argument Username leads to authentication bypass by spoofing.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-16076/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-16077/",
      "current_public_safe_latest": false,
      "cvss_score": 1.9,
      "cvss_severity": "LOW",
      "epss_percentile": 0.06384,
      "epss_score": 0.00168,
      "first_observed_at": "2026-07-24T22:30:22.773708+00:00",
      "id": "CVE-2026-16077",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-25T05:58:56.044661+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A vulnerability was found in AstrBotDevs AstrBot up to 4.25.5. NVD: Impacted is the function _normalize_rw_path of the file astrbot/core/tools/computer_tools/fs.py of the component Filesystem Computer-Use Tool. NVD: Performing a manipulation results in link following.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260725T060125Z/items/CVE-2026-16077.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability was found in AstrBotDevs AstrBot up to 4.25.5. NVD: Impacted is the function _normalize_rw_path of the file astrbot/core/tools/computer_tools/fs.py of the component Filesystem Computer-Use Tool. NVD: Performing a manipulation results in link following.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-16077/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-16081/",
      "current_public_safe_latest": false,
      "cvss_score": 2.1,
      "cvss_severity": "LOW",
      "epss_percentile": 0.062,
      "epss_score": 0.00166,
      "first_observed_at": "2026-07-24T22:30:22.773708+00:00",
      "id": "CVE-2026-16081",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-25T05:58:56.044661+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A vulnerability was determined in Sipeed PicoClaw up to 0.2.9. NVD: The affected element is an unknown function of the file web/backend/api/auth.go. NVD: Executing a manipulation can lead to cross-site request forgery.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260725T060125Z/items/CVE-2026-16081.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability was determined in Sipeed PicoClaw up to 0.2.9. NVD: The affected element is an unknown function of the file web/backend/api/auth.go. NVD: Executing a manipulation can lead to cross-site request forgery.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-16081/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-16082/",
      "current_public_safe_latest": false,
      "cvss_score": 1.9,
      "cvss_severity": "LOW",
      "epss_percentile": 0.0059,
      "epss_score": 0.00091,
      "first_observed_at": "2026-07-24T22:30:22.773708+00:00",
      "id": "CVE-2026-16082",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-25T05:58:56.044661+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A vulnerability was identified in Sipeed PicoClaw up to 0.2.9. NVD: The impacted element is the function ExecTool.executeRun of the file pkg/agent/pipeline_execute.go. NVD: The manipulation of the argument cwe leads to time-of-check time-of-use.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260725T060125Z/items/CVE-2026-16082.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability was identified in Sipeed PicoClaw up to 0.2.9. NVD: The impacted element is the function ExecTool.executeRun of the file pkg/agent/pipeline_execute.go. NVD: The manipulation of the argument cwe leads to time-of-check time-of-use.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-16082/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-16083/",
      "current_public_safe_latest": false,
      "cvss_score": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.35178,
      "epss_score": 0.0043,
      "first_observed_at": "2026-07-24T22:30:22.773708+00:00",
      "id": "CVE-2026-16083",
      "impact_tags": [
        "authentication boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-25T05:58:56.044661+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A security flaw has been discovered in Sipeed PicoClaw up to 0.2.9. NVD: This affects the function webhook.ParseRequest of the file pkg/channels/line/line.go of the component LINE Webhook. NVD: The manipulation results in authentication bypass by capture-replay.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260725T060125Z/items/CVE-2026-16083.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes authentication boundary review. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authentication boundary review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A security flaw has been discovered in Sipeed PicoClaw up to 0.2.9. NVD: This affects the function webhook.ParseRequest of the file pkg/channels/line/line.go of the component LINE Webhook. NVD: The manipulation results in authentication bypass by capture-replay.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-16083/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-16084/",
      "current_public_safe_latest": false,
      "cvss_score": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.32707,
      "epss_score": 0.00401,
      "first_observed_at": "2026-07-24T22:30:22.773708+00:00",
      "id": "CVE-2026-16084",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-25T05:58:56.044661+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A weakness has been identified in Sipeed PicoClaw up to 0.2.9. NVD: This impacts the function web_fetch of the file pkg/tools/integration/web.go. NVD: This manipulation causes server-side request forgery.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260725T060125Z/items/CVE-2026-16084.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A weakness has been identified in Sipeed PicoClaw up to 0.2.9. NVD: This impacts the function web_fetch of the file pkg/tools/integration/web.go. NVD: This manipulation causes server-side request forgery.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-16084/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-16085/",
      "current_public_safe_latest": false,
      "cvss_score": 1.9,
      "cvss_severity": "LOW",
      "epss_percentile": 0.01645,
      "epss_score": 0.00113,
      "first_observed_at": "2026-07-24T22:30:22.773708+00:00",
      "id": "CVE-2026-16085",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-25T05:58:56.044661+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A security vulnerability has been detected in Sipeed PicoClaw up to 0.2.9. NVD: Affected is the function NewContextBuilder of the file pkg/agent/context.go. NVD: Such manipulation leads to inclusion of functionality from untrusted control sphere.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260725T060125Z/items/CVE-2026-16085.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A security vulnerability has been detected in Sipeed PicoClaw up to 0.2.9. NVD: Affected is the function NewContextBuilder of the file pkg/agent/context.go. NVD: Such manipulation leads to inclusion of functionality from untrusted control sphere.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-16085/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-16088/",
      "current_public_safe_latest": false,
      "cvss_score": 2.0,
      "cvss_severity": "LOW",
      "epss_percentile": 0.25327,
      "epss_score": 0.0033,
      "first_observed_at": "2026-07-24T22:30:22.773708+00:00",
      "id": "CVE-2026-16088",
      "impact_tags": [
        "path traversal review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-25T05:58:56.044661+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A vulnerability was detected in halo-dev halo up to 2.24.2. NVD: Affected by this vulnerability is the function Download of the file MigrationEndpoint.java of the component Files Backup Endpoint. NVD: Performing a manipulation results in path traversal.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260725T060125Z/items/CVE-2026-16088.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes path traversal review. Possible impact: An attacker may be able to reach files outside the intended application path.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability was detected in halo-dev halo up to 2.24.2. NVD: Affected by this vulnerability is the function Download of the file MigrationEndpoint.java of the component Files Backup Endpoint. NVD: Performing a manipulation results in path traversal.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-16088/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-1609/",
      "current_public_safe_latest": false,
      "cvss_score": 8.1,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.40189,
      "epss_score": 0.00506,
      "first_observed_at": "2026-07-22T22:28:24.662524+00:00",
      "id": "CVE-2026-1609",
      "impact_tags": [
        "unauthorized access risk",
        "remote exposure relevant"
      ],
      "kev": false,
      "last_observed_at": "2026-07-22T22:28:24.662524+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A flaw was found in Keycloak. NVD: When the JSON Web Token (JWT) authorization grant preview feature is enabled and a user account is disabled, Keycloak fails to validate the user’s disabled status during JWT authorization grant processing. NVD: A remote attacker with low privileges can exploit this improper access control vulnerability by presenting a valid assertion token from an external identity provider to obtain a JWT for a disabled user.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260722T223443Z/items/CVE-2026-1609.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes unauthorized access risk · remote exposure. Possible impact: A remote attacker may access resources that should require stronger authorization.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A flaw was found in Keycloak. NVD: When the JSON Web Token (JWT) authorization grant preview feature is enabled and a user account is disabled, Keycloak fails to validate the user’s disabled status during JWT authorization grant processing. NVD: A remote attacker with low privileges can exploit this improper access control vulnerability by presenting a valid assertion token from an external identity provider to obtain a JWT for a disabled user.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-1609/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-16093/",
      "current_public_safe_latest": false,
      "cvss_score": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.09255,
      "epss_score": 0.00193,
      "first_observed_at": "2026-07-24T16:59:54.170943+00:00",
      "id": "CVE-2026-16093",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-24T16:59:54.170943+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Keycloak provides a mechanism called Client Policies to enforce security requirements on clients, such as requiring them to use signed JWTs for authentication. NVD: A flaw was discovered where this enforcement can be bypassed. NVD: An attacker with valid client credentials can provide a fake, unsigned assertion header that tricks the system into thinking the policy requirements have been met.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260724T170351Z/items/CVE-2026-16093.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Keycloak provides a mechanism called Client Policies to enforce security requirements on clients, such as requiring them to use signed JWTs for authentication. NVD: A flaw was discovered where this enforcement can be bypassed. NVD: An attacker with valid client credentials can provide a fake, unsigned assertion header that tricks the system into thinking the policy requirements have been met.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-16093/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-16095/",
      "current_public_safe_latest": false,
      "cvss_score": 8.7,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.34289,
      "epss_score": 0.00419,
      "first_observed_at": "2026-07-24T22:30:22.773708+00:00",
      "id": "CVE-2026-16095",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-25T10:46:49.898242+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A flaw has been found in Shibby Tomato 1.28 RT-N5x MIPSR2 Build 124. NVD: Affected by this issue is the function setup_conntrack of the file /sbin/rc. NVD: Executing a manipulation of the argument ct_tcp_timeout can lead to out-of-bounds write.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260725T104916Z/items/CVE-2026-16095.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 3,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A flaw has been found in Shibby Tomato 1.28 RT-N5x MIPSR2 Build 124. NVD: Affected by this issue is the function setup_conntrack of the file /sbin/rc. NVD: Executing a manipulation of the argument ct_tcp_timeout can lead to out-of-bounds write.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-16095/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-16096/",
      "current_public_safe_latest": false,
      "cvss_score": 8.7,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.35793,
      "epss_score": 0.00438,
      "first_observed_at": "2026-07-24T22:30:22.773708+00:00",
      "id": "CVE-2026-16096",
      "impact_tags": [
        "memory safety review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-25T10:46:49.898242+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A vulnerability has been found in Shibby Tomato 1.28 RT-N5x MIPSR2 Build 124. NVD: This affects the function sub_40BB50 of the file /proc/webmon_recent_domains. NVD: The manipulation leads to stack-based buffer overflow.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260725T104916Z/items/CVE-2026-16096.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 3,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes memory safety review. Possible impact: The affected component has memory-safety risk that may lead to crash, privilege, or code-execution impact depending on exposure.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability has been found in Shibby Tomato 1.28 RT-N5x MIPSR2 Build 124. NVD: This affects the function sub_40BB50 of the file /proc/webmon_recent_domains. NVD: The manipulation leads to stack-based buffer overflow.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-16096/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-16097/",
      "current_public_safe_latest": false,
      "cvss_score": 8.7,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.37564,
      "epss_score": 0.00463,
      "first_observed_at": "2026-07-24T22:30:22.773708+00:00",
      "id": "CVE-2026-16097",
      "impact_tags": [
        "memory safety review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-25T10:46:49.898242+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A vulnerability was found in Shibby Tomato 1.28. NVD: This vulnerability affects the function sub_42537C of the component Scheduler Name Handler. NVD: The manipulation of the argument a1 results in stack-based buffer overflow.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260725T104916Z/items/CVE-2026-16097.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 3,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes memory safety review. Possible impact: The affected component has memory-safety risk that may lead to crash, privilege, or code-execution impact depending on exposure.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability was found in Shibby Tomato 1.28. NVD: This vulnerability affects the function sub_42537C of the component Scheduler Name Handler. NVD: The manipulation of the argument a1 results in stack-based buffer overflow.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-16097/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-16103/",
      "current_public_safe_latest": false,
      "cvss_score": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.10903,
      "epss_score": 0.00207,
      "first_observed_at": "2026-07-24T16:59:54.170943+00:00",
      "id": "CVE-2026-16103",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-24T16:59:54.170943+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A flaw was found in the keycloak-services component of Keycloak. NVD: This issue is an incomplete fix for CVE-2026-9798, where brute-force protection checks were added to the Client-Initiated Backchannel Authentication (CIBA) initiation handler but were omitted from the token redemption handler. NVD: This allows an attacker with valid client credentials to obtain access and refresh tokens for a user account that has been locked due to brute-force protection, provided the authentication request was started before the lockout occurred and was approved by...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260724T170351Z/items/CVE-2026-16103.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A flaw was found in the keycloak-services component of Keycloak. NVD: This issue is an incomplete fix for CVE-2026-9798, where brute-force protection checks were added to the Client-Initiated Backchannel Authentication (CIBA) initiation handler but were omitted from the token redemption handler. NVD: This allows an attacker with valid client credentials to obtain access and refresh tokens for a user account that has been locked due to brute-force protection, provided the authentication request was started before the lockout occurred and was approved by...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-16103/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-16104/",
      "current_public_safe_latest": false,
      "cvss_score": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.10553,
      "epss_score": 0.00204,
      "first_observed_at": "2026-07-24T16:59:54.170943+00:00",
      "id": "CVE-2026-16104",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-24T16:59:54.170943+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A flaw was found in the authentication configuration endpoint of the keycloak-services component, which is the core engine for Red Hat Build of Keycloak identity and access management. NVD: The issue occurs because the system fails to mask sensitive configuration values, such as reCAPTCHA secret keys, when they are requested by administrators with view-only permissions. NVD: This can lead to the exposure of third-party service credentials to unauthorized personnel or through administrative logs.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260724T170351Z/items/CVE-2026-16104.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A flaw was found in the authentication configuration endpoint of the keycloak-services component, which is the core engine for Red Hat Build of Keycloak identity and access management. NVD: The issue occurs because the system fails to mask sensitive configuration values, such as reCAPTCHA secret keys, when they are requested by administrators with view-only permissions. NVD: This can lead to the exposure of third-party service credentials to unauthorized personnel or through administrative logs.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-16104/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-16106/",
      "current_public_safe_latest": false,
      "cvss_score": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.1014,
      "epss_score": 0.00201,
      "first_observed_at": "2026-07-24T16:59:54.170943+00:00",
      "id": "CVE-2026-16106",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-24T16:59:54.170943+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A flaw was found in the admin REST API of Keycloak, a solution for identity and access management. NVD: The issue occurs when a delegated administrator attempts to remove a child role from a composite role. NVD: Due to missing authorization checks, an attacker with limited administrative permissions can remove privileged roles they are not authorized to manage, leading to a loss of access for other users and administrators.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260724T170351Z/items/CVE-2026-16106.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A flaw was found in the admin REST API of Keycloak, a solution for identity and access management. NVD: The issue occurs when a delegated administrator attempts to remove a child role from a composite role. NVD: Due to missing authorization checks, an attacker with limited administrative permissions can remove privileged roles they are not authorized to manage, leading to a loss of access for other users and administrators.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-16106/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-16108/",
      "current_public_safe_latest": false,
      "cvss_score": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.08142,
      "epss_score": 0.00183,
      "first_observed_at": "2026-07-24T16:59:54.170943+00:00",
      "id": "CVE-2026-16108",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-24T16:59:54.170943+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A flaw was found in the default-groups REST endpoint and realm representation of Keycloak. NVD: This component is responsible for managing groups that are automatically assigned to new users within a realm. NVD: The issue allows a delegated administrator with realm-viewing permissions to see the names and identifiers of hidden default groups, even if they lack the specific permissions to view those groups.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260724T170351Z/items/CVE-2026-16108.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A flaw was found in the default-groups REST endpoint and realm representation of Keycloak. NVD: This component is responsible for managing groups that are automatically assigned to new users within a realm. NVD: The issue allows a delegated administrator with realm-viewing permissions to see the names and identifiers of hidden default groups, even if they lack the specific permissions to view those groups.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-16108/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-16143/",
      "current_public_safe_latest": false,
      "cvss_score": 7.2,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.14719,
      "epss_score": 0.00236,
      "first_observed_at": "2026-08-12T05:08:50.991993+00:00",
      "id": "CVE-2026-16143",
      "impact_tags": [
        "XSS risk",
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-12T05:08:50.991993+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The VikRentItems – Flexible Rental Management System plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the customer email field of the booking checkout form in versions up to, and including, 1.2.1. NVD: This is due to insufficient input sanitization and output escaping in the saveorder() function, which stores the raw email value via VikRequest::getString() (applying only sanitize_text_field(), which does not neutralize HTML attribute-breaking characters... NVD: This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260812T051428Z/items/CVE-2026-16143.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes XSS risk · remote exposure · authenticated boundary. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk · remote exposure · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The VikRentItems – Flexible Rental Management System plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the customer email field of the booking checkout form in versions up to, and including, 1.2.1. NVD: This is due to insufficient input sanitization and output escaping in the saveorder() function, which stores the raw email value via VikRequest::getString() (applying only sanitize_text_field(), which does not neutralize HTML attribute-breaking characters... NVD: This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-16143/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-16156/",
      "current_public_safe_latest": false,
      "cvss_score": 2.0,
      "cvss_severity": "LOW",
      "epss_percentile": 0.09889,
      "epss_score": 0.00199,
      "first_observed_at": "2026-07-25T22:13:31.040742+00:00",
      "id": "CVE-2026-16156",
      "impact_tags": [
        "XSS risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-25T22:13:31.040742+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A security flaw has been discovered in SourceCodester Class and Exam Timetabling System 1.0. NVD: This affects an unknown part of the file /forexam.php. NVD: The manipulation of the argument day results in cross site scripting.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260725T221848Z/items/CVE-2026-16156.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes XSS risk. Possible impact: This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A security flaw has been discovered in SourceCodester Class and Exam Timetabling System 1.0. NVD: This affects an unknown part of the file /forexam.php. NVD: The manipulation of the argument day results in cross site scripting.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-16156/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-16157/",
      "current_public_safe_latest": false,
      "cvss_score": 7.8,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.02035,
      "epss_score": 0.00119,
      "first_observed_at": "2026-07-29T16:40:34.107276+00:00",
      "id": "CVE-2026-16157",
      "impact_tags": [
        "local exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-29T16:40:34.107276+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Duplicati v2.3.0.1 backup software gives Authenticated Users MODIFY permissions that propagate to all subdirectories. NVD: Installing the software outside of the Program Files directory, or on a custom path, creates a LocalSystem service running from a directory that any standard local user can write to. NVD: A standard local user can overwrite any DLL in the service directory.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260729T164826Z/items/CVE-2026-16157.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes local exposure · authenticated boundary. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for local exposure · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Duplicati v2.3.0.1 backup software gives Authenticated Users MODIFY permissions that propagate to all subdirectories. NVD: Installing the software outside of the Program Files directory, or on a custom path, creates a LocalSystem service running from a directory that any standard local user can write to. NVD: A standard local user can overwrite any DLL in the service directory.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-16157/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-16158/",
      "current_public_safe_latest": false,
      "cvss_score": 8.7,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.13826,
      "epss_score": 0.00229,
      "first_observed_at": "2026-07-25T05:58:56.044661+00:00",
      "id": "CVE-2026-16158",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-25T10:46:49.898242+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Impact: @fastify/reply-from versions from 8.3.1 up to but not including 12.6.4 build the internal URL cache key by concatenating the destination and source path without a delimiter. NVD: Different destination and source pairs can therefore produce the same key while resolving to different upstream URLs. NVD: When getUpstream selects an upstream from request data, a URL cached for one upstream can be reused for a request intended for another upstream, causing cross-upstream data access and modification.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260725T104916Z/items/CVE-2026-16158.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Impact: @fastify/reply-from versions from 8.3.1 up to but not including 12.6.4 build the internal URL cache key by concatenating the destination and source path without a delimiter. NVD: Different destination and source pairs can therefore produce the same key while resolving to different upstream URLs. NVD: When getUpstream selects an upstream from request data, a URL cached for one upstream can be reused for a request intended for another upstream, causing cross-upstream data access and modification.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-16158/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-1617/",
      "current_public_safe_latest": false,
      "cvss_score": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.17644,
      "epss_score": 0.0026,
      "first_observed_at": "2026-07-28T11:30:16.925551+00:00",
      "id": "CVE-2026-1617",
      "impact_tags": [
        "SQL injection risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-28T11:30:16.925551+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Turkmesh Communication Services Inc. NVD: Turkhotspot 5651 Loglama allows SQL Injection. NVD: This issue affects Turkhotspot 5651 Loglama: from 5.1.2 before 5.1.3.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260728T113720Z/items/CVE-2026-1617.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes SQL injection risk. Possible impact: An attacker may be able to read or change database-backed application data.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Turkmesh Communication Services Inc. NVD: Turkhotspot 5651 Loglama allows SQL Injection. NVD: This issue affects Turkhotspot 5651 Loglama: from 5.1.2 before 5.1.3.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-1617/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-16194/",
      "current_public_safe_latest": false,
      "cvss_score": 2.1,
      "cvss_severity": "LOW",
      "epss_percentile": 0.2542,
      "epss_score": 0.0033,
      "first_observed_at": "2026-07-25T22:13:31.040742+00:00",
      "id": "CVE-2026-16194",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-25T22:13:31.040742+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A vulnerability was determined in zhayujie CowAgent up to 2.1.1. NVD: This affects the function WebFetch.execute of the file agent/tools/web_fetch/web_fetch.py. NVD: Executing a manipulation of the argument url can lead to server-side request forgery.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260725T221848Z/items/CVE-2026-16194.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: of.",
      "source_published_summary": "NVD: A vulnerability was determined in zhayujie CowAgent up to 2.1.1. NVD: This affects the function WebFetch.execute of the file agent/tools/web_fetch/web_fetch.py. NVD: Executing a manipulation of the argument url can lead to server-side request forgery.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-16194/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-16195/",
      "current_public_safe_latest": false,
      "cvss_score": 2.1,
      "cvss_severity": "LOW",
      "epss_percentile": 0.11265,
      "epss_score": 0.00209,
      "first_observed_at": "2026-07-25T22:13:31.040742+00:00",
      "id": "CVE-2026-16195",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-25T22:13:31.040742+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A security flaw has been discovered in Sipeed PicoClaw up to 0.2.9. NVD: This issue affects the function dispatchIncoming of the file pkg/channels/wecom/wecom.go of the component Group Message Handler. NVD: The manipulation results in incorrect authorization.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260725T221848Z/items/CVE-2026-16195.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A security flaw has been discovered in Sipeed PicoClaw up to 0.2.9. NVD: This issue affects the function dispatchIncoming of the file pkg/channels/wecom/wecom.go of the component Group Message Handler. NVD: The manipulation results in incorrect authorization.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-16195/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-16196/",
      "current_public_safe_latest": false,
      "cvss_score": 2.1,
      "cvss_severity": "LOW",
      "epss_percentile": 0.21115,
      "epss_score": 0.00289,
      "first_observed_at": "2026-07-25T22:13:31.040742+00:00",
      "id": "CVE-2026-16196",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-25T22:13:31.040742+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A weakness has been identified in Sipeed PicoClaw up to 0.2.9. NVD: Impacted is the function isPrivateOrRestrictedIP of the file pkg/tools/integration/web.go of the component web_fetch. NVD: This manipulation causes server-side request forgery.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260725T221848Z/items/CVE-2026-16196.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A weakness has been identified in Sipeed PicoClaw up to 0.2.9. NVD: Impacted is the function isPrivateOrRestrictedIP of the file pkg/tools/integration/web.go of the component web_fetch. NVD: This manipulation causes server-side request forgery.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-16196/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-16197/",
      "current_public_safe_latest": false,
      "cvss_score": 2.1,
      "cvss_severity": "LOW",
      "epss_percentile": 0.11263,
      "epss_score": 0.00209,
      "first_observed_at": "2026-07-25T22:13:31.040742+00:00",
      "id": "CVE-2026-16197",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-25T22:13:31.040742+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A security vulnerability has been detected in Sipeed PicoClaw up to 0.2.9. NVD: The affected element is the function handleMessageReceive of the file pkg/channels/feishu/feishu_64.go of the component Group Message Handler. NVD: Such manipulation leads to missing authorization.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260725T221848Z/items/CVE-2026-16197.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A security vulnerability has been detected in Sipeed PicoClaw up to 0.2.9. NVD: The affected element is the function handleMessageReceive of the file pkg/channels/feishu/feishu_64.go of the component Group Message Handler. NVD: Such manipulation leads to missing authorization.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-16197/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-16198/",
      "current_public_safe_latest": false,
      "cvss_score": 2.9,
      "cvss_severity": "LOW",
      "epss_percentile": 0.31922,
      "epss_score": 0.00393,
      "first_observed_at": "2026-07-25T22:13:31.040742+00:00",
      "id": "CVE-2026-16198",
      "impact_tags": [
        "authentication boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-25T22:13:31.040742+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A vulnerability was detected in Sipeed PicoClaw up to 0.2.9. NVD: The impacted element is an unknown function of the file web/backend/middleware/access_control.go of the component First Run Setup. NVD: Performing a manipulation of the argument allowed_cidrs results in authentication bypass using alternate channel.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260725T221848Z/items/CVE-2026-16198.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes authentication boundary review. Possible impact: This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authentication boundary review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability was detected in Sipeed PicoClaw up to 0.2.9. NVD: The impacted element is an unknown function of the file web/backend/middleware/access_control.go of the component First Run Setup. NVD: Performing a manipulation of the argument allowed_cidrs results in authentication bypass using alternate channel.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-16198/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-16199/",
      "current_public_safe_latest": false,
      "cvss_score": 2.1,
      "cvss_severity": "LOW",
      "epss_percentile": 0.11263,
      "epss_score": 0.00209,
      "first_observed_at": "2026-07-25T22:13:31.040742+00:00",
      "id": "CVE-2026-16199",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-25T22:13:31.040742+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A flaw has been found in nextlevelbuilder GoClaw up to 3.13.3-beta.3. NVD: This affects the function ExecTool.Execute of the file goclaw/internal/tools/credentialed_exec.go. NVD: Executing a manipulation can lead to improper authorization.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260725T221848Z/items/CVE-2026-16199.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A flaw has been found in nextlevelbuilder GoClaw up to 3.13.3-beta.3. NVD: This affects the function ExecTool.Execute of the file goclaw/internal/tools/credentialed_exec.go. NVD: Executing a manipulation can lead to improper authorization.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-16199/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-16200/",
      "current_public_safe_latest": false,
      "cvss_score": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.2103,
      "epss_score": 0.00288,
      "first_observed_at": "2026-07-25T22:13:31.040742+00:00",
      "id": "CVE-2026-16200",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-25T22:13:31.040742+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A vulnerability has been found in zevorn rt-claw up to 0.2.0. NVD: This impacts the function claw_tool_invoke of the file claw/services/swarm/swarm.c of the component RPC Handler. NVD: The manipulation leads to incorrect authorization.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260725T221848Z/items/CVE-2026-16200.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability has been found in zevorn rt-claw up to 0.2.0. NVD: This impacts the function claw_tool_invoke of the file claw/services/swarm/swarm.c of the component RPC Handler. NVD: The manipulation leads to incorrect authorization.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-16200/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-16201/",
      "current_public_safe_latest": false,
      "cvss_score": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.23472,
      "epss_score": 0.00311,
      "first_observed_at": "2026-07-25T22:13:31.040742+00:00",
      "id": "CVE-2026-16201",
      "impact_tags": [
        "information exposure review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-25T22:13:31.040742+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A vulnerability was found in zevorn rt-claw up to 0.2.0. NVD: Affected is the function claw_net_get/claw_net_post of the file claw/services/tools/net.c of the component http_request. NVD: The manipulation results in information disclosure.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260725T221848Z/items/CVE-2026-16201.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes information exposure review. Possible impact: An attacker may be able to access information that should not be exposed.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability was found in zevorn rt-claw up to 0.2.0. NVD: Affected is the function claw_net_get/claw_net_post of the file claw/services/tools/net.c of the component http_request. NVD: The manipulation results in information disclosure.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-16201/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-16202/",
      "current_public_safe_latest": false,
      "cvss_score": 2.0,
      "cvss_severity": "LOW",
      "epss_percentile": 0.09888,
      "epss_score": 0.00199,
      "first_observed_at": "2026-07-25T22:13:31.040742+00:00",
      "id": "CVE-2026-16202",
      "impact_tags": [
        "XSS risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-25T22:13:31.040742+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A vulnerability was determined in SourceCodester Class and Exam Timetabling System 1.0. NVD: Affected by this vulnerability is an unknown functionality of the file /CYS.php. NVD: This manipulation of the argument course causes cross site scripting.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260725T221848Z/items/CVE-2026-16202.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes XSS risk. Possible impact: This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability was determined in SourceCodester Class and Exam Timetabling System 1.0. NVD: Affected by this vulnerability is an unknown functionality of the file /CYS.php. NVD: This manipulation of the argument course causes cross site scripting.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-16202/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-16203/",
      "current_public_safe_latest": false,
      "cvss_score": 2.0,
      "cvss_severity": "LOW",
      "epss_percentile": 0.09888,
      "epss_score": 0.00199,
      "first_observed_at": "2026-07-25T22:13:31.040742+00:00",
      "id": "CVE-2026-16203",
      "impact_tags": [
        "XSS risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-25T22:13:31.040742+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A vulnerability was identified in SourceCodester Class and Exam Timetabling System 1.0. NVD: Affected by this issue is some unknown functionality of the file /forCYS.php. NVD: Such manipulation of the argument course leads to cross site scripting.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260725T221848Z/items/CVE-2026-16203.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes XSS risk. Possible impact: This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability was identified in SourceCodester Class and Exam Timetabling System 1.0. NVD: Affected by this issue is some unknown functionality of the file /forCYS.php. NVD: Such manipulation of the argument course leads to cross site scripting.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-16203/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-16204/",
      "current_public_safe_latest": false,
      "cvss_score": 2.1,
      "cvss_severity": "LOW",
      "epss_percentile": 0.23671,
      "epss_score": 0.00313,
      "first_observed_at": "2026-07-25T22:13:31.040742+00:00",
      "id": "CVE-2026-16204",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-25T22:13:31.040742+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A security flaw has been discovered in zevorn rt-claw up to 0.2.0. NVD: This affects the function tool_run_script_execute of the file claw/services/tools/script.c of the component Telegram-to-AI Tool Execution Flow. NVD: Performing a manipulation results in code injection.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260725T221848Z/items/CVE-2026-16204.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A security flaw has been discovered in zevorn rt-claw up to 0.2.0. NVD: This affects the function tool_run_script_execute of the file claw/services/tools/script.c of the component Telegram-to-AI Tool Execution Flow. NVD: Performing a manipulation results in code injection.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-16204/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-16205/",
      "current_public_safe_latest": false,
      "cvss_score": 1.9,
      "cvss_severity": "LOW",
      "epss_percentile": 0.10299,
      "epss_score": 0.00202,
      "first_observed_at": "2026-07-25T22:13:31.040742+00:00",
      "id": "CVE-2026-16205",
      "impact_tags": [
        "XSS risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-25T22:13:31.040742+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A weakness has been identified in Pluck CMS up to 4.7.21. NVD: This vulnerability affects the function htmlspecialchars_decode of the file data/modules/albums/albums.admin.php of the component Albums Module. NVD: Executing a manipulation of the argument Info can lead to cross site scripting.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260725T221848Z/items/CVE-2026-16205.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes XSS risk. Possible impact: This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A weakness has been identified in Pluck CMS up to 4.7.21. NVD: This vulnerability affects the function htmlspecialchars_decode of the file data/modules/albums/albums.admin.php of the component Albums Module. NVD: Executing a manipulation of the argument Info can lead to cross site scripting.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-16205/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-16206/",
      "current_public_safe_latest": false,
      "cvss_score": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.11262,
      "epss_score": 0.00209,
      "first_observed_at": "2026-07-25T22:13:31.040742+00:00",
      "id": "CVE-2026-16206",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-25T22:13:31.040742+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A security vulnerability has been detected in django-oauth django-oauth-toolkit 3.3.0. NVD: This issue affects the function _load_id_token of the file oauth2_provider/oauth2_validators.py. NVD: The manipulation leads to session expiration.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260725T221848Z/items/CVE-2026-16206.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A security vulnerability has been detected in django-oauth django-oauth-toolkit 3.3.0. NVD: This issue affects the function _load_id_token of the file oauth2_provider/oauth2_validators.py. NVD: The manipulation leads to session expiration.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-16206/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-16207/",
      "current_public_safe_latest": false,
      "cvss_score": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.32505,
      "epss_score": 0.00399,
      "first_observed_at": "2026-07-25T22:13:31.040742+00:00",
      "id": "CVE-2026-16207",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-25T22:13:31.040742+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A vulnerability was detected in django-tastypie up to 0.15.1. NVD: Impacted is the function ApiKeyAuthentication of the file tastypie/authentication.py. NVD: The manipulation results in use of get request method with sensitive query strings.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260725T221848Z/items/CVE-2026-16207.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability was detected in django-tastypie up to 0.15.1. NVD: Impacted is the function ApiKeyAuthentication of the file tastypie/authentication.py. NVD: The manipulation results in use of get request method with sensitive query strings.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-16207/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-16208/",
      "current_public_safe_latest": false,
      "cvss_score": 2.3,
      "cvss_severity": "LOW",
      "epss_percentile": 0.06344,
      "epss_score": 0.00167,
      "first_observed_at": "2026-07-25T22:13:31.040742+00:00",
      "id": "CVE-2026-16208",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-25T22:13:31.040742+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A flaw has been found in django-tastypie up to 0.15.1. NVD: The affected element is the function CacheThrottle/CacheDBThrottle of the file tastypie/throttle.py. NVD: This manipulation causes race condition.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260725T221848Z/items/CVE-2026-16208.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A flaw has been found in django-tastypie up to 0.15.1. NVD: The affected element is the function CacheThrottle/CacheDBThrottle of the file tastypie/throttle.py. NVD: This manipulation causes race condition.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-16208/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-16209/",
      "current_public_safe_latest": false,
      "cvss_score": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.33607,
      "epss_score": 0.0041,
      "first_observed_at": "2026-07-25T22:13:31.040742+00:00",
      "id": "CVE-2026-16209",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-25T22:13:31.040742+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A vulnerability has been found in Gerapy up to 0.9.13. NVD: The impacted element is an unknown function of the file gerapy/server/core/views.py of the component Project Upload Endpoint. NVD: Such manipulation leads to missing authentication.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260725T221848Z/items/CVE-2026-16209.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability has been found in Gerapy up to 0.9.13. NVD: The impacted element is an unknown function of the file gerapy/server/core/views.py of the component Project Upload Endpoint. NVD: Such manipulation leads to missing authentication.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-16209/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-16210/",
      "current_public_safe_latest": false,
      "cvss_score": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.32368,
      "epss_score": 0.00397,
      "first_observed_at": "2026-07-25T22:13:31.040742+00:00",
      "id": "CVE-2026-16210",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-25T22:13:31.040742+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A vulnerability was found in newpanjing simpleui 2026.01.13. NVD: This affects the function self.get_action of the file simpleui/admin.py of the component AjaxAdmin AJAX Endpoint. NVD: Performing a manipulation results in missing authentication.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260725T221848Z/items/CVE-2026-16210.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability was found in newpanjing simpleui 2026.01.13. NVD: This affects the function self.get_action of the file simpleui/admin.py of the component AjaxAdmin AJAX Endpoint. NVD: Performing a manipulation results in missing authentication.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-16210/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-16211/",
      "current_public_safe_latest": false,
      "cvss_score": 1.2,
      "cvss_severity": "LOW",
      "epss_percentile": 0.05303,
      "epss_score": 0.00157,
      "first_observed_at": "2026-07-25T22:13:31.040742+00:00",
      "id": "CVE-2026-16211",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-25T22:13:31.040742+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A vulnerability was determined in allegro up to bcf65b994ef29fb3fc2e10b660e6288723d5209e. NVD: This impacts the function AssetLastHostname.increment_hostname of the file src/ralph/assets/models/assets.py of the component Hostname Allocation Handler. NVD: Executing a manipulation of the argument counter can lead to race condition.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260725T221848Z/items/CVE-2026-16211.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability was determined in allegro up to bcf65b994ef29fb3fc2e10b660e6288723d5209e. NVD: This impacts the function AssetLastHostname.increment_hostname of the file src/ralph/assets/models/assets.py of the component Hostname Allocation Handler. NVD: Executing a manipulation of the argument counter can lead to race condition.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-16211/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-16219/",
      "current_public_safe_latest": false,
      "cvss_score": 2.1,
      "cvss_severity": "LOW",
      "epss_percentile": 0.26866,
      "epss_score": 0.00343,
      "first_observed_at": "2026-07-26T06:17:48.937613+00:00",
      "id": "CVE-2026-16219",
      "impact_tags": [
        "path traversal review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-26T06:17:48.937613+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A flaw has been found in Croogo CMS up to 4.0.7. NVD: This affects the function FileManager::isEditable of the file FileManager/src/Utility/FileManager.php of the component Admin File Manager. NVD: This manipulation causes path traversal.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260726T062024Z/items/CVE-2026-16219.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes path traversal review. Possible impact: An attacker may be able to reach files outside the intended application path.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A flaw has been found in Croogo CMS up to 4.0.7. NVD: This affects the function FileManager::isEditable of the file FileManager/src/Utility/FileManager.php of the component Admin File Manager. NVD: This manipulation causes path traversal.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-16219/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-16220/",
      "current_public_safe_latest": false,
      "cvss_score": 2.1,
      "cvss_severity": "LOW",
      "epss_percentile": 0.19447,
      "epss_score": 0.00273,
      "first_observed_at": "2026-07-26T06:17:48.937613+00:00",
      "id": "CVE-2026-16220",
      "impact_tags": [
        "XSS risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-26T06:17:48.937613+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A vulnerability has been found in code-projects Online Examination System 1.0. NVD: This vulnerability affects unknown code of the file /account.php?q=quiz. NVD: Such manipulation of the argument eid/n/t leads to cross site scripting.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260726T062024Z/items/CVE-2026-16220.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes XSS risk. Possible impact: This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability has been found in code-projects Online Examination System 1.0. NVD: This vulnerability affects unknown code of the file /account.php?q=quiz. NVD: Such manipulation of the argument eid/n/t leads to cross site scripting.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-16220/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-16222/",
      "current_public_safe_latest": false,
      "cvss_score": 2.1,
      "cvss_severity": "LOW",
      "epss_percentile": 0.11953,
      "epss_score": 0.00214,
      "first_observed_at": "2026-07-26T06:17:48.937613+00:00",
      "id": "CVE-2026-16222",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-26T06:17:48.937613+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A vulnerability was found in 1Panel-dev CordysCRM up to 1.4.1. NVD: This issue affects some unknown processing of the file backend/crm/src/main/java/cn/cordys/crm/integration/sso/service/TokenService.java of the component Third Party Endpoint. NVD: Performing a manipulation of the argument mkAddress results in server-side request forgery.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260726T062024Z/items/CVE-2026-16222.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability was found in 1Panel-dev CordysCRM up to 1.4.1. NVD: This issue affects some unknown processing of the file backend/crm/src/main/java/cn/cordys/crm/integration/sso/service/TokenService.java of the component Third Party Endpoint. NVD: Performing a manipulation of the argument mkAddress results in server-side request forgery.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-16222/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-16223/",
      "current_public_safe_latest": false,
      "cvss_score": 2.1,
      "cvss_severity": "LOW",
      "epss_percentile": 0.11953,
      "epss_score": 0.00214,
      "first_observed_at": "2026-07-26T06:17:48.937613+00:00",
      "id": "CVE-2026-16223",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-26T06:17:48.937613+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A vulnerability was determined in 1Panel-dev CordysCRM up to 1.4.1. NVD: Impacted is the function getSqlBotSrc of the file backend/crm/src/main/java/cn/cordys/crm/system/service/IntegrationConfigService.java of the component Third Party Edit Endpoint. NVD: Executing a manipulation of the argument appSecret can lead to server-side request forgery.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260726T062024Z/items/CVE-2026-16223.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability was determined in 1Panel-dev CordysCRM up to 1.4.1. NVD: Impacted is the function getSqlBotSrc of the file backend/crm/src/main/java/cn/cordys/crm/system/service/IntegrationConfigService.java of the component Third Party Edit Endpoint. NVD: Executing a manipulation of the argument appSecret can lead to server-side request forgery.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-16223/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-16224/",
      "current_public_safe_latest": false,
      "cvss_score": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.12908,
      "epss_score": 0.00222,
      "first_observed_at": "2026-07-26T06:17:48.937613+00:00",
      "id": "CVE-2026-16224",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-26T06:17:48.937613+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A vulnerability was identified in jxxghp MoviePilot up to 2.13.5. NVD: The affected element is an unknown function of the file /jxxghp/MoviePilot of the component Application API. NVD: The manipulation leads to improper authorization.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260726T062024Z/items/CVE-2026-16224.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability was identified in jxxghp MoviePilot up to 2.13.5. NVD: The affected element is an unknown function of the file /jxxghp/MoviePilot of the component Application API. NVD: The manipulation leads to improper authorization.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-16224/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-16225/",
      "current_public_safe_latest": false,
      "cvss_score": 2.1,
      "cvss_severity": "LOW",
      "epss_percentile": 0.13773,
      "epss_score": 0.00228,
      "first_observed_at": "2026-07-26T06:17:48.937613+00:00",
      "id": "CVE-2026-16225",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-26T06:17:48.937613+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A security flaw has been discovered in davenardella snap7 up to 1.4.3. NVD: The impacted element is the function TSnap7Peer::NegotiatePDULength of the file src/core/s7_peer.cpp. NVD: The manipulation of the argument PDULength results in out-of-bounds write.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260726T062024Z/items/CVE-2026-16225.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A security flaw has been discovered in davenardella snap7 up to 1.4.3. NVD: The impacted element is the function TSnap7Peer::NegotiatePDULength of the file src/core/s7_peer.cpp. NVD: The manipulation of the argument PDULength results in out-of-bounds write.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-16225/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-16226/",
      "current_public_safe_latest": false,
      "cvss_score": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.12402,
      "epss_score": 0.00218,
      "first_observed_at": "2026-07-26T06:17:48.937613+00:00",
      "id": "CVE-2026-16226",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-26T06:17:48.937613+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A weakness has been identified in SourceCodester Pizzafy Ecommerce System 1.0. NVD: This affects the function save_settings of the file /admin/admin_class_novo.php. NVD: This manipulation of the argument img causes unrestricted upload.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260726T062024Z/items/CVE-2026-16226.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A weakness has been identified in SourceCodester Pizzafy Ecommerce System 1.0. NVD: This affects the function save_settings of the file /admin/admin_class_novo.php. NVD: This manipulation of the argument img causes unrestricted upload.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-16226/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-16227/",
      "current_public_safe_latest": false,
      "cvss_score": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.1802,
      "epss_score": 0.00263,
      "first_observed_at": "2026-07-26T06:17:48.937613+00:00",
      "id": "CVE-2026-16227",
      "impact_tags": [
        "SQL injection risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-26T06:17:48.937613+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A security vulnerability has been detected in SourceCodester Class and Exam Timetabling System 1.0. NVD: This impacts an unknown function of the file /edit_subject.php. NVD: Such manipulation of the argument ID leads to sql injection.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260726T062024Z/items/CVE-2026-16227.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes SQL injection risk. Possible impact: An attacker may be able to read or change database-backed application data.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A security vulnerability has been detected in SourceCodester Class and Exam Timetabling System 1.0. NVD: This impacts an unknown function of the file /edit_subject.php. NVD: Such manipulation of the argument ID leads to sql injection.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-16227/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-16228/",
      "current_public_safe_latest": false,
      "cvss_score": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.18024,
      "epss_score": 0.00263,
      "first_observed_at": "2026-07-26T06:17:48.937613+00:00",
      "id": "CVE-2026-16228",
      "impact_tags": [
        "SQL injection risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-26T06:17:48.937613+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A vulnerability was detected in SourceCodester Class and Exam Timetabling System 1.0. NVD: Affected is an unknown function of the file /edit_schoolyr.php. NVD: Performing a manipulation of the argument ID results in sql injection.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260726T062024Z/items/CVE-2026-16228.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes SQL injection risk. Possible impact: An attacker may be able to read or change database-backed application data.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability was detected in SourceCodester Class and Exam Timetabling System 1.0. NVD: Affected is an unknown function of the file /edit_schoolyr.php. NVD: Performing a manipulation of the argument ID results in sql injection.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-16228/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-16229/",
      "current_public_safe_latest": false,
      "cvss_score": 2.1,
      "cvss_severity": "LOW",
      "epss_percentile": 0.19446,
      "epss_score": 0.00273,
      "first_observed_at": "2026-07-26T06:17:48.937613+00:00",
      "id": "CVE-2026-16229",
      "impact_tags": [
        "XSS risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-26T06:17:48.937613+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A flaw has been found in itsourcecode Courier Management System up to 1.0. NVD: Affected by this vulnerability is an unknown functionality of the file /index.php. NVD: Executing a manipulation of the argument page can lead to cross site scripting.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260726T062024Z/items/CVE-2026-16229.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes XSS risk. Possible impact: This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A flaw has been found in itsourcecode Courier Management System up to 1.0. NVD: Affected by this vulnerability is an unknown functionality of the file /index.php. NVD: Executing a manipulation of the argument page can lead to cross site scripting.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-16229/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-16235/",
      "current_public_safe_latest": false,
      "cvss_score": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.28309,
      "epss_score": 0.00357,
      "first_observed_at": "2026-07-26T22:15:56.881440+00:00",
      "id": "CVE-2026-16235",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-27T06:45:51.031460+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Crypt::Password versions through 0.28 for Perl generate insecure random values for salts. NVD: These versions use the built-in rand function, which is predictable and unsuitable for cryptography.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260727T065126Z/items/CVE-2026-16235.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Crypt::Password versions through 0.28 for Perl generate insecure random values for salts. NVD: These versions use the built-in rand function, which is predictable and unsuitable for cryptography.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-16235/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-16244/",
      "current_public_safe_latest": false,
      "cvss_score": 2.1,
      "cvss_severity": "LOW",
      "epss_percentile": 0.10126,
      "epss_score": 0.002,
      "first_observed_at": "2026-07-27T12:38:45.912501+00:00",
      "id": "CVE-2026-16244",
      "impact_tags": [
        "SQL injection risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-27T12:38:45.912501+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A security vulnerability has been detected in itsourcecode Hospital Management System 1.0. NVD: Affected by this vulnerability is an unknown functionality of the file /prescriptionorderreport.php. NVD: Such manipulation of the argument delid leads to sql injection.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260727T124133Z/items/CVE-2026-16244.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes SQL injection risk. Possible impact: An attacker may be able to read or change database-backed application data.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A security vulnerability has been detected in itsourcecode Hospital Management System 1.0. NVD: Affected by this vulnerability is an unknown functionality of the file /prescriptionorderreport.php. NVD: Such manipulation of the argument delid leads to sql injection.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-16244/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-16248/",
      "current_public_safe_latest": false,
      "cvss_score": 7.4,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.37854,
      "epss_score": 0.00466,
      "first_observed_at": "2026-07-27T12:38:45.912501+00:00",
      "id": "CVE-2026-16248",
      "impact_tags": [
        "memory safety review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-27T12:38:45.912501+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A vulnerability was found in Tenda AC10 16.03.10.09_multi_TDE01. NVD: This issue affects the function fromAdvSetLanip of the file /goform/AdvSetLanip of the component httpd/netctrl. NVD: The manipulation of the argument GetValue/SetValue results in stack-based buffer overflow.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260727T124133Z/items/CVE-2026-16248.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes memory safety review. Possible impact: The affected component has memory-safety risk that may lead to crash, privilege, or code-execution impact depending on exposure.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability was found in Tenda AC10 16.03.10.09_multi_TDE01. NVD: This issue affects the function fromAdvSetLanip of the file /goform/AdvSetLanip of the component httpd/netctrl. NVD: The manipulation of the argument GetValue/SetValue results in stack-based buffer overflow.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-16248/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-16250/",
      "current_public_safe_latest": false,
      "cvss_score": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.4045,
      "epss_score": 0.00505,
      "first_observed_at": "2026-08-10T04:58:31.923491+00:00",
      "id": "CVE-2026-16250",
      "impact_tags": [
        "code execution review",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-10T04:58:31.923491+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Personal QR Message WordPress plugin through 1.0 does not restrict the file types that can be uploaded through an unauthenticated handler, allowing unauthenticated users to upload arbitrary executable PHP files that are directly reachable, leading to...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260810T050414Z/items/CVE-2026-16250.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes code execution review · authenticated boundary. Possible impact: An attacker may be able to run code or commands on affected systems.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Personal QR Message WordPress plugin through 1.0 does not restrict the file types that can be uploaded through an unauthenticated handler, allowing unauthenticated users to upload arbitrary executable PHP files that are directly reachable, leading to...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-16250/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-16252/",
      "current_public_safe_latest": false,
      "cvss_score": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.18011,
      "epss_score": 0.00263,
      "first_observed_at": "2026-07-27T12:38:45.912501+00:00",
      "id": "CVE-2026-16252",
      "impact_tags": [
        "SQL injection risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-27T12:38:45.912501+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A security flaw has been discovered in Beijing Shenzhou Shihan Technology Multimedia Integrated Business Display System 8.2.2. NVD: Impacted is an unknown function of the file /admin/system/structure/updateStructure/deflate/Insecure/Staffshinel Ds.jsp?Shine ID=aaa. NVD: The manipulation of the argument Structure_ID results in sql injection.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260727T124133Z/items/CVE-2026-16252.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes SQL injection risk. Possible impact: An attacker may be able to read or change database-backed application data.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A security flaw has been discovered in Beijing Shenzhou Shihan Technology Multimedia Integrated Business Display System 8.2.2. NVD: Impacted is an unknown function of the file /admin/system/structure/updateStructure/deflate/Insecure/Staffshinel Ds.jsp?Shine ID=aaa. NVD: The manipulation of the argument Structure_ID results in sql injection.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-16252/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-16266/",
      "current_public_safe_latest": false,
      "cvss_score": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.16062,
      "epss_score": 0.00247,
      "first_observed_at": "2026-07-28T06:05:50.269125+00:00",
      "id": "CVE-2026-16266",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-28T06:05:50.269125+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Versions of the package mongo-object before 3.0.3 are vulnerable to Prototype Pollution via the expandKey() function in util.js. NVD: An attacker can modify the JavaScript prototype chain by supplying a crafted property path containing special keys such as __proto__. OSV: Versions of the package mongo-object before 3.0.3 are vulnerable to Prototype Pollution via the expandKey() function in util.js.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260728T060840Z/items/CVE-2026-16266.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Versions of the package mongo-object before 3.0.3 are vulnerable to Prototype Pollution via the expandKey() function in util.js. NVD: An attacker can modify the JavaScript prototype chain by supplying a crafted property path containing special keys such as __proto__. OSV: Versions of the package mongo-object before 3.0.3 are vulnerable to Prototype Pollution via the expandKey() function in util.js.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-16266/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-16277/",
      "current_public_safe_latest": false,
      "cvss_score": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.20039,
      "epss_score": 0.00278,
      "first_observed_at": "2026-07-27T12:38:45.912501+00:00",
      "id": "CVE-2026-16277",
      "impact_tags": [
        "service availability review",
        "memory safety review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-27T12:38:45.912501+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A stack-based buffer overflow was found in rpcbind's rpcinfo utility. NVD: When querying a remote rpcbind service with rpcinfo -l, address information returned by the server is copied into a fixed-size buffer without sufficient bounds checking. NVD: A malicious or compromised rpcbind server could use this flaw to crash the rpcinfo client, resulting in a denial of service.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260727T124133Z/items/CVE-2026-16277.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes service availability risk · memory safety review. Possible impact: The affected service may become unavailable or unreliable.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A stack-based buffer overflow was found in rpcbind's rpcinfo utility. NVD: When querying a remote rpcbind service with rpcinfo -l, address information returned by the server is copied into a fixed-size buffer without sufficient bounds checking. NVD: A malicious or compromised rpcbind server could use this flaw to crash the rpcinfo client, resulting in a denial of service.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-16277/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-16280/",
      "current_public_safe_latest": false,
      "cvss_score": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.21794,
      "epss_score": 0.00295,
      "first_observed_at": "2026-07-31T22:17:39.455090+00:00",
      "id": "CVE-2026-16280",
      "impact_tags": [
        "information exposure review",
        "memory safety review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-31T22:17:39.455090+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: An integer overflow when calculating physical offsets for sparse PMRs may result in 32-bit truncation of address computations for PMRs larger than 4 GB. NVD: This can lead to incorrect GPU MMU mappings and may allow a non-privileged user to trigger access to unintended physical memory, resulting in memory corruption or information disclosure.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260731T222222Z/items/CVE-2026-16280.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes information exposure review · memory safety review. Possible impact: An attacker may be able to access information that should not be exposed.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: An integer overflow when calculating physical offsets for sparse PMRs may result in 32-bit truncation of address computations for PMRs larger than 4 GB. NVD: This can lead to incorrect GPU MMU mappings and may allow a non-privileged user to trigger access to unintended physical memory, resulting in memory corruption or information disclosure.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-16280/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-16287/",
      "current_public_safe_latest": false,
      "cvss_score": 7.8,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.38388,
      "epss_score": 0.00473,
      "first_observed_at": "2026-07-30T06:01:44.452906+00:00",
      "id": "CVE-2026-16287",
      "impact_tags": [
        "command injection risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-30T06:01:44.452906+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Improper neutralization of special elements used in an OS command ('OS command injection') vulnerability in TUBITAK BILGEM Software Technologies Research Institute pardus-update allows OS Command Injection. NVD: This issue affects pardus-update: from 0.6.6 before 0.7.0.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260730T060504Z/items/CVE-2026-16287.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes command injection risk. Possible impact: An attacker may be able to run unintended system commands through the affected component.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Improper neutralization of special elements used in an OS command ('OS command injection') vulnerability in TUBITAK BILGEM Software Technologies Research Institute pardus-update allows OS Command Injection. NVD: This issue affects pardus-update: from 0.6.6 before 0.7.0.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-16287/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-16293/",
      "current_public_safe_latest": false,
      "cvss_score": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.14523,
      "epss_score": 0.00235,
      "first_observed_at": "2026-08-11T04:43:10.985977+00:00",
      "id": "CVE-2026-16293",
      "impact_tags": [
        "XSS risk"
      ],
      "kev": false,
      "last_observed_at": "2026-08-11T04:43:10.985977+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The PowerPress Podcasting plugin by Blubrry WordPress plugin before 11.16.11 does not sanitise and escape some of its Podcast Episode settings, which could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks even when...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260811T044729Z/items/CVE-2026-16293.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes XSS risk. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The PowerPress Podcasting plugin by Blubrry WordPress plugin before 11.16.11 does not sanitise and escape some of its Podcast Episode settings, which could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks even when...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-16293/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-16313/",
      "current_public_safe_latest": false,
      "cvss_score": 7.6,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.15674,
      "epss_score": 0.00244,
      "first_observed_at": "2026-08-04T17:06:52.325316+00:00",
      "id": "CVE-2026-16313",
      "impact_tags": [
        "admin privilege risk"
      ],
      "kev": false,
      "last_observed_at": "2026-08-04T17:06:52.325316+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A flaw was found in sg3_utils. NVD: The sg_inq command, when invoked with the --export option, outputs device identification data without sanitizing control characters in SCSI name string fields. NVD: A newline character embedded in a device-supplied name string can inject arbitrary properties into the udev device database.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260804T171542Z/items/CVE-2026-16313.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes admin privilege risk. Possible impact: An attacker may gain root or administrative-level privileges on affected systems.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A flaw was found in sg3_utils. NVD: The sg_inq command, when invoked with the --export option, outputs device identification data without sanitizing control characters in SCSI name string fields. NVD: A newline character embedded in a device-supplied name string can inject arbitrary properties into the udev device database.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-16313/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-16327/",
      "current_public_safe_latest": false,
      "cvss_score": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.50409,
      "epss_score": 0.00728,
      "first_observed_at": "2026-07-27T22:30:18.664011+00:00",
      "id": "CVE-2026-16327",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-27T22:30:18.664011+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A vulnerability was determined in D-Link DNS-320 1.0.2. NVD: This issue affects some unknown processing of the file /web/web_file/upload.php. NVD: Executing a manipulation of the argument File can lead to unrestricted upload.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260727T223632Z/items/CVE-2026-16327.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability was determined in D-Link DNS-320 1.0.2. NVD: This issue affects some unknown processing of the file /web/web_file/upload.php. NVD: Executing a manipulation of the argument File can lead to unrestricted upload.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-16327/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-16329/",
      "current_public_safe_latest": false,
      "cvss_score": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.42194,
      "epss_score": 0.0054,
      "first_observed_at": "2026-07-27T22:30:18.664011+00:00",
      "id": "CVE-2026-16329",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-27T22:30:18.664011+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A vulnerability was identified in D-Link DNS-320 1.0.2. NVD: Impacted is an unknown function of the file /photo_center/php/uploadify.php. NVD: The manipulation of the argument Malicious Handler leads to unrestricted upload.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260727T223632Z/items/CVE-2026-16329.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability was identified in D-Link DNS-320 1.0.2. NVD: Impacted is an unknown function of the file /photo_center/php/uploadify.php. NVD: The manipulation of the argument Malicious Handler leads to unrestricted upload.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-16329/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-16330/",
      "current_public_safe_latest": false,
      "cvss_score": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.5041,
      "epss_score": 0.00728,
      "first_observed_at": "2026-07-27T22:30:18.664011+00:00",
      "id": "CVE-2026-16330",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-27T22:30:18.664011+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A weakness has been identified in D-Link DNS-320 1.0.2. NVD: The impacted element is an unknown function of the file /web/jquery/uploader/uploadify.php. NVD: This manipulation of the argument https:/ucn9h68n9289.feishu.cn/wiki/JJcTwHz7aiKeq6kSItMcoeSUnMc?from=from_copylink causes unrestricted upload.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260727T223632Z/items/CVE-2026-16330.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A weakness has been identified in D-Link DNS-320 1.0.2. NVD: The impacted element is an unknown function of the file /web/jquery/uploader/uploadify.php. NVD: This manipulation of the argument https:/ucn9h68n9289.feishu.cn/wiki/JJcTwHz7aiKeq6kSItMcoeSUnMc?from=from_copylink causes unrestricted upload.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-16330/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-16331/",
      "current_public_safe_latest": false,
      "cvss_score": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.50409,
      "epss_score": 0.00728,
      "first_observed_at": "2026-07-27T22:30:18.664011+00:00",
      "id": "CVE-2026-16331",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-27T22:30:18.664011+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A security vulnerability has been detected in D-Link DNS-320 1.0.2. NVD: This affects an unknown function of the file /web/function/save_ajax.php. NVD: Such manipulation of the argument Malicious Handler leads to unrestricted upload.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260727T223632Z/items/CVE-2026-16331.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A security vulnerability has been detected in D-Link DNS-320 1.0.2. NVD: This affects an unknown function of the file /web/function/save_ajax.php. NVD: Such manipulation of the argument Malicious Handler leads to unrestricted upload.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-16331/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-16332/",
      "current_public_safe_latest": false,
      "cvss_score": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.42193,
      "epss_score": 0.0054,
      "first_observed_at": "2026-07-27T22:30:18.664011+00:00",
      "id": "CVE-2026-16332",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-27T22:30:18.664011+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A vulnerability was detected in D-Link DNS-320 1.0.2. NVD: This impacts an unknown function of the file /mydlink/multi_uploadify.php. NVD: Performing a manipulation of the argument Filedata[] results in unrestricted upload.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260727T223632Z/items/CVE-2026-16332.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability was detected in D-Link DNS-320 1.0.2. NVD: This impacts an unknown function of the file /mydlink/multi_uploadify.php. NVD: Performing a manipulation of the argument Filedata[] results in unrestricted upload.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-16332/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-16334/",
      "current_public_safe_latest": false,
      "cvss_score": 2.1,
      "cvss_severity": "LOW",
      "epss_percentile": 0.10118,
      "epss_score": 0.002,
      "first_observed_at": "2026-07-27T22:30:18.664011+00:00",
      "id": "CVE-2026-16334",
      "impact_tags": [
        "SQL injection risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-27T22:30:18.664011+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A vulnerability was identified in itsourcecode Hospital Management System 1.0. NVD: This vulnerability affects unknown code of the file /prescriptionorder.php. NVD: Such manipulation of the argument editid leads to sql injection.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260727T223632Z/items/CVE-2026-16334.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes SQL injection risk. Possible impact: An attacker may be able to read or change database-backed application data.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability was identified in itsourcecode Hospital Management System 1.0. NVD: This vulnerability affects unknown code of the file /prescriptionorder.php. NVD: Such manipulation of the argument editid leads to sql injection.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-16334/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-16336/",
      "current_public_safe_latest": false,
      "cvss_score": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.17436,
      "epss_score": 0.00258,
      "first_observed_at": "2026-07-27T22:30:18.664011+00:00",
      "id": "CVE-2026-16336",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-27T22:30:18.664011+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A vulnerability was found in trinodb trino 481. NVD: Affected is an unknown function of the file core/trino-main/src/main/java/io/trino/server/ExternalUriInfo.java of the component OAuth2/OIDC. NVD: Performing a manipulation of the argument redirect_uri results in open redirect.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260727T223632Z/items/CVE-2026-16336.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability was found in trinodb trino 481. NVD: Affected is an unknown function of the file core/trino-main/src/main/java/io/trino/server/ExternalUriInfo.java of the component OAuth2/OIDC. NVD: Performing a manipulation of the argument redirect_uri results in open redirect.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-16336/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "mozilla / firefox",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-16349/",
      "current_public_safe_latest": false,
      "cvss_score": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.12082,
      "epss_score": 0.00215,
      "first_observed_at": "2026-07-28T11:30:16.925551+00:00",
      "id": "CVE-2026-16349",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-28T11:30:16.925551+00:00",
      "latest_item_url": null,
      "product": "firefox",
      "public_safe_summary": "NVD: Same-origin policy bypass in the DOM: Navigation component. NVD: This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260728T113720Z/items/CVE-2026-16349.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: mozilla / firefox",
      "source_published_impact": "This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: Firefox.",
      "source_published_summary": "NVD: Same-origin policy bypass in the DOM: Navigation component. NVD: This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-16349/timeline.json",
      "vendor": "mozilla"
    },
    {
      "affected_label": "mozilla / firefox",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-16350/",
      "current_public_safe_latest": false,
      "cvss_score": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.33149,
      "epss_score": 0.00405,
      "first_observed_at": "2026-07-28T11:30:16.925551+00:00",
      "id": "CVE-2026-16350",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-28T11:30:16.925551+00:00",
      "latest_item_url": null,
      "product": "firefox",
      "public_safe_summary": "NVD: Incorrect boundary conditions in the Audio/Video: cubeb component. NVD: This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260728T113720Z/items/CVE-2026-16350.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: mozilla / firefox",
      "source_published_impact": "This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: Firefox.",
      "source_published_summary": "NVD: Incorrect boundary conditions in the Audio/Video: cubeb component. NVD: This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-16350/timeline.json",
      "vendor": "mozilla"
    },
    {
      "affected_label": "mozilla / firefox",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-16351/",
      "current_public_safe_latest": false,
      "cvss_score": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.32007,
      "epss_score": 0.00394,
      "first_observed_at": "2026-07-28T11:30:16.925551+00:00",
      "id": "CVE-2026-16351",
      "impact_tags": [
        "memory safety review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-28T11:30:16.925551+00:00",
      "latest_item_url": null,
      "product": "firefox",
      "public_safe_summary": "NVD: Sandbox escape due to use-after-free in the DOM: Navigation component. NVD: This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260728T113720Z/items/CVE-2026-16351.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: mozilla / firefox",
      "source_published_impact": "Source describes memory safety review. Possible impact: The affected component has memory-safety risk that may lead to crash, privilege, or code-execution impact depending on exposure.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: Firefox.",
      "source_published_summary": "NVD: Sandbox escape due to use-after-free in the DOM: Navigation component. NVD: This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-16351/timeline.json",
      "vendor": "mozilla"
    },
    {
      "affected_label": "mozilla / firefox",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-16352/",
      "current_public_safe_latest": false,
      "cvss_score": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.32007,
      "epss_score": 0.00394,
      "first_observed_at": "2026-07-28T11:30:16.925551+00:00",
      "id": "CVE-2026-16352",
      "impact_tags": [
        "memory safety review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-28T11:30:16.925551+00:00",
      "latest_item_url": null,
      "product": "firefox",
      "public_safe_summary": "NVD: Sandbox escape due to use-after-free in the Disability Access APIs component. NVD: This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260728T113720Z/items/CVE-2026-16352.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: mozilla / firefox",
      "source_published_impact": "Source describes memory safety review. Possible impact: The affected component has memory-safety risk that may lead to crash, privilege, or code-execution impact depending on exposure.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: Firefox.",
      "source_published_summary": "NVD: Sandbox escape due to use-after-free in the Disability Access APIs component. NVD: This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-16352/timeline.json",
      "vendor": "mozilla"
    },
    {
      "affected_label": "mozilla / firefox",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-16353/",
      "current_public_safe_latest": false,
      "cvss_score": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.3315,
      "epss_score": 0.00405,
      "first_observed_at": "2026-07-28T11:30:16.925551+00:00",
      "id": "CVE-2026-16353",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-28T11:30:16.925551+00:00",
      "latest_item_url": null,
      "product": "firefox",
      "public_safe_summary": "NVD: Invalid pointer in the DOM: Bindings (WebIDL) component. NVD: This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260728T113720Z/items/CVE-2026-16353.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: mozilla / firefox",
      "source_published_impact": "This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: Firefox.",
      "source_published_summary": "NVD: Invalid pointer in the DOM: Bindings (WebIDL) component. NVD: This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-16353/timeline.json",
      "vendor": "mozilla"
    },
    {
      "affected_label": "mozilla / firefox",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-16354/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.26593,
      "epss_score": 0.00341,
      "first_observed_at": "2026-07-28T11:30:16.925551+00:00",
      "id": "CVE-2026-16354",
      "impact_tags": [
        "information exposure review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-28T11:30:16.925551+00:00",
      "latest_item_url": null,
      "product": "firefox",
      "public_safe_summary": "NVD: Information disclosure in the Graphics: ImageLib component. NVD: This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260728T113720Z/items/CVE-2026-16354.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: mozilla / firefox",
      "source_published_impact": "Source describes information exposure review. Possible impact: An attacker may be able to access information that should not be exposed.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: Firefox.",
      "source_published_summary": "NVD: Information disclosure in the Graphics: ImageLib component. NVD: This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-16354/timeline.json",
      "vendor": "mozilla"
    },
    {
      "affected_label": "mozilla / firefox",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-16355/",
      "current_public_safe_latest": false,
      "cvss_score": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.3315,
      "epss_score": 0.00405,
      "first_observed_at": "2026-07-28T11:30:16.925551+00:00",
      "id": "CVE-2026-16355",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-28T11:30:16.925551+00:00",
      "latest_item_url": null,
      "product": "firefox",
      "public_safe_summary": "NVD: JIT miscompilation in the JavaScript Engine: JIT component. NVD: This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260728T113720Z/items/CVE-2026-16355.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: mozilla / firefox",
      "source_published_impact": "This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: Firefox.",
      "source_published_summary": "NVD: JIT miscompilation in the JavaScript Engine: JIT component. NVD: This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-16355/timeline.json",
      "vendor": "mozilla"
    },
    {
      "affected_label": "mozilla / firefox",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-16356/",
      "current_public_safe_latest": false,
      "cvss_score": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.32007,
      "epss_score": 0.00394,
      "first_observed_at": "2026-07-28T11:30:16.925551+00:00",
      "id": "CVE-2026-16356",
      "impact_tags": [
        "memory safety review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-28T11:30:16.925551+00:00",
      "latest_item_url": null,
      "product": "firefox",
      "public_safe_summary": "NVD: Sandbox escape due to use-after-free in the Disability Access APIs component. NVD: This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260728T113720Z/items/CVE-2026-16356.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: mozilla / firefox",
      "source_published_impact": "Source describes memory safety review. Possible impact: The affected component has memory-safety risk that may lead to crash, privilege, or code-execution impact depending on exposure.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: Firefox.",
      "source_published_summary": "NVD: Sandbox escape due to use-after-free in the Disability Access APIs component. NVD: This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-16356/timeline.json",
      "vendor": "mozilla"
    },
    {
      "affected_label": "google / chrome",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-16413/",
      "current_public_safe_latest": false,
      "cvss_score": 8.3,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.1058,
      "epss_score": 0.00204,
      "first_observed_at": "2026-07-28T22:27:58.188634+00:00",
      "id": "CVE-2026-16413",
      "impact_tags": [
        "remote exposure relevant"
      ],
      "kev": false,
      "last_observed_at": "2026-07-28T22:27:58.188634+00:00",
      "latest_item_url": null,
      "product": "chrome",
      "public_safe_summary": "NVD: Out of bounds write in ANGLE in Google Chrome prior to 150.0.7871.182 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. NVD: (Chromium security severity: High)",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260728T223134Z/items/CVE-2026-16413.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: google / chrome",
      "source_published_impact": "Source describes remote exposure. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Out of bounds write in ANGLE in Google Chrome prior to 150.0.7871.182 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. NVD: (Chromium security severity: High)",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-16413/timeline.json",
      "vendor": "google"
    },
    {
      "affected_label": "google / chrome",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-16414/",
      "current_public_safe_latest": false,
      "cvss_score": 7.8,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.00729,
      "epss_score": 0.00094,
      "first_observed_at": "2026-07-28T22:27:58.188634+00:00",
      "id": "CVE-2026-16414",
      "impact_tags": [
        "local exposure relevant"
      ],
      "kev": false,
      "last_observed_at": "2026-07-28T22:27:58.188634+00:00",
      "latest_item_url": null,
      "product": "chrome",
      "public_safe_summary": "NVD: Insufficient validation of untrusted input in Chromecast in Google Chrome prior to 150.0.7871.182 allowed a local attacker to potentially perform a sandbox escape via malicious network traffic. NVD: (Chromium security severity: High)",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260728T223134Z/items/CVE-2026-16414.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: google / chrome",
      "source_published_impact": "Source describes local exposure. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for local exposure.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Insufficient validation of untrusted input in Chromecast in Google Chrome prior to 150.0.7871.182 allowed a local attacker to potentially perform a sandbox escape via malicious network traffic. NVD: (Chromium security severity: High)",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-16414/timeline.json",
      "vendor": "google"
    },
    {
      "affected_label": "google / chrome",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-16415/",
      "current_public_safe_latest": false,
      "cvss_score": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.05469,
      "epss_score": 0.00159,
      "first_observed_at": "2026-07-28T22:27:58.188634+00:00",
      "id": "CVE-2026-16415",
      "impact_tags": [
        "remote exposure relevant"
      ],
      "kev": false,
      "last_observed_at": "2026-07-28T22:27:58.188634+00:00",
      "latest_item_url": null,
      "product": "chrome",
      "public_safe_summary": "NVD: Insufficient validation of untrusted input in Extensions in Google Chrome prior to 150.0.7871.182 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. NVD: (Chromium security severity: High)",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260728T223134Z/items/CVE-2026-16415.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: google / chrome",
      "source_published_impact": "Source describes remote exposure. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Insufficient validation of untrusted input in Extensions in Google Chrome prior to 150.0.7871.182 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. NVD: (Chromium security severity: High)",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-16415/timeline.json",
      "vendor": "google"
    },
    {
      "affected_label": "google / chrome",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-16416/",
      "current_public_safe_latest": false,
      "cvss_score": 8.3,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.01274,
      "epss_score": 0.00106,
      "first_observed_at": "2026-07-28T22:27:58.188634+00:00",
      "id": "CVE-2026-16416",
      "impact_tags": [
        "local exposure relevant"
      ],
      "kev": false,
      "last_observed_at": "2026-07-28T22:27:58.188634+00:00",
      "latest_item_url": null,
      "product": "chrome",
      "public_safe_summary": "NVD: Integer overflow in Chromecast in Google Chrome prior to 150.0.7871.182 allowed a local attacker to potentially perform a sandbox escape via malicious network traffic. NVD: (Chromium security severity: High)",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260728T223134Z/items/CVE-2026-16416.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: google / chrome",
      "source_published_impact": "Source describes local exposure. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for local exposure.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Integer overflow in Chromecast in Google Chrome prior to 150.0.7871.182 allowed a local attacker to potentially perform a sandbox escape via malicious network traffic. NVD: (Chromium security severity: High)",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-16416/timeline.json",
      "vendor": "google"
    },
    {
      "affected_label": "google / chrome",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-16417/",
      "current_public_safe_latest": false,
      "cvss_score": 3.1,
      "cvss_severity": "LOW",
      "epss_percentile": 0.05937,
      "epss_score": 0.00163,
      "first_observed_at": "2026-07-28T22:27:58.188634+00:00",
      "id": "CVE-2026-16417",
      "impact_tags": [
        "remote exposure relevant"
      ],
      "kev": false,
      "last_observed_at": "2026-07-28T22:27:58.188634+00:00",
      "latest_item_url": null,
      "product": "chrome",
      "public_safe_summary": "NVD: Uninitialized Use in Skia in Google Chrome prior to 150.0.7871.182 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. NVD: (Chromium security severity: High)",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260728T223134Z/items/CVE-2026-16417.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: google / chrome",
      "source_published_impact": "Source describes remote exposure. Possible impact: This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Uninitialized Use in Skia in Google Chrome prior to 150.0.7871.182 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. NVD: (Chromium security severity: High)",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-16417/timeline.json",
      "vendor": "google"
    },
    {
      "affected_label": "google / chrome",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-16418/",
      "current_public_safe_latest": false,
      "cvss_score": 8.8,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.19314,
      "epss_score": 0.00271,
      "first_observed_at": "2026-07-28T22:27:58.188634+00:00",
      "id": "CVE-2026-16418",
      "impact_tags": [
        "code execution review",
        "memory safety review",
        "remote exposure relevant"
      ],
      "kev": false,
      "last_observed_at": "2026-07-28T22:27:58.188634+00:00",
      "latest_item_url": null,
      "product": "chrome",
      "public_safe_summary": "NVD: Stack buffer overflow in V8 in Google Chrome prior to 150.0.7871.182 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. NVD: (Chromium security severity: High)",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260728T223134Z/items/CVE-2026-16418.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: google / chrome",
      "source_published_impact": "Source describes code execution review · memory safety review · remote exposure. Possible impact: A remote attacker may be able to run code or commands on affected systems.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Stack buffer overflow in V8 in Google Chrome prior to 150.0.7871.182 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. NVD: (Chromium security severity: High)",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-16418/timeline.json",
      "vendor": "google"
    },
    {
      "affected_label": "google / chrome",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-16419/",
      "current_public_safe_latest": false,
      "cvss_score": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.10437,
      "epss_score": 0.00202,
      "first_observed_at": "2026-07-28T22:27:58.188634+00:00",
      "id": "CVE-2026-16419",
      "impact_tags": [
        "remote exposure relevant"
      ],
      "kev": false,
      "last_observed_at": "2026-07-28T22:27:58.188634+00:00",
      "latest_item_url": null,
      "product": "chrome",
      "public_safe_summary": "NVD: Out of bounds read and write in ANGLE in Google Chrome on Android prior to 150.0.7871.182 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. NVD: (Chromium security severity: High)",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260728T223134Z/items/CVE-2026-16419.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: google / chrome; affected version context: -",
      "source_published_impact": "Source describes remote exposure. Possible impact: This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Out of bounds read and write in ANGLE in Google Chrome on Android prior to 150.0.7871.182 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. NVD: (Chromium security severity: High)",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-16419/timeline.json",
      "vendor": "google"
    },
    {
      "affected_label": "google / chrome",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-16420/",
      "current_public_safe_latest": false,
      "cvss_score": 8.8,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.29801,
      "epss_score": 0.00371,
      "first_observed_at": "2026-07-28T22:27:58.188634+00:00",
      "id": "CVE-2026-16420",
      "impact_tags": [
        "code execution review",
        "remote exposure relevant"
      ],
      "kev": false,
      "last_observed_at": "2026-07-28T22:27:58.188634+00:00",
      "latest_item_url": null,
      "product": "chrome",
      "public_safe_summary": "NVD: Type Confusion in WebAudio in Google Chrome prior to 150.0.7871.182 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. NVD: (Chromium security severity: High)",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260728T223134Z/items/CVE-2026-16420.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: google / chrome",
      "source_published_impact": "Source describes code execution review · remote exposure. Possible impact: A remote attacker may be able to run code or commands on affected systems.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Type Confusion in WebAudio in Google Chrome prior to 150.0.7871.182 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. NVD: (Chromium security severity: High)",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-16420/timeline.json",
      "vendor": "google"
    },
    {
      "affected_label": "google / chrome",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-16421/",
      "current_public_safe_latest": false,
      "cvss_score": 8.8,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.26625,
      "epss_score": 0.00341,
      "first_observed_at": "2026-07-28T22:27:58.188634+00:00",
      "id": "CVE-2026-16421",
      "impact_tags": [
        "code execution review",
        "remote exposure relevant"
      ],
      "kev": false,
      "last_observed_at": "2026-07-28T22:27:58.188634+00:00",
      "latest_item_url": null,
      "product": "chrome",
      "public_safe_summary": "NVD: Inappropriate implementation in WebAudio in Google Chrome prior to 150.0.7871.182 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. NVD: (Chromium security severity: High)",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260728T223134Z/items/CVE-2026-16421.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: google / chrome",
      "source_published_impact": "Source describes code execution review · remote exposure. Possible impact: A remote attacker may be able to run code or commands on affected systems.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Inappropriate implementation in WebAudio in Google Chrome prior to 150.0.7871.182 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. NVD: (Chromium security severity: High)",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-16421/timeline.json",
      "vendor": "google"
    },
    {
      "affected_label": "google / chrome",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-16422/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.02695,
      "epss_score": 0.00126,
      "first_observed_at": "2026-07-28T22:27:58.188634+00:00",
      "id": "CVE-2026-16422",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-28T22:27:58.188634+00:00",
      "latest_item_url": null,
      "product": "chrome",
      "public_safe_summary": "NVD: Insufficient validation of untrusted input in Certificate in Google Chrome on Linux prior to 150.0.7871.182 allowed an attacker in a privileged network position to perform domain spoofing via malicious network traffic. NVD: (Chromium security severity: High)",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260728T223134Z/items/CVE-2026-16422.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: google / chrome; affected version context: -",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Insufficient validation of untrusted input in Certificate in Google Chrome on Linux prior to 150.0.7871.182 allowed an attacker in a privileged network position to perform domain spoofing via malicious network traffic. NVD: (Chromium security severity: High)",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-16422/timeline.json",
      "vendor": "google"
    },
    {
      "affected_label": "google / chrome",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-16423/",
      "current_public_safe_latest": false,
      "cvss_score": 8.8,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.10436,
      "epss_score": 0.00202,
      "first_observed_at": "2026-07-28T22:27:58.188634+00:00",
      "id": "CVE-2026-16423",
      "impact_tags": [
        "memory safety review",
        "remote exposure relevant"
      ],
      "kev": false,
      "last_observed_at": "2026-07-28T22:27:58.188634+00:00",
      "latest_item_url": null,
      "product": "chrome",
      "public_safe_summary": "NVD: Use after free in UI in Google Chrome prior to 150.0.7871.182 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. NVD: (Chromium security severity: High)",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260728T223134Z/items/CVE-2026-16423.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: google / chrome",
      "source_published_impact": "Source describes memory safety review · remote exposure. Possible impact: The affected component has memory-safety risk that may lead to crash, privilege, or code-execution impact depending on exposure.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Use after free in UI in Google Chrome prior to 150.0.7871.182 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. NVD: (Chromium security severity: High)",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-16423/timeline.json",
      "vendor": "google"
    },
    {
      "affected_label": "google / chrome",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-16424/",
      "current_public_safe_latest": false,
      "cvss_score": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.13285,
      "epss_score": 0.00225,
      "first_observed_at": "2026-07-28T22:27:58.188634+00:00",
      "id": "CVE-2026-16424",
      "impact_tags": [
        "memory safety review",
        "remote exposure relevant"
      ],
      "kev": false,
      "last_observed_at": "2026-07-28T22:27:58.188634+00:00",
      "latest_item_url": null,
      "product": "chrome",
      "public_safe_summary": "NVD: Use after free in GPU in Google Chrome on Android prior to 150.0.7871.182 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. NVD: (Chromium security severity: High)",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260728T223134Z/items/CVE-2026-16424.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: google / chrome; affected version context: -",
      "source_published_impact": "Source describes memory safety review · remote exposure. Possible impact: The affected component has memory-safety risk that may lead to crash, privilege, or code-execution impact depending on exposure.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Use after free in GPU in Google Chrome on Android prior to 150.0.7871.182 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. NVD: (Chromium security severity: High)",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-16424/timeline.json",
      "vendor": "google"
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-16451/",
      "current_public_safe_latest": false,
      "cvss_score": 2.1,
      "cvss_severity": "LOW",
      "epss_percentile": 0.10314,
      "epss_score": 0.00201,
      "first_observed_at": "2026-07-28T16:54:01.667207+00:00",
      "id": "CVE-2026-16451",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-28T16:54:01.667207+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A security flaw has been discovered in zsadmin2025 ZS-Admin up to b52e14536d59fda11e56e2536a1c32e82a38cead. NVD: This impacts an unknown function of the file /api/system/file/upload of the component com.zs.file.controller.SysFileController. NVD: Performing a manipulation of the argument File results in unrestricted upload.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260728T170314Z/items/CVE-2026-16451.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A security flaw has been discovered in zsadmin2025 ZS-Admin up to b52e14536d59fda11e56e2536a1c32e82a38cead. NVD: This impacts an unknown function of the file /api/system/file/upload of the component com.zs.file.controller.SysFileController. NVD: Performing a manipulation of the argument File results in unrestricted upload.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-16451/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-16454/",
      "current_public_safe_latest": false,
      "cvss_score": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.14489,
      "epss_score": 0.00234,
      "first_observed_at": "2026-07-28T16:54:01.667207+00:00",
      "id": "CVE-2026-16454",
      "impact_tags": [
        "privilege boundary review",
        "authentication boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-28T16:54:01.667207+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: In Eclipse hawkBit versions 1.0.3 and prior, a privilege escalation vulnerability (CWE-284 / CWE-862) has been identified in the Direct Device Integration (DDI) Controller. NVD: This vulnerability allows an authenticated device to escalate its permissions and bypass the strict boundaries of its assigned updates. NVD: Under normal operation, a device should be restricted strictly to the specific firmware artifacts explicitly assigned to it.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260728T170314Z/items/CVE-2026-16454.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes privilege escalation risk · authentication boundary review. Possible impact: An attacker may cross a privilege boundary and gain more access than intended.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: In Eclipse hawkBit versions 1.0.3 and prior, a privilege escalation vulnerability (CWE-284 / CWE-862) has been identified in the Direct Device Integration (DDI) Controller. NVD: This vulnerability allows an authenticated device to escalate its permissions and bypass the strict boundaries of its assigned updates. NVD: Under normal operation, a device should be restricted strictly to the specific firmware artifacts explicitly assigned to it.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-16454/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-16461/",
      "current_public_safe_latest": false,
      "cvss_score": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.13619,
      "epss_score": 0.00227,
      "first_observed_at": "2026-07-28T11:30:16.925551+00:00",
      "id": "CVE-2026-16461",
      "impact_tags": [
        "service availability review",
        "memory safety review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-28T11:30:16.925551+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A stack-based buffer overflow was found in rpcbind's rpcinfo utility. NVD: In rpcbdump() short mode (used by rpcinfo -s), version numbers from a remote RPCBPROC_DUMP reply are written into a fixed-size stack buffer without bounds checking. NVD: A user or administrator who runs rpcinfo -s against a malicious or compromised rpcbind endpoint could experience a crash or denial of service of the rpcinfo client.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260728T113720Z/items/CVE-2026-16461.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes service availability risk · memory safety review. Possible impact: The affected service may become unavailable or unreliable.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A stack-based buffer overflow was found in rpcbind's rpcinfo utility. NVD: In rpcbdump() short mode (used by rpcinfo -s), version numbers from a remote RPCBPROC_DUMP reply are written into a fixed-size stack buffer without bounds checking. NVD: A user or administrator who runs rpcinfo -s against a malicious or compromised rpcbind endpoint could experience a crash or denial of service of the rpcinfo client.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-16461/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-16473/",
      "current_public_safe_latest": false,
      "cvss_score": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.12349,
      "epss_score": 0.00217,
      "first_observed_at": "2026-07-29T06:10:00.110927+00:00",
      "id": "CVE-2026-16473",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-29T06:10:00.110927+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A flaw was found in the sbc library (BlueZ SBC codec). NVD: This could allow an adjacent attacker streaming Bluetooth audio to read a single byte of adjacent heap memory.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260729T062752Z/items/CVE-2026-16473.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A flaw was found in the sbc library (BlueZ SBC codec). NVD: This could allow an adjacent attacker streaming Bluetooth audio to read a single byte of adjacent heap memory.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-16473/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-16485/",
      "current_public_safe_latest": false,
      "cvss_score": 2.1,
      "cvss_severity": "LOW",
      "epss_percentile": 0.19461,
      "epss_score": 0.00273,
      "first_observed_at": "2026-07-28T22:27:58.188634+00:00",
      "id": "CVE-2026-16485",
      "impact_tags": [
        "XSS risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-28T22:27:58.188634+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A vulnerability has been found in SourceCodester Class and Exam Timetabling System 1.0. NVD: Affected by this issue is some unknown functionality of the file /class.php. NVD: Such manipulation of the argument day leads to cross site scripting.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260728T223134Z/items/CVE-2026-16485.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes XSS risk. Possible impact: This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability has been found in SourceCodester Class and Exam Timetabling System 1.0. NVD: Affected by this issue is some unknown functionality of the file /class.php. NVD: Such manipulation of the argument day leads to cross site scripting.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-16485/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-16486/",
      "current_public_safe_latest": false,
      "cvss_score": 2.1,
      "cvss_severity": "LOW",
      "epss_percentile": 0.19461,
      "epss_score": 0.00273,
      "first_observed_at": "2026-07-28T22:27:58.188634+00:00",
      "id": "CVE-2026-16486",
      "impact_tags": [
        "XSS risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-28T22:27:58.188634+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A vulnerability was found in SourceCodester Class and Exam Timetabling System 1.0. NVD: This affects an unknown part of the file /BSIS.php. NVD: Performing a manipulation of the argument day results in cross site scripting.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260728T223134Z/items/CVE-2026-16486.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes XSS risk. Possible impact: This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability was found in SourceCodester Class and Exam Timetabling System 1.0. NVD: This affects an unknown part of the file /BSIS.php. NVD: Performing a manipulation of the argument day results in cross site scripting.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-16486/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-16503/",
      "current_public_safe_latest": false,
      "cvss_score": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.15914,
      "epss_score": 0.00246,
      "first_observed_at": "2026-08-07T16:11:58.676122+00:00",
      "id": "CVE-2026-16503",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-07T16:11:58.676122+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Deployment of the VPS.org one-click Supabase template deploys a PostgreSQL instance that is published on all interfaces (0.0.0.0:5432) with a default database password set to \"postgres\". NVD: Because Docker installs its own iptables rules, this exposure bypasses a standard host UFW configuration.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260807T162046Z/items/CVE-2026-16503.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Deployment of the VPS.org one-click Supabase template deploys a PostgreSQL instance that is published on all interfaces (0.0.0.0:5432) with a default database password set to \"postgres\". NVD: Because Docker installs its own iptables rules, this exposure bypasses a standard host UFW configuration.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-16503/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-16504/",
      "current_public_safe_latest": false,
      "cvss_score": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.18741,
      "epss_score": 0.00268,
      "first_observed_at": "2026-08-07T16:11:58.676122+00:00",
      "id": "CVE-2026-16504",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-07T16:11:58.676122+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Deployment of the VPS.org one-click Zulip template deploys a hardcoded application signing key, a default database password (\"zulip\"), and DISABLE_HTTPS=True.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260807T162046Z/items/CVE-2026-16504.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Deployment of the VPS.org one-click Zulip template deploys a hardcoded application signing key, a default database password (\"zulip\"), and DISABLE_HTTPS=True.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-16504/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-16517/",
      "current_public_safe_latest": false,
      "cvss_score": 2.9,
      "cvss_severity": "LOW",
      "epss_percentile": 0.00175,
      "epss_score": 0.00078,
      "first_observed_at": "2026-07-28T22:27:58.188634+00:00",
      "id": "CVE-2026-16517",
      "impact_tags": [
        "memory safety review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-28T22:27:58.188634+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A signed integer overflow vulnerability was found in libarchive's ZIP writer. NVD: In the archive_write_zip_header function in archive_write_set_format_zip.c, when ZIP encryption is enabled and the entry file size is close to INT64_MAX, the addition of the encryption overhead to the entry size overflows int64_t, resulting in undefined... NVD: This could lead to incorrect Zip64 extension decisions or potential memory corruption.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260728T223134Z/items/CVE-2026-16517.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes memory safety review. Possible impact: The affected component has memory-safety risk that may lead to crash, privilege, or code-execution impact depending on exposure.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A signed integer overflow vulnerability was found in libarchive's ZIP writer. NVD: In the archive_write_zip_header function in archive_write_set_format_zip.c, when ZIP encryption is enabled and the entry file size is close to INT64_MAX, the addition of the encryption overhead to the entry size overflows int64_t, resulting in undefined... NVD: This could lead to incorrect Zip64 extension decisions or potential memory corruption.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-16517/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-16519/",
      "current_public_safe_latest": false,
      "cvss_score": 7.3,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.01976,
      "epss_score": 0.00118,
      "first_observed_at": "2026-07-31T06:26:41.124454+00:00",
      "id": "CVE-2026-16519",
      "impact_tags": [
        "local exposure relevant"
      ],
      "kev": false,
      "last_observed_at": "2026-07-31T06:26:41.124454+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A DLL hijacking vulnerability exists in the GeoVision GV-IP Device Utility desktop application. NVD: The application loads one or more dynamic-link libraries (DLLs) from an unsafe search path, allowing a local attacker to place a malicious DLL in a location searched before the legitimate library location.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260731T063057Z/items/CVE-2026-16519.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes local exposure. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for local exposure.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A DLL hijacking vulnerability exists in the GeoVision GV-IP Device Utility desktop application. NVD: The application loads one or more dynamic-link libraries (DLLs) from an unsafe search path, allowing a local attacker to place a malicious DLL in a location searched before the legitimate library location.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-16519/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-16544/",
      "current_public_safe_latest": false,
      "cvss_score": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.27299,
      "epss_score": 0.00347,
      "first_observed_at": "2026-07-29T06:10:00.110927+00:00",
      "id": "CVE-2026-16544",
      "impact_tags": [
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-29T11:36:18.065267+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A flaw was found in AWX. NVD: The websocket event consumer performs RBAC authorization checks only for event groups that are mapped in the consumer_access() function (job_events, workflow_events, ad_hoc_command_events). NVD: Three event groups - inventory_update_events, project_update_events, and system_job_events — are not mapped, causing the authorization check to be skipped.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260729T114432Z/items/CVE-2026-16544.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A flaw was found in AWX. NVD: The websocket event consumer performs RBAC authorization checks only for event groups that are mapped in the consumer_access() function (job_events, workflow_events, ad_hoc_command_events). NVD: Three event groups - inventory_update_events, project_update_events, and system_job_events — are not mapped, causing the authorization check to be skipped.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-16544/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-16551/",
      "current_public_safe_latest": false,
      "cvss_score": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.16801,
      "epss_score": 0.00253,
      "first_observed_at": "2026-07-29T06:10:00.110927+00:00",
      "id": "CVE-2026-16551",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-29T11:36:18.065267+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Denial-of-Service in Thinkst Applied Research OpenCanary (MongoDB module) allows Excessive Allocation. NVD: This issue affects OpenCanary 0.9.8 only. OSV: Denial-of-Service in OpenCanary's MongoDB module",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260729T114432Z/items/CVE-2026-16551.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Denial-of-Service in Thinkst Applied Research OpenCanary (MongoDB module) allows Excessive Allocation. NVD: This issue affects OpenCanary 0.9.8 only. OSV: Denial-of-Service in OpenCanary's MongoDB module",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-16551/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-16585/",
      "current_public_safe_latest": false,
      "cvss_score": 7.2,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.50842,
      "epss_score": 0.00734,
      "first_observed_at": "2026-08-04T06:07:04.591309+00:00",
      "id": "CVE-2026-16585",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-04T06:07:04.591309+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_sticker function in all versions up to, and including, 2.15.19. NVD: This makes it possible for authenticated attackers, with administrator-level access and above, to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php).",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260804T061658Z/items/CVE-2026-16585.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_sticker function in all versions up to, and including, 2.15.19. NVD: This makes it possible for authenticated attackers, with administrator-level access and above, to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php).",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-16585/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-16587/",
      "current_public_safe_latest": false,
      "cvss_score": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.12848,
      "epss_score": 0.00222,
      "first_observed_at": "2026-08-04T06:07:04.591309+00:00",
      "id": "CVE-2026-16587",
      "impact_tags": [
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-04T06:07:04.591309+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Advanced Form Integration — Connect Forms to 200+ Apps plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.6.0. NVD: This is due to the plugin not properly verifying that a user is authorized to perform an action. NVD: This makes it possible for authenticated attackers, with subscriber-level access and above, to overwrite the site's stored MailUp OAuth tokens in the adfoin_mailup_keys option with attacker-controlled tokens, hijacking future form-submission data to a MailUp...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260804T061658Z/items/CVE-2026-16587.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Advanced Form Integration — Connect Forms to 200+ Apps plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.6.0. NVD: This is due to the plugin not properly verifying that a user is authorized to perform an action. NVD: This makes it possible for authenticated attackers, with subscriber-level access and above, to overwrite the site's stored MailUp OAuth tokens in the adfoin_mailup_keys option with attacker-controlled tokens, hijacking future form-submission data to a MailUp...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-16587/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-16615/",
      "current_public_safe_latest": false,
      "cvss_score": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.16994,
      "epss_score": 0.00254,
      "first_observed_at": "2026-07-29T16:40:34.107276+00:00",
      "id": "CVE-2026-16615",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-29T16:40:34.107276+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A flaw was found in librest. NVD: The PKCE implementation for OAuth authorization uses the GRand function from the GLib API, a cryptographically insecure pseudo-random number generator. NVD: Because the generated \"code verifier\" lacks sufficient cryptographic entropy, a malicious actor can reverse-engineer the pseudo-random number generator (PRNG) seed to predict or reconstruct the code verifier string, allowing an attacker to bypass PKCE...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260729T164826Z/items/CVE-2026-16615.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A flaw was found in librest. NVD: The PKCE implementation for OAuth authorization uses the GRand function from the GLib API, a cryptographically insecure pseudo-random number generator. NVD: Because the generated \"code verifier\" lacks sufficient cryptographic entropy, a malicious actor can reverse-engineer the pseudo-random number generator (PRNG) seed to predict or reconstruct the code verifier string, allowing an attacker to bypass PKCE...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-16615/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-16624/",
      "current_public_safe_latest": false,
      "cvss_score": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.20357,
      "epss_score": 0.00281,
      "first_observed_at": "2026-07-29T16:40:34.107276+00:00",
      "id": "CVE-2026-16624",
      "impact_tags": [
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-29T16:40:34.107276+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Cal.com OSS ships lacks authorization on webhook teamId creation, allowing any authenticated user to create a webhook on any team via unvalidated teamId injection, then steal booking data, including fields like organizer/attendee emails and custom responses... OSV: CVE-2026-16624 OSV: Cal.com OSS ships lacks authorization on webhook teamId creation, allowing any authenticated user to create a webhook on any team via unvalidated teamId injection, then steal booking data, including fields like organizer/attendee emails and custom responses...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260729T164826Z/items/CVE-2026-16624.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes authenticated boundary. Possible impact: This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Cal.com OSS ships lacks authorization on webhook teamId creation, allowing any authenticated user to create a webhook on any team via unvalidated teamId injection, then steal booking data, including fields like organizer/attendee emails and custom responses... OSV: CVE-2026-16624 OSV: Cal.com OSS ships lacks authorization on webhook teamId creation, allowing any authenticated user to create a webhook on any team via unvalidated teamId injection, then steal booking data, including fields like organizer/attendee emails and custom responses...",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-16624/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-16628/",
      "current_public_safe_latest": false,
      "cvss_score": 1.9,
      "cvss_severity": "LOW",
      "epss_percentile": 0.46249,
      "epss_score": 0.00622,
      "first_observed_at": "2026-07-29T22:16:26.828679+00:00",
      "id": "CVE-2026-16628",
      "impact_tags": [
        "command injection risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-29T22:16:26.828679+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A vulnerability was detected in oclif up to 4.23.16. NVD: Affected by this vulnerability is the function child_process.exec of the component JIT Plugin Entry Handler. NVD: Performing a manipulation of the argument jitPlugins results in os command injection.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260729T222441Z/items/CVE-2026-16628.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes command injection risk. Possible impact: An attacker may be able to run unintended system commands through the affected component.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability was detected in oclif up to 4.23.16. NVD: Affected by this vulnerability is the function child_process.exec of the component JIT Plugin Entry Handler. NVD: Performing a manipulation of the argument jitPlugins results in os command injection.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-16628/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-16629/",
      "current_public_safe_latest": false,
      "cvss_score": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.46249,
      "epss_score": 0.00622,
      "first_observed_at": "2026-07-29T22:16:26.828679+00:00",
      "id": "CVE-2026-16629",
      "impact_tags": [
        "command injection risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-29T22:16:26.828679+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A vulnerability was identified in danger danger-js up to 13.0.7. NVD: Impacted is the function danger.git.diffForFile of the file source/platforms/git/localGetFileAtSHA.ts of the component CLI. NVD: Such manipulation of the argument File leads to os command injection.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260729T222441Z/items/CVE-2026-16629.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes command injection risk. Possible impact: An attacker may be able to run unintended system commands through the affected component.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability was identified in danger danger-js up to 13.0.7. NVD: Impacted is the function danger.git.diffForFile of the file source/platforms/git/localGetFileAtSHA.ts of the component CLI. NVD: Such manipulation of the argument File leads to os command injection.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-16629/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-16630/",
      "current_public_safe_latest": false,
      "cvss_score": 1.9,
      "cvss_severity": "LOW",
      "epss_percentile": 0.46817,
      "epss_score": 0.00635,
      "first_observed_at": "2026-07-29T22:16:26.828679+00:00",
      "id": "CVE-2026-16630",
      "impact_tags": [
        "command injection risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-29T22:16:26.828679+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A security vulnerability has been detected in syncfusion ej2-javascript-ui-controls up to 33.2.3. NVD: This affects the function child_process.exec of the file package.json. NVD: The manipulation leads to os command injection.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260729T222441Z/items/CVE-2026-16630.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes command injection risk. Possible impact: An attacker may be able to run unintended system commands through the affected component.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A security vulnerability has been detected in syncfusion ej2-javascript-ui-controls up to 33.2.3. NVD: This affects the function child_process.exec of the file package.json. NVD: The manipulation leads to os command injection.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-16630/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-16631/",
      "current_public_safe_latest": false,
      "cvss_score": 1.9,
      "cvss_severity": "LOW",
      "epss_percentile": 0.46812,
      "epss_score": 0.00635,
      "first_observed_at": "2026-07-29T22:16:26.828679+00:00",
      "id": "CVE-2026-16631",
      "impact_tags": [
        "command injection risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-29T22:16:26.828679+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A vulnerability was detected in publint up to 0.1.4. NVD: This impacts the function child_process.exec of the file src/node/pack.js of the component package-manager Command Handler. NVD: The manipulation results in os command injection.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260729T222441Z/items/CVE-2026-16631.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes command injection risk. Possible impact: An attacker may be able to run unintended system commands through the affected component.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability was detected in publint up to 0.1.4. NVD: This impacts the function child_process.exec of the file src/node/pack.js of the component package-manager Command Handler. NVD: The manipulation results in os command injection.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-16631/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-16632/",
      "current_public_safe_latest": false,
      "cvss_score": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.23402,
      "epss_score": 0.0031,
      "first_observed_at": "2026-07-29T22:16:26.828679+00:00",
      "id": "CVE-2026-16632",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-29T22:16:26.828679+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A flaw has been found in boazsegev facil.io up to 0.7.4. NVD: Affected is the function websocket_on_protocol_error in the library lib/facil/http/parsers/websocket_parser.h of the component WebSocket Frame Parser. NVD: This manipulation of the argument on_message causes improper input validation.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260729T222441Z/items/CVE-2026-16632.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A flaw has been found in boazsegev facil.io up to 0.7.4. NVD: Affected is the function websocket_on_protocol_error in the library lib/facil/http/parsers/websocket_parser.h of the component WebSocket Frame Parser. NVD: This manipulation of the argument on_message causes improper input validation.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-16632/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-16653/",
      "current_public_safe_latest": false,
      "cvss_score": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.38809,
      "epss_score": 0.0048,
      "first_observed_at": "2026-07-29T22:16:26.828679+00:00",
      "id": "CVE-2026-16653",
      "impact_tags": [
        "path traversal review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-29T22:16:26.828679+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A security flaw has been discovered in boazsegev facil.io up to 0.7.58. NVD: This affects the function http_sendfile2 of the file lib/facil/http/http.c of the component Public Folder Handler. NVD: Performing a manipulation results in path traversal.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260729T222441Z/items/CVE-2026-16653.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes path traversal review. Possible impact: An attacker may be able to reach files outside the intended application path.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A security flaw has been discovered in boazsegev facil.io up to 0.7.58. NVD: This affects the function http_sendfile2 of the file lib/facil/http/http.c of the component Public Folder Handler. NVD: Performing a manipulation results in path traversal.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-16653/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-1667/",
      "current_public_safe_latest": false,
      "cvss_score": 7.2,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.08364,
      "epss_score": 0.00186,
      "first_observed_at": "2026-07-17T16:36:32.072333+00:00",
      "id": "CVE-2026-1667",
      "impact_tags": [
        "XSS risk",
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-17T16:36:32.072333+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The SEO Plugin by Squirrly SEO plugin for WordPress is vulnerable to Arbitrary Post Creation and Stored Cross-Site Scripting in all versions up to, and including, 14.0.0 due to a leak of an API token and insufficient input sanitization and output escaping. NVD: This makes it possible for unauthenticated attackers to create arbitrary posts, and, if the Advanced Custom Fields plugin is installed and activated, inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260717T164048Z/items/CVE-2026-1667.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes XSS risk · remote exposure · authenticated boundary. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk · remote exposure · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The SEO Plugin by Squirrly SEO plugin for WordPress is vulnerable to Arbitrary Post Creation and Stored Cross-Site Scripting in all versions up to, and including, 14.0.0 due to a leak of an API token and insufficient input sanitization and output escaping. NVD: This makes it possible for unauthenticated attackers to create arbitrary posts, and, if the Advanced Custom Fields plugin is installed and activated, inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-1667/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-16723/",
      "current_public_safe_latest": false,
      "cvss_score": 9.0,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.33949,
      "epss_score": 0.00413,
      "first_observed_at": "2026-07-30T06:01:44.452906+00:00",
      "id": "CVE-2026-16723",
      "impact_tags": [
        "code execution review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-30T06:01:44.452906+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A remote code execution (RCE) vulnerability exists in fastjson 1.2.68 through 1.2.83. NVD: This vulnerability is exploitable under fastjson's stock default configuration — no AutoType enablement required, no classpath gadget required.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260730T060504Z/items/CVE-2026-16723.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes code execution review. Possible impact: An attacker may be able to run code or commands on affected systems.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A remote code execution (RCE) vulnerability exists in fastjson 1.2.68 through 1.2.83. NVD: This vulnerability is exploitable under fastjson's stock default configuration — no AutoType enablement required, no classpath gadget required.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-16723/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "nodejs / undici",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-16729/",
      "current_public_safe_latest": false,
      "cvss_score": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.07351,
      "epss_score": 0.00176,
      "first_observed_at": "2026-08-05T16:55:08.588478+00:00",
      "id": "CVE-2026-16729",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-05T16:55:08.588478+00:00",
      "latest_item_url": null,
      "product": "undici",
      "public_safe_summary": "NVD: undici's setCookie function does not fully sanitize cookie attributes. NVD: In undici before 6.28.0, from 7.0.0 up to before 7.29.0, and from 8.0.0 up to before 8.9.0, a domain value is not checked for semicolons and entries in the unparsed array are not sanitized, so attacker-influenced input can inject additional cookie attributes. NVD: For example, a domain value containing a semicolon can append attributes such as SameSite, and an unparsed entry can inject attributes such as HttpOnly, without the caller setting them.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260805T165944Z/items/CVE-2026-16729.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: nodejs / undici",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: undici.",
      "source_published_summary": "NVD: undici's setCookie function does not fully sanitize cookie attributes. NVD: In undici before 6.28.0, from 7.0.0 up to before 7.29.0, and from 8.0.0 up to before 8.9.0, a domain value is not checked for semicolons and entries in the unparsed array are not sanitized, so attacker-influenced input can inject additional cookie attributes. NVD: For example, a domain value containing a semicolon can append attributes such as SameSite, and an unparsed entry can inject attributes such as HttpOnly, without the caller setting them.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-16729/timeline.json",
      "vendor": "nodejs"
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-16730/",
      "current_public_safe_latest": false,
      "cvss_score": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.01328,
      "epss_score": 0.00107,
      "first_observed_at": "2026-07-31T11:36:05.167842+00:00",
      "id": "CVE-2026-16730",
      "impact_tags": [
        "local exposure relevant"
      ],
      "kev": false,
      "last_observed_at": "2026-07-31T11:36:05.167842+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A flaw was found in dbus-broker. NVD: When the process file-descriptor limit is reached, EMFILE/ENFILE errors during peer setup (notably SO_PEERPIDFD) are handled as fatal failures, causing the broker to exit. NVD: A local attacker who can open many connections to the user session bus can trigger this and deny service to the desktop session.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260731T115001Z/items/CVE-2026-16730.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes local exposure. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for local exposure.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A flaw was found in dbus-broker. NVD: When the process file-descriptor limit is reached, EMFILE/ENFILE errors during peer setup (notably SO_PEERPIDFD) are handled as fatal failures, causing the broker to exit. NVD: A local attacker who can open many connections to the user session bus can trigger this and deny service to the desktop session.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-16730/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-16743/",
      "current_public_safe_latest": false,
      "cvss_score": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.00936,
      "epss_score": 0.00099,
      "first_observed_at": "2026-07-31T11:36:05.167842+00:00",
      "id": "CVE-2026-16743",
      "impact_tags": [
        "admin privilege risk",
        "local exposure relevant"
      ],
      "kev": false,
      "last_observed_at": "2026-07-31T11:36:05.167842+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A flaw was found in accountsservice. NVD: The systemd-homed code path for SetIconFile opens a user-supplied filename as root without the validation and privilege drop performed by the classic handler. NVD: A local attacker with a systemd-homed-managed account can read arbitrary files accessible to the accounts-daemon process.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260731T115001Z/items/CVE-2026-16743.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes admin privilege risk · local exposure. Possible impact: A local user may gain root or administrative-level privileges on affected systems.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A flaw was found in accountsservice. NVD: The systemd-homed code path for SetIconFile opens a user-supplied filename as root without the validation and privilege drop performed by the classic handler. NVD: A local attacker with a systemd-homed-managed account can read arbitrary files accessible to the accounts-daemon process.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-16743/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-16751/",
      "current_public_safe_latest": false,
      "cvss_score": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.21758,
      "epss_score": 0.00295,
      "first_observed_at": "2026-08-05T11:32:09.387600+00:00",
      "id": "CVE-2026-16751",
      "impact_tags": [
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-05T11:32:09.387600+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Authorization Bypass in the emergency recovery approval component in Ente Technologies Ente Museum Server allows an authenticated attacker configured as a victim's emergency contact to bypass the configured recovery waiting period and take over the victim's...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260805T113552Z/items/CVE-2026-16751.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Authorization Bypass in the emergency recovery approval component in Ente Technologies Ente Museum Server allows an authenticated attacker configured as a victim's emergency contact to bypass the configured recovery waiting period and take over the victim's...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-16751/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-16766/",
      "current_public_safe_latest": false,
      "cvss_score": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.6768,
      "epss_score": 0.01304,
      "first_observed_at": "2026-07-31T22:17:39.455090+00:00",
      "id": "CVE-2026-16766",
      "impact_tags": [
        "code execution review",
        "command injection risk"
      ],
      "kev": false,
      "last_observed_at": "2026-08-01T06:11:07.668739+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Catalyst::View::Wkhtmltopdf versions before 0.6.1 for Perl allow shell command injection (RCE) via PDF render options. NVD: Options are passed directly to the wkhtmltopdf command without sanitization. NVD: Any web application that passes user-controlled options such as the page_size, orientation or margins without validation allows shell command injection.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260801T061801Z/items/CVE-2026-16766.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes code execution review · command injection risk. Possible impact: An attacker may be able to run code or commands on affected systems.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Catalyst::View::Wkhtmltopdf versions before 0.6.1 for Perl allow shell command injection (RCE) via PDF render options. NVD: Options are passed directly to the wkhtmltopdf command without sanitization. NVD: Any web application that passes user-controlled options such as the page_size, orientation or margins without validation allows shell command injection.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-16766/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-16767/",
      "current_public_safe_latest": false,
      "cvss_score": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.38805,
      "epss_score": 0.00479,
      "first_observed_at": "2026-07-30T22:30:38.166118+00:00",
      "id": "CVE-2026-16767",
      "impact_tags": [
        "path traversal review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-30T22:30:38.166118+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A vulnerability was detected in Ne-Lexa php-zip up to 4.0.2. NVD: This affects the function ZipFile::extractTo of the file src/ZipFile.php of the component ZIP Handler. NVD: Performing a manipulation of the argument entryName results in path traversal.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260730T224832Z/items/CVE-2026-16767.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes path traversal review. Possible impact: An attacker may be able to reach files outside the intended application path.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability was detected in Ne-Lexa php-zip up to 4.0.2. NVD: This affects the function ZipFile::extractTo of the file src/ZipFile.php of the component ZIP Handler. NVD: Performing a manipulation of the argument entryName results in path traversal.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-16767/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-16773/",
      "current_public_safe_latest": false,
      "cvss_score": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.19548,
      "epss_score": 0.00273,
      "first_observed_at": "2026-08-04T11:35:47.800052+00:00",
      "id": "CVE-2026-16773",
      "impact_tags": [
        "information exposure review",
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-04T11:35:47.800052+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The WPBot – AI ChatBot for Live Support, Lead Generation, AI Services plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 8.5.9 via the wpbot_send_email_transcript_free. NVD: This makes it possible for unauthenticated attackers to exfiltrate full chat transcripts and associated user PII — including names, email addresses, and phone numbers — stored in the wpbot_user and wpbot_conversation tables to an attacker-controlled email...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260804T114328Z/items/CVE-2026-16773.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes information exposure review · remote exposure · authenticated boundary. Possible impact: A remote attacker may be able to access information that should not be exposed.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The WPBot – AI ChatBot for Live Support, Lead Generation, AI Services plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 8.5.9 via the wpbot_send_email_transcript_free. NVD: This makes it possible for unauthenticated attackers to exfiltrate full chat transcripts and associated user PII — including names, email addresses, and phone numbers — stored in the wpbot_user and wpbot_conversation tables to an attacker-controlled email...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-16773/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-16774/",
      "current_public_safe_latest": false,
      "cvss_score": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.14539,
      "epss_score": 0.00235,
      "first_observed_at": "2026-08-04T11:35:47.800052+00:00",
      "id": "CVE-2026-16774",
      "impact_tags": [
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-04T11:35:47.800052+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Chatbot plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 8.5.9 via the wpcs_send_email() AJAX handler. NVD: This is due to the wpcs_send_email() function being registered on both wp_ajax_wpcs_send_email and wp_ajax_nopriv_wpcs_send_email with no nonce verification, capability check, or rate limiting, while forwarding attacker-controlled recipient, subject, and body... NVD: This makes it possible for unauthenticated attackers to send arbitrary emails to any recipient from the site's domain, enabling spam, phishing, and abuse that can lead to the site's IP/domain being blacklisted.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260804T114328Z/items/CVE-2026-16774.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes remote exposure · authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Chatbot plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 8.5.9 via the wpcs_send_email() AJAX handler. NVD: This is due to the wpcs_send_email() function being registered on both wp_ajax_wpcs_send_email and wp_ajax_nopriv_wpcs_send_email with no nonce verification, capability check, or rate limiting, while forwarding attacker-controlled recipient, subject, and body... NVD: This makes it possible for unauthenticated attackers to send arbitrary emails to any recipient from the site's domain, enabling spam, phishing, and abuse that can lead to the site's IP/domain being blacklisted.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-16774/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-16797/",
      "current_public_safe_latest": false,
      "cvss_score": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.12344,
      "epss_score": 0.00218,
      "first_observed_at": "2026-08-04T06:07:04.591309+00:00",
      "id": "CVE-2026-16797",
      "impact_tags": [
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-04T06:07:04.591309+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.4.5 via the 'optionSection' parameter due to missing validation on a user... NVD: This makes it possible for authenticated attackers, with contributor-level access and above, to read arbitrary wp_options rows — including internal plugin news feed data, WooCommerce block pattern transients, and third-party configuration records — whose...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260804T061658Z/items/CVE-2026-16797.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.4.5 via the 'optionSection' parameter due to missing validation on a user... NVD: This makes it possible for authenticated attackers, with contributor-level access and above, to read arbitrary wp_options rows — including internal plugin news feed data, WooCommerce block pattern transients, and third-party configuration records — whose...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-16797/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-16811/",
      "current_public_safe_latest": false,
      "cvss_score": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.1869,
      "epss_score": 0.00266,
      "first_observed_at": "2026-08-04T06:07:04.591309+00:00",
      "id": "CVE-2026-16811",
      "impact_tags": [
        "information exposure review",
        "SQL injection risk",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-04T06:07:04.591309+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin plugin for WordPress is vulnerable to time-based SQL Injection via the 'orderby' parameter in all versions up to, and including, 3.4.5 due to insufficient escaping on the user supplied... NVD: This makes it possible for authenticated attackers, with administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260804T061658Z/items/CVE-2026-16811.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes information exposure review · SQL injection risk · authenticated boundary. Possible impact: An attacker may be able to read or change database-backed application data.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin plugin for WordPress is vulnerable to time-based SQL Injection via the 'orderby' parameter in all versions up to, and including, 3.4.5 due to insufficient escaping on the user supplied... NVD: This makes it possible for authenticated attackers, with administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-16811/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-16843/",
      "current_public_safe_latest": false,
      "cvss_score": 7.2,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.55986,
      "epss_score": 0.00891,
      "first_observed_at": "2026-08-07T10:13:53.604723+00:00",
      "id": "CVE-2026-16843",
      "impact_tags": [
        "command execution review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-07T10:13:53.604723+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Some Hikvision Networking Products are vulnerable to authenticated command execution due to insufficient input validation. NVD: Attackers with valid credentials can exploit this flaw by sending crafted packets containing malicious commands to affected devices, leading to arbitrary command execution.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260807T102646Z/items/CVE-2026-16843.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes command execution risk. Possible impact: An attacker may be able to run code or commands on affected systems.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Some Hikvision Networking Products are vulnerable to authenticated command execution due to insufficient input validation. NVD: Attackers with valid credentials can exploit this flaw by sending crafted packets containing malicious commands to affected devices, leading to arbitrary command execution.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-16843/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-16881/",
      "current_public_safe_latest": false,
      "cvss_score": 8.7,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.17818,
      "epss_score": 0.00262,
      "first_observed_at": "2026-08-11T04:43:10.985977+00:00",
      "id": "CVE-2026-16881",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-11T04:43:10.985977+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A code injection vulnerability exists in the LINE Android app prior to version 26.7.2. NVD: The profile rendering component does not adequately validate or sandbox externally supplied script content embedded in profile templates. NVD: As a result, an attacker who is able to place crafted content in a profile could cause unintended code to execute with the application's privileges when a victim views that profile.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260811T044729Z/items/CVE-2026-16881.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A code injection vulnerability exists in the LINE Android app prior to version 26.7.2. NVD: The profile rendering component does not adequately validate or sandbox externally supplied script content embedded in profile templates. NVD: As a result, an attacker who is able to place crafted content in a profile could cause unintended code to execute with the application's privileges when a victim views that profile.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-16881/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-16910/",
      "current_public_safe_latest": false,
      "cvss_score": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.11803,
      "epss_score": 0.00213,
      "first_observed_at": "2026-07-31T06:26:41.124454+00:00",
      "id": "CVE-2026-16910",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-31T06:26:41.124454+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A flaw was found in Red Hat Quay's notification webhook feature. NVD: The Slack and generic webhook notification handlers accept user-supplied URLs without SSRF validation, allowing a repository administrator to make the Quay worker issue POST requests to internal network addresses or cloud infrastructure endpoints that should...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260731T063057Z/items/CVE-2026-16910.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A flaw was found in Red Hat Quay's notification webhook feature. NVD: The Slack and generic webhook notification handlers accept user-supplied URLs without SSRF validation, allowing a repository administrator to make the Quay worker issue POST requests to internal network addresses or cloud infrastructure endpoints that should...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-16910/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-17048/",
      "current_public_safe_latest": false,
      "cvss_score": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.11009,
      "epss_score": 0.00207,
      "first_observed_at": "2026-07-31T11:36:05.167842+00:00",
      "id": "CVE-2026-17048",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-31T11:36:05.167842+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A flaw was found in the Keycloak Admin REST API, which is used to manage security realms and clients. NVD: The issue occurs when the system processes requests for rotated client secrets that are stored in a secure vault. NVD: Due to improper boundary enforcement, a delegated administrator with view-only permissions can retrieve the actual resolved secret instead of the vault placeholder, leading to the exposure of sensitive credentials.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260731T115001Z/items/CVE-2026-17048.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A flaw was found in the Keycloak Admin REST API, which is used to manage security realms and clients. NVD: The issue occurs when the system processes requests for rotated client secrets that are stored in a secure vault. NVD: Due to improper boundary enforcement, a delegated administrator with view-only permissions can retrieve the actual resolved secret instead of the vault placeholder, leading to the exposure of sensitive credentials.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-17048/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-17107/",
      "current_public_safe_latest": false,
      "cvss_score": 8.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.27291,
      "epss_score": 0.00346,
      "first_observed_at": "2026-07-31T16:59:34.622526+00:00",
      "id": "CVE-2026-17107",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-31T16:59:34.622526+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A flaw was found in the cluster-proxy service-proxy component used in Red Hat Advanced Cluster Management for Kubernetes (RHACM) and multicluster-engine (MCE). NVD: The service-proxy appends impersonation group headers to proxied requests without first removing caller-supplied values, and the spoke ServiceAccount holds unrestricted impersonation permissions. NVD: An authenticated hub principal can inject an Impersonate-Group header to escalate to cluster-admin on every managed cluster.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260731T171256Z/items/CVE-2026-17107.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A flaw was found in the cluster-proxy service-proxy component used in Red Hat Advanced Cluster Management for Kubernetes (RHACM) and multicluster-engine (MCE). NVD: The service-proxy appends impersonation group headers to proxied requests without first removing caller-supplied values, and the spoke ServiceAccount holds unrestricted impersonation permissions. NVD: An authenticated hub principal can inject an Impersonate-Group header to escalate to cluster-admin on every managed cluster.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-17107/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-17161/",
      "current_public_safe_latest": false,
      "cvss_score": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.09238,
      "epss_score": 0.00193,
      "first_observed_at": "2026-08-04T22:31:51.932237+00:00",
      "id": "CVE-2026-17161",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-04T22:31:51.932237+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The WowStore – Store Builder & Product Blocks for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'filterMobileText' Block Attribute in all versions up to, and including, 4.4.24 due to insufficient input sanitization and... NVD: This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260804T223546Z/items/CVE-2026-17161.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The WowStore – Store Builder & Product Blocks for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'filterMobileText' Block Attribute in all versions up to, and including, 4.4.24 due to insufficient input sanitization and... NVD: This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-17161/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-17162/",
      "current_public_safe_latest": false,
      "cvss_score": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.09238,
      "epss_score": 0.00193,
      "first_observed_at": "2026-08-04T22:31:51.932237+00:00",
      "id": "CVE-2026-17162",
      "impact_tags": [
        "XSS risk",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-04T22:31:51.932237+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The WowStore – Store Builder & Product Blocks for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'currentPostId' Block Attribute in all versions up to, and including, 4.4.24 due to insufficient input sanitization and output... NVD: This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260804T223546Z/items/CVE-2026-17162.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes XSS risk · authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The WowStore – Store Builder & Product Blocks for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'currentPostId' Block Attribute in all versions up to, and including, 4.4.24 due to insufficient input sanitization and output... NVD: This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-17162/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-17166/",
      "current_public_safe_latest": false,
      "cvss_score": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.14173,
      "epss_score": 0.00232,
      "first_observed_at": "2026-08-04T22:31:51.932237+00:00",
      "id": "CVE-2026-17166",
      "impact_tags": [
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-04T22:31:51.932237+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Event Booking Manager for WooCommerce – Sell Tickets, Event Registration, RSVP & Event Calendar plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.3.7. NVD: This is due to the plugin not properly verifying that a user is authorized to perform an action. NVD: This makes it possible for authenticated attackers, with contributor-level access and above, to modify site-wide payment settings — including WooCommerce payment enablement, cart redirect behavior, login requirements for checkout, confirmation page ID, and...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260804T223546Z/items/CVE-2026-17166.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Event Booking Manager for WooCommerce – Sell Tickets, Event Registration, RSVP & Event Calendar plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.3.7. NVD: This is due to the plugin not properly verifying that a user is authorized to perform an action. NVD: This makes it possible for authenticated attackers, with contributor-level access and above, to modify site-wide payment settings — including WooCommerce payment enablement, cart redirect behavior, login requirements for checkout, confirmation page ID, and...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-17166/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "pgadmin / pgadmin_4",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-17346/",
      "current_public_safe_latest": false,
      "cvss_score": 8.7,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.3499,
      "epss_score": 0.00424,
      "first_observed_at": "2026-08-07T16:11:58.676122+00:00",
      "id": "CVE-2026-17346",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-07T16:11:58.676122+00:00",
      "latest_item_url": null,
      "product": "pgadmin_4",
      "public_safe_summary": "NVD: The fix for CVE-2026-12044 in pgAdmin 4 9.16 hardened qtLiteral and switched sixteen COMMENT ON / pgstattuple / pgstatindex templates to it, but missed several sinks that had been placed in test_sql_string_literal_lint.py's ALLOWLIST on the incorrect... NVD: PostgreSQL permits arbitrary characters in quoted identifiers, so a low-privileged user able to CREATE TABLE, CREATE PUBLICATION, or CREATE SUBSCRIPTION can plant an apostrophe'd object name that breaks out of the unescaped '{{ name }}' template interpolation... NVD: Affected sinks: the Index Statistics query for all-indexes listing (coll_stats.sql, both the 16_plus and default PostgreSQL-version template variants -- distinct from the single-index stats.sql path already fixed in CVE-2026-12044), and the publication and...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260807T162046Z/items/CVE-2026-17346.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: pgadmin / pgadmin_4",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: CVE-2026-12044.",
      "source_published_summary": "NVD: The fix for CVE-2026-12044 in pgAdmin 4 9.16 hardened qtLiteral and switched sixteen COMMENT ON / pgstattuple / pgstatindex templates to it, but missed several sinks that had been placed in test_sql_string_literal_lint.py's ALLOWLIST on the incorrect... NVD: PostgreSQL permits arbitrary characters in quoted identifiers, so a low-privileged user able to CREATE TABLE, CREATE PUBLICATION, or CREATE SUBSCRIPTION can plant an apostrophe'd object name that breaks out of the unescaped '{{ name }}' template interpolation... NVD: Affected sinks: the Index Statistics query for all-indexes listing (coll_stats.sql, both the 16_plus and default PostgreSQL-version template variants -- distinct from the single-index stats.sql path already fixed in CVE-2026-12044), and the publication and...",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-17346/timeline.json",
      "vendor": "pgadmin"
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-17347/",
      "current_public_safe_latest": false,
      "cvss_score": 7.7,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.18648,
      "epss_score": 0.00267,
      "first_observed_at": "2026-08-07T16:11:58.676122+00:00",
      "id": "CVE-2026-17347",
      "impact_tags": [
        "command injection risk",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-07T16:11:58.676122+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The MASTER_PASSWORD_HOOK setting, introduced in pgAdmin 4 7.2, lets an administrator configure an external command that returns a per-user encryption key, with %u in the configured string replaced by the current user's name. NVD: The previous implementation substituted the username directly into the command string and executed the result with subprocess.Popen(..., shell=True). NVD: Because the username can originate from an external authentication source (OAuth/OIDC claims, Kerberos, webserver auth) rather than a value pgAdmin fully controls, a username containing shell metacharacters (';', '$()', backticks, pipes, '&&', newlines)...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260807T162046Z/items/CVE-2026-17347.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes command injection risk · authenticated boundary. Possible impact: An attacker may be able to run unintended system commands through the affected component.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The MASTER_PASSWORD_HOOK setting, introduced in pgAdmin 4 7.2, lets an administrator configure an external command that returns a per-user encryption key, with %u in the configured string replaced by the current user's name. NVD: The previous implementation substituted the username directly into the command string and executed the result with subprocess.Popen(..., shell=True). NVD: Because the username can originate from an external authentication source (OAuth/OIDC claims, Kerberos, webserver auth) rather than a value pgAdmin fully controls, a username containing shell metacharacters (';', '$()', backticks, pipes, '&&', newlines)...",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-17347/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "pgadmin / pgadmin_4",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-17348/",
      "current_public_safe_latest": false,
      "cvss_score": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.14895,
      "epss_score": 0.00238,
      "first_observed_at": "2026-08-07T16:11:58.676122+00:00",
      "id": "CVE-2026-17348",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-07T16:11:58.676122+00:00",
      "latest_item_url": null,
      "product": "pgadmin_4",
      "public_safe_summary": "NVD: In SERVER mode, pgAdmin 4 enforces authentication per route via the @pga_login_required decorator; the application's before_request hook only handles desktop-mode auto-login and the Kerberos/Webserver-auth redirect, so any route shipped without the decorator... NVD: This is the same defect class previously fixed as CVE-2026-12046 (the sqleditor close/update_connection routes). NVD: A follow-up sweep, prompted by a report describing an incomplete fix for CVE-2026-12046, found further routes missing @pga_login_required: the Constraints blueprint's nodes and proplist (object listing) routes and its delete route (a state-mutating DELETE...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260807T162046Z/items/CVE-2026-17348.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: pgadmin / pgadmin_4",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: In SERVER mode, pgAdmin 4 enforces authentication per route via the @pga_login_required decorator; the application's before_request hook only handles desktop-mode auto-login and the Kerberos/Webserver-auth redirect, so any route shipped without the decorator... NVD: This is the same defect class previously fixed as CVE-2026-12046 (the sqleditor close/update_connection routes). NVD: A follow-up sweep, prompted by a report describing an incomplete fix for CVE-2026-12046, found further routes missing @pga_login_required: the Constraints blueprint's nodes and proplist (object listing) routes and its delete route (a state-mutating DELETE...",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-17348/timeline.json",
      "vendor": "pgadmin"
    },
    {
      "affected_label": "pgadmin / pgadmin_4",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-17349/",
      "current_public_safe_latest": false,
      "cvss_score": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.20946,
      "epss_score": 0.00288,
      "first_observed_at": "2026-08-07T16:11:58.676122+00:00",
      "id": "CVE-2026-17349",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-07T16:11:58.676122+00:00",
      "latest_item_url": null,
      "product": "pgadmin_4",
      "public_safe_summary": "NVD: /misc/workspace/adhoc_connect_server, part of the Workspaces feature introduced in pgAdmin 4 9.0, when passed the id of an existing server, clones that server via Server.clone(), which copies every column from the source row, including user_id, shared... NVD: When a non-owner triggered an adhoc connect against another user's (in practice, typically an administrator's) shared server, the clone inherited that user's ownership, shared flag, and stored database credentials verbatim. NVD: pgAdmin persisted this cross-tenant, credential-bearing server row before the connection was even attempted, so it survived even when the connection subsequently failed.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260807T162046Z/items/CVE-2026-17349.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: pgadmin / pgadmin_4",
      "source_published_impact": "This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: /misc/workspace/adhoc_connect_server, part of the Workspaces feature introduced in pgAdmin 4 9.0, when passed the id of an existing server, clones that server via Server.clone(), which copies every column from the source row, including user_id, shared... NVD: When a non-owner triggered an adhoc connect against another user's (in practice, typically an administrator's) shared server, the clone inherited that user's ownership, shared flag, and stored database credentials verbatim. NVD: pgAdmin persisted this cross-tenant, credential-bearing server row before the connection was even attempted, so it survived even when the connection subsequently failed.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-17349/timeline.json",
      "vendor": "pgadmin"
    },
    {
      "affected_label": "pgadmin / pgadmin_4",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-17350/",
      "current_public_safe_latest": false,
      "cvss_score": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.12088,
      "epss_score": 0.00216,
      "first_observed_at": "2026-08-07T16:11:58.676122+00:00",
      "id": "CVE-2026-17350",
      "impact_tags": [
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-07T16:11:58.676122+00:00",
      "latest_item_url": null,
      "product": "pgadmin_4",
      "public_safe_summary": "NVD: The per-tool permission system (custom roles / role-based tool permissions, introduced in pgAdmin 4 9.3) did not enforce its permission check consistently. NVD: In SERVER mode, pgAdmin 4 gates each tool behind a per-tool Flask-Security permission, but the permission decorator (permissions_required) was applied only to a single \"front door\" route per tool. NVD: Every other backend route and Socket.IO handler in that tool's workflow relied solely on pga_login_required/socket_login_required, which check authentication but not the tool permission.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260807T162046Z/items/CVE-2026-17350.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: pgadmin / pgadmin_4",
      "source_published_impact": "Source describes authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The per-tool permission system (custom roles / role-based tool permissions, introduced in pgAdmin 4 9.3) did not enforce its permission check consistently. NVD: In SERVER mode, pgAdmin 4 gates each tool behind a per-tool Flask-Security permission, but the permission decorator (permissions_required) was applied only to a single \"front door\" route per tool. NVD: Every other backend route and Socket.IO handler in that tool's workflow relied solely on pga_login_required/socket_login_required, which check authentication but not the tool permission.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-17350/timeline.json",
      "vendor": "pgadmin"
    },
    {
      "affected_label": "pgadmin / pgadmin_4",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-17351/",
      "current_public_safe_latest": false,
      "cvss_score": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.30896,
      "epss_score": 0.00381,
      "first_observed_at": "2026-08-07T16:11:58.676122+00:00",
      "id": "CVE-2026-17351",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-07T16:11:58.676122+00:00",
      "latest_item_url": null,
      "product": "pgadmin_4",
      "public_safe_summary": "NVD: The fix for CVE-2026-12045 in pgAdmin 4 9.16 required the LLM-supplied query passed to the AI Assistant's execute_sql_query tool to parse, via sqlparse, as exactly one non-transaction-control statement before running it inside a BEGIN TRANSACTION READ ONLY... NVD: sqlparse's string-literal lexing can disagree with PostgreSQL's own parser: under standard_conforming_strings = on (PostgreSQL's default since 9.1), a backslash immediately before a quote is an ordinary character to PostgreSQL, but sqlparse treats it as... NVD: An initial candidate fix ran the query with psycopg's execute(..., prepare=True), intending to force PostgreSQL's own Parse step (extended query protocol) to reject multi-statement text regardless of sqlparse's classification.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260807T162046Z/items/CVE-2026-17351.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: pgadmin / pgadmin_4",
      "source_published_impact": "This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The fix for CVE-2026-12045 in pgAdmin 4 9.16 required the LLM-supplied query passed to the AI Assistant's execute_sql_query tool to parse, via sqlparse, as exactly one non-transaction-control statement before running it inside a BEGIN TRANSACTION READ ONLY... NVD: sqlparse's string-literal lexing can disagree with PostgreSQL's own parser: under standard_conforming_strings = on (PostgreSQL's default since 9.1), a backslash immediately before a quote is an ordinary character to PostgreSQL, but sqlparse treats it as... NVD: An initial candidate fix ran the query with psycopg's execute(..., prepare=True), intending to force PostgreSQL's own Parse step (extended query protocol) to reject multi-statement text regardless of sqlparse's classification.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-17351/timeline.json",
      "vendor": "pgadmin"
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-17432/",
      "current_public_safe_latest": false,
      "cvss_score": 1.3,
      "cvss_severity": "LOW",
      "epss_percentile": 0.13988,
      "epss_score": 0.0023,
      "first_observed_at": "2026-08-01T10:51:40.555213+00:00",
      "id": "CVE-2026-17432",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-01T22:14:19.808804+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A vulnerability was detected in NousResearch hermes-agent 2026.6.5. NVD: Affected by this vulnerability is an unknown functionality of the file hermes-agent/plugins/platforms/simplex/adapter.py of the component SimpleX Gateway Authorization. NVD: The manipulation of the argument contactId results in improper access controls.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260801T221753Z/items/CVE-2026-17432.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 3,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability was detected in NousResearch hermes-agent 2026.6.5. NVD: Affected by this vulnerability is an unknown functionality of the file hermes-agent/plugins/platforms/simplex/adapter.py of the component SimpleX Gateway Authorization. NVD: The manipulation of the argument contactId results in improper access controls.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-17432/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-17433/",
      "current_public_safe_latest": false,
      "cvss_score": 1.9,
      "cvss_severity": "LOW",
      "epss_percentile": 0.01169,
      "epss_score": 0.00103,
      "first_observed_at": "2026-08-01T10:51:40.555213+00:00",
      "id": "CVE-2026-17433",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-01T22:14:19.808804+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A vulnerability was detected in nanocoai NanoClaw up to 2.0.64. NVD: This impacts the function createChatSdkBridge.setup of the file src/channels/chat-sdk-bridge.ts of the component MCP Server Approval. NVD: Performing a manipulation results in improper authorization.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260801T221753Z/items/CVE-2026-17433.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 3,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability was detected in nanocoai NanoClaw up to 2.0.64. NVD: This impacts the function createChatSdkBridge.setup of the file src/channels/chat-sdk-bridge.ts of the component MCP Server Approval. NVD: Performing a manipulation results in improper authorization.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-17433/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-17434/",
      "current_public_safe_latest": false,
      "cvss_score": 2.1,
      "cvss_severity": "LOW",
      "epss_percentile": 0.11946,
      "epss_score": 0.00214,
      "first_observed_at": "2026-08-01T10:51:40.555213+00:00",
      "id": "CVE-2026-17434",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-01T22:14:19.808804+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A flaw has been found in nanocoai NanoClaw up to 2.0.64. NVD: Affected is the function handleAddMcpServer of the file src/modules/self-mod/request.ts of the component add_mcp_server. NVD: Executing a manipulation can lead to improper authorization.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260801T221753Z/items/CVE-2026-17434.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 3,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A flaw has been found in nanocoai NanoClaw up to 2.0.64. NVD: Affected is the function handleAddMcpServer of the file src/modules/self-mod/request.ts of the component add_mcp_server. NVD: Executing a manipulation can lead to improper authorization.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-17434/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-17457/",
      "current_public_safe_latest": false,
      "cvss_score": 2.1,
      "cvss_severity": "LOW",
      "epss_percentile": 0.23954,
      "epss_score": 0.00315,
      "first_observed_at": "2026-08-01T10:51:40.555213+00:00",
      "id": "CVE-2026-17457",
      "impact_tags": [
        "information exposure review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-02T06:14:57.521051+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A vulnerability has been found in mf-yang openclaw-cn up to 0.2.1. NVD: Affected by this issue is the function assertBrowserNavigationAllowed of the file src/browser/navigation-guard.ts of the component Scheme Handler. NVD: Such manipulation of the argument url leads to information disclosure.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260802T061806Z/items/CVE-2026-17457.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 4,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes information exposure review. Possible impact: An attacker may be able to access information that should not be exposed.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability has been found in mf-yang openclaw-cn up to 0.2.1. NVD: Affected by this issue is the function assertBrowserNavigationAllowed of the file src/browser/navigation-guard.ts of the component Scheme Handler. NVD: Such manipulation of the argument url leads to information disclosure.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-17457/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-17458/",
      "current_public_safe_latest": false,
      "cvss_score": 2.1,
      "cvss_severity": "LOW",
      "epss_percentile": 0.13679,
      "epss_score": 0.00228,
      "first_observed_at": "2026-08-01T10:51:40.555213+00:00",
      "id": "CVE-2026-17458",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-02T10:52:32.597181+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A vulnerability was found in mf-yang openclaw-cn up to 0.2.1. NVD: This affects the function clickViaPlaywright of the file src/browser/routes/agent.act.ts of the component Browser Control HTTP API. NVD: Performing a manipulation results in server-side request forgery.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260802T110240Z/items/CVE-2026-17458.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 5,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability was found in mf-yang openclaw-cn up to 0.2.1. NVD: This affects the function clickViaPlaywright of the file src/browser/routes/agent.act.ts of the component Browser Control HTTP API. NVD: Performing a manipulation results in server-side request forgery.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-17458/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-17459/",
      "current_public_safe_latest": false,
      "cvss_score": 2.1,
      "cvss_severity": "LOW",
      "epss_percentile": 0.24335,
      "epss_score": 0.00319,
      "first_observed_at": "2026-08-01T10:51:40.555213+00:00",
      "id": "CVE-2026-17459",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-02T10:52:32.597181+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A vulnerability was determined in perwendel spark up to 2.9.4. NVD: This vulnerability affects the function staticFiles.externalLocation of the file src/main/java/spark/resource/ExternalResourceHandler.jav of the component SparkJava. NVD: Executing a manipulation can lead to symlink following.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260802T110240Z/items/CVE-2026-17459.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 5,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability was determined in perwendel spark up to 2.9.4. NVD: This vulnerability affects the function staticFiles.externalLocation of the file src/main/java/spark/resource/ExternalResourceHandler.jav of the component SparkJava. NVD: Executing a manipulation can lead to symlink following.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-17459/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-17496/",
      "current_public_safe_latest": false,
      "cvss_score": 8.1,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.22401,
      "epss_score": 0.00301,
      "first_observed_at": "2026-08-01T10:51:40.555213+00:00",
      "id": "CVE-2026-17496",
      "impact_tags": [
        "XSS risk"
      ],
      "kev": false,
      "last_observed_at": "2026-08-02T10:52:32.597181+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: NoteGen before 0.32.0 renders AI chat responses with markdown-it configured with html:true and injects the result into the DOM via dangerouslySetInnerHTML in chat-preview, without HTML sanitization and with CSP set to null. NVD: Attacker-controlled content that reaches the model prompt (for example a malicious skill REFERENCE.md that instructs the model to emit HTML) can cause the model response to include executable markup such as an img onerror handler. NVD: When the user views the chat response, that markup runs as JavaScript in the privileged Tauri webview, enabling arbitrary script execution in the application context (cross-site scripting).",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260802T110240Z/items/CVE-2026-17496.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 5,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes XSS risk. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: NoteGen before 0.32.0 renders AI chat responses with markdown-it configured with html:true and injects the result into the DOM via dangerouslySetInnerHTML in chat-preview, without HTML sanitization and with CSP set to null. NVD: Attacker-controlled content that reaches the model prompt (for example a malicious skill REFERENCE.md that instructs the model to emit HTML) can cause the model response to include executable markup such as an img onerror handler. NVD: When the user views the chat response, that markup runs as JavaScript in the privileged Tauri webview, enabling arbitrary script execution in the application context (cross-site scripting).",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-17496/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-17497/",
      "current_public_safe_latest": false,
      "cvss_score": 8.3,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.37259,
      "epss_score": 0.00455,
      "first_observed_at": "2026-08-01T10:51:40.555213+00:00",
      "id": "CVE-2026-17497",
      "impact_tags": [
        "code execution review",
        "command execution review",
        "XSS risk"
      ],
      "kev": false,
      "last_observed_at": "2026-08-02T10:52:32.597181+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: NoteGen before 0.32.0 grants the Tauri shell plugin shell:allow-execute capability for bash, python, and python3 with arbitrary arguments in the default desktop capabilities. NVD: JavaScript running in the application webview can therefore invoke plugin:shell|execute to run attacker-controlled operating system commands with the privileges of the NoteGen process. NVD: In combination with script execution in the webview (for example via chat XSS), this enables full remote code execution on the user's machine.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260802T110240Z/items/CVE-2026-17497.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 5,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes code execution review · command execution risk · XSS risk. Possible impact: An attacker may be able to run code or commands on affected systems.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: NoteGen before 0.32.0 grants the Tauri shell plugin shell:allow-execute capability for bash, python, and python3 with arbitrary arguments in the default desktop capabilities. NVD: JavaScript running in the application webview can therefore invoke plugin:shell|execute to run attacker-controlled operating system commands with the privileges of the NoteGen process. NVD: In combination with script execution in the webview (for example via chat XSS), this enables full remote code execution on the user's machine.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-17497/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-17500/",
      "current_public_safe_latest": false,
      "cvss_score": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.34478,
      "epss_score": 0.00419,
      "first_observed_at": "2026-08-01T10:51:40.555213+00:00",
      "id": "CVE-2026-17500",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-02T22:13:42.582353+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A vulnerability was detected in ggml-org llama.cpp d006858/e15efe0. NVD: This affects the function _visit_pattern of the file common/json-schema-to-grammar.cpp. NVD: The manipulation results in null pointer dereference.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260802T221659Z/items/CVE-2026-17500.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 7,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability was detected in ggml-org llama.cpp d006858/e15efe0. NVD: This affects the function _visit_pattern of the file common/json-schema-to-grammar.cpp. NVD: The manipulation results in null pointer dereference.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-17500/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-17501/",
      "current_public_safe_latest": false,
      "cvss_score": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.34477,
      "epss_score": 0.00419,
      "first_observed_at": "2026-08-01T16:16:22.294010+00:00",
      "id": "CVE-2026-17501",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-02T22:13:42.582353+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A flaw has been found in ggml-org llama.cpp e15efe0. NVD: This vulnerability affects the function transform of the file common/json-schema-to-grammar.cpp of the component JSON-Schema-to-GBNF Conversion. NVD: This manipulation causes uncontrolled recursion.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260802T221659Z/items/CVE-2026-17501.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 6,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A flaw has been found in ggml-org llama.cpp e15efe0. NVD: This vulnerability affects the function transform of the file common/json-schema-to-grammar.cpp of the component JSON-Schema-to-GBNF Conversion. NVD: This manipulation causes uncontrolled recursion.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-17501/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-17512/",
      "current_public_safe_latest": false,
      "cvss_score": 1.9,
      "cvss_severity": "LOW",
      "epss_percentile": 0.01651,
      "epss_score": 0.00113,
      "first_observed_at": "2026-08-03T12:38:03.310457+00:00",
      "id": "CVE-2026-17512",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-03T12:38:03.310457+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A vulnerability has been found in ggml-org whisper.cpp 1.8.4-58. NVD: This impacts the function log_mel_spectrogram of the file src/whisper.cpp. NVD: The manipulation leads to out-of-bounds read.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260803T124716Z/items/CVE-2026-17512.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability has been found in ggml-org whisper.cpp 1.8.4-58. NVD: This impacts the function log_mel_spectrogram of the file src/whisper.cpp. NVD: The manipulation leads to out-of-bounds read.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-17512/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-17513/",
      "current_public_safe_latest": false,
      "cvss_score": 1.9,
      "cvss_severity": "LOW",
      "epss_percentile": 0.01605,
      "epss_score": 0.00112,
      "first_observed_at": "2026-08-03T12:38:03.310457+00:00",
      "id": "CVE-2026-17513",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-03T12:38:03.310457+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A vulnerability was found in ggml-org whisper.cpp 95ea8f9b. NVD: Affected is the function ggml_ftype_to_ggml_type of the file ggml/src/ggml.c. NVD: The manipulation of the argument ftype results in reachable assertion.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260803T124716Z/items/CVE-2026-17513.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability was found in ggml-org whisper.cpp 95ea8f9b. NVD: Affected is the function ggml_ftype_to_ggml_type of the file ggml/src/ggml.c. NVD: The manipulation of the argument ftype results in reachable assertion.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-17513/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-17514/",
      "current_public_safe_latest": false,
      "cvss_score": 1.9,
      "cvss_severity": "LOW",
      "epss_percentile": 0.03569,
      "epss_score": 0.00137,
      "first_observed_at": "2026-08-03T12:38:03.310457+00:00",
      "id": "CVE-2026-17514",
      "impact_tags": [
        "path traversal review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-03T12:38:03.310457+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A vulnerability was determined in ZJONSSON node-unzipper up to 0.12.3. NVD: Affected by this vulnerability is the function Extract of the file lib/extract.js. NVD: This manipulation causes path traversal.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260803T124716Z/items/CVE-2026-17514.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes path traversal review. Possible impact: An attacker may be able to reach files outside the intended application path.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability was determined in ZJONSSON node-unzipper up to 0.12.3. NVD: Affected by this vulnerability is the function Extract of the file lib/extract.js. NVD: This manipulation causes path traversal.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-17514/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-17524/",
      "current_public_safe_latest": false,
      "cvss_score": 8.7,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.52525,
      "epss_score": 0.00785,
      "first_observed_at": "2026-08-03T22:29:45.220405+00:00",
      "id": "CVE-2026-17524",
      "impact_tags": [
        "path traversal review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-04T06:07:04.591309+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Versions of the package zip-lib before 1.1.0 are vulnerable to Directory Traversal via the caching mechanism for path validation during the extraction process. NVD: An attacker can bypass security checks designed to prevent directory traversal. NVD: The intended security function, isOutsideTargetFolder, only checks and caches the path status when the initial directory symlink is created during the first extraction.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260804T061658Z/items/CVE-2026-17524.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes path traversal review. Possible impact: An attacker may be able to reach files outside the intended application path.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Versions of the package zip-lib before 1.1.0 are vulnerable to Directory Traversal via the caching mechanism for path validation during the extraction process. NVD: An attacker can bypass security checks designed to prevent directory traversal. NVD: The intended security function, isOutsideTargetFolder, only checks and caches the path status when the initial directory symlink is created during the first extraction.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-17524/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-17528/",
      "current_public_safe_latest": false,
      "cvss_score": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.1232,
      "epss_score": 0.00218,
      "first_observed_at": "2026-08-03T22:29:45.220405+00:00",
      "id": "CVE-2026-17528",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-04T06:07:04.591309+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Versions of the package nice-select2 before 2.4.1 are vulnerable to Cross-site Scripting (XSS) via the <select> element. OSV: Versions of the package nice-select2 before 2.4.1 are vulnerable to Cross-site Scripting (XSS) via the <select> element.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260804T061658Z/items/CVE-2026-17528.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Versions of the package nice-select2 before 2.4.1 are vulnerable to Cross-site Scripting (XSS) via the <select> element. OSV: Versions of the package nice-select2 before 2.4.1 are vulnerable to Cross-site Scripting (XSS) via the <select> element.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-17528/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "php / php",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-17543/",
      "current_public_safe_latest": false,
      "cvss_score": 8.1,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.313,
      "epss_score": 0.00386,
      "first_observed_at": "2026-08-06T11:35:20.545945+00:00",
      "id": "CVE-2026-17543",
      "impact_tags": [
        "SQL injection risk"
      ],
      "kev": false,
      "last_observed_at": "2026-08-06T11:35:20.545945+00:00",
      "latest_item_url": null,
      "product": "php",
      "public_safe_summary": "NVD: Improper escaping of backslashes in attacker-provided parameters would allow for trivial SQL injection in PHP versions from 8.2.* before 8.2.33, from 8.3.* before 8.3.33, from 8.4.* before 8.4.24, and from 8.5.* before 8.5.9.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260806T114533Z/items/CVE-2026-17543.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: php / php",
      "source_published_impact": "Source describes SQL injection risk. Possible impact: An attacker may be able to read or change database-backed application data.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Improper escaping of backslashes in attacker-provided parameters would allow for trivial SQL injection in PHP versions from 8.2.* before 8.2.33, from 8.3.* before 8.3.33, from 8.4.* before 8.4.24, and from 8.5.* before 8.5.9.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-17543/timeline.json",
      "vendor": "php"
    },
    {
      "affected_label": "php / php",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-17544/",
      "current_public_safe_latest": false,
      "cvss_score": 8.1,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.3519,
      "epss_score": 0.00428,
      "first_observed_at": "2026-08-06T11:35:20.545945+00:00",
      "id": "CVE-2026-17544",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-06T11:35:20.545945+00:00",
      "latest_item_url": null,
      "product": "php",
      "public_safe_summary": "NVD: Attacker-provided inputs to bccomp() could lead to an out-of-bounds write with stack and heap corruption in PHP versions from 8.4.* before 8.4.24 and from 8.5.* before 8.5.9.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260806T114533Z/items/CVE-2026-17544.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: php / php",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Attacker-provided inputs to bccomp() could lead to an out-of-bounds write with stack and heap corruption in PHP versions from 8.4.* before 8.4.24 and from 8.5.* before 8.5.9.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-17544/timeline.json",
      "vendor": "php"
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-17552/",
      "current_public_safe_latest": false,
      "cvss_score": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.27611,
      "epss_score": 0.00349,
      "first_observed_at": "2026-08-03T17:21:47.396014+00:00",
      "id": "CVE-2026-17552",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-03T17:21:47.396014+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Plack::App::Prerender versions before 0.3.0 for Perl can proxy to an arbitrary host via unvalidated REQUEST_URI concatenation in call. NVD: When the rewrite base is a plain string, the REQUEST_URI is appended to it, with no check that the path starts with a forward slash ('/'). NVD: When the rewrite base does not contain a path (which is the standard given in the SYNOPSIS), an attacker can create a request that changes the hostname.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260803T174717Z/items/CVE-2026-17552.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Plack::App::Prerender versions before 0.3.0 for Perl can proxy to an arbitrary host via unvalidated REQUEST_URI concatenation in call. NVD: When the rewrite base is a plain string, the REQUEST_URI is appended to it, with no check that the path starts with a forward slash ('/'). NVD: When the rewrite base does not contain a path (which is the standard given in the SYNOPSIS), an attacker can create a request that changes the hostname.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-17552/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-17561/",
      "current_public_safe_latest": false,
      "cvss_score": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.23733,
      "epss_score": 0.00314,
      "first_observed_at": "2026-08-07T10:13:53.604723+00:00",
      "id": "CVE-2026-17561",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-07T10:13:53.604723+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Improper Control of Generation of Code ('Code Injection') vulnerability in Innotim Software, Telecommunications and Consulting Trade Ltd. NVD: Co. NVD: Logsign SIEM allows Code Injection.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260807T102646Z/items/CVE-2026-17561.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Improper Control of Generation of Code ('Code Injection') vulnerability in Innotim Software, Telecommunications and Consulting Trade Ltd. NVD: Co. NVD: Logsign SIEM allows Code Injection.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-17561/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "pgadmin / pgadmin_4",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-17566/",
      "current_public_safe_latest": false,
      "cvss_score": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.33625,
      "epss_score": 0.00408,
      "first_observed_at": "2026-08-07T16:11:58.676122+00:00",
      "id": "CVE-2026-17566",
      "impact_tags": [
        "code execution review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-07T16:11:58.676122+00:00",
      "latest_item_url": null,
      "product": "pgadmin_4",
      "public_safe_summary": "NVD: pgAdmin 4's Import/Export Data tool builds a psql \\copy (...) command line by interpolating a user-supplied SQL query into a Jinja template and passing the rendered line to psql via --command. NVD: To stop an attacker from breaking out of the (...) wrapper, create_import_export_job() (route POST /import_export/job/<sid>, gated only by the ordinary, commonly-granted tools_import_export_data permission) validated the query with a hand-written... NVD: That checker always treated a backslash before a single quote (\\') as escaping the quote, i.e.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260807T162046Z/items/CVE-2026-17566.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: pgadmin / pgadmin_4",
      "source_published_impact": "Source describes code execution review. Possible impact: An attacker may be able to run code or commands on affected systems.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: pgAdmin 4's Import/Export Data tool builds a psql \\copy (...) command line by interpolating a user-supplied SQL query into a Jinja template and passing the rendered line to psql via --command. NVD: To stop an attacker from breaking out of the (...) wrapper, create_import_export_job() (route POST /import_export/job/<sid>, gated only by the ordinary, commonly-granted tools_import_export_data permission) validated the query with a hand-written... NVD: That checker always treated a backslash before a single quote (\\') as escaping the quote, i.e.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-17566/timeline.json",
      "vendor": "pgadmin"
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-17567/",
      "current_public_safe_latest": false,
      "cvss_score": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.30414,
      "epss_score": 0.00377,
      "first_observed_at": "2026-08-07T10:13:53.604723+00:00",
      "id": "CVE-2026-17567",
      "impact_tags": [
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-07T10:13:53.604723+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 6.2.8 via the 'transaction' parameter due to missing... NVD: This makes it possible for unauthenticated attackers to brute-force valid transaction hashes and view sensitive payment receipt data including customer name, email address, billing address, order items, payment method, and payment status belonging to other... NVD: Because submission ID, form ID, and transaction creation time are either observable or guessable by an attacker, the effective brute-force space is bounded to approximately 900 candidates per second per (submission, form) pair, making exploitation practical...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260807T102646Z/items/CVE-2026-17567.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes remote exposure · authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 6.2.8 via the 'transaction' parameter due to missing... NVD: This makes it possible for unauthenticated attackers to brute-force valid transaction hashes and view sensitive payment receipt data including customer name, email address, billing address, order items, payment method, and payment status belonging to other... NVD: Because submission ID, form ID, and transaction creation time are either observable or guessable by an attacker, the effective brute-force space is bounded to approximately 900 candidates per second per (submission, form) pair, making exploitation practical...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-17567/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "devolutions / devolutions_server",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-17568/",
      "current_public_safe_latest": false,
      "cvss_score": 8.8,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.14193,
      "epss_score": 0.00232,
      "first_observed_at": "2026-08-03T17:21:47.396014+00:00",
      "id": "CVE-2026-17568",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-03T17:21:47.396014+00:00",
      "latest_item_url": null,
      "product": "devolutions_server",
      "public_safe_summary": "NVD: Improper access control in the role membership management endpoint in Devolutions Server allows an authenticated non-administrative user holding the user-group membership management permission to escalate privileges to administrator via a crafted API request. NVD: This issue affects : * Devolutions Server 2026.2.4.0 through 2026.2.12.0 * Devolutions Server 2026.1.23.0 and earlier",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260803T174717Z/items/CVE-2026-17568.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: devolutions / devolutions_server",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Improper access control in the role membership management endpoint in Devolutions Server allows an authenticated non-administrative user holding the user-group membership management permission to escalate privileges to administrator via a crafted API request. NVD: This issue affects : * Devolutions Server 2026.2.4.0 through 2026.2.12.0 * Devolutions Server 2026.1.23.0 and earlier",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-17568/timeline.json",
      "vendor": "devolutions"
    },
    {
      "affected_label": "devolutions / devolutions_server",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-17569/",
      "current_public_safe_latest": false,
      "cvss_score": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.05833,
      "epss_score": 0.00162,
      "first_observed_at": "2026-08-03T17:21:47.396014+00:00",
      "id": "CVE-2026-17569",
      "impact_tags": [
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-03T17:21:47.396014+00:00",
      "latest_item_url": null,
      "product": "devolutions_server",
      "public_safe_summary": "NVD: Improper access control in the NetBox synchronizer in Devolutions Server allows an authenticated user with view-only permission on an entry to obtain a stored API token via the partial connection endpoint. NVD: This issue affects : * Devolutions Server 2026.2.4.0 through 2026.2.12.0 * Devolutions Server 2026.1.23.0 and earlier",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260803T174717Z/items/CVE-2026-17569.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: devolutions / devolutions_server",
      "source_published_impact": "Source describes authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Improper access control in the NetBox synchronizer in Devolutions Server allows an authenticated user with view-only permission on an entry to obtain a stored API token via the partial connection endpoint. NVD: This issue affects : * Devolutions Server 2026.2.4.0 through 2026.2.12.0 * Devolutions Server 2026.1.23.0 and earlier",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-17569/timeline.json",
      "vendor": "devolutions"
    },
    {
      "affected_label": "devolutions / devolutions_server",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-17570/",
      "current_public_safe_latest": false,
      "cvss_score": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.05736,
      "epss_score": 0.00161,
      "first_observed_at": "2026-08-03T17:21:47.396014+00:00",
      "id": "CVE-2026-17570",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-03T17:21:47.396014+00:00",
      "latest_item_url": null,
      "product": "devolutions_server",
      "public_safe_summary": "NVD: Improper access control in the PAM password history endpoints in Devolutions Server allows an authenticated low-privileged user to disclose plaintext credential secrets via crafted API requests. NVD: This issue affects : * Devolutions Server 2026.2.4.0 through 2026.2.12.0 * Devolutions Server 2026.1.23.0 and earlier",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260803T174717Z/items/CVE-2026-17570.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: devolutions / devolutions_server",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Improper access control in the PAM password history endpoints in Devolutions Server allows an authenticated low-privileged user to disclose plaintext credential secrets via crafted API requests. NVD: This issue affects : * Devolutions Server 2026.2.4.0 through 2026.2.12.0 * Devolutions Server 2026.1.23.0 and earlier",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-17570/timeline.json",
      "vendor": "devolutions"
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-17578/",
      "current_public_safe_latest": true,
      "cvss_score": 2.3,
      "cvss_severity": "LOW",
      "epss_percentile": 0.04712,
      "epss_score": 0.0015,
      "first_observed_at": "2026-08-12T10:29:37.194110+00:00",
      "id": "CVE-2026-17578",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-12T10:29:37.194110+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-17578.json",
      "product": null,
      "public_safe_summary": "NVD: Kong Event Gateway versions 1.0.0 through 1.1.1 and 1.2.0 do not enforce key rotation before reaching NIST SP 800-38D recommended usage limit for AES-GCM encryption keys with random nonces when the AWS IAM encryption feature is enabled. NVD: If a producer sends messages at a sustained high rate without key rotation, which only occurs on reboot of the Kong Event Gateway instance, the probability of a nonce collision becomes non-negligible. NVD: An authorized consumer who detects a nonce collision can recover parts of plaintext from the affected messages.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260812T103932Z/items/CVE-2026-17578.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Kong Event Gateway versions 1.0.0 through 1.1.1 and 1.2.0 do not enforce key rotation before reaching NIST SP 800-38D recommended usage limit for AES-GCM encryption keys with random nonces when the AWS IAM encryption feature is enabled. NVD: If a producer sends messages at a sustained high rate without key rotation, which only occurs on reboot of the Kong Event Gateway instance, the probability of a nonce collision becomes non-negligible. NVD: An authorized consumer who detects a nonce collision can recover parts of plaintext from the affected messages.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-17578/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-17650/",
      "current_public_safe_latest": false,
      "cvss_score": 8.3,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.31344,
      "epss_score": 0.00386,
      "first_observed_at": "2026-08-05T22:30:13.133185+00:00",
      "id": "CVE-2026-17650",
      "impact_tags": [
        "memory safety review",
        "remote exposure relevant"
      ],
      "kev": false,
      "last_observed_at": "2026-08-05T22:30:13.133185+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Use after free in Compositing in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. NVD: (Chromium security severity: Critical)",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260805T223715Z/items/CVE-2026-17650.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes memory safety review · remote exposure. Possible impact: The affected component has memory-safety risk that may lead to crash, privilege, or code-execution impact depending on exposure.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Use after free in Compositing in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. NVD: (Chromium security severity: Critical)",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-17650/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "google / chrome",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-17651/",
      "current_public_safe_latest": false,
      "cvss_score": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.32429,
      "epss_score": 0.00397,
      "first_observed_at": "2026-08-05T22:30:13.133185+00:00",
      "id": "CVE-2026-17651",
      "impact_tags": [
        "remote exposure relevant"
      ],
      "kev": false,
      "last_observed_at": "2026-08-05T22:30:13.133185+00:00",
      "latest_item_url": null,
      "product": "chrome",
      "public_safe_summary": "NVD: Insufficient validation of untrusted input in Dawn in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. NVD: (Chromium security severity: Critical)",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260805T223715Z/items/CVE-2026-17651.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: google / chrome; affected version context: -",
      "source_published_impact": "Source describes remote exposure. Possible impact: This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Insufficient validation of untrusted input in Dawn in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. NVD: (Chromium security severity: Critical)",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-17651/timeline.json",
      "vendor": "google"
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-17652/",
      "current_public_safe_latest": false,
      "cvss_score": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.3423,
      "epss_score": 0.00416,
      "first_observed_at": "2026-08-05T22:30:13.133185+00:00",
      "id": "CVE-2026-17652",
      "impact_tags": [
        "memory safety review",
        "remote exposure relevant"
      ],
      "kev": false,
      "last_observed_at": "2026-08-05T22:30:13.133185+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Use after free in Views in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. NVD: (Chromium security severity: Critical)",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260805T223715Z/items/CVE-2026-17652.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes memory safety review · remote exposure. Possible impact: The affected component has memory-safety risk that may lead to crash, privilege, or code-execution impact depending on exposure.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Use after free in Views in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. NVD: (Chromium security severity: Critical)",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-17652/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-17653/",
      "current_public_safe_latest": false,
      "cvss_score": 8.3,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.31344,
      "epss_score": 0.00386,
      "first_observed_at": "2026-08-05T22:30:13.133185+00:00",
      "id": "CVE-2026-17653",
      "impact_tags": [
        "memory safety review",
        "remote exposure relevant"
      ],
      "kev": false,
      "last_observed_at": "2026-08-05T22:30:13.133185+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Use after free in Skia in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. NVD: (Chromium security severity: Critical)",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260805T223715Z/items/CVE-2026-17653.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes memory safety review · remote exposure. Possible impact: The affected component has memory-safety risk that may lead to crash, privilege, or code-execution impact depending on exposure.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Use after free in Skia in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. NVD: (Chromium security severity: Critical)",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-17653/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-17654/",
      "current_public_safe_latest": false,
      "cvss_score": 7.8,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.01761,
      "epss_score": 0.00114,
      "first_observed_at": "2026-08-05T22:30:13.133185+00:00",
      "id": "CVE-2026-17654",
      "impact_tags": [
        "privilege boundary review",
        "local exposure relevant"
      ],
      "kev": false,
      "last_observed_at": "2026-08-05T22:30:13.133185+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Race in Updater in Google Chrome on Mac prior to 151.0.7922.72 allowed a local attacker to perform OS-level privilege escalation via a malicious file. NVD: (Chromium security severity: Critical)",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260805T223715Z/items/CVE-2026-17654.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes privilege escalation risk · local exposure. Possible impact: A local user may cross a privilege boundary and gain more access than intended.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Race in Updater in Google Chrome on Mac prior to 151.0.7922.72 allowed a local attacker to perform OS-level privilege escalation via a malicious file. NVD: (Chromium security severity: Critical)",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-17654/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-17655/",
      "current_public_safe_latest": false,
      "cvss_score": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.34194,
      "epss_score": 0.00416,
      "first_observed_at": "2026-08-05T22:30:13.133185+00:00",
      "id": "CVE-2026-17655",
      "impact_tags": [
        "remote exposure relevant"
      ],
      "kev": false,
      "last_observed_at": "2026-08-05T22:30:13.133185+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. NVD: (Chromium security severity: Critical)",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260805T223715Z/items/CVE-2026-17655.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes remote exposure. Possible impact: This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. NVD: (Chromium security severity: Critical)",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-17655/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-17656/",
      "current_public_safe_latest": false,
      "cvss_score": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.34194,
      "epss_score": 0.00416,
      "first_observed_at": "2026-08-05T22:30:13.133185+00:00",
      "id": "CVE-2026-17656",
      "impact_tags": [
        "memory safety review",
        "remote exposure relevant"
      ],
      "kev": false,
      "last_observed_at": "2026-08-05T22:30:13.133185+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Use after free in Ozone in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. NVD: (Chromium security severity: Critical)",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260805T223715Z/items/CVE-2026-17656.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes memory safety review · remote exposure. Possible impact: The affected component has memory-safety risk that may lead to crash, privilege, or code-execution impact depending on exposure.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Use after free in Ozone in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. NVD: (Chromium security severity: Critical)",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-17656/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-17657/",
      "current_public_safe_latest": false,
      "cvss_score": 8.3,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.28598,
      "epss_score": 0.00359,
      "first_observed_at": "2026-08-05T22:30:13.133185+00:00",
      "id": "CVE-2026-17657",
      "impact_tags": [
        "memory safety review",
        "remote exposure relevant"
      ],
      "kev": false,
      "last_observed_at": "2026-08-05T22:30:13.133185+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Use after free in Navigation in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. NVD: (Chromium security severity: High)",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260805T223715Z/items/CVE-2026-17657.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes memory safety review · remote exposure. Possible impact: The affected component has memory-safety risk that may lead to crash, privilege, or code-execution impact depending on exposure.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Use after free in Navigation in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. NVD: (Chromium security severity: High)",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-17657/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-17658/",
      "current_public_safe_latest": false,
      "cvss_score": 8.8,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.37844,
      "epss_score": 0.00464,
      "first_observed_at": "2026-08-05T22:30:13.133185+00:00",
      "id": "CVE-2026-17658",
      "impact_tags": [
        "code execution review",
        "memory safety review",
        "remote exposure relevant"
      ],
      "kev": false,
      "last_observed_at": "2026-08-05T22:30:13.133185+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Use after free in V8 in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. NVD: (Chromium security severity: High)",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260805T223715Z/items/CVE-2026-17658.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes code execution review · memory safety review · remote exposure. Possible impact: A remote attacker may be able to run code or commands on affected systems.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Use after free in V8 in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. NVD: (Chromium security severity: High)",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-17658/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-17659/",
      "current_public_safe_latest": false,
      "cvss_score": 4.2,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.17794,
      "epss_score": 0.00262,
      "first_observed_at": "2026-08-05T22:30:13.133185+00:00",
      "id": "CVE-2026-17659",
      "impact_tags": [
        "remote exposure relevant"
      ],
      "kev": false,
      "last_observed_at": "2026-08-05T22:30:13.133185+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Inappropriate implementation in SiteIsolation in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. NVD: (Chromium security severity: High)",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260805T223715Z/items/CVE-2026-17659.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes remote exposure. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Inappropriate implementation in SiteIsolation in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. NVD: (Chromium security severity: High)",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-17659/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-17660/",
      "current_public_safe_latest": false,
      "cvss_score": 8.3,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.31076,
      "epss_score": 0.00384,
      "first_observed_at": "2026-08-05T22:30:13.133185+00:00",
      "id": "CVE-2026-17660",
      "impact_tags": [
        "remote exposure relevant"
      ],
      "kev": false,
      "last_observed_at": "2026-08-05T22:30:13.133185+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Insufficient validation of untrusted input in Network in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. NVD: (Chromium security severity: High)",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260805T223715Z/items/CVE-2026-17660.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes remote exposure. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Insufficient validation of untrusted input in Network in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. NVD: (Chromium security severity: High)",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-17660/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-17661/",
      "current_public_safe_latest": false,
      "cvss_score": 8.8,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.37844,
      "epss_score": 0.00464,
      "first_observed_at": "2026-08-05T22:30:13.133185+00:00",
      "id": "CVE-2026-17661",
      "impact_tags": [
        "code execution review",
        "memory safety review",
        "remote exposure relevant"
      ],
      "kev": false,
      "last_observed_at": "2026-08-05T22:30:13.133185+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Use after free in Loader in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. NVD: (Chromium security severity: High)",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260805T223715Z/items/CVE-2026-17661.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes code execution review · memory safety review · remote exposure. Possible impact: A remote attacker may be able to run code or commands on affected systems.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Use after free in Loader in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. NVD: (Chromium security severity: High)",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-17661/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-17662/",
      "current_public_safe_latest": false,
      "cvss_score": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.10682,
      "epss_score": 0.00205,
      "first_observed_at": "2026-08-05T22:30:13.133185+00:00",
      "id": "CVE-2026-17662",
      "impact_tags": [
        "remote exposure relevant"
      ],
      "kev": false,
      "last_observed_at": "2026-08-05T22:30:13.133185+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Insufficient policy enforcement in Prefetch in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. NVD: (Chromium security severity: High)",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260805T223715Z/items/CVE-2026-17662.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes remote exposure. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Insufficient policy enforcement in Prefetch in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. NVD: (Chromium security severity: High)",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-17662/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "google / chrome",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-17663/",
      "current_public_safe_latest": false,
      "cvss_score": 8.3,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.27304,
      "epss_score": 0.00347,
      "first_observed_at": "2026-08-05T22:30:13.133185+00:00",
      "id": "CVE-2026-17663",
      "impact_tags": [
        "remote exposure relevant"
      ],
      "kev": false,
      "last_observed_at": "2026-08-05T22:30:13.133185+00:00",
      "latest_item_url": null,
      "product": "chrome",
      "public_safe_summary": "NVD: Insufficient validation of untrusted input in GPU in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. NVD: (Chromium security severity: High)",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260805T223715Z/items/CVE-2026-17663.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: google / chrome; affected version context: -",
      "source_published_impact": "Source describes remote exposure. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Insufficient validation of untrusted input in GPU in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. NVD: (Chromium security severity: High)",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-17663/timeline.json",
      "vendor": "google"
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-17664/",
      "current_public_safe_latest": false,
      "cvss_score": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.29327,
      "epss_score": 0.00367,
      "first_observed_at": "2026-08-05T22:30:13.133185+00:00",
      "id": "CVE-2026-17664",
      "impact_tags": [
        "remote exposure relevant"
      ],
      "kev": false,
      "last_observed_at": "2026-08-05T22:30:13.133185+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Insufficient validation of untrusted input in Loader in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. NVD: (Chromium security severity: High)",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260805T223715Z/items/CVE-2026-17664.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes remote exposure. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Insufficient validation of untrusted input in Loader in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. NVD: (Chromium security severity: High)",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-17664/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-18038/",
      "current_public_safe_latest": false,
      "cvss_score": 2.1,
      "cvss_severity": "LOW",
      "epss_percentile": 0.12876,
      "epss_score": 0.00222,
      "first_observed_at": "2026-08-04T11:35:47.800052+00:00",
      "id": "CVE-2026-18038",
      "impact_tags": [
        "information exposure review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-04T11:35:47.800052+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A flaw has been found in nextlevelbuilder GoClaw up to 3.13.2. NVD: Affected by this vulnerability is the function ExecTool.Execute of the file goclaw/internal/http/tools_invoke.go of the component jq Handler. NVD: Executing a manipulation can lead to information disclosure.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260804T114328Z/items/CVE-2026-18038.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes information exposure review. Possible impact: An attacker may be able to access information that should not be exposed.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A flaw has been found in nextlevelbuilder GoClaw up to 3.13.2. NVD: Affected by this vulnerability is the function ExecTool.Execute of the file goclaw/internal/http/tools_invoke.go of the component jq Handler. NVD: Executing a manipulation can lead to information disclosure.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-18038/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-18047/",
      "current_public_safe_latest": false,
      "cvss_score": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.20443,
      "epss_score": 0.00281,
      "first_observed_at": "2026-08-04T11:35:47.800052+00:00",
      "id": "CVE-2026-18047",
      "impact_tags": [
        "service availability review",
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-04T11:35:47.800052+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A flaw was found in Dogtag PKI's ACME responder where the web.xml security constraints use exact URL pattern matching for admin-only enable/disable endpoints. NVD: By appending a trailing slash to the URL, an unauthenticated attacker can bypass the Tomcat authentication constraint while RESTEasy still routes the request to the handler, allowing unauthorized toggling of the ACME service state including persistent denial...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260804T114328Z/items/CVE-2026-18047.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes service availability risk · remote exposure · authenticated boundary. Possible impact: The affected service may become unavailable or unreliable.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A flaw was found in Dogtag PKI's ACME responder where the web.xml security constraints use exact URL pattern matching for admin-only enable/disable endpoints. NVD: By appending a trailing slash to the URL, an unauthenticated attacker can bypass the Tomcat authentication constraint while RESTEasy still routes the request to the handler, allowing unauthorized toggling of the ACME service state including persistent denial...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-18047/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-18084/",
      "current_public_safe_latest": false,
      "cvss_score": 8.6,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.17373,
      "epss_score": 0.00258,
      "first_observed_at": "2026-08-04T17:06:52.325316+00:00",
      "id": "CVE-2026-18084",
      "impact_tags": [
        "XSS risk"
      ],
      "kev": false,
      "last_observed_at": "2026-08-04T17:06:52.325316+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Improper Neutralization of Input During Web Page Generation vulnerability in BlackBerry UEM Management Console of BlackBerry UEM allows Cross-Site Scripting (XSS). NVD: This issue affects UEM: 12.23.0 QF8 or earlier.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260804T171542Z/items/CVE-2026-18084.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes XSS risk. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Improper Neutralization of Input During Web Page Generation vulnerability in BlackBerry UEM Management Console of BlackBerry UEM allows Cross-Site Scripting (XSS). NVD: This issue affects UEM: 12.23.0 QF8 or earlier.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-18084/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-18085/",
      "current_public_safe_latest": false,
      "cvss_score": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.10983,
      "epss_score": 0.00207,
      "first_observed_at": "2026-08-04T17:06:52.325316+00:00",
      "id": "CVE-2026-18085",
      "impact_tags": [
        "service availability review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-04T17:06:52.325316+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: An Improper Input Validation in the BlackBerry UEM Management Console of BlackBerry UEM 12.23.0 QF8 and earlier allows Arbitrary File Download and Potential Denial of Service.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260804T171542Z/items/CVE-2026-18085.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes service availability risk. Possible impact: The affected service may become unavailable or unreliable.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: An Improper Input Validation in the BlackBerry UEM Management Console of BlackBerry UEM 12.23.0 QF8 and earlier allows Arbitrary File Download and Potential Denial of Service.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-18085/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "timlegge / net\\",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-18089/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.07184,
      "epss_score": 0.00175,
      "first_observed_at": "2026-08-10T10:38:36.347227+00:00",
      "id": "CVE-2026-18089",
      "impact_tags": [
        "authentication boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-10T10:38:36.347227+00:00",
      "latest_item_url": null,
      "product": "net\\",
      "public_safe_summary": "NVD: Net::SAML2 versions before 0.86 for Perl allow SAML authentication bypass by verifying responses against the response-embedded certificate in verify_xml when no trust anchor is configured. NVD: verify_xml in Net::SAML2::Role::VerifyXML runs \"return if !$anchors && !$cacert;\" as soon as the XML::Sig check succeeds, and that check uses the X.509 certificate taken from the response's own dsig:KeyInfo/dsig:X509Certificate element, so an unanchored... NVD: Binding::POST declares cacert as an optional Maybe[Str] with no default, so a POST binding built without one takes that path, and _verify_encrypted_assertion returns early the same way with \"return $xml unless $cacert;\".",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260810T105121Z/items/CVE-2026-18089.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: timlegge / net\\; affected version context: \\",
      "source_published_impact": "Source describes authentication boundary review. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authentication boundary review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Net::SAML2 versions before 0.86 for Perl allow SAML authentication bypass by verifying responses against the response-embedded certificate in verify_xml when no trust anchor is configured. NVD: verify_xml in Net::SAML2::Role::VerifyXML runs \"return if !$anchors && !$cacert;\" as soon as the XML::Sig check succeeds, and that check uses the X.509 certificate taken from the response's own dsig:KeyInfo/dsig:X509Certificate element, so an unanchored... NVD: Binding::POST declares cacert as an optional Maybe[Str] with no default, so a POST binding built without one takes that path, and _verify_encrypted_assertion returns early the same way with \"return $xml unless $cacert;\".",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-18089/timeline.json",
      "vendor": "timlegge"
    },
    {
      "affected_label": "timlegge / net\\",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-18092/",
      "current_public_safe_latest": false,
      "cvss_score": 8.1,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.09461,
      "epss_score": 0.00196,
      "first_observed_at": "2026-08-10T10:38:36.347227+00:00",
      "id": "CVE-2026-18092",
      "impact_tags": [
        "authentication boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-10T10:38:36.347227+00:00",
      "latest_item_url": null,
      "product": "net\\",
      "public_safe_summary": "NVD: Net::SAML2 versions before 0.86 for Perl allow SAML authentication bypass via XML signature wrapping because new_from_xml reads assertion identity with document-wide XPath instead of the signed subtree. NVD: new_from_xml reads the NameID, attribute values, SessionIndex, audience and other identity fields with document-wide XPath, such as //saml:Assertion/saml:AttributeStatement/saml:Attribute and //saml:Subject/saml:NameID, which select the first matching element... NVD: handle_response confirms that a signature is present and, when a cacert is configured, that it chains to the CA, but XML::Sig verifies only the element named by the signature's Reference URI, so unsigned sibling assertions in the same document are not covered.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260810T105121Z/items/CVE-2026-18092.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: timlegge / net\\; affected version context: \\",
      "source_published_impact": "Source describes authentication boundary review. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authentication boundary review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Net::SAML2 versions before 0.86 for Perl allow SAML authentication bypass via XML signature wrapping because new_from_xml reads assertion identity with document-wide XPath instead of the signed subtree. NVD: new_from_xml reads the NameID, attribute values, SessionIndex, audience and other identity fields with document-wide XPath, such as //saml:Assertion/saml:AttributeStatement/saml:Attribute and //saml:Subject/saml:NameID, which select the first matching element... NVD: handle_response confirms that a signature is present and, when a cacert is configured, that it chains to the CA, but XML::Sig verifies only the element named by the signature's Reference URI, so unsigned sibling assertions in the same document are not covered.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-18092/timeline.json",
      "vendor": "timlegge"
    },
    {
      "affected_label": "timlegge / net\\",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-18108/",
      "current_public_safe_latest": false,
      "cvss_score": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.12538,
      "epss_score": 0.0022,
      "first_observed_at": "2026-08-10T10:38:36.347227+00:00",
      "id": "CVE-2026-18108",
      "impact_tags": [
        "authentication boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-10T10:38:36.347227+00:00",
      "latest_item_url": null,
      "product": "net\\",
      "public_safe_summary": "NVD: Net::SAML2 versions before 0.86 for Perl allow authentication bypass because _verify_encrypted_assertion accepts an EncryptedAssertion whose decrypted content carries no signature. NVD: _verify_encrypted_assertion decrypts the EncryptedAssertion and returns it as verified when it carries no signature, via \"return $xml unless $xpath->exists('dsig:Signature', $assert);\". NVD: The signature check and the trust anchor check that follow run only when a signature is present, so a decrypted assertion with no dsig:Signature element reaches new_from_xml unverified and its NameID and attributes are read into the assertion object.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260810T105121Z/items/CVE-2026-18108.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: timlegge / net\\; affected version context: \\",
      "source_published_impact": "Source describes authentication boundary review. Possible impact: This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authentication boundary review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Net::SAML2 versions before 0.86 for Perl allow authentication bypass because _verify_encrypted_assertion accepts an EncryptedAssertion whose decrypted content carries no signature. NVD: _verify_encrypted_assertion decrypts the EncryptedAssertion and returns it as verified when it carries no signature, via \"return $xml unless $xpath->exists('dsig:Signature', $assert);\". NVD: The signature check and the trust anchor check that follow run only when a signature is present, so a decrypted assertion with no dsig:Signature element reaches new_from_xml unverified and its NameID and attributes are read into the assertion object.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-18108/timeline.json",
      "vendor": "timlegge"
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-18141/",
      "current_public_safe_latest": false,
      "cvss_score": 8.2,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.2321,
      "epss_score": 0.00309,
      "first_observed_at": "2026-08-07T16:11:58.676122+00:00",
      "id": "CVE-2026-18141",
      "impact_tags": [
        "remote exposure relevant"
      ],
      "kev": false,
      "last_observed_at": "2026-08-07T16:11:58.676122+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A flaw was found in aap-gateway, a component of Ansible Automation Platform's Event-Driven Ansible (EDA). NVD: An unauthenticated remote attacker can bypass mutual Transport Layer Security (mTLS) authentication for event streams. NVD: This is achieved by manipulating the event stream URL and forging the HTTP Subject header.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260807T162046Z/items/CVE-2026-18141.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes remote exposure. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A flaw was found in aap-gateway, a component of Ansible Automation Platform's Event-Driven Ansible (EDA). NVD: An unauthenticated remote attacker can bypass mutual Transport Layer Security (mTLS) authentication for event streams. NVD: This is achieved by manipulating the event stream URL and forging the HTTP Subject header.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-18141/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-18174/",
      "current_public_safe_latest": false,
      "cvss_score": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.09205,
      "epss_score": 0.00193,
      "first_observed_at": "2026-08-05T11:32:09.387600+00:00",
      "id": "CVE-2026-18174",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-05T11:32:09.387600+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: @fastify/forwarded resolves client addresses from the X-Forwarded-For header. NVD: In versions before 3.0.2, when the header contains two or more comma separated entries, the parser trims only space characters and does not strip horizontal tabs, even though RFC 7230 defines optional whitespace as both space and tab. NVD: As a result, an entry padded with a tab keeps the literal tab in the resolved address string.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260805T113552Z/items/CVE-2026-18174.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: @fastify/forwarded resolves client addresses from the X-Forwarded-For header. NVD: In versions before 3.0.2, when the header contains two or more comma separated entries, the parser trims only space characters and does not strip horizontal tabs, even though RFC 7230 defines optional whitespace as both space and tab. NVD: As a result, an entry padded with a tab keeps the literal tab in the resolved address string.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-18174/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-18243/",
      "current_public_safe_latest": false,
      "cvss_score": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.07977,
      "epss_score": 0.00182,
      "first_observed_at": "2026-08-10T16:12:24.021737+00:00",
      "id": "CVE-2026-18243",
      "impact_tags": [
        "XSS risk"
      ],
      "kev": false,
      "last_observed_at": "2026-08-10T16:12:24.021737+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Certain HP DesignJet products may be potentially vulnerable to cross-site scripting (XSS), which may allow unauthenticated HTTP requests to view print job previews.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260810T162156Z/items/CVE-2026-18243.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes XSS risk. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Certain HP DesignJet products may be potentially vulnerable to cross-site scripting (XSS), which may allow unauthenticated HTTP requests to view print job previews.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-18243/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-18248/",
      "current_public_safe_latest": false,
      "cvss_score": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.12234,
      "epss_score": 0.00218,
      "first_observed_at": "2026-08-10T16:12:24.021737+00:00",
      "id": "CVE-2026-18248",
      "impact_tags": [
        "privilege boundary review",
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-10T16:12:24.021737+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: @fastify/aws-lambda version 6.4.0 decorates each Fastify request with request.awsLambda.event and request.awsLambda.context, values that applications are documented to use for authorization decisions such as reading API Gateway authorizer claims. NVD: In the default configuration, the getter that populates this decoration reads the client-controlled x-apigateway-event and x-apigateway-context HTTP headers before falling back to the trusted internal request token, and those reserved headers are not stripped... NVD: An unauthenticated attacker who can set a single HTTP header can therefore forge the entire Lambda proxy event, including the authorizer context, and override the genuine one.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260810T162156Z/items/CVE-2026-18248.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes privilege escalation risk · remote exposure · authenticated boundary. Possible impact: A remote attacker may cross a privilege boundary and gain more access than intended.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: @fastify/aws-lambda version 6.4.0 decorates each Fastify request with request.awsLambda.event and request.awsLambda.context, values that applications are documented to use for authorization decisions such as reading API Gateway authorizer claims. NVD: In the default configuration, the getter that populates this decoration reads the client-controlled x-apigateway-event and x-apigateway-context HTTP headers before falling back to the trusted internal request token, and those reserved headers are not stripped... NVD: An unauthenticated attacker who can set a single HTTP header can therefore forge the entire Lambda proxy event, including the authorizer context, and override the genuine one.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-18248/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-18255/",
      "current_public_safe_latest": false,
      "cvss_score": 7.2,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.19277,
      "epss_score": 0.00272,
      "first_observed_at": "2026-08-05T16:55:08.588478+00:00",
      "id": "CVE-2026-18255",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-05T16:55:08.588478+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A flaw was found in Quay. NVD: A user configured in GLOBAL_READONLY_SUPER_USERS is able to view robot account tokens for repositories they are not a member of, allowing an attacker with read-only superuser privileges to impersonate any robot account.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260805T165944Z/items/CVE-2026-18255.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A flaw was found in Quay. NVD: A user configured in GLOBAL_READONLY_SUPER_USERS is able to view robot account tokens for repositories they are not a member of, allowing an attacker with read-only superuser privileges to impersonate any robot account.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-18255/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-18257/",
      "current_public_safe_latest": false,
      "cvss_score": 5.6,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.00983,
      "epss_score": 0.001,
      "first_observed_at": "2026-08-05T16:55:08.588478+00:00",
      "id": "CVE-2026-18257",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-05T16:55:08.588478+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Improper validity period check for root issuer certificate in CycloneCrypto cryptographic wrapper of S2OPC allows a certificate issued by this root issuer to be considered trusted",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260805T165944Z/items/CVE-2026-18257.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Improper validity period check for root issuer certificate in CycloneCrypto cryptographic wrapper of S2OPC allows a certificate issued by this root issuer to be considered trusted",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-18257/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-1832/",
      "current_public_safe_latest": false,
      "cvss_score": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.10446,
      "epss_score": 0.00204,
      "first_observed_at": "2026-07-18T05:13:28.850753+00:00",
      "id": "CVE-2026-1832",
      "impact_tags": [
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-18T05:13:28.850753+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The ThriveDesk – Live Chat, AI Chatbot, Helpdesk & Knowledge Base plugin for WordPress is vulnerable to unauthorized cache deletion due to a missing capability check on the 'thrivedesk_clear_cache' AJAX action in all versions up to, and including, 2.1.7. NVD: This makes it possible for authenticated attackers, with Subscriber-level access and above, to clear the plugin's cache.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260718T051545Z/items/CVE-2026-1832.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The ThriveDesk – Live Chat, AI Chatbot, Helpdesk & Knowledge Base plugin for WordPress is vulnerable to unauthorized cache deletion due to a missing capability check on the 'thrivedesk_clear_cache' AJAX action in all versions up to, and including, 2.1.7. NVD: This makes it possible for authenticated attackers, with Subscriber-level access and above, to clear the plugin's cache.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-1832/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-18322/",
      "current_public_safe_latest": false,
      "cvss_score": 8.8,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.23888,
      "epss_score": 0.00314,
      "first_observed_at": "2026-08-12T05:08:50.991993+00:00",
      "id": "CVE-2026-18322",
      "impact_tags": [
        "privilege boundary review",
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-12T05:08:50.991993+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Smart Popup by Supsystic plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.12.0. NVD: This is due to a permission map collision in the havePermissions() function in classes/frame.php, where array_merge() overwrites the popup module's administrator-restricted method list with the base controller's value, silently removing save from protected... NVD: This makes it possible for unauthenticated attackers to submit a crafted POST request to admin-ajax.php using a nonce obtained from a public subscription confirmation email, setting params[tpl][sub_wp_create_user_role] to administrator via the exposed...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260812T051428Z/items/CVE-2026-18322.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes privilege escalation risk · remote exposure · authenticated boundary. Possible impact: A remote attacker may cross a privilege boundary and gain more access than intended.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Smart Popup by Supsystic plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.12.0. NVD: This is due to a permission map collision in the havePermissions() function in classes/frame.php, where array_merge() overwrites the popup module's administrator-restricted method list with the base controller's value, silently removing save from protected... NVD: This makes it possible for unauthenticated attackers to submit a crafted POST request to admin-ajax.php using a nonce obtained from a public subscription confirmation email, setting params[tpl][sub_wp_create_user_role] to administrator via the exposed...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-18322/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-18352/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.48833,
      "epss_score": 0.00676,
      "first_observed_at": "2026-08-08T15:50:31.311576+00:00",
      "id": "CVE-2026-18352",
      "impact_tags": [
        "information exposure review",
        "path traversal review",
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-08T21:49:51.726843+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The User Access Manager plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.3.15 via the 'uamgetfile' parameter parameter. NVD: This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information. NVD: This is possible because when attachment_url_to_postid() returns 0 for a traversal path, the plugin falls back to the global post set by a valid ?attachment_id parameter supplied by the attacker, causing the access check to pass against a legitimate public...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260808T215635Z/items/CVE-2026-18352.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes information exposure review · path traversal review · remote exposure. Possible impact: A remote attacker may be able to reach files outside the intended application path.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The User Access Manager plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.3.15 via the 'uamgetfile' parameter parameter. NVD: This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information. NVD: This is possible because when attachment_url_to_postid() returns 0 for a traversal path, the plugin falls back to the global post set by a valid ?attachment_id parameter supplied by the attacker, causing the access check to pass against a legitimate public...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-18352/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-18358/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.35216,
      "epss_score": 0.00428,
      "first_observed_at": "2026-08-07T10:13:53.604723+00:00",
      "id": "CVE-2026-18358",
      "impact_tags": [
        "remote exposure relevant"
      ],
      "kev": false,
      "last_observed_at": "2026-08-07T10:13:53.604723+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A flaw was found in gnome-remote-desktop as shipped in Red Hat Enterprise Linux. NVD: When the daemon is running in system mode with RDP enabled, the incoming connection handler bypasses the connection throttler, allowing an unauthenticated remote attacker to open many parallel pre-authentication connections to the RDP listener. NVD: This can accumulate accepted sockets and pending routing-token operations until timeout, exhausting resources and preventing legitimate users from establishing RDP sessions.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260807T102646Z/items/CVE-2026-18358.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes remote exposure. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A flaw was found in gnome-remote-desktop as shipped in Red Hat Enterprise Linux. NVD: When the daemon is running in system mode with RDP enabled, the incoming connection handler bypasses the connection throttler, allowing an unauthenticated remote attacker to open many parallel pre-authentication connections to the RDP listener. NVD: This can accumulate accepted sockets and pending routing-token operations until timeout, exhausting resources and preventing legitimate users from establishing RDP sessions.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-18358/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-18378/",
      "current_public_safe_latest": false,
      "cvss_score": 7.6,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.14968,
      "epss_score": 0.00239,
      "first_observed_at": "2026-08-06T11:35:20.545945+00:00",
      "id": "CVE-2026-18378",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-06T11:35:20.545945+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A flaw was found in koku-metrics-operator. NVD: The operator's CostManagementMetricsConfig custom resource allows user able to edit the CR to specify an arbitrary upload URL. NVD: When authentication.type is set to token (the default), the cluster-global Red Hat Cloud pull-secret bearer token is attached to HTTP requests sent to this user-controlled URL, allowing the attacker to obtain the token.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260806T114533Z/items/CVE-2026-18378.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A flaw was found in koku-metrics-operator. NVD: The operator's CostManagementMetricsConfig custom resource allows user able to edit the CR to specify an arbitrary upload URL. NVD: When authentication.type is set to token (the default), the cluster-global Red Hat Cloud pull-secret bearer token is attached to HTTP requests sent to this user-controlled URL, allowing the attacker to obtain the token.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-18378/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-18381/",
      "current_public_safe_latest": false,
      "cvss_score": 7.6,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.09594,
      "epss_score": 0.00197,
      "first_observed_at": "2026-08-06T11:35:20.545945+00:00",
      "id": "CVE-2026-18381",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-06T11:35:20.545945+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A flaw was found in the koku-metrics-operator for Red Hat OpenShift. NVD: The operator's CostManagementMetricsConfig custom resource allows a user able to edit the CR to specify an arbitrary upload URL. NVD: The operator attaches its own Kubernetes service-account bearer token to queries sent to this user-controlled URL, allowing the attacker to obtain the token.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260806T114533Z/items/CVE-2026-18381.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A flaw was found in the koku-metrics-operator for Red Hat OpenShift. NVD: The operator's CostManagementMetricsConfig custom resource allows a user able to edit the CR to specify an arbitrary upload URL. NVD: The operator attaches its own Kubernetes service-account bearer token to queries sent to this user-controlled URL, allowing the attacker to obtain the token.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-18381/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-18382/",
      "current_public_safe_latest": false,
      "cvss_score": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.20191,
      "epss_score": 0.0028,
      "first_observed_at": "2026-08-06T11:35:20.545945+00:00",
      "id": "CVE-2026-18382",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-06T11:35:20.545945+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A flaw was found in koku-metrics-operator. NVD: The operator's CostManagementMetricsConfig custom resource allows a user able to edit the CR to specify an arbitrary OAuth token endpoint. NVD: When authentication.type is set to service-account, the operator sends the tenant's Red Hat SSO client_id and client_secret to this user-controlled URL, allowing the attacker to obtain the credentials.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260806T114533Z/items/CVE-2026-18382.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A flaw was found in koku-metrics-operator. NVD: The operator's CostManagementMetricsConfig custom resource allows a user able to edit the CR to specify an arbitrary OAuth token endpoint. NVD: When authentication.type is set to service-account, the operator sends the tenant's Red Hat SSO client_id and client_secret to this user-controlled URL, allowing the attacker to obtain the credentials.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-18382/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-18436/",
      "current_public_safe_latest": false,
      "cvss_score": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.13467,
      "epss_score": 0.00227,
      "first_observed_at": "2026-08-07T10:13:53.604723+00:00",
      "id": "CVE-2026-18436",
      "impact_tags": [
        "unauthorized access risk",
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-07T10:13:53.604723+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The MailPress plugin for WordPress is vulnerable to unauthorized access in versions up to, and including, 1.5.0 via the campaign revision-restore REST endpoint (POST /wp-json/mailpress/v1/campaign/<id>/restore-revision/<revision_id>). NVD: The route in the vulnerable range was registered without a permissionCallback, allowing the restoreRevision() handler to run for unauthenticated requests and overwrite a campaign's content_html with any prior revision. NVD: This makes it possible for unauthenticated attackers to modify campaign content by restoring an arbitrary revision.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260807T102646Z/items/CVE-2026-18436.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes unauthorized access risk · remote exposure · authenticated boundary. Possible impact: A remote attacker may access resources that should require stronger authorization.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The MailPress plugin for WordPress is vulnerable to unauthorized access in versions up to, and including, 1.5.0 via the campaign revision-restore REST endpoint (POST /wp-json/mailpress/v1/campaign/<id>/restore-revision/<revision_id>). NVD: The route in the vulnerable range was registered without a permissionCallback, allowing the restoreRevision() handler to run for unauthenticated requests and overwrite a campaign's content_html with any prior revision. NVD: This makes it possible for unauthenticated attackers to modify campaign content by restoring an arbitrary revision.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-18436/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-18437/",
      "current_public_safe_latest": false,
      "cvss_score": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.2191,
      "epss_score": 0.00297,
      "first_observed_at": "2026-08-07T10:13:53.604723+00:00",
      "id": "CVE-2026-18437",
      "impact_tags": [
        "unauthorized access risk",
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-07T10:13:53.604723+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The MailerPress – Newsletter, email marketing & AI automation plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the mailerpress/v1/contact endpoint in all versions up to, and including, 1.5.0. NVD: This makes it possible for unauthenticated attackers to update contact details.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260807T102646Z/items/CVE-2026-18437.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes unauthorized access risk · remote exposure · authenticated boundary. Possible impact: A remote attacker may access resources that should require stronger authorization.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The MailerPress – Newsletter, email marketing & AI automation plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the mailerpress/v1/contact endpoint in all versions up to, and including, 1.5.0. NVD: This makes it possible for unauthenticated attackers to update contact details.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-18437/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-18477/",
      "current_public_safe_latest": false,
      "cvss_score": 4.4,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.01227,
      "epss_score": 0.00105,
      "first_observed_at": "2026-08-10T16:12:24.021737+00:00",
      "id": "CVE-2026-18477",
      "impact_tags": [
        "privilege boundary review",
        "local exposure relevant"
      ],
      "kev": false,
      "last_observed_at": "2026-08-10T16:12:24.021737+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A TOCTOU (Time-of-Check Time-of-Use) vulnerability in GNU tar's incremental dumpdir 'X' rename handling allows a local attacker with write access to a directory being backed up to influence the restore process if the attacker has access to the system where... NVD: During restoration, files or directories may be created, renamed or overwritten outside the intended extraction directory. NVD: This could lead to unauthorized file modification or, in some cases, privilege escalation.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260810T162156Z/items/CVE-2026-18477.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes privilege escalation risk · local exposure. Possible impact: A local user may cross a privilege boundary and gain more access than intended.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A TOCTOU (Time-of-Check Time-of-Use) vulnerability in GNU tar's incremental dumpdir 'X' rename handling allows a local attacker with write access to a directory being backed up to influence the restore process if the attacker has access to the system where... NVD: During restoration, files or directories may be created, renamed or overwritten outside the intended extraction directory. NVD: This could lead to unauthorized file modification or, in some cases, privilege escalation.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-18477/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-18508/",
      "current_public_safe_latest": false,
      "cvss_score": 4.4,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.03565,
      "epss_score": 0.00137,
      "first_observed_at": "2026-08-10T16:12:24.021737+00:00",
      "id": "CVE-2026-18508",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-10T16:12:24.021737+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A flaw was found in GNU tar. NVD: When extracting an archive with the --one-top-level option, hardlink targets are not confined to the designated top-level directory and may resolve relative to the extraction working directory. NVD: A crafted archive can create hardlinks that escape the intended boundary and, when combined with a preexisting symbolic link under the working directory, may allow writing outside that boundary during a single extraction.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260810T162156Z/items/CVE-2026-18508.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A flaw was found in GNU tar. NVD: When extracting an archive with the --one-top-level option, hardlink targets are not confined to the designated top-level directory and may resolve relative to the extraction working directory. NVD: A crafted archive can create hardlinks that escape the intended boundary and, when combined with a preexisting symbolic link under the working directory, may allow writing outside that boundary during a single extraction.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-18508/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "rrwo / data\\",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-18536/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.05099,
      "epss_score": 0.00154,
      "first_observed_at": "2026-08-08T09:56:53.105288+00:00",
      "id": "CVE-2026-18536",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-08T09:56:53.105288+00:00",
      "latest_item_url": null,
      "product": "data\\",
      "public_safe_summary": "NVD: Data::Entropy versions before 0.010 for Perl read remote entropy sources over plain HTTP. NVD: The Data::Entropy::RawSource::RandomOrg and Data::Entropy::RawSource::RandomnumbersInfo remote sources are accessed over plain HTTP. NVD: The Data::Entropy::RawSource::RandomOrg integrity check trivially matches any non-empty byte string.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260808T100051Z/items/CVE-2026-18536.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: rrwo / data\\; affected version context: \\",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Data::Entropy versions before 0.010 for Perl read remote entropy sources over plain HTTP. NVD: The Data::Entropy::RawSource::RandomOrg and Data::Entropy::RawSource::RandomnumbersInfo remote sources are accessed over plain HTTP. NVD: The Data::Entropy::RawSource::RandomOrg integrity check trivially matches any non-empty byte string.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-18536/timeline.json",
      "vendor": "rrwo"
    },
    {
      "affected_label": "n-able / n-central",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-18556/",
      "current_public_safe_latest": false,
      "cvss_score": 8.2,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.39696,
      "epss_score": 0.00492,
      "first_observed_at": "2026-08-08T15:50:31.311576+00:00",
      "id": "CVE-2026-18556",
      "impact_tags": [
        "authentication boundary review"
      ],
      "kev": true,
      "last_observed_at": "2026-08-08T15:50:31.311576+00:00",
      "latest_item_url": null,
      "product": "n-central",
      "public_safe_summary": "NVD: Authentication bypass using an alternate path or channel vulnerability in N-able N-central allows Authentication Bypass. NVD: This issue affects N-central: through 2026.1. CISA KEV: N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260808T155819Z/items/CVE-2026-18556.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: n-able / n-central",
      "source_published_impact": "Source describes known exploited catalog listed · authentication boundary review. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for known exploited catalog listed · authentication boundary review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Authentication bypass using an alternate path or channel vulnerability in N-able N-central allows Authentication Bypass. NVD: This issue affects N-central: through 2026.1. CISA KEV: N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability",
      "sources": [
        "NVD",
        "CISA KEV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-18556/timeline.json",
      "vendor": "n-able"
    },
    {
      "affected_label": "xml\\ / \\",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-18568/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.08907,
      "epss_score": 0.00191,
      "first_observed_at": "2026-08-10T16:12:24.021737+00:00",
      "id": "CVE-2026-18568",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-10T16:12:24.021737+00:00",
      "latest_item_url": null,
      "product": "\\",
      "public_safe_summary": "NVD: XML::Sig versions from 0.29 before 0.72 for Perl allow signature verification bypass because verify returns true when every signature was skipped before any cryptographic check. NVD: verify in lib/XML/Sig.pm counts the //dsig:Signature elements into $numsigs and iterates over them, but two paths reach next before any digest or key check runs: a SignedInfo/Reference/@URI that resolves to no element while $numsigs is greater than 1, and... NVD: The loop records nothing about what it checked, so when every signature takes one of those paths control reaches the unconditional return 1 that ends verify.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260810T162156Z/items/CVE-2026-18568.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: xml\\ / \\; affected version context: sig_project",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: XML::Sig versions from 0.29 before 0.72 for Perl allow signature verification bypass because verify returns true when every signature was skipped before any cryptographic check. NVD: verify in lib/XML/Sig.pm counts the //dsig:Signature elements into $numsigs and iterates over them, but two paths reach next before any digest or key check runs: a SignedInfo/Reference/@URI that resolves to no element while $numsigs is greater than 1, and... NVD: The loop records nothing about what it checked, so when every signature takes one of those paths control reaches the unconditional return 1 that ends verify.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-18568/timeline.json",
      "vendor": "xml\\"
    },
    {
      "affected_label": "redhat / build_of_keycloak",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-18569/",
      "current_public_safe_latest": false,
      "cvss_score": 3.7,
      "cvss_severity": "LOW",
      "epss_percentile": 0.05786,
      "epss_score": 0.00162,
      "first_observed_at": "2026-08-11T04:43:10.985977+00:00",
      "id": "CVE-2026-18569",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-11T04:43:10.985977+00:00",
      "latest_item_url": null,
      "product": "build_of_keycloak",
      "public_safe_summary": "NVD: A flaw was found in the backchannel logout endpoint of the keycloak-services component, which is part of the Red Hat Build of Keycloak. NVD: This component handles authentication and session management for applications. NVD: The issue occurs when an OIDC identity provider is configured to skip signature validation.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260811T044729Z/items/CVE-2026-18569.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: redhat / build_of_keycloak; affected version context: -",
      "source_published_impact": "This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A flaw was found in the backchannel logout endpoint of the keycloak-services component, which is part of the Red Hat Build of Keycloak. NVD: This component handles authentication and session management for applications. NVD: The issue occurs when an OIDC identity provider is configured to skip signature validation.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-18569/timeline.json",
      "vendor": "redhat"
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-18574/",
      "current_public_safe_latest": false,
      "cvss_score": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.59256,
      "epss_score": 0.00991,
      "first_observed_at": "2026-08-10T10:38:36.347227+00:00",
      "id": "CVE-2026-18574",
      "impact_tags": [
        "authentication boundary review",
        "remote exposure relevant"
      ],
      "kev": false,
      "last_observed_at": "2026-08-10T10:38:36.347227+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: An authentication bypass vulnerability in Check Point Security Management Server and Multi-Domain Security Management Server (MDS) could allow an unauthenticated remote attacker with network access to Management services to execute arbitrary commands on the... NVD: Successful exploitation could result in full compromise of the Security Management system. NVD: Check Point discovered this issue internally and has no indication of active exploitation.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260810T105121Z/items/CVE-2026-18574.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes authentication boundary review · remote exposure. Possible impact: This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authentication boundary review · remote exposure.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: An authentication bypass vulnerability in Check Point Security Management Server and Multi-Domain Security Management Server (MDS) could allow an unauthenticated remote attacker with network access to Management services to execute arbitrary commands on the... NVD: Successful exploitation could result in full compromise of the Security Management system. NVD: Check Point discovered this issue internally and has no indication of active exploitation.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-18574/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "n-able / n-central",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-18577/",
      "current_public_safe_latest": false,
      "cvss_score": 8.2,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.89787,
      "epss_score": 0.04103,
      "first_observed_at": "2026-08-09T09:59:30.349754+00:00",
      "id": "CVE-2026-18577",
      "impact_tags": [
        "authentication boundary review"
      ],
      "kev": true,
      "last_observed_at": "2026-08-09T21:51:57.260007+00:00",
      "latest_item_url": null,
      "product": "n-central",
      "public_safe_summary": "NVD: An incomplete patch for CVE-2026-18556 allows for authentication bypass and account takeover in N-central Versions through 2026.3.1 CISA KEV: N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260809T215750Z/items/CVE-2026-18577.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 3,
      "source_published_affected": "vendor/product: n-able / n-central; affected version context: 2026.3",
      "source_published_impact": "Source describes known exploited catalog listed · authentication boundary review. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for known exploited catalog listed · authentication boundary review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: An incomplete patch for CVE-2026-18556 allows for authentication bypass and account takeover in N-central Versions through 2026.3.1 CISA KEV: N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability",
      "sources": [
        "NVD",
        "CISA KEV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-18577/timeline.json",
      "vendor": "n-able"
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-18581/",
      "current_public_safe_latest": false,
      "cvss_score": 1.9,
      "cvss_severity": "LOW",
      "epss_percentile": 0.01587,
      "epss_score": 0.00112,
      "first_observed_at": "2026-08-09T09:59:30.349754+00:00",
      "id": "CVE-2026-18581",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-09T21:51:57.260007+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A vulnerability was determined in ggml-org llama.cpp e15efe0. NVD: Affected by this issue is some unknown functionality of the file common/jinja/parser.cpp of the component Jinja Minja Template Parser. NVD: Executing a manipulation with the input {{9|9|{ can lead to reachable assertion.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260809T215750Z/items/CVE-2026-18581.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 3,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability was determined in ggml-org llama.cpp e15efe0. NVD: Affected by this issue is some unknown functionality of the file common/jinja/parser.cpp of the component Jinja Minja Template Parser. NVD: Executing a manipulation with the input {{9|9|{ can lead to reachable assertion.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-18581/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-18583/",
      "current_public_safe_latest": false,
      "cvss_score": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.3994,
      "epss_score": 0.00496,
      "first_observed_at": "2026-08-10T04:58:31.923491+00:00",
      "id": "CVE-2026-18583",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-10T04:58:31.923491+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A weakness has been identified in mz-automation libiec61850 up to 1.6.1. NVD: This issue affects the function checkDataSetAccess of the file src/iec61850/server/mms_mapping/mms_mapping.c of the component MMS Request Handler. NVD: This manipulation causes out-of-bounds read.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260810T050414Z/items/CVE-2026-18583.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A weakness has been identified in mz-automation libiec61850 up to 1.6.1. NVD: This issue affects the function checkDataSetAccess of the file src/iec61850/server/mms_mapping/mms_mapping.c of the component MMS Request Handler. NVD: This manipulation causes out-of-bounds read.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-18583/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-18584/",
      "current_public_safe_latest": false,
      "cvss_score": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.13827,
      "epss_score": 0.0023,
      "first_observed_at": "2026-08-10T04:58:31.923491+00:00",
      "id": "CVE-2026-18584",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-10T04:58:31.923491+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A security vulnerability has been detected in GL.iNet E5800, E750, X2000, X3000, XE3000 and XE300 up to 20260707. NVD: Impacted is an unknown function of the file /sdk/v1 of the component eSIM LPA API. NVD: Such manipulation leads to improper authorization.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260810T050414Z/items/CVE-2026-18584.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A security vulnerability has been detected in GL.iNet E5800, E750, X2000, X3000, XE3000 and XE300 up to 20260707. NVD: Impacted is an unknown function of the file /sdk/v1 of the component eSIM LPA API. NVD: Such manipulation leads to improper authorization.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-18584/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-18585/",
      "current_public_safe_latest": false,
      "cvss_score": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.22167,
      "epss_score": 0.00299,
      "first_observed_at": "2026-08-10T04:58:31.923491+00:00",
      "id": "CVE-2026-18585",
      "impact_tags": [
        "memory safety review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-10T04:58:31.923491+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A vulnerability was detected in GL.iNet MT3000, MT6000, BE9300, BE3600, MT3600BE, E5800, BE6500, MT5000, X3000, XE3000 and MT2500 up to 20260707. NVD: The affected element is the function nas-web.get_file_list of the component APPS-NAS Module. NVD: Performing a manipulation results in heap-based buffer overflow.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260810T050414Z/items/CVE-2026-18585.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes memory safety review. Possible impact: The affected component has memory-safety risk that may lead to crash, privilege, or code-execution impact depending on exposure.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability was detected in GL.iNet MT3000, MT6000, BE9300, BE3600, MT3600BE, E5800, BE6500, MT5000, X3000, XE3000 and MT2500 up to 20260707. NVD: The affected element is the function nas-web.get_file_list of the component APPS-NAS Module. NVD: Performing a manipulation results in heap-based buffer overflow.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-18585/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-18598/",
      "current_public_safe_latest": false,
      "cvss_score": 7.4,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.74285,
      "epss_score": 0.01652,
      "first_observed_at": "2026-08-10T10:38:36.347227+00:00",
      "id": "CVE-2026-18598",
      "impact_tags": [
        "command injection risk"
      ],
      "kev": false,
      "last_observed_at": "2026-08-10T10:38:36.347227+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A vulnerability was detected in GL.iNet GL-MT3000 up to 4.4.5. NVD: The affected element is the function logread.get_system_log of the file /usr/lib/oui-httpd/rpc/logread of the component Logread Lua RPC plugin. NVD: The manipulation of the argument module results in command injection.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260810T105121Z/items/CVE-2026-18598.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes command injection risk. Possible impact: An attacker may be able to run unintended system commands through the affected component.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability was detected in GL.iNet GL-MT3000 up to 4.4.5. NVD: The affected element is the function logread.get_system_log of the file /usr/lib/oui-httpd/rpc/logread of the component Logread Lua RPC plugin. NVD: The manipulation of the argument module results in command injection.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-18598/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-18599/",
      "current_public_safe_latest": false,
      "cvss_score": 7.3,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.69845,
      "epss_score": 0.01397,
      "first_observed_at": "2026-08-10T10:38:36.347227+00:00",
      "id": "CVE-2026-18599",
      "impact_tags": [
        "command injection risk"
      ],
      "kev": false,
      "last_observed_at": "2026-08-10T10:38:36.347227+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A flaw has been found in GL.iNet GL-MT3000 up to 4.4.5. NVD: The impacted element is the function logread.set_config of the file /usr/lib/oui-httpd/rpc/logread of the component Logread Lua RPC Plugin. NVD: This manipulation of the argument record_size causes command injection.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260810T105121Z/items/CVE-2026-18599.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes command injection risk. Possible impact: An attacker may be able to run unintended system commands through the affected component.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A flaw has been found in GL.iNet GL-MT3000 up to 4.4.5. NVD: The impacted element is the function logread.set_config of the file /usr/lib/oui-httpd/rpc/logread of the component Logread Lua RPC Plugin. NVD: This manipulation of the argument record_size causes command injection.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-18599/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-18600/",
      "current_public_safe_latest": false,
      "cvss_score": 7.4,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.78597,
      "epss_score": 0.01977,
      "first_observed_at": "2026-08-10T10:38:36.347227+00:00",
      "id": "CVE-2026-18600",
      "impact_tags": [
        "command injection risk"
      ],
      "kev": false,
      "last_observed_at": "2026-08-10T10:38:36.347227+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A vulnerability has been found in GL.iNet GL-MT3000 up to 4.4.5. NVD: This affects the function network.switch_info/network.switch_status of the file /usr/lib/oui-httpd/rpc/network of the component Network Lua RPC Plugin. NVD: Such manipulation of the argument switch leads to command injection.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260810T105121Z/items/CVE-2026-18600.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes command injection risk. Possible impact: An attacker may be able to run unintended system commands through the affected component.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability has been found in GL.iNet GL-MT3000 up to 4.4.5. NVD: This affects the function network.switch_info/network.switch_status of the file /usr/lib/oui-httpd/rpc/network of the component Network Lua RPC Plugin. NVD: Such manipulation of the argument switch leads to command injection.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-18600/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-18601/",
      "current_public_safe_latest": false,
      "cvss_score": 8.9,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.82293,
      "epss_score": 0.0238,
      "first_observed_at": "2026-08-10T10:38:36.347227+00:00",
      "id": "CVE-2026-18601",
      "impact_tags": [
        "command injection risk"
      ],
      "kev": false,
      "last_observed_at": "2026-08-10T10:38:36.347227+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A vulnerability was found in GL.iNet GL-MT3000 up to 4.4.5. NVD: This impacts the function ovpn-client.check_config of the file /cgi-bin/glc of the component ovpn-client.so Native Plugin. NVD: Performing a manipulation of the argument filename results in command injection.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260810T105121Z/items/CVE-2026-18601.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes command injection risk. Possible impact: An attacker may be able to run unintended system commands through the affected component.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability was found in GL.iNet GL-MT3000 up to 4.4.5. NVD: This impacts the function ovpn-client.check_config of the file /cgi-bin/glc of the component ovpn-client.so Native Plugin. NVD: Performing a manipulation of the argument filename results in command injection.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-18601/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-18602/",
      "current_public_safe_latest": false,
      "cvss_score": 8.9,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.78725,
      "epss_score": 0.01989,
      "first_observed_at": "2026-08-10T16:12:24.021737+00:00",
      "id": "CVE-2026-18602",
      "impact_tags": [
        "command injection risk"
      ],
      "kev": false,
      "last_observed_at": "2026-08-10T16:12:24.021737+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A vulnerability was determined in GL.iNet GL-MT3000 up to 4.4.5. NVD: Affected is the function ovpn-client.get_recommend_config of the file /cgi-bin/glc of the component ovpn-client.so Native Plugin. NVD: Executing a manipulation of the argument Hostname can lead to command injection.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260810T162156Z/items/CVE-2026-18602.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes command injection risk. Possible impact: An attacker may be able to run unintended system commands through the affected component.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability was determined in GL.iNet GL-MT3000 up to 4.4.5. NVD: Affected is the function ovpn-client.get_recommend_config of the file /cgi-bin/glc of the component ovpn-client.so Native Plugin. NVD: Executing a manipulation of the argument Hostname can lead to command injection.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-18602/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-18604/",
      "current_public_safe_latest": false,
      "cvss_score": 1.9,
      "cvss_severity": "LOW",
      "epss_percentile": 0.01108,
      "epss_score": 0.00103,
      "first_observed_at": "2026-08-10T16:12:24.021737+00:00",
      "id": "CVE-2026-18604",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-10T16:12:24.021737+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A vulnerability was identified in textPlus Text Message and Call App up to 8.3.5 on Android. NVD: This impacts the function DialerActivity of the component com.gogii.textplus. NVD: Such manipulation leads to improper export of android application components.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260810T162156Z/items/CVE-2026-18604.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability was identified in textPlus Text Message and Call App up to 8.3.5 on Android. NVD: This impacts the function DialerActivity of the component com.gogii.textplus. NVD: Such manipulation leads to improper export of android application components.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-18604/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-18605/",
      "current_public_safe_latest": false,
      "cvss_score": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.01889,
      "epss_score": 0.00116,
      "first_observed_at": "2026-08-10T16:12:24.021737+00:00",
      "id": "CVE-2026-18605",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-10T16:12:24.021737+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A security flaw has been discovered in CheckMAL AppCheck Pro 3.1.43.10. NVD: Affected is an unknown function in the library AppCheckD.sys of the component Kernel Mini-Filter Driver. NVD: Performing a manipulation results in uncontrolled search path.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260810T162156Z/items/CVE-2026-18605.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A security flaw has been discovered in CheckMAL AppCheck Pro 3.1.43.10. NVD: Affected is an unknown function in the library AppCheckD.sys of the component Kernel Mini-Filter Driver. NVD: Performing a manipulation results in uncontrolled search path.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-18605/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-18606/",
      "current_public_safe_latest": false,
      "cvss_score": 7.1,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.01509,
      "epss_score": 0.00111,
      "first_observed_at": "2026-08-10T16:12:24.021737+00:00",
      "id": "CVE-2026-18606",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-10T16:12:24.021737+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A weakness has been identified in Razer RzUpdateService 1.10.14.0. NVD: Affected by this vulnerability is an unknown functionality of the file C:\\Program Files (x86)\\Razer\\RzUpdateEngineService\\RzUpdateService.exe of the component Named Pipe Handler. NVD: Executing a manipulation of the argument lpThreadParameter can lead to improper privilege management.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260810T162156Z/items/CVE-2026-18606.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A weakness has been identified in Razer RzUpdateService 1.10.14.0. NVD: Affected by this vulnerability is an unknown functionality of the file C:\\Program Files (x86)\\Razer\\RzUpdateEngineService\\RzUpdateService.exe of the component Named Pipe Handler. NVD: Executing a manipulation of the argument lpThreadParameter can lead to improper privilege management.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-18606/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-18607/",
      "current_public_safe_latest": false,
      "cvss_score": 7.4,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.36042,
      "epss_score": 0.00438,
      "first_observed_at": "2026-08-10T16:12:24.021737+00:00",
      "id": "CVE-2026-18607",
      "impact_tags": [
        "memory safety review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-10T16:12:24.021737+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A security vulnerability has been detected in Wavlink WN572, WN570H, WN573, WN529, WN530, WN531, WN535, etc. NVD: WN529, WN530, WN531, WN535, WN536, WN551, WN557 and NU516 up to 20260609. NVD: Affected by this issue is the function strcpy of the file upload.cgi of the component lighttpd.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260810T162156Z/items/CVE-2026-18607.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes memory safety review. Possible impact: The affected component has memory-safety risk that may lead to crash, privilege, or code-execution impact depending on exposure.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A security vulnerability has been detected in Wavlink WN572, WN570H, WN573, WN529, WN530, WN531, WN535, etc. NVD: WN529, WN530, WN531, WN535, WN536, WN551, WN557 and NU516 up to 20260609. NVD: Affected by this issue is the function strcpy of the file upload.cgi of the component lighttpd.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-18607/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-18610/",
      "current_public_safe_latest": false,
      "cvss_score": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.32478,
      "epss_score": 0.00397,
      "first_observed_at": "2026-08-10T16:12:24.021737+00:00",
      "id": "CVE-2026-18610",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-10T16:12:24.021737+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A vulnerability was detected in NewType WebEIP up to 3.0. NVD: This affects an unknown part of the file /EIP_Com_FileList.aspx. NVD: The manipulation results in improper authentication.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260810T162156Z/items/CVE-2026-18610.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability was detected in NewType WebEIP up to 3.0. NVD: This affects an unknown part of the file /EIP_Com_FileList.aspx. NVD: The manipulation results in improper authentication.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-18610/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-18642/",
      "current_public_safe_latest": false,
      "cvss_score": 7.8,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.03298,
      "epss_score": 0.00134,
      "first_observed_at": "2026-08-10T10:38:36.347227+00:00",
      "id": "CVE-2026-18642",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-10T10:38:36.347227+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Deserialization of untrusted data vulnerability in TUBITAK BILGEM Software Technologies Research Institute eta-otp-lock allows Object Injection. NVD: This issue affects eta-otp-lock: before 1.0.4.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260810T105121Z/items/CVE-2026-18642.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Deserialization of untrusted data vulnerability in TUBITAK BILGEM Software Technologies Research Institute eta-otp-lock allows Object Injection. NVD: This issue affects eta-otp-lock: before 1.0.4.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-18642/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "redhat / directory_server",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-18651/",
      "current_public_safe_latest": false,
      "cvss_score": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.06287,
      "epss_score": 0.00167,
      "first_observed_at": "2026-08-10T16:12:24.021737+00:00",
      "id": "CVE-2026-18651",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-10T16:12:24.021737+00:00",
      "latest_item_url": null,
      "product": "directory_server",
      "public_safe_summary": "NVD: A flaw was found in 389 Directory Server. NVD: During SASL PLAIN authentication, the server installs connection-level bind credentials before performing the account-lock check. NVD: If the account is subsequently found to be locked, the bind is reported as failed to the client, but the already-installed authenticated state on the connection is not reverted.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260810T162156Z/items/CVE-2026-18651.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: redhat / directory_server; affected version context: -, 10.0, 11.0, 12.0, 13.0",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A flaw was found in 389 Directory Server. NVD: During SASL PLAIN authentication, the server installs connection-level bind credentials before performing the account-lock check. NVD: If the account is subsequently found to be locked, the bind is reported as failed to the client, but the already-installed authenticated state on the connection is not reverted.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-18651/timeline.json",
      "vendor": "redhat"
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-18667/",
      "current_public_safe_latest": false,
      "cvss_score": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.32019,
      "epss_score": 0.00392,
      "first_observed_at": "2026-08-10T22:01:27.436532+00:00",
      "id": "CVE-2026-18667",
      "impact_tags": [
        "remote exposure relevant"
      ],
      "kev": false,
      "last_observed_at": "2026-08-10T22:01:27.436532+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A vulnerability in Tenable Sensor Proxy allows a remote attacker to execute code with elevated privileges by inducing an operator to connect the sensor to an attacker-controlled host.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260810T220919Z/items/CVE-2026-18667.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes remote exposure. Possible impact: This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability in Tenable Sensor Proxy allows a remote attacker to execute code with elevated privileges by inducing an operator to connect the sensor to an attacker-controlled host.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-18667/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-18682/",
      "current_public_safe_latest": false,
      "cvss_score": 1.3,
      "cvss_severity": "LOW",
      "epss_percentile": 0.15975,
      "epss_score": 0.00247,
      "first_observed_at": "2026-08-10T22:01:27.436532+00:00",
      "id": "CVE-2026-18682",
      "impact_tags": [
        "XSS risk"
      ],
      "kev": false,
      "last_observed_at": "2026-08-10T22:01:27.436532+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A security flaw has been discovered in OpenAkita up to 1.27.12. NVD: This vulnerability affects unknown code of the file /api/upload of the component File Upload API. NVD: The manipulation of the argument File results in cross site scripting.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260810T220919Z/items/CVE-2026-18682.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes XSS risk. Possible impact: This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A security flaw has been discovered in OpenAkita up to 1.27.12. NVD: This vulnerability affects unknown code of the file /api/upload of the component File Upload API. NVD: The manipulation of the argument File results in cross site scripting.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-18682/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-18684/",
      "current_public_safe_latest": false,
      "cvss_score": 8.9,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.7918,
      "epss_score": 0.02028,
      "first_observed_at": "2026-08-10T22:01:27.436532+00:00",
      "id": "CVE-2026-18684",
      "impact_tags": [
        "command injection risk"
      ],
      "kev": false,
      "last_observed_at": "2026-08-10T22:01:27.436532+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A weakness has been identified in GL.iNet GL-MT3000 up to 4.4.5. NVD: This issue affects the function remove_profile of the file /cgi-bin/glc of the component modem.so. NVD: This manipulation causes command injection.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260810T220919Z/items/CVE-2026-18684.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes command injection risk. Possible impact: An attacker may be able to run unintended system commands through the affected component.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A weakness has been identified in GL.iNet GL-MT3000 up to 4.4.5. NVD: This issue affects the function remove_profile of the file /cgi-bin/glc of the component modem.so. NVD: This manipulation causes command injection.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-18684/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-18718/",
      "current_public_safe_latest": false,
      "cvss_score": 7.1,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.10763,
      "epss_score": 0.00206,
      "first_observed_at": "2026-08-10T16:12:24.021737+00:00",
      "id": "CVE-2026-18718",
      "impact_tags": [
        "code execution review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-10T16:12:24.021737+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Ghidra contains an arbitrary code execution vulnerability in the Swift demangler analyzer that allows an attacker to execute arbitrary binaries by supplying a malicious Ghidra project with a crafted Swift tool directory path. NVD: When a victim opens the attacker-supplied project, SwiftDemanglerAnalyzer restores the persisted Swift binary directory from project state and SwiftNativeDemangler executes the resolved binary without integrity or signature verification, causing... OSV: Ghidra Swift Demangler Analyzer Arbitrary Code Execution via Project State",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260810T162156Z/items/CVE-2026-18718.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes code execution review. Possible impact: An attacker may be able to run code or commands on affected systems.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Ghidra contains an arbitrary code execution vulnerability in the Swift demangler analyzer that allows an attacker to execute arbitrary binaries by supplying a malicious Ghidra project with a crafted Swift tool directory path. NVD: When a victim opens the attacker-supplied project, SwiftDemanglerAnalyzer restores the persisted Swift binary directory from project state and SwiftNativeDemangler executes the resolved binary without integrity or signature verification, causing... OSV: Ghidra Swift Demangler Analyzer Arbitrary Code Execution via Project State",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-18718/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-18739/",
      "current_public_safe_latest": false,
      "cvss_score": 2.5,
      "cvss_severity": "LOW",
      "epss_percentile": 0.00721,
      "epss_score": 0.00095,
      "first_observed_at": "2026-08-11T04:43:10.985977+00:00",
      "id": "CVE-2026-18739",
      "impact_tags": [
        "code execution review",
        "local exposure relevant"
      ],
      "kev": false,
      "last_observed_at": "2026-08-11T04:43:10.985977+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A flaw was found in popt, a command-line option parsing library. NVD: An off-by-one error in the poptStuffArgs function, when repeatedly called by a host application or through deep alias nesting, can lead to corruption of internal program data. NVD: This corruption could potentially enable a local attacker to execute arbitrary code if the host application then unsafely processes the altered data.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260811T044729Z/items/CVE-2026-18739.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes code execution review · local exposure. Possible impact: A local user may be able to run code or commands on affected systems.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A flaw was found in popt, a command-line option parsing library. NVD: An off-by-one error in the poptStuffArgs function, when repeatedly called by a host application or through deep alias nesting, can lead to corruption of internal program data. NVD: This corruption could potentially enable a local attacker to execute arbitrary code if the host application then unsafely processes the altered data.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-18739/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-18772/",
      "current_public_safe_latest": false,
      "cvss_score": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.03141,
      "epss_score": 0.00132,
      "first_observed_at": "2026-08-11T10:14:04.199465+00:00",
      "id": "CVE-2026-18772",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-11T10:14:04.199465+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Improperly controlled sequential memory allocation vulnerability in Samsung Open Source rlottie allows Exponential Data Expansion.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260811T102539Z/items/CVE-2026-18772.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Improperly controlled sequential memory allocation vulnerability in Samsung Open Source rlottie allows Exponential Data Expansion.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-18772/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-18806/",
      "current_public_safe_latest": false,
      "cvss_score": 7.1,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.01045,
      "epss_score": 0.00101,
      "first_observed_at": "2026-08-11T10:14:04.199465+00:00",
      "id": "CVE-2026-18806",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-11T10:14:04.199465+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: External control of file name or path vulnerability in TÜBİTAK BİLGEM Software Technologies Research Institute pardus-image-writer allows Removing Important Client Functionality. NVD: This issue affects pardus-image-writer: before 0.9.0.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260811T102539Z/items/CVE-2026-18806.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: External control of file name or path vulnerability in TÜBİTAK BİLGEM Software Technologies Research Institute pardus-image-writer allows Removing Important Client Functionality. NVD: This issue affects pardus-image-writer: before 0.9.0.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-18806/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-18809/",
      "current_public_safe_latest": false,
      "cvss_score": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.11351,
      "epss_score": 0.00211,
      "first_observed_at": "2026-08-11T10:14:04.199465+00:00",
      "id": "CVE-2026-18809",
      "impact_tags": [
        "information exposure review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-11T10:14:04.199465+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Information disclosure in Firefox for Android and Firefox Focus for Android. NVD: This vulnerability was fixed in Firefox 153.0.3.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260811T102539Z/items/CVE-2026-18809.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes information exposure review. Possible impact: An attacker may be able to access information that should not be exposed.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: Firefox.",
      "source_published_summary": "NVD: Information disclosure in Firefox for Android and Firefox Focus for Android. NVD: This vulnerability was fixed in Firefox 153.0.3.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-18809/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-18814/",
      "current_public_safe_latest": false,
      "cvss_score": 7.3,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.84563,
      "epss_score": 0.02705,
      "first_observed_at": "2026-08-11T22:08:35.096641+00:00",
      "id": "CVE-2026-18814",
      "impact_tags": [
        "command injection risk"
      ],
      "kev": false,
      "last_observed_at": "2026-08-11T22:08:35.096641+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A vulnerability was found in H3C NX15 V100R017. NVD: This impacts the function reload.reload_config of the file /api/esps. NVD: The manipulation results in command injection.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260811T221806Z/items/CVE-2026-18814.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes command injection risk. Possible impact: An attacker may be able to run unintended system commands through the affected component.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability was found in H3C NX15 V100R017. NVD: This impacts the function reload.reload_config of the file /api/esps. NVD: The manipulation results in command injection.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-18814/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-18816/",
      "current_public_safe_latest": false,
      "cvss_score": 2.3,
      "cvss_severity": "LOW",
      "epss_percentile": 0.26628,
      "epss_score": 0.00339,
      "first_observed_at": "2026-08-11T22:08:35.096641+00:00",
      "id": "CVE-2026-18816",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-11T22:08:35.096641+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A vulnerability was identified in Baserow up to 2.3.2. NVD: Affected by this vulnerability is the function verify of the file backend/src/baserow/api/two_factor_auth/views.py of the component 2FA Verify Endpoint. NVD: Such manipulation leads to improper authentication.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260811T221806Z/items/CVE-2026-18816.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: of.",
      "source_published_summary": "NVD: A vulnerability was identified in Baserow up to 2.3.2. NVD: Affected by this vulnerability is the function verify of the file backend/src/baserow/api/two_factor_auth/views.py of the component 2FA Verify Endpoint. NVD: Such manipulation leads to improper authentication.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-18816/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-18817/",
      "current_public_safe_latest": false,
      "cvss_score": 2.1,
      "cvss_severity": "LOW",
      "epss_percentile": 0.10429,
      "epss_score": 0.00203,
      "first_observed_at": "2026-08-11T22:08:35.096641+00:00",
      "id": "CVE-2026-18817",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-11T22:08:35.096641+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A security flaw has been discovered in Baserow up to 2.3.2. NVD: Affected by this issue is the function BaserowImpersonateAuthTokenSerializer of the file backend/src/baserow/api/admin/users/serializers.py of the component Inactive Non-Staff User Handler. NVD: Performing a manipulation results in improper authorization.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260811T221806Z/items/CVE-2026-18817.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A security flaw has been discovered in Baserow up to 2.3.2. NVD: Affected by this issue is the function BaserowImpersonateAuthTokenSerializer of the file backend/src/baserow/api/admin/users/serializers.py of the component Inactive Non-Staff User Handler. NVD: Performing a manipulation results in improper authorization.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-18817/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-18900/",
      "current_public_safe_latest": false,
      "cvss_score": 7.3,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.8235,
      "epss_score": 0.02384,
      "first_observed_at": "2026-08-12T05:08:50.991993+00:00",
      "id": "CVE-2026-18900",
      "impact_tags": [
        "command injection risk"
      ],
      "kev": false,
      "last_observed_at": "2026-08-12T05:08:50.991993+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A weakness has been identified in H3C NX15 V100R017. NVD: This impacts the function file.exec of the file /api/esps of the component Backend RPC. NVD: This manipulation of the argument File causes os command injection.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260812T051428Z/items/CVE-2026-18900.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes command injection risk. Possible impact: An attacker may be able to run unintended system commands through the affected component.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A weakness has been identified in H3C NX15 V100R017. NVD: This impacts the function file.exec of the file /api/esps of the component Backend RPC. NVD: This manipulation of the argument File causes os command injection.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-18900/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-18901/",
      "current_public_safe_latest": false,
      "cvss_score": 7.3,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.37337,
      "epss_score": 0.00454,
      "first_observed_at": "2026-08-12T05:08:50.991993+00:00",
      "id": "CVE-2026-18901",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-12T05:08:50.991993+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A security vulnerability has been detected in H3C NX15 V100R017. NVD: Affected is the function service.add of the file /api/esps of the component Web API. NVD: Such manipulation leads to exposed dangerous routine.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260812T051428Z/items/CVE-2026-18901.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A security vulnerability has been detected in H3C NX15 V100R017. NVD: Affected is the function service.add of the file /api/esps of the component Web API. NVD: Such manipulation leads to exposed dangerous routine.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-18901/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-18902/",
      "current_public_safe_latest": false,
      "cvss_score": 7.3,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.8235,
      "epss_score": 0.02384,
      "first_observed_at": "2026-08-12T05:08:50.991993+00:00",
      "id": "CVE-2026-18902",
      "impact_tags": [
        "command injection risk"
      ],
      "kev": false,
      "last_observed_at": "2026-08-12T05:08:50.991993+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A vulnerability was detected in H3C NX15 V100R017. NVD: Affected by this vulnerability is the function esps.wan.repeater.set/repeaterproc of the file /api/esps. NVD: Performing a manipulation of the argument my2P4key results in command injection.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260812T051428Z/items/CVE-2026-18902.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes command injection risk. Possible impact: An attacker may be able to run unintended system commands through the affected component.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability was detected in H3C NX15 V100R017. NVD: Affected by this vulnerability is the function esps.wan.repeater.set/repeaterproc of the file /api/esps. NVD: Performing a manipulation of the argument my2P4key results in command injection.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-18902/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-18903/",
      "current_public_safe_latest": false,
      "cvss_score": 2.1,
      "cvss_severity": "LOW",
      "epss_percentile": 0.28568,
      "epss_score": 0.00357,
      "first_observed_at": "2026-08-12T05:08:50.991993+00:00",
      "id": "CVE-2026-18903",
      "impact_tags": [
        "path traversal review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-12T05:08:50.991993+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A vulnerability was determined in yeqifu warehouse up to aaf29962ba407d22d991781de28796ee7b4670e4. NVD: This issue affects some unknown processing of the file src/main/java/com/yeqifu/sys/controller/FileController.java. NVD: This manipulation of the argument path causes path traversal.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260812T051428Z/items/CVE-2026-18903.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes path traversal review. Possible impact: An attacker may be able to reach files outside the intended application path.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability was determined in yeqifu warehouse up to aaf29962ba407d22d991781de28796ee7b4670e4. NVD: This issue affects some unknown processing of the file src/main/java/com/yeqifu/sys/controller/FileController.java. NVD: This manipulation of the argument path causes path traversal.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-18903/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "cisco / identity_services_engine_passive_identity_connector",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-20146/",
      "current_public_safe_latest": false,
      "cvss_score": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.26447,
      "epss_score": 0.0034,
      "first_observed_at": "2026-07-22T16:52:32.770874+00:00",
      "id": "CVE-2026-20146",
      "impact_tags": [
        "path traversal review",
        "remote exposure relevant"
      ],
      "kev": false,
      "last_observed_at": "2026-07-22T16:52:32.770874+00:00",
      "latest_item_url": null,
      "product": "identity_services_engine_passive_identity_connector",
      "public_safe_summary": "NVD: A vulnerability in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker to perform path traversal attacks on the underlying operating system to either read or delete arbitrary... NVD: To exploit this vulnerability, the attacker must have valid administrative credentials.&nbsp; This vulnerability is due to improper validation of user-supplied input. NVD: An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected system.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260722T165509Z/items/CVE-2026-20146.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: cisco / identity_services_engine_passive_identity_connector; affected version context: 3.3.0, 3.4.0, 3.5.0",
      "source_published_impact": "Source describes path traversal review · remote exposure. Possible impact: A remote attacker may be able to reach files outside the intended application path.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker to perform path traversal attacks on the underlying operating system to either read or delete arbitrary... NVD: To exploit this vulnerability, the attacker must have valid administrative credentials.&nbsp; This vulnerability is due to improper validation of user-supplied input. NVD: An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected system.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-20146/timeline.json",
      "vendor": "cisco"
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-20150/",
      "current_public_safe_latest": false,
      "cvss_score": 8.8,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.1289,
      "epss_score": 0.00222,
      "first_observed_at": "2026-07-22T16:52:32.770874+00:00",
      "id": "CVE-2026-20150",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-22T16:52:32.770874+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive internal security review. NVD: This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. NVD: The vulnerabilities tracked by CVE-2026-20150 are related to improper access control&nbsp;that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-284.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260722T165509Z/items/CVE-2026-20150.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive internal security review. NVD: This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. NVD: The vulnerabilities tracked by CVE-2026-20150 are related to improper access control&nbsp;that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-284.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-20150/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-20153/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.16668,
      "epss_score": 0.00252,
      "first_observed_at": "2026-07-22T16:52:32.770874+00:00",
      "id": "CVE-2026-20153",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-22T16:52:32.770874+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive internal security review. NVD: This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. NVD: The vulnerabilities tracked by CVE-2026-20153 are related to improper input validation that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-20.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260722T165509Z/items/CVE-2026-20153.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive internal security review. NVD: This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. NVD: The vulnerabilities tracked by CVE-2026-20153 are related to improper input validation that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-20.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-20153/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-20156/",
      "current_public_safe_latest": false,
      "cvss_score": 8.1,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.13675,
      "epss_score": 0.00228,
      "first_observed_at": "2026-07-22T16:52:32.770874+00:00",
      "id": "CVE-2026-20156",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-22T16:52:32.770874+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive internal security review. NVD: This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. NVD: The vulnerabilities tracked by CVE-2026-20156 are related to improper restriction of operations within the bounds of a memory buffer that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-119.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260722T165509Z/items/CVE-2026-20156.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive internal security review. NVD: This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. NVD: The vulnerabilities tracked by CVE-2026-20156 are related to improper restriction of operations within the bounds of a memory buffer that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-119.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-20156/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-20157/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.00012,
      "epss_score": 0.00061,
      "first_observed_at": "2026-07-22T16:52:32.770874+00:00",
      "id": "CVE-2026-20157",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-22T16:52:32.770874+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive internal security review. NVD: This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. NVD: The vulnerabilities tracked by CVE-2026-20157 are related to missing encryption that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-311.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260722T165509Z/items/CVE-2026-20157.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive internal security review. NVD: This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. NVD: The vulnerabilities tracked by CVE-2026-20157 are related to missing encryption that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-311.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-20157/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-20158/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.16668,
      "epss_score": 0.00252,
      "first_observed_at": "2026-07-22T16:52:32.770874+00:00",
      "id": "CVE-2026-20158",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-22T16:52:32.770874+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive internal security review. NVD: This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. NVD: The vulnerabilities tracked by CVE-2026-20158 are related to improper control of a resource through its lifetime that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-664.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260722T165509Z/items/CVE-2026-20158.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive internal security review. NVD: This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. NVD: The vulnerabilities tracked by CVE-2026-20158 are related to improper control of a resource through its lifetime that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-664.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-20158/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-20187/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.16668,
      "epss_score": 0.00252,
      "first_observed_at": "2026-07-22T16:52:32.770874+00:00",
      "id": "CVE-2026-20187",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-22T16:52:32.770874+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive internal security review. NVD: This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. NVD: The vulnerabilities tracked by CVE-2026-20187 are related to improper handling of exceptional conditions that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-703.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260722T165509Z/items/CVE-2026-20187.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive internal security review. NVD: This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. NVD: The vulnerabilities tracked by CVE-2026-20187 are related to improper handling of exceptional conditions that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-703.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-20187/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "cisco / secure_firewall_management_center",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-20316/",
      "current_public_safe_latest": false,
      "cvss_score": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.52702,
      "epss_score": 0.00788,
      "first_observed_at": "2026-08-05T16:55:08.588478+00:00",
      "id": "CVE-2026-20316",
      "impact_tags": [
        "remote exposure relevant"
      ],
      "kev": true,
      "last_observed_at": "2026-08-05T16:55:08.588478+00:00",
      "latest_item_url": null,
      "product": "secure_firewall_management_center",
      "public_safe_summary": "NVD: A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to access sensitive data within the impacted systems. NVD: This vulnerability is due to the presence of static user credentials for a low-privileged&nbsp;account. NVD: An attacker could exploit this vulnerability by using the account to log in to an affected system.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260805T165944Z/items/CVE-2026-20316.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: cisco / secure_firewall_management_center",
      "source_published_impact": "Source describes known exploited catalog listed · remote exposure. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for known exploited catalog listed · remote exposure.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to access sensitive data within the impacted systems. NVD: This vulnerability is due to the presence of static user credentials for a low-privileged&nbsp;account. NVD: An attacker could exploit this vulnerability by using the account to log in to an affected system.",
      "sources": [
        "NVD",
        "CISA KEV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-20316/timeline.json",
      "vendor": "cisco"
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-21047/",
      "current_public_safe_latest": false,
      "cvss_score": 8.3,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.32432,
      "epss_score": 0.00396,
      "first_observed_at": "2026-08-04T11:35:47.800052+00:00",
      "id": "CVE-2026-21047",
      "impact_tags": [
        "code execution review",
        "remote exposure relevant"
      ],
      "kev": false,
      "last_observed_at": "2026-08-04T11:35:47.800052+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Out-of-bounds write in ImsService prior to SMR Jul-2026 Release 1 allows remote attackers to potentially execute arbitrary code.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260804T114328Z/items/CVE-2026-21047.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes code execution review · remote exposure. Possible impact: A remote attacker may be able to run code or commands on affected systems.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Out-of-bounds write in ImsService prior to SMR Jul-2026 Release 1 allows remote attackers to potentially execute arbitrary code.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-21047/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-21729/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.1794,
      "epss_score": 0.00263,
      "first_observed_at": "2026-07-22T22:28:24.662524+00:00",
      "id": "CVE-2026-21729",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-22T22:28:24.662524+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Loki queries with large limits can cause large memory allocations which can impact the availability of the service, depending on its deployment strategy.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260722T223443Z/items/CVE-2026-21729.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Loki queries with large limits can cause large memory allocations which can impact the availability of the service, depending on its deployment strategy.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-21729/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-21760/",
      "current_public_safe_latest": false,
      "cvss_score": 4.6,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.04491,
      "epss_score": 0.00148,
      "first_observed_at": "2026-07-24T16:59:54.170943+00:00",
      "id": "CVE-2026-21760",
      "impact_tags": [
        "unauthorized access risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-24T16:59:54.170943+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: HCL DevOps Loop is affected by an Unauthorized Access to Admin Functionality (Forced Browsing) vulnerability. NVD: Improper authorization checks may allow unauthorized users to access restricted administrative functionality by directly accessing protected application endpoints.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260724T170351Z/items/CVE-2026-21760.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes unauthorized access risk. Possible impact: An attacker may access resources that should require stronger authorization.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: HCL DevOps Loop is affected by an Unauthorized Access to Admin Functionality (Forced Browsing) vulnerability. NVD: Improper authorization checks may allow unauthorized users to access restricted administrative functionality by directly accessing protected application endpoints.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-21760/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-21761/",
      "current_public_safe_latest": false,
      "cvss_score": 4.2,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.04228,
      "epss_score": 0.00145,
      "first_observed_at": "2026-07-24T16:59:54.170943+00:00",
      "id": "CVE-2026-21761",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-24T16:59:54.170943+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: HCL DevOps Loop is affected by a Cross-Origin Resource Sharing (CORS) misconfiguration. NVD: Improper CORS configuration may allow unauthorized cross-origin requests, potentially exposing application resources to untrusted domains.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260724T170351Z/items/CVE-2026-21761.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: HCL DevOps Loop is affected by a Cross-Origin Resource Sharing (CORS) misconfiguration. NVD: Improper CORS configuration may allow unauthorized cross-origin requests, potentially exposing application resources to untrusted domains.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-21761/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-21762/",
      "current_public_safe_latest": false,
      "cvss_score": 3.7,
      "cvss_severity": "LOW",
      "epss_percentile": 0.06742,
      "epss_score": 0.00171,
      "first_observed_at": "2026-07-24T16:59:54.170943+00:00",
      "id": "CVE-2026-21762",
      "impact_tags": [
        "XSS risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-24T16:59:54.170943+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: HCL DevOps Loop is affected by missing HTTP security headers. NVD: Missing security headers may reduce browser protections against common web-based attacks such as clickjacking, MIME-type sniffing, and cross-site scripting.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260724T170351Z/items/CVE-2026-21762.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes XSS risk. Possible impact: This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: HCL DevOps Loop is affected by missing HTTP security headers. NVD: Missing security headers may reduce browser protections against common web-based attacks such as clickjacking, MIME-type sniffing, and cross-site scripting.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-21762/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-21764/",
      "current_public_safe_latest": false,
      "cvss_score": 3.1,
      "cvss_severity": "LOW",
      "epss_percentile": 0.04903,
      "epss_score": 0.00153,
      "first_observed_at": "2026-07-24T16:59:54.170943+00:00",
      "id": "CVE-2026-21764",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-24T16:59:54.170943+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: HCL DevOps Loop is affected by insufficient input validation that allows special characters where they should be restricted. NVD: This may result in unintended application behavior under certain conditions.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260724T170351Z/items/CVE-2026-21764.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: HCL DevOps Loop is affected by insufficient input validation that allows special characters where they should be restricted. NVD: This may result in unintended application behavior under certain conditions.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-21764/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-21840/",
      "current_public_safe_latest": false,
      "cvss_score": 3.1,
      "cvss_severity": "LOW",
      "epss_percentile": 0.04885,
      "epss_score": 0.00153,
      "first_observed_at": "2026-07-21T22:14:32.860584+00:00",
      "id": "CVE-2026-21840",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-21T22:14:32.860584+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: HCL BigFix Platform is affected by a user enumeration vulnerability which might allow an attacker, through careful system control and response time monitoring, to perform some level of user enumeration for the BigFix service.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260721T221655Z/items/CVE-2026-21840.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: HCL BigFix Platform is affected by a user enumeration vulnerability which might allow an attacker, through careful system control and response time monitoring, to perform some level of user enumeration for the BigFix service.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-21840/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-22049/",
      "current_public_safe_latest": false,
      "cvss_score": 8.7,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.20891,
      "epss_score": 0.00286,
      "first_observed_at": "2026-07-29T16:40:34.107276+00:00",
      "id": "CVE-2026-22049",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-29T16:40:34.107276+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: ONTAP versions 9.16.1 and higher with WebAuthn multi-factor authentication (MFA) configured are susceptible to a vulnerability related to the Relying Party ID which when successfully exploited could allow an attacker with valid credentials to bypass MFA.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260729T164826Z/items/CVE-2026-22049.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: ONTAP versions 9.16.1 and higher with WebAuthn multi-factor authentication (MFA) configured are susceptible to a vulnerability related to the Relying Party ID which when successfully exploited could allow an attacker with valid credentials to bypass MFA.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-22049/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-22104/",
      "current_public_safe_latest": false,
      "cvss_score": 7.1,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.26202,
      "epss_score": 0.00338,
      "first_observed_at": "2026-07-24T06:06:41.160911+00:00",
      "id": "CVE-2026-22104",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-24T06:06:41.160911+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Improper access control in Hashtopolis server web-interface chunk activity component for versions prior to 0.14.8 allows any created account to read all cracked hashes of a Hashtopolis server instance. OSV: Improper access control in Hashtopolis server chunk activity component OSV: Improper access control in Hashtopolis server web-interface chunk activity component for versions prior to 0.14.8 allows any created account to read all cracked hashes of a Hashtopolis server instance.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260724T061150Z/items/CVE-2026-22104.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Improper access control in Hashtopolis server web-interface chunk activity component for versions prior to 0.14.8 allows any created account to read all cracked hashes of a Hashtopolis server instance. OSV: Improper access control in Hashtopolis server chunk activity component OSV: Improper access control in Hashtopolis server web-interface chunk activity component for versions prior to 0.14.8 allows any created account to read all cracked hashes of a Hashtopolis server instance.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-22104/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-22659/",
      "current_public_safe_latest": false,
      "cvss_score": 7.2,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.20387,
      "epss_score": 0.00284,
      "first_observed_at": "2026-07-17T10:59:18.822206+00:00",
      "id": "CVE-2026-22659",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-17T10:59:18.822206+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: FlaskBB through 2.2.0, fixed in commit acc88cf, contains an authorization bypass vulnerability that allows authenticated moderators to perform unauthorized actions on topics in forums they do not control by submitting crafted topic ID lists. NVD: Attackers can include a low-ID topic from a permitted forum as an anchor in a batch request, causing the permission check applied only to the first result to pass, and then execute lock, unlock, delete, or hide actions against topics in unmoderated forums. OSV: FlaskBB Authorization Bypass via Topic ID Manipulation",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260717T110142Z/items/CVE-2026-22659.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: commit.",
      "source_published_summary": "NVD: FlaskBB through 2.2.0, fixed in commit acc88cf, contains an authorization bypass vulnerability that allows authenticated moderators to perform unauthorized actions on topics in forums they do not control by submitting crafted topic ID lists. NVD: Attackers can include a low-ID topic from a permitted forum as an anchor in a batch request, causing the permission check applied only to the first result to pass, and then execute lock, unlock, delete, or hide actions against topics in unmoderated forums. OSV: FlaskBB Authorization Bypass via Topic ID Manipulation",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-22659/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-22660/",
      "current_public_safe_latest": false,
      "cvss_score": 8.6,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.24923,
      "epss_score": 0.00328,
      "first_observed_at": "2026-07-17T10:59:18.822206+00:00",
      "id": "CVE-2026-22660",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-17T10:59:18.822206+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: FlaskBB through 2.2.0, fixed in commit a5da9a5, contains a logic flaw vulnerability that allows authenticated administrators to delete all built-in authorization groups by exploiting a type mismatch in the bulk delete protection check. NVD: The bulk AJAX endpoint in the management views compares received JSON integer group IDs against string literals, causing the protection check to always pass, which allows deletion of all six built-in groups and destroys the forum's permission model... OSV: FlaskBB Logic Flaw Authorization Group Deletion via Bulk AJAX Endpoint",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260717T110142Z/items/CVE-2026-22660.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: commit.",
      "source_published_summary": "NVD: FlaskBB through 2.2.0, fixed in commit a5da9a5, contains a logic flaw vulnerability that allows authenticated administrators to delete all built-in authorization groups by exploiting a type mismatch in the bulk delete protection check. NVD: The bulk AJAX endpoint in the management views compares received JSON integer group IDs against string literals, causing the protection check to always pass, which allows deletion of all six built-in groups and destroys the forum's permission model... OSV: FlaskBB Logic Flaw Authorization Group Deletion via Bulk AJAX Endpoint",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-22660/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-2346/",
      "current_public_safe_latest": false,
      "cvss_score": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.20649,
      "epss_score": 0.00285,
      "first_observed_at": "2026-08-10T10:38:36.347227+00:00",
      "id": "CVE-2026-2346",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-10T10:38:36.347227+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Authorization bypass through User-Controlled key vulnerability in Menulux Software Inc. NVD: Mobile App allows Software Integrity Attack. NVD: This issue affects Mobile App: through 12.05.2026.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260810T105121Z/items/CVE-2026-2346.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Authorization bypass through User-Controlled key vulnerability in Menulux Software Inc. NVD: Mobile App allows Software Integrity Attack. NVD: This issue affects Mobile App: through 12.05.2026.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-2346/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-23538/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.51039,
      "epss_score": 0.00748,
      "first_observed_at": "2026-07-22T22:28:24.662524+00:00",
      "id": "CVE-2026-23538",
      "impact_tags": [
        "service availability review",
        "remote exposure relevant"
      ],
      "kev": false,
      "last_observed_at": "2026-07-22T22:28:24.662524+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A vulnerability was identified in the Feast Feature Server's /ws/chat endpoint that allows remote attackers to establish persistent WebSocket connections without any authentication. NVD: By opening a large number of simultaneous connections, an attacker can exhaust server resources—such as memory, CPU, and file descriptors—leading to a complete denial of service for legitimate users.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260722T223443Z/items/CVE-2026-23538.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes service availability risk · remote exposure. Possible impact: The affected service may become unavailable or unreliable.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability was identified in the Feast Feature Server's /ws/chat endpoint that allows remote attackers to establish persistent WebSocket connections without any authentication. NVD: By opening a large number of simultaneous connections, an attacker can exhaust server resources—such as memory, CPU, and file descriptors—leading to a complete denial of service for legitimate users.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-23538/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-2354/",
      "current_public_safe_latest": false,
      "cvss_score": 8.8,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.42459,
      "epss_score": 0.00553,
      "first_observed_at": "2026-07-18T05:13:28.850753+00:00",
      "id": "CVE-2026-2354",
      "impact_tags": [
        "code execution review",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-18T05:13:28.850753+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Swiss Toolkit For WP plugin for WordPress is vulnerable to arbitrary file upload due to a flawed file type validation bypass in the upload_extension_files() function in all versions up to, and including, 1.4.6. NVD: The upload_extension_files() function hooks into WordPress's wp_check_filetype_and_ext filter and uses strpos() to check if a filename contains a configured extension string, rather than verifying the actual file extension. NVD: This makes it possible for authenticated attackers, with Author-level access and above, to upload arbitrary files (including PHP) on the affected site's server which may make remote code execution possible, granted the \"Enhanced Multi-Format Image Support\"...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260718T051545Z/items/CVE-2026-2354.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes code execution review · authenticated boundary. Possible impact: An attacker may be able to run code or commands on affected systems.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Swiss Toolkit For WP plugin for WordPress is vulnerable to arbitrary file upload due to a flawed file type validation bypass in the upload_extension_files() function in all versions up to, and including, 1.4.6. NVD: The upload_extension_files() function hooks into WordPress's wp_check_filetype_and_ext filter and uses strpos() to check if a filename contains a configured extension string, rather than verifying the actual file extension. NVD: This makes it possible for authenticated attackers, with Author-level access and above, to upload arbitrary files (including PHP) on the affected site's server which may make remote code execution possible, granted the \"Enhanced Multi-Format Image Support\"...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-2354/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-23697/",
      "current_public_safe_latest": false,
      "cvss_score": 8.7,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.50933,
      "epss_score": 0.00758,
      "first_observed_at": "2026-07-14T16:41:04.043226+00:00",
      "id": "CVE-2026-23697",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-14T16:41:04.043226+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Vtiger CRM before 8.4.0 contains an authenticated file upload vulnerability that allows low-privileged users to achieve remote code execution by uploading a .phar file containing arbitrary PHP code through the Documents module, bypassing the extension...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260714T164406Z/items/CVE-2026-23697.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Vtiger CRM before 8.4.0 contains an authenticated file upload vulnerability that allows low-privileged users to achieve remote code execution by uploading a .phar file containing arbitrary PHP code through the Documents module, bypassing the extension...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-23697/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-23698/",
      "current_public_safe_latest": false,
      "cvss_score": 8.6,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.54506,
      "epss_score": 0.00867,
      "first_observed_at": "2026-07-14T16:41:04.043226+00:00",
      "id": "CVE-2026-23698",
      "impact_tags": [
        "code execution review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-14T16:41:04.043226+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Vtiger CRM through 8.4.0 contains an authenticated remote code execution vulnerability in the admin module import feature that allows administrator-level attackers to upload arbitrary PHP files by submitting a crafted zip archive through the ModuleManager... NVD: Attackers can place executable PHP files in the modules/ directory that become directly accessible via HTTP, bypassing Vtiger's authentication and authorization layer entirely since Apache resolves the path and invokes the PHP interpreter before the...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260714T164406Z/items/CVE-2026-23698.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes code execution review. Possible impact: An attacker may be able to run code or commands on affected systems.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Vtiger CRM through 8.4.0 contains an authenticated remote code execution vulnerability in the admin module import feature that allows administrator-level attackers to upload arbitrary PHP files by submitting a crafted zip archive through the ModuleManager... NVD: Attackers can place executable PHP files in the modules/ directory that become directly accessible via HTTP, bypassing Vtiger's authentication and authorization layer entirely since Apache resolves the path and invokes the PHP interpreter before the...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-23698/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-2398/",
      "current_public_safe_latest": false,
      "cvss_score": 8.8,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.16359,
      "epss_score": 0.0025,
      "first_observed_at": "2026-07-17T16:36:32.072333+00:00",
      "id": "CVE-2026-2398",
      "impact_tags": [
        "privilege boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-17T16:36:32.072333+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Authorization bypass through User-Controlled key vulnerability in Adam Retail Automation Ltd. NVD: MobilMen 20T allows Privilege Escalation. NVD: This issue affects MobilMen 20T: from v3 through 10072026.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260717T164048Z/items/CVE-2026-2398.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes privilege escalation risk. Possible impact: An attacker may cross a privilege boundary and gain more access than intended.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Authorization bypass through User-Controlled key vulnerability in Adam Retail Automation Ltd. NVD: MobilMen 20T allows Privilege Escalation. NVD: This issue affects MobilMen 20T: from v3 through 10072026.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-2398/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "apache / iotdb",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-24012/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.41934,
      "epss_score": 0.00546,
      "first_observed_at": "2026-07-13T06:32:51.098771+00:00",
      "id": "CVE-2026-24012",
      "impact_tags": [
        "service availability review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-13T06:32:51.098771+00:00",
      "latest_item_url": null,
      "product": "iotdb",
      "public_safe_summary": "NVD: Uncontrolled Resource Consumption vulnerability in Apache IoTDB. NVD: Some interface fails to impose reasonable limits on the time span and aggregation interval of the query. NVD: An attacker can construct a request with extreme parameters (e.g., a very large time range combined with a minimal interval).",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260713T063521Z/items/CVE-2026-24012.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: apache / iotdb",
      "source_published_impact": "Source describes service availability risk. Possible impact: The affected service may become unavailable or unreliable.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: Uncontrolled Resource Consumption vulnerability in Apache IoTDB. NVD: Some interface fails to impose reasonable limits on the time span and aggregation interval of the query. NVD: An attacker can construct a request with extreme parameters (e.g., a very large time range combined with a minimal interval).",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-24012/timeline.json",
      "vendor": "apache"
    },
    {
      "affected_label": "apache / iotdb",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-24013/",
      "current_public_safe_latest": false,
      "cvss_score": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.3754,
      "epss_score": 0.00471,
      "first_observed_at": "2026-07-13T06:32:51.098771+00:00",
      "id": "CVE-2026-24013",
      "impact_tags": [
        "authentication boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-13T06:32:51.098771+00:00",
      "latest_item_url": null,
      "product": "iotdb",
      "public_safe_summary": "NVD: Authentication Bypass by Spoofing vulnerability in Apache IoTDB. NVD: Certain Thrift RPC query handlers lack strict validation of the sessionId parameter. NVD: An attacker can construct requests with a forged sessionId and, without performing openSession authentication, receive valid query results.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260713T063521Z/items/CVE-2026-24013.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: apache / iotdb",
      "source_published_impact": "Source describes authentication boundary review. Possible impact: This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authentication boundary review.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: Authentication Bypass by Spoofing vulnerability in Apache IoTDB. NVD: Certain Thrift RPC query handlers lack strict validation of the sessionId parameter. NVD: An attacker can construct requests with a forged sessionId and, without performing openSession authentication, receive valid query results.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-24013/timeline.json",
      "vendor": "apache"
    },
    {
      "affected_label": "apache / iotdb",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-24014/",
      "current_public_safe_latest": false,
      "cvss_score": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.39824,
      "epss_score": 0.00509,
      "first_observed_at": "2026-07-13T06:32:51.098771+00:00",
      "id": "CVE-2026-24014",
      "impact_tags": [
        "path traversal review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-13T06:32:51.098771+00:00",
      "latest_item_url": null,
      "product": "iotdb",
      "public_safe_summary": "NVD: Apache IoTDB DataNode’s internal RPC interface for creating Trigger instances uses the uploaded Trigger JAR name to build a file path without sufficient validation. NVD: If the internal DataNode RPC port is exposed to an untrusted network, an attacker may use path traversal sequences in the JAR name to write files outside the intended Trigger installation directory. NVD: This could allow arbitrary file write with the permissions of the IoTDB process.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260713T063521Z/items/CVE-2026-24014.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: apache / iotdb",
      "source_published_impact": "Source describes path traversal review. Possible impact: An attacker may be able to reach files outside the intended application path.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: Apache IoTDB DataNode’s internal RPC interface for creating Trigger instances uses the uploaded Trigger JAR name to build a file path without sufficient validation. NVD: If the internal DataNode RPC port is exposed to an untrusted network, an attacker may use path traversal sequences in the JAR name to write files outside the intended Trigger installation directory. NVD: This could allow arbitrary file write with the permissions of the IoTDB process.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-24014/timeline.json",
      "vendor": "apache"
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-2406/",
      "current_public_safe_latest": false,
      "cvss_score": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.21365,
      "epss_score": 0.00291,
      "first_observed_at": "2026-07-29T06:10:00.110927+00:00",
      "id": "CVE-2026-2406",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-29T06:10:00.110927+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Authorization bypass through User-Controlled key vulnerability in Universe Software Computer Marketing Trade and Industry Inc. NVD: Online Registration and Workflow Management System allows Exploiting Trust in Client. NVD: This issue affects Online Registration and Workflow Management System: through 12022026.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260729T062752Z/items/CVE-2026-2406.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Authorization bypass through User-Controlled key vulnerability in Universe Software Computer Marketing Trade and Industry Inc. NVD: Online Registration and Workflow Management System allows Exploiting Trust in Client. NVD: This issue affects Online Registration and Workflow Management System: through 12022026.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-2406/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "zephyrproject / zephyr",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-2411/",
      "current_public_safe_latest": false,
      "cvss_score": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.02544,
      "epss_score": 0.00124,
      "first_observed_at": "2026-08-08T09:56:53.105288+00:00",
      "id": "CVE-2026-2411",
      "impact_tags": [
        "information exposure review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-08T09:56:53.105288+00:00",
      "latest_item_url": null,
      "product": "zephyr",
      "public_safe_summary": "NVD: Zephyr's Bluetooth host declares a GATT characteristic as two consecutive attributes: a Characteristic Declaration whose permission is hard-coded to BT_GATT_PERM_READ, and a Characteristic Value attribute that carries the application-specified security... NVD: BT_GATT_PERM_READ_ENCRYPT / READ_AUTHEN / READ_LESC). NVD: The public notify and indicate APIs explicitly accept either attribute, and passing the declaration is the documented, common idiom.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260808T100051Z/items/CVE-2026-2411.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: zephyrproject / zephyr",
      "source_published_impact": "Source describes information exposure review. Possible impact: An attacker may be able to access information that should not be exposed.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Zephyr's Bluetooth host declares a GATT characteristic as two consecutive attributes: a Characteristic Declaration whose permission is hard-coded to BT_GATT_PERM_READ, and a Characteristic Value attribute that carries the application-specified security... NVD: BT_GATT_PERM_READ_ENCRYPT / READ_AUTHEN / READ_LESC). NVD: The public notify and indicate APIs explicitly accept either attribute, and passing the declaration is the documented, common idiom.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-2411/timeline.json",
      "vendor": "zephyrproject"
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-24232/",
      "current_public_safe_latest": false,
      "cvss_score": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.03826,
      "epss_score": 0.0014,
      "first_observed_at": "2026-07-28T16:54:01.667207+00:00",
      "id": "CVE-2026-24232",
      "impact_tags": [
        "information exposure review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-28T16:54:01.667207+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: NVIDIA Tranformers4Rec contains a vulnerability where an attacker could cause improper deserialization of untrusted data. NVD: A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260728T170314Z/items/CVE-2026-24232.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes information exposure review. Possible impact: An attacker may be able to access information that should not be exposed.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: NVIDIA Tranformers4Rec contains a vulnerability where an attacker could cause improper deserialization of untrusted data. NVD: A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-24232/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-24537/",
      "current_public_safe_latest": false,
      "cvss_score": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.01338,
      "epss_score": 0.00107,
      "first_observed_at": "2026-07-30T11:23:25.389138+00:00",
      "id": "CVE-2026-24537",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-30T11:23:25.389138+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Unauthenticated Cross Site Request Forgery (CSRF) in WP Accessibility Helper (WAH) <= 0.6.6 versions.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260730T112643Z/items/CVE-2026-24537.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Unauthenticated Cross Site Request Forgery (CSRF) in WP Accessibility Helper (WAH) <= 0.6.6 versions.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-24537/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-24552/",
      "current_public_safe_latest": false,
      "cvss_score": 8.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.11527,
      "epss_score": 0.00211,
      "first_observed_at": "2026-07-30T11:23:25.389138+00:00",
      "id": "CVE-2026-24552",
      "impact_tags": [
        "SQL injection risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-30T11:23:25.389138+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Contributor SQL Injection in Create by Mediavine <= 2.5.3 versions.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260730T112643Z/items/CVE-2026-24552.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes SQL injection risk. Possible impact: An attacker may be able to read or change database-backed application data.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Contributor SQL Injection in Create by Mediavine <= 2.5.3 versions.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-24552/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-24628/",
      "current_public_safe_latest": false,
      "cvss_score": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.06869,
      "epss_score": 0.00172,
      "first_observed_at": "2026-07-30T11:23:25.389138+00:00",
      "id": "CVE-2026-24628",
      "impact_tags": [
        "XSS risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-30T11:23:25.389138+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Administrator Cross Site Scripting (XSS) in Photo Gallery by Supsystic <= 1.16.3 versions.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260730T112643Z/items/CVE-2026-24628.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes XSS risk. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Administrator Cross Site Scripting (XSS) in Photo Gallery by Supsystic <= 1.16.3 versions.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-24628/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-24639/",
      "current_public_safe_latest": false,
      "cvss_score": 4.4,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.05677,
      "epss_score": 0.00161,
      "first_observed_at": "2026-07-30T11:23:25.389138+00:00",
      "id": "CVE-2026-24639",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-30T11:23:25.389138+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Author Server Side Request Forgery (SSRF) in Photo Block <= 1.7.1 versions.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260730T112643Z/items/CVE-2026-24639.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Author Server Side Request Forgery (SSRF) in Photo Block <= 1.7.1 versions.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-24639/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-25405/",
      "current_public_safe_latest": false,
      "cvss_score": 8.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.11527,
      "epss_score": 0.00211,
      "first_observed_at": "2026-07-30T11:23:25.389138+00:00",
      "id": "CVE-2026-25405",
      "impact_tags": [
        "SQL injection risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-30T11:23:25.389138+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Contributor SQL Injection in eRoom <= 1.7.1 versions.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260730T112643Z/items/CVE-2026-25405.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes SQL injection risk. Possible impact: An attacker may be able to read or change database-backed application data.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Contributor SQL Injection in eRoom <= 1.7.1 versions.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-25405/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-25424/",
      "current_public_safe_latest": false,
      "cvss_score": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.08388,
      "epss_score": 0.00185,
      "first_observed_at": "2026-07-30T11:23:25.389138+00:00",
      "id": "CVE-2026-25424",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-30T11:23:25.389138+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Contributor Broken Access Control in Mediavine Control Panel <= 2.10.10 versions.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260730T112643Z/items/CVE-2026-25424.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Contributor Broken Access Control in Mediavine Control Panel <= 2.10.10 versions.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-25424/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-25427/",
      "current_public_safe_latest": false,
      "cvss_score": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.19689,
      "epss_score": 0.00275,
      "first_observed_at": "2026-07-30T11:23:25.389138+00:00",
      "id": "CVE-2026-25427",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-30T11:23:25.389138+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Subscriber Broken Access Control in eRoom <= 1.7.1 versions.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260730T112643Z/items/CVE-2026-25427.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Subscriber Broken Access Control in eRoom <= 1.7.1 versions.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-25427/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-25466/",
      "current_public_safe_latest": false,
      "cvss_score": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.13669,
      "epss_score": 0.00228,
      "first_observed_at": "2026-07-30T11:23:25.389138+00:00",
      "id": "CVE-2026-25466",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-30T11:23:25.389138+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Unauthenticated Broken Access Control in WP Go Maps <= 10.1.04 versions.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260730T112643Z/items/CVE-2026-25466.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Unauthenticated Broken Access Control in WP Go Maps <= 10.1.04 versions.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-25466/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-2594/",
      "current_public_safe_latest": false,
      "cvss_score": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.15188,
      "epss_score": 0.0024,
      "first_observed_at": "2026-07-23T22:18:14.498937+00:00",
      "id": "CVE-2026-2594",
      "impact_tags": [
        "XSS risk",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-23T22:18:14.498937+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Smart Custom Fields plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.0.7. NVD: This is due to insufficient input sanitization and output escaping of uploaded image attachment titles. NVD: This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260723T222557Z/items/CVE-2026-2594.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes XSS risk · authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk · authenticated boundary.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: 5.0.7..",
      "source_published_summary": "NVD: The Smart Custom Fields plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.0.7. NVD: This is due to insufficient input sanitization and output escaping of uploaded image attachment titles. NVD: This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-2594/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "microsoft / azure_synapse",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-26145/",
      "current_public_safe_latest": false,
      "cvss_score": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.27949,
      "epss_score": 0.00359,
      "first_observed_at": "2026-07-09T22:45:10.548837+00:00",
      "id": "CVE-2026-26145",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-09T22:45:10.548837+00:00",
      "latest_item_url": null,
      "product": "azure_synapse",
      "public_safe_summary": "NVD: Improper access control in Azure Synapse allows an authorized attacker to elevate privileges over a network.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260709T224554Z/items/CVE-2026-26145.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: microsoft / azure_synapse; affected version context: -",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Improper access control in Azure Synapse allows an authorized attacker to elevate privileges over a network.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-26145/timeline.json",
      "vendor": "microsoft"
    },
    {
      "affected_label": "dell / data_domain_operating_system",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-26355/",
      "current_public_safe_latest": false,
      "cvss_score": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.60301,
      "epss_score": 0.01052,
      "first_observed_at": "2026-07-10T12:09:55.374028+00:00",
      "id": "CVE-2026-26355",
      "impact_tags": [
        "command execution review",
        "command injection risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-10T12:09:55.374028+00:00",
      "latest_item_url": null,
      "product": "data_domain_operating_system",
      "public_safe_summary": "NVD: Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an improper neutralization of special... NVD: A high privileged attacker with remote access could potentially exploit this vulnerability, leading to command execution.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260710T121119Z/items/CVE-2026-26355.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: dell / data_domain_operating_system",
      "source_published_impact": "Source describes command execution risk · command injection risk. Possible impact: An attacker may be able to run code or commands on affected systems.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an improper neutralization of special... NVD: A high privileged attacker with remote access could potentially exploit this vulnerability, leading to command execution.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-26355/timeline.json",
      "vendor": "dell"
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-27060/",
      "current_public_safe_latest": false,
      "cvss_score": 8.8,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.20572,
      "epss_score": 0.00288,
      "first_observed_at": "2026-07-09T11:52:04.215901+00:00",
      "id": "CVE-2026-27060",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-09T11:52:04.215901+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Contributor PHP Object Injection in ARMember Premium <= 7.0 versions.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260709T115259Z/items/CVE-2026-27060.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Contributor PHP Object Injection in ARMember Premium <= 7.0 versions.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-27060/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-27064/",
      "current_public_safe_latest": false,
      "cvss_score": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.19985,
      "epss_score": 0.00278,
      "first_observed_at": "2026-07-30T11:23:25.389138+00:00",
      "id": "CVE-2026-27064",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-30T11:23:25.389138+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Editor Arbitrary File Upload in Mailster <= 4.1.17 versions.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260730T112643Z/items/CVE-2026-27064.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Editor Arbitrary File Upload in Mailster <= 4.1.17 versions.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-27064/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-27355/",
      "current_public_safe_latest": false,
      "cvss_score": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.19979,
      "epss_score": 0.00277,
      "first_observed_at": "2026-07-30T11:23:25.389138+00:00",
      "id": "CVE-2026-27355",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-30T11:23:25.389138+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Unauthenticated Broken Access Control in Ditty <= 3.1.66 versions.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260730T112643Z/items/CVE-2026-27355.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Unauthenticated Broken Access Control in Ditty <= 3.1.66 versions.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-27355/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-27372/",
      "current_public_safe_latest": false,
      "cvss_score": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.18774,
      "epss_score": 0.00268,
      "first_observed_at": "2026-07-30T11:23:25.389138+00:00",
      "id": "CVE-2026-27372",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-30T11:23:25.389138+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Unauthenticated Sensitive Data Exposure in PeproDev Ultimate Invoice <= 2.2.6 versions.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260730T112643Z/items/CVE-2026-27372.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Unauthenticated Sensitive Data Exposure in PeproDev Ultimate Invoice <= 2.2.6 versions.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-27372/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-27377/",
      "current_public_safe_latest": false,
      "cvss_score": 6.7,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.18963,
      "epss_score": 0.0027,
      "first_observed_at": "2026-07-30T11:23:25.389138+00:00",
      "id": "CVE-2026-27377",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-30T11:23:25.389138+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Booking Agent Broken Access Control in QuickCal - Appointment Booking Calendar for WordPress <= 1.0.16 versions.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260730T112643Z/items/CVE-2026-27377.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Booking Agent Broken Access Control in QuickCal - Appointment Booking Calendar for WordPress <= 1.0.16 versions.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-27377/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-27391/",
      "current_public_safe_latest": false,
      "cvss_score": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.1969,
      "epss_score": 0.00275,
      "first_observed_at": "2026-07-30T11:23:25.389138+00:00",
      "id": "CVE-2026-27391",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-30T11:23:25.389138+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Subscriber Broken Access Control in uListing <= 2.2.0 versions.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260730T112643Z/items/CVE-2026-27391.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Subscriber Broken Access Control in uListing <= 2.2.0 versions.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-27391/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-27392/",
      "current_public_safe_latest": false,
      "cvss_score": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.08384,
      "epss_score": 0.00185,
      "first_observed_at": "2026-07-30T11:23:25.389138+00:00",
      "id": "CVE-2026-27392",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-30T11:23:25.389138+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Contributor Broken Access Control in uListing <= 2.2.0 versions.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260730T112643Z/items/CVE-2026-27392.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Contributor Broken Access Control in uListing <= 2.2.0 versions.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-27392/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-27399/",
      "current_public_safe_latest": false,
      "cvss_score": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.11915,
      "epss_score": 0.00214,
      "first_observed_at": "2026-07-30T11:23:25.389138+00:00",
      "id": "CVE-2026-27399",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-30T11:23:25.389138+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Unauthenticated Broken Access Control in MarketKing <= 2.1.40 versions.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260730T112643Z/items/CVE-2026-27399.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Unauthenticated Broken Access Control in MarketKing <= 2.1.40 versions.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-27399/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-27402/",
      "current_public_safe_latest": false,
      "cvss_score": 7.1,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.07695,
      "epss_score": 0.0018,
      "first_observed_at": "2026-07-09T11:52:04.215901+00:00",
      "id": "CVE-2026-27402",
      "impact_tags": [
        "XSS risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-09T11:52:04.215901+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Unauthenticated Cross Site Scripting (XSS) in Kids Life | Children School WordPress <= 5.2 versions.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260709T115259Z/items/CVE-2026-27402.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes XSS risk. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Unauthenticated Cross Site Scripting (XSS) in Kids Life | Children School WordPress <= 5.2 versions.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-27402/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-27403/",
      "current_public_safe_latest": false,
      "cvss_score": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.05681,
      "epss_score": 0.00161,
      "first_observed_at": "2026-07-30T11:23:25.389138+00:00",
      "id": "CVE-2026-27403",
      "impact_tags": [
        "XSS risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-30T11:23:25.389138+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NerdPress Hubbub Lite allows Stored XSS. NVD: This issue affects Hubbub Lite: from n/a through 1.36.3.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260730T112643Z/items/CVE-2026-27403.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes XSS risk. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NerdPress Hubbub Lite allows Stored XSS. NVD: This issue affects Hubbub Lite: from n/a through 1.36.3.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-27403/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-27404/",
      "current_public_safe_latest": false,
      "cvss_score": 7.1,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.07715,
      "epss_score": 0.0018,
      "first_observed_at": "2026-07-09T11:52:04.215901+00:00",
      "id": "CVE-2026-27404",
      "impact_tags": [
        "XSS risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-09T11:52:04.215901+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Unauthenticated Cross Site Scripting (XSS) in LMS <= 9.7 versions.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260709T115259Z/items/CVE-2026-27404.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes XSS risk. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Unauthenticated Cross Site Scripting (XSS) in LMS <= 9.7 versions.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-27404/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-27408/",
      "current_public_safe_latest": false,
      "cvss_score": 7.1,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.07716,
      "epss_score": 0.0018,
      "first_observed_at": "2026-07-09T11:52:04.215901+00:00",
      "id": "CVE-2026-27408",
      "impact_tags": [
        "XSS risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-09T11:52:04.215901+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Unauthenticated Cross Site Scripting (XSS) in NativeChurch <= 4.8.8.2 versions.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260709T115259Z/items/CVE-2026-27408.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes XSS risk. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Unauthenticated Cross Site Scripting (XSS) in NativeChurch <= 4.8.8.2 versions.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-27408/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-27412/",
      "current_public_safe_latest": false,
      "cvss_score": 8.1,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.20052,
      "epss_score": 0.00282,
      "first_observed_at": "2026-07-09T11:52:04.215901+00:00",
      "id": "CVE-2026-27412",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-09T11:52:04.215901+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Unauthenticated Local File Inclusion in Pearl - Corporate Business <= 3.4.10 versions.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260709T115259Z/items/CVE-2026-27412.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Unauthenticated Local File Inclusion in Pearl - Corporate Business <= 3.4.10 versions.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-27412/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-27414/",
      "current_public_safe_latest": false,
      "cvss_score": 8.8,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.20572,
      "epss_score": 0.00288,
      "first_observed_at": "2026-07-09T11:52:04.215901+00:00",
      "id": "CVE-2026-27414",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-09T11:52:04.215901+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Contributor PHP Object Injection in Werkstatt <= 4.8.3 versions.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260709T115259Z/items/CVE-2026-27414.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Contributor PHP Object Injection in Werkstatt <= 4.8.3 versions.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-27414/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-27418/",
      "current_public_safe_latest": false,
      "cvss_score": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.11918,
      "epss_score": 0.00214,
      "first_observed_at": "2026-07-30T11:23:25.389138+00:00",
      "id": "CVE-2026-27418",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-30T11:23:25.389138+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Unauthenticated Broken Access Control in WP Fast Total Search <= 1.81.282 versions.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260730T112643Z/items/CVE-2026-27418.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Unauthenticated Broken Access Control in WP Fast Total Search <= 1.81.282 versions.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-27418/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-27419/",
      "current_public_safe_latest": false,
      "cvss_score": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.28268,
      "epss_score": 0.00362,
      "first_observed_at": "2026-07-09T11:52:04.215901+00:00",
      "id": "CVE-2026-27419",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-09T11:52:04.215901+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Subscriber Arbitrary File Upload in Zegen <= 1.1.9 versions.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260709T115259Z/items/CVE-2026-27419.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Subscriber Arbitrary File Upload in Zegen <= 1.1.9 versions.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-27419/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-27422/",
      "current_public_safe_latest": false,
      "cvss_score": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.11916,
      "epss_score": 0.00214,
      "first_observed_at": "2026-07-30T11:23:25.389138+00:00",
      "id": "CVE-2026-27422",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-30T11:23:25.389138+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Unauthenticated Broken Access Control in YT Player <= 2.0.9 versions.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260730T112643Z/items/CVE-2026-27422.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Unauthenticated Broken Access Control in YT Player <= 2.0.9 versions.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-27422/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-27423/",
      "current_public_safe_latest": false,
      "cvss_score": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.15658,
      "epss_score": 0.00243,
      "first_observed_at": "2026-07-30T11:23:25.389138+00:00",
      "id": "CVE-2026-27423",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-30T11:23:25.389138+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Subscriber Broken Access Control in Participants Database <= 2.7.8.4 versions.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260730T112643Z/items/CVE-2026-27423.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Subscriber Broken Access Control in Participants Database <= 2.7.8.4 versions.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-27423/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-28564/",
      "current_public_safe_latest": false,
      "cvss_score": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.28896,
      "epss_score": 0.00367,
      "first_observed_at": "2026-07-17T05:58:07.763993+00:00",
      "id": "CVE-2026-28564",
      "impact_tags": [
        "authentication boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-17T05:58:07.763993+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Insufficient Session Expiration, Authentication Bypass by Capture-replay vulnerability in Apache IoTDB. NVD: REST Basic Authentication Accepts Stale Cached Credentials This issue affects Apache IoTDB: from 1.0.0 before 2.0.10. NVD: Users are recommended to upgrade to version 2.0.10, which fixes the issue.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260717T060336Z/items/CVE-2026-28564.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes authentication boundary review. Possible impact: This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authentication boundary review.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: Insufficient Session Expiration, Authentication Bypass by Capture-replay vulnerability in Apache IoTDB. NVD: REST Basic Authentication Accepts Stale Cached Credentials This issue affects Apache IoTDB: from 1.0.0 before 2.0.10. NVD: Users are recommended to upgrade to version 2.0.10, which fixes the issue.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-28564/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-28698/",
      "current_public_safe_latest": false,
      "cvss_score": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.17549,
      "epss_score": 0.00259,
      "first_observed_at": "2026-07-30T22:30:38.166118+00:00",
      "id": "CVE-2026-28698",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-30T22:30:38.166118+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Pronetiqs IntraVUE versions 3.2.1a14 and prior have an exposure of sensitive system information to an unauthorized control sphere vulnerability which could expose the underlying host/share filesystem.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260730T224832Z/items/CVE-2026-28698.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Pronetiqs IntraVUE versions 3.2.1a14 and prior have an exposure of sensitive system information to an unauthorized control sphere vulnerability which could expose the underlying host/share filesystem.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-28698/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-29007/",
      "current_public_safe_latest": false,
      "cvss_score": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.37738,
      "epss_score": 0.00472,
      "first_observed_at": "2026-07-15T16:47:57.605966+00:00",
      "id": "CVE-2026-29007",
      "impact_tags": [
        "remote exposure relevant"
      ],
      "kev": false,
      "last_observed_at": "2026-07-15T16:47:57.605966+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: U-Boot through 2026.04-rc3 contains an out-of-bounds read vulnerability in tcp_rx_state_machine() (net/tcp.c) when CONFIG_PROT_TCP is enabled, allowing remote attackers to read beyond TCP segment boundaries by crafting a malicious packet with a mismatched IP... NVD: Attackers can send a packet with an IP total length of 40 bytes and a TCP data offset claiming 60 bytes of header to cause tcp_parse_options() to read 40 bytes past the end of the TCP segment, potentially corrupting connection state variables such as... OSV: U-Boot 2026.04-rc3 Out-of-Bounds Read in tcp_rx_state_machine via tcp.c",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260715T164957Z/items/CVE-2026-29007.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes remote exposure. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: U-Boot through 2026.04-rc3 contains an out-of-bounds read vulnerability in tcp_rx_state_machine() (net/tcp.c) when CONFIG_PROT_TCP is enabled, allowing remote attackers to read beyond TCP segment boundaries by crafting a malicious packet with a mismatched IP... NVD: Attackers can send a packet with an IP total length of 40 bytes and a TCP data offset claiming 60 bytes of header to cause tcp_parse_options() to read 40 bytes past the end of the TCP segment, potentially corrupting connection state variables such as... OSV: U-Boot 2026.04-rc3 Out-of-Bounds Read in tcp_rx_state_machine via tcp.c",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-29007/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-29008/",
      "current_public_safe_latest": false,
      "cvss_score": 8.7,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.36064,
      "epss_score": 0.00446,
      "first_observed_at": "2026-07-15T16:47:57.605966+00:00",
      "id": "CVE-2026-29008",
      "impact_tags": [
        "service availability review",
        "memory safety review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-15T16:47:57.605966+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: U-Boot through 2026.04-rc3 contains an integer underflow vulnerability in the tcp_rx_state_machine() function (net/tcp.c) that allows a network-adjacent attacker to crash the bootloader by sending a malformed TCP SYN+ACK packet with a manipulated data offset... NVD: When the TCP_SYN_SENT handler calls tcp_rx_user_data() without invoking tcp_seg_in_wnd() validation, the negative payload_len is implicitly converted to a large unsigned integer (e.g., 0xFFFFFFD8) and passed to memcpy() in store_block(), causing an immediate... OSV: U-Boot 2026.04-rc3 Integer Underflow DoS via tcp_rx_state_machine()",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260715T164957Z/items/CVE-2026-29008.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes service availability risk · memory safety review. Possible impact: The affected service may become unavailable or unreliable.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: U-Boot through 2026.04-rc3 contains an integer underflow vulnerability in the tcp_rx_state_machine() function (net/tcp.c) that allows a network-adjacent attacker to crash the bootloader by sending a malformed TCP SYN+ACK packet with a manipulated data offset... NVD: When the TCP_SYN_SENT handler calls tcp_rx_user_data() without invoking tcp_seg_in_wnd() validation, the negative payload_len is implicitly converted to a large unsigned integer (e.g., 0xFFFFFFD8) and passed to memcpy() in store_block(), causing an immediate... OSV: U-Boot 2026.04-rc3 Integer Underflow DoS via tcp_rx_state_machine()",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-29008/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-29009/",
      "current_public_safe_latest": false,
      "cvss_score": 8.8,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.35426,
      "epss_score": 0.00438,
      "first_observed_at": "2026-07-15T16:47:57.605966+00:00",
      "id": "CVE-2026-29009",
      "impact_tags": [
        "memory safety review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-15T16:47:57.605966+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: U-Boot through 2026.04-rc3 contains a buffer overflow vulnerability in nfs_readlink_reply() (net/nfs-common.c) when CONFIG_CMD_NFS is enabled, allowing a malicious or compromised NFS server to overflow the 2048-byte nfs_path_buff buffer by returning multiple... NVD: Attackers can send two or more READLINK responses containing relative symlink targets of approximately 1100 bytes each to corrupt adjacent BSS variables including nfs_server_ip, nfs_server_mount_port, nfs_server_port, nfs_our_port, nfs_state, and rpc_id... OSV: U-Boot 2026.04-rc3 Buffer Overflow in nfs_readlink_reply() via NFS READLINK",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260715T164957Z/items/CVE-2026-29009.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes memory safety review. Possible impact: The affected component has memory-safety risk that may lead to crash, privilege, or code-execution impact depending on exposure.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: U-Boot through 2026.04-rc3 contains a buffer overflow vulnerability in nfs_readlink_reply() (net/nfs-common.c) when CONFIG_CMD_NFS is enabled, allowing a malicious or compromised NFS server to overflow the 2048-byte nfs_path_buff buffer by returning multiple... NVD: Attackers can send two or more READLINK responses containing relative symlink targets of approximately 1100 bytes each to corrupt adjacent BSS variables including nfs_server_ip, nfs_server_mount_port, nfs_server_port, nfs_our_port, nfs_state, and rpc_id... OSV: U-Boot 2026.04-rc3 Buffer Overflow in nfs_readlink_reply() via NFS READLINK",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-29009/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-29519/",
      "current_public_safe_latest": false,
      "cvss_score": 6.2,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.30866,
      "epss_score": 0.00386,
      "first_observed_at": "2026-07-17T10:59:18.822206+00:00",
      "id": "CVE-2026-29519",
      "impact_tags": [
        "XSS risk",
        "remote exposure relevant"
      ],
      "kev": false,
      "last_observed_at": "2026-07-17T10:59:18.822206+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Lucee CFML Server versions across the 5.3.x, 6.1.x, 6.2.x, and 7.0.x release lines contain a reflected cross-site scripting vulnerability in URL path parsing that allows unauthenticated remote attackers to execute arbitrary JavaScript in a victim's browser by... NVD: Attackers can craft a malicious URL containing injected script content that is reflected in the server's response without proper output encoding, enabling session hijacking or unauthorized actions against the Lucee administrative interface when a victim... OSV: Lucee CFML Server Reflected XSS via URL Path Parsing",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260717T110142Z/items/CVE-2026-29519.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes XSS risk · remote exposure. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk · remote exposure.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Lucee CFML Server versions across the 5.3.x, 6.1.x, 6.2.x, and 7.0.x release lines contain a reflected cross-site scripting vulnerability in URL path parsing that allows unauthenticated remote attackers to execute arbitrary JavaScript in a victim's browser by... NVD: Attackers can craft a malicious URL containing injected script content that is reflected in the server's response without proper output encoding, enabling session hijacking or unauthorized actions against the Lucee administrative interface when a victim... OSV: Lucee CFML Server Reflected XSS via URL Path Parsing",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-29519/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-3031/",
      "current_public_safe_latest": false,
      "cvss_score": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.32723,
      "epss_score": 0.00402,
      "first_observed_at": "2026-07-23T16:53:12.033252+00:00",
      "id": "CVE-2026-3031",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-23T16:53:12.033252+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Image::EPEG versions through 0.15 for Perl embeds an unsupported version of the Epeg library. NVD: Image::EPEG includes Epeg 0.9.0 that was last updated in 2004. NVD: Epeg is a fast JPEG thumbnail library that was once part of the Englightenment Project.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260723T171217Z/items/CVE-2026-3031.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Image::EPEG versions through 0.15 for Perl embeds an unsupported version of the Epeg library. NVD: Image::EPEG includes Epeg 0.9.0 that was last updated in 2004. NVD: Epeg is a fast JPEG thumbnail library that was once part of the Englightenment Project.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-3031/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-31309/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.24476,
      "epss_score": 0.00324,
      "first_observed_at": "2026-07-15T22:16:59.245057+00:00",
      "id": "CVE-2026-31309",
      "impact_tags": [
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-15T22:16:59.245057+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Improper authorization in the /tequilapi/config/user endpoint of Mysterium Node from v1.21.1-rc0 before v1.36.0 allows an unauthenticated attacker to arbitrarily overwrite the node's configuration and achieve a full node takeover via a crafted POST request. OSV: Improper authorization in the /tequilapi/config/user endpoint of Mysterium Node from v1.21.1-rc0 before v1.36.0 allows an unauthenticated attacker to arbitrarily overwrite the node's configuration and achieve a full node takeover via a crafted POST request.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260715T221956Z/items/CVE-2026-31309.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes remote exposure · authenticated boundary. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Improper authorization in the /tequilapi/config/user endpoint of Mysterium Node from v1.21.1-rc0 before v1.36.0 allows an unauthenticated attacker to arbitrarily overwrite the node's configuration and achieve a full node takeover via a crafted POST request. OSV: Improper authorization in the /tequilapi/config/user endpoint of Mysterium Node from v1.21.1-rc0 before v1.36.0 allows an unauthenticated attacker to arbitrarily overwrite the node's configuration and achieve a full node takeover via a crafted POST request.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-31309/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-3141/",
      "current_public_safe_latest": false,
      "cvss_score": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.38103,
      "epss_score": 0.00467,
      "first_observed_at": "2026-08-08T04:31:15.594937+00:00",
      "id": "CVE-2026-3141",
      "impact_tags": [
        "path traversal review",
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-08T04:31:15.594937+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The FormGent plugin for WordPress is vulnerable to unauthorized arbitrary file deletion due to a missing capability check on the /wp-json/formgent/responses/attachments REST API endpoint in all versions up to, and including, 1.9.2 This is due to the REST API... NVD: This makes it possible for unauthenticated attackers to delete arbitrary files within the formgent uploads directory. NVD: Additionally, on Linux servers where the wp-content/uploads/formgent directory does not yet exist (the default state after plugin installation), the path traversal protection can be bypassed, enabling deletion of arbitrary files including wp-config.php which...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260808T043750Z/items/CVE-2026-3141.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes path traversal review · remote exposure · authenticated boundary. Possible impact: A remote attacker may be able to reach files outside the intended application path.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The FormGent plugin for WordPress is vulnerable to unauthorized arbitrary file deletion due to a missing capability check on the /wp-json/formgent/responses/attachments REST API endpoint in all versions up to, and including, 1.9.2 This is due to the REST API... NVD: This makes it possible for unauthenticated attackers to delete arbitrary files within the formgent uploads directory. NVD: Additionally, on Linux servers where the wp-content/uploads/formgent directory does not yet exist (the default state after plugin installation), the path traversal protection can be bypassed, enabling deletion of arbitrary files including wp-config.php which...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-3141/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-3182/",
      "current_public_safe_latest": false,
      "cvss_score": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.19868,
      "epss_score": 0.00277,
      "first_observed_at": "2026-07-28T06:05:50.269125+00:00",
      "id": "CVE-2026-3182",
      "impact_tags": [
        "information exposure review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-28T06:05:50.269125+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Zohocorp ManageEngine Endpoint Central versions before 11.4.2528.34 are affected by cleartext transmission of sensitive information vulnerability.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260728T060840Z/items/CVE-2026-3182.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes information exposure review. Possible impact: An attacker may be able to access information that should not be exposed.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Zohocorp ManageEngine Endpoint Central versions before 11.4.2528.34 are affected by cleartext transmission of sensitive information vulnerability.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-3182/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-3183/",
      "current_public_safe_latest": false,
      "cvss_score": 7.1,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.38748,
      "epss_score": 0.00481,
      "first_observed_at": "2026-07-28T06:05:50.269125+00:00",
      "id": "CVE-2026-3183",
      "impact_tags": [
        "authentication boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-28T06:05:50.269125+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Zohocorp ManageEngine ADSelfService Plus versions before 6524 are vulnerable to Multi Factor Authentication Bypass.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260728T060840Z/items/CVE-2026-3183.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes authentication boundary review. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authentication boundary review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Zohocorp ManageEngine ADSelfService Plus versions before 6524 are vulnerable to Multi Factor Authentication Bypass.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-3183/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-3245/",
      "current_public_safe_latest": false,
      "cvss_score": 7.7,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.15166,
      "epss_score": 0.00241,
      "first_observed_at": "2026-08-09T09:59:30.349754+00:00",
      "id": "CVE-2026-3245",
      "impact_tags": [
        "code execution review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-09T21:51:57.260007+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A deserialization vulnerability in PRISMAproduction Version 6.5 or earlier that may lead to arbitrary code execution.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260809T215750Z/items/CVE-2026-3245.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 3,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes code execution review. Possible impact: An attacker may be able to run code or commands on affected systems.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A deserialization vulnerability in PRISMAproduction Version 6.5 or earlier that may lead to arbitrary code execution.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-3245/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-3251/",
      "current_public_safe_latest": false,
      "cvss_score": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.04428,
      "epss_score": 0.00148,
      "first_observed_at": "2026-07-17T16:36:32.072333+00:00",
      "id": "CVE-2026-3251",
      "impact_tags": [
        "XSS risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-17T16:36:32.072333+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Webremium Istanbul Web Design Mezunum Satiyorum allows Stored XSS. NVD: This issue affects Mezunum Satiyorum: from 1.2.504 through 10072026. NVD: NOTE: The vendor was contacted early about this disclosure but did not respond in any way.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260717T164048Z/items/CVE-2026-3251.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes XSS risk. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Webremium Istanbul Web Design Mezunum Satiyorum allows Stored XSS. NVD: This issue affects Mezunum Satiyorum: from 1.2.504 through 10072026. NVD: NOTE: The vendor was contacted early about this disclosure but did not respond in any way.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-3251/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-32718/",
      "current_public_safe_latest": false,
      "cvss_score": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.116,
      "epss_score": 0.00213,
      "first_observed_at": "2026-07-13T22:14:02.217047+00:00",
      "id": "CVE-2026-32718",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-13T22:14:02.217047+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. NVD: Prior to 4.0.0-beta.466, mutating API validation endpoints are guarded by read ability, allowing read-scoped API tokens to perform state-changing operations such as validating cloud tokens and servers. NVD: This issue is fixed in version 4.0.0-beta.466.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260714T042224Z/items/CVE-2026-32718.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. NVD: Prior to 4.0.0-beta.466, mutating API validation endpoints are guarded by read ability, allowing read-scoped API tokens to perform state-changing operations such as validating cloud tokens and servers. NVD: This issue is fixed in version 4.0.0-beta.466.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-32718/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-32806/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.20861,
      "epss_score": 0.00287,
      "first_observed_at": "2026-07-27T17:12:53.854417+00:00",
      "id": "CVE-2026-32806",
      "impact_tags": [
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-27T17:12:53.854417+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. NVD: In dataCycle-CORE, the module handling core processing and framework rules, before and including version 25.07.3, any authenticated user can request arbitrary partials or helper-backed render functions through /remote_render. NVD: The endpoint does not restrict which partial can be rendered and does not apply controller-specific authorization before rendering the selected view.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260727T171933Z/items/CVE-2026-32806.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes authenticated boundary. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: 26.06.08..",
      "source_published_summary": "NVD: dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. NVD: In dataCycle-CORE, the module handling core processing and framework rules, before and including version 25.07.3, any authenticated user can request arbitrary partials or helper-backed render functions through /remote_render. NVD: The endpoint does not restrict which partial can be rendered and does not apply controller-specific authorization before rendering the selected view.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-32806/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-32819/",
      "current_public_safe_latest": false,
      "cvss_score": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.09688,
      "epss_score": 0.00197,
      "first_observed_at": "2026-07-27T17:12:53.854417+00:00",
      "id": "CVE-2026-32819",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-27T17:12:53.854417+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. NVD: In dataCycle-CORE, the module handling core processing and framework rules, before and including version 25.07.3, a Standard user can enumerate other users' names and email addresses through /users/search, even though direct access to those user profiles is... NVD: This leaks internal staff addresses, full names, and existence of guest and external test accounts.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260727T171933Z/items/CVE-2026-32819.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. NVD: In dataCycle-CORE, the module handling core processing and framework rules, before and including version 25.07.3, a Standard user can enumerate other users' names and email addresses through /users/search, even though direct access to those user profiles is... NVD: This leaks internal staff addresses, full names, and existence of guest and external test accounts.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-32819/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-32820/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.45279,
      "epss_score": 0.00603,
      "first_observed_at": "2026-07-27T17:12:53.854417+00:00",
      "id": "CVE-2026-32820",
      "impact_tags": [
        "path traversal review",
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-27T17:12:53.854417+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. NVD: In dataCycle-CORE, the module handling core processing and framework rules, before and including version 25.07.3, the documentation and static markdown renderer accepts attacker-controlled path segments and only runs them through the Rails HTML sanitizer... NVD: An unauthenticated attacker can traverse out of the intended docs or static directories and render arbitrary .md files from the application root or engine root.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260727T171933Z/items/CVE-2026-32820.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes path traversal review · remote exposure · authenticated boundary. Possible impact: A remote attacker may be able to reach files outside the intended application path.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. NVD: In dataCycle-CORE, the module handling core processing and framework rules, before and including version 25.07.3, the documentation and static markdown renderer accepts attacker-controlled path segments and only runs them through the Rails HTML sanitizer... NVD: An unauthenticated attacker can traverse out of the intended docs or static directories and render arbitrary .md files from the application root or engine root.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-32820/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-32821/",
      "current_public_safe_latest": false,
      "cvss_score": 8.1,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.10178,
      "epss_score": 0.00201,
      "first_observed_at": "2026-07-27T17:12:53.854417+00:00",
      "id": "CVE-2026-32821",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-27T17:12:53.854417+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. NVD: In dataCycle-CORE, the module handling core processing and framework rules, before and including version 25.07.3, any authenticated API user who has their own access token can ask the collection API to evaluate permissions as a different user by supplying... NVD: If the target user has collections, this can expose those collections through the API.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260727T171933Z/items/CVE-2026-32821.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. NVD: In dataCycle-CORE, the module handling core processing and framework rules, before and including version 25.07.3, any authenticated API user who has their own access token can ask the collection API to evaluate permissions as a different user by supplying... NVD: If the target user has collections, this can expose those collections through the API.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-32821/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-32823/",
      "current_public_safe_latest": false,
      "cvss_score": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.01345,
      "epss_score": 0.00107,
      "first_observed_at": "2026-07-27T17:12:53.854417+00:00",
      "id": "CVE-2026-32823",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-27T17:12:53.854417+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. NVD: In dataCycle-CORE, the module handling core processing and framework rules, before and including version 25.07.3, the application exposes server-side state changes through GET routes. NVD: Because browsers automatically send cookies on same-site top-level navigation and Rails does not apply CSRF protections to GET, an attacker can force a logged-in victim to modify application state by embedding a link, image, iframe, or redirect to one of...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260727T171933Z/items/CVE-2026-32823.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. NVD: In dataCycle-CORE, the module handling core processing and framework rules, before and including version 25.07.3, the application exposes server-side state changes through GET routes. NVD: Because browsers automatically send cookies on same-site top-level navigation and Rails does not apply CSRF protections to GET, an attacker can force a logged-in victim to modify application state by embedding a link, image, iframe, or redirect to one of...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-32823/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-32824/",
      "current_public_safe_latest": false,
      "cvss_score": 7.3,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.21754,
      "epss_score": 0.00296,
      "first_observed_at": "2026-07-27T17:12:53.854417+00:00",
      "id": "CVE-2026-32824",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-27T17:12:53.854417+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. NVD: In dataCycle-CORE, the module handling core processing and framework rules, before and including version 25.07.3, a low-privileged authenticated API user can supply forwardToUrl and redirectUrl values when triggering password reset or confirmation flows. NVD: Those values are then embedded into the outgoing email workflow without host allowlisting.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260727T171933Z/items/CVE-2026-32824.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. NVD: In dataCycle-CORE, the module handling core processing and framework rules, before and including version 25.07.3, a low-privileged authenticated API user can supply forwardToUrl and redirectUrl values when triggering password reset or confirmation flows. NVD: Those values are then embedded into the outgoing email workflow without host allowlisting.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-32824/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-32825/",
      "current_public_safe_latest": false,
      "cvss_score": 7.3,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.21754,
      "epss_score": 0.00296,
      "first_observed_at": "2026-07-27T17:12:53.854417+00:00",
      "id": "CVE-2026-32825",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-27T17:12:53.854417+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. NVD: In dataCycle-CORE, the module handling core processing and framework rules, before and including version 25.07.3, the application accepts unlimited password guesses against both the browser login flow and the JSON login endpoint. NVD: The source code enables Devise's :lockable module on the user model but explicitly disables both lock and unlock strategies, and no request throttling or rate-limiting layer was identified in the Rails code.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260727T171933Z/items/CVE-2026-32825.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. NVD: In dataCycle-CORE, the module handling core processing and framework rules, before and including version 25.07.3, the application accepts unlimited password guesses against both the browser login flow and the JSON login endpoint. NVD: The source code enables Devise's :lockable module on the user model but explicitly disables both lock and unlock strategies, and no request throttling or rate-limiting layer was identified in the Rails code.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-32825/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-33327/",
      "current_public_safe_latest": false,
      "cvss_score": 7.0,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.03151,
      "epss_score": 0.00132,
      "first_observed_at": "2026-07-27T17:12:53.854417+00:00",
      "id": "CVE-2026-33327",
      "impact_tags": [
        "memory safety review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-27T17:12:53.854417+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: libvips is a fast image processing library with low memory needs. NVD: The vipsload operation in versions before and including 8.18.0 could incorrectly determine image dimensions leading to an integer overflow and a subsequent heap-based buffer overflow. NVD: This has been patched in version 8.18.1.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260727T171933Z/items/CVE-2026-33327.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes memory safety review. Possible impact: The affected component has memory-safety risk that may lead to crash, privilege, or code-execution impact depending on exposure.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: libvips is a fast image processing library with low memory needs. NVD: The vipsload operation in versions before and including 8.18.0 could incorrectly determine image dimensions leading to an integer overflow and a subsequent heap-based buffer overflow. NVD: This has been patched in version 8.18.1.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-33327/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-33328/",
      "current_public_safe_latest": false,
      "cvss_score": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.02126,
      "epss_score": 0.0012,
      "first_observed_at": "2026-07-27T17:12:53.854417+00:00",
      "id": "CVE-2026-33328",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-27T17:12:53.854417+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: libvips is a fast image processing library with low memory needs. NVD: On 32-bit systems in versions before and including 8.18.0, the gifload operation could incorrectly determine dimensions leading to an integer overflow. NVD: This has been patched in version 8.18.1.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260727T171933Z/items/CVE-2026-33328.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: libvips is a fast image processing library with low memory needs. NVD: On 32-bit systems in versions before and including 8.18.0, the gifload operation could incorrectly determine dimensions leading to an integer overflow. NVD: This has been patched in version 8.18.1.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-33328/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-33385/",
      "current_public_safe_latest": false,
      "cvss_score": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.1523,
      "epss_score": 0.0024,
      "first_observed_at": "2026-08-05T11:32:09.387600+00:00",
      "id": "CVE-2026-33385",
      "impact_tags": [
        "SQL injection risk"
      ],
      "kev": false,
      "last_observed_at": "2026-08-05T11:32:09.387600+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A Blind SQL injection vulnerability has been identified in Quick.CMS. NVD: Improper neutralization of input provided by a high-privileged user into multiple fields in administration panel allows for Blind SQL Injection attacks. NVD: The vendor states that this administration panel already allows for significant modification capabilities.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260805T113552Z/items/CVE-2026-33385.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes SQL injection risk. Possible impact: An attacker may be able to read or change database-backed application data.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A Blind SQL injection vulnerability has been identified in Quick.CMS. NVD: Improper neutralization of input provided by a high-privileged user into multiple fields in administration panel allows for Blind SQL Injection attacks. NVD: The vendor states that this administration panel already allows for significant modification capabilities.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-33385/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "wazuh / wazuh",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-33434/",
      "current_public_safe_latest": false,
      "cvss_score": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.1393,
      "epss_score": 0.0023,
      "first_observed_at": "2026-07-23T22:18:14.498937+00:00",
      "id": "CVE-2026-33434",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-23T22:18:14.498937+00:00",
      "latest_item_url": null,
      "product": "wazuh",
      "public_safe_summary": "NVD: Wazuh is a free and open source platform used for threat prevention, detection, and response. NVD: In versions 4.6.0 and above, prior to 4.14.5, a logic error in CheckRateLimitsMiddleware.dispatch() causes the /events endpoint rate check to unconditionally overwrite the general rate limit result. NVD: When the global max_request_per_minute is exceeded, requests to /events still succeed if the events-specific counter (hardcoded 30/min) has not been reached.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260723T222557Z/items/CVE-2026-33434.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: wazuh / wazuh",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: Wazuh is a free and open source platform used for threat prevention, detection, and response. NVD: In versions 4.6.0 and above, prior to 4.14.5, a logic error in CheckRateLimitsMiddleware.dispatch() causes the /events endpoint rate check to unconditionally overwrite the general rate limit result. NVD: When the global max_request_per_minute is exceeded, requests to /events still succeed if the events-specific counter (hardcoded 30/min) has not been reached.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-33434/timeline.json",
      "vendor": "wazuh"
    },
    {
      "affected_label": "newapi / new_api",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-33655/",
      "current_public_safe_latest": false,
      "cvss_score": 7.7,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.3541,
      "epss_score": 0.00437,
      "first_observed_at": "2026-07-16T22:18:24.817461+00:00",
      "id": "CVE-2026-33655",
      "impact_tags": [
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-16T22:18:24.817461+00:00",
      "latest_item_url": null,
      "product": "new_api",
      "public_safe_summary": "NVD: New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. NVD: Prior to 0.12.0-alpha.1, the default SSRF protection configuration did not apply IP filtering to hostnames; with ApplyIPFilterForDomain disabled by default, URL validation checked domain allow/block rules but did not resolve a hostname and validate the... NVD: This issue is fixed in version 0.12.0-alpha.1.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260716T222035Z/items/CVE-2026-33655.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: newapi / new_api",
      "source_published_impact": "Source describes authenticated boundary. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. NVD: Prior to 0.12.0-alpha.1, the default SSRF protection configuration did not apply IP filtering to hostnames; with ApplyIPFilterForDomain disabled by default, URL validation checked domain allow/block rules but did not resolve a hostname and validate the... NVD: This issue is fixed in version 0.12.0-alpha.1.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-33655/timeline.json",
      "vendor": "newapi"
    },
    {
      "affected_label": "wazuh / wazuh",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-33754/",
      "current_public_safe_latest": false,
      "cvss_score": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.13667,
      "epss_score": 0.00228,
      "first_observed_at": "2026-07-23T22:18:14.498937+00:00",
      "id": "CVE-2026-33754",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-23T22:18:14.498937+00:00",
      "latest_item_url": null,
      "product": "wazuh",
      "public_safe_summary": "NVD: Wazuh is a free and open source platform used for threat prevention, detection, and response. NVD: The length is trusted before authentication/decryption and used directly to allocate memory, allowing unauthenticated denial of service of the cluster service. NVD: This issue has been fixed in version 4.14.5.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260723T222557Z/items/CVE-2026-33754.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: wazuh / wazuh",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: Wazuh is a free and open source platform used for threat prevention, detection, and response. NVD: The length is trusted before authentication/decryption and used directly to allocate memory, allowing unauthenticated denial of service of the cluster service. NVD: This issue has been fixed in version 4.14.5.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-33754/timeline.json",
      "vendor": "wazuh"
    },
    {
      "affected_label": "microsoft / windows_10_1607",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-33842/",
      "current_public_safe_latest": false,
      "cvss_score": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.2772,
      "epss_score": 0.00353,
      "first_observed_at": "2026-07-21T16:48:32.557544+00:00",
      "id": "CVE-2026-33842",
      "impact_tags": [
        "information exposure review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-21T16:48:32.557544+00:00",
      "latest_item_url": null,
      "product": "windows_10_1607",
      "public_safe_summary": "NVD: Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260721T165442Z/items/CVE-2026-33842.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: microsoft / windows_10_1607; affected version context: -, r2",
      "source_published_impact": "Source describes information exposure review. Possible impact: An attacker may be able to access information that should not be exposed.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-33842/timeline.json",
      "vendor": "microsoft"
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-34049/",
      "current_public_safe_latest": false,
      "cvss_score": 3.3,
      "cvss_severity": "LOW",
      "epss_percentile": 0.09379,
      "epss_score": 0.00195,
      "first_observed_at": "2026-07-13T22:14:02.217047+00:00",
      "id": "CVE-2026-34049",
      "impact_tags": [
        "command injection risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-13T22:14:02.217047+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. NVD: From 4.0.0-beta.451 through 4.0.0-beta.470, database backup handling for MongoDB collection names did not fully validate shell metacharacters, allowing a highly privileged attacker who can configure backup inputs to inject commands. NVD: This issue is fixed in version 4.0.0-beta.471.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260714T042224Z/items/CVE-2026-34049.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes command injection risk. Possible impact: An attacker may be able to run unintended system commands through the affected component.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. NVD: From 4.0.0-beta.451 through 4.0.0-beta.470, database backup handling for MongoDB collection names did not fully validate shell metacharacters, allowing a highly privileged attacker who can configure backup inputs to inject commands. NVD: This issue is fixed in version 4.0.0-beta.471.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-34049/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-34050/",
      "current_public_safe_latest": false,
      "cvss_score": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.11599,
      "epss_score": 0.00213,
      "first_observed_at": "2026-07-13T22:14:02.217047+00:00",
      "id": "CVE-2026-34050",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-13T22:14:02.217047+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. NVD: Prior to 4.0.0-beta.471, the Settings/Updates Livewire component does not check isInstanceAdmin in its mount method, allowing non-admin users to access the Updates settings page and potentially modify auto-update settings or trigger update checks. NVD: This issue is fixed in version 4.0.0-beta.471.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260714T042224Z/items/CVE-2026-34050.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. NVD: Prior to 4.0.0-beta.471, the Settings/Updates Livewire component does not check isInstanceAdmin in its mount method, allowing non-admin users to access the Updates settings page and potentially modify auto-update settings or trigger update checks. NVD: This issue is fixed in version 4.0.0-beta.471.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-34050/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "wazuh / wazuh",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-34150/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.13066,
      "epss_score": 0.00224,
      "first_observed_at": "2026-07-23T22:18:14.498937+00:00",
      "id": "CVE-2026-34150",
      "impact_tags": [
        "memory safety review",
        "remote exposure relevant"
      ],
      "kev": false,
      "last_observed_at": "2026-07-23T22:18:14.498937+00:00",
      "latest_item_url": null,
      "product": "wazuh",
      "public_safe_summary": "NVD: Wazuh is a free and open source platform used for threat prevention, detection, and response. NVD: In versions 1.0.0 and above, prior to 4.14.5, a heap buffer overflow in wazuh-analysisd allows an unauthenticated remote attacker to crash the Wazuh manager's analysis engine, causing complete loss of SIEM alert processing. NVD: The attack exploits the default configuration shipped in the official wazuh/wazuh-docker deployment with default configuration.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260723T222557Z/items/CVE-2026-34150.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: wazuh / wazuh",
      "source_published_impact": "Source describes memory safety review · remote exposure. Possible impact: The affected component has memory-safety risk that may lead to crash, privilege, or code-execution impact depending on exposure.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Wazuh is a free and open source platform used for threat prevention, detection, and response. NVD: In versions 1.0.0 and above, prior to 4.14.5, a heap buffer overflow in wazuh-analysisd allows an unauthenticated remote attacker to crash the Wazuh manager's analysis engine, causing complete loss of SIEM alert processing. NVD: The attack exploits the default configuration shipped in the official wazuh/wazuh-docker deployment with default configuration.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-34150/timeline.json",
      "vendor": "wazuh"
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-34153/",
      "current_public_safe_latest": false,
      "cvss_score": 8.8,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.32429,
      "epss_score": 0.00403,
      "first_observed_at": "2026-07-13T22:14:02.217047+00:00",
      "id": "CVE-2026-34153",
      "impact_tags": [
        "code execution review",
        "command execution review",
        "command injection risk",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-13T22:14:02.217047+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. NVD: Prior to 4.0.0-beta.471, LocalFileVolume::saveStorageOnServer builds shell commands using unescaped fs_path and parent_dir values before validation, and submitFileStorage does not validate the user-controlled file-mount path before creating a volume, allowing... NVD: This issue is fixed in version 4.0.0-beta.471.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260714T042224Z/items/CVE-2026-34153.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes code execution review · command execution risk · command injection risk. Possible impact: An attacker may be able to run code or commands on affected systems.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. NVD: Prior to 4.0.0-beta.471, LocalFileVolume::saveStorageOnServer builds shell commands using unescaped fs_path and parent_dir values before validation, and submitFileStorage does not validate the user-controlled file-mount path before creating a volume, allowing... NVD: This issue is fixed in version 4.0.0-beta.471.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-34153/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-34167/",
      "current_public_safe_latest": false,
      "cvss_score": 5.0,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.0987,
      "epss_score": 0.00199,
      "first_observed_at": "2026-07-13T22:14:02.217047+00:00",
      "id": "CVE-2026-34167",
      "impact_tags": [
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-13T22:14:02.217047+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. NVD: Prior to 4.0.0-beta.471, the ActivityMonitor Livewire component exposes a public $activityId property without Livewire's #[Locked] attribute. NVD: It loads activities via Activity::find($this->activityId) with no authorization or team scoping.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260714T042224Z/items/CVE-2026-34167.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. NVD: Prior to 4.0.0-beta.471, the ActivityMonitor Livewire component exposes a public $activityId property without Livewire's #[Locked] attribute. NVD: It loads activities via Activity::find($this->activityId) with no authorization or team scoping.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-34167/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "microsoft / windows_10_1809",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-34328/",
      "current_public_safe_latest": false,
      "cvss_score": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.27722,
      "epss_score": 0.00353,
      "first_observed_at": "2026-07-21T16:48:32.557544+00:00",
      "id": "CVE-2026-34328",
      "impact_tags": [
        "information exposure review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-21T16:48:32.557544+00:00",
      "latest_item_url": null,
      "product": "windows_10_1809",
      "public_safe_summary": "NVD: Exposure of sensitive information to an unauthorized actor in Windows Audio Service allows an authorized attacker to disclose information locally.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260721T165442Z/items/CVE-2026-34328.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: microsoft / windows_10_1809",
      "source_published_impact": "Source describes information exposure review. Possible impact: An attacker may be able to access information that should not be exposed.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Exposure of sensitive information to an unauthorized actor in Windows Audio Service allows an authorized attacker to disclose information locally.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-34328/timeline.json",
      "vendor": "microsoft"
    },
    {
      "affected_label": "microsoft / windows_10_1607",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-34346/",
      "current_public_safe_latest": false,
      "cvss_score": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.10357,
      "epss_score": 0.00202,
      "first_observed_at": "2026-07-21T16:48:32.557544+00:00",
      "id": "CVE-2026-34346",
      "impact_tags": [
        "information exposure review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-21T16:48:32.557544+00:00",
      "latest_item_url": null,
      "product": "windows_10_1607",
      "public_safe_summary": "NVD: Cleartext transmission of sensitive information in Windows Ancillary Function Driver for WinSock allows an authorized attacker to disclose information locally.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260721T165442Z/items/CVE-2026-34346.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: microsoft / windows_10_1607; affected version context: -, r2",
      "source_published_impact": "Source describes information exposure review. Possible impact: An attacker may be able to access information that should not be exposed.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Cleartext transmission of sensitive information in Windows Ancillary Function Driver for WinSock allows an authorized attacker to disclose information locally.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-34346/timeline.json",
      "vendor": "microsoft"
    },
    {
      "affected_label": "microsoft / windows_10_1809",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-34348/",
      "current_public_safe_latest": false,
      "cvss_score": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.49691,
      "epss_score": 0.00715,
      "first_observed_at": "2026-07-21T16:48:32.557544+00:00",
      "id": "CVE-2026-34348",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-21T16:48:32.557544+00:00",
      "latest_item_url": null,
      "product": "windows_10_1809",
      "public_safe_summary": "NVD: Protection mechanism failure in Windows Event Logging Service allows an authorized attacker to disclose information over a network.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260721T165442Z/items/CVE-2026-34348.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: microsoft / windows_10_1809",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Protection mechanism failure in Windows Event Logging Service allows an authorized attacker to disclose information over a network.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-34348/timeline.json",
      "vendor": "microsoft"
    },
    {
      "affected_label": "microsoft / windows_10_1809",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-34349/",
      "current_public_safe_latest": false,
      "cvss_score": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.2777,
      "epss_score": 0.00354,
      "first_observed_at": "2026-07-21T16:48:32.557544+00:00",
      "id": "CVE-2026-34349",
      "impact_tags": [
        "information exposure review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-21T16:48:32.557544+00:00",
      "latest_item_url": null,
      "product": "windows_10_1809",
      "public_safe_summary": "NVD: Exposure of sensitive information to an unauthorized actor in Windows Media allows an authorized attacker to disclose information locally.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260721T165442Z/items/CVE-2026-34349.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: microsoft / windows_10_1809",
      "source_published_impact": "Source describes information exposure review. Possible impact: An attacker may be able to access information that should not be exposed.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Exposure of sensitive information to an unauthorized actor in Windows Media allows an authorized attacker to disclose information locally.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-34349/timeline.json",
      "vendor": "microsoft"
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-34599/",
      "current_public_safe_latest": false,
      "cvss_score": 8.8,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.69017,
      "epss_score": 0.01385,
      "first_observed_at": "2026-07-13T22:14:02.217047+00:00",
      "id": "CVE-2026-34599",
      "impact_tags": [
        "code execution review",
        "admin privilege risk",
        "command injection risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-13T22:14:02.217047+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. NVD: Prior to 4.0.0-beta.471, there is an authenticated command injection vulnerability in the GetLogs Livewire component which allows users with team membership (lowest privilege member role) to execute arbitrary commands as root on managed servers. NVD: The $container Livewire public property is interpolated directly into shell commands (docker logs, docker service logs) without sanitization, and can be modified by any client via the Livewire wire protocol because it lacks the #[Locked] attribute.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260714T042224Z/items/CVE-2026-34599.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes code execution review · admin privilege risk · command injection risk. Possible impact: An attacker may gain root or administrative-level privileges on affected systems.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. NVD: Prior to 4.0.0-beta.471, there is an authenticated command injection vulnerability in the GetLogs Livewire component which allows users with team membership (lowest privilege member role) to execute arbitrary commands as root on managed servers. NVD: The $container Livewire public property is interpolated directly into shell commands (docker logs, docker service logs) without sanitization, and can be modified by any client via the Livewire wire protocol because it lacks the #[Locked] attribute.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-34599/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "adobe / premiere",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-34641/",
      "current_public_safe_latest": false,
      "cvss_score": 7.8,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.03691,
      "epss_score": 0.00139,
      "first_observed_at": "2026-08-07T21:58:42.606809+00:00",
      "id": "CVE-2026-34641",
      "impact_tags": [
        "code execution review",
        "user interaction review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-07T21:58:42.606809+00:00",
      "latest_item_url": null,
      "product": "premiere",
      "public_safe_summary": "NVD: Premiere Pro is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. NVD: Exploitation of this issue requires user interaction in that a victim must open a malicious file.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260807T220457Z/items/CVE-2026-34641.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: adobe / premiere; affected version context: -",
      "source_published_impact": "Source describes code execution review · user interaction required. Possible impact: An attacker may be able to run code or commands on affected systems.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Premiere Pro is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. NVD: Exploitation of this issue requires user interaction in that a victim must open a malicious file.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-34641/timeline.json",
      "vendor": "adobe"
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-3482/",
      "current_public_safe_latest": false,
      "cvss_score": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.19548,
      "epss_score": 0.00274,
      "first_observed_at": "2026-07-29T16:40:34.107276+00:00",
      "id": "CVE-2026-3482",
      "impact_tags": [
        "information exposure review",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-29T16:40:34.107276+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 could allow an unauthenticated user to read sensitive information by bypassing authentication through a specially...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260729T164826Z/items/CVE-2026-3482.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes information exposure review · authenticated boundary. Possible impact: An attacker may be able to access information that should not be exposed.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 could allow an unauthenticated user to read sensitive information by bypassing authentication through a specially...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-3482/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-35048/",
      "current_public_safe_latest": false,
      "cvss_score": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.24517,
      "epss_score": 0.00322,
      "first_observed_at": "2026-07-27T17:12:53.854417+00:00",
      "id": "CVE-2026-35048",
      "impact_tags": [
        "code execution review",
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-27T17:12:53.854417+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Piwigo installer in versions 16.3.0 and earlier accepts POST parameters for database configuration and writes them directly into a PHP configuration file without proper sanitization. NVD: On PHP 8+, the addslashes() protection is bypassed because it checks for get_magic_quotes_gpc(), a function removed in PHP 8.0. NVD: This allows raw user input to be interpolated directly into PHP source code.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260727T171933Z/items/CVE-2026-35048.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes code execution review · remote exposure · authenticated boundary. Possible impact: A remote attacker may be able to run code or commands on affected systems.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Piwigo installer in versions 16.3.0 and earlier accepts POST parameters for database configuration and writes them directly into a PHP configuration file without proper sanitization. NVD: On PHP 8+, the addslashes() protection is bypassed because it checks for get_magic_quotes_gpc(), a function removed in PHP 8.0. NVD: This allows raw user input to be interpolated directly into PHP source code.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-35048/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "hcltech / dfxanalytics",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-35140/",
      "current_public_safe_latest": false,
      "cvss_score": 3.0,
      "cvss_severity": "LOW",
      "epss_percentile": 0.05768,
      "epss_score": 0.00161,
      "first_observed_at": "2026-07-23T11:21:51.498947+00:00",
      "id": "CVE-2026-35140",
      "impact_tags": [
        "remote exposure relevant"
      ],
      "kev": false,
      "last_observed_at": "2026-07-23T11:21:51.498947+00:00",
      "latest_item_url": null,
      "product": "dfxanalytics",
      "public_safe_summary": "NVD: HCL DFXAnalytics is affected by a Missing Secure Attribute in Encrypted Session (SSL) Cookie vulnerability. NVD: The application fails to set the \"secure\" attribute on session cookies generated during authentication, which could allow a remote attacker to intercept network traffic and capture sensitive cookies, session tokens, or credentials sent in cleartext over...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260723T112431Z/items/CVE-2026-35140.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: hcltech / dfxanalytics",
      "source_published_impact": "Source describes remote exposure. Possible impact: This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: HCL DFXAnalytics is affected by a Missing Secure Attribute in Encrypted Session (SSL) Cookie vulnerability. NVD: The application fails to set the \"secure\" attribute on session cookies generated during authentication, which could allow a remote attacker to intercept network traffic and capture sensitive cookies, session tokens, or credentials sent in cleartext over...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-35140/timeline.json",
      "vendor": "hcltech"
    },
    {
      "affected_label": "hcltech / dfxanalytics",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-35141/",
      "current_public_safe_latest": false,
      "cvss_score": 2.6,
      "cvss_severity": "LOW",
      "epss_percentile": 0.09114,
      "epss_score": 0.00192,
      "first_observed_at": "2026-07-23T11:21:51.498947+00:00",
      "id": "CVE-2026-35141",
      "impact_tags": [
        "unauthorized access risk",
        "remote exposure relevant"
      ],
      "kev": false,
      "last_observed_at": "2026-07-23T11:21:51.498947+00:00",
      "latest_item_url": null,
      "product": "dfxanalytics",
      "public_safe_summary": "NVD: HCL DFXAnalytics is affected by a Login Replay Attack vulnerability. NVD: The application allows a remote attacker to intercept, delay, or fraudulently retransmit valid authentication data to achieve unauthorized access. NVD: To mitigate this risk, the application must implement a mechanism to include timestamps with every message, ensuring that messages exceeding a specific age threshold are automatically rejected by the recipient system.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260723T112431Z/items/CVE-2026-35141.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: hcltech / dfxanalytics",
      "source_published_impact": "Source describes unauthorized access risk · remote exposure. Possible impact: A remote attacker may access resources that should require stronger authorization.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: HCL DFXAnalytics is affected by a Login Replay Attack vulnerability. NVD: The application allows a remote attacker to intercept, delay, or fraudulently retransmit valid authentication data to achieve unauthorized access. NVD: To mitigate this risk, the application must implement a mechanism to include timestamps with every message, ensuring that messages exceeding a specific age threshold are automatically rejected by the recipient system.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-35141/timeline.json",
      "vendor": "hcltech"
    },
    {
      "affected_label": "hcltech / dfxanalytics",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-35142/",
      "current_public_safe_latest": false,
      "cvss_score": 2.6,
      "cvss_severity": "LOW",
      "epss_percentile": 0.08179,
      "epss_score": 0.00183,
      "first_observed_at": "2026-07-23T11:21:51.498947+00:00",
      "id": "CVE-2026-35142",
      "impact_tags": [
        "remote exposure relevant"
      ],
      "kev": false,
      "last_observed_at": "2026-07-23T11:21:51.498947+00:00",
      "latest_item_url": null,
      "product": "dfxanalytics",
      "public_safe_summary": "NVD: HCL DFXAnalytics is affected by an Internal IP Address Disclosure vulnerability. NVD: The application includes internal IP address details within its generated server responses, which could allow a remote attacker to gather sensitive network topology information and use it to map the internal infrastructure for further targeted attacks.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260723T112431Z/items/CVE-2026-35142.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: hcltech / dfxanalytics",
      "source_published_impact": "Source describes remote exposure. Possible impact: This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: HCL DFXAnalytics is affected by an Internal IP Address Disclosure vulnerability. NVD: The application includes internal IP address details within its generated server responses, which could allow a remote attacker to gather sensitive network topology information and use it to map the internal infrastructure for further targeted attacks.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-35142/timeline.json",
      "vendor": "hcltech"
    },
    {
      "affected_label": "hcltech / dfxanalytics",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-35143/",
      "current_public_safe_latest": false,
      "cvss_score": 3.0,
      "cvss_severity": "LOW",
      "epss_percentile": 0.01439,
      "epss_score": 0.00108,
      "first_observed_at": "2026-07-23T11:21:51.498947+00:00",
      "id": "CVE-2026-35143",
      "impact_tags": [
        "remote exposure relevant"
      ],
      "kev": false,
      "last_observed_at": "2026-07-23T11:21:51.498947+00:00",
      "latest_item_url": null,
      "product": "dfxanalytics",
      "public_safe_summary": "NVD: HCL DFXAnalytics is affected by a Missing SameSite Attribute vulnerability. NVD: The application fails to set the \"SameSite\" attribute on session cookies generated during authentication, which could allow a remote attacker to execute Cross-Site Request Forgery (CSRF) attacks if additional mitigations, such as Anti-CSRF tokens, are not...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260723T112431Z/items/CVE-2026-35143.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: hcltech / dfxanalytics",
      "source_published_impact": "Source describes remote exposure. Possible impact: This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: HCL DFXAnalytics is affected by a Missing SameSite Attribute vulnerability. NVD: The application fails to set the \"SameSite\" attribute on session cookies generated during authentication, which could allow a remote attacker to execute Cross-Site Request Forgery (CSRF) attacks if additional mitigations, such as Anti-CSRF tokens, are not...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-35143/timeline.json",
      "vendor": "hcltech"
    },
    {
      "affected_label": "hcltech / dfxanalytics",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-35145/",
      "current_public_safe_latest": false,
      "cvss_score": 3.1,
      "cvss_severity": "LOW",
      "epss_percentile": 0.06998,
      "epss_score": 0.00173,
      "first_observed_at": "2026-07-23T11:21:51.498947+00:00",
      "id": "CVE-2026-35145",
      "impact_tags": [
        "remote exposure relevant"
      ],
      "kev": false,
      "last_observed_at": "2026-07-23T11:21:51.498947+00:00",
      "latest_item_url": null,
      "product": "dfxanalytics",
      "public_safe_summary": "NVD: HCL DFXAnalytics is affected by a Missing HTTP Strict-Transport-Security Header vulnerability. NVD: The application fails to implement the HTTP Strict Transport Security (HSTS) policy within its responses, which could allow a remote attacker to downgrade the communication channel to an unencrypted connection (HTTP) and conduct man-in-the-middle (MitM)... NVD: To remediate this, the application must include the \"Strict-Transport-Security\" header in all web application responses.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260723T112431Z/items/CVE-2026-35145.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: hcltech / dfxanalytics",
      "source_published_impact": "Source describes remote exposure. Possible impact: This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: HCL DFXAnalytics is affected by a Missing HTTP Strict-Transport-Security Header vulnerability. NVD: The application fails to implement the HTTP Strict Transport Security (HSTS) policy within its responses, which could allow a remote attacker to downgrade the communication channel to an unencrypted connection (HTTP) and conduct man-in-the-middle (MitM)... NVD: To remediate this, the application must include the \"Strict-Transport-Security\" header in all web application responses.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-35145/timeline.json",
      "vendor": "hcltech"
    },
    {
      "affected_label": "hcltech / dfx_server",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-35146/",
      "current_public_safe_latest": false,
      "cvss_score": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.01924,
      "epss_score": 0.00116,
      "first_observed_at": "2026-07-23T11:21:51.498947+00:00",
      "id": "CVE-2026-35146",
      "impact_tags": [
        "remote exposure relevant"
      ],
      "kev": false,
      "last_observed_at": "2026-07-23T11:21:51.498947+00:00",
      "latest_item_url": null,
      "product": "dfx_server",
      "public_safe_summary": "NVD: HCL DFXServer is affected by an Unencrypted Communication vulnerability. NVD: The application permits users to establish connections over unencrypted channels via the HTTP protocol, which could allow a remote attacker to intercept network traffic and expose sensitive data transmitted between the user and the application.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260723T112431Z/items/CVE-2026-35146.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: hcltech / dfx_server",
      "source_published_impact": "Source describes remote exposure. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: HCL DFXServer is affected by an Unencrypted Communication vulnerability. NVD: The application permits users to establish connections over unencrypted channels via the HTTP protocol, which could allow a remote attacker to intercept network traffic and expose sensitive data transmitted between the user and the application.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-35146/timeline.json",
      "vendor": "hcltech"
    },
    {
      "affected_label": "hcltech / dfx_server",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-35147/",
      "current_public_safe_latest": false,
      "cvss_score": 8.2,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.17876,
      "epss_score": 0.00262,
      "first_observed_at": "2026-07-23T11:21:51.498947+00:00",
      "id": "CVE-2026-35147",
      "impact_tags": [
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-23T11:21:51.498947+00:00",
      "latest_item_url": null,
      "product": "dfx_server",
      "public_safe_summary": "NVD: HCL DFXServer is affected by a Broken Authentication vulnerability via direct API access. NVD: The application fails to verify the user's authentication status when accessing specific API endpoints, allowing an unauthenticated attacker to interact with the APIs and perform unauthorized actions without valid credentials.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260723T112431Z/items/CVE-2026-35147.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: hcltech / dfx_server",
      "source_published_impact": "Source describes remote exposure · authenticated boundary. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: HCL DFXServer is affected by a Broken Authentication vulnerability via direct API access. NVD: The application fails to verify the user's authentication status when accessing specific API endpoints, allowing an unauthenticated attacker to interact with the APIs and perform unauthorized actions without valid credentials.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-35147/timeline.json",
      "vendor": "hcltech"
    },
    {
      "affected_label": "hcltech / dfx_server",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-35148/",
      "current_public_safe_latest": false,
      "cvss_score": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.06381,
      "epss_score": 0.00167,
      "first_observed_at": "2026-07-23T11:21:51.498947+00:00",
      "id": "CVE-2026-35148",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-23T11:21:51.498947+00:00",
      "latest_item_url": null,
      "product": "dfx_server",
      "public_safe_summary": "NVD: HCL DFXServer is affected by a Missing Access Control vulnerability. NVD: This vulnerability states that certain endpoints are accessible without any form of authentication in another browser. NVD: This allows any network user to invoke these APIs and interact with the application without verification of their identity or authorization level.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260723T112431Z/items/CVE-2026-35148.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: hcltech / dfx_server",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: HCL DFXServer is affected by a Missing Access Control vulnerability. NVD: This vulnerability states that certain endpoints are accessible without any form of authentication in another browser. NVD: This allows any network user to invoke these APIs and interact with the application without verification of their identity or authorization level.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-35148/timeline.json",
      "vendor": "hcltech"
    },
    {
      "affected_label": "hcltech / dfx_server",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-35149/",
      "current_public_safe_latest": false,
      "cvss_score": 8.2,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.15478,
      "epss_score": 0.00242,
      "first_observed_at": "2026-07-23T11:21:51.498947+00:00",
      "id": "CVE-2026-35149",
      "impact_tags": [
        "unauthorized access risk",
        "authentication boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-23T11:21:51.498947+00:00",
      "latest_item_url": null,
      "product": "dfx_server",
      "public_safe_summary": "NVD: HCL DFXServer is affected by an Authentication Bypass vulnerability via server response manipulation. NVD: An unauthorized user without valid credentials can exploit this flaw by intercepting and altering the server's authentication responses, allowing them to gain unauthorized access to the application without verification.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260723T112431Z/items/CVE-2026-35149.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: hcltech / dfx_server",
      "source_published_impact": "Source describes unauthorized access risk · authentication boundary review. Possible impact: An attacker may access resources that should require stronger authorization.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: HCL DFXServer is affected by an Authentication Bypass vulnerability via server response manipulation. NVD: An unauthorized user without valid credentials can exploit this flaw by intercepting and altering the server's authentication responses, allowing them to gain unauthorized access to the application without verification.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-35149/timeline.json",
      "vendor": "hcltech"
    },
    {
      "affected_label": "apache / fineract",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-35152/",
      "current_public_safe_latest": false,
      "cvss_score": 8.8,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.87867,
      "epss_score": 0.03492,
      "first_observed_at": "2026-07-22T06:07:21.492959+00:00",
      "id": "CVE-2026-35152",
      "impact_tags": [
        "unauthorized access risk",
        "SQL injection risk",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-22T06:07:21.492959+00:00",
      "latest_item_url": null,
      "product": "fineract",
      "public_safe_summary": "NVD: A SQL Injection vulnerability exists in Apache Fineract's Report Execution API (runreports endpoint) in versions up to and including 1.14.0. NVD: Report parameter values are incorporated into the generated SQL query without sufficient validation, allowing an authenticated user with permission to run reports to inject arbitrary SQL via crafted parameter values. NVD: This can be leveraged to perform unauthorized access to data beyond what the report was designed to expose.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260722T060931Z/items/CVE-2026-35152.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: apache / fineract",
      "source_published_impact": "Source describes unauthorized access risk · SQL injection risk · authenticated boundary. Possible impact: An attacker may be able to read or change database-backed application data.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: a.",
      "source_published_summary": "NVD: A SQL Injection vulnerability exists in Apache Fineract's Report Execution API (runreports endpoint) in versions up to and including 1.14.0. NVD: Report parameter values are incorporated into the generated SQL query without sufficient validation, allowing an authenticated user with permission to run reports to inject arbitrary SQL via crafted parameter values. NVD: This can be leveraged to perform unauthorized access to data beyond what the report was designed to expose.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-35152/timeline.json",
      "vendor": "apache"
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-35217/",
      "current_public_safe_latest": false,
      "cvss_score": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.09362,
      "epss_score": 0.00194,
      "first_observed_at": "2026-07-27T17:12:53.854417+00:00",
      "id": "CVE-2026-35217",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-27T17:12:53.854417+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: NanoMQ contains a protocol-semantics flaw in its MQTT v5 SUBSCRIBE handling: if a subscription entry is missing the final 1-byte Subscription Options field, the broker may still accept the malformed packet and install the subscription into internal broker... NVD: Under a specific packet-length construction, the same parser flaw also causes a 1-byte out-of-bounds read that crosses the real heap allocation boundary and is detected by ASAN as a heap-buffer-overflow. NVD: If the consumed byte happens to look acceptable, NanoMQ may continue and append the malformed subscription entry into its internal subinfol state.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260727T171933Z/items/CVE-2026-35217.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: NanoMQ contains a protocol-semantics flaw in its MQTT v5 SUBSCRIBE handling: if a subscription entry is missing the final 1-byte Subscription Options field, the broker may still accept the malformed packet and install the subscription into internal broker... NVD: Under a specific packet-length construction, the same parser flaw also causes a 1-byte out-of-bounds read that crosses the real heap allocation boundary and is detected by ASAN as a heap-buffer-overflow. NVD: If the consumed byte happens to look acceptable, NanoMQ may continue and append the malformed subscription entry into its internal subinfol state.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-35217/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-35425/",
      "current_public_safe_latest": false,
      "cvss_score": 8.0,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.39028,
      "epss_score": 0.00483,
      "first_observed_at": "2026-07-30T22:30:38.166118+00:00",
      "id": "CVE-2026-35425",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-30T22:30:38.166118+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Improper access control in Azure API Management (APIM) allows an authorized attacker to execute code over a network.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260730T224832Z/items/CVE-2026-35425.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Improper access control in Azure API Management (APIM) allows an authorized attacker to execute code over a network.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-35425/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-3552/",
      "current_public_safe_latest": false,
      "cvss_score": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.11637,
      "epss_score": 0.00213,
      "first_observed_at": "2026-07-18T05:13:28.850753+00:00",
      "id": "CVE-2026-3552",
      "impact_tags": [
        "service availability review",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-18T05:13:28.850753+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The SurfLink - Ultimate Link Manager plugin for WordPress is vulnerable to unauthorized data modification due to a missing capability check on the ajax_import_410() function in all versions up to 2.6.0. NVD: This is due to a missing capability check (current_user_can()) and missing nonce verification (check_ajax_referer()) in the ajax_import_410() function, while all other AJAX handlers in the same class (ajax_add_single_410, ajax_save_editted_410... NVD: This makes it possible for authenticated attackers, with Subscriber-level access and above, to import arbitrary URLs into the 410 Gone database table via the surfl_import_410 AJAX action.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260718T051545Z/items/CVE-2026-3552.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes service availability risk · authenticated boundary. Possible impact: The affected service may become unavailable or unreliable.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The SurfLink - Ultimate Link Manager plugin for WordPress is vulnerable to unauthorized data modification due to a missing capability check on the ajax_import_410() function in all versions up to 2.6.0. NVD: This is due to a missing capability check (current_user_can()) and missing nonce verification (check_ajax_referer()) in the ajax_import_410() function, while all other AJAX handlers in the same class (ajax_add_single_410, ajax_save_editted_410... NVD: This makes it possible for authenticated attackers, with Subscriber-level access and above, to import arbitrary URLs into the 410 Gone database table via the surfl_import_410 AJAX action.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-3552/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-35552/",
      "current_public_safe_latest": false,
      "cvss_score": 8.1,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.19556,
      "epss_score": 0.00276,
      "first_observed_at": "2026-07-15T22:16:59.245057+00:00",
      "id": "CVE-2026-35552",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-15T22:16:59.245057+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: In CAXperts UPVWebServices 2.4.2212.603 through 2.7.6 and UDiTH Portal 2026.0.0 through 2026.2.0, an authenticated remote user can invoke an administrative API endpoint intended for privileged users. NVD: Due to missing authorization checks, this allows the attacker to deactivate the application's license.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260715T221956Z/items/CVE-2026-35552.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: In CAXperts UPVWebServices 2.4.2212.603 through 2.7.6 and UDiTH Portal 2026.0.0 through 2026.2.0, an authenticated remote user can invoke an administrative API endpoint intended for privileged users. NVD: Due to missing authorization checks, this allows the attacker to deactivate the application's license.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-35552/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-35590/",
      "current_public_safe_latest": false,
      "cvss_score": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.02126,
      "epss_score": 0.0012,
      "first_observed_at": "2026-07-27T17:12:53.854417+00:00",
      "id": "CVE-2026-35590",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-27T17:12:53.854417+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: libvips is a fast image processing library with low memory needs. NVD: The EXIF decoder within libvips versions before and including 8.18.1 was not verifying the range of EXIF tag groups before passing data to libexif, leading to a possible null pointer dereference and crash. NVD: This has been patched in version 8.18.2.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260727T171933Z/items/CVE-2026-35590.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: libvips is a fast image processing library with low memory needs. NVD: The EXIF decoder within libvips versions before and including 8.18.1 was not verifying the range of EXIF tag groups before passing data to libexif, leading to a possible null pointer dereference and crash. NVD: This has been patched in version 8.18.2.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-35590/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-35591/",
      "current_public_safe_latest": false,
      "cvss_score": 7.0,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.03151,
      "epss_score": 0.00132,
      "first_observed_at": "2026-07-27T17:12:53.854417+00:00",
      "id": "CVE-2026-35591",
      "impact_tags": [
        "memory safety review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-27T17:12:53.854417+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: libvips is a fast image processing library with low memory needs. NVD: The tiffload operation in libvips versions before and including 8.18.1 could incorrectly determine the number of channels in a JPEG or JPEG2000-encoded tile within a TIFF image, leading to a possible buffer overflow. NVD: This has been patched in version 8.18.2.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260727T171933Z/items/CVE-2026-35591.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes memory safety review. Possible impact: The affected component has memory-safety risk that may lead to crash, privilege, or code-execution impact depending on exposure.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: libvips is a fast image processing library with low memory needs. NVD: The tiffload operation in libvips versions before and including 8.18.1 could incorrectly determine the number of channels in a JPEG or JPEG2000-encoded tile within a TIFF image, leading to a possible buffer overflow. NVD: This has been patched in version 8.18.2.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-35591/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-3576/",
      "current_public_safe_latest": false,
      "cvss_score": 7.2,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.27945,
      "epss_score": 0.00357,
      "first_observed_at": "2026-07-18T05:13:28.850753+00:00",
      "id": "CVE-2026-3576",
      "impact_tags": [
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-18T05:13:28.850753+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Planyo Online Reservation System plugin for WordPress is vulnerable to Server-Side Request Forgery leading to Local File Inclusion in all versions up to, and including, 3.0. NVD: The ulap.php file acts as an AJAX proxy and is directly accessible without WordPress bootstrapping or any authentication. NVD: The send_http_post() function validates the host of the provided URL against an allowlist that includes 'localhost', but critically fails to validate the URL scheme/protocol.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260718T051545Z/items/CVE-2026-3576.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes remote exposure · authenticated boundary. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Planyo Online Reservation System plugin for WordPress is vulnerable to Server-Side Request Forgery leading to Local File Inclusion in all versions up to, and including, 3.0. NVD: The ulap.php file acts as an AJAX proxy and is directly accessible without WordPress bootstrapping or any authentication. NVD: The send_http_post() function validates the host of the provided URL against an allowlist that includes 'localhost', but critically fails to validate the URL scheme/protocol.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-3576/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-36162/",
      "current_public_safe_latest": false,
      "cvss_score": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.03837,
      "epss_score": 0.00141,
      "first_observed_at": "2026-07-14T22:16:58.989760+00:00",
      "id": "CVE-2026-36162",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-14T22:16:58.989760+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "CVE-2026-36162: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review. Human-readable risk label: defensive exposure review. CVSS 5.4 (MEDIUM) helps set defensive review priority. EPSS percentile is 4. Official references are linked for patch or mitigation review.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260714T222111Z/items/CVE-2026-36162.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-36162/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-36163/",
      "current_public_safe_latest": false,
      "cvss_score": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.03839,
      "epss_score": 0.00141,
      "first_observed_at": "2026-07-14T22:16:58.989760+00:00",
      "id": "CVE-2026-36163",
      "impact_tags": [
        "authenticated boundary review",
        "user interaction review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-14T22:16:58.989760+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: An HTML injection vulnerability in the file view endpoint of LiquidFiles v4.2.7 allows authenticated attackers to execute arbitrary JavaScript in the context of the victim's browser via the uploading of and user interaction with a crafted HTML file.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260714T222111Z/items/CVE-2026-36163.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes authenticated boundary · user interaction required. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary · user interaction required.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: An HTML injection vulnerability in the file view endpoint of LiquidFiles v4.2.7 allows authenticated attackers to execute arbitrary JavaScript in the context of the victim's browser via the uploading of and user interaction with a crafted HTML file.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-36163/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-36214/",
      "current_public_safe_latest": false,
      "cvss_score": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.25204,
      "epss_score": 0.0033,
      "first_observed_at": "2026-07-21T16:48:32.557544+00:00",
      "id": "CVE-2026-36214",
      "impact_tags": [
        "XSS risk",
        "remote exposure relevant"
      ],
      "kev": false,
      "last_observed_at": "2026-07-21T16:48:32.557544+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: osTicket versions from 1.10 up to 1.17.7 and from 1.18.0 up to 1.18.3 are vulnerable to a stored XSS due to a vulnerable Bootstrap Tooltip component and insufficient HTML sanitization, allowing remote attackers to execute arbitrary JavaScript in Agent or... OSV: osTicket versions from 1.10 up to 1.17.7 and from 1.18.0 up to 1.18.3 are vulnerable to a stored XSS due to a vulnerable Bootstrap Tooltip component and insufficient HTML sanitization, allowing remote attackers to execute arbitrary JavaScript in Agent or...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260721T165442Z/items/CVE-2026-36214.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes XSS risk · remote exposure. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk · remote exposure.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: osTicket versions from 1.10 up to 1.17.7 and from 1.18.0 up to 1.18.3 are vulnerable to a stored XSS due to a vulnerable Bootstrap Tooltip component and insufficient HTML sanitization, allowing remote attackers to execute arbitrary JavaScript in Agent or... OSV: osTicket versions from 1.10 up to 1.17.7 and from 1.18.0 up to 1.18.3 are vulnerable to a stored XSS due to a vulnerable Bootstrap Tooltip component and insufficient HTML sanitization, allowing remote attackers to execute arbitrary JavaScript in Agent or...",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-36214/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-3688/",
      "current_public_safe_latest": false,
      "cvss_score": 8.1,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.12826,
      "epss_score": 0.00223,
      "first_observed_at": "2026-07-15T11:03:27.604769+00:00",
      "id": "CVE-2026-3688",
      "impact_tags": [
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-15T11:03:27.604769+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The WCFM Membership – WooCommerce Memberships for Multivendor Marketplace plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.11.10. NVD: This is due to the 'wcfmvm_membership_change' AJAX action not validating user permission to modify other users. NVD: This makes it possible for authenticated attackers, with vendor level access and above, to change any user's role to 'wcfm_vendor' by changing their membership plan.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260715T110622Z/items/CVE-2026-3688.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes authenticated boundary. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The WCFM Membership – WooCommerce Memberships for Multivendor Marketplace plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.11.10. NVD: This is due to the 'wcfmvm_membership_change' AJAX action not validating user permission to modify other users. NVD: This makes it possible for authenticated attackers, with vendor level access and above, to change any user's role to 'wcfm_vendor' by changing their membership plan.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-3688/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-37270/",
      "current_public_safe_latest": false,
      "cvss_score": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.29574,
      "epss_score": 0.00374,
      "first_observed_at": "2026-07-14T22:16:58.989760+00:00",
      "id": "CVE-2026-37270",
      "impact_tags": [
        "authentication boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-14T22:16:58.989760+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Trueview Security camera T18161- AF v4.9.60.0 contains an authentication bypass vulnerability caused by improper password validation and the presence of hard-coded credentials in the firmware.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260714T222111Z/items/CVE-2026-37270.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes authentication boundary review. Possible impact: This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authentication boundary review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Trueview Security camera T18161- AF v4.9.60.0 contains an authentication bypass vulnerability caused by improper password validation and the presence of hard-coded credentials in the firmware.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-37270/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-37271/",
      "current_public_safe_latest": false,
      "cvss_score": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.29418,
      "epss_score": 0.00373,
      "first_observed_at": "2026-07-14T22:16:58.989760+00:00",
      "id": "CVE-2026-37271",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-14T22:16:58.989760+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Fire-Boltt Smartwatch FB BGS001 Firmware: MOY-JS14-2.0.4 is vulnerable to Improper Authentication, The device accepts GATT Write Request commands without sufficient authentication or strong session validation. NVD: Under specific conditions, previously captured BLE packets can be replayed from a nearby device to trigger functionality on the smartwatch.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260714T222111Z/items/CVE-2026-37271.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Fire-Boltt Smartwatch FB BGS001 Firmware: MOY-JS14-2.0.4 is vulnerable to Improper Authentication, The device accepts GATT Write Request commands without sufficient authentication or strong session validation. NVD: Under specific conditions, previously captured BLE packets can be replayed from a nearby device to trigger functionality on the smartwatch.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-37271/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-38057/",
      "current_public_safe_latest": false,
      "cvss_score": 7.0,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.2279,
      "epss_score": 0.00308,
      "first_observed_at": "2026-07-17T10:59:18.822206+00:00",
      "id": "CVE-2026-38057",
      "impact_tags": [
        "remote exposure relevant"
      ],
      "kev": false,
      "last_observed_at": "2026-07-17T10:59:18.822206+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The iDirect iQ200 does not validate CSRF tokens on state-changing API endpoints after authentication. NVD: The /api/reboot endpoint accepts POST requests authenticated solely by a session cookie that lacks the SameSite attribute. NVD: A remote attacker can host a malicious web page that, when visited by an authenticated administrator, automatically submits a cross-site POST request causing an immediate device reboot and satellite link loss.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260717T110142Z/items/CVE-2026-38057.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes remote exposure. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The iDirect iQ200 does not validate CSRF tokens on state-changing API endpoints after authentication. NVD: The /api/reboot endpoint accepts POST requests authenticated solely by a session cookie that lacks the SameSite attribute. NVD: A remote attacker can host a malicious web page that, when visited by an authenticated administrator, automatically submits a cross-site POST request causing an immediate device reboot and satellite link loss.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-38057/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-38059/",
      "current_public_safe_latest": false,
      "cvss_score": 8.7,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.44361,
      "epss_score": 0.00592,
      "first_observed_at": "2026-07-17T10:59:18.822206+00:00",
      "id": "CVE-2026-38059",
      "impact_tags": [
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-17T10:59:18.822206+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The iDirect iQ200 exposes the /api/identity and /api/ REST API endpoints without authentication. NVD: An unauthenticated attacker with network access can retrieve sensitive device information including the serial number, Device ID (DID), Terminal Private Key identifier (TPK), MAC address, and exact firmware version. NVD: The DID and TPK are used for satellite network authentication in the iDirect platform, potentially enabling terminal impersonation and network reconnaissance.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260717T110142Z/items/CVE-2026-38059.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes remote exposure · authenticated boundary. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The iDirect iQ200 exposes the /api/identity and /api/ REST API endpoints without authentication. NVD: An unauthenticated attacker with network access can retrieve sensitive device information including the serial number, Device ID (DID), Terminal Private Key identifier (TPK), MAC address, and exact firmware version. NVD: The DID and TPK are used for satellite network authentication in the iDirect platform, potentially enabling terminal impersonation and network reconnaissance.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-38059/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-3821/",
      "current_public_safe_latest": false,
      "cvss_score": 8.8,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.28139,
      "epss_score": 0.00355,
      "first_observed_at": "2026-07-29T06:10:00.110927+00:00",
      "id": "CVE-2026-3821",
      "impact_tags": [
        "code execution review",
        "service availability review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-29T06:10:00.110927+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Supermicro (SMC) SMASH services contain an Arbitrary code execution issue in X14DBG-DAP and X14DBI. NVD: An authorized attacker can exploit SMASH’s input capability to compromise data integrity or launch a Denial-of-Service (DoS) attack against the BMC.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260729T062752Z/items/CVE-2026-3821.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes code execution review · service availability risk. Possible impact: An attacker may be able to run code or commands on affected systems.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Supermicro (SMC) SMASH services contain an Arbitrary code execution issue in X14DBG-DAP and X14DBI. NVD: An authorized attacker can exploit SMASH’s input capability to compromise data integrity or launch a Denial-of-Service (DoS) attack against the BMC.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-3821/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-3842/",
      "current_public_safe_latest": false,
      "cvss_score": 7.8,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.01984,
      "epss_score": 0.00117,
      "first_observed_at": "2026-07-22T22:28:24.662524+00:00",
      "id": "CVE-2026-3842",
      "impact_tags": [
        "unauthorized access risk",
        "information exposure review",
        "service availability review",
        "local exposure relevant"
      ],
      "kev": false,
      "last_observed_at": "2026-07-22T22:28:24.662524+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A flaw was found in QEMU. NVD: This vulnerability allows a local attacker within a guest virtual machine to write data beyond its allocated memory. NVD: This occurs when cpu_physical_memory_map() returns a shorter length than expected, leading to an out-of-bounds write.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260722T223443Z/items/CVE-2026-3842.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes unauthorized access risk · information exposure review · service availability risk. Possible impact: A local user may be able to access information that should not be exposed.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A flaw was found in QEMU. NVD: This vulnerability allows a local attacker within a guest virtual machine to write data beyond its allocated memory. NVD: This occurs when cpu_physical_memory_map() returns a shorter length than expected, leading to an out-of-bounds write.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-3842/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-38450/",
      "current_public_safe_latest": false,
      "cvss_score": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.52057,
      "epss_score": 0.00785,
      "first_observed_at": "2026-07-21T22:14:32.860584+00:00",
      "id": "CVE-2026-38450",
      "impact_tags": [
        "code execution review",
        "remote exposure relevant"
      ],
      "kev": false,
      "last_observed_at": "2026-07-21T22:14:32.860584+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: An issue in Aetopia Digital Asset Management DAM v.1.0.0 allows a remote attacker to execute arbitrary code via the name and description parameter of the Add/Update Project function",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260721T221655Z/items/CVE-2026-38450.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes code execution review · remote exposure. Possible impact: A remote attacker may be able to run code or commands on affected systems.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: An issue in Aetopia Digital Asset Management DAM v.1.0.0 allows a remote attacker to execute arbitrary code via the name and description parameter of the Add/Update Project function",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-38450/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-38763/",
      "current_public_safe_latest": false,
      "cvss_score": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.07393,
      "epss_score": 0.00176,
      "first_observed_at": "2026-07-29T22:16:26.828679+00:00",
      "id": "CVE-2026-38763",
      "impact_tags": [
        "service availability review",
        "local exposure relevant"
      ],
      "kev": false,
      "last_observed_at": "2026-07-29T22:16:26.828679+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: An issue in Unistal Systems Pvt. NVD: Ltd.Protegent 360 v2.0.0.4 allows a local attacker to cause a denial of service via the function sub_13828",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260729T222441Z/items/CVE-2026-38763.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes service availability risk · local exposure. Possible impact: The affected service may become unavailable or unreliable.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: An issue in Unistal Systems Pvt. NVD: Ltd.Protegent 360 v2.0.0.4 allows a local attacker to cause a denial of service via the function sub_13828",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-38763/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-38765/",
      "current_public_safe_latest": false,
      "cvss_score": 7.8,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.06786,
      "epss_score": 0.00171,
      "first_observed_at": "2026-07-29T22:16:26.828679+00:00",
      "id": "CVE-2026-38765",
      "impact_tags": [
        "local exposure relevant"
      ],
      "kev": false,
      "last_observed_at": "2026-07-29T22:16:26.828679+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: An issue in Unistal Systems Pvt. NVD: Ltd.Protegent 360 v2.0.0.4 allows a local attacker to escalate privileges via the kernel driver pgsecdl.sys",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260729T222441Z/items/CVE-2026-38765.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes local exposure. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for local exposure.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: An issue in Unistal Systems Pvt. NVD: Ltd.Protegent 360 v2.0.0.4 allows a local attacker to escalate privileges via the kernel driver pgsecdl.sys",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-38765/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-38766/",
      "current_public_safe_latest": false,
      "cvss_score": 7.8,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.06786,
      "epss_score": 0.00171,
      "first_observed_at": "2026-07-29T22:16:26.828679+00:00",
      "id": "CVE-2026-38766",
      "impact_tags": [
        "local exposure relevant"
      ],
      "kev": false,
      "last_observed_at": "2026-07-29T22:16:26.828679+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: An issue in Unistal Systems Pvt. NVD: Ltd.Protegent 360 v2.0.0.4 allows a local attacker to escalate privileges via the sub_186f4 function",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260729T222441Z/items/CVE-2026-38766.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes local exposure. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for local exposure.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: An issue in Unistal Systems Pvt. NVD: Ltd.Protegent 360 v2.0.0.4 allows a local attacker to escalate privileges via the sub_186f4 function",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-38766/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-38973/",
      "current_public_safe_latest": false,
      "cvss_score": 4.4,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.01888,
      "epss_score": 0.00116,
      "first_observed_at": "2026-07-13T22:14:02.217047+00:00",
      "id": "CVE-2026-38973",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-13T22:14:02.217047+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: mrubyc through release3.4.1 was found to contain an out-of-bounds read in builtin missing-method lookup inside mrbc_find_method(). OSV: mrubyc through release3.4.1 was found to contain an out-of-bounds read in builtin missing-method lookup inside mrbc_find_method().",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260714T042224Z/items/CVE-2026-38973.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: mrubyc through release3.4.1 was found to contain an out-of-bounds read in builtin missing-method lookup inside mrbc_find_method(). OSV: mrubyc through release3.4.1 was found to contain an out-of-bounds read in builtin missing-method lookup inside mrbc_find_method().",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-38973/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-38976/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.25947,
      "epss_score": 0.00339,
      "first_observed_at": "2026-07-13T22:14:02.217047+00:00",
      "id": "CVE-2026-38976",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-13T22:14:02.217047+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: mrubyc through 3.4.1 was found to contain a NULL pointer dereference in src/vm.c in op_super() / OP_SUPER due to a missing runtime guard for top-level super. OSV: mrubyc through 3.4.1 was found to contain a NULL pointer dereference in src/vm.c in op_super() / OP_SUPER due to a missing runtime guard for top-level super.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260714T042224Z/items/CVE-2026-38976.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: mrubyc through 3.4.1 was found to contain a NULL pointer dereference in src/vm.c in op_super() / OP_SUPER due to a missing runtime guard for top-level super. OSV: mrubyc through 3.4.1 was found to contain a NULL pointer dereference in src/vm.c in op_super() / OP_SUPER due to a missing runtime guard for top-level super.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-38976/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-38979/",
      "current_public_safe_latest": false,
      "cvss_score": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.05495,
      "epss_score": 0.00159,
      "first_observed_at": "2026-07-13T22:14:02.217047+00:00",
      "id": "CVE-2026-38979",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-13T22:14:02.217047+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: ajenti through v2.2.13 has a clickjacking weakness in the browser-facing login and administrative UI. NVD: In ajenti-core/aj/http.py, the core HTTP response path initializes an empty header list, forwards handler-added headers verbatim, and finalizes responses through WSGI start_response() without adding anti-framing protections such as X-Frame-Options or a... OSV: ajenti through v2.2.13 has a clickjacking weakness in the browser-facing login and administrative UI.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260714T042224Z/items/CVE-2026-38979.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: ajenti through v2.2.13 has a clickjacking weakness in the browser-facing login and administrative UI. NVD: In ajenti-core/aj/http.py, the core HTTP response path initializes an empty header list, forwards handler-added headers verbatim, and finalizes responses through WSGI start_response() without adding anti-framing protections such as X-Frame-Options or a... OSV: ajenti through v2.2.13 has a clickjacking weakness in the browser-facing login and administrative UI.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-38979/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-39042/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.33249,
      "epss_score": 0.00409,
      "first_observed_at": "2026-07-20T22:16:32.807845+00:00",
      "id": "CVE-2026-39042",
      "impact_tags": [
        "service availability review",
        "remote exposure relevant"
      ],
      "kev": false,
      "last_observed_at": "2026-07-20T22:16:32.807845+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: An issue in MikroTIk (SIA Mikrotikls, Latvia) RouterOS 7.21.x before v.7.21.4 and 7.22.x before v.7.22.2 allows a remote attacker to cause a denial of service via the unflatten() function in libumsg.so.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260720T222315Z/items/CVE-2026-39042.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes service availability risk · remote exposure. Possible impact: The affected service may become unavailable or unreliable.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: An issue in MikroTIk (SIA Mikrotikls, Latvia) RouterOS 7.21.x before v.7.21.4 and 7.22.x before v.7.22.2 allows a remote attacker to cause a denial of service via the unflatten() function in libumsg.so.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-39042/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-39178/",
      "current_public_safe_latest": false,
      "cvss_score": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.05255,
      "epss_score": 0.00157,
      "first_observed_at": "2026-07-15T22:16:59.245057+00:00",
      "id": "CVE-2026-39178",
      "impact_tags": [
        "SQL injection risk",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-15T22:16:59.245057+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A SQL injection vulnerability in SOGo before 5.12.7 allows authenticated users to execute arbitrary SQL statements via the search parameter of the allContactSearch endpoint. OSV: A SQL injection vulnerability in SOGo before 5.12.7 allows authenticated users to execute arbitrary SQL statements via the search parameter of the allContactSearch endpoint.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260715T221956Z/items/CVE-2026-39178.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes SQL injection risk · authenticated boundary. Possible impact: An attacker may be able to read or change database-backed application data.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A SQL injection vulnerability in SOGo before 5.12.7 allows authenticated users to execute arbitrary SQL statements via the search parameter of the allContactSearch endpoint. OSV: A SQL injection vulnerability in SOGo before 5.12.7 allows authenticated users to execute arbitrary SQL statements via the search parameter of the allContactSearch endpoint.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-39178/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-39179/",
      "current_public_safe_latest": false,
      "cvss_score": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.05254,
      "epss_score": 0.00157,
      "first_observed_at": "2026-07-15T22:16:59.245057+00:00",
      "id": "CVE-2026-39179",
      "impact_tags": [
        "SQL injection risk",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-15T22:16:59.245057+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A SQL injection vulnerability in SOGo before 5.12.7 allows authenticated users to execute arbitrary SQL statements via the newPassword parameter in the password change functionality. OSV: A SQL injection vulnerability in SOGo before 5.12.7 allows authenticated users to execute arbitrary SQL statements via the newPassword parameter in the password change functionality.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260715T221956Z/items/CVE-2026-39179.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes SQL injection risk · authenticated boundary. Possible impact: An attacker may be able to read or change database-backed application data.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A SQL injection vulnerability in SOGo before 5.12.7 allows authenticated users to execute arbitrary SQL statements via the newPassword parameter in the password change functionality. OSV: A SQL injection vulnerability in SOGo before 5.12.7 allows authenticated users to execute arbitrary SQL statements via the newPassword parameter in the password change functionality.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-39179/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-39244/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.34975,
      "epss_score": 0.00432,
      "first_observed_at": "2026-07-17T16:36:32.072333+00:00",
      "id": "CVE-2026-39244",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-17T16:36:32.072333+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: adm-zip before 0.5.18 is vulnerable to denial of service via a crafted ZIP file with a manipulated uncompressed size header field. NVD: In zipEntry.js line 103, Buffer.alloc(_centralHeader.size) allocates memory based on the declared uncompressed size from the ZIP central directory header without validating it against the actual compressed data size or imposing any upper bound. NVD: The size value is read directly from the binary header at entryHeader.js line 266 with no bounds check.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260717T164048Z/items/CVE-2026-39244.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: adm-zip before 0.5.18 is vulnerable to denial of service via a crafted ZIP file with a manipulated uncompressed size header field. NVD: In zipEntry.js line 103, Buffer.alloc(_centralHeader.size) allocates memory based on the declared uncompressed size from the ZIP central directory header without validating it against the actual compressed data size or imposing any upper bound. NVD: The size value is read directly from the binary header at entryHeader.js line 266 with no bounds check.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-39244/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "wazuh / wazuh",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-39359/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.16452,
      "epss_score": 0.0025,
      "first_observed_at": "2026-07-23T22:18:14.498937+00:00",
      "id": "CVE-2026-39359",
      "impact_tags": [
        "path traversal review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-23T22:18:14.498937+00:00",
      "latest_item_url": null,
      "product": "wazuh",
      "public_safe_summary": "NVD: Wazuh is a free and open source platform used for threat prevention, detection, and response. NVD: In versions 4.0.0 through 4.10.3 and 4.11.0 through 4.14.4, a logic flaw affects the Wazuh Manager's enrollment daemon (authd) and synchronization daemon (remoted). NVD: The authd process allows agents to select a group during enrollment but does not filter path traversal sequences such as \"...\" While the manager checks for the group directory using wopendir(), the \"..\" sequence references the parent directory...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260723T222557Z/items/CVE-2026-39359.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: wazuh / wazuh",
      "source_published_impact": "Source describes path traversal review. Possible impact: An attacker may be able to reach files outside the intended application path.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: versions.",
      "source_published_summary": "NVD: Wazuh is a free and open source platform used for threat prevention, detection, and response. NVD: In versions 4.0.0 through 4.10.3 and 4.11.0 through 4.14.4, a logic flaw affects the Wazuh Manager's enrollment daemon (authd) and synchronization daemon (remoted). NVD: The authd process allows agents to select a group during enrollment but does not filter path traversal sequences such as \"...\" While the manager checks for the group directory using wopendir(), the \"..\" sequence references the parent directory...",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-39359/timeline.json",
      "vendor": "wazuh"
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-39385/",
      "current_public_safe_latest": false,
      "cvss_score": 7.1,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.12581,
      "epss_score": 0.0022,
      "first_observed_at": "2026-07-27T17:12:53.854417+00:00",
      "id": "CVE-2026-39385",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-27T17:12:53.854417+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Frappe LMS is an open source learning management system. NVD: In version 2.51.0 and earlier, a user could bypass payment validation for courses by using unrelated batch. NVD: This has been patched in 2.52.0 with enrollment now validating that the batch is linked to course.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260727T171933Z/items/CVE-2026-39385.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: 2.52.0.",
      "source_published_summary": "NVD: Frappe LMS is an open source learning management system. NVD: In version 2.51.0 and earlier, a user could bypass payment validation for courses by using unrelated batch. NVD: This has been patched in 2.52.0 with enrollment now validating that the batch is linked to course.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-39385/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "golang / go",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-39822/",
      "current_public_safe_latest": false,
      "cvss_score": 7.8,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.08055,
      "epss_score": 0.00183,
      "first_observed_at": "2026-07-15T16:47:57.605966+00:00",
      "id": "CVE-2026-39822",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-15T16:47:57.605966+00:00",
      "latest_item_url": null,
      "product": "go",
      "public_safe_summary": "NVD: On Unix systems, opening a file in an os.Root improperly follows symlinks to locations outside of the Root when the final path component of the a path is a symbolic link and the path ends in /. NVD: For example, 'root.Open(\"symlink/\")' will open \"symlink\" even when \"symlink\" is a symbolic link pointing outside of the root.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260715T164957Z/items/CVE-2026-39822.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: golang / go; affected version context: 1.27",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: On Unix systems, opening a file in an os.Root improperly follows symlinks to locations outside of the Root when the final path component of the a path is a symbolic link and the path ends in /. NVD: For example, 'root.Open(\"symlink/\")' will open \"symlink\" even when \"symlink\" is a symbolic link pointing outside of the root.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-39822/timeline.json",
      "vendor": "golang"
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-39879/",
      "current_public_safe_latest": false,
      "cvss_score": 7.1,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.06813,
      "epss_score": 0.00172,
      "first_observed_at": "2026-07-27T17:12:53.854417+00:00",
      "id": "CVE-2026-39879",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-27T17:12:53.854417+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Due to a missing sanitization call in [afsql_dd_run_query]( syslog-ng before 4.12 are vulnerable to SQL injection from an untrusted source. NVD: This is not part of the default configuration, the SQL driver has to be manually configured. NVD: Fixes are in syslog-ng 4.12, syslog-ng Premium Edition 8.2 and syslog-ng Store Box 7.8",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260727T171933Z/items/CVE-2026-39879.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Due to a missing sanitization call in [afsql_dd_run_query]( syslog-ng before 4.12 are vulnerable to SQL injection from an untrusted source. NVD: This is not part of the default configuration, the SQL driver has to be manually configured. NVD: Fixes are in syslog-ng 4.12, syslog-ng Premium Edition 8.2 and syslog-ng Store Box 7.8",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-39879/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-39903/",
      "current_public_safe_latest": false,
      "cvss_score": 7.1,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.25511,
      "epss_score": 0.00333,
      "first_observed_at": "2026-07-17T16:36:32.072333+00:00",
      "id": "CVE-2026-39903",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-17T16:36:32.072333+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Simple Machines Forum 2.1 prior to commit 7d048f8 and 3.0 prior to commit a7875e8 contains an authorization bypass vulnerability in Sources/Actions/AttachmentApprove.php where a single-character operator error causes the permission check to always pass... NVD: An authenticated low-privileged user can approve, reject, or delete any pending attachments on any board without holding the required approve_posts permission, bypass moderation queues for their own uploads, and enumerate and delete other users' pending... OSV: Simple Machines Forum Authorization Bypass via AttachmentApprove.php",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260717T164048Z/items/CVE-2026-39903.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Simple Machines Forum 2.1 prior to commit 7d048f8 and 3.0 prior to commit a7875e8 contains an authorization bypass vulnerability in Sources/Actions/AttachmentApprove.php where a single-character operator error causes the permission check to always pass... NVD: An authenticated low-privileged user can approve, reject, or delete any pending attachments on any board without holding the required approve_posts permission, bypass moderation queues for their own uploads, and enumerate and delete other users' pending... OSV: Simple Machines Forum Authorization Bypass via AttachmentApprove.php",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-39903/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-39931/",
      "current_public_safe_latest": false,
      "cvss_score": 8.6,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.25212,
      "epss_score": 0.00327,
      "first_observed_at": "2026-08-10T16:12:24.021737+00:00",
      "id": "CVE-2026-39931",
      "impact_tags": [
        "SQL injection risk"
      ],
      "kev": false,
      "last_observed_at": "2026-08-10T16:12:24.021737+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: OpenEMR through 8.2.0 contains an authenticated SQL injection vulnerability in the backup configuration import feature that allows administrators with admin or super ACL privileges to execute arbitrary DDL and DML statements against the application database... NVD: Attackers can exploit the unfiltered shell_exec invocation of the mysql command-line client to extract credential hashes, modify access control tables, inject backdoor accounts, create persistent triggers or stored procedures, and write arbitrary files to the... OSV: OpenEMR Authenticated SQL Injection via backup.php Import Feature",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260810T162156Z/items/CVE-2026-39931.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes SQL injection risk. Possible impact: An attacker may be able to read or change database-backed application data.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: OpenEMR through 8.2.0 contains an authenticated SQL injection vulnerability in the backup configuration import feature that allows administrators with admin or super ACL privileges to execute arbitrary DDL and DML statements against the application database... NVD: Attackers can exploit the unfiltered shell_exec invocation of the mysql command-line client to extract credential hashes, modify access control tables, inject backdoor accounts, create persistent triggers or stored procedures, and write arbitrary files to the... OSV: OpenEMR Authenticated SQL Injection via backup.php Import Feature",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-39931/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-39932/",
      "current_public_safe_latest": false,
      "cvss_score": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.52313,
      "epss_score": 0.00773,
      "first_observed_at": "2026-08-10T16:12:24.021737+00:00",
      "id": "CVE-2026-39932",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-10T16:12:24.021737+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: OpenEMR through 8.2.0 contains a remote code execution vulnerability in the document category tree component (library/classes/Tree.class.php) that allows authenticated administrators to execute arbitrary operating system commands by injecting PHP payloads... OSV: OpenEMR 8.2.0 Remote Code Execution via CategoryTree eval() Injection OSV: OpenEMR through 8.2.0 contains a remote code execution vulnerability in the document category tree component (library/classes/Tree.class.php) that allows authenticated administrators to execute arbitrary operating system commands by injecting PHP payloads...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260810T162156Z/items/CVE-2026-39932.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: OpenEMR through 8.2.0 contains a remote code execution vulnerability in the document category tree component (library/classes/Tree.class.php) that allows authenticated administrators to execute arbitrary operating system commands by injecting PHP payloads... OSV: OpenEMR 8.2.0 Remote Code Execution via CategoryTree eval() Injection OSV: OpenEMR through 8.2.0 contains a remote code execution vulnerability in the document category tree component (library/classes/Tree.class.php) that allows authenticated administrators to execute arbitrary operating system commands by injecting PHP payloads...",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-39932/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-40005/",
      "current_public_safe_latest": false,
      "cvss_score": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.27073,
      "epss_score": 0.00349,
      "first_observed_at": "2026-07-17T05:58:07.763993+00:00",
      "id": "CVE-2026-40005",
      "impact_tags": [
        "path traversal review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-17T05:58:07.763993+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache IoTDB. NVD: An attacker can write arbitrary files anywhere the IoTDB process has write permissions with unsafe API. NVD: This issue affects Apache IoTDB: from 1.0.0 before 2.0.10.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260717T060336Z/items/CVE-2026-40005.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes path traversal review. Possible impact: An attacker may be able to reach files outside the intended application path.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache IoTDB. NVD: An attacker can write arbitrary files anywhere the IoTDB process has write permissions with unsafe API. NVD: This issue affects Apache IoTDB: from 1.0.0 before 2.0.10.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-40005/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-40006/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.24391,
      "epss_score": 0.00323,
      "first_observed_at": "2026-07-17T05:58:07.763993+00:00",
      "id": "CVE-2026-40006",
      "impact_tags": [
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-17T05:58:07.763993+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Memory Allocation with Excessive Size Value, Allocation of Resources Without Limits or Throttling, Missing Authentication for Critical Function vulnerability in Apache IoTDB. NVD: When pipe_air_gap_receiver_enabled=true, the IoTDB AirGap pipe receiver accepts raw TCP connections on port 9780 with no authentication. NVD: The readLength method reads an attacker-controlled 32-bit integer from the socket and readData passes it directly to new byte[length] with no upper-bound check.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260717T060336Z/items/CVE-2026-40006.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes remote exposure · authenticated boundary. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: Memory Allocation with Excessive Size Value, Allocation of Resources Without Limits or Throttling, Missing Authentication for Critical Function vulnerability in Apache IoTDB. NVD: When pipe_air_gap_receiver_enabled=true, the IoTDB AirGap pipe receiver accepts raw TCP connections on port 9780 with no authentication. NVD: The readLength method reads an attacker-controlled 32-bit integer from the socket and readData passes it directly to new byte[length] with no upper-bound check.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-40006/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-40007/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.19819,
      "epss_score": 0.00278,
      "first_observed_at": "2026-07-17T05:58:07.763993+00:00",
      "id": "CVE-2026-40007",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-17T05:58:07.763993+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Uncontrolled Recursion, Uncontrolled Resource Consumption vulnerability in Apache IoTDB. NVD: When pipe_air_gap_receiver_enabled=true, the IoTDB AirGap receiver's readLength method calls itself recursively each time it recognises the E-language prefix in socket data, with no depth limit. NVD: An unauthenticated attacker can send a stream of repeated E-language prefixes that drives the recursion arbitrarily deep, exhausting the receiver thread's JVM stack and raising StackOverflowError.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260717T060336Z/items/CVE-2026-40007.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: Uncontrolled Recursion, Uncontrolled Resource Consumption vulnerability in Apache IoTDB. NVD: When pipe_air_gap_receiver_enabled=true, the IoTDB AirGap receiver's readLength method calls itself recursively each time it recognises the E-language prefix in socket data, with no depth limit. NVD: An unauthenticated attacker can send a stream of repeated E-language prefixes that drives the recursion arbitrarily deep, exhausting the receiver thread's JVM stack and raising StackOverflowError.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-40007/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-40008/",
      "current_public_safe_latest": false,
      "cvss_score": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.2536,
      "epss_score": 0.00332,
      "first_observed_at": "2026-07-17T05:58:07.763993+00:00",
      "id": "CVE-2026-40008",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-17T05:58:07.763993+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in Apache IoTDB. NVD: The pipe processor reads a fully qualified Java class name and instantiates it using Class.forName().newInstance() without any validation or allowlisting. NVD: This issue affects Apache IoTDB: from 1.0.0 before 2.0.10.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260717T060336Z/items/CVE-2026-40008.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in Apache IoTDB. NVD: The pipe processor reads a fully qualified Java class name and instantiates it using Class.forName().newInstance() without any validation or allowlisting. NVD: This issue affects Apache IoTDB: from 1.0.0 before 2.0.10.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-40008/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-40009/",
      "current_public_safe_latest": false,
      "cvss_score": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.11026,
      "epss_score": 0.00209,
      "first_observed_at": "2026-07-17T05:58:07.763993+00:00",
      "id": "CVE-2026-40009",
      "impact_tags": [
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-17T05:58:07.763993+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Improper Privilege Management, Improper Access Control vulnerability in Apache IoTDB. NVD: Authenticated users can escalate to full tree-path access by renaming themselves to __internal_auditor. NVD: This issue affects Apache IoTDB: from 2.0.8 before 2.0.10.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260717T060336Z/items/CVE-2026-40009.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: Improper Privilege Management, Improper Access Control vulnerability in Apache IoTDB. NVD: Authenticated users can escalate to full tree-path access by renaming themselves to __internal_auditor. NVD: This issue affects Apache IoTDB: from 2.0.8 before 2.0.10.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-40009/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "apache / camel",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-40047/",
      "current_public_safe_latest": false,
      "cvss_score": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.72449,
      "epss_score": 0.01569,
      "first_observed_at": "2026-07-13T06:32:51.098771+00:00",
      "id": "CVE-2026-40047",
      "impact_tags": [
        "path traversal review",
        "command injection risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-13T06:32:51.098771+00:00",
      "latest_item_url": null,
      "product": "camel",
      "public_safe_summary": "NVD: Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Apache Camel Docling component. NVD: The camel-docling component invokes the external docling command-line tool by assembling an argument list in DoclingProducer and executing it through java.lang.ProcessBuilder. NVD: Custom CLI arguments supplied through the CamelDoclingCustomArguments exchange header (a List<String>) were appended to that argument list with insufficient validation: the original implementation relied on a denylist of disallowed flags and only rejected...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260713T063521Z/items/CVE-2026-40047.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: apache / camel",
      "source_published_impact": "Source describes path traversal review · command injection risk. Possible impact: An attacker may be able to run unintended system commands through the affected component.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: 4.18.3., a.",
      "source_published_summary": "NVD: Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Apache Camel Docling component. NVD: The camel-docling component invokes the external docling command-line tool by assembling an argument list in DoclingProducer and executing it through java.lang.ProcessBuilder. NVD: Custom CLI arguments supplied through the CamelDoclingCustomArguments exchange header (a List<String>) were appended to that argument list with insufficient validation: the original implementation relied on a denylist of disallowed flags and only rejected...",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-40047/timeline.json",
      "vendor": "apache"
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-40187/",
      "current_public_safe_latest": false,
      "cvss_score": 8.6,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.57048,
      "epss_score": 0.00933,
      "first_observed_at": "2026-07-27T17:12:53.854417+00:00",
      "id": "CVE-2026-40187",
      "impact_tags": [
        "code execution review",
        "command execution review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-27T17:12:53.854417+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: In egroupware version 26.0 and earlier, an authenticated administrator can achieve OS-level Remote Code Execution (RCE) by uploading a malicious eTemplate XML file (.xet) to the VFS /etemplates mount. NVD: The Widget::expand_name() method passes template widget attribute values directly into a PHP eval() call with only double-quote escaping applied - **backtick characters are not escaped**. NVD: In PHP, backticks inside a double-quoted eval() string execute shell commands.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260727T171933Z/items/CVE-2026-40187.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes code execution review · command execution risk. Possible impact: An attacker may be able to run code or commands on affected systems.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: In egroupware version 26.0 and earlier, an authenticated administrator can achieve OS-level Remote Code Execution (RCE) by uploading a malicious eTemplate XML file (.xet) to the VFS /etemplates mount. NVD: The Widget::expand_name() method passes template widget attribute values directly into a PHP eval() call with only double-quote escaping applied - **backtick characters are not escaped**. NVD: In PHP, backticks inside a double-quoted eval() string execute shell commands.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-40187/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "microsoft / windows_10_1607",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-40378/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.53113,
      "epss_score": 0.00816,
      "first_observed_at": "2026-07-21T16:48:32.557544+00:00",
      "id": "CVE-2026-40378",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-21T16:48:32.557544+00:00",
      "latest_item_url": null,
      "product": "windows_10_1607",
      "public_safe_summary": "NVD: Memory allocation with excessive size value in Windows Local Security Authority Subsystem Service (LSASS) allows an unauthorized attacker to deny service over a network.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260721T165442Z/items/CVE-2026-40378.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: microsoft / windows_10_1607; affected version context: -, r2",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Memory allocation with excessive size value in Windows Local Security Authority Subsystem Service (LSASS) allows an unauthorized attacker to deny service over a network.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-40378/timeline.json",
      "vendor": "microsoft"
    },
    {
      "affected_label": "microsoft / windows_10_1607",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-40400/",
      "current_public_safe_latest": false,
      "cvss_score": 8.0,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.44288,
      "epss_score": 0.00588,
      "first_observed_at": "2026-07-21T16:48:32.557544+00:00",
      "id": "CVE-2026-40400",
      "impact_tags": [
        "path traversal review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-21T16:48:32.557544+00:00",
      "latest_item_url": null,
      "product": "windows_10_1607",
      "public_safe_summary": "NVD: Relative path traversal in Windows PowerShell allows an authorized attacker to execute code over a network.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260721T165442Z/items/CVE-2026-40400.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: microsoft / windows_10_1607; affected version context: -, r2",
      "source_published_impact": "Source describes path traversal review. Possible impact: An attacker may be able to reach files outside the intended application path.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Relative path traversal in Windows PowerShell allows an authorized attacker to execute code over a network.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-40400/timeline.json",
      "vendor": "microsoft"
    },
    {
      "affected_label": "microsoft / windows_10_1607",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-40422/",
      "current_public_safe_latest": false,
      "cvss_score": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.21915,
      "epss_score": 0.00298,
      "first_observed_at": "2026-07-21T16:48:32.557544+00:00",
      "id": "CVE-2026-40422",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-21T16:48:32.557544+00:00",
      "latest_item_url": null,
      "product": "windows_10_1607",
      "public_safe_summary": "NVD: Use of uninitialized resource in Windows File Explorer allows an authorized attacker to disclose information locally.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260721T165442Z/items/CVE-2026-40422.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: microsoft / windows_10_1607",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Use of uninitialized resource in Windows File Explorer allows an authorized attacker to disclose information locally.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-40422/timeline.json",
      "vendor": "microsoft"
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-40430/",
      "current_public_safe_latest": false,
      "cvss_score": 8.7,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.14226,
      "epss_score": 0.00232,
      "first_observed_at": "2026-07-30T22:30:38.166118+00:00",
      "id": "CVE-2026-40430",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-30T22:30:38.166118+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Pronetiqs IntraVUE Versions 3.2.1a14 and prior have a plaintext storage of a password vulnerability that could expose cleartext credentials through the API.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260730T224832Z/items/CVE-2026-40430.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Pronetiqs IntraVUE Versions 3.2.1a14 and prior have a plaintext storage of a password vulnerability that could expose cleartext credentials through the API.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-40430/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-40452/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.17022,
      "epss_score": 0.00256,
      "first_observed_at": "2026-07-17T05:58:07.763993+00:00",
      "id": "CVE-2026-40452",
      "impact_tags": [
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-17T05:58:07.763993+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Incorrect Authorization, Improper Access Control vulnerability in Apache IoTDB. NVD: Authorization bypass in /rest/v2/fastLastQuery exposes last-value data to unauthorized authenticated users. NVD: This issue affects Apache IoTDB: from 1.3.5 before 1.3.8, from 2.0.5 before 2.0.10.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260717T060336Z/items/CVE-2026-40452.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes authenticated boundary. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: Incorrect Authorization, Improper Access Control vulnerability in Apache IoTDB. NVD: Authorization bypass in /rest/v2/fastLastQuery exposes last-value data to unauthorized authenticated users. NVD: This issue affects Apache IoTDB: from 1.3.5 before 1.3.8, from 2.0.5 before 2.0.10.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-40452/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-40454/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.1982,
      "epss_score": 0.00278,
      "first_observed_at": "2026-07-17T05:58:07.763993+00:00",
      "id": "CVE-2026-40454",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-17T05:58:07.763993+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Out-of-bounds Read, Improper Input Validation vulnerability in Apache IoTDB C++ client. NVD: Out-of-bounds reads in IoTDB C++ client TsBlock deserializer crash client process on malformed server data. NVD: This issue affects Apache IoTDB C++ client: from 1.3.5 before 1.3.8, from 2.0.5 before 2.0.10.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260717T060336Z/items/CVE-2026-40454.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: Out-of-bounds Read, Improper Input Validation vulnerability in Apache IoTDB C++ client. NVD: Out-of-bounds reads in IoTDB C++ client TsBlock deserializer crash client process on malformed server data. NVD: This issue affects Apache IoTDB C++ client: from 1.3.5 before 1.3.8, from 2.0.5 before 2.0.10.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-40454/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "fossies / gawk",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-40467/",
      "current_public_safe_latest": false,
      "cvss_score": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.11635,
      "epss_score": 0.00213,
      "first_observed_at": "2026-07-20T11:59:42.107493+00:00",
      "id": "CVE-2026-40467",
      "impact_tags": [
        "memory safety review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-20T11:59:42.107493+00:00",
      "latest_item_url": null,
      "product": "gawk",
      "public_safe_summary": "NVD: Use After Free vulnerability has been found in \"io.c\" program file of gawk (do_getline_redir() routine). NVD: This issue may lead to a crash. NVD: It affects gawk in versions 5.4.0 and below.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260720T120206Z/items/CVE-2026-40467.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: fossies / gawk",
      "source_published_impact": "Source describes memory safety review. Possible impact: The affected component has memory-safety risk that may lead to crash, privilege, or code-execution impact depending on exposure.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Use After Free vulnerability has been found in \"io.c\" program file of gawk (do_getline_redir() routine). NVD: This issue may lead to a crash. NVD: It affects gawk in versions 5.4.0 and below.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-40467/timeline.json",
      "vendor": "fossies"
    },
    {
      "affected_label": "fossies / gawk",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-40468/",
      "current_public_safe_latest": false,
      "cvss_score": 2.1,
      "cvss_severity": "LOW",
      "epss_percentile": 0.1008,
      "epss_score": 0.00201,
      "first_observed_at": "2026-07-20T11:59:42.107493+00:00",
      "id": "CVE-2026-40468",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-20T11:59:42.107493+00:00",
      "latest_item_url": null,
      "product": "gawk",
      "public_safe_summary": "NVD: Integer overflow vulnerability has been found in \"builtin.c\" program file of gawk. NVD: This issue may lead to memory exhaustion on the hosting operating system and could be used to overwrite gawk heap metadata and objects with attacker-controlled bytes. NVD: It affects gawk in versions 5.4.0 and below.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260720T120206Z/items/CVE-2026-40468.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: fossies / gawk",
      "source_published_impact": "This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Integer overflow vulnerability has been found in \"builtin.c\" program file of gawk. NVD: This issue may lead to memory exhaustion on the hosting operating system and could be used to overwrite gawk heap metadata and objects with attacker-controlled bytes. NVD: It affects gawk in versions 5.4.0 and below.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-40468/timeline.json",
      "vendor": "fossies"
    },
    {
      "affected_label": "fossies / gawk",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-40469/",
      "current_public_safe_latest": false,
      "cvss_score": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.11636,
      "epss_score": 0.00213,
      "first_observed_at": "2026-07-20T11:59:42.107493+00:00",
      "id": "CVE-2026-40469",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-20T11:59:42.107493+00:00",
      "latest_item_url": null,
      "product": "gawk",
      "public_safe_summary": "NVD: Integer overflow vulnerability has been found in \"builtin.c\" program file of gawk (do_sub() routine). NVD: This issue could be used to overwrite gawk heap metadata and objects causing the program to crash. NVD: It affects 32-bit builds of gawk in versions 5.4.0 and below.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260720T120206Z/items/CVE-2026-40469.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: fossies / gawk",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Integer overflow vulnerability has been found in \"builtin.c\" program file of gawk (do_sub() routine). NVD: This issue could be used to overwrite gawk heap metadata and objects causing the program to crash. NVD: It affects 32-bit builds of gawk in versions 5.4.0 and below.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-40469/timeline.json",
      "vendor": "fossies"
    },
    {
      "affected_label": "fossies / gawk",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-40553/",
      "current_public_safe_latest": false,
      "cvss_score": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.21005,
      "epss_score": 0.00291,
      "first_observed_at": "2026-07-20T11:59:42.107493+00:00",
      "id": "CVE-2026-40553",
      "impact_tags": [
        "memory safety review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-20T11:59:42.107493+00:00",
      "latest_item_url": null,
      "product": "gawk",
      "public_safe_summary": "NVD: Buffer overflow vulnerability has been found in \"extension/readdir.c\" program file of gawk (ftype() routine). NVD: This issue could be used to crash the program and potentially to achieve code execution, although the latter has not been confirmed to be feasible. NVD: It affects gawk in versions 5.4.0 and below.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260720T120206Z/items/CVE-2026-40553.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: fossies / gawk",
      "source_published_impact": "Source describes memory safety review. Possible impact: The affected component has memory-safety risk that may lead to crash, privilege, or code-execution impact depending on exposure.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Buffer overflow vulnerability has been found in \"extension/readdir.c\" program file of gawk (ftype() routine). NVD: This issue could be used to crash the program and potentially to achieve code execution, although the latter has not been confirmed to be feasible. NVD: It affects gawk in versions 5.4.0 and below.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-40553/timeline.json",
      "vendor": "fossies"
    },
    {
      "affected_label": "dell / powerscale_onefs",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-40633/",
      "current_public_safe_latest": false,
      "cvss_score": 7.8,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.01474,
      "epss_score": 0.00109,
      "first_observed_at": "2026-07-22T06:07:21.492959+00:00",
      "id": "CVE-2026-40633",
      "impact_tags": [
        "information exposure review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-22T06:07:21.492959+00:00",
      "latest_item_url": null,
      "product": "powerscale_onefs",
      "public_safe_summary": "NVD: Dell PowerScale OneFS versions 9.5.0.0 through 9.10.1.7, versions 9.11.0.0 through 9.13.0.2 contains an Insertion of Sensitive Information into Log File vulnerability. NVD: A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information disclosure.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260722T060931Z/items/CVE-2026-40633.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: dell / powerscale_onefs",
      "source_published_impact": "Source describes information exposure review. Possible impact: An attacker may be able to access information that should not be exposed.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Dell PowerScale OneFS versions 9.5.0.0 through 9.10.1.7, versions 9.11.0.0 through 9.13.0.2 contains an Insertion of Sensitive Information into Log File vulnerability. NVD: A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information disclosure.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-40633/timeline.json",
      "vendor": "dell"
    },
    {
      "affected_label": "apache / camel",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-40859/",
      "current_public_safe_latest": false,
      "cvss_score": 8.1,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.49718,
      "epss_score": 0.00724,
      "first_observed_at": "2026-07-13T06:32:51.098771+00:00",
      "id": "CVE-2026-40859",
      "impact_tags": [
        "code execution review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-13T06:32:51.098771+00:00",
      "latest_item_url": null,
      "product": "camel",
      "public_safe_summary": "NVD: Deserialization of Untrusted Data vulnerability in Apache Camel. NVD: The camel-vertx-http component deserializes HTTP response bodies carrying the Content-Type application/x-java-serialized-object using a raw java.io.ObjectInputStream, without applying any ObjectInputFilter (VertxHttpHelper.deserializeJavaObjectFromStream)... NVD: An attacker who controls the backend the Camel producer talks to - through a man-in-the-middle position on an unencrypted (plain HTTP) connection, or by compromising the backend service - can return a crafted serialized Java object and, if a suitable gadget...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260713T063521Z/items/CVE-2026-40859.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: apache / camel; affected version context: 4.19.0",
      "source_published_impact": "Source describes code execution review. Possible impact: An attacker may be able to run code or commands on affected systems.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: 4.14.8., 4.18.3., version.",
      "source_published_summary": "NVD: Deserialization of Untrusted Data vulnerability in Apache Camel. NVD: The camel-vertx-http component deserializes HTTP response bodies carrying the Content-Type application/x-java-serialized-object using a raw java.io.ObjectInputStream, without applying any ObjectInputFilter (VertxHttpHelper.deserializeJavaObjectFromStream)... NVD: An attacker who controls the backend the Camel producer talks to - through a man-in-the-middle position on an unencrypted (plain HTTP) connection, or by compromising the backend service - can return a crafted serialized Java object and, if a suitable gadget...",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-40859/timeline.json",
      "vendor": "apache"
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-41042/",
      "current_public_safe_latest": false,
      "cvss_score": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.20429,
      "epss_score": 0.00285,
      "first_observed_at": "2026-07-15T11:03:27.604769+00:00",
      "id": "CVE-2026-41042",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-15T11:03:27.604769+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Unauthenticated callers can supply a malicious H2 JDBC URL through the testConnection API, which executes arbitrary Java code on the server via H2's INIT parameter. NVD: Vulnerability in Apache Gravitino. NVD: This issue affects Apache Gravitino: before 1.2.1.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260715T110622Z/items/CVE-2026-41042.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: Unauthenticated callers can supply a malicious H2 JDBC URL through the testConnection API, which executes arbitrary Java code on the server via H2's INIT parameter. NVD: Vulnerability in Apache Gravitino. NVD: This issue affects Apache Gravitino: before 1.2.1.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-41042/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "microsoft / windows_10_1607",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-41087/",
      "current_public_safe_latest": false,
      "cvss_score": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.2772,
      "epss_score": 0.00353,
      "first_observed_at": "2026-07-21T16:48:32.557544+00:00",
      "id": "CVE-2026-41087",
      "impact_tags": [
        "information exposure review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-21T16:48:32.557544+00:00",
      "latest_item_url": null,
      "product": "windows_10_1607",
      "public_safe_summary": "NVD: Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260721T165442Z/items/CVE-2026-41087.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: microsoft / windows_10_1607",
      "source_published_impact": "Source describes information exposure review. Possible impact: An attacker may be able to access information that should not be exposed.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-41087/timeline.json",
      "vendor": "microsoft"
    },
    {
      "affected_label": "microsoft / 365_copilot",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-41106/",
      "current_public_safe_latest": false,
      "cvss_score": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.4105,
      "epss_score": 0.00531,
      "first_observed_at": "2026-07-09T22:45:10.548837+00:00",
      "id": "CVE-2026-41106",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-09T22:45:10.548837+00:00",
      "latest_item_url": null,
      "product": "365_copilot",
      "public_safe_summary": "NVD: Url redirection to untrusted site ('open redirect') in M365 Copilot allows an unauthorized attacker to elevate privileges over a network.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260709T224554Z/items/CVE-2026-41106.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: microsoft / 365_copilot; affected version context: -",
      "source_published_impact": "This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Url redirection to untrusted site ('open redirect') in M365 Copilot allows an unauthorized attacker to elevate privileges over a network.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-41106/timeline.json",
      "vendor": "microsoft"
    },
    {
      "affected_label": "dell / data_domain_operating_system",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-41123/",
      "current_public_safe_latest": false,
      "cvss_score": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.04801,
      "epss_score": 0.00152,
      "first_observed_at": "2026-07-10T12:09:55.374028+00:00",
      "id": "CVE-2026-41123",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-10T12:09:55.374028+00:00",
      "latest_item_url": null,
      "product": "data_domain_operating_system",
      "public_safe_summary": "NVD: Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an improper access control... NVD: A low privileged attacker with remote access could potentially exploit this vulnerability, leading to information tampering.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260710T121119Z/items/CVE-2026-41123.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: dell / data_domain_operating_system",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an improper access control... NVD: A low privileged attacker with remote access could potentially exploit this vulnerability, leading to information tampering.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-41123/timeline.json",
      "vendor": "dell"
    },
    {
      "affected_label": "dell / data_domain_operating_system",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-41124/",
      "current_public_safe_latest": false,
      "cvss_score": 2.3,
      "cvss_severity": "LOW",
      "epss_percentile": 0.0273,
      "epss_score": 0.00127,
      "first_observed_at": "2026-07-10T12:09:55.374028+00:00",
      "id": "CVE-2026-41124",
      "impact_tags": [
        "path traversal review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-10T12:09:55.374028+00:00",
      "latest_item_url": null,
      "product": "data_domain_operating_system",
      "public_safe_summary": "NVD: Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an Improper limitation of a pathname... NVD: A high privileged attacker with local access could potentially exploit this vulnerability, leading to Information exposure.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260710T121119Z/items/CVE-2026-41124.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: dell / data_domain_operating_system",
      "source_published_impact": "Source describes path traversal review. Possible impact: An attacker may be able to reach files outside the intended application path.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an Improper limitation of a pathname... NVD: A high privileged attacker with local access could potentially exploit this vulnerability, leading to Information exposure.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-41124/timeline.json",
      "vendor": "dell"
    },
    {
      "affected_label": "neutrinolabs / xrdp",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-41252/",
      "current_public_safe_latest": false,
      "cvss_score": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.4553,
      "epss_score": 0.00609,
      "first_observed_at": "2026-07-27T17:12:53.854417+00:00",
      "id": "CVE-2026-41252",
      "impact_tags": [
        "code execution review",
        "service availability review",
        "memory safety review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-27T17:12:53.854417+00:00",
      "latest_item_url": null,
      "product": "xrdp",
      "public_safe_summary": "NVD: xrdp is an open source RDP server. NVD: Versions 0.10.6 and prior contain a missing bounds check in xrdp, which allows a heap-based buffer overflow when operating in vnc-any mode. NVD: The issue occurs during the handling of RFB protocol color map messages from a VNC server, where incoming color indices are not properly validated.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260727T171933Z/items/CVE-2026-41252.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: neutrinolabs / xrdp",
      "source_published_impact": "Source describes code execution review · service availability risk · memory safety review. Possible impact: An attacker may be able to run code or commands on affected systems.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: xrdp is an open source RDP server. NVD: Versions 0.10.6 and prior contain a missing bounds check in xrdp, which allows a heap-based buffer overflow when operating in vnc-any mode. NVD: The issue occurs during the handling of RFB protocol color map messages from a VNC server, where incoming color indices are not properly validated.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-41252/timeline.json",
      "vendor": "neutrinolabs"
    },
    {
      "affected_label": "trustedfirmware / op-tee",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-41434/",
      "current_public_safe_latest": false,
      "cvss_score": 3.3,
      "cvss_severity": "LOW",
      "epss_percentile": 0.01289,
      "epss_score": 0.00105,
      "first_observed_at": "2026-07-13T17:24:46.617207+00:00",
      "id": "CVE-2026-41434",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-13T17:24:46.617207+00:00",
      "latest_item_url": null,
      "product": "op-tee",
      "public_safe_summary": "NVD: OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone technology. NVD: Starting in version 3.10.0 and prior to version 4.11.0, an unbounded recursion can crash the PKCS#11 TA. NVD: Version 4.11.0 contains a patch.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260713T172750Z/items/CVE-2026-41434.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: trustedfirmware / op-tee",
      "source_published_impact": "This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone technology. NVD: Starting in version 3.10.0 and prior to version 4.11.0, an unbounded recursion can crash the PKCS#11 TA. NVD: Version 4.11.0 contains a patch.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-41434/timeline.json",
      "vendor": "trustedfirmware"
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-41452/",
      "current_public_safe_latest": false,
      "cvss_score": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.48116,
      "epss_score": 0.00658,
      "first_observed_at": "2026-08-10T16:12:24.021737+00:00",
      "id": "CVE-2026-41452",
      "impact_tags": [
        "remote exposure relevant"
      ],
      "kev": false,
      "last_observed_at": "2026-08-10T16:12:24.021737+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Krayin CRM 2.2.4 contains a missing authentication vulnerability in the installer middleware that allows unauthenticated remote attackers to overwrite the primary administrator account by sending a crafted HTTP POST request with the X-Requested-With... NVD: Attackers can supply arbitrary name, email, and password values to the admin-config-setup endpoint, which performs an unauthenticated updateOrInsert targeting the hardcoded administrator user ID, enabling full administrative access to all CRM data. OSV: Krayin CRM 2.2.4 Missing Authentication via install/api/admin-config-setup",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260810T162156Z/items/CVE-2026-41452.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes remote exposure. Possible impact: This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Krayin CRM 2.2.4 contains a missing authentication vulnerability in the installer middleware that allows unauthenticated remote attackers to overwrite the primary administrator account by sending a crafted HTTP POST request with the X-Requested-With... NVD: Attackers can supply arbitrary name, email, and password values to the admin-config-setup endpoint, which performs an unauthenticated updateOrInsert targeting the hardcoded administrator user ID, enabling full administrative access to all CRM data. OSV: Krayin CRM 2.2.4 Missing Authentication via install/api/admin-config-setup",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-41452/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-41453/",
      "current_public_safe_latest": false,
      "cvss_score": 8.7,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.27699,
      "epss_score": 0.0035,
      "first_observed_at": "2026-08-10T16:12:24.021737+00:00",
      "id": "CVE-2026-41453",
      "impact_tags": [
        "SQL injection risk",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-10T16:12:24.021737+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Krayin CRM before 2.2.4 contains a blind SQL injection vulnerability in the leads DataGrid that allows authenticated users with leads access to inject arbitrary SQL into a HAVING clause by manipulating the rotten_lead[in] query parameter, which is... NVD: Attackers can exploit this flaw using time-based and boolean-based blind injection techniques to extract the entire database contents, including user credential hashes, CRM records, and application configuration data. OSV: Krayin CRM < 2.2.4 Blind SQL Injection via LeadDataGrid.php rotten_lead Parameter",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260810T162156Z/items/CVE-2026-41453.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes SQL injection risk · authenticated boundary. Possible impact: An attacker may be able to read or change database-backed application data.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Krayin CRM before 2.2.4 contains a blind SQL injection vulnerability in the leads DataGrid that allows authenticated users with leads access to inject arbitrary SQL into a HAVING clause by manipulating the rotten_lead[in] query parameter, which is... NVD: Attackers can exploit this flaw using time-based and boolean-based blind injection techniques to extract the entire database contents, including user credential hashes, CRM records, and application configuration data. OSV: Krayin CRM < 2.2.4 Blind SQL Injection via LeadDataGrid.php rotten_lead Parameter",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-41453/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "trustedfirmware / op-tee",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-41514/",
      "current_public_safe_latest": false,
      "cvss_score": 2.5,
      "cvss_severity": "LOW",
      "epss_percentile": 0.00833,
      "epss_score": 0.00095,
      "first_observed_at": "2026-07-13T17:24:46.617207+00:00",
      "id": "CVE-2026-41514",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-13T17:24:46.617207+00:00",
      "latest_item_url": null,
      "product": "op-tee",
      "public_safe_summary": "NVD: OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone technology. NVD: Starting in version 4.5.0 and prior to version 4.11.0, the RSA-OAEP decryption implementation in the Hisilicon HPRE crypto driver uses non-constant-time memcmp() for label hash verification and has multiple distinguishable error paths. NVD: This creates a Manger-style padding oracle that allows an attacker to recover RSA-OAEP plaintext with approximately 1000-2000 adaptive chosen ciphertext queries.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260713T172750Z/items/CVE-2026-41514.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: trustedfirmware / op-tee",
      "source_published_impact": "This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone technology. NVD: Starting in version 4.5.0 and prior to version 4.11.0, the RSA-OAEP decryption implementation in the Hisilicon HPRE crypto driver uses non-constant-time memcmp() for label hash verification and has multiple distinguishable error paths. NVD: This creates a Manger-style padding oracle that allows an attacker to recover RSA-OAEP plaintext with approximately 1000-2000 adaptive chosen ciphertext queries.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-41514/timeline.json",
      "vendor": "trustedfirmware"
    },
    {
      "affected_label": "trustedfirmware / op-tee",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-41515/",
      "current_public_safe_latest": false,
      "cvss_score": 2.5,
      "cvss_severity": "LOW",
      "epss_percentile": 0.00727,
      "epss_score": 0.00094,
      "first_observed_at": "2026-07-13T17:24:46.617207+00:00",
      "id": "CVE-2026-41515",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-13T17:24:46.617207+00:00",
      "latest_item_url": null,
      "product": "op-tee",
      "public_safe_summary": "NVD: OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone technology. NVD: Starting in version 3.9.0 and prior to version 4.11.0, the RSA-OAEP decryption implementation in the NXP CAAM crypto driver uses non-constant-time memcmp() for label hash verification and has multiple distinguishable error paths. NVD: This creates a Manger-style padding oracle that allows an attacker to recover RSA-OAEP plaintext with approximately 1000-2000 adaptive chosen ciphertext queries.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260713T172750Z/items/CVE-2026-41515.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: trustedfirmware / op-tee",
      "source_published_impact": "This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone technology. NVD: Starting in version 3.9.0 and prior to version 4.11.0, the RSA-OAEP decryption implementation in the NXP CAAM crypto driver uses non-constant-time memcmp() for label hash verification and has multiple distinguishable error paths. NVD: This creates a Manger-style padding oracle that allows an attacker to recover RSA-OAEP plaintext with approximately 1000-2000 adaptive chosen ciphertext queries.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-41515/timeline.json",
      "vendor": "trustedfirmware"
    },
    {
      "affected_label": "trustedfirmware / op-tee",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-41516/",
      "current_public_safe_latest": false,
      "cvss_score": 2.5,
      "cvss_severity": "LOW",
      "epss_percentile": 0.0097,
      "epss_score": 0.00099,
      "first_observed_at": "2026-07-13T17:24:46.617207+00:00",
      "id": "CVE-2026-41516",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-13T17:24:46.617207+00:00",
      "latest_item_url": null,
      "product": "op-tee",
      "public_safe_summary": "NVD: OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone technology. NVD: Starting in version 4.5.0 and prior to version 4.11.0, the RSA PKCS#1 v1.5 decryption implementation in the Hisilicon HPRE crypto driver uses non-constant-time memcmp() for label hash verification and has multiple distinguishable error paths. NVD: This creates a Bleichenbacher-style padding oracle that allows an attacker to recover RSA PKCS#1 v1.5 plaintext.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260713T172750Z/items/CVE-2026-41516.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: trustedfirmware / op-tee",
      "source_published_impact": "This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone technology. NVD: Starting in version 4.5.0 and prior to version 4.11.0, the RSA PKCS#1 v1.5 decryption implementation in the Hisilicon HPRE crypto driver uses non-constant-time memcmp() for label hash verification and has multiple distinguishable error paths. NVD: This creates a Bleichenbacher-style padding oracle that allows an attacker to recover RSA PKCS#1 v1.5 plaintext.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-41516/timeline.json",
      "vendor": "trustedfirmware"
    },
    {
      "affected_label": "neutrinolabs / xrdp",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-41521/",
      "current_public_safe_latest": false,
      "cvss_score": 8.2,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.31758,
      "epss_score": 0.00392,
      "first_observed_at": "2026-07-27T17:12:53.854417+00:00",
      "id": "CVE-2026-41521",
      "impact_tags": [
        "information exposure review",
        "service availability review",
        "remote exposure relevant"
      ],
      "kev": false,
      "last_observed_at": "2026-07-27T17:12:53.854417+00:00",
      "latest_item_url": null,
      "product": "xrdp",
      "public_safe_summary": "NVD: xrdp is an open source RDP server. NVD: Versions 0.10.6 and prior contain an integer overflow vulnerability when processing screen update messages within the vnc-any connection mode. NVD: A malicious remote VNC server can send crafted image dimensions that cause an integer overflow during memory buffer size calculation, resulting in an undersized allocation.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260727T171933Z/items/CVE-2026-41521.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: neutrinolabs / xrdp",
      "source_published_impact": "Source describes information exposure review · service availability risk · remote exposure. Possible impact: A remote attacker may be able to access information that should not be exposed.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: xrdp is an open source RDP server. NVD: Versions 0.10.6 and prior contain an integer overflow vulnerability when processing screen update messages within the vnc-any connection mode. NVD: A malicious remote VNC server can send crafted image dimensions that cause an integer overflow during memory buffer size calculation, resulting in an undersized allocation.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-41521/timeline.json",
      "vendor": "neutrinolabs"
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-41703/",
      "current_public_safe_latest": false,
      "cvss_score": 7.6,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.43204,
      "epss_score": 0.00556,
      "first_observed_at": "2026-08-06T11:35:20.545945+00:00",
      "id": "CVE-2026-41703",
      "impact_tags": [
        "information exposure review",
        "service availability review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-06T11:35:20.545945+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: VMware ESX, Workstation, and Fusion contain an out-of-bounds read vulnerability. NVD: A malicious actor with VM deployment privileges could trigger an out-of-bounds read, potentially leading to information disclosure or more likely a Denial-of-Service (DoS) condition of the host process. NVD: On Workstation and Fusion, the impact of this vulnerability is restricted to information disclosure.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260806T114533Z/items/CVE-2026-41703.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes information exposure review · service availability risk. Possible impact: An attacker may be able to access information that should not be exposed.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: VMware ESX, Workstation, and Fusion contain an out-of-bounds read vulnerability. NVD: A malicious actor with VM deployment privileges could trigger an out-of-bounds read, potentially leading to information disclosure or more likely a Denial-of-Service (DoS) condition of the host process. NVD: On Workstation and Fusion, the impact of this vulnerability is restricted to information disclosure.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-41703/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-41709/",
      "current_public_safe_latest": false,
      "cvss_score": 2.7,
      "cvss_severity": "LOW",
      "epss_percentile": 0.30866,
      "epss_score": 0.00382,
      "first_observed_at": "2026-08-06T11:35:20.545945+00:00",
      "id": "CVE-2026-41709",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-06T11:35:20.545945+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: VMware ESX contains an insufficient logging vulnerability. NVD: A malicious administrator could exploit this issue to perform certain operations without them being logged.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260806T114533Z/items/CVE-2026-41709.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: VMware ESX contains an insufficient logging vulnerability. NVD: A malicious administrator could exploit this issue to perform certain operations without them being logged.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-41709/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "cloudfoundry / bosh_cli",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-41857/",
      "current_public_safe_latest": false,
      "cvss_score": 7.1,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.04427,
      "epss_score": 0.00148,
      "first_observed_at": "2026-07-16T05:57:17.509937+00:00",
      "id": "CVE-2026-41857",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-16T05:57:17.509937+00:00",
      "latest_item_url": null,
      "product": "bosh_cli",
      "public_safe_summary": "NVD: A compromised or malicious BOSH Director can execute arbitrary shell commands on the operator's workstation when the operator runs bosh ssh (or bosh scp/bosh logs -f) with default flags. NVD: Affected versions: BOSH CLI versions prior to 7.10.5. OSV: BOSH CLI Shell Injection",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260716T055845Z/items/CVE-2026-41857.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: cloudfoundry / bosh_cli",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A compromised or malicious BOSH Director can execute arbitrary shell commands on the operator's workstation when the operator runs bosh ssh (or bosh scp/bosh logs -f) with default flags. NVD: Affected versions: BOSH CLI versions prior to 7.10.5. OSV: BOSH CLI Shell Injection",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-41857/timeline.json",
      "vendor": "cloudfoundry"
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-41874/",
      "current_public_safe_latest": false,
      "cvss_score": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.03214,
      "epss_score": 0.00133,
      "first_observed_at": "2026-08-04T11:35:47.800052+00:00",
      "id": "CVE-2026-41874",
      "impact_tags": [
        "privilege boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-04T11:35:47.800052+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Quick.Cart stores hard-coded, plaintext admin credentials in a configuration file. NVD: This flaw allows attackers with access to the server file system to retrieve authentication details, potentially leading to privilege escalation. NVD: The vendor assessed the likelihood of exploitation as very low and determined that a fix is not necessary.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260804T114328Z/items/CVE-2026-41874.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes privilege escalation risk. Possible impact: An attacker may cross a privilege boundary and gain more access than intended.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Quick.Cart stores hard-coded, plaintext admin credentials in a configuration file. NVD: This flaw allows attackers with access to the server file system to retrieve authentication details, potentially leading to privilege escalation. NVD: The vendor assessed the likelihood of exploitation as very low and determined that a fix is not necessary.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-41874/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-41899/",
      "current_public_safe_latest": false,
      "cvss_score": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.21805,
      "epss_score": 0.003,
      "first_observed_at": "2026-07-13T22:14:02.217047+00:00",
      "id": "CVE-2026-41899",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-13T22:14:02.217047+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. NVD: Prior to 4.0.0-beta.474, POST /api/feedback has no authentication, no rate limiting, and no input validation, allowing arbitrary content to be forwarded directly to a Discord webhook and enabling spam, content injection, and webhook abuse. NVD: This issue is fixed in version 4.0.0-beta.474.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260714T042224Z/items/CVE-2026-41899.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. NVD: Prior to 4.0.0-beta.474, POST /api/feedback has no authentication, no rate limiting, and no input validation, allowing arbitrary content to be forwarded directly to a Discord webhook and enabling spam, content injection, and webhook abuse. NVD: This issue is fixed in version 4.0.0-beta.474.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-41899/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-42049/",
      "current_public_safe_latest": false,
      "cvss_score": 8.4,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.04751,
      "epss_score": 0.00151,
      "first_observed_at": "2026-07-21T22:14:32.860584+00:00",
      "id": "CVE-2026-42049",
      "impact_tags": [
        "code execution review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-21T22:14:32.860584+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: jadx is a Dex to Java decompiler. NVD: Prior to 1.5.6, jadx inserts the android:versionName value from an AndroidManifest into the generated app/build.gradle Groovy template without proper sanitization when exporting a decompiled APK as an Android Gradle project. NVD: A malicious APK can break out of the string context so that opening or building the exported Gradle project executes attacker-controlled Groovy code on the victim machine.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260721T221655Z/items/CVE-2026-42049.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes code execution review. Possible impact: An attacker may be able to run code or commands on affected systems.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: jadx is a Dex to Java decompiler. NVD: Prior to 1.5.6, jadx inserts the android:versionName value from an AndroidManifest into the generated app/build.gradle Groovy template without proper sanitization when exporting a decompiled APK as an Android Gradle project. NVD: A malicious APK can break out of the string context so that opening or building the exported Gradle project executes attacker-controlled Groovy code on the victim machine.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-42049/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-42148/",
      "current_public_safe_latest": false,
      "cvss_score": 3.8,
      "cvss_severity": "LOW",
      "epss_percentile": 0.02219,
      "epss_score": 0.00121,
      "first_observed_at": "2026-07-13T22:14:02.217047+00:00",
      "id": "CVE-2026-42148",
      "impact_tags": [
        "command injection risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-13T22:14:02.217047+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. NVD: Prior to 4.0.0-beta.474, the buildHelperImage method in app/Livewire/Settings/Index.php constructs a Docker build command using the dev_helper_version field without shell escaping, allowing an attacker who can set the helper version and trigger the helper... NVD: This issue is fixed in version 4.0.0-beta.474.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260714T042224Z/items/CVE-2026-42148.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes command injection risk. Possible impact: An attacker may be able to run unintended system commands through the affected component.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. NVD: Prior to 4.0.0-beta.474, the buildHelperImage method in app/Livewire/Settings/Index.php constructs a Docker build command using the dev_helper_version field without shell escaping, allowing an attacker who can set the helper version and trigger the helper... NVD: This issue is fixed in version 4.0.0-beta.474.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-42148/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-42153/",
      "current_public_safe_latest": false,
      "cvss_score": 8.8,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.28032,
      "epss_score": 0.00359,
      "first_observed_at": "2026-07-13T22:14:02.217047+00:00",
      "id": "CVE-2026-42153",
      "impact_tags": [
        "command injection risk",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-13T22:14:02.217047+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. NVD: Prior to 4.0.0-beta.474, PostgreSQL healthcheck command generation used attacker-controlled database settings (postgres_user and postgres_db) in shell-form commands, allowing an authenticated user to inject commands executed in the database container. NVD: This issue is fixed in version 4.0.0-beta.474.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260714T042224Z/items/CVE-2026-42153.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes command injection risk · authenticated boundary. Possible impact: An attacker may be able to run unintended system commands through the affected component.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. NVD: Prior to 4.0.0-beta.474, PostgreSQL healthcheck command generation used attacker-controlled database settings (postgres_user and postgres_db) in shell-form commands, allowing an authenticated user to inject commands executed in the database container. NVD: This issue is fixed in version 4.0.0-beta.474.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-42153/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-42204/",
      "current_public_safe_latest": false,
      "cvss_score": 8.8,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.28032,
      "epss_score": 0.00359,
      "first_observed_at": "2026-07-13T22:14:02.217047+00:00",
      "id": "CVE-2026-42204",
      "impact_tags": [
        "code execution review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-13T22:14:02.217047+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. NVD: From 4.0.0-beta.471 through 4.0.0-beta.473, a regression in SHELL_SAFE_COMMAND_PATTERN allowed ampersands in custom Docker Compose build, start, and pre/post-deployment command fields, allowing an authenticated team member to inject shell commands that... NVD: This issue is fixed in version 4.0.0-beta.474.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260714T042224Z/items/CVE-2026-42204.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes code execution review. Possible impact: An attacker may be able to run code or commands on affected systems.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. NVD: From 4.0.0-beta.471 through 4.0.0-beta.473, a regression in SHELL_SAFE_COMMAND_PATTERN allowed ampersands in custom Docker Compose build, start, and pre/post-deployment command fields, allowing an authenticated team member to inject shell commands that... NVD: This issue is fixed in version 4.0.0-beta.474.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-42204/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-42210/",
      "current_public_safe_latest": false,
      "cvss_score": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.34249,
      "epss_score": 0.00418,
      "first_observed_at": "2026-07-27T17:12:53.854417+00:00",
      "id": "CVE-2026-42210",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-27T17:12:53.854417+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Webmin is a web-based system administration tool for Unix-like servers. NVD: Prior to version 2.640, for Webmin accounts that require a second authentication factor (typically TOTP), an attacker with knowledge of the username and password can bypass the 2FA requirement by using Basic authentication. NVD: As a workaround, apply the patch from commit da18a16c84ae5c0b78cad79609cb0efb174000ec manually.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260727T171933Z/items/CVE-2026-42210.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Webmin is a web-based system administration tool for Unix-like servers. NVD: Prior to version 2.640, for Webmin accounts that require a second authentication factor (typically TOTP), an attacker with knowledge of the username and password can bypass the 2FA requirement by using Basic authentication. NVD: As a workaround, apply the patch from commit da18a16c84ae5c0b78cad79609cb0efb174000ec manually.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-42210/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-42447/",
      "current_public_safe_latest": false,
      "cvss_score": 3.6,
      "cvss_severity": "LOW",
      "epss_percentile": 0.03675,
      "epss_score": 0.00139,
      "first_observed_at": "2026-07-21T22:14:32.860584+00:00",
      "id": "CVE-2026-42447",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-21T22:14:32.860584+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: jadx is a Dex to Java decompiler. NVD: Prior to 1.5.6, jadx-gui is affected by an HTML injection vulnerability in the Summary tab because SummaryNode.java appends arches and perArchCount values derived from .so file path components inside an APK into an HTML panel without escaping. NVD: A malicious APK with an HTML URL-encoded ZIP entry name can force rendering of arbitrary HTML, perform out-of-band requests, disclose the victim IP address, or interact with locally exposed applications.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260721T221655Z/items/CVE-2026-42447.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: jadx is a Dex to Java decompiler. NVD: Prior to 1.5.6, jadx-gui is affected by an HTML injection vulnerability in the Summary tab because SummaryNode.java appends arches and perArchCount values derived from .so file path components inside an APK into an HTML panel without escaping. NVD: A malicious APK with an HTML URL-encoded ZIP entry name can force rendering of arbitrary HTML, perform out-of-band requests, disclose the victim IP address, or interact with locally exposed applications.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-42447/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-42492/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.38746,
      "epss_score": 0.00477,
      "first_observed_at": "2026-08-04T11:35:47.800052+00:00",
      "id": "CVE-2026-42492",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-04T11:35:47.800052+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Xenstore, to have an up-to-date picture of the entire system, wants to know of domains appearing and disappearing. NVD: To make this more robust, a new XEN_DOMCTL_get_domain_state was introduced. NVD: The management of the bitmap underlying that operation is tied into the binding of the VIRQ_DOM_EXC virtual IRQ.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260804T114328Z/items/CVE-2026-42492.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Xenstore, to have an up-to-date picture of the entire system, wants to know of domains appearing and disappearing. NVD: To make this more robust, a new XEN_DOMCTL_get_domain_state was introduced. NVD: The management of the bitmap underlying that operation is tied into the binding of the VIRQ_DOM_EXC virtual IRQ.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-42492/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-42493/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.38517,
      "epss_score": 0.00474,
      "first_observed_at": "2026-08-04T11:35:47.800052+00:00",
      "id": "CVE-2026-42493",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-04T11:35:47.800052+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Addressing certain issues, in particular related to operations which may take excessively long and therefore would need preemption, has turned out overly costly. NVD: Since alternatives (HVM/PVH: HAP, PV: shim) are commonly available, the decision was to deprecate the functionality, while still retaining it for people to use at their own (security) risk. NVD: Memory-wise small enough guests may still be okay to run.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260804T114328Z/items/CVE-2026-42493.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Addressing certain issues, in particular related to operations which may take excessively long and therefore would need preemption, has turned out overly costly. NVD: Since alternatives (HVM/PVH: HAP, PV: shim) are commonly available, the decision was to deprecate the functionality, while still retaining it for people to use at their own (security) risk. NVD: Memory-wise small enough guests may still be okay to run.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-42493/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-42494/",
      "current_public_safe_latest": false,
      "cvss_score": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.01795,
      "epss_score": 0.00115,
      "first_observed_at": "2026-08-04T11:35:47.800052+00:00",
      "id": "CVE-2026-42494",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-04T11:35:47.800052+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] The directory and Rock Ridge / SUSP walk in libfsimage's iso9660 driver derives several lengths directly from attacker-controlled... NVD: This is CVE-2026-42494. NVD: * The calculation of the System Use area may underflow.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260804T114328Z/items/CVE-2026-42494.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] The directory and Rock Ridge / SUSP walk in libfsimage's iso9660 driver derives several lengths directly from attacker-controlled... NVD: This is CVE-2026-42494. NVD: * The calculation of the System Use area may underflow.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-42494/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-42495/",
      "current_public_safe_latest": false,
      "cvss_score": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.10711,
      "epss_score": 0.00205,
      "first_observed_at": "2026-08-04T11:35:47.800052+00:00",
      "id": "CVE-2026-42495",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-04T11:35:47.800052+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] The directory and Rock Ridge / SUSP walk in libfsimage's iso9660 driver derives several lengths directly from attacker-controlled... NVD: This is CVE-2026-42494. NVD: * The calculation of the System Use area may underflow.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260804T114328Z/items/CVE-2026-42495.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] The directory and Rock Ridge / SUSP walk in libfsimage's iso9660 driver derives several lengths directly from attacker-controlled... NVD: This is CVE-2026-42494. NVD: * The calculation of the System Use area may underflow.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-42495/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "golang / go",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-42505/",
      "current_public_safe_latest": false,
      "cvss_score": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.33374,
      "epss_score": 0.00413,
      "first_observed_at": "2026-07-15T16:47:57.605966+00:00",
      "id": "CVE-2026-42505",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-15T16:47:57.605966+00:00",
      "latest_item_url": null,
      "product": "go",
      "public_safe_summary": "NVD: Handshakes which used Encrypted Client Hello could be de-anonymized by a passive network observer due to a disclosure of pre-shared key identities in the unencrypted client hello.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260715T164957Z/items/CVE-2026-42505.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: golang / go; affected version context: 1.27",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Handshakes which used Encrypted Client Hello could be de-anonymized by a passive network observer due to a disclosure of pre-shared key identities in the unencrypted client hello.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-42505/timeline.json",
      "vendor": "golang"
    },
    {
      "affected_label": "apache / camel",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-42527/",
      "current_public_safe_latest": false,
      "cvss_score": 8.1,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.41926,
      "epss_score": 0.00546,
      "first_observed_at": "2026-07-13T06:32:51.098771+00:00",
      "id": "CVE-2026-42527",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-13T06:32:51.098771+00:00",
      "latest_item_url": null,
      "product": "camel",
      "public_safe_summary": "NVD: Deserialization of Untrusted Data vulnerability in Apache Camel. NVD: The default ObjectInputFilter pattern shipped with several Apache Camel components for defense-in-depth deserialization filtering ('java.**;javax.**;org.apache.camel.**;!*', or the no-'javax.**' variant in the aggregation-repository components) uses a... NVD: The class-level filter check passes because the resulting object's class (HashMap) is allow-listed; the DNS query is observable on an attacker-controlled DNS server, providing an out-of-band side channel.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260713T063521Z/items/CVE-2026-42527.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: apache / camel; affected version context: 4.20.0",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: a.",
      "source_published_summary": "NVD: Deserialization of Untrusted Data vulnerability in Apache Camel. NVD: The default ObjectInputFilter pattern shipped with several Apache Camel components for defense-in-depth deserialization filtering ('java.**;javax.**;org.apache.camel.**;!*', or the no-'javax.**' variant in the aggregation-repository components) uses a... NVD: The class-level filter check passes because the resulting object's class (HashMap) is allow-listed; the DNS query is observable on an attacker-controlled DNS server, providing an out-of-band side channel.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-42527/timeline.json",
      "vendor": "apache"
    },
    {
      "affected_label": "trustedfirmware / op-tee",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-42546/",
      "current_public_safe_latest": false,
      "cvss_score": 3.8,
      "cvss_severity": "LOW",
      "epss_percentile": 0.01289,
      "epss_score": 0.00105,
      "first_observed_at": "2026-07-13T17:24:46.617207+00:00",
      "id": "CVE-2026-42546",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-13T17:24:46.617207+00:00",
      "latest_item_url": null,
      "product": "op-tee",
      "public_safe_summary": "NVD: OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone technology. NVD: Starting in version 3.3.0 and prior to version 4.11.0, a resource leak exists in OP-TEE’s shared memory cleanup logic because the function cleanup_shm_refs() in core/tee/entry_std.c fails to apply a required bitmask (OPTEE_MSG_ATTR_TYPE_MASK) to parameter... NVD: When processing non-contiguous memory parameters from a normal-world caller, the system fails to match the attribute type in its internal switch statement and skips the necessary mobj_put() call.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260713T172750Z/items/CVE-2026-42546.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: trustedfirmware / op-tee",
      "source_published_impact": "This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone technology. NVD: Starting in version 3.3.0 and prior to version 4.11.0, a resource leak exists in OP-TEE’s shared memory cleanup logic because the function cleanup_shm_refs() in core/tee/entry_std.c fails to apply a required bitmask (OPTEE_MSG_ATTR_TYPE_MASK) to parameter... NVD: When processing non-contiguous memory parameters from a normal-world caller, the system fails to match the attribute type in its internal switch statement and skips the necessary mobj_put() call.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-42546/timeline.json",
      "vendor": "trustedfirmware"
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-4256/",
      "current_public_safe_latest": false,
      "cvss_score": 8.2,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.11582,
      "epss_score": 0.00213,
      "first_observed_at": "2026-07-16T13:54:14.110513+00:00",
      "id": "CVE-2026-4256",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-16T13:54:14.110513+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Improper neutralization of special elements used in an LDAP query ('LDAP injection') vulnerability in PEAKUP Technology Inc. NVD: PassGate allows LDAP Injection. NVD: This issue affects PassGate: through 30042026.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260716T135621Z/items/CVE-2026-4256.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Improper neutralization of special elements used in an LDAP query ('LDAP injection') vulnerability in PEAKUP Technology Inc. NVD: PassGate allows LDAP Injection. NVD: This issue affects PassGate: through 30042026.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-4256/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-42566/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.20109,
      "epss_score": 0.00279,
      "first_observed_at": "2026-07-26T22:15:56.881440+00:00",
      "id": "CVE-2026-42566",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-26T22:15:56.881440+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Meshtastic is an open source mesh networking solution. NVD: Prior to version 2.7.23.b246bcd, a single node advertising a User.long_name that contains a malformed character encoding can render other radios unusable over BLE when managed through the iOS app. NVD: The malformed name does not need to be maliciously crafted — it can arise from ordinary buffer truncation and has been observed occurring naturally in the wild.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260726T221942Z/items/CVE-2026-42566.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Meshtastic is an open source mesh networking solution. NVD: Prior to version 2.7.23.b246bcd, a single node advertising a User.long_name that contains a malformed character encoding can render other radios unusable over BLE when managed through the iOS app. NVD: The malformed name does not need to be maliciously crafted — it can arise from ordinary buffer truncation and has been observed occurring naturally in the wild.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-42566/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-4275/",
      "current_public_safe_latest": false,
      "cvss_score": 8.8,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.08421,
      "epss_score": 0.00187,
      "first_observed_at": "2026-07-16T11:14:01.223847+00:00",
      "id": "CVE-2026-4275",
      "impact_tags": [
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-16T11:14:01.223847+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Divi Torque Lite – Divi Theme, Divi Builder & Extra Theme plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.2.3. NVD: This is due to the use of '__return_true' as the permission_callback for the /install_plugin and /activate_plugin REST API endpoints, which bypasses WordPress's built-in REST API nonce verification. NVD: Although the endpoint callbacks contain internal current_user_can() checks, the absence of nonce verification means that a forged cross-site request from a logged-in administrator's browser will pass the capability check via the admin's session cookies.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260716T111601Z/items/CVE-2026-4275.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes remote exposure · authenticated boundary. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Divi Torque Lite – Divi Theme, Divi Builder & Extra Theme plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.2.3. NVD: This is due to the use of '__return_true' as the permission_callback for the /install_plugin and /activate_plugin REST API endpoints, which bypasses WordPress's built-in REST API nonce verification. NVD: Although the endpoint callbacks contain internal current_user_can() checks, the absence of nonce verification means that a forged cross-site request from a logged-in administrator's browser will pass the capability check via the admin's session cookies.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-4275/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "microsoft / windows_10_1607",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-42900/",
      "current_public_safe_latest": false,
      "cvss_score": 8.1,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.31315,
      "epss_score": 0.00389,
      "first_observed_at": "2026-07-21T16:48:32.557544+00:00",
      "id": "CVE-2026-42900",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-21T16:48:32.557544+00:00",
      "latest_item_url": null,
      "product": "windows_10_1607",
      "public_safe_summary": "NVD: Concurrent execution using shared resource with improper synchronization ('race condition') in Windows App Store allows an unauthorized attacker to elevate privileges over a network.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260721T165442Z/items/CVE-2026-42900.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: microsoft / windows_10_1607",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Concurrent execution using shared resource with improper synchronization ('race condition') in Windows App Store allows an unauthorized attacker to elevate privileges over a network.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-42900/timeline.json",
      "vendor": "microsoft"
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-42933/",
      "current_public_safe_latest": false,
      "cvss_score": 10.0,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.20739,
      "epss_score": 0.00285,
      "first_observed_at": "2026-07-30T22:30:38.166118+00:00",
      "id": "CVE-2026-42933",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-30T22:30:38.166118+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Pronetiqs IntraVUE versions 3.2.1a14 and prior have an unintended proxy or intermediary vulnerability which could allow an attacker to use an active proxy, which would bypass OT segmentation.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260730T224832Z/items/CVE-2026-42933.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Pronetiqs IntraVUE versions 3.2.1a14 and prior have an unintended proxy or intermediary vulnerability which could allow an attacker to use an active proxy, which would bypass OT segmentation.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-42933/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-42936/",
      "current_public_safe_latest": false,
      "cvss_score": 8.4,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.03913,
      "epss_score": 0.00142,
      "first_observed_at": "2026-07-22T06:07:21.492959+00:00",
      "id": "CVE-2026-42936",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-22T06:07:21.492959+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The installer of HYPER SBI 2 insecurely loads Dynamic Link Libraries. NVD: If there is a crafted DLL at the same directory when invoking the affected installer, arbitrary code may be executed with the privilege of the user invoking the installer.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260722T060931Z/items/CVE-2026-42936.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The installer of HYPER SBI 2 insecurely loads Dynamic Link Libraries. NVD: If there is a crafted DLL at the same directory when invoking the affected installer, arbitrary code may be executed with the privilege of the user invoking the installer.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-42936/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-4298/",
      "current_public_safe_latest": false,
      "cvss_score": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.10429,
      "epss_score": 0.00204,
      "first_observed_at": "2026-07-16T11:14:01.223847+00:00",
      "id": "CVE-2026-4298",
      "impact_tags": [
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-16T11:14:01.223847+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The DSGVO All in one for WP plugin for WordPress is vulnerable to Missing Authorization in all versions up to and including 4.9. NVD: This is due to the dsgvo_reset_policy_service_func() function lacking both capability checks and nonce verification while processing user-supplied parameters to reset plugin options. NVD: This makes it possible for authenticated attackers, with Subscriber-level access and above, to reset all customized privacy policy content including cookie notices, Google Analytics policies, Facebook policies, and YouTube policies to their default values.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260716T111601Z/items/CVE-2026-4298.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The DSGVO All in one for WP plugin for WordPress is vulnerable to Missing Authorization in all versions up to and including 4.9. NVD: This is due to the dsgvo_reset_policy_service_func() function lacking both capability checks and nonce verification while processing user-supplied parameters to reset plugin options. NVD: This makes it possible for authenticated attackers, with Subscriber-level access and above, to reset all customized privacy policy content including cookie notices, Google Analytics policies, Facebook policies, and YouTube policies to their default values.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-4298/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-4375/",
      "current_public_safe_latest": false,
      "cvss_score": 9.0,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.16019,
      "epss_score": 0.00248,
      "first_observed_at": "2026-07-14T05:42:23.241208+00:00",
      "id": "CVE-2026-4375",
      "impact_tags": [
        "code execution review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-14T05:42:23.241208+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The DoLeads Integrator WordPress plugin through 0.65, wp2epub WordPress plugin through 0.65 have been seen to be used to achieve RCE, once they are added adding to a blog, for example using a vulnerability where unclosed extensions from wordpress.org can be...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260714T054512Z/items/CVE-2026-4375.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes code execution review. Possible impact: An attacker may be able to run code or commands on affected systems.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The DoLeads Integrator WordPress plugin through 0.65, wp2epub WordPress plugin through 0.65 have been seen to be used to achieve RCE, once they are added adding to a blog, for example using a vulnerability where unclosed extensions from wordpress.org can be...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-4375/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-43918/",
      "current_public_safe_latest": false,
      "cvss_score": 8.7,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.1437,
      "epss_score": 0.00235,
      "first_observed_at": "2026-07-13T22:14:02.217047+00:00",
      "id": "CVE-2026-43918",
      "impact_tags": [
        "privilege boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-13T22:14:02.217047+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: FOSSBilling is a free, open-source billing and client management system. NVD: Prior to version 0.8.0, when a client or staff/admin account is suspended or marked inactive, existing authenticated sessions are not invalidated. NVD: The session identity loaders in src/di.php (loggedin_client and loggedin_admin) only reject sessions if the backing account record no longer exists in the database.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260714T042224Z/items/CVE-2026-43918.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes privilege escalation risk. Possible impact: An attacker may cross a privilege boundary and gain more access than intended.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: FOSSBilling is a free, open-source billing and client management system. NVD: Prior to version 0.8.0, when a client or staff/admin account is suspended or marked inactive, existing authenticated sessions are not invalidated. NVD: The session identity loaders in src/di.php (loggedin_client and loggedin_admin) only reject sessions if the backing account record no longer exists in the database.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-43918/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-43921/",
      "current_public_safe_latest": false,
      "cvss_score": 8.9,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.19237,
      "epss_score": 0.00274,
      "first_observed_at": "2026-07-13T22:14:02.217047+00:00",
      "id": "CVE-2026-43921",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-13T22:14:02.217047+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: FOSSBilling is a free, open-source billing and client management system. NVD: Versions 0.6.10 through 0.7.2 have a PHP code injection vulnerability in FOSSBilling's Config::prettyPrintArrayToPHP() method. NVD: When configuration values are updated, string values are written into config.php without escaping single quotes.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260714T042224Z/items/CVE-2026-43921.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: FOSSBilling is a free, open-source billing and client management system. NVD: Versions 0.6.10 through 0.7.2 have a PHP code injection vulnerability in FOSSBilling's Config::prettyPrintArrayToPHP() method. NVD: When configuration values are updated, string values are written into config.php without escaping single quotes.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-43921/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-43925/",
      "current_public_safe_latest": false,
      "cvss_score": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.21651,
      "epss_score": 0.00298,
      "first_observed_at": "2026-07-13T22:14:02.217047+00:00",
      "id": "CVE-2026-43925",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-13T22:14:02.217047+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: FOSSBilling is a free, open-source billing and client management system. NVD: Prior to version 0.8.0, an unauthenticated mass assignment vulnerability in the client self-registration endpoint allows any visitor to assign themselves to an arbitrary client group during sign-up. NVD: Because client groups can gate promo code eligibility, an attacker may apply group-restricted discount codes and receive unauthorized discounts.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260714T042224Z/items/CVE-2026-43925.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: FOSSBilling is a free, open-source billing and client management system. NVD: Prior to version 0.8.0, an unauthenticated mass assignment vulnerability in the client self-registration endpoint allows any visitor to assign themselves to an arbitrary client group during sign-up. NVD: Because client groups can gate promo code eligibility, an attacker may apply group-restricted discount codes and receive unauthorized discounts.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-43925/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-43927/",
      "current_public_safe_latest": false,
      "cvss_score": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.1248,
      "epss_score": 0.0022,
      "first_observed_at": "2026-07-13T22:14:02.217047+00:00",
      "id": "CVE-2026-43927",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-13T22:14:02.217047+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: FOSSBilling is a free, open-source billing and client management system. NVD: Prior to version 0.8.0, a race condition in the cart checkout flow allows an authenticated client to apply a promo code beyond its configured maximum uses. NVD: By sending concurrent checkout requests before any single request completes the usage increment, a client can obtain unlimited discounted or free orders from a single-use or limited-use promo code.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260714T042224Z/items/CVE-2026-43927.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: FOSSBilling is a free, open-source billing and client management system. NVD: Prior to version 0.8.0, a race condition in the cart checkout flow allows an authenticated client to apply a promo code beyond its configured maximum uses. NVD: By sending concurrent checkout requests before any single request completes the usage increment, a client can obtain unlimited discounted or free orders from a single-use or limited-use promo code.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-43927/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-43928/",
      "current_public_safe_latest": false,
      "cvss_score": 2.3,
      "cvss_severity": "LOW",
      "epss_percentile": 0.19224,
      "epss_score": 0.00274,
      "first_observed_at": "2026-07-13T22:14:02.217047+00:00",
      "id": "CVE-2026-43928",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-13T22:14:02.217047+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: FOSSBilling is a free, open-source billing and client management system. NVD: Prior to version 0.8.0, the PayPalEmail payment adapter accepts PayPal IPN callbacks and credits the IPN-supplied amount (mc_gross) to the client's balance without validating it against the invoice total. NVD: Combined with a $0.05 floating-point epsilon tolerance in the invoice credit-payment logic, this allows a client to underpay an invoice by up to $0.04 and still have it marked as fully paid.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260714T042224Z/items/CVE-2026-43928.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: FOSSBilling is a free, open-source billing and client management system. NVD: Prior to version 0.8.0, the PayPalEmail payment adapter accepts PayPal IPN callbacks and credits the IPN-supplied amount (mc_gross) to the client's balance without validating it against the invoice total. NVD: Combined with a $0.05 floating-point epsilon tolerance in the invoice credit-payment logic, this allows a client to underpay an invoice by up to $0.04 and still have it marked as fully paid.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-43928/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-43977/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.14144,
      "epss_score": 0.00232,
      "first_observed_at": "2026-07-23T22:18:14.498937+00:00",
      "id": "CVE-2026-43977",
      "impact_tags": [
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-23T22:18:14.498937+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: wger is a free, open-source workout and fitness manager. NVD: In versions prior to 2.6, any authenticated user can read another user's private workout session notes, exercise history, and training statistics by calling the /logs/ and /stats/ actions on a routine they do not own. NVD: The vulnerability exists in RoutineViewSet (wger/manager/api/views.py).",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260723T222557Z/items/CVE-2026-43977.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes authenticated boundary. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: wger is a free, open-source workout and fitness manager. NVD: In versions prior to 2.6, any authenticated user can read another user's private workout session notes, exercise history, and training statistics by calling the /logs/ and /stats/ actions on a routine they do not own. NVD: The vulnerability exists in RoutineViewSet (wger/manager/api/views.py).",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-43977/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-43978/",
      "current_public_safe_latest": false,
      "cvss_score": 8.1,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.11697,
      "epss_score": 0.00213,
      "first_observed_at": "2026-07-23T22:18:14.498937+00:00",
      "id": "CVE-2026-43978",
      "impact_tags": [
        "privilege boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-23T22:18:14.498937+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: wger is a free, open-source workout and fitness manager. NVD: In versions prior to 2.6, a gym trainer can escalate their session to any higher-privileged account (gym manager, general manager) by chaining two calls to the trainer-login endpoint. NVD: Once a trainer performs a legitimate switch into a low-privileged user, the session flag trainer.identity is set and this flag alone bypasses the permission check on all subsequent trainer-login calls.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260723T222557Z/items/CVE-2026-43978.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes privilege escalation risk. Possible impact: An attacker may cross a privilege boundary and gain more access than intended.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: wger is a free, open-source workout and fitness manager. NVD: In versions prior to 2.6, a gym trainer can escalate their session to any higher-privileged account (gym manager, general manager) by chaining two calls to the trainer-login endpoint. NVD: Once a trainer performs a legitimate switch into a low-privileged user, the session flag trainer.identity is set and this flag alone bypasses the permission check on all subsequent trainer-login calls.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-43978/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "fluentd / fluentd",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-44024/",
      "current_public_safe_latest": false,
      "cvss_score": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.61448,
      "epss_score": 0.01085,
      "first_observed_at": "2026-07-15T22:16:59.245057+00:00",
      "id": "CVE-2026-44024",
      "impact_tags": [
        "code execution review",
        "path traversal review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-15T22:16:59.245057+00:00",
      "latest_item_url": null,
      "product": "fluentd",
      "public_safe_summary": "NVD: Fluentd collects events from various data sources and writes them to files, RDBMS, NoSQL, IaaS, SaaS, Hadoop and so on. NVD: Prior to 1.19.3, Fluentd allows dynamically constructing file paths using the ${tag} placeholder, and insufficient validation of ${tag} in file configurations such as the path parameter of the out_file plugin allows attackers sending untrusted tags containing... NVD: This issue is fixed in version 1.19.3.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260715T221956Z/items/CVE-2026-44024.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: fluentd / fluentd",
      "source_published_impact": "Source describes code execution review · path traversal review. Possible impact: An attacker may be able to run code or commands on affected systems.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: Fluentd collects events from various data sources and writes them to files, RDBMS, NoSQL, IaaS, SaaS, Hadoop and so on. NVD: Prior to 1.19.3, Fluentd allows dynamically constructing file paths using the ${tag} placeholder, and insufficient validation of ${tag} in file configurations such as the path parameter of the out_file plugin allows attackers sending untrusted tags containing... NVD: This issue is fixed in version 1.19.3.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-44024/timeline.json",
      "vendor": "fluentd"
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-44025/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.38344,
      "epss_score": 0.00482,
      "first_observed_at": "2026-07-15T22:16:59.245057+00:00",
      "id": "CVE-2026-44025",
      "impact_tags": [
        "information exposure review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-15T22:16:59.245057+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Fluentd collects events from various data sources and writes them to files, RDBMS, NoSQL, IaaS, SaaS, Hadoop and so on. NVD: Prior to 1.19.3, Fluentd's Monitor Agent plugin in_monitor_agent exposes internal metrics and plugin information via a REST API, and responses from /api/plugins.json and related endpoints unintentionally include internal instance variables that may contain... NVD: This issue is fixed in version 1.19.3.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260715T221956Z/items/CVE-2026-44025.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes information exposure review. Possible impact: An attacker may be able to access information that should not be exposed.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: Fluentd collects events from various data sources and writes them to files, RDBMS, NoSQL, IaaS, SaaS, Hadoop and so on. NVD: Prior to 1.19.3, Fluentd's Monitor Agent plugin in_monitor_agent exposes internal metrics and plugin information via a REST API, and responses from /api/plugins.json and related endpoints unintentionally include internal instance variables that may contain... NVD: This issue is fixed in version 1.19.3.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-44025/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "fluentd / fluentd",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-44160/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.45635,
      "epss_score": 0.0062,
      "first_observed_at": "2026-07-15T22:16:59.245057+00:00",
      "id": "CVE-2026-44160",
      "impact_tags": [
        "service availability review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-15T22:16:59.245057+00:00",
      "latest_item_url": null,
      "product": "fluentd",
      "public_safe_summary": "NVD: Fluentd collects events from various data sources and writes them to files, RDBMS, NoSQL, IaaS, SaaS, Hadoop and so on. NVD: Prior to 1.19.3, Fluentd's in_http and in_forward plugins support gzip-compressed data but enforce limits only on compressed payloads through settings such as body_size_limit and chunk_size_limit, allowing crafted compressed payloads to decompress in memory... NVD: This issue is fixed in version 1.19.3.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260715T221956Z/items/CVE-2026-44160.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: fluentd / fluentd",
      "source_published_impact": "Source describes service availability risk. Possible impact: The affected service may become unavailable or unreliable.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: Fluentd collects events from various data sources and writes them to files, RDBMS, NoSQL, IaaS, SaaS, Hadoop and so on. NVD: Prior to 1.19.3, Fluentd's in_http and in_forward plugins support gzip-compressed data but enforce limits only on compressed payloads through settings such as body_size_limit and chunk_size_limit, allowing crafted compressed payloads to decompress in memory... NVD: This issue is fixed in version 1.19.3.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-44160/timeline.json",
      "vendor": "fluentd"
    },
    {
      "affected_label": "fluentd / fluentd",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-44161/",
      "current_public_safe_latest": false,
      "cvss_score": 7.2,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.35721,
      "epss_score": 0.00442,
      "first_observed_at": "2026-07-15T22:16:59.245057+00:00",
      "id": "CVE-2026-44161",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-15T22:16:59.245057+00:00",
      "latest_item_url": null,
      "product": "fluentd",
      "public_safe_summary": "NVD: Fluentd collects events from various data sources and writes them to files, RDBMS, NoSQL, IaaS, SaaS, Hadoop and so on. NVD: Prior to 1.19.3, the Fluentd out_http output plugin allows placeholders such as ${tag} in the endpoint configuration parameter, and if a placeholder value is derived from untrusted input an attacker can control the destination hostname of outbound HTTP... NVD: This issue is fixed in version 1.19.3.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260715T221956Z/items/CVE-2026-44161.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: fluentd / fluentd",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: Fluentd collects events from various data sources and writes them to files, RDBMS, NoSQL, IaaS, SaaS, Hadoop and so on. NVD: Prior to 1.19.3, the Fluentd out_http output plugin allows placeholders such as ${tag} in the endpoint configuration parameter, and if a placeholder value is derived from untrusted input an attacker can control the destination hostname of outbound HTTP... NVD: This issue is fixed in version 1.19.3.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-44161/timeline.json",
      "vendor": "fluentd"
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-44181/",
      "current_public_safe_latest": false,
      "cvss_score": 10.0,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.37377,
      "epss_score": 0.0046,
      "first_observed_at": "2026-07-23T22:18:14.498937+00:00",
      "id": "CVE-2026-44181",
      "impact_tags": [
        "code execution review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-23T22:18:14.498937+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Jupyter Enterprise Gateway launches remote Jupyter Notebook kernels across distributed clusters like Apache Spark, Kubernetes, and Docker Swarm. NVD: In versions 2.0.0rc2 and above, prior to 3.3.0, the environment variables (KERNEL_XXX) used during the rendering of the Kubernetes manifest are vulnerable to Server Side Template Injection (SSTI). NVD: By including Jinja2 template expressions it is possible to execution Python code and OS Commands in the Enterprise Gateway service.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260723T222557Z/items/CVE-2026-44181.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes code execution review. Possible impact: An attacker may be able to run code or commands on affected systems.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: Jupyter Enterprise Gateway launches remote Jupyter Notebook kernels across distributed clusters like Apache Spark, Kubernetes, and Docker Swarm. NVD: In versions 2.0.0rc2 and above, prior to 3.3.0, the environment variables (KERNEL_XXX) used during the rendering of the Kubernetes manifest are vulnerable to Server Side Template Injection (SSTI). NVD: By including Jinja2 template expressions it is possible to execution Python code and OS Commands in the Enterprise Gateway service.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-44181/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-44182/",
      "current_public_safe_latest": false,
      "cvss_score": 10.0,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.27206,
      "epss_score": 0.00347,
      "first_observed_at": "2026-07-23T22:18:14.498937+00:00",
      "id": "CVE-2026-44182",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-23T22:18:14.498937+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Jupyter Enterprise Gateway launches remote Jupyter Notebook kernels across distributed clusters like Apache Spark, Kubernetes, and Docker Swarm. NVD: In versions prior to 3.3.0, the server interpolates untrusted environment variables (e.g., KERNEL_XXX) into Kubernetes manifests without YAML-aware escaping, enabling YAML injection attacks. NVD: Attackers can inject new fields, overwrite critical fields (e.g., duplicate securityContext keys, where the last one prevails), and inject document boundaries (--- for new documents, ...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260723T222557Z/items/CVE-2026-44182.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: Jupyter Enterprise Gateway launches remote Jupyter Notebook kernels across distributed clusters like Apache Spark, Kubernetes, and Docker Swarm. NVD: In versions prior to 3.3.0, the server interpolates untrusted environment variables (e.g., KERNEL_XXX) into Kubernetes manifests without YAML-aware escaping, enabling YAML injection attacks. NVD: Attackers can inject new fields, overwrite critical fields (e.g., duplicate securityContext keys, where the last one prevails), and inject document boundaries (--- for new documents, ...",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-44182/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-44187/",
      "current_public_safe_latest": false,
      "cvss_score": 3.3,
      "cvss_severity": "LOW",
      "epss_percentile": 0.00527,
      "epss_score": 0.00089,
      "first_observed_at": "2026-07-29T06:10:00.110927+00:00",
      "id": "CVE-2026-44187",
      "impact_tags": [
        "information exposure review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-29T11:36:18.065267+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A flaw was found in the Ansible Lightspeed extension for Visual Studio Code. NVD: This vulnerability allows an attacker with local access to the workstation, or malware running with the user's privileges, to read the Google Gemini API key. NVD: The extension insecurely stores the API key in plain text within the user's configuration file and writes it to output log files.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260729T114432Z/items/CVE-2026-44187.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes information exposure review. Possible impact: An attacker may be able to access information that should not be exposed.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A flaw was found in the Ansible Lightspeed extension for Visual Studio Code. NVD: This vulnerability allows an attacker with local access to the workstation, or malware running with the user's privileges, to read the Google Gemini API key. NVD: The extension insecurely stores the API key in plain text within the user's configuration file and writes it to output log files.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-44187/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-44189/",
      "current_public_safe_latest": false,
      "cvss_score": 7.8,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.42045,
      "epss_score": 0.00536,
      "first_observed_at": "2026-07-29T06:10:00.110927+00:00",
      "id": "CVE-2026-44189",
      "impact_tags": [
        "command injection risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-29T11:36:18.065267+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A flaw was found in the Visual Studio Code Ansible Lightspeed extension's AnsiblePlaybookRunProvider. NVD: This command injection vulnerability allows an attacker to craft a malicious playbook filename containing special characters. NVD: When a victim runs the playbook, these characters are not properly sanitized, leading to the execution of arbitrary code with the privileges of the user running VS Code.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260729T114432Z/items/CVE-2026-44189.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes command injection risk. Possible impact: An attacker may be able to run unintended system commands through the affected component.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A flaw was found in the Visual Studio Code Ansible Lightspeed extension's AnsiblePlaybookRunProvider. NVD: This command injection vulnerability allows an attacker to craft a malicious playbook filename containing special characters. NVD: When a victim runs the playbook, these characters are not properly sanitized, leading to the execution of arbitrary code with the privileges of the user running VS Code.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-44189/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-44190/",
      "current_public_safe_latest": false,
      "cvss_score": 7.8,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.35413,
      "epss_score": 0.00432,
      "first_observed_at": "2026-07-29T06:10:00.110927+00:00",
      "id": "CVE-2026-44190",
      "impact_tags": [
        "command injection risk",
        "remote exposure relevant"
      ],
      "kev": false,
      "last_observed_at": "2026-07-29T11:36:18.065267+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A flaw was found in the Ansible Lightspeed Visual Studio Code extension. NVD: This Command Injection vulnerability (CWE-78) allows a remote attacker to execute unauthorized commands on a user's system. NVD: The issue occurs because the ansible.python.activationScript setting, intended for a virtual environment activation script, does not properly validate user input as a file path.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260729T114432Z/items/CVE-2026-44190.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes command injection risk · remote exposure. Possible impact: A remote attacker may be able to run unintended system commands through the affected component.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A flaw was found in the Ansible Lightspeed Visual Studio Code extension. NVD: This Command Injection vulnerability (CWE-78) allows a remote attacker to execute unauthorized commands on a user's system. NVD: The issue occurs because the ansible.python.activationScript setting, intended for a virtual environment activation script, does not properly validate user input as a file path.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-44190/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-44192/",
      "current_public_safe_latest": false,
      "cvss_score": 6.6,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.04568,
      "epss_score": 0.00149,
      "first_observed_at": "2026-07-29T06:10:00.110927+00:00",
      "id": "CVE-2026-44192",
      "impact_tags": [
        "path traversal review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-29T11:36:18.065267+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A flaw was found in the Ansible Lightspeed Model Context Protocol (MCP) server. NVD: This vulnerability, known as path traversal, allows an attacker to manipulate an AI agent through indirect prompt injection. NVD: By doing so, the attacker can cause the server to write files to unauthorized locations on the user's system.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260729T114432Z/items/CVE-2026-44192.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes path traversal review. Possible impact: An attacker may be able to reach files outside the intended application path.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A flaw was found in the Ansible Lightspeed Model Context Protocol (MCP) server. NVD: This vulnerability, known as path traversal, allows an attacker to manipulate an AI agent through indirect prompt injection. NVD: By doing so, the attacker can cause the server to write files to unauthorized locations on the user's system.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-44192/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "dell / data_domain_operating_system",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-44268/",
      "current_public_safe_latest": false,
      "cvss_score": 4.4,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.01246,
      "epss_score": 0.00104,
      "first_observed_at": "2026-07-10T12:09:55.374028+00:00",
      "id": "CVE-2026-44268",
      "impact_tags": [
        "unauthorized access risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-10T12:09:55.374028+00:00",
      "latest_item_url": null,
      "product": "data_domain_operating_system",
      "public_safe_summary": "NVD: Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an incorrect permission Assignment for... NVD: A high privileged attacker with local access could potentially exploit this vulnerability, leading to unauthorized access.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260710T121119Z/items/CVE-2026-44268.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: dell / data_domain_operating_system",
      "source_published_impact": "Source describes unauthorized access risk. Possible impact: An attacker may access resources that should require stronger authorization.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an incorrect permission Assignment for... NVD: A high privileged attacker with local access could potentially exploit this vulnerability, leading to unauthorized access.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-44268/timeline.json",
      "vendor": "dell"
    },
    {
      "affected_label": "dell / data_domain_operating_system",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-44269/",
      "current_public_safe_latest": false,
      "cvss_score": 4.4,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.03223,
      "epss_score": 0.00133,
      "first_observed_at": "2026-07-10T12:09:55.374028+00:00",
      "id": "CVE-2026-44269",
      "impact_tags": [
        "unauthorized access risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-10T12:09:55.374028+00:00",
      "latest_item_url": null,
      "product": "data_domain_operating_system",
      "public_safe_summary": "NVD: Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an improper link resolution before... NVD: A high privileged attacker with local access could potentially exploit this vulnerability, leading to unauthorized access.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260710T121119Z/items/CVE-2026-44269.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: dell / data_domain_operating_system",
      "source_published_impact": "Source describes unauthorized access risk. Possible impact: An attacker may access resources that should require stronger authorization.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an improper link resolution before... NVD: A high privileged attacker with local access could potentially exploit this vulnerability, leading to unauthorized access.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-44269/timeline.json",
      "vendor": "dell"
    },
    {
      "affected_label": "newapi / new_api",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-44342/",
      "current_public_safe_latest": false,
      "cvss_score": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.0844,
      "epss_score": 0.00187,
      "first_observed_at": "2026-07-16T22:18:24.817461+00:00",
      "id": "CVE-2026-44342",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-16T22:18:24.817461+00:00",
      "latest_item_url": null,
      "product": "new_api",
      "public_safe_summary": "NVD: New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. NVD: Prior to 0.12.0-alpha.1, the email and WeChat account binding endpoints GET /api/oauth/email/bind and GET /api/oauth/wechat/bind used GET requests for state-changing account operations, allowing an attacker to trigger a logged-in user's browser to bind an... NVD: This issue is fixed in version 0.12.0-alpha.1.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260716T222035Z/items/CVE-2026-44342.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: newapi / new_api",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. NVD: Prior to 0.12.0-alpha.1, the email and WeChat account binding endpoints GET /api/oauth/email/bind and GET /api/oauth/wechat/bind used GET requests for state-changing account operations, allowing an attacker to trigger a logged-in user's browser to bind an... NVD: This issue is fixed in version 0.12.0-alpha.1.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-44342/timeline.json",
      "vendor": "newapi"
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-44359/",
      "current_public_safe_latest": false,
      "cvss_score": 10.0,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.59347,
      "epss_score": 0.01003,
      "first_observed_at": "2026-07-26T22:15:56.881440+00:00",
      "id": "CVE-2026-44359",
      "impact_tags": [
        "code execution review",
        "command injection risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-26T22:15:56.881440+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Meshtastic is an open source mesh networking solution. NVD: Prior to version 2.7.21.1370b23, the Meshtastic GitHub repository's main_matrix.yml workflow is triggered by pull_request_target and multiple jobs check out the attacker's fork code and execute it with access to repository secrets and elevated GITHUB_TOKEN... NVD: No approval gate exists.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260726T221942Z/items/CVE-2026-44359.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes code execution review · command injection risk. Possible impact: An attacker may be able to run code or commands on affected systems.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Meshtastic is an open source mesh networking solution. NVD: Prior to version 2.7.21.1370b23, the Meshtastic GitHub repository's main_matrix.yml workflow is triggered by pull_request_target and multiple jobs check out the attacker's fork code and execute it with access to repository secrets and elevated GITHUB_TOKEN... NVD: No approval gate exists.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-44359/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "trustedfirmware / op-tee",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-44362/",
      "current_public_safe_latest": false,
      "cvss_score": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.02358,
      "epss_score": 0.00122,
      "first_observed_at": "2026-07-13T17:24:46.617207+00:00",
      "id": "CVE-2026-44362",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-13T17:24:46.617207+00:00",
      "latest_item_url": null,
      "product": "op-tee",
      "public_safe_summary": "NVD: OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone technology. NVD: Starting in version 3.20.0 and prior to version 4.11.0, a vulnerability in OP-TEE’s subkey rollback protection allows the use of revoked or older subkey versions because the system fails to propagate versioning data during the Trusted Application (TA) loading... NVD: In core/crypto/signed_hdr.c, the function shdr_load_pub_key() parses subkey headers but does not assign the subkey_version to the runtime shdr_pub_key structure.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260713T172750Z/items/CVE-2026-44362.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: trustedfirmware / op-tee",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone technology. NVD: Starting in version 3.20.0 and prior to version 4.11.0, a vulnerability in OP-TEE’s subkey rollback protection allows the use of revoked or older subkey versions because the system fails to propagate versioning data during the Trusted Application (TA) loading... NVD: In core/crypto/signed_hdr.c, the function shdr_load_pub_key() parses subkey headers but does not assign the subkey_version to the runtime shdr_pub_key structure.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-44362/timeline.json",
      "vendor": "trustedfirmware"
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-44433/",
      "current_public_safe_latest": false,
      "cvss_score": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.16057,
      "epss_score": 0.00247,
      "first_observed_at": "2026-07-23T22:18:14.498937+00:00",
      "id": "CVE-2026-44433",
      "impact_tags": [
        "service availability review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-23T22:18:14.498937+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Quicly is an IETF QUIC protocol implementation intended primarily for use within the H2O HTTP server. NVD: Prior to commit 8b178e6, an adversarial peer could send a STREAM frame carrying just one byte at the largest offset being permitted to obtain additional flow control credit, which under certain circumstances could lead to a Denial of Service. NVD: Assuming the application prepares a receive buffer for storing all data that arrive out-of-order, up to the largest offset being received, this behavior could lead to the application allocating large amount of memory with the peer sending only a handful of...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260723T222557Z/items/CVE-2026-44433.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes service availability risk. Possible impact: The affected service may become unavailable or unreliable.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Quicly is an IETF QUIC protocol implementation intended primarily for use within the H2O HTTP server. NVD: Prior to commit 8b178e6, an adversarial peer could send a STREAM frame carrying just one byte at the largest offset being permitted to obtain additional flow control credit, which under certain circumstances could lead to a Denial of Service. NVD: Assuming the application prepares a receive buffer for storing all data that arrive out-of-order, up to the largest offset being received, this behavior could lead to the application allocating large amount of memory with the peer sending only a handful of...",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-44433/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-44434/",
      "current_public_safe_latest": false,
      "cvss_score": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.04412,
      "epss_score": 0.00147,
      "first_observed_at": "2026-07-23T22:18:14.498937+00:00",
      "id": "CVE-2026-44434",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-23T22:18:14.498937+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Quicly is an IETF QUIC protocol implementation intended primarily for use within the H2O HTTP server. NVD: Prior to commit dccf5d4, Quicly was vulnerable to stateless reset injection through lack of packet entry validation. NVD: The QUIC protocol is designed to withstand packet injection attacks, once the handshake is complete.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260723T222557Z/items/CVE-2026-44434.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Quicly is an IETF QUIC protocol implementation intended primarily for use within the H2O HTTP server. NVD: Prior to commit dccf5d4, Quicly was vulnerable to stateless reset injection through lack of packet entry validation. NVD: The QUIC protocol is designed to withstand packet injection attacks, once the handshake is complete.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-44434/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-44435/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.20002,
      "epss_score": 0.00278,
      "first_observed_at": "2026-07-23T22:18:14.498937+00:00",
      "id": "CVE-2026-44435",
      "impact_tags": [
        "service availability review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-23T22:18:14.498937+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Quicly is an IETF QUIC protocol implementation intended primarily for use within the H2O HTTP server. NVD: Prior to commit 937d0e9, an assertion failure is raised when the total number of valid handshake messages received over a CRYPTO stream of a single packet number space exceeds 32KB, causing a Denial of Service. NVD: This issue has been fixed by commit 937d0e9.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260723T222557Z/items/CVE-2026-44435.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes service availability risk. Possible impact: The affected service may become unavailable or unreliable.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Quicly is an IETF QUIC protocol implementation intended primarily for use within the H2O HTTP server. NVD: Prior to commit 937d0e9, an assertion failure is raised when the total number of valid handshake messages received over a CRYPTO stream of a single packet number space exceeds 32KB, causing a Denial of Service. NVD: This issue has been fixed by commit 937d0e9.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-44435/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "h2o / quicly",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-44436/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.20003,
      "epss_score": 0.00278,
      "first_observed_at": "2026-07-23T22:18:14.498937+00:00",
      "id": "CVE-2026-44436",
      "impact_tags": [
        "service availability review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-23T22:18:14.498937+00:00",
      "latest_item_url": null,
      "product": "quicly",
      "public_safe_summary": "NVD: Quicly is an IETF QUIC protocol implementation intended primarily for use within the H2O HTTP server. NVD: Prior to commit 8b178e6, Quicly is vulnerable to a Denial of Service attack through connection state corruption. NVD: In QUIC Invariants, the maximum length of a Connection ID is 255 bytes, while QUIC version 1 further restricts the maximum to 20 bytes.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260723T222557Z/items/CVE-2026-44436.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: h2o / quicly",
      "source_published_impact": "Source describes service availability risk. Possible impact: The affected service may become unavailable or unreliable.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Quicly is an IETF QUIC protocol implementation intended primarily for use within the H2O HTTP server. NVD: Prior to commit 8b178e6, Quicly is vulnerable to a Denial of Service attack through connection state corruption. NVD: In QUIC Invariants, the maximum length of a Connection ID is 255 bytes, while QUIC version 1 further restricts the maximum to 20 bytes.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-44436/timeline.json",
      "vendor": "h2o"
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-44452/",
      "current_public_safe_latest": false,
      "cvss_score": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.16432,
      "epss_score": 0.0025,
      "first_observed_at": "2026-07-23T22:18:14.498937+00:00",
      "id": "CVE-2026-44452",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-23T22:18:14.498937+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: h2o is an HTTP server with support for HTTP/1.x, HTTP/2 and HTTP/3. NVD: Prior to commit 8dc37cb, when h2o receives a ClientHello message over TLS or QUIC and it contains a zero-length SNI extension, the h2o server runs over the zero-length hostname while trying to copy the hostname, assuming that it is NULL-terminated. NVD: This is a potential denial-of-service attack vector in sense that it might trigger segmentation violation.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260723T222557Z/items/CVE-2026-44452.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: h2o is an HTTP server with support for HTTP/1.x, HTTP/2 and HTTP/3. NVD: Prior to commit 8dc37cb, when h2o receives a ClientHello message over TLS or QUIC and it contains a zero-length SNI extension, the h2o server runs over the zero-length hostname while trying to copy the hostname, assuming that it is NULL-terminated. NVD: This is a potential denial-of-service attack vector in sense that it might trigger segmentation violation.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-44452/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-44453/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.20001,
      "epss_score": 0.00278,
      "first_observed_at": "2026-07-23T22:18:14.498937+00:00",
      "id": "CVE-2026-44453",
      "impact_tags": [
        "service availability review",
        "memory safety review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-23T22:18:14.498937+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: h2o is an HTTP server with support for HTTP/1.x, HTTP/2 and HTTP/3. NVD: Prior to commit 6b5370d, h2o is vulnerable to a Denial of Service attack when calling alloca under certain conditions. NVD: When serving static files, h2o builds the file path on stack, by calling alloca.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260723T222557Z/items/CVE-2026-44453.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes service availability risk · memory safety review. Possible impact: The affected service may become unavailable or unreliable.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: h2o is an HTTP server with support for HTTP/1.x, HTTP/2 and HTTP/3. NVD: Prior to commit 6b5370d, h2o is vulnerable to a Denial of Service attack when calling alloca under certain conditions. NVD: When serving static files, h2o builds the file path on stack, by calling alloca.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-44453/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "spaceapplications / yamcs",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-44595/",
      "current_public_safe_latest": false,
      "cvss_score": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.59418,
      "epss_score": 0.01008,
      "first_observed_at": "2026-07-23T16:53:12.033252+00:00",
      "id": "CVE-2026-44595",
      "impact_tags": [
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-23T16:53:12.033252+00:00",
      "latest_item_url": null,
      "product": "yamcs",
      "public_safe_summary": "NVD: Yamcs is a mission control framework. NVD: Prior to 5.12.7, the IAM API endpoints listUsers, getUser, listGroups, and getGroup in yamcs-core did not enforce the required SystemPrivilege.ControlAccess check in yamcs-core/src/main/java/org/yamcs/http/api/IamApi.java, so any authenticated user, even one... NVD: This issue is fixed in versions 5.12.7 and 5.13.0.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260723T171217Z/items/CVE-2026-44595.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: spaceapplications / yamcs",
      "source_published_impact": "Source describes authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: versions.",
      "source_published_summary": "NVD: Yamcs is a mission control framework. NVD: Prior to 5.12.7, the IAM API endpoints listUsers, getUser, listGroups, and getGroup in yamcs-core did not enforce the required SystemPrivilege.ControlAccess check in yamcs-core/src/main/java/org/yamcs/http/api/IamApi.java, so any authenticated user, even one... NVD: This issue is fixed in versions 5.12.7 and 5.13.0.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-44595/timeline.json",
      "vendor": "spaceapplications"
    },
    {
      "affected_label": "spaceapplications / yamcs",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-44596/",
      "current_public_safe_latest": false,
      "cvss_score": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.75811,
      "epss_score": 0.0177,
      "first_observed_at": "2026-07-23T16:53:12.033252+00:00",
      "id": "CVE-2026-44596",
      "impact_tags": [
        "remote exposure relevant"
      ],
      "kev": false,
      "last_observed_at": "2026-07-23T16:53:12.033252+00:00",
      "latest_item_url": null,
      "product": "yamcs",
      "public_safe_summary": "NVD: Yamcs is a mission control framework. NVD: Prior to 5.12.7, the authentication endpoint POST /auth/token in yamcs-core, handled by yamcs-core/src/main/java/org/yamcs/http/auth/AuthHandler.java, lacked any rate limiting, account lockout, or failed-attempt throttling, so an unauthenticated remote... NVD: This issue is fixed in versions 5.12.7 and 5.13.0.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260723T171217Z/items/CVE-2026-44596.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: spaceapplications / yamcs",
      "source_published_impact": "Source describes remote exposure. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: versions.",
      "source_published_summary": "NVD: Yamcs is a mission control framework. NVD: Prior to 5.12.7, the authentication endpoint POST /auth/token in yamcs-core, handled by yamcs-core/src/main/java/org/yamcs/http/auth/AuthHandler.java, lacked any rate limiting, account lockout, or failed-attempt throttling, so an unauthenticated remote... NVD: This issue is fixed in versions 5.12.7 and 5.13.0.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-44596/timeline.json",
      "vendor": "spaceapplications"
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-44615/",
      "current_public_safe_latest": false,
      "cvss_score": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.40178,
      "epss_score": 0.00501,
      "first_observed_at": "2026-08-07T10:13:53.604723+00:00",
      "id": "CVE-2026-44615",
      "impact_tags": [
        "path traversal review",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-07T10:13:53.604723+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Path traversal vulnerability in Apache Zeppelin. NVD: When FileSystemNotebookRepo is configured, an authenticated attacker with permission to rename a note, or access to folder operations, could supply traversal segments in note or folder paths. NVD: Zeppelin composed these values into filesystem paths using the server's filesystem or Hadoop identity without ensuring that the result remained under the configured notebook directory.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260807T102646Z/items/CVE-2026-44615.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes path traversal review · authenticated boundary. Possible impact: An attacker may be able to reach files outside the intended application path.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: Path traversal vulnerability in Apache Zeppelin. NVD: When FileSystemNotebookRepo is configured, an authenticated attacker with permission to rename a note, or access to folder operations, could supply traversal segments in note or folder paths. NVD: Zeppelin composed these values into filesystem paths using the server's filesystem or Hadoop identity without ensuring that the result remained under the configured notebook directory.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-44615/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "spaceapplications / yamcs",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-44632/",
      "current_public_safe_latest": false,
      "cvss_score": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.57253,
      "epss_score": 0.0094,
      "first_observed_at": "2026-07-23T16:53:12.033252+00:00",
      "id": "CVE-2026-44632",
      "impact_tags": [
        "code execution review",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-23T16:53:12.033252+00:00",
      "latest_item_url": null,
      "product": "yamcs",
      "public_safe_summary": "NVD: Yamcs is a mission control framework. NVD: Prior to 5.12.7, a server-side code injection vulnerability existed in the Yamcs algorithm evaluation engine org.yamcs.algorithms.JavaExprAlgorithmExecutionFactory, which dynamically compiled and evaluated user-controlled algorithm text through the Janino... NVD: This issue is fixed in versions 5.12.7 and 5.13.0, which disable algorithm editing by default.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260723T171217Z/items/CVE-2026-44632.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: spaceapplications / yamcs",
      "source_published_impact": "Source describes code execution review · authenticated boundary. Possible impact: An attacker may be able to run code or commands on affected systems.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: versions.",
      "source_published_summary": "NVD: Yamcs is a mission control framework. NVD: Prior to 5.12.7, a server-side code injection vulnerability existed in the Yamcs algorithm evaluation engine org.yamcs.algorithms.JavaExprAlgorithmExecutionFactory, which dynamically compiled and evaluated user-controlled algorithm text through the Janino... NVD: This issue is fixed in versions 5.12.7 and 5.13.0, which disable algorithm editing by default.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-44632/timeline.json",
      "vendor": "spaceapplications"
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-44722/",
      "current_public_safe_latest": false,
      "cvss_score": 6.2,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.00462,
      "epss_score": 0.00087,
      "first_observed_at": "2026-07-24T16:59:54.170943+00:00",
      "id": "CVE-2026-44722",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-24T16:59:54.170943+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: pyzipper is a replacement for Python's zipfile that can read and write AES encrypted zip files. NVD: Prior to 0.4.0, a Python operator precedence bug in pyzipper/zipfile_aes.py caused the AE-2 format to never be automatically selected during encryption, causing encrypted entries to be written in AE-1 format and exposing the plaintext CRC32 checksum in the... NVD: This issue is fixed in version 0.4.0.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260724T170351Z/items/CVE-2026-44722.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: pyzipper is a replacement for Python's zipfile that can read and write AES encrypted zip files. NVD: Prior to 0.4.0, a Python operator precedence bug in pyzipper/zipfile_aes.py caused the AE-2 format to never be automatically selected during encryption, causing encrypted entries to be written in AE-1 format and exposing the plaintext CRC32 checksum in the... NVD: This issue is fixed in version 0.4.0.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-44722/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-44907/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.25401,
      "epss_score": 0.00329,
      "first_observed_at": "2026-07-28T16:54:01.667207+00:00",
      "id": "CVE-2026-44907",
      "impact_tags": [
        "service availability review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-28T16:54:01.667207+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A denial of service vulnerability could be triggered by sending specially crafted HTTP requests to server function endpoints, this could lead to excessive CPU usage; affecting the following packages: react-server-dom-webpack, react-server-dom-parcel... OSV: A denial of service vulnerability could be triggered by sending specially crafted HTTP requests to server function endpoints, this could lead to excessive CPU usage; affecting the following packages: react-server-dom-webpack, react-server-dom-parcel...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260728T170314Z/items/CVE-2026-44907.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes service availability risk. Possible impact: The affected service may become unavailable or unreliable.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A denial of service vulnerability could be triggered by sending specially crafted HTTP requests to server function endpoints, this could lead to excessive CPU usage; affecting the following packages: react-server-dom-webpack, react-server-dom-parcel... OSV: A denial of service vulnerability could be triggered by sending specially crafted HTTP requests to server function endpoints, this could lead to excessive CPU usage; affecting the following packages: react-server-dom-webpack, react-server-dom-parcel...",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-44907/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-44938/",
      "current_public_safe_latest": false,
      "cvss_score": 8.8,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.39828,
      "epss_score": 0.00508,
      "first_observed_at": "2026-07-14T10:57:43.777280+00:00",
      "id": "CVE-2026-44938",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-14T10:57:43.777280+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A vulnerability has been identified in Fleet's agent-side deployer, which did not filter security-sensitive keys from namespaceLabels in fleet.yaml (or BundleDeployment.spec.options.namespaceLabels) when applying them to the target namespace. NVD: An attacker with git push access to a Fleet-monitored repository could overwrite Pod Security Standards (PSS) enforcement labels on a target namespace. NVD: This allows the attacker to weaken admission controls and deploy workloads that PSS policies would otherwise block.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260714T110007Z/items/CVE-2026-44938.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability has been identified in Fleet's agent-side deployer, which did not filter security-sensitive keys from namespaceLabels in fleet.yaml (or BundleDeployment.spec.options.namespaceLabels) when applying them to the target namespace. NVD: An attacker with git push access to a Fleet-monitored repository could overwrite Pod Security Standards (PSS) enforcement labels on a target namespace. NVD: This allows the attacker to weaken admission controls and deploy workloads that PSS policies would otherwise block.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-44938/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-44943/",
      "current_public_safe_latest": false,
      "cvss_score": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.25549,
      "epss_score": 0.0033,
      "first_observed_at": "2026-08-05T11:32:09.387600+00:00",
      "id": "CVE-2026-44943",
      "impact_tags": [
        "admin privilege risk",
        "path traversal review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-05T11:32:09.387600+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in open-iscsi allows remote MITM attackers to create root-owned files outside the database and inject lines into the record. NVD: This issue affects open-iscsi: from through 668ca1df9c9a1e9bdd5c999ae1d67c9c8909237e. OSV: remote limited file-write as root via discovery in open-iscsi",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260805T113552Z/items/CVE-2026-44943.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes admin privilege risk · path traversal review. Possible impact: An attacker may gain root or administrative-level privileges on affected systems.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in open-iscsi allows remote MITM attackers to create root-owned files outside the database and inject lines into the record. NVD: This issue affects open-iscsi: from through 668ca1df9c9a1e9bdd5c999ae1d67c9c8909237e. OSV: remote limited file-write as root via discovery in open-iscsi",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-44943/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-44944/",
      "current_public_safe_latest": false,
      "cvss_score": 8.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.00653,
      "epss_score": 0.00093,
      "first_observed_at": "2026-08-05T11:32:09.387600+00:00",
      "id": "CVE-2026-44944",
      "impact_tags": [
        "authentication boundary review",
        "local exposure relevant"
      ],
      "kev": false,
      "last_observed_at": "2026-08-05T11:32:09.387600+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: An Incorrect Authorization vulnerability in open-iscsi allows unprivilidged local users to use the isscsiuio control socket. NVD: This issue affects open-iscsi: from ? NVD: through 668ca1df9c9a1e9bdd5c999ae1d67c9c8909237e.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260805T113552Z/items/CVE-2026-44944.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes authentication boundary review · local exposure. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authentication boundary review · local exposure.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: An Incorrect Authorization vulnerability in open-iscsi allows unprivilidged local users to use the isscsiuio control socket. NVD: This issue affects open-iscsi: from ? NVD: through 668ca1df9c9a1e9bdd5c999ae1d67c9c8909237e.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-44944/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-44955/",
      "current_public_safe_latest": false,
      "cvss_score": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.10871,
      "epss_score": 0.00206,
      "first_observed_at": "2026-07-30T22:30:38.166118+00:00",
      "id": "CVE-2026-44955",
      "impact_tags": [
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-30T22:30:38.166118+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Pronetiqs IntraVUE versions 3.2.1a14 and prior have an exposure of sensitive system information to an unauthorized control sphere vulnerability which could allow for asset discovery by unauthenticated users.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260730T224832Z/items/CVE-2026-44955.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Pronetiqs IntraVUE versions 3.2.1a14 and prior have an exposure of sensitive system information to an unauthorized control sphere vulnerability which could allow for asset discovery by unauthenticated users.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-44955/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-45084/",
      "current_public_safe_latest": false,
      "cvss_score": 8.7,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.37984,
      "epss_score": 0.00464,
      "first_observed_at": "2026-08-11T22:08:35.096641+00:00",
      "id": "CVE-2026-45084",
      "impact_tags": [
        "service availability review",
        "remote exposure relevant"
      ],
      "kev": false,
      "last_observed_at": "2026-08-11T22:08:35.096641+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: OpenSIPS is a Session Initiation Protocol (SIP) server implementation. NVD: Versions 3.4.0 through 3.6.5 contain a denial of service vulnerability in the presence module. NVD: When the presence module's handle_publish() function processes a SIP PUBLISH request with an Event: presence header and a message body while the configuration option enable_sphere_check=1 is set, it invokes the get_content_type() macro without first calling...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260811T221806Z/items/CVE-2026-45084.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes service availability risk · remote exposure. Possible impact: The affected service may become unavailable or unreliable.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: OpenSIPS is a Session Initiation Protocol (SIP) server implementation. NVD: Versions 3.4.0 through 3.6.5 contain a denial of service vulnerability in the presence module. NVD: When the presence module's handle_publish() function processes a SIP PUBLISH request with an Event: presence header and a message body while the configuration option enable_sphere_check=1 is set, it invokes the get_content_type() macro without first calling...",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-45084/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-45086/",
      "current_public_safe_latest": false,
      "cvss_score": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.06755,
      "epss_score": 0.00171,
      "first_observed_at": "2026-08-07T21:58:42.606809+00:00",
      "id": "CVE-2026-45086",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-07T21:58:42.606809+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Decidim is a participatory democracy framework. NVD: From 0.31.1 before 0.31.5 and in 0.32.0.rc1 before 0.32.0.rc2, a participant can directly load /admin/demographics/questions/edit_questions and reach the demographics questionnaire editor without the required administrator authorization. NVD: The demographics questionnaire editor should require admin access, but the route under /admin/demographics/questions renders the editor interface without checking whether the caller is an admin.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260807T220457Z/items/CVE-2026-45086.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: versions.",
      "source_published_summary": "NVD: Decidim is a participatory democracy framework. NVD: From 0.31.1 before 0.31.5 and in 0.32.0.rc1 before 0.32.0.rc2, a participant can directly load /admin/demographics/questions/edit_questions and reach the demographics questionnaire editor without the required administrator authorization. NVD: The demographics questionnaire editor should require admin access, but the route under /admin/demographics/questions renders the editor interface without checking whether the caller is an admin.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-45086/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-45100/",
      "current_public_safe_latest": false,
      "cvss_score": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.44943,
      "epss_score": 0.00587,
      "first_observed_at": "2026-08-11T22:08:35.096641+00:00",
      "id": "CVE-2026-45100",
      "impact_tags": [
        "memory safety review",
        "remote exposure relevant"
      ],
      "kev": false,
      "last_observed_at": "2026-08-11T22:08:35.096641+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: OpenSIPS is a Session Initiation Protocol (SIP) server implementation. NVD: Versions 3.4.0-beta through 3.6.5 and 4.0.0-beta contain a buffer overflow in the {s.b64encode} string transformation. NVD: The size check for {s.b64encode} only verifies that the input fits within the 64 KB transformation buffer, but base64 encoding expands the data by roughly a third, so an input between about 49,153 and 65,535 bytes produces more output than the buffer can hold...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260811T221806Z/items/CVE-2026-45100.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes memory safety review · remote exposure. Possible impact: The affected component has memory-safety risk that may lead to crash, privilege, or code-execution impact depending on exposure.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: versions.",
      "source_published_summary": "NVD: OpenSIPS is a Session Initiation Protocol (SIP) server implementation. NVD: Versions 3.4.0-beta through 3.6.5 and 4.0.0-beta contain a buffer overflow in the {s.b64encode} string transformation. NVD: The size check for {s.b64encode} only verifies that the input fits within the 64 KB transformation buffer, but base64 encoding expands the data by roughly a third, so an input between about 49,153 and 65,535 bytes produces more output than the buffer can hold...",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-45100/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-45103/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.25394,
      "epss_score": 0.00328,
      "first_observed_at": "2026-08-11T22:08:35.096641+00:00",
      "id": "CVE-2026-45103",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-11T22:08:35.096641+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: OpenSIPS is a Session Initiation Protocol (SIP) server implementation. NVD: In versions prior to 3.6.6 and 4.0.0-rc1, the TCP message framing layer parses the Content-Length header using unsigned int arithmetic with no overflow check. NVD: When an attacker sends a Content-Length value that overflows unsigned int (e.g., 4294967296), the framing layer computes a wrapped-around value (e.g., 0) and splits the TCP stream at the wrong boundary, causing the body of the first SIP message to be...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260811T221806Z/items/CVE-2026-45103.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: versions.",
      "source_published_summary": "NVD: OpenSIPS is a Session Initiation Protocol (SIP) server implementation. NVD: In versions prior to 3.6.6 and 4.0.0-rc1, the TCP message framing layer parses the Content-Length header using unsigned int arithmetic with no overflow check. NVD: When an attacker sends a Content-Length value that overflows unsigned int (e.g., 4294967296), the framing layer computes a wrapped-around value (e.g., 0) and splits the TCP stream at the wrong boundary, causing the body of the first SIP message to be...",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-45103/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-45138/",
      "current_public_safe_latest": false,
      "cvss_score": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.04317,
      "epss_score": 0.00146,
      "first_observed_at": "2026-07-26T22:15:56.881440+00:00",
      "id": "CVE-2026-45138",
      "impact_tags": [
        "XSS risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-26T22:15:56.881440+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: CI4MS is a CodeIgniter 4-based content management system skeleton. NVD: Prior to version 0.31.9.0, the custom html_purify validation rule used to sanitize blog post bodies relies on by-reference mutation (?string &$str), but CodeIgniter 4's validator passes a local copy of the value, so the sanitized text is silently discarded. NVD: The Blog controller writes $lanData['content'] directly into blog_langs.content, and the public template echoes it without escaping — yielding stored XSS executable in any visitor's browser, including the superadmin when previewing or editing posts.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260726T221942Z/items/CVE-2026-45138.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes XSS risk. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: CI4MS is a CodeIgniter 4-based content management system skeleton. NVD: Prior to version 0.31.9.0, the custom html_purify validation rule used to sanitize blog post bodies relies on by-reference mutation (?string &$str), but CodeIgniter 4's validator passes a local copy of the value, so the sanitized text is silently discarded. NVD: The Blog controller writes $lanData['content'] directly into blog_langs.content, and the public template echoes it without escaping — yielding stored XSS executable in any visitor's browser, including the superadmin when previewing or editing posts.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-45138/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-45139/",
      "current_public_safe_latest": false,
      "cvss_score": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.18652,
      "epss_score": 0.00267,
      "first_observed_at": "2026-07-27T12:38:45.912501+00:00",
      "id": "CVE-2026-45139",
      "impact_tags": [
        "service availability review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-27T12:38:45.912501+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: CI4MS is a CodeIgniter 4-based content management system skeleton. NVD: Prior to version 0.31.9.0, the Fileeditor module enforces an extension allowlist (['css','js','html','txt','json','sql','md']) on content-write operations (saveFile, createFile), but two destructive endpoints — deleteFileOrFolder and renameFile — never... NVD: A backend user with file-editor permissions can therefore unlink or rename any file inside the project root that is not explicitly listed in the small $hiddenItems blocklist.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260727T124133Z/items/CVE-2026-45139.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes service availability risk. Possible impact: The affected service may become unavailable or unreliable.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: CI4MS is a CodeIgniter 4-based content management system skeleton. NVD: Prior to version 0.31.9.0, the Fileeditor module enforces an extension allowlist (['css','js','html','txt','json','sql','md']) on content-write operations (saveFile, createFile), but two destructive endpoints — deleteFileOrFolder and renameFile — never... NVD: A backend user with file-editor permissions can therefore unlink or rename any file inside the project root that is not explicitly listed in the small $hiddenItems blocklist.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-45139/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-45270/",
      "current_public_safe_latest": false,
      "cvss_score": 8.7,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.10971,
      "epss_score": 0.00207,
      "first_observed_at": "2026-07-27T12:38:45.912501+00:00",
      "id": "CVE-2026-45270",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-27T12:38:45.912501+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: CI4MS is a CodeIgniter 4-based content management system skeleton. NVD: Prior to version 0.31.9.0, the Pages backend module registers the html_purify validation rule on language-keyed page content but persists the raw, un-purified POST value into the database. NVD: The public renderer for pages (Home::index() → app/Views/templates/default/pages.php) emits $pageInfo->content without esc(), yielding stored XSS that fires for every public visitor of the affected page — including administrators.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260727T124133Z/items/CVE-2026-45270.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: CI4MS is a CodeIgniter 4-based content management system skeleton. NVD: Prior to version 0.31.9.0, the Pages backend module registers the html_purify validation rule on language-keyed page content but persists the raw, un-purified POST value into the database. NVD: The public renderer for pages (Home::index() → app/Views/templates/default/pages.php) emits $pageInfo->content without esc(), yielding stored XSS that fires for every public visitor of the affected page — including administrators.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-45270/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-45325/",
      "current_public_safe_latest": false,
      "cvss_score": 8.2,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.18571,
      "epss_score": 0.00267,
      "first_observed_at": "2026-07-23T16:53:12.033252+00:00",
      "id": "CVE-2026-45325",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-23T16:53:12.033252+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Gestor de Oferta is a web application for managing mobility service offerings. NVD: Prior to 20260509.0340.15, @tmlmobilidade/utils has a prototype pollution vulnerability in setValueAtPath() in packages/utils/src/generic/value-at-path.ts because unsafe path segments are not blocked. NVD: This issue is fixed in version 20260509.0340.15.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260723T171217Z/items/CVE-2026-45325.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: Gestor de Oferta is a web application for managing mobility service offerings. NVD: Prior to 20260509.0340.15, @tmlmobilidade/utils has a prototype pollution vulnerability in setValueAtPath() in packages/utils/src/generic/value-at-path.ts because unsafe path segments are not blocked. NVD: This issue is fixed in version 20260509.0340.15.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-45325/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-45330/",
      "current_public_safe_latest": false,
      "cvss_score": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.20071,
      "epss_score": 0.00279,
      "first_observed_at": "2026-08-07T21:58:42.606809+00:00",
      "id": "CVE-2026-45330",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-07T21:58:42.606809+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Decidim is a participatory democracy framework. NVD: Prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0.32.0.rc1 before 0.32.0.rc2, the identity-document verification admin controllers load pending Authorization records by raw identifier without confirming current_organization ownership, allowing an... NVD: This issue is fixed in versions 0.30.9, 0.31.5, and 0.32.0.rc2.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260807T220457Z/items/CVE-2026-45330.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: versions.",
      "source_published_summary": "NVD: Decidim is a participatory democracy framework. NVD: Prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0.32.0.rc1 before 0.32.0.rc2, the identity-document verification admin controllers load pending Authorization records by raw identifier without confirming current_organization ownership, allowing an... NVD: This issue is fixed in versions 0.30.9, 0.31.5, and 0.32.0.rc2.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-45330/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-45363/",
      "current_public_safe_latest": false,
      "cvss_score": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.15354,
      "epss_score": 0.00242,
      "first_observed_at": "2026-07-21T22:14:32.860584+00:00",
      "id": "CVE-2026-45363",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-21T22:14:32.860584+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: ruby-jwt is a Ruby implementation of the RFC 7519 OAuth JSON Web Token standard. NVD: The same path is reached when a keyfinder block or key_finder: argument returns an empty string, nil, or an array containing nil for an unknown key, affecting HS256, HS384, and HS512 verification through JWT.decode and JWT::EncodedToken#verify_signature!. NVD: This issue is fixed in versions 2.10.3 and 3.2.0.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260721T221655Z/items/CVE-2026-45363.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: versions.",
      "source_published_summary": "NVD: ruby-jwt is a Ruby implementation of the RFC 7519 OAuth JSON Web Token standard. NVD: The same path is reached when a keyfinder block or key_finder: argument returns an empty string, nil, or an array containing nil for an unknown key, affecting HS256, HS384, and HS512 verification through JWT.decode and JWT::EncodedToken#verify_signature!. NVD: This issue is fixed in versions 2.10.3 and 3.2.0.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-45363/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-45367/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.39163,
      "epss_score": 0.00489,
      "first_observed_at": "2026-07-23T16:53:12.033252+00:00",
      "id": "CVE-2026-45367",
      "impact_tags": [
        "service availability review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-23T16:53:12.033252+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. NVD: Prior to 6.9.7, the FHIRPathEngine implementation passes user-controlled regular expressions from matches(), matchesFull(), and replaceMatches() to Java regex operations without effective timeouts, allowing catastrophic backtracking and denial of service. NVD: This issue is fixed in version 6.9.7.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260723T171217Z/items/CVE-2026-45367.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes service availability risk. Possible impact: The affected service may become unavailable or unreliable.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. NVD: Prior to 6.9.7, the FHIRPathEngine implementation passes user-controlled regular expressions from matches(), matchesFull(), and replaceMatches() to Java regex operations without effective timeouts, allowing catastrophic backtracking and denial of service. NVD: This issue is fixed in version 6.9.7.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-45367/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-45376/",
      "current_public_safe_latest": false,
      "cvss_score": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.26807,
      "epss_score": 0.00341,
      "first_observed_at": "2026-08-07T21:58:42.606809+00:00",
      "id": "CVE-2026-45376",
      "impact_tags": [
        "SQL injection risk"
      ],
      "kev": false,
      "last_observed_at": "2026-08-07T21:58:42.606809+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Decidim is a participatory democracy framework. NVD: Prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0.32.0.rc1 before 0.32.0.rc2, the GET /admin/organization/users search interpolates params[:term] into raw Arel.sql ORDER BY similarity expressions before sanitization, allowing an authenticated organization... NVD: This issue is fixed in versions 0.30.9, 0.31.5, and 0.32.0.rc2.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260807T220457Z/items/CVE-2026-45376.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes SQL injection risk. Possible impact: An attacker may be able to read or change database-backed application data.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: versions.",
      "source_published_summary": "NVD: Decidim is a participatory democracy framework. NVD: Prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0.32.0.rc1 before 0.32.0.rc2, the GET /admin/organization/users search interpolates params[:term] into raw Arel.sql ORDER BY similarity expressions before sanitization, allowing an authenticated organization... NVD: This issue is fixed in versions 0.30.9, 0.31.5, and 0.32.0.rc2.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-45376/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-45377/",
      "current_public_safe_latest": false,
      "cvss_score": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.19504,
      "epss_score": 0.00274,
      "first_observed_at": "2026-08-07T21:58:42.606809+00:00",
      "id": "CVE-2026-45377",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-07T21:58:42.606809+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Decidim is a participatory democracy framework. NVD: Prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0.32.0.rc1 before 0.32.0.rc2, the normal download_your_data flow requires the requester to be logged in as the export owner, but the resulting Active Storage blob redirect URL can be replayed without... NVD: This is because Decidim::DownloadYourDataController#download_file authenticates the export owner but redirects to a signed Active Storage blob URL that is no longer bound to the owner session.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260807T220457Z/items/CVE-2026-45377.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: versions.",
      "source_published_summary": "NVD: Decidim is a participatory democracy framework. NVD: Prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0.32.0.rc1 before 0.32.0.rc2, the normal download_your_data flow requires the requester to be logged in as the export owner, but the resulting Active Storage blob redirect URL can be replayed without... NVD: This is because Decidim::DownloadYourDataController#download_file authenticates the export owner but redirects to a signed Active Storage blob URL that is no longer bound to the owner session.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-45377/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "microsoft / azure_openai",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-45499/",
      "current_public_safe_latest": false,
      "cvss_score": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.44884,
      "epss_score": 0.00608,
      "first_observed_at": "2026-07-09T22:45:10.548837+00:00",
      "id": "CVE-2026-45499",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-09T22:45:10.548837+00:00",
      "latest_item_url": null,
      "product": "azure_openai",
      "public_safe_summary": "NVD: Server-side request forgery (ssrf) in Azure OpenAI allows an authorized attacker to elevate privileges over a network.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260709T224554Z/items/CVE-2026-45499.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: microsoft / azure_openai; affected version context: -",
      "source_published_impact": "This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Server-side request forgery (ssrf) in Azure OpenAI allows an authorized attacker to elevate privileges over a network.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-45499/timeline.json",
      "vendor": "microsoft"
    },
    {
      "affected_label": "netfoundry / zrok",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-45568/",
      "current_public_safe_latest": false,
      "cvss_score": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.2856,
      "epss_score": 0.00361,
      "first_observed_at": "2026-07-23T16:53:12.033252+00:00",
      "id": "CVE-2026-45568",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-23T16:53:12.033252+00:00",
      "latest_item_url": null,
      "product": "zrok",
      "public_safe_summary": "NVD: zrok is software for sharing web services, files, and network resources. NVD: Prior to 2.0.3, zrok's Python SDK ProxyShare Flask proxy route accepts an absolute URL in the request path and passes it to urllib.parse.urljoin, allowing the requested path to replace the configured target host and causing requests.request to return a... NVD: This issue is fixed in version 2.0.3.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260723T171217Z/items/CVE-2026-45568.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: netfoundry / zrok",
      "source_published_impact": "This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: zrok is software for sharing web services, files, and network resources. NVD: Prior to 2.0.3, zrok's Python SDK ProxyShare Flask proxy route accepts an absolute URL in the request path and passes it to urllib.parse.urljoin, allowing the requested path to replace the configured target host and causing requests.request to return a... NVD: This issue is fixed in version 2.0.3.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-45568/timeline.json",
      "vendor": "netfoundry"
    },
    {
      "affected_label": "netfoundry / zrok",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-45576/",
      "current_public_safe_latest": false,
      "cvss_score": 8.3,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.25724,
      "epss_score": 0.00333,
      "first_observed_at": "2026-07-23T16:53:12.033252+00:00",
      "id": "CVE-2026-45576",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-23T16:53:12.033252+00:00",
      "latest_item_url": null,
      "product": "zrok",
      "public_safe_summary": "NVD: zrok is software for sharing web services, files, and network resources. NVD: From 0.4.23 until 2.0.3, zrok2 copy stores attacker-controlled WebDAV or zrok drive paths such as /../outside.txt in the source inventory and passes them to FilesystemTarget.WriteStream, allowing the sync pipeline to write files outside the selected local... NVD: This issue is fixed in version 2.0.3.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260723T171217Z/items/CVE-2026-45576.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: netfoundry / zrok",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: zrok is software for sharing web services, files, and network resources. NVD: From 0.4.23 until 2.0.3, zrok2 copy stores attacker-controlled WebDAV or zrok drive paths such as /../outside.txt in the source inventory and passes them to FilesystemTarget.WriteStream, allowing the sync pipeline to write files outside the selected local... NVD: This issue is fixed in version 2.0.3.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-45576/timeline.json",
      "vendor": "netfoundry"
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-45612/",
      "current_public_safe_latest": false,
      "cvss_score": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.02341,
      "epss_score": 0.00122,
      "first_observed_at": "2026-07-23T16:53:12.033252+00:00",
      "id": "CVE-2026-45612",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-23T16:53:12.033252+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: rz-libdemangle is a Rizin library for demangling symbols. NVD: Prior to 6bf56d3, the Rust demangler in src/rust/rust_v0.c can perform an out-of-bounds read when the demangler structure is not yet initialized. NVD: This issue is fixed in commit 6bf56d3.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260723T171217Z/items/CVE-2026-45612.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: commit.",
      "source_published_summary": "NVD: rz-libdemangle is a Rizin library for demangling symbols. NVD: Prior to 6bf56d3, the Rust demangler in src/rust/rust_v0.c can perform an out-of-bounds read when the demangler structure is not yet initialized. NVD: This issue is fixed in commit 6bf56d3.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-45612/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-45623/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.40299,
      "epss_score": 0.00503,
      "first_observed_at": "2026-08-03T17:21:47.396014+00:00",
      "id": "CVE-2026-45623",
      "impact_tags": [
        "information exposure review",
        "service availability review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-03T17:21:47.396014+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: PostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract Syntax Tree. NVD: In versions 8.5.11 and prior, the PreviousMap parses the /*# sourceMappingURL=PATH */ comment from any CSS string passed to process() and dereferences PATH against the local filesystem with no scheme, allowlist, or traversal check. NVD: An attacker who controls the CSS input can cause the host process to read any file readable by Node and leak the first ~10 bytes of its content through the resulting JSON.parse SyntaxError message.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260803T174717Z/items/CVE-2026-45623.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes information exposure review · service availability risk. Possible impact: An attacker may be able to access information that should not be exposed.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: PostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract Syntax Tree. NVD: In versions 8.5.11 and prior, the PreviousMap parses the /*# sourceMappingURL=PATH */ comment from any CSS string passed to process() and dereferences PATH against the local filesystem with no scheme, allowlist, or traversal check. NVD: An attacker who controls the CSS input can cause the host process to read any file readable by Node and leak the first ~10 bytes of its content through the resulting JSON.parse SyntaxError message.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-45623/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-45793/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.52675,
      "epss_score": 0.00797,
      "first_observed_at": "2026-07-22T16:52:32.770874+00:00",
      "id": "CVE-2026-45793",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-22T16:52:32.770874+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Composer is a dependency Manager for the PHP language. NVD: Prior to 1.10.28, 2.2.28, and 2.9.8, Composer\\IO\\BaseIO::loadConfiguration() validates GitHub OAuth tokens with the regex ^[.A-Za-z0-9_]+$ and interpolates rejected tokens into an UnexpectedValueException; GitHub Actions GITHUB_TOKEN values using the... NVD: This issue is fixed in versions 1.10.28, 2.2.28, and 2.9.8.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260722T165509Z/items/CVE-2026-45793.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: versions.",
      "source_published_summary": "NVD: Composer is a dependency Manager for the PHP language. NVD: Prior to 1.10.28, 2.2.28, and 2.9.8, Composer\\IO\\BaseIO::loadConfiguration() validates GitHub OAuth tokens with the regex ^[.A-Za-z0-9_]+$ and interpolates rejected tokens into an UnexpectedValueException; GitHub Actions GITHUB_TOKEN values using the... NVD: This issue is fixed in versions 1.10.28, 2.2.28, and 2.9.8.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-45793/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-45795/",
      "current_public_safe_latest": false,
      "cvss_score": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.05501,
      "epss_score": 0.00159,
      "first_observed_at": "2026-07-23T16:53:12.033252+00:00",
      "id": "CVE-2026-45795",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-23T16:53:12.033252+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Janssen Project is an open-source identity and access management (IAM) platform. NVD: Prior to 2.0.0, jans-auth-server accepts unsigned JWE request objects because JwtAuthorizationRequest skips inner signature validation when jwe.getSignedJWTPayload() returns null, and AuthzRequestService.processRequestObject() does not reject the unrecognized... NVD: This issue is fixed in version 2.0.0.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260723T171217Z/items/CVE-2026-45795.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: The Janssen Project is an open-source identity and access management (IAM) platform. NVD: Prior to 2.0.0, jans-auth-server accepts unsigned JWE request objects because JwtAuthorizationRequest skips inner signature validation when jwe.getSignedJWTPayload() returns null, and AuthzRequestService.processRequestObject() does not reject the unrecognized... NVD: This issue is fixed in version 2.0.0.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-45795/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-45804/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.18692,
      "epss_score": 0.00268,
      "first_observed_at": "2026-07-22T16:52:32.770874+00:00",
      "id": "CVE-2026-45804",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-22T16:52:32.770874+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Diffusers is the a library for pretrained diffusion models. NVD: Prior to 0.38.0, Diffusers' DiffusionPipeline.from_pretrained flow can bypass the trust_remote_code guard because download() validates model_index.json and custom pipeline code before later loading from a cached folder that can change, allowing a Hub... NVD: This issue is fixed in version 0.38.0.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260722T165509Z/items/CVE-2026-45804.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: Diffusers is the a library for pretrained diffusion models. NVD: Prior to 0.38.0, Diffusers' DiffusionPipeline.from_pretrained flow can bypass the trust_remote_code guard because download() validates model_index.json and custom pipeline code before later loading from a cached folder that can change, allowing a Hub... NVD: This issue is fixed in version 0.38.0.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-45804/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "apache / nimble",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-45811/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.26857,
      "epss_score": 0.00342,
      "first_observed_at": "2026-07-31T11:36:05.167842+00:00",
      "id": "CVE-2026-45811",
      "impact_tags": [
        "memory safety review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-31T11:36:05.167842+00:00",
      "latest_item_url": null,
      "product": "nimble",
      "public_safe_summary": "NVD: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in Apache NimBLE. NVD: The HCI socket transport did not check whether a received HCI event would fit the configured event pool before copying it, allowing a buffer overflow. NVD: Severity is low: exploitation requires either a misconfigured pool size or a malicious/compromised controller on the other end of the HCI socket link, not over-the-air Bluetooth access.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260731T115001Z/items/CVE-2026-45811.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: apache / nimble",
      "source_published_impact": "Source describes memory safety review. Possible impact: The affected component has memory-safety risk that may lead to crash, privilege, or code-execution impact depending on exposure.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in Apache NimBLE. NVD: The HCI socket transport did not check whether a received HCI event would fit the configured event pool before copying it, allowing a buffer overflow. NVD: Severity is low: exploitation requires either a misconfigured pool size or a malicious/compromised controller on the other end of the HCI socket link, not over-the-air Bluetooth access.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-45811/timeline.json",
      "vendor": "apache"
    },
    {
      "affected_label": "apache / nimble",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-45812/",
      "current_public_safe_latest": false,
      "cvss_score": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.34505,
      "epss_score": 0.00419,
      "first_observed_at": "2026-07-31T11:36:05.167842+00:00",
      "id": "CVE-2026-45812",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-31T11:36:05.167842+00:00",
      "latest_item_url": null,
      "product": "nimble",
      "public_safe_summary": "NVD: Incorrect Calculation of Buffer Size vulnerability in Apache NimBLE when processing Legacy Advertising Report HCI event. NVD: When a single HCI advertising report event bundles multiple reports, NimBLE miscalculated the offset to the next report. NVD: This can cause the host to read past the end of the buffer and deliver a GAP event with bogus data to the application.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260731T115001Z/items/CVE-2026-45812.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: apache / nimble",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: Incorrect Calculation of Buffer Size vulnerability in Apache NimBLE when processing Legacy Advertising Report HCI event. NVD: When a single HCI advertising report event bundles multiple reports, NimBLE miscalculated the offset to the next report. NVD: This can cause the host to read past the end of the buffer and deliver a GAP event with bogus data to the application.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-45812/timeline.json",
      "vendor": "apache"
    },
    {
      "affected_label": "apache / nimble",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-45813/",
      "current_public_safe_latest": false,
      "cvss_score": 8.8,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.2781,
      "epss_score": 0.00351,
      "first_observed_at": "2026-07-31T11:36:05.167842+00:00",
      "id": "CVE-2026-45813",
      "impact_tags": [
        "memory safety review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-31T11:36:05.167842+00:00",
      "latest_item_url": null,
      "product": "nimble",
      "public_safe_summary": "NVD: Out-of-bounds Write, Integer Underflow (Wrap or Wraparound) vulnerability in Apache NimBLE BASS service. NVD: Improper validation when parsing BASS service \"Add Source\" and \"Modify Source\" operation PDU could results in stack buffer overflow or arbitrary out-of-bound read. NVD: This can be triggered by nearby devices over Bluetooth connection, however pairing is required prior to accessing BASS service, which depending on device configuration may or may not require user action.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260731T115001Z/items/CVE-2026-45813.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: apache / nimble",
      "source_published_impact": "Source describes memory safety review. Possible impact: The affected component has memory-safety risk that may lead to crash, privilege, or code-execution impact depending on exposure.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: Out-of-bounds Write, Integer Underflow (Wrap or Wraparound) vulnerability in Apache NimBLE BASS service. NVD: Improper validation when parsing BASS service \"Add Source\" and \"Modify Source\" operation PDU could results in stack buffer overflow or arbitrary out-of-bound read. NVD: This can be triggered by nearby devices over Bluetooth connection, however pairing is required prior to accessing BASS service, which depending on device configuration may or may not require user action.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-45813/timeline.json",
      "vendor": "apache"
    },
    {
      "affected_label": "apache / nimble",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-45815/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.4539,
      "epss_score": 0.00602,
      "first_observed_at": "2026-07-31T11:36:05.167842+00:00",
      "id": "CVE-2026-45815",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-31T11:36:05.167842+00:00",
      "latest_item_url": null,
      "product": "nimble",
      "public_safe_summary": "NVD: Reachable Assertion vulnerability in Apache NimBLE. NVD: A specially crafted ATT Read Multiple Variable Response (BLE_ATT_OP_READ_MULT_VAR_RSP) may trigger assert in ATT parser. NVD: Severity is medium as this requires DUT to first send ATT Read Multiple Variable Request.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260731T115001Z/items/CVE-2026-45815.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: apache / nimble",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: Reachable Assertion vulnerability in Apache NimBLE. NVD: A specially crafted ATT Read Multiple Variable Response (BLE_ATT_OP_READ_MULT_VAR_RSP) may trigger assert in ATT parser. NVD: Severity is medium as this requires DUT to first send ATT Read Multiple Variable Request.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-45815/timeline.json",
      "vendor": "apache"
    },
    {
      "affected_label": "apache / nimble",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-45816/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.45987,
      "epss_score": 0.00615,
      "first_observed_at": "2026-07-31T11:36:05.167842+00:00",
      "id": "CVE-2026-45816",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-31T11:36:05.167842+00:00",
      "latest_item_url": null,
      "product": "nimble",
      "public_safe_summary": "NVD: NULL Pointer Dereference vulnerability in Apache NimBLE in LE Long Term Key Request event. NVD: This requires disabled asserts (otherwise assert would trigger before NULL dereference) and bogus (or misbehaving) controller, thus severity is low. NVD: This issue affects Apache NimBLE: through 1.9.0.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260731T115001Z/items/CVE-2026-45816.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: apache / nimble",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: NULL Pointer Dereference vulnerability in Apache NimBLE in LE Long Term Key Request event. NVD: This requires disabled asserts (otherwise assert would trigger before NULL dereference) and bogus (or misbehaving) controller, thus severity is low. NVD: This issue affects Apache NimBLE: through 1.9.0.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-45816/timeline.json",
      "vendor": "apache"
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-45820/",
      "current_public_safe_latest": false,
      "cvss_score": 6.6,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.17082,
      "epss_score": 0.00255,
      "first_observed_at": "2026-07-29T06:10:00.110927+00:00",
      "id": "CVE-2026-45820",
      "impact_tags": [
        "service availability review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-29T06:10:00.110927+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: fflate through 0.8.2 is vulnerable to denial of service via an infinite loop in unzipSync(). NVD: A crafted ZIP archive with a central directory entry declaring compressed_size=0xFFFFFFFF (ZIP64 sentinel) but missing the required ZIP64 extra field tag 0x0001 causes z64e() to loop indefinitely due to out-of-bounds reads returning undefined, which coerces... OSV: fflate through 0.8.2 is vulnerable to denial of service via an infinite loop in unzipSync().",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260729T062752Z/items/CVE-2026-45820.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes service availability risk. Possible impact: The affected service may become unavailable or unreliable.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: fflate through 0.8.2 is vulnerable to denial of service via an infinite loop in unzipSync(). NVD: A crafted ZIP archive with a central directory entry declaring compressed_size=0xFFFFFFFF (ZIP64 sentinel) but missing the required ZIP64 extra field tag 0x0001 causes z64e() to loop indefinitely due to out-of-bounds reads returning undefined, which coerces... OSV: fflate through 0.8.2 is vulnerable to denial of service via an infinite loop in unzipSync().",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-45820/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-46410/",
      "current_public_safe_latest": false,
      "cvss_score": 8.7,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.17942,
      "epss_score": 0.00263,
      "first_observed_at": "2026-07-27T12:38:45.912501+00:00",
      "id": "CVE-2026-46410",
      "impact_tags": [
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-27T12:38:45.912501+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: FileBrowser Quantum is a free, self-hosted, web-based file manager. NVD: Versions prior to 1.3.2-stable and 1.4.1-beta may leak some sensitive info, such as source and path. NVD: Versions 1.3.2-stable and 1.4.1-beta fix the issue.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260727T124133Z/items/CVE-2026-46410.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes authenticated boundary. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: FileBrowser Quantum is a free, self-hosted, web-based file manager. NVD: Versions prior to 1.3.2-stable and 1.4.1-beta may leak some sensitive info, such as source and path. NVD: Versions 1.3.2-stable and 1.4.1-beta fix the issue.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-46410/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "apache / nimble",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-46452/",
      "current_public_safe_latest": false,
      "cvss_score": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.43425,
      "epss_score": 0.00561,
      "first_observed_at": "2026-07-31T11:36:05.167842+00:00",
      "id": "CVE-2026-46452",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-31T11:36:05.167842+00:00",
      "latest_item_url": null,
      "product": "nimble",
      "public_safe_summary": "NVD: Improper Input Validation vulnerability in Apache NimBLE in Mesh Proxy SAR reassembly could result in passing broken data toward application resulting in memory pressure and unstable parsing behavior. NVD: This issue affects Apache NimBLE: through 1.9.0. NVD: Users are recommended to upgrade to version 1.10.0, which fixes the issue.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260731T115001Z/items/CVE-2026-46452.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: apache / nimble",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: Improper Input Validation vulnerability in Apache NimBLE in Mesh Proxy SAR reassembly could result in passing broken data toward application resulting in memory pressure and unstable parsing behavior. NVD: This issue affects Apache NimBLE: through 1.9.0. NVD: Users are recommended to upgrade to version 1.10.0, which fixes the issue.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-46452/timeline.json",
      "vendor": "apache"
    },
    {
      "affected_label": "dell / data_domain_operating_system",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-46463/",
      "current_public_safe_latest": false,
      "cvss_score": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.15387,
      "epss_score": 0.00243,
      "first_observed_at": "2026-07-10T12:09:55.374028+00:00",
      "id": "CVE-2026-46463",
      "impact_tags": [
        "service availability review",
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-10T12:09:55.374028+00:00",
      "latest_item_url": null,
      "product": "data_domain_operating_system",
      "public_safe_summary": "NVD: Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an integer overflow or wraparound... NVD: An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to denial of service.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260710T121119Z/items/CVE-2026-46463.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: dell / data_domain_operating_system",
      "source_published_impact": "Source describes service availability risk · remote exposure · authenticated boundary. Possible impact: The affected service may become unavailable or unreliable.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an integer overflow or wraparound... NVD: An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to denial of service.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-46463/timeline.json",
      "vendor": "dell"
    },
    {
      "affected_label": "dell / data_domain_operating_system",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-46464/",
      "current_public_safe_latest": false,
      "cvss_score": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.34082,
      "epss_score": 0.00422,
      "first_observed_at": "2026-07-10T12:09:55.374028+00:00",
      "id": "CVE-2026-46464",
      "impact_tags": [
        "information exposure review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-10T12:09:55.374028+00:00",
      "latest_item_url": null,
      "product": "data_domain_operating_system",
      "public_safe_summary": "NVD: Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an improper link resolution before... NVD: A high privileged attacker with remote access could potentially exploit this vulnerability, leading to information disclosure.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260710T121119Z/items/CVE-2026-46464.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: dell / data_domain_operating_system",
      "source_published_impact": "Source describes information exposure review. Possible impact: An attacker may be able to access information that should not be exposed.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an improper link resolution before... NVD: A high privileged attacker with remote access could potentially exploit this vulnerability, leading to information disclosure.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-46464/timeline.json",
      "vendor": "dell"
    },
    {
      "affected_label": "dell / data_domain_operating_system",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-46465/",
      "current_public_safe_latest": false,
      "cvss_score": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.14734,
      "epss_score": 0.00238,
      "first_observed_at": "2026-07-10T12:09:55.374028+00:00",
      "id": "CVE-2026-46465",
      "impact_tags": [
        "information exposure review",
        "service availability review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-10T12:09:55.374028+00:00",
      "latest_item_url": null,
      "product": "data_domain_operating_system",
      "public_safe_summary": "NVD: Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an use of externally-controlled format... NVD: A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure and denial of service.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260710T121119Z/items/CVE-2026-46465.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: dell / data_domain_operating_system",
      "source_published_impact": "Source describes information exposure review · service availability risk. Possible impact: An attacker may be able to access information that should not be exposed.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an use of externally-controlled format... NVD: A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure and denial of service.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-46465/timeline.json",
      "vendor": "dell"
    },
    {
      "affected_label": "dell / data_domain_operating_system",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-46466/",
      "current_public_safe_latest": false,
      "cvss_score": 2.7,
      "cvss_severity": "LOW",
      "epss_percentile": 0.01479,
      "epss_score": 0.00109,
      "first_observed_at": "2026-07-10T12:09:55.374028+00:00",
      "id": "CVE-2026-46466",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-10T12:09:55.374028+00:00",
      "latest_item_url": null,
      "product": "data_domain_operating_system",
      "public_safe_summary": "NVD: Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an use of less trusted source... NVD: A high privileged attacker with remote access could potentially exploit this vulnerability, leading to information tampering.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260710T121119Z/items/CVE-2026-46466.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: dell / data_domain_operating_system",
      "source_published_impact": "This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an use of less trusted source... NVD: A high privileged attacker with remote access could potentially exploit this vulnerability, leading to information tampering.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-46466/timeline.json",
      "vendor": "dell"
    },
    {
      "affected_label": "dell / data_domain_operating_system",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-46467/",
      "current_public_safe_latest": false,
      "cvss_score": 5.8,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.00405,
      "epss_score": 0.00085,
      "first_observed_at": "2026-07-10T12:09:55.374028+00:00",
      "id": "CVE-2026-46467",
      "impact_tags": [
        "information exposure review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-10T12:09:55.374028+00:00",
      "latest_item_url": null,
      "product": "data_domain_operating_system",
      "public_safe_summary": "NVD: Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an insertion of sensitive information... NVD: A low privileged attacker with local access could potentially exploit this vulnerability, leading to information exposure.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260710T121119Z/items/CVE-2026-46467.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: dell / data_domain_operating_system",
      "source_published_impact": "Source describes information exposure review. Possible impact: An attacker may be able to access information that should not be exposed.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an insertion of sensitive information... NVD: A low privileged attacker with local access could potentially exploit this vulnerability, leading to information exposure.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-46467/timeline.json",
      "vendor": "dell"
    },
    {
      "affected_label": "dell / data_domain_operating_system",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-46468/",
      "current_public_safe_latest": false,
      "cvss_score": 4.4,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.03222,
      "epss_score": 0.00133,
      "first_observed_at": "2026-07-10T12:09:55.374028+00:00",
      "id": "CVE-2026-46468",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-10T12:09:55.374028+00:00",
      "latest_item_url": null,
      "product": "data_domain_operating_system",
      "public_safe_summary": "NVD: Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an improper link resolution before... NVD: A high privileged attacker with local access could potentially exploit this vulnerability, leading to information exposure.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260710T121119Z/items/CVE-2026-46468.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: dell / data_domain_operating_system",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an improper link resolution before... NVD: A high privileged attacker with local access could potentially exploit this vulnerability, leading to information exposure.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-46468/timeline.json",
      "vendor": "dell"
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-4648/",
      "current_public_safe_latest": false,
      "cvss_score": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.02023,
      "epss_score": 0.00118,
      "first_observed_at": "2026-08-04T11:35:47.800052+00:00",
      "id": "CVE-2026-4648",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-04T11:35:47.800052+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Use of an insecure cryptographic algorithm in the cashless payment system using NFC wristbands from CasfID Servicios Tecnológicos S.L.U. NVD: (version used at Resurrection Fest 2025), which employs cards based on MIFARE Classic technology (FM11RF08S). NVD: The cryptographic weakness of the authentication algorithm allows an attacker to retrieve access keys using techniques known as Backdoored Nested Attack, read the wristband’s entire contents, and clone its credentials onto a compatible rewritable card.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260804T114328Z/items/CVE-2026-4648.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Use of an insecure cryptographic algorithm in the cashless payment system using NFC wristbands from CasfID Servicios Tecnológicos S.L.U. NVD: (version used at Resurrection Fest 2025), which employs cards based on MIFARE Classic technology (FM11RF08S). NVD: The cryptographic weakness of the authentication algorithm allows an attacker to retrieve access keys using techniques known as Backdoored Nested Attack, read the wristband’s entire contents, and clone its credentials onto a compatible rewritable card.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-4648/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-46516/",
      "current_public_safe_latest": false,
      "cvss_score": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.17708,
      "epss_score": 0.00261,
      "first_observed_at": "2026-07-27T12:38:45.912501+00:00",
      "id": "CVE-2026-46516",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-27T12:38:45.912501+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Frogman provides headless FreePBX control. NVD: Prior to version 1.6.6, Frogman's chat-console markdown formatter (assets/js/chat.js's formatMarkdown) inserted regex capture groups as raw HTML in four template patterns: inline code, bold, markdown links, and download links. NVD: Tool responses that reflect user-controlled fields — extension names, ring-group descriptions, IVR names, queue descriptions, etc.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260727T124133Z/items/CVE-2026-46516.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Frogman provides headless FreePBX control. NVD: Prior to version 1.6.6, Frogman's chat-console markdown formatter (assets/js/chat.js's formatMarkdown) inserted regex capture groups as raw HTML in four template patterns: inline code, bold, markdown links, and download links. NVD: Tool responses that reflect user-controlled fields — extension names, ring-group descriptions, IVR names, queue descriptions, etc.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-46516/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-46593/",
      "current_public_safe_latest": false,
      "cvss_score": 8.6,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.21898,
      "epss_score": 0.00297,
      "first_observed_at": "2026-08-07T10:13:53.604723+00:00",
      "id": "CVE-2026-46593",
      "impact_tags": [
        "SQL injection risk",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-07T10:13:53.604723+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A SQL injection vulnerability has been identified in the PHP Jabbers - PHP Poll Script. NVD: Improper neutralization of input provided by user to pjAdminPolls.controller.php endpoint allows an authenticated attacker to perform SQL Injection attacks. NVD: This issue was fixed in version 4.1.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260807T102646Z/items/CVE-2026-46593.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes SQL injection risk · authenticated boundary. Possible impact: An attacker may be able to read or change database-backed application data.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: A SQL injection vulnerability has been identified in the PHP Jabbers - PHP Poll Script. NVD: Improper neutralization of input provided by user to pjAdminPolls.controller.php endpoint allows an authenticated attacker to perform SQL Injection attacks. NVD: This issue was fixed in version 4.1.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-46593/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-46594/",
      "current_public_safe_latest": false,
      "cvss_score": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.27436,
      "epss_score": 0.00348,
      "first_observed_at": "2026-08-07T10:13:53.604723+00:00",
      "id": "CVE-2026-46594",
      "impact_tags": [
        "XSS risk"
      ],
      "kev": false,
      "last_observed_at": "2026-08-07T10:13:53.604723+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A reflected cross-site scripting (XSS) vulnerability has been identified in the PHP Jabbers - PHP Poll Script. NVD: A malicious attacker can craft a specially crafted URL that, when opened, results in arbitrary JavaScript execution in the victim's browser. NVD: This issue was fixed in version 4.1.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260807T102646Z/items/CVE-2026-46594.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes XSS risk. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: A reflected cross-site scripting (XSS) vulnerability has been identified in the PHP Jabbers - PHP Poll Script. NVD: A malicious attacker can craft a specially crafted URL that, when opened, results in arbitrary JavaScript execution in the victim's browser. NVD: This issue was fixed in version 4.1.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-46594/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-4661/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.24775,
      "epss_score": 0.00326,
      "first_observed_at": "2026-07-18T05:38:40.092323+00:00",
      "id": "CVE-2026-4661",
      "impact_tags": [
        "information exposure review",
        "SQL injection risk",
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-18T07:15:27.585758+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The WP CTA – Sticky CTA Builder, Generate Leads, Promote Sales plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'fildname' parameter in all versions up to, and including, 2.2.2. NVD: This is due to insufficient escaping of user-supplied column names in the ajaxCheck() method and lack of preparation in the $wpdb->update() call. NVD: The vulnerability is compounded by the complete absence of authorization checks and the endpoint being registered for unauthenticated users via wp_ajax_nopriv_.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260718T071858Z/items/CVE-2026-4661.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes information exposure review · SQL injection risk · remote exposure. Possible impact: A remote attacker may be able to read or change database-backed application data.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The WP CTA – Sticky CTA Builder, Generate Leads, Promote Sales plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'fildname' parameter in all versions up to, and including, 2.2.2. NVD: This is due to insufficient escaping of user-supplied column names in the ajaxCheck() method and lack of preparation in the $wpdb->update() call. NVD: The vulnerability is compounded by the complete absence of authorization checks and the endpoint being registered for unauthenticated users via wp_ajax_nopriv_.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-4661/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "symfony / twig",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-46627/",
      "current_public_safe_latest": false,
      "cvss_score": 7.1,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.30849,
      "epss_score": 0.00385,
      "first_observed_at": "2026-07-21T22:14:32.860584+00:00",
      "id": "CVE-2026-46627",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-21T22:14:32.860584+00:00",
      "latest_item_url": null,
      "product": "twig",
      "public_safe_summary": "NVD: Twig is a template language for PHP. NVD: Prior to 3.26.0, the Twig sandbox does not prevent a template from consuming CPU, memory, or wall-clock time, even under the strictest allow-list, allowing untrusted templates to cause resource exhaustion. NVD: This issue is addressed in version 3.26.0 by documenting that the sandbox does not protect against resource exhaustion.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260721T221655Z/items/CVE-2026-46627.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: symfony / twig",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Twig is a template language for PHP. NVD: Prior to 3.26.0, the Twig sandbox does not prevent a template from consuming CPU, memory, or wall-clock time, even under the strictest allow-list, allowing untrusted templates to cause resource exhaustion. NVD: This issue is addressed in version 3.26.0 by documenting that the sandbox does not protect against resource exhaustion.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-46627/timeline.json",
      "vendor": "symfony"
    },
    {
      "affected_label": "symfony / twig",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-46628/",
      "current_public_safe_latest": false,
      "cvss_score": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.06611,
      "epss_score": 0.00169,
      "first_observed_at": "2026-07-21T22:14:32.860584+00:00",
      "id": "CVE-2026-46628",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-21T22:14:32.860584+00:00",
      "latest_item_url": null,
      "product": "twig",
      "public_safe_summary": "NVD: Twig is a template language for PHP. NVD: Prior to 3.26.0, the deprecated spaceless filter is registered as safe for HTML, causing Twig autoescaping to emit attacker-controlled markup unescaped when spaceless is applied to untrusted input. NVD: This issue is fixed in version 3.26.0.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260721T221655Z/items/CVE-2026-46628.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: symfony / twig",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: Twig is a template language for PHP. NVD: Prior to 3.26.0, the deprecated spaceless filter is registered as safe for HTML, causing Twig autoescaping to emit attacker-controlled markup unescaped when spaceless is applied to untrusted input. NVD: This issue is fixed in version 3.26.0.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-46628/timeline.json",
      "vendor": "symfony"
    },
    {
      "affected_label": "symfony / twig",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-46629/",
      "current_public_safe_latest": false,
      "cvss_score": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.2227,
      "epss_score": 0.00302,
      "first_observed_at": "2026-07-21T22:14:32.860584+00:00",
      "id": "CVE-2026-46629",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-21T22:14:32.860584+00:00",
      "latest_item_url": null,
      "product": "twig",
      "public_safe_summary": "NVD: Twig is a template language for PHP. NVD: Prior to 3.26.0, twig/intl-extra memoises IntlDateFormatter and NumberFormatter instances in arrays keyed by template-controlled filter arguments such as locale, pattern, and attrs, allowing a template to allocate many ICU formatter objects that remain pinned... NVD: This issue is fixed in version 3.26.0.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260721T221655Z/items/CVE-2026-46629.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: symfony / twig",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: Twig is a template language for PHP. NVD: Prior to 3.26.0, twig/intl-extra memoises IntlDateFormatter and NumberFormatter instances in arrays keyed by template-controlled filter arguments such as locale, pattern, and attrs, allowing a template to allocate many ICU formatter objects that remain pinned... NVD: This issue is fixed in version 3.26.0.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-46629/timeline.json",
      "vendor": "symfony"
    },
    {
      "affected_label": "symfony / twig",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-46633/",
      "current_public_safe_latest": false,
      "cvss_score": 8.7,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.46775,
      "epss_score": 0.00642,
      "first_observed_at": "2026-07-21T22:14:32.860584+00:00",
      "id": "CVE-2026-46633",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-21T22:14:32.860584+00:00",
      "latest_item_url": null,
      "product": "twig",
      "public_safe_summary": "NVD: Twig is a template language for PHP. NVD: Prior to 3.26.0, Compiler::string() does not escape single quotes when a template name from a {% use %} tag is placed inside a PHP single-quoted string literal, allowing a crafted template name to terminate the string and inject arbitrary PHP expressions into... NVD: This issue is fixed in version 3.26.0.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260721T221655Z/items/CVE-2026-46633.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: symfony / twig",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: Twig is a template language for PHP. NVD: Prior to 3.26.0, Compiler::string() does not escape single quotes when a template name from a {% use %} tag is placed inside a PHP single-quoted string literal, allowing a crafted template name to terminate the string and inject arbitrary PHP expressions into... NVD: This issue is fixed in version 3.26.0.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-46633/timeline.json",
      "vendor": "symfony"
    },
    {
      "affected_label": "symfony / twig",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-46634/",
      "current_public_safe_latest": false,
      "cvss_score": 7.7,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.34112,
      "epss_score": 0.00419,
      "first_observed_at": "2026-07-21T22:14:32.860584+00:00",
      "id": "CVE-2026-46634",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-21T22:14:32.860584+00:00",
      "latest_item_url": null,
      "product": "twig",
      "public_safe_summary": "NVD: Twig is a template language for PHP. NVD: From 3.9.0 until 3.26.0, template_from_string() compiles an inner template under a synthesized __string_template__<hash> name that can fall outside a SourcePolicyInterface sandbox decision, allowing a sandboxed template that can call template_from_string and... NVD: This issue is fixed in version 3.26.0.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260721T221655Z/items/CVE-2026-46634.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: symfony / twig",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: Twig is a template language for PHP. NVD: From 3.9.0 until 3.26.0, template_from_string() compiles an inner template under a synthesized __string_template__<hash> name that can fall outside a SourcePolicyInterface sandbox decision, allowing a sandboxed template that can call template_from_string and... NVD: This issue is fixed in version 3.26.0.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-46634/timeline.json",
      "vendor": "symfony"
    },
    {
      "affected_label": "symfony / twig",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-46635/",
      "current_public_safe_latest": false,
      "cvss_score": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.21712,
      "epss_score": 0.00297,
      "first_observed_at": "2026-07-21T22:14:32.860584+00:00",
      "id": "CVE-2026-46635",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-21T22:14:32.860584+00:00",
      "latest_item_url": null,
      "product": "twig",
      "public_safe_summary": "NVD: Twig is a template language for PHP. NVD: Prior to 3.26.0, the column filter passes object arrays to PHP array_column(), which reads public and magic properties without reaching CoreExtension::getAttribute() or SandboxExtension::checkPropertyAllowed(), allowing an untrusted template author with... NVD: This issue is fixed in version 3.26.0.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260721T221655Z/items/CVE-2026-46635.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: symfony / twig",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: Twig is a template language for PHP. NVD: Prior to 3.26.0, the column filter passes object arrays to PHP array_column(), which reads public and magic properties without reaching CoreExtension::getAttribute() or SandboxExtension::checkPropertyAllowed(), allowing an untrusted template author with... NVD: This issue is fixed in version 3.26.0.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-46635/timeline.json",
      "vendor": "symfony"
    },
    {
      "affected_label": "symfony / twig",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-46637/",
      "current_public_safe_latest": false,
      "cvss_score": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.07252,
      "epss_score": 0.00175,
      "first_observed_at": "2026-07-21T22:14:32.860584+00:00",
      "id": "CVE-2026-46637",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-21T22:14:32.860584+00:00",
      "latest_item_url": null,
      "product": "twig",
      "public_safe_summary": "NVD: Twig is a template language for PHP. NVD: Prior to 3.26.0, several filters in twig/markdown-extra and twig/cssinliner-extra are registered with is_safe => [all], causing Twig to treat plain text or HTML output as safe in HTML, JavaScript, CSS, URL, and other contexts where the output is not properly... NVD: This issue is fixed in version 3.26.0.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260721T221655Z/items/CVE-2026-46637.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: symfony / twig",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: Twig is a template language for PHP. NVD: Prior to 3.26.0, several filters in twig/markdown-extra and twig/cssinliner-extra are registered with is_safe => [all], causing Twig to treat plain text or HTML output as safe in HTML, JavaScript, CSS, URL, and other contexts where the output is not properly... NVD: This issue is fixed in version 3.26.0.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-46637/timeline.json",
      "vendor": "symfony"
    },
    {
      "affected_label": "symfony / twig",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-46638/",
      "current_public_safe_latest": false,
      "cvss_score": 6.0,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.18095,
      "epss_score": 0.00265,
      "first_observed_at": "2026-07-21T22:14:32.860584+00:00",
      "id": "CVE-2026-46638",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-21T22:14:32.860584+00:00",
      "latest_item_url": null,
      "product": "twig",
      "public_safe_summary": "NVD: Twig is a template language for PHP. NVD: Prior to 3.26.0, {% sandbox %}{% include %} can include a template that was previously loaded outside the sandbox without re-invoking checkSecurity(), allowing the cached template to use tags, filters, and functions that should have been denied by... NVD: This issue is fixed in version 3.26.0.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260721T221655Z/items/CVE-2026-46638.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: symfony / twig",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: Twig is a template language for PHP. NVD: Prior to 3.26.0, {% sandbox %}{% include %} can include a template that was previously loaded outside the sandbox without re-invoking checkSecurity(), allowing the cached template to use tags, filters, and functions that should have been denied by... NVD: This issue is fixed in version 3.26.0.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-46638/timeline.json",
      "vendor": "symfony"
    },
    {
      "affected_label": "symfony / twig",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-46639/",
      "current_public_safe_latest": false,
      "cvss_score": 7.1,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.27443,
      "epss_score": 0.00351,
      "first_observed_at": "2026-07-21T22:14:32.860584+00:00",
      "id": "CVE-2026-46639",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-21T22:14:32.860584+00:00",
      "latest_item_url": null,
      "product": "twig",
      "public_safe_summary": "NVD: Twig is a template language for PHP. NVD: From 3.24.0 until 3.26.0, object-destructuring assignment compiles CoreExtension::getAttribute() with the sandbox argument hardcoded to false, disabling property and method policy checks and allowing an attacker with write access to a sandboxed Twig template... NVD: This issue is fixed in version 3.26.0.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260721T221655Z/items/CVE-2026-46639.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: symfony / twig",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: Twig is a template language for PHP. NVD: From 3.24.0 until 3.26.0, object-destructuring assignment compiles CoreExtension::getAttribute() with the sandbox argument hardcoded to false, disabling property and method policy checks and allowing an attacker with write access to a sandboxed Twig template... NVD: This issue is fixed in version 3.26.0.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-46639/timeline.json",
      "vendor": "symfony"
    },
    {
      "affected_label": "symfony / twig",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-46640/",
      "current_public_safe_latest": false,
      "cvss_score": 8.7,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.32855,
      "epss_score": 0.00405,
      "first_observed_at": "2026-07-21T22:14:32.860584+00:00",
      "id": "CVE-2026-46640",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-21T22:14:32.860584+00:00",
      "latest_item_url": null,
      "product": "twig",
      "public_safe_summary": "NVD: Twig is a template language for PHP. NVD: From 3.15.0 until 3.26.0, _self.(<string>) and import-alias dynamic attribute syntax can concatenate an attacker-controlled string into a MacroReferenceExpression name without identifier validation, causing raw PHP to be emitted into the generated template... NVD: This issue is fixed in version 3.26.0.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260721T221655Z/items/CVE-2026-46640.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: symfony / twig",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: Twig is a template language for PHP. NVD: From 3.15.0 until 3.26.0, _self.(<string>) and import-alias dynamic attribute syntax can concatenate an attacker-controlled string into a MacroReferenceExpression name without identifier validation, causing raw PHP to be emitted into the generated template... NVD: This issue is fixed in version 3.26.0.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-46640/timeline.json",
      "vendor": "symfony"
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-46712/",
      "current_public_safe_latest": false,
      "cvss_score": 2.3,
      "cvss_severity": "LOW",
      "epss_percentile": 0.11964,
      "epss_score": 0.00215,
      "first_observed_at": "2026-08-10T22:01:27.436532+00:00",
      "id": "CVE-2026-46712",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-10T22:01:27.436532+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Misskey is an open source, federated social media platform. NVD: Versions 2025.3.2 and later, but prior to 2026.5.4, contain a vulnerability where a lack of proper permission checks allows access to certain data points from the Direct Messages (formerly Chat) feature, regardless of account permissions. NVD: This vulnerability occurs whether or not federation is enabled.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260810T220919Z/items/CVE-2026-46712.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: Misskey is an open source, federated social media platform. NVD: Versions 2025.3.2 and later, but prior to 2026.5.4, contain a vulnerability where a lack of proper permission checks allows access to certain data points from the Direct Messages (formerly Chat) feature, regardless of account permissions. NVD: This vulnerability occurs whether or not federation is enabled.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-46712/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-46713/",
      "current_public_safe_latest": false,
      "cvss_score": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.07052,
      "epss_score": 0.00174,
      "first_observed_at": "2026-08-10T22:01:27.436532+00:00",
      "id": "CVE-2026-46713",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-10T22:01:27.436532+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Misskey is an open source, federated social media platform. NVD: Versions 12.37.0 and later, but prior to 2026.5.4, contain a vulnerability in the JSON-LD signature validation and compaction process that allows spoofed activities to be accepted as valid. NVD: This issue has been fixed in version 2026.5.4.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260810T220919Z/items/CVE-2026-46713.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: Misskey is an open source, federated social media platform. NVD: Versions 12.37.0 and later, but prior to 2026.5.4, contain a vulnerability in the JSON-LD signature validation and compaction process that allows spoofed activities to be accepted as valid. NVD: This issue has been fixed in version 2026.5.4.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-46713/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-46714/",
      "current_public_safe_latest": false,
      "cvss_score": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.17892,
      "epss_score": 0.00263,
      "first_observed_at": "2026-08-10T22:01:27.436532+00:00",
      "id": "CVE-2026-46714",
      "impact_tags": [
        "service availability review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-10T22:01:27.436532+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Misskey is an open source, federated social media platform. NVD: IVersions 8.63.0 and later, but prior to 2026.5.4, contain a vulnerability that can cause the Misskey web client to slow down or crash when it applies a malformed theme. NVD: This issue has been fixed in version 2026.5.4.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260810T220919Z/items/CVE-2026-46714.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes service availability risk. Possible impact: The affected service may become unavailable or unreliable.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: Misskey is an open source, federated social media platform. NVD: IVersions 8.63.0 and later, but prior to 2026.5.4, contain a vulnerability that can cause the Misskey web client to slow down or crash when it applies a malformed theme. NVD: This issue has been fixed in version 2026.5.4.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-46714/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "dell / data_domain_operating_system",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-46730/",
      "current_public_safe_latest": false,
      "cvss_score": 4.2,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.01917,
      "epss_score": 0.00116,
      "first_observed_at": "2026-07-10T12:09:55.374028+00:00",
      "id": "CVE-2026-46730",
      "impact_tags": [
        "command execution review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-10T12:09:55.374028+00:00",
      "latest_item_url": null,
      "product": "data_domain_operating_system",
      "public_safe_summary": "NVD: Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an incorrect authorization... NVD: A high privileged attacker with local access could potentially exploit this vulnerability, leading to unauthorized command execution.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260710T121119Z/items/CVE-2026-46730.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: dell / data_domain_operating_system",
      "source_published_impact": "Source describes command execution risk. Possible impact: An attacker may be able to run code or commands on affected systems.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an incorrect authorization... NVD: A high privileged attacker with local access could potentially exploit this vulnerability, leading to unauthorized command execution.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-46730/timeline.json",
      "vendor": "dell"
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-47219/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.37644,
      "epss_score": 0.00461,
      "first_observed_at": "2026-08-04T22:31:51.932237+00:00",
      "id": "CVE-2026-47219",
      "impact_tags": [
        "service availability review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-04T22:31:51.932237+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: find-my-way is a framework-independent HTTP router that internally uses a Radix Tree and supports route parameters and wildcards. NVD: Versions prior to 9.7.0 are vulnerable to remotely triggerable DoS in find-my-way when it is used with Node's HTTP/2 server. NVD: The lookup() function passes req.method into find(), and find() indexes this.trees[method].",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260804T223546Z/items/CVE-2026-47219.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes service availability risk. Possible impact: The affected service may become unavailable or unreliable.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: find-my-way is a framework-independent HTTP router that internally uses a Radix Tree and supports route parameters and wildcards. NVD: Versions prior to 9.7.0 are vulnerable to remotely triggerable DoS in find-my-way when it is used with Node's HTTP/2 server. NVD: The lookup() function passes req.method into find(), and find() indexes this.trees[method].",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-47219/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-47397/",
      "current_public_safe_latest": false,
      "cvss_score": 7.1,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.3077,
      "epss_score": 0.00381,
      "first_observed_at": "2026-07-28T16:54:01.667207+00:00",
      "id": "CVE-2026-47397",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-28T16:54:01.667207+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: PraisonAI is a multi-agent teams system. NVD: Prior to version 4.6.40, hidden metadata in a webpage causes PraisonAI agents to write attacker-controlled content to arbitrary paths. NVD: write_file skips path validation when workspace=None (always None in production).",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260728T170314Z/items/CVE-2026-47397.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: PraisonAI is a multi-agent teams system. NVD: Prior to version 4.6.40, hidden metadata in a webpage causes PraisonAI agents to write attacker-controlled content to arbitrary paths. NVD: write_file skips path validation when workspace=None (always None in production).",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-47397/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-47398/",
      "current_public_safe_latest": false,
      "cvss_score": 8.1,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.25496,
      "epss_score": 0.0033,
      "first_observed_at": "2026-07-28T16:54:01.667207+00:00",
      "id": "CVE-2026-47398",
      "impact_tags": [
        "code execution review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-28T16:54:01.667207+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: PraisonAI is a multi-agent teams system. NVD: The v4.6.32 chokepoint refactor (which patched CVE-2026-44334 / GHSA-xcmw-grxf-wjhj) added the PRAISONAI_ALLOW_LOCAL_TOOLS env-var gate to the tool_override.py sinks. NVD: However, two additional spec.loader.exec_module call sites in praisonai/agents_generator.py were missed and remain completely unguarded in versions prior to 4.6.40.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260728T170314Z/items/CVE-2026-47398.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes code execution review. Possible impact: An attacker may be able to run code or commands on affected systems.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: PraisonAI is a multi-agent teams system. NVD: The v4.6.32 chokepoint refactor (which patched CVE-2026-44334 / GHSA-xcmw-grxf-wjhj) added the PRAISONAI_ALLOW_LOCAL_TOOLS env-var gate to the tool_override.py sinks. NVD: However, two additional spec.loader.exec_module call sites in praisonai/agents_generator.py were missed and remain completely unguarded in versions prior to 4.6.40.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-47398/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-47399/",
      "current_public_safe_latest": false,
      "cvss_score": 8.8,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.21246,
      "epss_score": 0.0029,
      "first_observed_at": "2026-07-28T16:54:01.667207+00:00",
      "id": "CVE-2026-47399",
      "impact_tags": [
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-28T16:54:01.667207+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. NVD: Prior to version 0.1.4, the workspace-scoped REST routes contain a systemic object-level authorization flaw that allows an authenticated user from one workspace to access, modify, and delete objects belonging to another workspace by supplying the victim... NVD: The affected pattern appears in workspace-scoped routes such as agents, projects, issues, and comments.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260728T170314Z/items/CVE-2026-47399.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes authenticated boundary. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. NVD: Prior to version 0.1.4, the workspace-scoped REST routes contain a systemic object-level authorization flaw that allows an authenticated user from one workspace to access, modify, and delete objects belonging to another workspace by supplying the victim... NVD: The affected pattern appears in workspace-scoped routes such as agents, projects, issues, and comments.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-47399/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-47405/",
      "current_public_safe_latest": false,
      "cvss_score": 8.8,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.21218,
      "epss_score": 0.0029,
      "first_observed_at": "2026-07-28T16:54:01.667207+00:00",
      "id": "CVE-2026-47405",
      "impact_tags": [
        "privilege boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-28T16:54:01.667207+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. NVD: Versions prior to 0.1.4 have a broken workspace authorization check that allows any authenticated low-privilege workspace member to escalate their own role to owner. NVD: The issue is caused by privileged workspace-management routes using the shared dependency require_workspace_member(...) without requiring admin or owner.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260728T170314Z/items/CVE-2026-47405.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes privilege escalation risk. Possible impact: An attacker may cross a privilege boundary and gain more access than intended.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. NVD: Versions prior to 0.1.4 have a broken workspace authorization check that allows any authenticated low-privilege workspace member to escalate their own role to owner. NVD: The issue is caused by privileged workspace-management routes using the shared dependency require_workspace_member(...) without requiring admin or owner.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-47405/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-47406/",
      "current_public_safe_latest": false,
      "cvss_score": 8.1,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.14094,
      "epss_score": 0.00231,
      "first_observed_at": "2026-07-28T16:54:01.667207+00:00",
      "id": "CVE-2026-47406",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-28T16:54:01.667207+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. NVD: Versions prior to 0.1.4 have an Insecure Direct Object Reference. NVD: The dependency endpoints (POST/GET /workspaces/{workspace_id}/issues/{issue_id}/dependencies and DELETE .../dependencies/{dep_id}) gate access on require_workspace_member(workspace_id) only, then dispatch to DependencyService calls that take URL/body-supplied...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260728T170314Z/items/CVE-2026-47406.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. NVD: Versions prior to 0.1.4 have an Insecure Direct Object Reference. NVD: The dependency endpoints (POST/GET /workspaces/{workspace_id}/issues/{issue_id}/dependencies and DELETE .../dependencies/{dep_id}) gate access on require_workspace_member(workspace_id) only, then dispatch to DependencyService calls that take URL/body-supplied...",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-47406/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-47407/",
      "current_public_safe_latest": false,
      "cvss_score": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.15031,
      "epss_score": 0.00238,
      "first_observed_at": "2026-07-28T16:54:01.667207+00:00",
      "id": "CVE-2026-47407",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-28T16:54:01.667207+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. NVD: Prior to version 0.1.4, the Platform server exposes resources under /api/v1/workspaces/{workspace_id}/... NVD: and protects them with a require_workspace_member(workspace_id) FastAPI dependency.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260728T170314Z/items/CVE-2026-47407.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. NVD: Prior to version 0.1.4, the Platform server exposes resources under /api/v1/workspaces/{workspace_id}/... NVD: and protects them with a require_workspace_member(workspace_id) FastAPI dependency.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-47407/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-47408/",
      "current_public_safe_latest": false,
      "cvss_score": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.14095,
      "epss_score": 0.00231,
      "first_observed_at": "2026-07-28T16:54:01.667207+00:00",
      "id": "CVE-2026-47408",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-28T16:54:01.667207+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. NVD: Versions prior to 0.1.4 have an Insecure Direct Object Reference. NVD: The GET /workspaces/{workspace_id}/issues/{issue_id}/activity endpoint is gated by require_workspace_member(workspace_id) and dispatches to ActivityService.list_for_issue(issue_id), which executes SELECT * FROM activity WHERE issue_id = :issue_id with no...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260728T170314Z/items/CVE-2026-47408.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. NVD: Versions prior to 0.1.4 have an Insecure Direct Object Reference. NVD: The GET /workspaces/{workspace_id}/issues/{issue_id}/activity endpoint is gated by require_workspace_member(workspace_id) and dispatches to ActivityService.list_for_issue(issue_id), which executes SELECT * FROM activity WHERE issue_id = :issue_id with no...",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-47408/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-47703/",
      "current_public_safe_latest": false,
      "cvss_score": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.03417,
      "epss_score": 0.00135,
      "first_observed_at": "2026-07-22T16:52:32.770874+00:00",
      "id": "CVE-2026-47703",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-22T16:52:32.770874+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: AdGuard Home is a network-wide software for blocking ads and tracking. NVD: Prior to 0.107.75, AdGuard Home's client-triggered DoQ forwarding path to a udp:// upstream reduced backend UDP DNS state by producing dns_id=0 or txid=0 and exposed a quoted-port ICMP source-port oracle, weakening DNS response matching for forwarded queries. NVD: This issue is fixed in version 0.107.75.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260722T165509Z/items/CVE-2026-47703.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: AdGuard Home is a network-wide software for blocking ads and tracking. NVD: Prior to 0.107.75, AdGuard Home's client-triggered DoQ forwarding path to a udp:// upstream reduced backend UDP DNS state by producing dns_id=0 or txid=0 and exposed a quoted-port ICMP source-port oracle, weakening DNS response matching for forwarded queries. NVD: This issue is fixed in version 0.107.75.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-47703/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-4773/",
      "current_public_safe_latest": false,
      "cvss_score": 8.1,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.24331,
      "epss_score": 0.00319,
      "first_observed_at": "2026-07-29T06:10:00.110927+00:00",
      "id": "CVE-2026-4773",
      "impact_tags": [
        "authentication boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-29T11:36:18.065267+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Improper validation of specified type of input vulnerability in Magarsus Consulting Ltd. NVD: Co. NVD: IDM-MFA allows Authentication Bypass.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260729T114432Z/items/CVE-2026-4773.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes authentication boundary review. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authentication boundary review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Improper validation of specified type of input vulnerability in Magarsus Consulting Ltd. NVD: Co. NVD: IDM-MFA allows Authentication Bypass.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-4773/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "symfony / twig",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-47730/",
      "current_public_safe_latest": false,
      "cvss_score": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.06611,
      "epss_score": 0.00169,
      "first_observed_at": "2026-07-21T22:14:32.860584+00:00",
      "id": "CVE-2026-47730",
      "impact_tags": [
        "XSS risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-21T22:14:32.860584+00:00",
      "latest_item_url": null,
      "product": "twig",
      "public_safe_summary": "NVD: Twig is a template language for PHP. NVD: From 3.0.0 until 3.26.0, Twig\\Profiler\\Dumper\\HtmlDumper writes Profile::getTemplate() and Profile::getName() into HTML output without escaping, allowing attacker-controlled template or profile names to inject arbitrary HTML when a browser renders the... NVD: This issue is fixed in version 3.26.0.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260721T221655Z/items/CVE-2026-47730.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: symfony / twig",
      "source_published_impact": "Source describes XSS risk. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: Twig is a template language for PHP. NVD: From 3.0.0 until 3.26.0, Twig\\Profiler\\Dumper\\HtmlDumper writes Profile::getTemplate() and Profile::getName() into HTML output without escaping, allowing attacker-controlled template or profile names to inject arbitrary HTML when a browser renders the... NVD: This issue is fixed in version 3.26.0.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-47730/timeline.json",
      "vendor": "symfony"
    },
    {
      "affected_label": "symfony / twig",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-47732/",
      "current_public_safe_latest": false,
      "cvss_score": 7.1,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.28338,
      "epss_score": 0.0036,
      "first_observed_at": "2026-07-21T22:14:32.860584+00:00",
      "id": "CVE-2026-47732",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-21T22:14:32.860584+00:00",
      "latest_item_url": null,
      "product": "twig",
      "public_safe_summary": "NVD: Twig is a template language for PHP. NVD: Prior to 3.26.0, several Twig language constructs trigger PHP string coercion on a Stringable operand without consulting SecurityPolicy::checkMethodAllowed(), allowing a sandboxed template author to invoke __toString() on objects reachable in the render... NVD: range operator.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260721T221655Z/items/CVE-2026-47732.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: symfony / twig",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: Twig is a template language for PHP. NVD: Prior to 3.26.0, several Twig language constructs trigger PHP string coercion on a Stringable operand without consulting SecurityPolicy::checkMethodAllowed(), allowing a sandboxed template author to invoke __toString() on objects reachable in the render... NVD: range operator.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-47732/timeline.json",
      "vendor": "symfony"
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-47746/",
      "current_public_safe_latest": false,
      "cvss_score": 8.9,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.07979,
      "epss_score": 0.00182,
      "first_observed_at": "2026-08-10T22:01:27.436532+00:00",
      "id": "CVE-2026-47746",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-10T22:01:27.436532+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Misskey is an open source, federated social media platform. NVD: Versions 12.37.0 and later, but prior to 2026.5.4, are vulnerable to timing attacks during JSON-LD signature validation and the compaction process. NVD: Because the JSON-LD parsing context is not shared between signature verification and subsequent processing, the application may trust information that should not be trusted, resulting in a time-of-check to time-of-use (TOCTOU) flaw.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260810T220919Z/items/CVE-2026-47746.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: Misskey is an open source, federated social media platform. NVD: Versions 12.37.0 and later, but prior to 2026.5.4, are vulnerable to timing attacks during JSON-LD signature validation and the compaction process. NVD: Because the JSON-LD parsing context is not shared between signature verification and subsequent processing, the application may trust information that should not be trusted, resulting in a time-of-check to time-of-use (TOCTOU) flaw.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-47746/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "cloudfoundry / bosh_cli",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-47826/",
      "current_public_safe_latest": false,
      "cvss_score": 8.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.25792,
      "epss_score": 0.00337,
      "first_observed_at": "2026-07-16T05:57:17.509937+00:00",
      "id": "CVE-2026-47826",
      "impact_tags": [
        "information exposure review",
        "path traversal review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-16T05:57:17.509937+00:00",
      "latest_item_url": null,
      "product": "bosh_cli",
      "public_safe_summary": "NVD: The blobs.yml path key traversal vulnerability in the BOSH CLI tool allows an attacker to write arbitrary files and exfiltrate sensitive information. NVD: Affected versions: BOSH CLI tool versions prior to v7.10.4. OSV: blobs.yaml Path Traversal Allows File Writes",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260716T055845Z/items/CVE-2026-47826.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: cloudfoundry / bosh_cli",
      "source_published_impact": "Source describes information exposure review · path traversal review. Possible impact: An attacker may be able to reach files outside the intended application path.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The blobs.yml path key traversal vulnerability in the BOSH CLI tool allows an attacker to write arbitrary files and exfiltrate sensitive information. NVD: Affected versions: BOSH CLI tool versions prior to v7.10.4. OSV: blobs.yaml Path Traversal Allows File Writes",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-47826/timeline.json",
      "vendor": "cloudfoundry"
    },
    {
      "affected_label": "cloudfoundry / bosh_cli",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-47828/",
      "current_public_safe_latest": false,
      "cvss_score": 8.9,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.04417,
      "epss_score": 0.00148,
      "first_observed_at": "2026-07-16T05:57:17.509937+00:00",
      "id": "CVE-2026-47828",
      "impact_tags": [
        "remote exposure relevant"
      ],
      "kev": false,
      "last_observed_at": "2026-07-16T05:57:17.509937+00:00",
      "latest_item_url": null,
      "product": "bosh_cli",
      "public_safe_summary": "NVD: During bosh create-env and bosh delete-env, the CLI uploads compiled CPI packages and rendered job templates to the new VM's DAV blobstore over HTTPS without verifying the server certificate, even though a CA certificate for that endpoint is available in the... NVD: A network attacker can terminate the TLS connection, harvest the Basic-auth credentials, and read the rendered-templates archive containing every bootstrap secret for the new BOSH Director, then replay the credentials against the real VM's agent for root code... NVD: Affected versions: bosh-cli versions prior to v7.10.4.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260716T055845Z/items/CVE-2026-47828.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: cloudfoundry / bosh_cli",
      "source_published_impact": "Source describes remote exposure. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: During bosh create-env and bosh delete-env, the CLI uploads compiled CPI packages and rendered job templates to the new VM's DAV blobstore over HTTPS without verifying the server certificate, even though a CA certificate for that endpoint is available in the... NVD: A network attacker can terminate the TLS connection, harvest the Basic-auth credentials, and read the rendered-templates archive containing every bootstrap secret for the new BOSH Director, then replay the credentials against the real VM's agent for root code... NVD: Affected versions: bosh-cli versions prior to v7.10.4.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-47828/timeline.json",
      "vendor": "cloudfoundry"
    },
    {
      "affected_label": "cloudfoundry / bosh_cli",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-47829/",
      "current_public_safe_latest": false,
      "cvss_score": 7.7,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.13059,
      "epss_score": 0.00225,
      "first_observed_at": "2026-07-16T05:57:17.509937+00:00",
      "id": "CVE-2026-47829",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-16T05:57:17.509937+00:00",
      "latest_item_url": null,
      "product": "bosh_cli",
      "public_safe_summary": "NVD: Affected versions: bosh-cli versions prior to v7.10.4. OSV: Argument Injection in BOSH CLI Allows Local Command Execution on Operator Workstations via Compromised Director OSV: Affected versions: bosh-cli versions prior to v7.10.4.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260716T055845Z/items/CVE-2026-47829.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: cloudfoundry / bosh_cli",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Affected versions: bosh-cli versions prior to v7.10.4. OSV: Argument Injection in BOSH CLI Allows Local Command Execution on Operator Workstations via Compromised Director OSV: Affected versions: bosh-cli versions prior to v7.10.4.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-47829/timeline.json",
      "vendor": "cloudfoundry"
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-47830/",
      "current_public_safe_latest": false,
      "cvss_score": 8.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.01055,
      "epss_score": 0.001,
      "first_observed_at": "2026-07-16T05:57:17.509937+00:00",
      "id": "CVE-2026-47830",
      "impact_tags": [
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-16T05:57:17.509937+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Incorrect Permission Assignment in BOSH.Utils.psm1 in BOSH-Ecosystem bosh-windows-stemcell-builder allows low-privilege authenticated users to overwrite C:\\bosh\\service_wrapper.exe or C:\\bosh\\bosh-agent.exe and gain NT AUTHORITY\\SYSTEM on the next service... NVD: This can lead to full host control. NVD: Affected versions: bosh-windows-stemcell-builder versions prior to v2019.98.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260716T055845Z/items/CVE-2026-47830.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes authenticated boundary. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Incorrect Permission Assignment in BOSH.Utils.psm1 in BOSH-Ecosystem bosh-windows-stemcell-builder allows low-privilege authenticated users to overwrite C:\\bosh\\service_wrapper.exe or C:\\bosh\\bosh-agent.exe and gain NT AUTHORITY\\SYSTEM on the next service... NVD: This can lead to full host control. NVD: Affected versions: bosh-windows-stemcell-builder versions prior to v2019.98.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-47830/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-47831/",
      "current_public_safe_latest": false,
      "cvss_score": 7.7,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.08863,
      "epss_score": 0.00191,
      "first_observed_at": "2026-07-16T05:57:17.509937+00:00",
      "id": "CVE-2026-47831",
      "impact_tags": [
        "remote exposure relevant"
      ],
      "kev": false,
      "last_observed_at": "2026-07-16T05:57:17.509937+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Use of a cryptographically weak random number generator in the GenerateRandomPassword function in bosh-windows-stemcell-builder allows a remote attacker to brute-force the resulting SSH login via TCP/22. NVD: Affected versions: bosh-windows-stemcell-builder versions prior to v2019.98.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260716T055845Z/items/CVE-2026-47831.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes remote exposure. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Use of a cryptographically weak random number generator in the GenerateRandomPassword function in bosh-windows-stemcell-builder allows a remote attacker to brute-force the resulting SSH login via TCP/22. NVD: Affected versions: bosh-windows-stemcell-builder versions prior to v2019.98.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-47831/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-47840/",
      "current_public_safe_latest": false,
      "cvss_score": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.03153,
      "epss_score": 0.00132,
      "first_observed_at": "2026-07-16T05:57:17.509937+00:00",
      "id": "CVE-2026-47840",
      "impact_tags": [
        "remote exposure relevant"
      ],
      "kev": false,
      "last_observed_at": "2026-07-16T05:57:17.509937+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A network attacker positioned between UAA and its LDAP directory can impersonate the directory using any certificate from any trusted CA, then harvest the LDAP bind password and every end-user password sent during simple-bind authentication, and return forged... NVD: This affects every deployment that authenticates users against LDAP over StartTLS. NVD: Affected versions: UAA versions prior to v78.13.0; Cf-deployment versions prior to v56.2.0.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260716T055845Z/items/CVE-2026-47840.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes remote exposure. Possible impact: This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A network attacker positioned between UAA and its LDAP directory can impersonate the directory using any certificate from any trusted CA, then harvest the LDAP bind password and every end-user password sent during simple-bind authentication, and return forged... NVD: This affects every deployment that authenticates users against LDAP over StartTLS. NVD: Affected versions: UAA versions prior to v78.13.0; Cf-deployment versions prior to v56.2.0.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-47840/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-47865/",
      "current_public_safe_latest": false,
      "cvss_score": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.55161,
      "epss_score": 0.00874,
      "first_observed_at": "2026-07-24T22:30:22.773708+00:00",
      "id": "CVE-2026-47865",
      "impact_tags": [
        "authentication boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-25T05:58:56.044661+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: VMware Avi Load Balancer contains an authentication bypass vulnerability. NVD: A malicious user with network access may be able to access the Avi Control plane by bypassing the authentication mechanism. NVD: Affected versions: 31.1.1 through 31.2.2 (fixed in 31.2.2-2p3) 30.1.1 through 30.2.6 (fixed in 30.2.7) 22.1.1 through 22.1.7 (fixed in 30.2.7)",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260725T060125Z/items/CVE-2026-47865.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes authentication boundary review. Possible impact: This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authentication boundary review.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: 30.2.7, 31.2.2-2p3.",
      "source_published_summary": "NVD: VMware Avi Load Balancer contains an authentication bypass vulnerability. NVD: A malicious user with network access may be able to access the Avi Control plane by bypassing the authentication mechanism. NVD: Affected versions: 31.1.1 through 31.2.2 (fixed in 31.2.2-2p3) 30.1.1 through 30.2.6 (fixed in 30.2.7) 22.1.1 through 22.1.7 (fixed in 30.2.7)",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-47865/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-47866/",
      "current_public_safe_latest": false,
      "cvss_score": 8.3,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.18699,
      "epss_score": 0.00268,
      "first_observed_at": "2026-07-24T22:30:22.773708+00:00",
      "id": "CVE-2026-47866",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-25T05:58:56.044661+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: VMware Avi Load Balancer contains an authorization bypass vulnerability. NVD: A malicious actor on the network can access a limited subset of the Avi Control Plane without proper authorization. NVD: Affected versions: 32.1.1 (fixed in 32.1.2) 31.1.1 through 31.2.2 (fixed in 31.2.2-2p3) 30.1.1 through 30.2.6 (fixed in 30.2.7) 22.1.1 through 22.1.7 (fixed in 30.2.7)",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260725T060125Z/items/CVE-2026-47866.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: 30.2.7, 31.2.2-2p3, 32.1.2.",
      "source_published_summary": "NVD: VMware Avi Load Balancer contains an authorization bypass vulnerability. NVD: A malicious actor on the network can access a limited subset of the Avi Control Plane without proper authorization. NVD: Affected versions: 32.1.1 (fixed in 32.1.2) 31.1.1 through 31.2.2 (fixed in 31.2.2-2p3) 30.1.1 through 30.2.6 (fixed in 30.2.7) 22.1.1 through 22.1.7 (fixed in 30.2.7)",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-47866/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-47867/",
      "current_public_safe_latest": false,
      "cvss_score": 8.7,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.36039,
      "epss_score": 0.00441,
      "first_observed_at": "2026-07-24T22:30:22.773708+00:00",
      "id": "CVE-2026-47867",
      "impact_tags": [
        "code execution review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-25T05:58:56.044661+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: VMware Avi Load Balancer contains a remote code execution vulnerability. NVD: A malicious user with network access may be able to access the Avi Control plane and execute code remotely. NVD: Affected versions: 32.1.1 (fixed in 32.1.2) 31.1.1 through 31.2.2 (fixed in 31.2.2-2p3) 30.1.1 through 30.2.6 (fixed in 30.2.7) 22.1.1 through 22.1.7 (fixed in 30.2.7)",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260725T060125Z/items/CVE-2026-47867.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes code execution review. Possible impact: An attacker may be able to run code or commands on affected systems.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: 30.2.7, 31.2.2-2p3, 32.1.2.",
      "source_published_summary": "NVD: VMware Avi Load Balancer contains a remote code execution vulnerability. NVD: A malicious user with network access may be able to access the Avi Control plane and execute code remotely. NVD: Affected versions: 32.1.1 (fixed in 32.1.2) 31.1.1 through 31.2.2 (fixed in 31.2.2-2p3) 30.1.1 through 30.2.6 (fixed in 30.2.7) 22.1.1 through 22.1.7 (fixed in 30.2.7)",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-47867/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-47868/",
      "current_public_safe_latest": false,
      "cvss_score": 7.8,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.01481,
      "epss_score": 0.0011,
      "first_observed_at": "2026-07-24T22:30:22.773708+00:00",
      "id": "CVE-2026-47868",
      "impact_tags": [
        "admin privilege risk",
        "privilege boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-25T05:58:56.044661+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: VMware Avi Load Balancer contains a local privilege escalation vulnerability. NVD: A malicious user with local access may be able to escalate their privileges to run code as root. NVD: Affected versions: 32.1.1 (fixed in 32.1.2) 31.1.1 through 31.2.2 (fixed in 31.2.2-2p3) 30.1.1 through 30.2.6 (fixed in 30.2.7) 22.1.1 through 22.1.7 (fixed in 30.2.7)",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260725T060125Z/items/CVE-2026-47868.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes admin privilege risk · privilege escalation risk. Possible impact: An attacker may gain root or administrative-level privileges on affected systems.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: 30.2.7, 31.2.2-2p3, 32.1.2.",
      "source_published_summary": "NVD: VMware Avi Load Balancer contains a local privilege escalation vulnerability. NVD: A malicious user with local access may be able to escalate their privileges to run code as root. NVD: Affected versions: 32.1.1 (fixed in 32.1.2) 31.1.1 through 31.2.2 (fixed in 31.2.2-2p3) 30.1.1 through 30.2.6 (fixed in 30.2.7) 22.1.1 through 22.1.7 (fixed in 30.2.7)",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-47868/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-47869/",
      "current_public_safe_latest": false,
      "cvss_score": 8.7,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.36039,
      "epss_score": 0.00441,
      "first_observed_at": "2026-07-24T22:30:22.773708+00:00",
      "id": "CVE-2026-47869",
      "impact_tags": [
        "code execution review",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-25T05:58:56.044661+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: VMware Avi Load Balancer contains a remote code execution vulnerability. NVD: A malicious authenticated user with network access may be able to inject and execute code. NVD: Affected versions: 32.1.1 (fixed in 32.1.2) 31.1.1 through 31.2.2 (fixed in 31.2.2-2p3) 30.1.1 through 30.2.6 (fixed in 30.2.7) 22.1.1 through 22.1.7 (fixed in 30.2.7)",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260725T060125Z/items/CVE-2026-47869.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes code execution review · authenticated boundary. Possible impact: An attacker may be able to run code or commands on affected systems.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: 30.2.7, 31.2.2-2p3, 32.1.2.",
      "source_published_summary": "NVD: VMware Avi Load Balancer contains a remote code execution vulnerability. NVD: A malicious authenticated user with network access may be able to inject and execute code. NVD: Affected versions: 32.1.1 (fixed in 32.1.2) 31.1.1 through 31.2.2 (fixed in 31.2.2-2p3) 30.1.1 through 30.2.6 (fixed in 30.2.7) 22.1.1 through 22.1.7 (fixed in 30.2.7)",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-47869/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-47870/",
      "current_public_safe_latest": false,
      "cvss_score": 7.1,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.1674,
      "epss_score": 0.00252,
      "first_observed_at": "2026-07-24T22:30:22.773708+00:00",
      "id": "CVE-2026-47870",
      "impact_tags": [
        "privilege boundary review",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-25T05:58:56.044661+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: VMware Avi Load Balancer contains a privilege escalation vulnerability. NVD: A malicious authenticated user with network access may be able to execute remote code. NVD: Affected versions: 32.1.1 (fixed in 32.1.2) 31.1.1 through 31.2.2 (fixed in 31.2.2-2p3) 30.1.1 through 30.2.6 (fixed in 30.2.7) 22.1.1 through 22.1.7 (fixed in 30.2.7)",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260725T060125Z/items/CVE-2026-47870.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes privilege escalation risk · authenticated boundary. Possible impact: An attacker may cross a privilege boundary and gain more access than intended.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: 30.2.7, 31.2.2-2p3, 32.1.2.",
      "source_published_summary": "NVD: VMware Avi Load Balancer contains a privilege escalation vulnerability. NVD: A malicious authenticated user with network access may be able to execute remote code. NVD: Affected versions: 32.1.1 (fixed in 32.1.2) 31.1.1 through 31.2.2 (fixed in 31.2.2-2p3) 30.1.1 through 30.2.6 (fixed in 30.2.7) 22.1.1 through 22.1.7 (fixed in 30.2.7)",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-47870/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-47871/",
      "current_public_safe_latest": false,
      "cvss_score": 8.8,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.4741,
      "epss_score": 0.00651,
      "first_observed_at": "2026-07-24T22:30:22.773708+00:00",
      "id": "CVE-2026-47871",
      "impact_tags": [
        "path traversal review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-25T05:58:56.044661+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: VMware Avi Load Balancer contains a directory traversal vulnerability. NVD: Flaws in file path validation allow malicious, authenticated network users to perform directory traversal attacks. NVD: Affected versions: 32.1.1 (fixed in 32.1.2) 31.1.1 through 31.2.2 (fixed in 31.2.2-2p3) 30.1.1 through 30.2.6 (fixed in 30.2.7) 22.1.1 through 22.1.7 (fixed in 30.2.7)",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260725T060125Z/items/CVE-2026-47871.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes path traversal review. Possible impact: An attacker may be able to reach files outside the intended application path.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: 30.2.7, 31.2.2-2p3, 32.1.2.",
      "source_published_summary": "NVD: VMware Avi Load Balancer contains a directory traversal vulnerability. NVD: Flaws in file path validation allow malicious, authenticated network users to perform directory traversal attacks. NVD: Affected versions: 32.1.1 (fixed in 32.1.2) 31.1.1 through 31.2.2 (fixed in 31.2.2-2p3) 30.1.1 through 30.2.6 (fixed in 30.2.7) 22.1.1 through 22.1.7 (fixed in 30.2.7)",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-47871/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-47876/",
      "current_public_safe_latest": false,
      "cvss_score": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.20281,
      "epss_score": 0.00281,
      "first_observed_at": "2026-08-06T11:35:20.545945+00:00",
      "id": "CVE-2026-47876",
      "impact_tags": [
        "admin privilege risk"
      ],
      "kev": false,
      "last_observed_at": "2026-08-06T11:35:20.545945+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: VMware ESX contains an out-of-bounds write vulnerability in the VMXNET3 virtual network adapter. NVD: A malicious actor with local administrative privileges on a virtual machine with VMXNET3 virtual network adapter may exploit this issue to execute code on the host. NVD: Non VMXNET3 virtual adapters are not affected by this issue.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260806T114533Z/items/CVE-2026-47876.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes admin privilege risk. Possible impact: An attacker may gain root or administrative-level privileges on affected systems.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: VMware ESX contains an out-of-bounds write vulnerability in the VMXNET3 virtual network adapter. NVD: A malicious actor with local administrative privileges on a virtual machine with VMXNET3 virtual network adapter may exploit this issue to execute code on the host. NVD: Non VMXNET3 virtual adapters are not affected by this issue.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-47876/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-48021/",
      "current_public_safe_latest": false,
      "cvss_score": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.02551,
      "epss_score": 0.00124,
      "first_observed_at": "2026-07-31T16:59:34.622526+00:00",
      "id": "CVE-2026-48021",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-31T16:59:34.622526+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: In epa4all, prior to version 2026-05-20, an attacker who can intercept the TLS connection between epa4all and the ePA backend can complete the VAU handshake with attacker-controlled keys and obtain the session encryption keys. NVD: All inner HTTP traffic (patient consent decisions, medication data, document operations, authorization tokens, and entitlement queries) becomes readable and modifiable. NVD: The attacker can also inject arbitrary requests through the hijacked channel.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260731T171256Z/items/CVE-2026-48021.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: In epa4all, prior to version 2026-05-20, an attacker who can intercept the TLS connection between epa4all and the ePA backend can complete the VAU handshake with attacker-controlled keys and obtain the session encryption keys. NVD: All inner HTTP traffic (patient consent decisions, medication data, document operations, authorization tokens, and entitlement queries) becomes readable and modifiable. NVD: The attacker can also inject arbitrary requests through the hijacked channel.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-48021/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-48025/",
      "current_public_safe_latest": false,
      "cvss_score": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.21382,
      "epss_score": 0.00291,
      "first_observed_at": "2026-08-04T17:06:52.325316+00:00",
      "id": "CVE-2026-48025",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-04T17:06:52.325316+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. NVD: Prior to version 0.3.7, internal/pki/resolver.go:36-64 constructs a CAManager with the plaintext ed25519.PrivateKey after unwrapping via the master key; internal/pki/ca.go:13-16 stores it. NVD: Callers at internal/api/enroll.go:116, internal/api/updates.go:297, and internal/api/mobile_bundle.go:40 use the manager for one Sign() and drop the reference on function return — but the underlying slice contents are not wiped before release.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260804T171542Z/items/CVE-2026-48025.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. NVD: Prior to version 0.3.7, internal/pki/resolver.go:36-64 constructs a CAManager with the plaintext ed25519.PrivateKey after unwrapping via the master key; internal/pki/ca.go:13-16 stores it. NVD: Callers at internal/api/enroll.go:116, internal/api/updates.go:297, and internal/api/mobile_bundle.go:40 use the manager for one Sign() and drop the reference on function return — but the underlying slice contents are not wiped before release.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-48025/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-48030/",
      "current_public_safe_latest": false,
      "cvss_score": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.72524,
      "epss_score": 0.01545,
      "first_observed_at": "2026-08-03T17:21:47.396014+00:00",
      "id": "CVE-2026-48030",
      "impact_tags": [
        "code execution review",
        "command injection risk",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-03T17:21:47.396014+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Pheditor is a single-file editor and file manager written in PHP. NVD: From version 2.0.1 to before version 2.0.4, an OS Command Injection vulnerability in the terminal action handler allows any authenticated user to execute arbitrary OS commands by injecting shell metacharacters into the 'dir' POST parameter, completely... NVD: This issue has been patched in version 2.0.4.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260803T174717Z/items/CVE-2026-48030.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes code execution review · command injection risk · authenticated boundary. Possible impact: An attacker may be able to run code or commands on affected systems.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: Pheditor is a single-file editor and file manager written in PHP. NVD: From version 2.0.1 to before version 2.0.4, an OS Command Injection vulnerability in the terminal action handler allows any authenticated user to execute arbitrary OS commands by injecting shell metacharacters into the 'dir' POST parameter, completely... NVD: This issue has been patched in version 2.0.4.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-48030/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-48032/",
      "current_public_safe_latest": false,
      "cvss_score": 8.3,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.23313,
      "epss_score": 0.00309,
      "first_observed_at": "2026-07-31T16:59:34.622526+00:00",
      "id": "CVE-2026-48032",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-31T16:59:34.622526+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Hulumi is an open-source toolkit that ships secure-by-default cloud and platform infrastructure components for Pulumi. NVD: Prior to version 1.4.0, IAM-role policy checks can be bypassed when the role trusts multiple OIDC providers. NVD: This issue has been patched in version 1.4.0.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260731T171256Z/items/CVE-2026-48032.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: Hulumi is an open-source toolkit that ships secure-by-default cloud and platform infrastructure components for Pulumi. NVD: Prior to version 1.4.0, IAM-role policy checks can be bypassed when the role trusts multiple OIDC providers. NVD: This issue has been patched in version 1.4.0.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-48032/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-48033/",
      "current_public_safe_latest": false,
      "cvss_score": 8.4,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.19731,
      "epss_score": 0.00275,
      "first_observed_at": "2026-07-31T16:59:34.622526+00:00",
      "id": "CVE-2026-48033",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-31T16:59:34.622526+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Hulumi is an open-source toolkit that ships secure-by-default cloud and platform infrastructure components for Pulumi. NVD: Prior to version 1.4.0, policy packs can be bypassed by a forged Pulumi-URN logical name. NVD: This issue has been patched in version 1.4.0.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260731T171256Z/items/CVE-2026-48033.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: Hulumi is an open-source toolkit that ships secure-by-default cloud and platform infrastructure components for Pulumi. NVD: Prior to version 1.4.0, policy packs can be bypassed by a forged Pulumi-URN logical name. NVD: This issue has been patched in version 1.4.0.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-48033/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-48034/",
      "current_public_safe_latest": false,
      "cvss_score": 8.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.17487,
      "epss_score": 0.00258,
      "first_observed_at": "2026-07-31T16:59:34.622526+00:00",
      "id": "CVE-2026-48034",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-31T16:59:34.622526+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Hulumi is an open-source toolkit that ships secure-by-default cloud and platform infrastructure components for Pulumi. NVD: Prior to version 1.4.0, there is a bypass via decoy sibling resources targeting a different bucket. NVD: This issue has been patched in version 1.4.0.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260731T171256Z/items/CVE-2026-48034.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: Hulumi is an open-source toolkit that ships secure-by-default cloud and platform infrastructure components for Pulumi. NVD: Prior to version 1.4.0, there is a bypass via decoy sibling resources targeting a different bucket. NVD: This issue has been patched in version 1.4.0.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-48034/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-48035/",
      "current_public_safe_latest": false,
      "cvss_score": 7.1,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.17618,
      "epss_score": 0.00259,
      "first_observed_at": "2026-07-31T16:59:34.622526+00:00",
      "id": "CVE-2026-48035",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-31T16:59:34.622526+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Hulumi is an open-source toolkit that ships secure-by-default cloud and platform infrastructure components for Pulumi. NVD: Prior to version 1.4.0, consumers using AccountFoundation could ship an AWS account whose CloudTrail / Config audit logs were deletable by any S3-delete-capable principal — while believing the startup-hardened tier guaranteed tamper-resistance. NVD: Sandbox-tier deployments had no audit immutability at all (defects 1 and 3 compounded).",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260731T171256Z/items/CVE-2026-48035.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: Hulumi is an open-source toolkit that ships secure-by-default cloud and platform infrastructure components for Pulumi. NVD: Prior to version 1.4.0, consumers using AccountFoundation could ship an AWS account whose CloudTrail / Config audit logs were deletable by any S3-delete-capable principal — while believing the startup-hardened tier guaranteed tamper-resistance. NVD: Sandbox-tier deployments had no audit immutability at all (defects 1 and 3 compounded).",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-48035/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-48036/",
      "current_public_safe_latest": false,
      "cvss_score": 8.4,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.21662,
      "epss_score": 0.00294,
      "first_observed_at": "2026-07-31T16:59:34.622526+00:00",
      "id": "CVE-2026-48036",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-31T16:59:34.622526+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Hulumi is an open-source toolkit that ships secure-by-default cloud and platform infrastructure components for Pulumi. NVD: Prior to version 1.4.0, consumers running drift detection in CI / cron could see transient adapter failures silently cached as \"all clear\" — masking real attacks for up to six hours — or see ordinary provider-version churn falsely promoted to incident... NVD: Either way, the verdict source was unreliable for downstream incident workflows that gate on it.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260731T171256Z/items/CVE-2026-48036.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: Hulumi is an open-source toolkit that ships secure-by-default cloud and platform infrastructure components for Pulumi. NVD: Prior to version 1.4.0, consumers running drift detection in CI / cron could see transient adapter failures silently cached as \"all clear\" — masking real attacks for up to six hours — or see ordinary provider-version churn falsely promoted to incident... NVD: Either way, the verdict source was unreliable for downstream incident workflows that gate on it.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-48036/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-48037/",
      "current_public_safe_latest": false,
      "cvss_score": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.17618,
      "epss_score": 0.00259,
      "first_observed_at": "2026-07-31T16:59:34.622526+00:00",
      "id": "CVE-2026-48037",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-31T16:59:34.622526+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Hulumi is an open-source toolkit that ships secure-by-default cloud and platform infrastructure components for Pulumi. NVD: Prior to version 1.4.0, AccountFoundation reuse paths silently downgrade GuardDuty / Security Hub posture. NVD: This issue has been patched in version 1.4.0.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260731T171256Z/items/CVE-2026-48037.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: Hulumi is an open-source toolkit that ships secure-by-default cloud and platform infrastructure components for Pulumi. NVD: Prior to version 1.4.0, AccountFoundation reuse paths silently downgrade GuardDuty / Security Hub posture. NVD: This issue has been patched in version 1.4.0.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-48037/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-48051/",
      "current_public_safe_latest": false,
      "cvss_score": 3.5,
      "cvss_severity": "LOW",
      "epss_percentile": 0.10984,
      "epss_score": 0.00207,
      "first_observed_at": "2026-08-03T17:21:47.396014+00:00",
      "id": "CVE-2026-48051",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-03T17:21:47.396014+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Papra is a minimalistic document management and archiving platform. NVD: Prior to version 26.5.0, Papra's webhook delivery system contains an SSRF protection bypass that allows any authenticated organisation member to cause the server to make HTTP requests to internal addresses — loopback, link-local, and RFC-1918 ranges. NVD: The SSRF protection validates the registered webhook URL but ignores redirect destinations.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260803T174717Z/items/CVE-2026-48051.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: Papra is a minimalistic document management and archiving platform. NVD: Prior to version 26.5.0, Papra's webhook delivery system contains an SSRF protection bypass that allows any authenticated organisation member to cause the server to make HTTP requests to internal addresses — loopback, link-local, and RFC-1918 ranges. NVD: The SSRF protection validates the registered webhook URL but ignores redirect destinations.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-48051/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-48052/",
      "current_public_safe_latest": false,
      "cvss_score": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.11558,
      "epss_score": 0.00211,
      "first_observed_at": "2026-08-03T17:21:47.396014+00:00",
      "id": "CVE-2026-48052",
      "impact_tags": [
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-03T17:21:47.396014+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Papra is a minimalistic document management and archiving platform. NVD: Prior to version 26.5.0, an authenticated user who is a member of any organization can delete or rename tags belonging to a different organization, given the target tag's ID. NVD: The route handler verifies the caller's membership of the \":organizationId\" in the URL, but the repository write filters on tag.id alone, so the URL-level org scope never reaches the database.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260803T174717Z/items/CVE-2026-48052.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: Papra is a minimalistic document management and archiving platform. NVD: Prior to version 26.5.0, an authenticated user who is a member of any organization can delete or rename tags belonging to a different organization, given the target tag's ID. NVD: The route handler verifies the caller's membership of the \":organizationId\" in the URL, but the repository write filters on tag.id alone, so the URL-level org scope never reaches the database.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-48052/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-48115/",
      "current_public_safe_latest": false,
      "cvss_score": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.16236,
      "epss_score": 0.00249,
      "first_observed_at": "2026-08-10T22:01:27.436532+00:00",
      "id": "CVE-2026-48115",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-10T22:01:27.436532+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Misskey is an open source, federated social media platform. NVD: All Misskey servers running versions 2024.5.0 and later, but prior to 2026.5.4, contain a vulnerability in the Server Announcements API where insufficient permission checks allow attackers to access limited portions of data that they normally couldn't view. NVD: This vulnerability occurs whether or not federation is enabled.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260810T220919Z/items/CVE-2026-48115.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: Misskey is an open source, federated social media platform. NVD: All Misskey servers running versions 2024.5.0 and later, but prior to 2026.5.4, contain a vulnerability in the Server Announcements API where insufficient permission checks allow attackers to access limited portions of data that they normally couldn't view. NVD: This vulnerability occurs whether or not federation is enabled.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-48115/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "adobe / illustrator",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-48275/",
      "current_public_safe_latest": false,
      "cvss_score": 8.6,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.05399,
      "epss_score": 0.00158,
      "first_observed_at": "2026-07-21T22:14:32.860584+00:00",
      "id": "CVE-2026-48275",
      "impact_tags": [
        "code execution review",
        "user interaction review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-21T22:14:32.860584+00:00",
      "latest_item_url": null,
      "product": "illustrator",
      "public_safe_summary": "NVD: Illustrator is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the context of the current user. NVD: Exploitation of this issue requires user interaction in that a victim must open a malicious file. NVD: Scope is changed.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260721T221655Z/items/CVE-2026-48275.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: adobe / illustrator; affected version context: -",
      "source_published_impact": "Source describes code execution review · user interaction required. Possible impact: An attacker may be able to run code or commands on affected systems.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Illustrator is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the context of the current user. NVD: Exploitation of this issue requires user interaction in that a victim must open a malicious file. NVD: Scope is changed.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-48275/timeline.json",
      "vendor": "adobe"
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-48372/",
      "current_public_safe_latest": false,
      "cvss_score": 7.8,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.08467,
      "epss_score": 0.00186,
      "first_observed_at": "2026-08-04T17:06:52.325316+00:00",
      "id": "CVE-2026-48372",
      "impact_tags": [
        "code execution review",
        "memory safety review",
        "user interaction review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-04T17:06:52.325316+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Format Plugins is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. NVD: Exploitation of this issue requires user interaction in that a victim must open a malicious file.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260804T171542Z/items/CVE-2026-48372.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes code execution review · memory safety review · user interaction required. Possible impact: An attacker may be able to run code or commands on affected systems.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Format Plugins is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. NVD: Exploitation of this issue requires user interaction in that a victim must open a malicious file.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-48372/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-48388/",
      "current_public_safe_latest": false,
      "cvss_score": 8.6,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.06926,
      "epss_score": 0.00173,
      "first_observed_at": "2026-08-04T17:06:52.325316+00:00",
      "id": "CVE-2026-48388",
      "impact_tags": [
        "code execution review",
        "user interaction review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-04T17:06:52.325316+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Adobe Photoshop Installer was affected by an Uncontrolled Search Path Element vulnerability that could have resulted in arbitrary code execution in the context of the current user. NVD: An attacker could have exploited this vulnerability by placing a malicious library in a directory searched by the installer. NVD: Exploitation of this issue required user interaction in that a victim must have been running the installer.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260804T171542Z/items/CVE-2026-48388.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes code execution review · user interaction required. Possible impact: An attacker may be able to run code or commands on affected systems.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Adobe Photoshop Installer was affected by an Uncontrolled Search Path Element vulnerability that could have resulted in arbitrary code execution in the context of the current user. NVD: An attacker could have exploited this vulnerability by placing a malicious library in a directory searched by the installer. NVD: Exploitation of this issue required user interaction in that a victim must have been running the installer.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-48388/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "snipeitapp / snipe-it",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-48492/",
      "current_public_safe_latest": false,
      "cvss_score": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.30681,
      "epss_score": 0.00385,
      "first_observed_at": "2026-07-15T22:16:59.245057+00:00",
      "id": "CVE-2026-48492",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-15T22:16:59.245057+00:00",
      "latest_item_url": null,
      "product": "snipe-it",
      "public_safe_summary": "NVD: Snipe-IT is an IT asset/license management system. NVD: Prior to version 8.6.1, the GET /api/v1/{object}/selectlist API endpoint is missing an authorization check. NVD: Any user who can log into Snipe-IT - regardless of permissions - can retrieve a paginated list of all user accounts using only their web session cookie.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260715T221956Z/items/CVE-2026-48492.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: snipeitapp / snipe-it",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Snipe-IT is an IT asset/license management system. NVD: Prior to version 8.6.1, the GET /api/v1/{object}/selectlist API endpoint is missing an authorization check. NVD: Any user who can log into Snipe-IT - regardless of permissions - can retrieve a paginated list of all user accounts using only their web session cookie.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-48492/timeline.json",
      "vendor": "snipeitapp"
    },
    {
      "affected_label": "djangoproject / django",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-48588/",
      "current_public_safe_latest": false,
      "cvss_score": 2.3,
      "cvss_severity": "LOW",
      "epss_percentile": 0.29613,
      "epss_score": 0.00375,
      "first_observed_at": "2026-07-14T10:57:43.777280+00:00",
      "id": "CVE-2026-48588",
      "impact_tags": [
        "remote exposure relevant"
      ],
      "kev": false,
      "last_observed_at": "2026-07-14T10:57:43.777280+00:00",
      "latest_item_url": null,
      "product": "django",
      "public_safe_summary": "NVD: An issue was discovered in Django 6.0 before 6.0.7 and 5.2 before 5.2.16. NVD: UpdateCacheMiddleware and the cache_page() decorator cache responses that vary on cookies when the incoming request carries unrelated cookies, which allows remote attackers to read private data from the shared cache. NVD: Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260714T110007Z/items/CVE-2026-48588.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: djangoproject / django",
      "source_published_impact": "Source describes remote exposure. Possible impact: This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: An issue was discovered in Django 6.0 before 6.0.7 and 5.2 before 5.2.16. NVD: UpdateCacheMiddleware and the cache_page() decorator cache responses that vary on cookies when the incoming request carries unrelated cookies, which allows remote attackers to read private data from the shared cache. NVD: Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-48588/timeline.json",
      "vendor": "djangoproject"
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-48614/",
      "current_public_safe_latest": false,
      "cvss_score": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.24997,
      "epss_score": 0.0033,
      "first_observed_at": "2026-07-13T17:24:46.617207+00:00",
      "id": "CVE-2026-48614",
      "impact_tags": [
        "admin privilege risk",
        "privilege boundary review",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-13T17:24:46.617207+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: An improper authorization vulnerability in the Plesk XML API allows an authenticated user to inject arbitrary configuration directives, resulting in arbitrary file write as root and full privilege escalation on the underlying server.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260713T172750Z/items/CVE-2026-48614.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes admin privilege risk · privilege escalation risk · authenticated boundary. Possible impact: An attacker may gain root or administrative-level privileges on affected systems.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: An improper authorization vulnerability in the Plesk XML API allows an authenticated user to inject arbitrary configuration directives, resulting in arbitrary file write as root and full privilege escalation on the underlying server.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-48614/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-48799/",
      "current_public_safe_latest": false,
      "cvss_score": 7.7,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.06042,
      "epss_score": 0.00164,
      "first_observed_at": "2026-07-22T16:52:32.770874+00:00",
      "id": "CVE-2026-48799",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-22T16:52:32.770874+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Postiz is an AI social media scheduling tool. NVD: Prior to 2.21.8, Postiz fails to verify Nowpayments IPN callback authenticity against the payment provider shared secret and reads the target subscription identifier from the untrusted request body, allowing a low-privileged account to grant arbitrary... NVD: This issue is fixed in version 2.21.8.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260722T165509Z/items/CVE-2026-48799.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: Postiz is an AI social media scheduling tool. NVD: Prior to 2.21.8, Postiz fails to verify Nowpayments IPN callback authenticity against the payment provider shared secret and reads the target subscription identifier from the untrusted request body, allowing a low-privileged account to grant arbitrary... NVD: This issue is fixed in version 2.21.8.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-48799/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-48863/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.53104,
      "epss_score": 0.0081,
      "first_observed_at": "2026-07-22T22:28:24.662524+00:00",
      "id": "CVE-2026-48863",
      "impact_tags": [
        "service availability review",
        "memory safety review",
        "remote exposure relevant"
      ],
      "kev": false,
      "last_observed_at": "2026-07-22T22:28:24.662524+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A flaw was found in libsolv. NVD: A stack-based buffer overflow vulnerability exists in the PGP verification component due to incorrect length handling when copying EdDSA 's' MPI into a stack buffer. NVD: A remote attacker could craft a malicious Ed25519 PGP signature with mismatched MPI lengths.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260722T223443Z/items/CVE-2026-48863.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes service availability risk · memory safety review · remote exposure. Possible impact: The affected service may become unavailable or unreliable.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A flaw was found in libsolv. NVD: A stack-based buffer overflow vulnerability exists in the PGP verification component due to incorrect length handling when copying EdDSA 's' MPI into a stack buffer. NVD: A remote attacker could craft a malicious Ed25519 PGP signature with mismatched MPI lengths.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-48863/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "joomla / joomla\\!",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-48947/",
      "current_public_safe_latest": false,
      "cvss_score": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.09642,
      "epss_score": 0.00197,
      "first_observed_at": "2026-07-14T16:41:04.043226+00:00",
      "id": "CVE-2026-48947",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-14T16:41:04.043226+00:00",
      "latest_item_url": null,
      "product": "joomla\\!",
      "public_safe_summary": "NVD: An improper access check allows privileged users to overwrite media files without editing permissions. OSV: An improper access check allows privileged users to overwrite media files without editing permissions.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260714T164406Z/items/CVE-2026-48947.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: joomla / joomla\\!",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: An improper access check allows privileged users to overwrite media files without editing permissions. OSV: An improper access check allows privileged users to overwrite media files without editing permissions.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-48947/timeline.json",
      "vendor": "joomla"
    },
    {
      "affected_label": "joomla / joomla\\!",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-48948/",
      "current_public_safe_latest": false,
      "cvss_score": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.1506,
      "epss_score": 0.0024,
      "first_observed_at": "2026-07-14T16:41:04.043226+00:00",
      "id": "CVE-2026-48948",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-14T16:41:04.043226+00:00",
      "latest_item_url": null,
      "product": "joomla\\!",
      "public_safe_summary": "NVD: An improper access check allows user to download vcard exports of com_contact contacts that are inaccessible. OSV: An improper access check allows user to download vcard exports of com_contact contacts that are inaccessible.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260714T164406Z/items/CVE-2026-48948.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: joomla / joomla\\!",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: An improper access check allows user to download vcard exports of com_contact contacts that are inaccessible. OSV: An improper access check allows user to download vcard exports of com_contact contacts that are inaccessible.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-48948/timeline.json",
      "vendor": "joomla"
    },
    {
      "affected_label": "joomla / joomla\\!",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-48949/",
      "current_public_safe_latest": false,
      "cvss_score": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.04355,
      "epss_score": 0.00147,
      "first_observed_at": "2026-07-14T16:41:04.043226+00:00",
      "id": "CVE-2026-48949",
      "impact_tags": [
        "XSS risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-14T16:41:04.043226+00:00",
      "latest_item_url": null,
      "product": "joomla\\!",
      "public_safe_summary": "NVD: Lack of validation leads to an XSS vulnerability in the MFA management views. OSV: Lack of validation leads to an XSS vulnerability in the MFA management views.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260714T164406Z/items/CVE-2026-48949.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: joomla / joomla\\!",
      "source_published_impact": "Source describes XSS risk. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Lack of validation leads to an XSS vulnerability in the MFA management views. OSV: Lack of validation leads to an XSS vulnerability in the MFA management views.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-48949/timeline.json",
      "vendor": "joomla"
    },
    {
      "affected_label": "joomla / joomla\\!",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-48950/",
      "current_public_safe_latest": false,
      "cvss_score": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.04354,
      "epss_score": 0.00147,
      "first_observed_at": "2026-07-14T16:41:04.043226+00:00",
      "id": "CVE-2026-48950",
      "impact_tags": [
        "XSS risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-14T16:41:04.043226+00:00",
      "latest_item_url": null,
      "product": "joomla\\!",
      "public_safe_summary": "NVD: Lack of escaping leads to an XSS vulnerability in the file management view of com_templates. OSV: Lack of escaping leads to an XSS vulnerability in the file management view of com_templates.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260714T164406Z/items/CVE-2026-48950.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: joomla / joomla\\!",
      "source_published_impact": "Source describes XSS risk. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Lack of escaping leads to an XSS vulnerability in the file management view of com_templates. OSV: Lack of escaping leads to an XSS vulnerability in the file management view of com_templates.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-48950/timeline.json",
      "vendor": "joomla"
    },
    {
      "affected_label": "joomla / joomla\\!",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-48951/",
      "current_public_safe_latest": false,
      "cvss_score": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.04354,
      "epss_score": 0.00147,
      "first_observed_at": "2026-07-14T16:41:04.043226+00:00",
      "id": "CVE-2026-48951",
      "impact_tags": [
        "XSS risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-14T16:41:04.043226+00:00",
      "latest_item_url": null,
      "product": "joomla\\!",
      "public_safe_summary": "NVD: Lack of escaping leads to XSS vulnerabilities in modalreturn layouts of various components. OSV: Lack of escaping leads to XSS vulnerabilities in modalreturn layouts of various components.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260714T164406Z/items/CVE-2026-48951.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: joomla / joomla\\!",
      "source_published_impact": "Source describes XSS risk. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Lack of escaping leads to XSS vulnerabilities in modalreturn layouts of various components. OSV: Lack of escaping leads to XSS vulnerabilities in modalreturn layouts of various components.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-48951/timeline.json",
      "vendor": "joomla"
    },
    {
      "affected_label": "joomla / joomla\\!",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-48952/",
      "current_public_safe_latest": false,
      "cvss_score": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.04354,
      "epss_score": 0.00147,
      "first_observed_at": "2026-07-14T16:41:04.043226+00:00",
      "id": "CVE-2026-48952",
      "impact_tags": [
        "XSS risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-14T16:41:04.043226+00:00",
      "latest_item_url": null,
      "product": "joomla\\!",
      "public_safe_summary": "NVD: Lack of escaping leads to an XSS vulnerability in the update list view of com_installer. OSV: Lack of escaping leads to an XSS vulnerability in the update list view of com_installer.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260714T164406Z/items/CVE-2026-48952.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: joomla / joomla\\!",
      "source_published_impact": "Source describes XSS risk. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Lack of escaping leads to an XSS vulnerability in the update list view of com_installer. OSV: Lack of escaping leads to an XSS vulnerability in the update list view of com_installer.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-48952/timeline.json",
      "vendor": "joomla"
    },
    {
      "affected_label": "joomla / joomla\\!",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-48953/",
      "current_public_safe_latest": false,
      "cvss_score": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.04354,
      "epss_score": 0.00147,
      "first_observed_at": "2026-07-14T16:41:04.043226+00:00",
      "id": "CVE-2026-48953",
      "impact_tags": [
        "XSS risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-14T16:41:04.043226+00:00",
      "latest_item_url": null,
      "product": "joomla\\!",
      "public_safe_summary": "NVD: Lack of escaping leads to an XSS vulnerability in the generic image output layout. OSV: Lack of escaping leads to an XSS vulnerability in the generic image output layout.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260714T164406Z/items/CVE-2026-48953.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: joomla / joomla\\!",
      "source_published_impact": "Source describes XSS risk. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Lack of escaping leads to an XSS vulnerability in the generic image output layout. OSV: Lack of escaping leads to an XSS vulnerability in the generic image output layout.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-48953/timeline.json",
      "vendor": "joomla"
    },
    {
      "affected_label": "joomla / joomla\\!",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-48954/",
      "current_public_safe_latest": false,
      "cvss_score": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.04355,
      "epss_score": 0.00147,
      "first_observed_at": "2026-07-14T16:41:04.043226+00:00",
      "id": "CVE-2026-48954",
      "impact_tags": [
        "XSS risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-14T16:41:04.043226+00:00",
      "latest_item_url": null,
      "product": "joomla\\!",
      "public_safe_summary": "NVD: Improper validation leads to a generic XSS vector in the language override feature. OSV: Improper validation leads to a generic XSS vector in the language override feature.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260714T164406Z/items/CVE-2026-48954.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: joomla / joomla\\!",
      "source_published_impact": "Source describes XSS risk. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Improper validation leads to a generic XSS vector in the language override feature. OSV: Improper validation leads to a generic XSS vector in the language override feature.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-48954/timeline.json",
      "vendor": "joomla"
    },
    {
      "affected_label": "joomla / joomla\\!",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-48955/",
      "current_public_safe_latest": false,
      "cvss_score": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.10926,
      "epss_score": 0.00208,
      "first_observed_at": "2026-07-14T16:41:04.043226+00:00",
      "id": "CVE-2026-48955",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-14T16:41:04.043226+00:00",
      "latest_item_url": null,
      "product": "joomla\\!",
      "public_safe_summary": "NVD: An improper access check allows unauthorized users to access workflow stage and transition information. OSV: An improper access check allows unauthorized users to access workflow stage and transition information.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260714T164406Z/items/CVE-2026-48955.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: joomla / joomla\\!",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: An improper access check allows unauthorized users to access workflow stage and transition information. OSV: An improper access check allows unauthorized users to access workflow stage and transition information.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-48955/timeline.json",
      "vendor": "joomla"
    },
    {
      "affected_label": "joomla / joomla\\!",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-48956/",
      "current_public_safe_latest": false,
      "cvss_score": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.06331,
      "epss_score": 0.00168,
      "first_observed_at": "2026-07-14T16:41:04.043226+00:00",
      "id": "CVE-2026-48956",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-14T16:41:04.043226+00:00",
      "latest_item_url": null,
      "product": "joomla\\!",
      "public_safe_summary": "NVD: An improper access check allows users to display a list of modules in the frontend. OSV: An improper access check allows users to display a list of modules in the frontend.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260714T164406Z/items/CVE-2026-48956.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: joomla / joomla\\!",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: An improper access check allows users to display a list of modules in the frontend. OSV: An improper access check allows users to display a list of modules in the frontend.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-48956/timeline.json",
      "vendor": "joomla"
    },
    {
      "affected_label": "joomla / joomla\\!",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-48957/",
      "current_public_safe_latest": false,
      "cvss_score": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.1506,
      "epss_score": 0.0024,
      "first_observed_at": "2026-07-14T16:41:04.043226+00:00",
      "id": "CVE-2026-48957",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-14T16:41:04.043226+00:00",
      "latest_item_url": null,
      "product": "joomla\\!",
      "public_safe_summary": "NVD: An improper access check allows unauthorized users to access com_privacy datasets. OSV: An improper access check allows unauthorized users to access com_privacy datasets.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260714T164406Z/items/CVE-2026-48957.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: joomla / joomla\\!",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: An improper access check allows unauthorized users to access com_privacy datasets. OSV: An improper access check allows unauthorized users to access com_privacy datasets.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-48957/timeline.json",
      "vendor": "joomla"
    },
    {
      "affected_label": "joomla / joomla\\!",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-48958/",
      "current_public_safe_latest": false,
      "cvss_score": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.1762,
      "epss_score": 0.00262,
      "first_observed_at": "2026-07-14T16:41:04.043226+00:00",
      "id": "CVE-2026-48958",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-14T16:41:04.043226+00:00",
      "latest_item_url": null,
      "product": "joomla\\!",
      "public_safe_summary": "NVD: An improper access check allows unauthorized users to create custom fields via webservices endpoints. OSV: An improper access check allows unauthorized users to create custom fields via webservices endpoints.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260714T164406Z/items/CVE-2026-48958.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: joomla / joomla\\!",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: An improper access check allows unauthorized users to create custom fields via webservices endpoints. OSV: An improper access check allows unauthorized users to create custom fields via webservices endpoints.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-48958/timeline.json",
      "vendor": "joomla"
    },
    {
      "affected_label": "microsoft / graph",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-49159/",
      "current_public_safe_latest": false,
      "cvss_score": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.43004,
      "epss_score": 0.00552,
      "first_observed_at": "2026-07-30T22:30:38.166118+00:00",
      "id": "CVE-2026-49159",
      "impact_tags": [
        "information exposure review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-30T22:30:38.166118+00:00",
      "latest_item_url": null,
      "product": "graph",
      "public_safe_summary": "NVD: Exposure of sensitive information to an unauthorized actor in Microsoft Graph allows an authorized attacker to disclose information over a network.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260730T224832Z/items/CVE-2026-49159.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: microsoft / graph; affected version context: -",
      "source_published_impact": "Source describes information exposure review. Possible impact: An attacker may be able to access information that should not be exposed.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Exposure of sensitive information to an unauthorized actor in Microsoft Graph allows an authorized attacker to disclose information over a network.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-49159/timeline.json",
      "vendor": "microsoft"
    },
    {
      "affected_label": "symfony / ux",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-49208/",
      "current_public_safe_latest": false,
      "cvss_score": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.15221,
      "epss_score": 0.0024,
      "first_observed_at": "2026-07-24T16:59:54.170943+00:00",
      "id": "CVE-2026-49208",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-24T16:59:54.170943+00:00",
      "latest_item_url": null,
      "product": "ux",
      "public_safe_summary": "NVD: Symfony UX is a JavaScript ecosystem for Symfony. NVD: From 2.8.0 until 2.36.0 and 3.1.0, when a #[LiveProp] is typed as DateTimeInterface and no explicit format is configured, Symfony\\UX\\LiveComponent\\LiveComponentHydrator::hydrateObjectValue() falls back to new $className($value), allowing client-supplied... NVD: This issue is fixed in versions 2.36.0 and 3.1.0.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260724T170351Z/items/CVE-2026-49208.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: symfony / ux; affected version context: 3.0.0",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: versions.",
      "source_published_summary": "NVD: Symfony UX is a JavaScript ecosystem for Symfony. NVD: From 2.8.0 until 2.36.0 and 3.1.0, when a #[LiveProp] is typed as DateTimeInterface and no explicit format is configured, Symfony\\UX\\LiveComponent\\LiveComponentHydrator::hydrateObjectValue() falls back to new $className($value), allowing client-supplied... NVD: This issue is fixed in versions 2.36.0 and 3.1.0.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-49208/timeline.json",
      "vendor": "symfony"
    },
    {
      "affected_label": "symfony / ux",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-49209/",
      "current_public_safe_latest": false,
      "cvss_score": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.23478,
      "epss_score": 0.00312,
      "first_observed_at": "2026-07-24T16:59:54.170943+00:00",
      "id": "CVE-2026-49209",
      "impact_tags": [
        "service availability review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-24T16:59:54.170943+00:00",
      "latest_item_url": null,
      "product": "ux",
      "public_safe_summary": "NVD: Symfony UX is a JavaScript ecosystem for Symfony. NVD: From 2.5.0 until 2.36.0 and 3.1.0, Symfony\\UX\\LiveComponent\\Controller\\BatchActionController::__invoke() iterates over the client-supplied actions array and issues a full HttpKernel sub-request for each entry; because the array size is never bounded, an... NVD: This issue is fixed in versions 2.36.0 and 3.1.0.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260724T170351Z/items/CVE-2026-49209.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: symfony / ux; affected version context: 3.0.0",
      "source_published_impact": "Source describes service availability risk. Possible impact: The affected service may become unavailable or unreliable.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: versions.",
      "source_published_summary": "NVD: Symfony UX is a JavaScript ecosystem for Symfony. NVD: From 2.5.0 until 2.36.0 and 3.1.0, Symfony\\UX\\LiveComponent\\Controller\\BatchActionController::__invoke() iterates over the client-supplied actions array and issues a full HttpKernel sub-request for each entry; because the array size is never bounded, an... NVD: This issue is fixed in versions 2.36.0 and 3.1.0.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-49209/timeline.json",
      "vendor": "symfony"
    },
    {
      "affected_label": "symfony / ux",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-49210/",
      "current_public_safe_latest": false,
      "cvss_score": 2.3,
      "cvss_severity": "LOW",
      "epss_percentile": 0.09324,
      "epss_score": 0.00194,
      "first_observed_at": "2026-07-24T16:59:54.170943+00:00",
      "id": "CVE-2026-49210",
      "impact_tags": [
        "XSS risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-24T16:59:54.170943+00:00",
      "latest_item_url": null,
      "product": "ux",
      "public_safe_summary": "NVD: Symfony UX is a JavaScript ecosystem for Symfony. NVD: From 2.8.0 until 2.36.0 and 3.1.0, Symfony\\UX\\LiveComponent\\Util\\ChildComponentPartialRenderer::createHtml() interpolates the client-controlled children[id].tag value from LiveComponentSubscriber and InterceptChildComponentRenderSubscriber directly into HTML... NVD: This issue is fixed in versions 2.36.0 and 3.1.0.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260724T170351Z/items/CVE-2026-49210.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: symfony / ux; affected version context: 3.0.0",
      "source_published_impact": "Source describes XSS risk. Possible impact: This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: versions.",
      "source_published_summary": "NVD: Symfony UX is a JavaScript ecosystem for Symfony. NVD: From 2.8.0 until 2.36.0 and 3.1.0, Symfony\\UX\\LiveComponent\\Util\\ChildComponentPartialRenderer::createHtml() interpolates the client-controlled children[id].tag value from LiveComponentSubscriber and InterceptChildComponentRenderSubscriber directly into HTML... NVD: This issue is fixed in versions 2.36.0 and 3.1.0.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-49210/timeline.json",
      "vendor": "symfony"
    },
    {
      "affected_label": "symfony / ux",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-49211/",
      "current_public_safe_latest": false,
      "cvss_score": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.22733,
      "epss_score": 0.00305,
      "first_observed_at": "2026-07-24T16:59:54.170943+00:00",
      "id": "CVE-2026-49211",
      "impact_tags": [
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-24T16:59:54.170943+00:00",
      "latest_item_url": null,
      "product": "ux",
      "public_safe_summary": "NVD: Symfony UX is a JavaScript ecosystem for Symfony. NVD: From 2.2.0 until 2.36.0 and 3.1.0, Symfony\\UX\\Autocomplete\\Doctrine\\EntitySearchUtil::addSearchClause() builds the LIKE expression used by the autocomplete endpoint by wrapping the client-supplied query in %...% without escaping SQL LIKE wildcards (%, _, \\)... NVD: This issue is fixed in versions 2.36.0 and 3.1.0.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260724T170351Z/items/CVE-2026-49211.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: symfony / ux; affected version context: 3.0.0",
      "source_published_impact": "Source describes authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: versions.",
      "source_published_summary": "NVD: Symfony UX is a JavaScript ecosystem for Symfony. NVD: From 2.2.0 until 2.36.0 and 3.1.0, Symfony\\UX\\Autocomplete\\Doctrine\\EntitySearchUtil::addSearchClause() builds the LIKE expression used by the autocomplete endpoint by wrapping the client-supplied query in %...% without escaping SQL LIKE wildcards (%, _, \\)... NVD: This issue is fixed in versions 2.36.0 and 3.1.0.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-49211/timeline.json",
      "vendor": "symfony"
    },
    {
      "affected_label": "symfony / ux",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-49212/",
      "current_public_safe_latest": false,
      "cvss_score": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.05714,
      "epss_score": 0.00161,
      "first_observed_at": "2026-07-24T16:59:54.170943+00:00",
      "id": "CVE-2026-49212",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-24T16:59:54.170943+00:00",
      "latest_item_url": null,
      "product": "ux",
      "public_safe_summary": "NVD: Symfony UX is a JavaScript ecosystem for Symfony. NVD: From 2.8.0 until 2.36.0 and 3.1.0, the HMAC computed by Symfony\\UX\\LiveComponent\\LiveComponentHydrator covered only sorted prop key/value pairs and did not include the component name, the slot identifier (props vs propsFromParent), or request context... NVD: This issue is fixed in versions 2.36.0 and 3.1.0.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260724T170351Z/items/CVE-2026-49212.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: symfony / ux; affected version context: 3.0.0",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: versions.",
      "source_published_summary": "NVD: Symfony UX is a JavaScript ecosystem for Symfony. NVD: From 2.8.0 until 2.36.0 and 3.1.0, the HMAC computed by Symfony\\UX\\LiveComponent\\LiveComponentHydrator covered only sorted prop key/value pairs and did not include the component name, the slot identifier (props vs propsFromParent), or request context... NVD: This issue is fixed in versions 2.36.0 and 3.1.0.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-49212/timeline.json",
      "vendor": "symfony"
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-49332/",
      "current_public_safe_latest": false,
      "cvss_score": 8.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.09326,
      "epss_score": 0.00194,
      "first_observed_at": "2026-08-04T11:35:47.800052+00:00",
      "id": "CVE-2026-49332",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-04T11:35:47.800052+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A flaw was found in openshift/oauth-proxy. NVD: The proxy sets authenticated identity headers using only dash-variant keys (X-Forwarded-User) but does not strip underscore-variant keys (X_Forwarded_User) from incoming requests. NVD: WSGI and PHP frameworks normalize both variants to the same variable, allowing an authenticated low-privilege user to smuggle a forged identity that may override the legitimate authenticated identity in the upstream application.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260804T114328Z/items/CVE-2026-49332.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A flaw was found in openshift/oauth-proxy. NVD: The proxy sets authenticated identity headers using only dash-variant keys (X-Forwarded-User) but does not strip underscore-variant keys (X_Forwarded_User) from incoming requests. NVD: WSGI and PHP frameworks normalize both variants to the same variable, allowing an authenticated low-privilege user to smuggle a forged identity that may override the legitimate authenticated identity in the upstream application.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-49332/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "apache / openmeetings",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-49488/",
      "current_public_safe_latest": false,
      "cvss_score": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.50342,
      "epss_score": 0.00733,
      "first_observed_at": "2026-07-21T11:20:19.325173+00:00",
      "id": "CVE-2026-49488",
      "impact_tags": [
        "path traversal review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-21T11:20:19.325173+00:00",
      "latest_item_url": null,
      "product": "openmeetings",
      "public_safe_summary": "NVD: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OpenMeetings. NVD: This issue affects Apache OpenMeetings: from 5.0.0 before 9.1.0. NVD: An attacker with moderator rights in any room can read arbitrary files accessible to the OS account running the OM server, including credentials and secrets, via a crafted download request.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260721T112231Z/items/CVE-2026-49488.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: apache / openmeetings",
      "source_published_impact": "Source describes path traversal review. Possible impact: An attacker may be able to reach files outside the intended application path.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OpenMeetings. NVD: This issue affects Apache OpenMeetings: from 5.0.0 before 9.1.0. NVD: An attacker with moderator rights in any room can read arbitrary files accessible to the OS account running the OM server, including credentials and secrets, via a crafted download request.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-49488/timeline.json",
      "vendor": "apache"
    },
    {
      "affected_label": "dell / powerscale_onefs",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-49501/",
      "current_public_safe_latest": false,
      "cvss_score": 6.7,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.01289,
      "epss_score": 0.00105,
      "first_observed_at": "2026-07-22T06:07:21.492959+00:00",
      "id": "CVE-2026-49501",
      "impact_tags": [
        "privilege boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-22T06:07:21.492959+00:00",
      "latest_item_url": null,
      "product": "powerscale_onefs",
      "public_safe_summary": "NVD: Dell PowerScale OneFS versions 9.5.0.0 through 9.10.1.7, and versions 9.11.0.0 through 9.13.0.2 contains an Improper Privilege Management vulnerability. NVD: A high privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260722T060931Z/items/CVE-2026-49501.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: dell / powerscale_onefs",
      "source_published_impact": "Source describes privilege escalation risk. Possible impact: An attacker may cross a privilege boundary and gain more access than intended.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Dell PowerScale OneFS versions 9.5.0.0 through 9.10.1.7, and versions 9.11.0.0 through 9.13.0.2 contains an Improper Privilege Management vulnerability. NVD: A high privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-49501/timeline.json",
      "vendor": "dell"
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-4967/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.32417,
      "epss_score": 0.00403,
      "first_observed_at": "2026-07-10T06:57:55.339390+00:00",
      "id": "CVE-2026-4967",
      "impact_tags": [
        "service availability review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-10T06:57:55.339390+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: In IMS, there is a possible out of bounds read due to a missing bounds check. NVD: This could lead to remote denial of service with no additional execution privileges needed.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260710T070012Z/items/CVE-2026-4967.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes service availability risk. Possible impact: The affected service may become unavailable or unreliable.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: In IMS, there is a possible out of bounds read due to a missing bounds check. NVD: This could lead to remote denial of service with no additional execution privileges needed.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-4967/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "dell / data_domain_operating_system",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-49813/",
      "current_public_safe_latest": false,
      "cvss_score": 6.7,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.36787,
      "epss_score": 0.0046,
      "first_observed_at": "2026-07-10T12:09:55.374028+00:00",
      "id": "CVE-2026-49813",
      "impact_tags": [
        "command execution review",
        "command injection risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-10T12:09:55.374028+00:00",
      "latest_item_url": null,
      "product": "data_domain_operating_system",
      "public_safe_summary": "NVD: Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an improper neutralization of special... NVD: A high privileged attacker with local access could potentially exploit this vulnerability, leading to arbitrary command execution.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260710T121119Z/items/CVE-2026-49813.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: dell / data_domain_operating_system",
      "source_published_impact": "Source describes command execution risk · command injection risk. Possible impact: An attacker may be able to run code or commands on affected systems.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an improper neutralization of special... NVD: A high privileged attacker with local access could potentially exploit this vulnerability, leading to arbitrary command execution.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-49813/timeline.json",
      "vendor": "dell"
    },
    {
      "affected_label": "dell / data_domain_operating_system",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-49814/",
      "current_public_safe_latest": false,
      "cvss_score": 7.2,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.64961,
      "epss_score": 0.01216,
      "first_observed_at": "2026-07-10T12:09:55.374028+00:00",
      "id": "CVE-2026-49814",
      "impact_tags": [
        "command execution review",
        "command injection risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-10T12:09:55.374028+00:00",
      "latest_item_url": null,
      "product": "data_domain_operating_system",
      "public_safe_summary": "NVD: Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an Improper Neutralization of Special... NVD: A high privileged attacker with remote access could potentially exploit this vulnerability, leading to arbitrary command execution.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260710T121119Z/items/CVE-2026-49814.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: dell / data_domain_operating_system",
      "source_published_impact": "Source describes command execution risk · command injection risk. Possible impact: An attacker may be able to run code or commands on affected systems.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an Improper Neutralization of Special... NVD: A high privileged attacker with remote access could potentially exploit this vulnerability, leading to arbitrary command execution.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-49814/timeline.json",
      "vendor": "dell"
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-49997/",
      "current_public_safe_latest": false,
      "cvss_score": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.27186,
      "epss_score": 0.00347,
      "first_observed_at": "2026-07-22T16:52:32.770874+00:00",
      "id": "CVE-2026-49997",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-22T16:52:32.770874+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: SurrealDB is a scalable, distributed, collaborative, document-graph database for the realtime web. NVD: Prior to 3.1.0, Document::purge_edges in surrealdb/core/src/doc/delete.rs automatically removed graph edge records with permissions disabled through opt.clone().with_perms(false) when a connected node was deleted, bypassing the edge table's PERMISSIONS FOR... NVD: This issue is fixed in version 3.1.0.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260722T165509Z/items/CVE-2026-49997.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: SurrealDB is a scalable, distributed, collaborative, document-graph database for the realtime web. NVD: Prior to 3.1.0, Document::purge_edges in surrealdb/core/src/doc/delete.rs automatically removed graph edge records with permissions disabled through opt.clone().with_perms(false) when a connected node was deleted, bypassing the edge table's PERMISSIONS FOR... NVD: This issue is fixed in version 3.1.0.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-49997/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-50044/",
      "current_public_safe_latest": false,
      "cvss_score": 7.6,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.00357,
      "epss_score": 0.00084,
      "first_observed_at": "2026-07-30T22:30:38.166118+00:00",
      "id": "CVE-2026-50044",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-30T22:30:38.166118+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Pronetiqs IntraVUE versions 3.2.1a14 and prior have an inadequate encryption strength vulnerability which could allow an attacker to steal admin credentials via weak hash or a pass-the-hash attack.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260730T224832Z/items/CVE-2026-50044.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Pronetiqs IntraVUE versions 3.2.1a14 and prior have an inadequate encryption strength vulnerability which could allow an attacker to steal admin credentials via weak hash or a pass-the-hash attack.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-50044/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-5005/",
      "current_public_safe_latest": false,
      "cvss_score": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.0318,
      "epss_score": 0.00133,
      "first_observed_at": "2026-07-16T13:54:14.110513+00:00",
      "id": "CVE-2026-5005",
      "impact_tags": [
        "XSS risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-16T13:54:14.110513+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Twiser Informatics Technology Consulting, Trade and Education Inc. NVD: OKRs & Goals allows Stored XSS. NVD: This issue affects OKRs & Goals: from 28220 before 28398.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260716T135621Z/items/CVE-2026-5005.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes XSS risk. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Twiser Informatics Technology Consulting, Trade and Education Inc. NVD: OKRs & Goals allows Stored XSS. NVD: This issue affects OKRs & Goals: from 28220 before 28398.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-5005/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-50180/",
      "current_public_safe_latest": false,
      "cvss_score": 8.7,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.48525,
      "epss_score": 0.00686,
      "first_observed_at": "2026-07-16T22:18:24.817461+00:00",
      "id": "CVE-2026-50180",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-16T22:18:24.817461+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Langroid is a framework for building large-language-model-powered applications. NVD: Prior to version 0.64.0, SQLChatAgent in langroid ships a _validate_query defense-in-depth layer whose _DANGEROUS_SQL_PATTERNS regex blocklist enumerates dangerous SQL primitives by specific function name. NVD: The list misses the canonical PostgreSQL filesystem-disclosure family pg_read_file(), pg_stat_file(), pg_ls_logdir(), pg_ls_waldir(), pg_current_logfile() (and similar SELECT-shaped functions in the same family).",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260716T222035Z/items/CVE-2026-50180.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Langroid is a framework for building large-language-model-powered applications. NVD: Prior to version 0.64.0, SQLChatAgent in langroid ships a _validate_query defense-in-depth layer whose _DANGEROUS_SQL_PATTERNS regex blocklist enumerates dangerous SQL primitives by specific function name. NVD: The list misses the canonical PostgreSQL filesystem-disclosure family pg_read_file(), pg_stat_file(), pg_ls_logdir(), pg_ls_waldir(), pg_current_logfile() (and similar SELECT-shaped functions in the same family).",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-50180/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-50181/",
      "current_public_safe_latest": false,
      "cvss_score": 7.1,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.08184,
      "epss_score": 0.00184,
      "first_observed_at": "2026-07-16T22:18:24.817461+00:00",
      "id": "CVE-2026-50181",
      "impact_tags": [
        "path traversal review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-16T22:18:24.817461+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Langroid is a framework for building large-language-model-powered applications. NVD: Prior to version 0.64.0, Langroid's ReadFileTool and WriteFileTool appear to treat curr_dir as the intended working-directory boundary for file operations. NVD: However, the tools only change the process working directory to curr_dir and then operate on the user-supplied file_path without resolving and enforcing that the final path remains inside curr_dir.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260716T222035Z/items/CVE-2026-50181.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes path traversal review. Possible impact: An attacker may be able to reach files outside the intended application path.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Langroid is a framework for building large-language-model-powered applications. NVD: Prior to version 0.64.0, Langroid's ReadFileTool and WriteFileTool appear to treat curr_dir as the intended working-directory boundary for file operations. NVD: However, the tools only change the process working directory to curr_dir and then operate on the user-supplied file_path without resolving and enforcing that the final path remains inside curr_dir.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-50181/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "microsoft / 365_copilot",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-50517/",
      "current_public_safe_latest": false,
      "cvss_score": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.66494,
      "epss_score": 0.01254,
      "first_observed_at": "2026-07-30T22:30:38.166118+00:00",
      "id": "CVE-2026-50517",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-30T22:30:38.166118+00:00",
      "latest_item_url": null,
      "product": "365_copilot",
      "public_safe_summary": "NVD: Deserialization of untrusted data in M365 Copilot allows an authorized attacker to execute code over a network.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260730T224832Z/items/CVE-2026-50517.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: microsoft / 365_copilot; affected version context: -",
      "source_published_impact": "This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Deserialization of untrusted data in M365 Copilot allows an authorized attacker to execute code over a network.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-50517/timeline.json",
      "vendor": "microsoft"
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-5062/",
      "current_public_safe_latest": false,
      "cvss_score": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.1866,
      "epss_score": 0.00266,
      "first_observed_at": "2026-08-12T05:08:50.991993+00:00",
      "id": "CVE-2026-5062",
      "impact_tags": [
        "information exposure review",
        "SQL injection risk",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-12T05:08:50.991993+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The PrettyLinks – Affiliate Links, Link Branding, Link Tracking, Marketing and Stripe Payments Plugin plugin for WordPress is vulnerable to SQL Injection via the 's' (search) parameter on the Pretty Links listing page in all versions up to, and including... NVD: This is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query in the search_links_table() function. NVD: This makes it possible for authenticated attackers, with Administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260812T051428Z/items/CVE-2026-5062.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes information exposure review · SQL injection risk · authenticated boundary. Possible impact: An attacker may be able to read or change database-backed application data.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The PrettyLinks – Affiliate Links, Link Branding, Link Tracking, Marketing and Stripe Payments Plugin plugin for WordPress is vulnerable to SQL Injection via the 's' (search) parameter on the Pretty Links listing page in all versions up to, and including... NVD: This is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query in the search_links_table() function. NVD: This makes it possible for authenticated attackers, with Administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-5062/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-50641/",
      "current_public_safe_latest": false,
      "cvss_score": 7.1,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.05664,
      "epss_score": 0.0016,
      "first_observed_at": "2026-08-05T11:32:09.387600+00:00",
      "id": "CVE-2026-50641",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-05T11:32:09.387600+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Streamsoft Business Intelligence (BI) stores users' passwords in plaintext form in the database This issue was fixed in version 6.8.0.0, users were also requested to change their password on the first login.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260805T113552Z/items/CVE-2026-50641.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: Streamsoft Business Intelligence (BI) stores users' passwords in plaintext form in the database This issue was fixed in version 6.8.0.0, users were also requested to change their password on the first login.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-50641/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-50644/",
      "current_public_safe_latest": false,
      "cvss_score": 8.6,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.19614,
      "epss_score": 0.00277,
      "first_observed_at": "2026-07-16T11:14:01.223847+00:00",
      "id": "CVE-2026-50644",
      "impact_tags": [
        "SQL injection risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-16T11:14:01.223847+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: SOPlanning is vulnerable to SQL injection in the audit retention configuration. NVD: An attacker holding parameters_all rights can inject SQL commands into the audit configuration form which is then saved. NVD: The execution is triggered when the audit functionality is accessed (by the attacker or another user).",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260716T111601Z/items/CVE-2026-50644.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes SQL injection risk. Possible impact: An attacker may be able to read or change database-backed application data.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: SOPlanning is vulnerable to SQL injection in the audit retention configuration. NVD: An attacker holding parameters_all rights can inject SQL commands into the audit configuration form which is then saved. NVD: The execution is triggered when the audit functionality is accessed (by the attacker or another user).",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-50644/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-50810/",
      "current_public_safe_latest": false,
      "cvss_score": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.02384,
      "epss_score": 0.00122,
      "first_observed_at": "2026-07-14T22:16:58.989760+00:00",
      "id": "CVE-2026-50810",
      "impact_tags": [
        "service availability review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-14T22:16:58.989760+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A NULL pointer dereference in smooth_parse_stream_index() in src/media_tools/mpd.c in GPAC master HEAD before commit b35c61f104b85fbb16520ac2838d5d2ef70845b5 allows attackers to cause a denial of service OSV: A NULL pointer dereference in smooth_parse_stream_index() in src/media_tools/mpd.c in GPAC master HEAD before commit b35c61f104b85fbb16520ac2838d5d2ef70845b5 allows attackers to cause a denial of service",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260714T222111Z/items/CVE-2026-50810.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes service availability risk. Possible impact: The affected service may become unavailable or unreliable.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A NULL pointer dereference in smooth_parse_stream_index() in src/media_tools/mpd.c in GPAC master HEAD before commit b35c61f104b85fbb16520ac2838d5d2ef70845b5 allows attackers to cause a denial of service OSV: A NULL pointer dereference in smooth_parse_stream_index() in src/media_tools/mpd.c in GPAC master HEAD before commit b35c61f104b85fbb16520ac2838d5d2ef70845b5 allows attackers to cause a denial of service",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-50810/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-50811/",
      "current_public_safe_latest": false,
      "cvss_score": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.19726,
      "epss_score": 0.00278,
      "first_observed_at": "2026-07-14T22:16:58.989760+00:00",
      "id": "CVE-2026-50811",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-14T22:16:58.989760+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: An out-of-bounds read vulnerability exists in FreeType 2.14.3 and versions before commit 5a280ecde6f324de0d226261036e736e0cb49a71 in src/truetype/ttgxvar.c, in the TT_Get_Var_Design implementation used by FT_Get_Var_Design_Coordinates OSV: An out-of-bounds read vulnerability exists in FreeType 2.14.3 and versions before commit 5a280ecde6f324de0d226261036e736e0cb49a71 in src/truetype/ttgxvar.c, in the TT_Get_Var_Design implementation used by FT_Get_Var_Design_Coordinates",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260714T222111Z/items/CVE-2026-50811.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: An out-of-bounds read vulnerability exists in FreeType 2.14.3 and versions before commit 5a280ecde6f324de0d226261036e736e0cb49a71 in src/truetype/ttgxvar.c, in the TT_Get_Var_Design implementation used by FT_Get_Var_Design_Coordinates OSV: An out-of-bounds read vulnerability exists in FreeType 2.14.3 and versions before commit 5a280ecde6f324de0d226261036e736e0cb49a71 in src/truetype/ttgxvar.c, in the TT_Get_Var_Design implementation used by FT_Get_Var_Design_Coordinates",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-50811/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-51119/",
      "current_public_safe_latest": false,
      "cvss_score": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.30451,
      "epss_score": 0.00382,
      "first_observed_at": "2026-07-17T16:36:32.072333+00:00",
      "id": "CVE-2026-51119",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-17T16:36:32.072333+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: An issue in Invixium IXM WEB v.2.3.85.25 allows an attacker to escalate privileges via the /SystemUsers/CreateAppUser components",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260717T164048Z/items/CVE-2026-51119.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: An issue in Invixium IXM WEB v.2.3.85.25 allows an attacker to escalate privileges via the /SystemUsers/CreateAppUser components",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-51119/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-51144/",
      "current_public_safe_latest": false,
      "cvss_score": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.11924,
      "epss_score": 0.00214,
      "first_observed_at": "2026-08-11T22:08:35.096641+00:00",
      "id": "CVE-2026-51144",
      "impact_tags": [
        "code execution review",
        "XSS risk",
        "remote exposure relevant"
      ],
      "kev": false,
      "last_observed_at": "2026-08-11T22:08:35.096641+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Cross Site Scripting vulnerability in Soliton Systems MailZen Management Protal v.2.62, v.2.63 allows a remote attacker to execute arbitrary code via the Role Name, First Name, Last Name, and Username fields.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260811T221806Z/items/CVE-2026-51144.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes code execution review · XSS risk · remote exposure. Possible impact: A remote attacker may be able to run code or commands on affected systems.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Cross Site Scripting vulnerability in Soliton Systems MailZen Management Protal v.2.62, v.2.63 allows a remote attacker to execute arbitrary code via the Role Name, First Name, Last Name, and Username fields.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-51144/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-51535/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.38735,
      "epss_score": 0.00488,
      "first_observed_at": "2026-07-15T22:16:59.245057+00:00",
      "id": "CVE-2026-51535",
      "impact_tags": [
        "service availability review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-15T22:16:59.245057+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: In OpENer 2.3.0 (commit 76b95cf), a resource exhaustion (Denial of Service) vulnerability exists in its network processing loop.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260715T221956Z/items/CVE-2026-51535.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes service availability risk. Possible impact: The affected service may become unavailable or unreliable.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: In OpENer 2.3.0 (commit 76b95cf), a resource exhaustion (Denial of Service) vulnerability exists in its network processing loop.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-51535/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-51536/",
      "current_public_safe_latest": false,
      "cvss_score": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.37888,
      "epss_score": 0.00472,
      "first_observed_at": "2026-07-20T22:16:32.807845+00:00",
      "id": "CVE-2026-51536",
      "impact_tags": [
        "memory safety review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-20T22:16:32.807845+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: In OpENer 2.3.0 (commit 76b95cf) when parsing incoming CIP (Common Industrial Protocol) network packets, the length parameter is inconsistently typed across the call stack. NVD: Specifically, an upstream length calculated as an int is passed to a downstream function that expects an EipInt16 (a 16-bit signed integer). NVD: If a maliciously crafted packet with specific length fields is processed, the length parameter can overflow or be truncated into a negative value.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260720T222315Z/items/CVE-2026-51536.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes memory safety review. Possible impact: The affected component has memory-safety risk that may lead to crash, privilege, or code-execution impact depending on exposure.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: In OpENer 2.3.0 (commit 76b95cf) when parsing incoming CIP (Common Industrial Protocol) network packets, the length parameter is inconsistently typed across the call stack. NVD: Specifically, an upstream length calculated as an int is passed to a downstream function that expects an EipInt16 (a 16-bit signed integer). NVD: If a maliciously crafted packet with specific length fields is processed, the length parameter can overflow or be truncated into a negative value.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-51536/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-51537/",
      "current_public_safe_latest": false,
      "cvss_score": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.35285,
      "epss_score": 0.00434,
      "first_observed_at": "2026-07-20T22:16:32.807845+00:00",
      "id": "CVE-2026-51537",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-20T22:16:32.807845+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: EIPStackGroup OpENer 2.3.0 (commit 76b95cf) has an out-of-bounds read issue in Connection Manager handling of ForwardOpen requests when processing short malformed packets. NVD: An attacker can send a valid ENIP outer frame carrying a malformed CIP ForwardOpen/LargeForwardOpen request, causing the parser to continue reading fields even when request data is insufficient. NVD: This issue is remotely triggerable via network traffic and does not require authentication.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260720T222315Z/items/CVE-2026-51537.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: EIPStackGroup OpENer 2.3.0 (commit 76b95cf) has an out-of-bounds read issue in Connection Manager handling of ForwardOpen requests when processing short malformed packets. NVD: An attacker can send a valid ENIP outer frame carrying a malformed CIP ForwardOpen/LargeForwardOpen request, causing the parser to continue reading fields even when request data is insufficient. NVD: This issue is remotely triggerable via network traffic and does not require authentication.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-51537/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-51538/",
      "current_public_safe_latest": false,
      "cvss_score": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.30209,
      "epss_score": 0.00379,
      "first_observed_at": "2026-07-20T22:16:32.807845+00:00",
      "id": "CVE-2026-51538",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-20T22:16:32.807845+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: EIPStackGroup OpENer 2.3.0 (commit 76b95cf) suffers from an Incorrect Access Control vulnerability in its handling of encapsulation sessions. NVD: When the server processes critical encapsulation commands, it verifies whether the provided session_handle exists in the global session list, but it fails to verify whether that handle belongs to the specific TCP connection issuing the request. NVD: Because there is no strong binding between a session handle and its originating socket, any attacker on the network can use a valid session handle created by another legitimate client to bypass access controls.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260720T222315Z/items/CVE-2026-51538.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: EIPStackGroup OpENer 2.3.0 (commit 76b95cf) suffers from an Incorrect Access Control vulnerability in its handling of encapsulation sessions. NVD: When the server processes critical encapsulation commands, it verifies whether the provided session_handle exists in the global session list, but it fails to verify whether that handle belongs to the specific TCP connection issuing the request. NVD: Because there is no strong binding between a session handle and its originating socket, any attacker on the network can use a valid session handle created by another legitimate client to bypass access controls.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-51538/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-51539/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.26648,
      "epss_score": 0.00343,
      "first_observed_at": "2026-07-20T22:16:32.807845+00:00",
      "id": "CVE-2026-51539",
      "impact_tags": [
        "service availability review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-20T22:16:32.807845+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A Denial of Service (DoS) vulnerability exists in the receive loop of libmodbus 3.1.12 when running on Windows. NVD: The issue stems from improper timeout management during network read operations.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260720T222315Z/items/CVE-2026-51539.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes service availability risk. Possible impact: The affected service may become unavailable or unreliable.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A Denial of Service (DoS) vulnerability exists in the receive loop of libmodbus 3.1.12 when running on Windows. NVD: The issue stems from improper timeout management during network read operations.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-51539/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-51540/",
      "current_public_safe_latest": false,
      "cvss_score": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.30281,
      "epss_score": 0.00379,
      "first_observed_at": "2026-07-20T22:16:32.807845+00:00",
      "id": "CVE-2026-51540",
      "impact_tags": [
        "memory safety review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-20T22:16:32.807845+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: OpENer 2.3.0 (master branch up to commit 76b95cf) is vulnerable to a severe memory corruption issue caused by an integer underflow in the processing of connected explicit messages (SendUnitData).",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260720T222315Z/items/CVE-2026-51540.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes memory safety review. Possible impact: The affected component has memory-safety risk that may lead to crash, privilege, or code-execution impact depending on exposure.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: OpENer 2.3.0 (master branch up to commit 76b95cf) is vulnerable to a severe memory corruption issue caused by an integer underflow in the processing of connected explicit messages (SendUnitData).",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-51540/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-51541/",
      "current_public_safe_latest": false,
      "cvss_score": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.30281,
      "epss_score": 0.00379,
      "first_observed_at": "2026-07-20T22:16:32.807845+00:00",
      "id": "CVE-2026-51541",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-20T22:16:32.807845+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: OpENer 2.3.0 (commit 76b95cf) has an out-of-bounds read issue in CIP message parsing when handling malformed explicit requests with a forged EPath size. NVD: Because the parser trusts the attacker-controlled path_size and continues decoding path segments without a remaining-length boundary, it reads beyond the end of the stack receive buffer.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260720T222315Z/items/CVE-2026-51541.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: OpENer 2.3.0 (commit 76b95cf) has an out-of-bounds read issue in CIP message parsing when handling malformed explicit requests with a forged EPath size. NVD: Because the parser trusts the attacker-controlled path_size and continues decoding path segments without a remaining-length boundary, it reads beyond the end of the stack receive buffer.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-51541/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-51565/",
      "current_public_safe_latest": false,
      "cvss_score": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.33089,
      "epss_score": 0.00403,
      "first_observed_at": "2026-08-03T22:29:45.220405+00:00",
      "id": "CVE-2026-51565",
      "impact_tags": [
        "XSS risk",
        "remote exposure relevant"
      ],
      "kev": false,
      "last_observed_at": "2026-08-03T22:29:45.220405+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Cross-site scripting (XSS) vulnerability in Modules/Docs/DocsController.php in Milk admin <=0.9.8 allows remote attackers to inject arbitrary web script or HTML via the action parameter in a crafted request",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260803T223322Z/items/CVE-2026-51565.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes XSS risk · remote exposure. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk · remote exposure.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Cross-site scripting (XSS) vulnerability in Modules/Docs/DocsController.php in Milk admin <=0.9.8 allows remote attackers to inject arbitrary web script or HTML via the action parameter in a crafted request",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-51565/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-51597/",
      "current_public_safe_latest": false,
      "cvss_score": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.29436,
      "epss_score": 0.00372,
      "first_observed_at": "2026-07-16T16:44:59.414444+00:00",
      "id": "CVE-2026-51597",
      "impact_tags": [
        "unauthorized access risk",
        "authentication boundary review",
        "remote exposure relevant"
      ],
      "kev": false,
      "last_observed_at": "2026-07-16T16:44:59.414444+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: MERCURY MIPC252W IP camera v1.0.5 Build 230306 Rel.79931n does not implement nonce expiration in RTSP Digest authentication. NVD: An adjacent network attacker can capture a legitimate authentication exchange and replay the nonce and response values in a new connection to bypass authentication without knowledge of the device credentials, gaining unauthorized access to the live video...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260716T164706Z/items/CVE-2026-51597.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes unauthorized access risk · authentication boundary review · remote exposure. Possible impact: A remote attacker may access resources that should require stronger authorization.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: MERCURY MIPC252W IP camera v1.0.5 Build 230306 Rel.79931n does not implement nonce expiration in RTSP Digest authentication. NVD: An adjacent network attacker can capture a legitimate authentication exchange and replay the nonce and response values in a new connection to bypass authentication without knowledge of the device credentials, gaining unauthorized access to the live video...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-51597/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-51598/",
      "current_public_safe_latest": false,
      "cvss_score": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.07443,
      "epss_score": 0.00177,
      "first_observed_at": "2026-07-16T16:44:59.414444+00:00",
      "id": "CVE-2026-51598",
      "impact_tags": [
        "service availability review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-16T16:44:59.414444+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: An input validation vulnerability in the RTSP service of MERCURY MIPC252W IP Camera v1.0.5 Build 230306 Rel.79931n) allows an unauthenticated, network-adjacent attacker to cause a denial of service via a crafted DESCRIBE request with a malformed URL in the...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260716T164706Z/items/CVE-2026-51598.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes service availability risk. Possible impact: The affected service may become unavailable or unreliable.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: An input validation vulnerability in the RTSP service of MERCURY MIPC252W IP Camera v1.0.5 Build 230306 Rel.79931n) allows an unauthenticated, network-adjacent attacker to cause a denial of service via a crafted DESCRIBE request with a malformed URL in the...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-51598/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-51599/",
      "current_public_safe_latest": false,
      "cvss_score": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.35036,
      "epss_score": 0.00433,
      "first_observed_at": "2026-07-16T16:44:59.414444+00:00",
      "id": "CVE-2026-51599",
      "impact_tags": [
        "remote exposure relevant"
      ],
      "kev": false,
      "last_observed_at": "2026-07-16T16:44:59.414444+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: An insufficient input validation vulnerability in the RTSP service of MERCURY MIPC252W v1.0.5 Build 230306 Rel.79931n allows an unauthenticated remote attacker to render an individual TCP connection temporarily unusable via sending an RTSP request with a... NVD: The affected RTSP parser enters a body-waiting state instead of rejecting the malformed request, causing all subsequent data on the connection to be silently consumed as body content until a server-side timeout closes the connection.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260716T164706Z/items/CVE-2026-51599.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes remote exposure. Possible impact: This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: An insufficient input validation vulnerability in the RTSP service of MERCURY MIPC252W v1.0.5 Build 230306 Rel.79931n allows an unauthenticated remote attacker to render an individual TCP connection temporarily unusable via sending an RTSP request with a... NVD: The affected RTSP parser enters a body-waiting state instead of rejecting the malformed request, causing all subsequent data on the connection to be silently consumed as body content until a server-side timeout closes the connection.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-51599/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-51600/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.32655,
      "epss_score": 0.00404,
      "first_observed_at": "2026-07-16T16:44:59.414444+00:00",
      "id": "CVE-2026-51600",
      "impact_tags": [
        "remote exposure relevant"
      ],
      "kev": false,
      "last_observed_at": "2026-07-16T16:44:59.414444+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Tenda CP3 V3.0 firmware V31.1.9.91 does not validate the Content-Length header field in RTSP requests (including DESCRIBE, SETUP, and PLAY methods). NVD: When a request carrying a Content-Length header is received without a corresponding message body, the RTSP parser enters a persistent body-awaiting state, causing the affected TCP connection to become permanently non-functional. NVD: The device does not actively close the connection, resulting in a TCP resource leak.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260716T164706Z/items/CVE-2026-51600.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes remote exposure. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Tenda CP3 V3.0 firmware V31.1.9.91 does not validate the Content-Length header field in RTSP requests (including DESCRIBE, SETUP, and PLAY methods). NVD: When a request carrying a Content-Length header is received without a corresponding message body, the RTSP parser enters a persistent body-awaiting state, causing the affected TCP connection to become permanently non-functional. NVD: The device does not actively close the connection, resulting in a TCP resource leak.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-51600/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-51601/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.33171,
      "epss_score": 0.0041,
      "first_observed_at": "2026-07-16T16:44:59.414444+00:00",
      "id": "CVE-2026-51601",
      "impact_tags": [
        "memory safety review",
        "remote exposure relevant"
      ],
      "kev": false,
      "last_observed_at": "2026-07-16T16:44:59.414444+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Tenda CP3 V3.0 firmware V31.1.9.91 contains a stack-based buffer overflow in the RTSP service. NVD: The device fails to validate the length of the clock= value in the Range header field when processing a PLAY request. NVD: An unauthenticated remote attacker who has completed a standard RTSP session handshake can send a PLAY request with an excessively long clock= value to cause the RTSP service to crash.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260716T164706Z/items/CVE-2026-51601.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes memory safety review · remote exposure. Possible impact: The affected component has memory-safety risk that may lead to crash, privilege, or code-execution impact depending on exposure.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Tenda CP3 V3.0 firmware V31.1.9.91 contains a stack-based buffer overflow in the RTSP service. NVD: The device fails to validate the length of the clock= value in the Range header field when processing a PLAY request. NVD: An unauthenticated remote attacker who has completed a standard RTSP session handshake can send a PLAY request with an excessively long clock= value to cause the RTSP service to crash.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-51601/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-51602/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.32497,
      "epss_score": 0.00402,
      "first_observed_at": "2026-07-16T16:44:59.414444+00:00",
      "id": "CVE-2026-51602",
      "impact_tags": [
        "service availability review",
        "memory safety review",
        "remote exposure relevant"
      ],
      "kev": false,
      "last_observed_at": "2026-07-16T16:44:59.414444+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A stack-based buffer overflow vulnerability in the RTSP service of Tenda CP3 V3.0 (firmware V31.1.9.91) allows an unauthenticated remote attacker to cause a denial of service via a crafted SETUP request. NVD: The RTSP service's second-stage URL routing parser fails to validate the length of the URL field in the first SETUP request. NVD: By supplying a URL consisting of exactly four consecutive repetitions of a valid RTSP URL, an attacker can bypass first-stage format validation and trigger a stack buffer overflow, causing an immediate crash of the RTSP service process and rendering the...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260716T164706Z/items/CVE-2026-51602.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes service availability risk · memory safety review · remote exposure. Possible impact: The affected service may become unavailable or unreliable.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A stack-based buffer overflow vulnerability in the RTSP service of Tenda CP3 V3.0 (firmware V31.1.9.91) allows an unauthenticated remote attacker to cause a denial of service via a crafted SETUP request. NVD: The RTSP service's second-stage URL routing parser fails to validate the length of the URL field in the first SETUP request. NVD: By supplying a URL consisting of exactly four consecutive repetitions of a valid RTSP URL, an attacker can bypass first-stage format validation and trigger a stack buffer overflow, causing an immediate crash of the RTSP service process and rendering the...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-51602/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-51603/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.33258,
      "epss_score": 0.00411,
      "first_observed_at": "2026-07-16T16:44:59.414444+00:00",
      "id": "CVE-2026-51603",
      "impact_tags": [
        "service availability review",
        "memory safety review",
        "remote exposure relevant"
      ],
      "kev": false,
      "last_observed_at": "2026-07-16T16:44:59.414444+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A stack-based buffer overflow vulnerability in the RTSP service of Tenda CP3 V3.0 (firmware V31.1.9.91) allows an unauthenticated remote attacker to cause a denial of service via a crafted second SETUP request. NVD: After completing the OPTIONS, DESCRIBE, and a legitimate first SETUP request to obtain a valid session ID, the RTSP service's second-stage URL routing parser fails to validate the length of the URL field in the subsequent SETUP request. NVD: By supplying a URL consisting of exactly four consecutive repetitions of a valid RTSP URL, an attacker can bypass first-stage format validation and trigger a stack buffer overflow, causing an immediate crash of the RTSP service process and rendering the...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260716T164706Z/items/CVE-2026-51603.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes service availability risk · memory safety review · remote exposure. Possible impact: The affected service may become unavailable or unreliable.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A stack-based buffer overflow vulnerability in the RTSP service of Tenda CP3 V3.0 (firmware V31.1.9.91) allows an unauthenticated remote attacker to cause a denial of service via a crafted second SETUP request. NVD: After completing the OPTIONS, DESCRIBE, and a legitimate first SETUP request to obtain a valid session ID, the RTSP service's second-stage URL routing parser fails to validate the length of the URL field in the subsequent SETUP request. NVD: By supplying a URL consisting of exactly four consecutive repetitions of a valid RTSP URL, an attacker can bypass first-stage format validation and trigger a stack buffer overflow, causing an immediate crash of the RTSP service process and rendering the...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-51603/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-51604/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.33171,
      "epss_score": 0.0041,
      "first_observed_at": "2026-07-16T16:44:59.414444+00:00",
      "id": "CVE-2026-51604",
      "impact_tags": [
        "service availability review",
        "memory safety review",
        "remote exposure relevant"
      ],
      "kev": false,
      "last_observed_at": "2026-07-16T16:44:59.414444+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A stack-based buffer overflow vulnerability in the RTSP service of Tenda CP3 V3.0 (firmware V31.1.9.91) allows an unauthenticated remote attacker to cause a denial of service via a crafted PLAY request.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260716T164706Z/items/CVE-2026-51604.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes service availability risk · memory safety review · remote exposure. Possible impact: The affected service may become unavailable or unreliable.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A stack-based buffer overflow vulnerability in the RTSP service of Tenda CP3 V3.0 (firmware V31.1.9.91) allows an unauthenticated remote attacker to cause a denial of service via a crafted PLAY request.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-51604/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-51605/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.33171,
      "epss_score": 0.0041,
      "first_observed_at": "2026-07-16T16:44:59.414444+00:00",
      "id": "CVE-2026-51605",
      "impact_tags": [
        "service availability review",
        "memory safety review",
        "remote exposure relevant"
      ],
      "kev": false,
      "last_observed_at": "2026-07-16T16:44:59.414444+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A stack-based buffer overflow vulnerability in the RTSP service of Tenda CP3 V3.0 (firmware V31.1.9.991) allows an unauthenticated remote attacker to cause a denial of service via a crafted TEARDOWN request.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260716T164706Z/items/CVE-2026-51605.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes service availability risk · memory safety review · remote exposure. Possible impact: The affected service may become unavailable or unreliable.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A stack-based buffer overflow vulnerability in the RTSP service of Tenda CP3 V3.0 (firmware V31.1.9.991) allows an unauthenticated remote attacker to cause a denial of service via a crafted TEARDOWN request.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-51605/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-51606/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.24497,
      "epss_score": 0.00324,
      "first_observed_at": "2026-07-16T16:44:59.414444+00:00",
      "id": "CVE-2026-51606",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-16T16:44:59.414444+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: An improper input handling vulnerability in the RTSP service of Tenda CP3 V3.0 (firmware V31.1.9.91) causes the device to abruptly terminate the TCP connection with a RST packet when a request containing an oversized field value is received, without returning... NVD: This behavior affects the request-line URL field and header field values across multiple RTSP request types.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260716T164706Z/items/CVE-2026-51606.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: An improper input handling vulnerability in the RTSP service of Tenda CP3 V3.0 (firmware V31.1.9.91) causes the device to abruptly terminate the TCP connection with a RST packet when a request containing an oversized field value is received, without returning... NVD: This behavior affects the request-line URL field and header field values across multiple RTSP request types.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-51606/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-51821/",
      "current_public_safe_latest": false,
      "cvss_score": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.41154,
      "epss_score": 0.00527,
      "first_observed_at": "2026-07-20T22:16:32.807845+00:00",
      "id": "CVE-2026-51821",
      "impact_tags": [
        "code execution review",
        "SQL injection risk",
        "remote exposure relevant"
      ],
      "kev": false,
      "last_observed_at": "2026-07-20T22:16:32.807845+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: SQL Injection vulnerability in Shenzhou Shihan Video Conference System v.1.0 allows a remote attacker to execute arbitrary code via the /user/getUserLogin endpoint",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260720T222315Z/items/CVE-2026-51821.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes code execution review · SQL injection risk · remote exposure. Possible impact: A remote attacker may be able to run code or commands on affected systems.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: SQL Injection vulnerability in Shenzhou Shihan Video Conference System v.1.0 allows a remote attacker to execute arbitrary code via the /user/getUserLogin endpoint",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-51821/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-51937/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.27097,
      "epss_score": 0.0035,
      "first_observed_at": "2026-07-14T22:16:58.989760+00:00",
      "id": "CVE-2026-51937",
      "impact_tags": [
        "information exposure review",
        "remote exposure relevant"
      ],
      "kev": false,
      "last_observed_at": "2026-07-14T22:16:58.989760+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: An issue in Oneblog V2.3.9 allows a remote attacker to obtain sensitive information via the RestApiController.java, JsApiTicketComponent.java, and the GetAccessTokenComponent.java component",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260714T222111Z/items/CVE-2026-51937.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes information exposure review · remote exposure. Possible impact: A remote attacker may be able to access information that should not be exposed.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: An issue in Oneblog V2.3.9 allows a remote attacker to obtain sensitive information via the RestApiController.java, JsApiTicketComponent.java, and the GetAccessTokenComponent.java component",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-51937/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-51953/",
      "current_public_safe_latest": false,
      "cvss_score": 7.4,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.19787,
      "epss_score": 0.00276,
      "first_observed_at": "2026-08-07T21:58:42.606809+00:00",
      "id": "CVE-2026-51953",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-07T21:58:42.606809+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: An issue in FeehiCMS v.2.1.1 allows an attacker to escalate privileges via the Session management module, authentication logic, logout handler components",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260807T220457Z/items/CVE-2026-51953.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: An issue in FeehiCMS v.2.1.1 allows an attacker to escalate privileges via the Session management module, authentication logic, logout handler components",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-51953/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-51992/",
      "current_public_safe_latest": false,
      "cvss_score": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.40989,
      "epss_score": 0.00515,
      "first_observed_at": "2026-08-05T16:55:08.588478+00:00",
      "id": "CVE-2026-51992",
      "impact_tags": [
        "code execution review",
        "SQL injection risk",
        "remote exposure relevant"
      ],
      "kev": false,
      "last_observed_at": "2026-08-05T16:55:08.588478+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: SQL Injection vulnerability in ClickHouse Server Versions <= 26.3.9.8 allows a remote attacker to execute arbitrary code via the create dictionaries function.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260805T165944Z/items/CVE-2026-51992.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes code execution review · SQL injection risk · remote exposure. Possible impact: A remote attacker may be able to run code or commands on affected systems.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: SQL Injection vulnerability in ClickHouse Server Versions <= 26.3.9.8 allows a remote attacker to execute arbitrary code via the create dictionaries function.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-51992/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-52134/",
      "current_public_safe_latest": false,
      "cvss_score": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.53153,
      "epss_score": 0.008,
      "first_observed_at": "2026-08-07T21:58:42.606809+00:00",
      "id": "CVE-2026-52134",
      "impact_tags": [
        "authentication boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-07T21:58:42.606809+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: An issue in the parseGoosePayload() function (/goose/goose_receiver.c) of libiec61850 v1.6 allows attackers to bypass authentication via a captured GOOSE frame.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260807T220457Z/items/CVE-2026-52134.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes authentication boundary review. Possible impact: This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authentication boundary review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: An issue in the parseGoosePayload() function (/goose/goose_receiver.c) of libiec61850 v1.6 allows attackers to bypass authentication via a captured GOOSE frame.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-52134/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-52200/",
      "current_public_safe_latest": false,
      "cvss_score": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.40331,
      "epss_score": 0.00515,
      "first_observed_at": "2026-07-15T22:16:59.245057+00:00",
      "id": "CVE-2026-52200",
      "impact_tags": [
        "code execution review",
        "remote exposure relevant"
      ],
      "kev": false,
      "last_observed_at": "2026-07-15T22:16:59.245057+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: An issue in Generic OEM UZ801_v2.1 4G LTE Router V3.4.3 allows a remote attacker to execute arbitrary code via the /ajax web management API endpoint in MifiService.apk",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260715T221956Z/items/CVE-2026-52200.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes code execution review · remote exposure. Possible impact: A remote attacker may be able to run code or commands on affected systems.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: An issue in Generic OEM UZ801_v2.1 4G LTE Router V3.4.3 allows a remote attacker to execute arbitrary code via the /ajax web management API endpoint in MifiService.apk",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-52200/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-52232/",
      "current_public_safe_latest": false,
      "cvss_score": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.04558,
      "epss_score": 0.00149,
      "first_observed_at": "2026-08-07T21:58:42.606809+00:00",
      "id": "CVE-2026-52232",
      "impact_tags": [
        "XSS risk"
      ],
      "kev": false,
      "last_observed_at": "2026-08-07T21:58:42.606809+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A reflected cross-site scripting (XSS) vulnerability in the /logo.asp component of FS Inc S3150-8T2F Switch 2.2.0D Build 118101 allows attackers to execute arbitrary Javascript in the context of the victim's browser via a crafted URL.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260807T220457Z/items/CVE-2026-52232.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes XSS risk. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A reflected cross-site scripting (XSS) vulnerability in the /logo.asp component of FS Inc S3150-8T2F Switch 2.2.0D Build 118101 allows attackers to execute arbitrary Javascript in the context of the victim's browser via a crafted URL.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-52232/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-52349/",
      "current_public_safe_latest": false,
      "cvss_score": 7.8,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.16789,
      "epss_score": 0.00253,
      "first_observed_at": "2026-07-27T12:38:45.912501+00:00",
      "id": "CVE-2026-52349",
      "impact_tags": [
        "code execution review",
        "path traversal review",
        "local exposure relevant"
      ],
      "kev": false,
      "last_observed_at": "2026-07-27T12:38:45.912501+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Directory Traversal vulnerability in Menyoo 2.0 Versions before commit 729aa48: fixed in commit 729aa48 allows a local attacker to execute arbitrary code via the Spooner file management, VehicleSpawner save/folder/rename functionality, WeaponOptions... OSV: Directory Traversal vulnerability in Menyoo 2.0 Versions before commit 729aa48: fixed in commit 729aa48 allows a local attacker to execute arbitrary code via the Spooner file management, VehicleSpawner save/folder/rename functionality, WeaponOptions...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260727T124133Z/items/CVE-2026-52349.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes code execution review · path traversal review · local exposure. Possible impact: A local user may be able to run code or commands on affected systems.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: commit.",
      "source_published_summary": "NVD: Directory Traversal vulnerability in Menyoo 2.0 Versions before commit 729aa48: fixed in commit 729aa48 allows a local attacker to execute arbitrary code via the Spooner file management, VehicleSpawner save/folder/rename functionality, WeaponOptions... OSV: Directory Traversal vulnerability in Menyoo 2.0 Versions before commit 729aa48: fixed in commit 729aa48 allows a local attacker to execute arbitrary code via the Spooner file management, VehicleSpawner save/folder/rename functionality, WeaponOptions...",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-52349/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-52370/",
      "current_public_safe_latest": false,
      "cvss_score": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.0875,
      "epss_score": 0.00189,
      "first_observed_at": "2026-08-11T22:08:35.096641+00:00",
      "id": "CVE-2026-52370",
      "impact_tags": [
        "XSS risk"
      ],
      "kev": false,
      "last_observed_at": "2026-08-11T22:08:35.096641+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A reflected cross-site scripting (XSS) vulnerability in the Forum posting function of O2OA v10 allows attackers to execute arbitrary Javascript in the context of the victim's browser via a crafted URL.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260811T221806Z/items/CVE-2026-52370.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes XSS risk. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A reflected cross-site scripting (XSS) vulnerability in the Forum posting function of O2OA v10 allows attackers to execute arbitrary Javascript in the context of the victim's browser via a crafted URL.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-52370/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-52371/",
      "current_public_safe_latest": false,
      "cvss_score": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.13089,
      "epss_score": 0.00224,
      "first_observed_at": "2026-08-07T21:58:42.606809+00:00",
      "id": "CVE-2026-52371",
      "impact_tags": [
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-07T21:58:42.606809+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A Server-Side Request Forgery (SSRF) in the xxl-job-admin/jobinfo/trigger component of xxl-job v3.4.0 allows authenticated attackers to scan resources via supplying a crafted HTTP request.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260807T220457Z/items/CVE-2026-52371.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A Server-Side Request Forgery (SSRF) in the xxl-job-admin/jobinfo/trigger component of xxl-job v3.4.0 allows authenticated attackers to scan resources via supplying a crafted HTTP request.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-52371/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-52533/",
      "current_public_safe_latest": false,
      "cvss_score": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.33689,
      "epss_score": 0.00414,
      "first_observed_at": "2026-07-20T22:16:32.807845+00:00",
      "id": "CVE-2026-52533",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-20T22:16:32.807845+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: An issue in D-Link DIR-1253 v.1.0.1.250923.142435 allows an attacker to escalate privileges via the etc/shadow component file",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260720T222315Z/items/CVE-2026-52533.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: An issue in D-Link DIR-1253 v.1.0.1.250923.142435 allows an attacker to escalate privileges via the etc/shadow component file",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-52533/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-52684/",
      "current_public_safe_latest": false,
      "cvss_score": 3.7,
      "cvss_severity": "LOW",
      "epss_percentile": 0.04039,
      "epss_score": 0.00143,
      "first_observed_at": "2026-07-30T06:01:44.452906+00:00",
      "id": "CVE-2026-52684",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-30T06:01:44.452906+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: If the auth responds very slowly and the records expire in between, the capping of TTLs is not enforced for lack of data. NVD: This does not happen on regular resolve as then then the child records are used immediately if not expired and thus valid, or the records are expired, and in that case not used. NVD: So this case can only happen if almost expired records are used to refresh the authoritative NS records.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260730T060504Z/items/CVE-2026-52684.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: If the auth responds very slowly and the records expire in between, the capping of TTLs is not enforced for lack of data. NVD: This does not happen on regular resolve as then then the child records are used immediately if not expired and thus valid, or the records are expired, and in that case not used. NVD: So this case can only happen if almost expired records are used to refresh the authoritative NS records.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-52684/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-52791/",
      "current_public_safe_latest": false,
      "cvss_score": 2.0,
      "cvss_severity": "LOW",
      "epss_percentile": 0.01111,
      "epss_score": 0.00102,
      "first_observed_at": "2026-08-05T16:55:08.588478+00:00",
      "id": "CVE-2026-52791",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-05T16:55:08.588478+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: fuse-overlayfs is an implementation of overlayfs in FUSE for rootless containers. NVD: Prior to 1.17, the release-1.x C branch preserves SUID and SGID mode bits in main.c during open(O_TRUNC) and truncate handling on a copied-up file, allowing a low-privileged process to leave the upper-layer file with mode 4777. NVD: This issue is fixed in version 1.17.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260805T165944Z/items/CVE-2026-52791.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: fuse-overlayfs is an implementation of overlayfs in FUSE for rootless containers. NVD: Prior to 1.17, the release-1.x C branch preserves SUID and SGID mode bits in main.c during open(O_TRUNC) and truncate handling on a copied-up file, allowing a low-privileged process to leave the upper-layer file with mode 4777. NVD: This issue is fixed in version 1.17.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-52791/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-52842/",
      "current_public_safe_latest": false,
      "cvss_score": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.05752,
      "epss_score": 0.00161,
      "first_observed_at": "2026-07-22T16:52:32.770874+00:00",
      "id": "CVE-2026-52842",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-22T16:52:32.770874+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Lightpanda is a headless browser designed for AI and automation. NVD: Prior to 0.3.1, Lightpanda searched for @ across the entire URL string instead of only the authority component when computing a page origin, so a URL such as was fetched from attacker.com but treated as allowing a complete Same-Origin Policy bypass. NVD: This issue is fixed in version 0.3.1.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260722T165509Z/items/CVE-2026-52842.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: Lightpanda is a headless browser designed for AI and automation. NVD: Prior to 0.3.1, Lightpanda searched for @ across the entire URL string instead of only the authority component when computing a page origin, so a URL such as was fetched from attacker.com but treated as allowing a complete Same-Origin Policy bypass. NVD: This issue is fixed in version 0.3.1.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-52842/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-52843/",
      "current_public_safe_latest": false,
      "cvss_score": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.07091,
      "epss_score": 0.00174,
      "first_observed_at": "2026-07-22T16:52:32.770874+00:00",
      "id": "CVE-2026-52843",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-22T16:52:32.770874+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Lightpanda is a headless browser designed for AI and automation. NVD: Prior to 0.2.9, Lightpanda fetch() and XMLHttpRequest unconditionally attached session cookies to every HTTP request, ignoring credentials: omit, credentials: same-origin, credentials: include, and XMLHttpRequest.withCredentials, allowing an... NVD: This issue is fixed in version 0.2.9.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260722T165509Z/items/CVE-2026-52843.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: Lightpanda is a headless browser designed for AI and automation. NVD: Prior to 0.2.9, Lightpanda fetch() and XMLHttpRequest unconditionally attached session cookies to every HTTP request, ignoring credentials: omit, credentials: same-origin, credentials: include, and XMLHttpRequest.withCredentials, allowing an... NVD: This issue is fixed in version 0.2.9.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-52843/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-52857/",
      "current_public_safe_latest": false,
      "cvss_score": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.01644,
      "epss_score": 0.00113,
      "first_observed_at": "2026-08-07T16:11:58.676122+00:00",
      "id": "CVE-2026-52857",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-07T16:11:58.676122+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. NVD: Prior to 1.13.0, unbounded json, yaml, and xml configuration-file parsers in parser.go can process an oversized non-file parser configuration file and exhaust Wings process memory. NVD: This issue is fixed in version 1.13.0.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260807T162046Z/items/CVE-2026-52857.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. NVD: Prior to 1.13.0, unbounded json, yaml, and xml configuration-file parsers in parser.go can process an oversized non-file parser configuration file and exhaust Wings process memory. NVD: This issue is fixed in version 1.13.0.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-52857/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "Kernel",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-53359/",
      "current_public_safe_latest": false,
      "cvss_score": null,
      "cvss_severity": "UNKNOWN",
      "epss_percentile": 0.0732,
      "epss_score": 0.00176,
      "first_observed_at": "2026-07-11T05:56:01.167453+00:00",
      "id": "CVE-2026-53359",
      "impact_tags": [
        "memory safety review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-11T10:36:25.311321+00:00",
      "latest_item_url": null,
      "product": "Kernel",
      "public_safe_summary": "NVD: In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Fix shadow paging use-after-free due to unexpected role Commit 0cb2af2ea66ad (\"KVM: x86: Fix shadow paging use-after-free due to unexpected GFN\") fixed a shadow paging mismatch... NVD: The rmap_remove() call would miss entries created after the PDE change because the GFN of the leaf SPTE does not match the GFN of the struct kvm_mmu_page. NVD: A similar hole however remains if the modified PDE points to a non-leaf page.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260711T103806Z/items/CVE-2026-53359.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "vendor/product: Kernel; package/component: Kernel",
      "source_published_impact": "Source describes memory safety review. Possible impact: The affected component has memory-safety risk that may lead to crash, privilege, or code-execution impact depending on exposure.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Fix shadow paging use-after-free due to unexpected role Commit 0cb2af2ea66ad (\"KVM: x86: Fix shadow paging use-after-free due to unexpected GFN\") fixed a shadow paging mismatch... NVD: The rmap_remove() call would miss entries created after the PDE change because the GFN of the leaf SPTE does not match the GFN of the struct kvm_mmu_page. NVD: A similar hole however remains if the modified PDE points to a non-leaf page.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-53359/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "Kernel",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-53360/",
      "current_public_safe_latest": false,
      "cvss_score": null,
      "cvss_severity": "UNKNOWN",
      "epss_percentile": 0.18358,
      "epss_score": 0.00267,
      "first_observed_at": "2026-07-11T05:56:01.167453+00:00",
      "id": "CVE-2026-53360",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-11T10:36:25.311321+00:00",
      "latest_item_url": null,
      "product": "Kernel",
      "public_safe_summary": "NVD: In the Linux kernel, the following vulnerability has been resolved: KVM: SEV: Require in-GHCB scratch area if GHCB v2+ is in use As per the GHCB spec, when using GHCB v2+ require the software scratch area to reside in the GHCB's shared buffer. NVD: Note, things like Page State Change (PSC) requests _rely_ on this behavior, as the guest can't provide a length when making the request, i.e. NVD: Failure to force usage of the GHCB, and a slew of other flaws, lets a malicious SNP guest corrupt host kernel heap memory, and leak host heap layout information.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260711T103806Z/items/CVE-2026-53360.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "vendor/product: Kernel; package/component: Kernel",
      "source_published_impact": "This unknown severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: In the Linux kernel, the following vulnerability has been resolved: KVM: SEV: Require in-GHCB scratch area if GHCB v2+ is in use As per the GHCB spec, when using GHCB v2+ require the software scratch area to reside in the GHCB's shared buffer. NVD: Note, things like Page State Change (PSC) requests _rely_ on this behavior, as the guest can't provide a length when making the request, i.e. NVD: Failure to force usage of the GHCB, and a slew of other flaws, lets a malicious SNP guest corrupt host kernel heap memory, and leak host heap layout information.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-53360/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "Kernel",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-53361/",
      "current_public_safe_latest": false,
      "cvss_score": null,
      "cvss_severity": "UNKNOWN",
      "epss_percentile": 0.06739,
      "epss_score": 0.00171,
      "first_observed_at": "2026-07-11T05:56:01.167453+00:00",
      "id": "CVE-2026-53361",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-11T10:36:25.311321+00:00",
      "latest_item_url": null,
      "product": "Kernel",
      "public_safe_summary": "NVD: In the Linux kernel, the following vulnerability has been resolved: af_unix: Set gc_in_progress to true in unix_gc(). NVD: Igor Ushakov reported that unix_gc() could run with gc_in_progress being false if the work is scheduled while running: Thread 1 Thread 2 Thread 3 -------- -------- -------- unix_schedule_gc() unix_schedule_gc() - if (!gc_in_progress) - if (!gc_in_progress) |-... NVD: - queue_work() | | - gc_in_progress = false | | unix_gc() <---------------------------------------------' | ...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260711T103806Z/items/CVE-2026-53361.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "vendor/product: Kernel; package/component: Kernel",
      "source_published_impact": "This unknown severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: In the Linux kernel, the following vulnerability has been resolved: af_unix: Set gc_in_progress to true in unix_gc(). NVD: Igor Ushakov reported that unix_gc() could run with gc_in_progress being false if the work is scheduled while running: Thread 1 Thread 2 Thread 3 -------- -------- -------- unix_schedule_gc() unix_schedule_gc() - if (!gc_in_progress) - if (!gc_in_progress) |-... NVD: - queue_work() | | - gc_in_progress = false | | unix_gc() <---------------------------------------------' | ...",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-53361/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "Kernel",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-53362/",
      "current_public_safe_latest": false,
      "cvss_score": null,
      "cvss_severity": "UNKNOWN",
      "epss_percentile": 0.07304,
      "epss_score": 0.00176,
      "first_observed_at": "2026-07-11T05:56:01.167453+00:00",
      "id": "CVE-2026-53362",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-11T10:36:25.311321+00:00",
      "latest_item_url": null,
      "product": "Kernel",
      "public_safe_summary": "NVD: In the Linux kernel, the following vulnerability has been resolved: ipv6: account for fraggap on the paged allocation path In __ip6_append_data(), when the paged-allocation branch is taken (MSG_MORE / NETIF_F_SG / large fraglen), alloclen and pagedlen are... NVD: When fraggap is non-zero, this is not the first skb and transhdrlen is zero. NVD: The fraggap bytes carried over from the previous skb are copied just past the fragment headers in the new skb's linear area.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260711T103806Z/items/CVE-2026-53362.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "vendor/product: Kernel; package/component: Kernel",
      "source_published_impact": "This unknown severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: In the Linux kernel, the following vulnerability has been resolved: ipv6: account for fraggap on the paged allocation path In __ip6_append_data(), when the paged-allocation branch is taken (MSG_MORE / NETIF_F_SG / large fraglen), alloclen and pagedlen are... NVD: When fraggap is non-zero, this is not the first skb and transhdrlen is zero. NVD: The fraggap bytes carried over from the previous skb are copied just past the fragment headers in the new skb's linear area.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-53362/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "Kernel",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-53363/",
      "current_public_safe_latest": false,
      "cvss_score": null,
      "cvss_severity": "UNKNOWN",
      "epss_percentile": 0.01555,
      "epss_score": 0.00111,
      "first_observed_at": "2026-07-17T10:59:18.822206+00:00",
      "id": "CVE-2026-53363",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-17T10:59:18.822206+00:00",
      "latest_item_url": null,
      "product": "Kernel",
      "public_safe_summary": "NVD: In the Linux kernel, the following vulnerability has been resolved: xfrm: iptfs: preserve shared-frag marker in iptfs_consume_frags() iptfs_consume_frags() transfers paged fragments from one socket buffer to another but fails to propagate the... NVD: This is the same class of bug that was fixed in skb_try_coalesce() for CVE-2026-46300: when fragments backed by read-only page-cache pages are merged, the marker indicating their shared nature must be preserved so that ESP can decide correctly whether... NVD: Apply the same two-line fix used in skb_try_coalesce() to iptfs_consume_frags().",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260717T110142Z/items/CVE-2026-53363.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: Kernel; package/component: Kernel",
      "source_published_impact": "This unknown severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: skb_try_coalesce.",
      "source_published_summary": "NVD: In the Linux kernel, the following vulnerability has been resolved: xfrm: iptfs: preserve shared-frag marker in iptfs_consume_frags() iptfs_consume_frags() transfers paged fragments from one socket buffer to another but fails to propagate the... NVD: This is the same class of bug that was fixed in skb_try_coalesce() for CVE-2026-46300: when fragments backed by read-only page-cache pages are merged, the marker indicating their shared nature must be preserved so that ESP can decide correctly whether... NVD: Apply the same two-line fix used in skb_try_coalesce() to iptfs_consume_frags().",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-53363/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "Kernel",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-53364/",
      "current_public_safe_latest": false,
      "cvss_score": null,
      "cvss_severity": "UNKNOWN",
      "epss_percentile": 0.05074,
      "epss_score": 0.00155,
      "first_observed_at": "2026-07-20T11:59:42.107493+00:00",
      "id": "CVE-2026-53364",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-20T11:59:42.107493+00:00",
      "latest_item_url": null,
      "product": "Kernel",
      "public_safe_summary": "NVD: In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_conn: Fix memory leak in hci_le_big_terminate() hci_le_big_terminate() allocates iso_list_data via kzalloc_obj but returns 0 without freeing it when neither pa_sync_term nor... NVD: This early-return path was introduced when hci_le_big_terminate() was refactored to take struct hci_conn instead of raw u8 parameters, adding PA/BIG flag evaluation logic. NVD: The existing kfree() on hci_cmd_sync_queue failure does not cover this path.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260720T120206Z/items/CVE-2026-53364.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: Kernel; package/component: Kernel",
      "source_published_impact": "This unknown severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_conn: Fix memory leak in hci_le_big_terminate() hci_le_big_terminate() allocates iso_list_data via kzalloc_obj but returns 0 without freeing it when neither pa_sync_term nor... NVD: This early-return path was introduced when hci_le_big_terminate() was refactored to take struct hci_conn instead of raw u8 parameters, adding PA/BIG flag evaluation logic. NVD: The existing kfree() on hci_cmd_sync_queue failure does not cover this path.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-53364/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "Kernel",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-53365/",
      "current_public_safe_latest": false,
      "cvss_score": null,
      "cvss_severity": "UNKNOWN",
      "epss_percentile": 0.05092,
      "epss_score": 0.00155,
      "first_observed_at": "2026-07-20T11:59:42.107493+00:00",
      "id": "CVE-2026-53365",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-20T11:59:42.107493+00:00",
      "latest_item_url": null,
      "product": "Kernel",
      "public_safe_summary": "NVD: In the Linux kernel, the following vulnerability has been resolved: vsock/virtio: fix zerocopy completion for multi-skb sends When a large message is fragmented into multiple skbs, the zerocopy uarg is only allocated and attached to the last skb in the loop. NVD: Non-final skbs carry pinned user pages with no completion tracking, so the kernel has no way to notify userspace when those pages are safe to reuse. NVD: If the loop breaks early the uarg is never allocated at all, leaking pinned pages with no completion notification.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260720T120206Z/items/CVE-2026-53365.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: Kernel; package/component: Kernel",
      "source_published_impact": "This unknown severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: In the Linux kernel, the following vulnerability has been resolved: vsock/virtio: fix zerocopy completion for multi-skb sends When a large message is fragmented into multiple skbs, the zerocopy uarg is only allocated and attached to the last skb in the loop. NVD: Non-final skbs carry pinned user pages with no completion tracking, so the kernel has no way to notify userspace when those pages are safe to reuse. NVD: If the loop breaks early the uarg is never allocated at all, leaking pinned pages with no completion notification.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-53365/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "linux / linux_kernel",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-53366/",
      "current_public_safe_latest": false,
      "cvss_score": 7.8,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.05212,
      "epss_score": 0.00156,
      "first_observed_at": "2026-07-23T06:13:21.015514+00:00",
      "id": "CVE-2026-53366",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-23T06:13:21.015514+00:00",
      "latest_item_url": null,
      "product": "linux_kernel",
      "public_safe_summary": "NVD: In the Linux kernel, the following vulnerability has been resolved: ipv4: account for fraggap on the paged allocation path In __ip_append_data(), when the paged-allocation branch is taken, alloclen and pagedlen are computed as alloclen = fragheaderlen +... NVD: The linear area is therefore undersized by fraggap bytes while pagedlen is overstated by the same amount. NVD: The non-paged branch sets alloclen to fraglen, which already accounts for fraggap because datalen does.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260723T061547Z/items/CVE-2026-53366.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: linux / linux_kernel; package/component: Kernel",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: In the Linux kernel, the following vulnerability has been resolved: ipv4: account for fraggap on the paged allocation path In __ip_append_data(), when the paged-allocation branch is taken, alloclen and pagedlen are computed as alloclen = fragheaderlen +... NVD: The linear area is therefore undersized by fraggap bytes while pagedlen is overstated by the same amount. NVD: The non-paged branch sets alloclen to fraglen, which already accounts for fraggap because datalen does.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-53366/timeline.json",
      "vendor": "linux"
    },
    {
      "affected_label": "Kernel",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-53367/",
      "current_public_safe_latest": false,
      "cvss_score": null,
      "cvss_severity": "UNKNOWN",
      "epss_percentile": 0.0512,
      "epss_score": 0.00155,
      "first_observed_at": "2026-07-26T06:17:48.937613+00:00",
      "id": "CVE-2026-53367",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-26T06:17:48.937613+00:00",
      "latest_item_url": null,
      "product": "Kernel",
      "public_safe_summary": "NVD: In the Linux kernel, the following vulnerability has been resolved: selinux: fix avdcache auditing The per-task avdcache was incorrectly saving and reusing the audited vector computed by avc_audit_required() rather than recomputing based on the currently... NVD: As a result, some permission checks were not being audited, e.g. NVD: directory write checks after a previously cached directory search check.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260726T062024Z/items/CVE-2026-53367.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: Kernel; package/component: Kernel",
      "source_published_impact": "This unknown severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: In the Linux kernel, the following vulnerability has been resolved: selinux: fix avdcache auditing The per-task avdcache was incorrectly saving and reusing the audited vector computed by avc_audit_required() rather than recomputing based on the currently... NVD: As a result, some permission checks were not being audited, e.g. NVD: directory write checks after a previously cached directory search check.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-53367/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "Kernel",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-53368/",
      "current_public_safe_latest": false,
      "cvss_score": 7.1,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.01879,
      "epss_score": 0.00116,
      "first_observed_at": "2026-07-26T06:17:48.937613+00:00",
      "id": "CVE-2026-53368",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-26T06:17:48.937613+00:00",
      "latest_item_url": null,
      "product": "Kernel",
      "public_safe_summary": "NVD: In the Linux kernel, the following vulnerability has been resolved: f2fs: fix fsck inconsistency caused by incorrect nat_entry flag usage f2fs_need_dentry_mark() reads nat_entry flags without mutual exclusion with the checkpoint path, which can result in an... NVD: The root cause is that the semantics of IS_CHECKPOINTED and HAS_FSYNCED_INODE are only guaranteed after the checkpoint write has fully completed. NVD: This patch moves set_dentry_mark() into __write_node_folio() and protects it with the sbi->node_write lock.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260726T062024Z/items/CVE-2026-53368.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: Kernel; package/component: Kernel",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: In the Linux kernel, the following vulnerability has been resolved: f2fs: fix fsck inconsistency caused by incorrect nat_entry flag usage f2fs_need_dentry_mark() reads nat_entry flags without mutual exclusion with the checkpoint path, which can result in an... NVD: The root cause is that the semantics of IS_CHECKPOINTED and HAS_FSYNCED_INODE are only guaranteed after the checkpoint write has fully completed. NVD: This patch moves set_dentry_mark() into __write_node_folio() and protects it with the sbi->node_write lock.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-53368/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "Kernel",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-53369/",
      "current_public_safe_latest": false,
      "cvss_score": 8.4,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.03699,
      "epss_score": 0.00139,
      "first_observed_at": "2026-07-26T06:17:48.937613+00:00",
      "id": "CVE-2026-53369",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-26T06:17:48.937613+00:00",
      "latest_item_url": null,
      "product": "Kernel",
      "public_safe_summary": "NVD: In the Linux kernel, the following vulnerability has been resolved: udf: reject descriptors with oversized CRC length udf_read_tagged() skips CRC verification when descCRCLength + sizeof(struct tag) exceeds the block size. NVD: A crafted UDF image can set descCRCLength to an oversized value to bypass CRC validation entirely; the descriptor is then accepted based solely on the 8-bit tag checksum, which is trivially recomputable. NVD: Reject such descriptors instead of silently accepting them.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260726T062024Z/items/CVE-2026-53369.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: Kernel; package/component: Kernel",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: In the Linux kernel, the following vulnerability has been resolved: udf: reject descriptors with oversized CRC length udf_read_tagged() skips CRC verification when descCRCLength + sizeof(struct tag) exceeds the block size. NVD: A crafted UDF image can set descCRCLength to an oversized value to bypass CRC validation entirely; the descriptor is then accepted based solely on the 8-bit tag checksum, which is trivially recomputable. NVD: Reject such descriptors instead of silently accepting them.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-53369/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "Kernel",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-53370/",
      "current_public_safe_latest": false,
      "cvss_score": null,
      "cvss_severity": "UNKNOWN",
      "epss_percentile": 0.05118,
      "epss_score": 0.00155,
      "first_observed_at": "2026-07-26T06:17:48.937613+00:00",
      "id": "CVE-2026-53370",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-26T06:17:48.937613+00:00",
      "latest_item_url": null,
      "product": "Kernel",
      "public_safe_summary": "NVD: In the Linux kernel, the following vulnerability has been resolved: perf/x86/intel: Improve validation and configuration of ACR masks Currently there are several issues on the user space ACR mask validation and configuration. NVD: - The validation for user space ACR mask (attr.config2) is incomplete, e.g., the ACR mask could include the index which belongs to another ACR events group, but it's not validated. NVD: - An early return on an invalid ACR mask caused all subsequent ACR groups to be skipped.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260726T062024Z/items/CVE-2026-53370.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: Kernel; package/component: Kernel",
      "source_published_impact": "This unknown severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: In the Linux kernel, the following vulnerability has been resolved: perf/x86/intel: Improve validation and configuration of ACR masks Currently there are several issues on the user space ACR mask validation and configuration. NVD: - The validation for user space ACR mask (attr.config2) is incomplete, e.g., the ACR mask could include the index which belongs to another ACR events group, but it's not validated. NVD: - An early return on an invalid ACR mask caused all subsequent ACR groups to be skipped.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-53370/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "Kernel",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-53371/",
      "current_public_safe_latest": false,
      "cvss_score": null,
      "cvss_severity": "UNKNOWN",
      "epss_percentile": 0.05105,
      "epss_score": 0.00155,
      "first_observed_at": "2026-07-26T06:17:48.937613+00:00",
      "id": "CVE-2026-53371",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-26T06:17:48.937613+00:00",
      "latest_item_url": null,
      "product": "Kernel",
      "public_safe_summary": "NVD: In the Linux kernel, the following vulnerability has been resolved: RDMA/ionic: bound node_desc sysfs read with %.64s node_desc[64] in struct ib_device is not guaranteed to be NUL- terminated. NVD: The core IB sysfs handler uses \"%.64s\" for exactly this reason (drivers/infiniband/core/sysfs.c:1307), since node_desc_store() performs a raw memcpy of up to IB_DEVICE_NODE_DESC_MAX bytes with no NUL termination: memcpy(desc.node_desc, buf, min_t(int, count... NVD: The ionic hca_type_show() handler uses unbounded \"%s\" and will read past the end of node_desc into adjacent fields of struct ib_device until it encounters a NUL.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260726T062024Z/items/CVE-2026-53371.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: Kernel; package/component: Kernel",
      "source_published_impact": "This unknown severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: In the Linux kernel, the following vulnerability has been resolved: RDMA/ionic: bound node_desc sysfs read with %.64s node_desc[64] in struct ib_device is not guaranteed to be NUL- terminated. NVD: The core IB sysfs handler uses \"%.64s\" for exactly this reason (drivers/infiniband/core/sysfs.c:1307), since node_desc_store() performs a raw memcpy of up to IB_DEVICE_NODE_DESC_MAX bytes with no NUL termination: memcpy(desc.node_desc, buf, min_t(int, count... NVD: The ionic hca_type_show() handler uses unbounded \"%s\" and will read past the end of node_desc into adjacent fields of struct ib_device until it encounters a NUL.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-53371/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "Kernel",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-53372/",
      "current_public_safe_latest": false,
      "cvss_score": null,
      "cvss_severity": "UNKNOWN",
      "epss_percentile": 0.05119,
      "epss_score": 0.00155,
      "first_observed_at": "2026-07-26T06:17:48.937613+00:00",
      "id": "CVE-2026-53372",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-26T06:17:48.937613+00:00",
      "latest_item_url": null,
      "product": "Kernel",
      "public_safe_summary": "NVD: In the Linux kernel, the following vulnerability has been resolved: iommu/vt-d: Block PASID attachment to nested domain with dirty tracking Kernel lacks dirty tracking support on nested domain attached to PASID, fails the attachment early if nesting parent... OSV: iommu/vt-d: Block PASID attachment to nested domain with dirty tracking OSV: In the Linux kernel, the following vulnerability has been resolved: iommu/vt-d: Block PASID attachment to nested domain with dirty tracking Kernel lacks dirty tracking support on nested domain attached to PASID, fails the attachment early if nesting parent...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260726T062024Z/items/CVE-2026-53372.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: Kernel; package/component: Kernel",
      "source_published_impact": "This unknown severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: In the Linux kernel, the following vulnerability has been resolved: iommu/vt-d: Block PASID attachment to nested domain with dirty tracking Kernel lacks dirty tracking support on nested domain attached to PASID, fails the attachment early if nesting parent... OSV: iommu/vt-d: Block PASID attachment to nested domain with dirty tracking OSV: In the Linux kernel, the following vulnerability has been resolved: iommu/vt-d: Block PASID attachment to nested domain with dirty tracking Kernel lacks dirty tracking support on nested domain attached to PASID, fails the attachment early if nesting parent...",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-53372/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "Kernel",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-53373/",
      "current_public_safe_latest": false,
      "cvss_score": 7.8,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.01613,
      "epss_score": 0.00112,
      "first_observed_at": "2026-07-26T06:17:48.937613+00:00",
      "id": "CVE-2026-53373",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-26T10:55:16.819709+00:00",
      "latest_item_url": null,
      "product": "Kernel",
      "public_safe_summary": "NVD: In the Linux kernel, the following vulnerability has been resolved: mm/vma: do not try to unmap a VMA if mmap_prepare() invoked from mmap() The mmap_prepare hook functionality includes the ability to invoke mmap_prepare() from the mmap() hook of existing... NVD: overlayfs, shm). NVD: As part of the mmap_prepare action functionality, we deal with errors by unmapping the VMA should one arise.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260726T110235Z/items/CVE-2026-53373.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "vendor/product: Kernel; package/component: Kernel",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: In the Linux kernel, the following vulnerability has been resolved: mm/vma: do not try to unmap a VMA if mmap_prepare() invoked from mmap() The mmap_prepare hook functionality includes the ability to invoke mmap_prepare() from the mmap() hook of existing... NVD: overlayfs, shm). NVD: As part of the mmap_prepare action functionality, we deal with errors by unmapping the VMA should one arise.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-53373/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "Kernel",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-53374/",
      "current_public_safe_latest": false,
      "cvss_score": 8.8,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.02185,
      "epss_score": 0.0012,
      "first_observed_at": "2026-07-26T06:17:48.937613+00:00",
      "id": "CVE-2026-53374",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-26T10:55:16.819709+00:00",
      "latest_item_url": null,
      "product": "Kernel",
      "public_safe_summary": "NVD: In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: zero-initialize GART table on allocation GART TLB is flushed after unmapping but not after mapping. NVD: Since amdgpu_bo_create_kernel() does not zero-initialize the buffer, when a single PTE is written the TLB may speculatively load other uninitialized entries from the same cacheline. NVD: Those garbage entries can appear valid, and a subsequent write to another PTE in the same cacheline may cause the GPU to use a stale garbage PTE from the TLB.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260726T110235Z/items/CVE-2026-53374.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "vendor/product: Kernel; package/component: Kernel",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: zero-initialize GART table on allocation GART TLB is flushed after unmapping but not after mapping. NVD: Since amdgpu_bo_create_kernel() does not zero-initialize the buffer, when a single PTE is written the TLB may speculatively load other uninitialized entries from the same cacheline. NVD: Those garbage entries can appear valid, and a subsequent write to another PTE in the same cacheline may cause the GPU to use a stale garbage PTE from the TLB.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-53374/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "Kernel",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-53375/",
      "current_public_safe_latest": false,
      "cvss_score": 8.8,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.02184,
      "epss_score": 0.0012,
      "first_observed_at": "2026-07-26T06:17:48.937613+00:00",
      "id": "CVE-2026-53375",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-26T10:55:16.819709+00:00",
      "latest_item_url": null,
      "product": "Kernel",
      "public_safe_summary": "NVD: In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/vce: Prevent partial address patches In the case that only one of lo/hi is valid, the patching could result in a bad address written to in FW. OSV: drm/amdgpu/vce: Prevent partial address patches OSV: In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/vce: Prevent partial address patches In the case that only one of lo/hi is valid, the patching could result in a bad address written to in FW.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260726T110235Z/items/CVE-2026-53375.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "vendor/product: Kernel; package/component: Kernel",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/vce: Prevent partial address patches In the case that only one of lo/hi is valid, the patching could result in a bad address written to in FW. OSV: drm/amdgpu/vce: Prevent partial address patches OSV: In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/vce: Prevent partial address patches In the case that only one of lo/hi is valid, the patching could result in a bad address written to in FW.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-53375/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "Kernel",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-53376/",
      "current_public_safe_latest": false,
      "cvss_score": null,
      "cvss_severity": "UNKNOWN",
      "epss_percentile": 0.0524,
      "epss_score": 0.00156,
      "first_observed_at": "2026-07-26T06:17:48.937613+00:00",
      "id": "CVE-2026-53376",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-26T10:55:16.819709+00:00",
      "latest_item_url": null,
      "product": "Kernel",
      "public_safe_summary": "NVD: In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: Add upper bound check for num_of_nodes drm/amdkfd: Add upper bound check for num_of_nodes in kfd_ioctl_get_process_apertures_new. NVD: (cherry picked from commit 98ff46a5ea090c14d2cdb4f5b993b05d74f3949f) OSV: drm/amdkfd: Add upper bound check for num_of_nodes",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260726T110235Z/items/CVE-2026-53376.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "vendor/product: Kernel; package/component: Kernel",
      "source_published_impact": "This unknown severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: Add upper bound check for num_of_nodes drm/amdkfd: Add upper bound check for num_of_nodes in kfd_ioctl_get_process_apertures_new. NVD: (cherry picked from commit 98ff46a5ea090c14d2cdb4f5b993b05d74f3949f) OSV: drm/amdkfd: Add upper bound check for num_of_nodes",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-53376/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "Kernel",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-53377/",
      "current_public_safe_latest": false,
      "cvss_score": null,
      "cvss_severity": "UNKNOWN",
      "epss_percentile": 0.05077,
      "epss_score": 0.00155,
      "first_observed_at": "2026-07-26T10:55:16.819709+00:00",
      "id": "CVE-2026-53377",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-26T10:55:16.819709+00:00",
      "latest_item_url": null,
      "product": "Kernel",
      "public_safe_summary": "NVD: In the Linux kernel, the following vulnerability has been resolved: drm/msm: always recover the gpu Previously, in case there was no more work to do, recover worker wouldn't trigger recovery and would instead rely on the gpu going to sleep and then resuming... NVD: Recover_worker will first increment the fence of the hung ring so, if there's only one job submitted to a ring and that causes an hang, it will early out. NVD: There's no guarantee that the gpu will suspend and resume before more work is submitted and if the gpu is in a hung state it will stay in that state and probably trigger a timeout again.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260726T110235Z/items/CVE-2026-53377.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: Kernel; package/component: Kernel",
      "source_published_impact": "This unknown severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: In the Linux kernel, the following vulnerability has been resolved: drm/msm: always recover the gpu Previously, in case there was no more work to do, recover worker wouldn't trigger recovery and would instead rely on the gpu going to sleep and then resuming... NVD: Recover_worker will first increment the fence of the hung ring so, if there's only one job submitted to a ring and that causes an hang, it will early out. NVD: There's no guarantee that the gpu will suspend and resume before more work is submitted and if the gpu is in a hung state it will stay in that state and probably trigger a timeout again.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-53377/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "Kernel",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-53378/",
      "current_public_safe_latest": false,
      "cvss_score": null,
      "cvss_severity": "UNKNOWN",
      "epss_percentile": 0.04238,
      "epss_score": 0.00145,
      "first_observed_at": "2026-07-26T10:55:16.819709+00:00",
      "id": "CVE-2026-53378",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-26T10:55:16.819709+00:00",
      "latest_item_url": null,
      "product": "Kernel",
      "public_safe_summary": "NVD: In the Linux kernel, the following vulnerability has been resolved: drm/colorop: Fix blob property reference tracking in state lifecycle The colorop state blob property handling had memory leaks during state duplication, destruction, and reset operations. NVD: The implementation failed to follow the established pattern from drm_crtc's handling of DEGAMMA/GAMMA blob properties. NVD: Issues fixed: - drm_colorop_atomic_destroy_state() was freeing state memory without releasing the blob reference, causing a leak - drm_colorop_reset() was directly freeing old state with kfree() instead of properly destroying it, leaking blob references -...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260726T110235Z/items/CVE-2026-53378.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: Kernel; package/component: Kernel",
      "source_published_impact": "This unknown severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: In the Linux kernel, the following vulnerability has been resolved: drm/colorop: Fix blob property reference tracking in state lifecycle The colorop state blob property handling had memory leaks during state duplication, destruction, and reset operations. NVD: The implementation failed to follow the established pattern from drm_crtc's handling of DEGAMMA/GAMMA blob properties. NVD: Issues fixed: - drm_colorop_atomic_destroy_state() was freeing state memory without releasing the blob reference, causing a leak - drm_colorop_reset() was directly freeing old state with kfree() instead of properly destroying it, leaking blob references -...",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-53378/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "Kernel",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-53379/",
      "current_public_safe_latest": false,
      "cvss_score": null,
      "cvss_severity": "UNKNOWN",
      "epss_percentile": 0.05674,
      "epss_score": 0.00161,
      "first_observed_at": "2026-07-26T10:55:16.819709+00:00",
      "id": "CVE-2026-53379",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-26T10:55:16.819709+00:00",
      "latest_item_url": null,
      "product": "Kernel",
      "public_safe_summary": "NVD: In the Linux kernel, the following vulnerability has been resolved: media: i2c: ov8856: free control handler on error in ov8856_init_controls() The control handler wasn't freed if adding controls failed, add an error exit label and convert the existing error... OSV: media: i2c: ov8856: free control handler on error in ov8856_init_controls() OSV: In the Linux kernel, the following vulnerability has been resolved: media: i2c: ov8856: free control handler on error in ov8856_init_controls() The control handler wasn't freed if adding controls failed, add an error exit label and convert the existing error...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260726T110235Z/items/CVE-2026-53379.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: Kernel; package/component: Kernel",
      "source_published_impact": "This unknown severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: In the Linux kernel, the following vulnerability has been resolved: media: i2c: ov8856: free control handler on error in ov8856_init_controls() The control handler wasn't freed if adding controls failed, add an error exit label and convert the existing error... OSV: media: i2c: ov8856: free control handler on error in ov8856_init_controls() OSV: In the Linux kernel, the following vulnerability has been resolved: media: i2c: ov8856: free control handler on error in ov8856_init_controls() The control handler wasn't freed if adding controls failed, add an error exit label and convert the existing error...",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-53379/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "Kernel",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-53380/",
      "current_public_safe_latest": false,
      "cvss_score": 7.8,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.01613,
      "epss_score": 0.00112,
      "first_observed_at": "2026-07-26T10:55:16.819709+00:00",
      "id": "CVE-2026-53380",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-26T10:55:16.819709+00:00",
      "latest_item_url": null,
      "product": "Kernel",
      "public_safe_summary": "NVD: In the Linux kernel, the following vulnerability has been resolved: media: rzv2h-ivc: Fix concurrent buffer list access The list of buffers (rzv2h_ivc::buffers.queue) is protected by a spinlock (rzv2h_ivc::buffers.lock). NVD: However, in rzv2h_ivc_transfer_buffer(), which runs in a separate workqueue, the list_del() call is executed without holding the spinlock, which makes it possible for the list to be concurrently modified Fix that by removing a buffer from the list in the lock... NVD: [assign ivc->buffers.curr in critical section as reported by Barnabas]",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260726T110235Z/items/CVE-2026-53380.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: Kernel; package/component: Kernel",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: In the Linux kernel, the following vulnerability has been resolved: media: rzv2h-ivc: Fix concurrent buffer list access The list of buffers (rzv2h_ivc::buffers.queue) is protected by a spinlock (rzv2h_ivc::buffers.lock). NVD: However, in rzv2h_ivc_transfer_buffer(), which runs in a separate workqueue, the list_del() call is executed without holding the spinlock, which makes it possible for the list to be concurrently modified Fix that by removing a buffer from the list in the lock... NVD: [assign ivc->buffers.curr in critical section as reported by Barnabas]",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-53380/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "Kernel",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-53381/",
      "current_public_safe_latest": false,
      "cvss_score": 7.8,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.03352,
      "epss_score": 0.00135,
      "first_observed_at": "2026-07-26T10:55:16.819709+00:00",
      "id": "CVE-2026-53381",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-26T10:55:16.819709+00:00",
      "latest_item_url": null,
      "product": "Kernel",
      "public_safe_summary": "NVD: In the Linux kernel, the following vulnerability has been resolved: virtiofs: fix UAF on submount umount iput() called from fuse_release_end() can Oops if the super block has already been destroyed. NVD: Normally this is prevented by waiting for num_waiting to go down to zero before commencing with super block shutdown. NVD: This only works, however, for the last submount instance, as the wait counter is per connection, not per superblock.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260726T110235Z/items/CVE-2026-53381.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: Kernel; package/component: Kernel",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: In the Linux kernel, the following vulnerability has been resolved: virtiofs: fix UAF on submount umount iput() called from fuse_release_end() can Oops if the super block has already been destroyed. NVD: Normally this is prevented by waiting for num_waiting to go down to zero before commencing with super block shutdown. NVD: This only works, however, for the last submount instance, as the wait counter is per connection, not per superblock.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-53381/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "Kernel",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-53382/",
      "current_public_safe_latest": false,
      "cvss_score": null,
      "cvss_severity": "UNKNOWN",
      "epss_percentile": 0.09473,
      "epss_score": 0.00195,
      "first_observed_at": "2026-07-26T10:55:16.819709+00:00",
      "id": "CVE-2026-53382",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-26T10:55:16.819709+00:00",
      "latest_item_url": null,
      "product": "Kernel",
      "public_safe_summary": "NVD: In the Linux kernel, the following vulnerability has been resolved: media: vidtv: fix NULL pointer dereference in vidtv_mux_push_si syzbot reported a general protection fault in vidtv_psi_ts_psi_write_into [1]. NVD: vidtv_mux_get_pid_ctx() can return NULL, but vidtv_mux_push_si() does not check for this before dereferencing the returned pointer to access the continuity counter. NVD: This leads to a general protection fault when accessing a near-NULL address.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260726T110235Z/items/CVE-2026-53382.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: Kernel; package/component: Kernel",
      "source_published_impact": "This unknown severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: In the Linux kernel, the following vulnerability has been resolved: media: vidtv: fix NULL pointer dereference in vidtv_mux_push_si syzbot reported a general protection fault in vidtv_psi_ts_psi_write_into [1]. NVD: vidtv_mux_get_pid_ctx() can return NULL, but vidtv_mux_push_si() does not check for this before dereferencing the returned pointer to access the continuity counter. NVD: This leads to a general protection fault when accessing a near-NULL address.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-53382/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "Kernel",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-53383/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.49033,
      "epss_score": 0.0069,
      "first_observed_at": "2026-07-26T10:55:16.819709+00:00",
      "id": "CVE-2026-53383",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-26T10:55:16.819709+00:00",
      "latest_item_url": null,
      "product": "Kernel",
      "public_safe_summary": "NVD: In the Linux kernel, the following vulnerability has been resolved: ksmbd: reject non-VALID session in compound request branch smb2_check_user_session() takes a shortcut for any operation that is not the first in a COMPOUND request: it reuses work->sess (the... NVD: It never re-checks work->sess->state == SMB2_SESSION_VALID, and a SessionId of 0xFFFFFFFFFFFFFFFF (ULLONG_MAX, the MS-SMB2 related-operation value) skips even the id comparison. NVD: The standalone path (ksmbd_session_lookup_all() plus the SESSION_SETUP state machine) does enforce the VALID state; the compound branch bypasses all of it.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260726T110235Z/items/CVE-2026-53383.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: Kernel; package/component: Kernel",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: In the Linux kernel, the following vulnerability has been resolved: ksmbd: reject non-VALID session in compound request branch smb2_check_user_session() takes a shortcut for any operation that is not the first in a COMPOUND request: it reuses work->sess (the... NVD: It never re-checks work->sess->state == SMB2_SESSION_VALID, and a SessionId of 0xFFFFFFFFFFFFFFFF (ULLONG_MAX, the MS-SMB2 related-operation value) skips even the id comparison. NVD: The standalone path (ksmbd_session_lookup_all() plus the SESSION_SETUP state machine) does enforce the VALID state; the compound branch bypasses all of it.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-53383/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "Kernel",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-53384/",
      "current_public_safe_latest": false,
      "cvss_score": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.39235,
      "epss_score": 0.00488,
      "first_observed_at": "2026-07-26T10:55:16.819709+00:00",
      "id": "CVE-2026-53384",
      "impact_tags": [
        "memory safety review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-26T10:55:16.819709+00:00",
      "latest_item_url": null,
      "product": "Kernel",
      "public_safe_summary": "NVD: In the Linux kernel, the following vulnerability has been resolved: serial: 8250_dw: unregister 8250 port if clk_notifier_register() fails dw8250_probe() registers the 8250 port via serial8250_register_8250_port() and then, if the device has a clock... NVD: If clk_notifier_register() fails, probe returns the error but leaves the 8250 port registered. NVD: The matching serial8250_unregister_port() lives in dw8250_remove(), which is not called when probe fails, so the port slot stays occupied until the device is rebound or the system is rebooted.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260726T110235Z/items/CVE-2026-53384.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: Kernel; package/component: Kernel",
      "source_published_impact": "Source describes memory safety review. Possible impact: The affected component has memory-safety risk that may lead to crash, privilege, or code-execution impact depending on exposure.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: In the Linux kernel, the following vulnerability has been resolved: serial: 8250_dw: unregister 8250 port if clk_notifier_register() fails dw8250_probe() registers the 8250 port via serial8250_register_8250_port() and then, if the device has a clock... NVD: If clk_notifier_register() fails, probe returns the error but leaves the 8250 port registered. NVD: The matching serial8250_unregister_port() lives in dw8250_remove(), which is not called when probe fails, so the port slot stays occupied until the device is rebound or the system is rebooted.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-53384/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "Kernel",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-53385/",
      "current_public_safe_latest": false,
      "cvss_score": null,
      "cvss_severity": "UNKNOWN",
      "epss_percentile": 0.09473,
      "epss_score": 0.00195,
      "first_observed_at": "2026-07-26T10:55:16.819709+00:00",
      "id": "CVE-2026-53385",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-26T10:55:16.819709+00:00",
      "latest_item_url": null,
      "product": "Kernel",
      "public_safe_summary": "NVD: In the Linux kernel, the following vulnerability has been resolved: vc_screen: fix null-ptr-deref in vcs_notifier() during concurrent vcs_write A KASAN null-ptr-deref was observed in vcs_notifier(): BUG: KASAN: null-ptr-deref in vcs_notifier+0x98/0x130 Read... NVD: When the console_lock is temporarily dropped (to copy data from userspace), the vc_data pointer obtained from vcs_vc() may become stale. NVD: After re-acquiring the lock, vcs_vc() is called again to re-validate the pointer.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260726T110235Z/items/CVE-2026-53385.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: Kernel; package/component: Kernel",
      "source_published_impact": "This unknown severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: In the Linux kernel, the following vulnerability has been resolved: vc_screen: fix null-ptr-deref in vcs_notifier() during concurrent vcs_write A KASAN null-ptr-deref was observed in vcs_notifier(): BUG: KASAN: null-ptr-deref in vcs_notifier+0x98/0x130 Read... NVD: When the console_lock is temporarily dropped (to copy data from userspace), the vc_data pointer obtained from vcs_vc() may become stale. NVD: After re-acquiring the lock, vcs_vc() is called again to re-validate the pointer.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-53385/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "Kernel",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-53386/",
      "current_public_safe_latest": false,
      "cvss_score": 7.8,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.02892,
      "epss_score": 0.00129,
      "first_observed_at": "2026-07-26T10:55:16.819709+00:00",
      "id": "CVE-2026-53386",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-26T10:55:16.819709+00:00",
      "latest_item_url": null,
      "product": "Kernel",
      "public_safe_summary": "NVD: In the Linux kernel, the following vulnerability has been resolved: iio: adc: ti-ads1298: add bounds check to pga_settings index ads1298_pga_settings has 7 elements but ADS1298_MASK_CH_PGA can yield values 0-7. NVD: If it yields a value >= 7, this causes an out-of-bounds array access. NVD: Add a bounds check and return -EINVAL if the index is out of range.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260726T110235Z/items/CVE-2026-53386.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: Kernel; package/component: Kernel",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: In the Linux kernel, the following vulnerability has been resolved: iio: adc: ti-ads1298: add bounds check to pga_settings index ads1298_pga_settings has 7 elements but ADS1298_MASK_CH_PGA can yield values 0-7. NVD: If it yields a value >= 7, this causes an out-of-bounds array access. NVD: Add a bounds check and return -EINVAL if the index is out of range.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-53386/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "Kernel",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-53387/",
      "current_public_safe_latest": false,
      "cvss_score": 7.1,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.02609,
      "epss_score": 0.00125,
      "first_observed_at": "2026-07-26T10:55:16.819709+00:00",
      "id": "CVE-2026-53387",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-26T10:55:16.819709+00:00",
      "latest_item_url": null,
      "product": "Kernel",
      "public_safe_summary": "NVD: In the Linux kernel, the following vulnerability has been resolved: iio: light: veml6075: add bounds check to veml6075_it_ms index veml6075_it_ms has 5 elements but VEML6075_CONF_IT can yield values 0-7. NVD: If it returns a value >= 5, this causes an out-of-bounds array access. NVD: Add a bounds check and return -EINVAL if the index is out of range.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260726T110235Z/items/CVE-2026-53387.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: Kernel; package/component: Kernel",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: In the Linux kernel, the following vulnerability has been resolved: iio: light: veml6075: add bounds check to veml6075_it_ms index veml6075_it_ms has 5 elements but VEML6075_CONF_IT can yield values 0-7. NVD: If it returns a value >= 5, this causes an out-of-bounds array access. NVD: Add a bounds check and return -EINVAL if the index is out of range.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-53387/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "Kernel",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-53388/",
      "current_public_safe_latest": false,
      "cvss_score": 7.8,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.02631,
      "epss_score": 0.00126,
      "first_observed_at": "2026-07-26T10:55:16.819709+00:00",
      "id": "CVE-2026-53388",
      "impact_tags": [
        "memory safety review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-26T10:55:16.819709+00:00",
      "latest_item_url": null,
      "product": "Kernel",
      "public_safe_summary": "NVD: In the Linux kernel, the following vulnerability has been resolved: fuse: re-lock request before replacing page cache folio fuse_try_move_folio() unlocks the request on entry but does not re-lock it on the success path. NVD: This means fuse_chan_abort() can end the request and free the fuse_io_args (eg fuse_readpages_end()) while the subsequent copy chain logic after fuse_try_move_folio() accesses the fuse_io_args, leading to use-after-free issues. NVD: Fix this by calling lock_request() before replace_page_cache_folio().",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260726T110235Z/items/CVE-2026-53388.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: Kernel; package/component: Kernel",
      "source_published_impact": "Source describes memory safety review. Possible impact: The affected component has memory-safety risk that may lead to crash, privilege, or code-execution impact depending on exposure.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: In the Linux kernel, the following vulnerability has been resolved: fuse: re-lock request before replacing page cache folio fuse_try_move_folio() unlocks the request on entry but does not re-lock it on the success path. NVD: This means fuse_chan_abort() can end the request and free the fuse_io_args (eg fuse_readpages_end()) while the subsequent copy chain logic after fuse_try_move_folio() accesses the fuse_io_args, leading to use-after-free issues. NVD: Fix this by calling lock_request() before replace_page_cache_folio().",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-53388/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "Kernel",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-53389/",
      "current_public_safe_latest": false,
      "cvss_score": 7.8,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.02598,
      "epss_score": 0.00125,
      "first_observed_at": "2026-07-26T10:55:16.819709+00:00",
      "id": "CVE-2026-53389",
      "impact_tags": [
        "memory safety review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-26T10:55:16.819709+00:00",
      "latest_item_url": null,
      "product": "Kernel",
      "public_safe_summary": "NVD: In the Linux kernel, the following vulnerability has been resolved: net/tcp-ao: fix use-after-free of key in del_async path In tcp_ao_delete_key(), the del_async path skips the current_key and rnext_key validity checks present in the synchronous path... NVD: However, if a key was added with set_current=1/set_rnext=1 while the socket was in CLOSE state, current_key and rnext_key will be non-NULL after listen() transitions the socket to LISTEN. NVD: When such a key is deleted with del_async=1, hlist_del_rcu() and call_rcu() free the key without clearing the dangling pointers.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260726T110235Z/items/CVE-2026-53389.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: Kernel; package/component: Kernel",
      "source_published_impact": "Source describes memory safety review. Possible impact: The affected component has memory-safety risk that may lead to crash, privilege, or code-execution impact depending on exposure.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: In the Linux kernel, the following vulnerability has been resolved: net/tcp-ao: fix use-after-free of key in del_async path In tcp_ao_delete_key(), the del_async path skips the current_key and rnext_key validity checks present in the synchronous path... NVD: However, if a key was added with set_current=1/set_rnext=1 while the socket was in CLOSE state, current_key and rnext_key will be non-NULL after listen() transitions the socket to LISTEN. NVD: When such a key is deleted with del_async=1, hlist_del_rcu() and call_rcu() free the key without clearing the dangling pointers.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-53389/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "Kernel",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-53390/",
      "current_public_safe_latest": false,
      "cvss_score": 8.1,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.36439,
      "epss_score": 0.00445,
      "first_observed_at": "2026-07-26T10:55:16.819709+00:00",
      "id": "CVE-2026-53390",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-26T10:55:16.819709+00:00",
      "latest_item_url": null,
      "product": "Kernel",
      "public_safe_summary": "NVD: In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix out-of-bounds read in smb_check_perm_dacl() The permission-check ACE walk in smb_check_perm_dacl() validates the ACE header size and caps sid.num_subauth at... NVD: CIFS_SID_BASE_SIZE covers the SID header up to but excluding the sub_auth[] array, and offsetof(struct smb_ace, sid) is the ACE header, so the existing guards only guarantee the 8-byte SID base, i.e. NVD: zero sub-authorities.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260726T110235Z/items/CVE-2026-53390.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: Kernel; package/component: Kernel",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix out-of-bounds read in smb_check_perm_dacl() The permission-check ACE walk in smb_check_perm_dacl() validates the ACE header size and caps sid.num_subauth at... NVD: CIFS_SID_BASE_SIZE covers the SID header up to but excluding the sub_auth[] array, and offsetof(struct smb_ace, sid) is the ACE header, so the existing guards only guarantee the 8-byte SID base, i.e. NVD: zero sub-authorities.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-53390/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "Kernel",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-53391/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.39313,
      "epss_score": 0.0049,
      "first_observed_at": "2026-07-26T10:55:16.819709+00:00",
      "id": "CVE-2026-53391",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-26T10:55:16.819709+00:00",
      "latest_item_url": null,
      "product": "Kernel",
      "public_safe_summary": "NVD: In the Linux kernel, the following vulnerability has been resolved: NFSv4/pNFS: reject zero-length r_addr in nfs4_decode_mp_ds_addr nfs4_decode_mp_ds_addr() decodes the r_netid and r_addr opaques of a netaddr4 from a GETDEVICEINFO multipath-DS body, then... NVD: Both decodes use xdr_stream_decode_string_dup(), and the current code checks only \"nlen < 0\" / \"rlen < 0\" before dereferencing the returned string. NVD: When the on-wire opaque has length zero, xdr_stream_decode_opaque_inline() returns 0 and xdr_stream_decode_string_dup() falls through to its \"*str = NULL; return ret\" tail, leaving buf NULL with a return value of 0.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260726T110235Z/items/CVE-2026-53391.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: Kernel; package/component: Kernel",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: In the Linux kernel, the following vulnerability has been resolved: NFSv4/pNFS: reject zero-length r_addr in nfs4_decode_mp_ds_addr nfs4_decode_mp_ds_addr() decodes the r_netid and r_addr opaques of a netaddr4 from a GETDEVICEINFO multipath-DS body, then... NVD: Both decodes use xdr_stream_decode_string_dup(), and the current code checks only \"nlen < 0\" / \"rlen < 0\" before dereferencing the returned string. NVD: When the on-wire opaque has length zero, xdr_stream_decode_opaque_inline() returns 0 and xdr_stream_decode_string_dup() falls through to its \"*str = NULL; return ret\" tail, leaving buf NULL with a return value of 0.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-53391/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "Kernel",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-53392/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.39981,
      "epss_score": 0.00501,
      "first_observed_at": "2026-07-26T10:55:16.819709+00:00",
      "id": "CVE-2026-53392",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-26T10:55:16.819709+00:00",
      "latest_item_url": null,
      "product": "Kernel",
      "public_safe_summary": "NVD: In the Linux kernel, the following vulnerability has been resolved: NFSv4/flexfiles: reject zero filehandle version count ff_layout_alloc_lseg() decodes the filehandle-version array count from the flexfiles layout body. NVD: The value is used as the count for kzalloc_objs(), and the current code only rejects NULL. NVD: A zero count yields ZERO_SIZE_PTR, which can be stored in dss_info->fh_versions even though later flexfiles paths assume that at least one filehandle version exists.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260726T110235Z/items/CVE-2026-53392.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: Kernel; package/component: Kernel",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: In the Linux kernel, the following vulnerability has been resolved: NFSv4/flexfiles: reject zero filehandle version count ff_layout_alloc_lseg() decodes the filehandle-version array count from the flexfiles layout body. NVD: The value is used as the count for kzalloc_objs(), and the current code only rejects NULL. NVD: A zero count yields ZERO_SIZE_PTR, which can be stored in dss_info->fh_versions even though later flexfiles paths assume that at least one filehandle version exists.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-53392/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-53405/",
      "current_public_safe_latest": false,
      "cvss_score": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.26994,
      "epss_score": 0.00344,
      "first_observed_at": "2026-07-27T12:38:45.912501+00:00",
      "id": "CVE-2026-53405",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-27T12:38:45.912501+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Improper Isolation or Compartmentalization vulnerability in Apache Syncope. NVD: An administrator with adequate entitlements can import arbitrary BPMN process definitions via the REST API and then start the process. NVD: When a BPMN process containing a Groovy scriptTask is imported and started, the Groovy script is executed directly on the server, with no sandbox.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260727T124133Z/items/CVE-2026-53405.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: Improper Isolation or Compartmentalization vulnerability in Apache Syncope. NVD: An administrator with adequate entitlements can import arbitrary BPMN process definitions via the REST API and then start the process. NVD: When a BPMN process containing a Groovy scriptTask is imported and started, the Groovy script is executed directly on the server, with no sandbox.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-53405/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-53421/",
      "current_public_safe_latest": false,
      "cvss_score": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.41842,
      "epss_score": 0.00533,
      "first_observed_at": "2026-07-27T12:38:45.912501+00:00",
      "id": "CVE-2026-53421",
      "impact_tags": [
        "code execution review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-27T12:38:45.912501+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Improper Isolation or Compartmentalization vulnerability in Apache Syncope. NVD: An administrator with adequate entitlements can achieve remote code execution through the connector subsystem by relying on scripted connectors' (REST and SQL) capability to run Groovy scripts. NVD: This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 Through 4.0.6, from 4.1.0-M0 through 4.1.1.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260727T124133Z/items/CVE-2026-53421.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes code execution review. Possible impact: An attacker may be able to run code or commands on affected systems.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: Improper Isolation or Compartmentalization vulnerability in Apache Syncope. NVD: An administrator with adequate entitlements can achieve remote code execution through the connector subsystem by relying on scripted connectors' (REST and SQL) capability to run Groovy scripts. NVD: This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 Through 4.0.6, from 4.1.0-M0 through 4.1.1.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-53421/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "dell / data_domain_operating_system",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-53479/",
      "current_public_safe_latest": false,
      "cvss_score": 7.2,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.64476,
      "epss_score": 0.01196,
      "first_observed_at": "2026-07-14T10:57:43.777280+00:00",
      "id": "CVE-2026-53479",
      "impact_tags": [
        "command execution review",
        "admin privilege risk",
        "command injection risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-14T10:57:43.777280+00:00",
      "latest_item_url": null,
      "product": "data_domain_operating_system",
      "public_safe_summary": "NVD: Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an improper neutralization of special... NVD: A remote high privileged attacker could potentially exploit this vulnerability, leading to protection mechanism bypass. NVD: This is a Critical vulnerability as it allows an attacker to invoke arbitrary command execution with root privileges; so Dell recommends customers to upgrade at the earliest opportunity.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260714T110007Z/items/CVE-2026-53479.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: dell / data_domain_operating_system",
      "source_published_impact": "Source describes command execution risk · admin privilege risk · command injection risk. Possible impact: An attacker may gain root or administrative-level privileges on affected systems.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an improper neutralization of special... NVD: A remote high privileged attacker could potentially exploit this vulnerability, leading to protection mechanism bypass. NVD: This is a Critical vulnerability as it allows an attacker to invoke arbitrary command execution with root privileges; so Dell recommends customers to upgrade at the earliest opportunity.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-53479/timeline.json",
      "vendor": "dell"
    },
    {
      "affected_label": "dell / data_domain_operating_system",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-53481/",
      "current_public_safe_latest": false,
      "cvss_score": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.46073,
      "epss_score": 0.00632,
      "first_observed_at": "2026-07-14T10:57:43.777280+00:00",
      "id": "CVE-2026-53481",
      "impact_tags": [
        "unauthorized access risk",
        "path traversal review",
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-14T10:57:43.777280+00:00",
      "latest_item_url": null,
      "product": "data_domain_operating_system",
      "public_safe_summary": "NVD: Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an improper limitation of a pathname... NVD: An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access to the system. NVD: This is a critical severity vulnerability as it allows an attacker to take complete control of system; so Dell recommends customers to upgrade at the earliest opportunity.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260714T110007Z/items/CVE-2026-53481.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: dell / data_domain_operating_system",
      "source_published_impact": "Source describes unauthorized access risk · path traversal review · remote exposure. Possible impact: A remote attacker may be able to reach files outside the intended application path.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an improper limitation of a pathname... NVD: An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access to the system. NVD: This is a critical severity vulnerability as it allows an attacker to take complete control of system; so Dell recommends customers to upgrade at the earliest opportunity.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-53481/timeline.json",
      "vendor": "dell"
    },
    {
      "affected_label": "dell / data_domain_operating_system",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-53483/",
      "current_public_safe_latest": false,
      "cvss_score": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.45813,
      "epss_score": 0.00625,
      "first_observed_at": "2026-07-14T10:57:43.777280+00:00",
      "id": "CVE-2026-53483",
      "impact_tags": [
        "unauthorized access risk",
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-14T10:57:43.777280+00:00",
      "latest_item_url": null,
      "product": "data_domain_operating_system",
      "public_safe_summary": "NVD: Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 an improper authentication vulnerability. NVD: An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access. NVD: This is a critical severity vulnerability as it allows an attacker to take complete control of system; so Dell recommends customers to upgrade at the earliest opportunity.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260714T110007Z/items/CVE-2026-53483.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: dell / data_domain_operating_system",
      "source_published_impact": "Source describes unauthorized access risk · remote exposure · authenticated boundary. Possible impact: A remote attacker may access resources that should require stronger authorization.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 an improper authentication vulnerability. NVD: An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access. NVD: This is a critical severity vulnerability as it allows an attacker to take complete control of system; so Dell recommends customers to upgrade at the earliest opportunity.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-53483/timeline.json",
      "vendor": "dell"
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-5356/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.11252,
      "epss_score": 0.0021,
      "first_observed_at": "2026-07-15T11:03:27.604769+00:00",
      "id": "CVE-2026-5356",
      "impact_tags": [
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-15T11:03:27.604769+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Improper Input Validation in all versions up to, and including, 5.4.0. NVD: This is due to the plugin's Stripe Connect payment processor accepting a client-supplied PaymentIntent ID. NVD: This makes it possible for unauthenticated attackers to pay an arbitrary amount by supplying a previously succeeded PaymentIntent token.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260715T110622Z/items/CVE-2026-5356.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes remote exposure · authenticated boundary. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Improper Input Validation in all versions up to, and including, 5.4.0. NVD: This is due to the plugin's Stripe Connect payment processor accepting a client-supplied PaymentIntent ID. NVD: This makes it possible for unauthenticated attackers to pay an arbitrary amount by supplying a previously succeeded PaymentIntent token.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-5356/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-53565/",
      "current_public_safe_latest": false,
      "cvss_score": 8.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.01051,
      "epss_score": 0.001,
      "first_observed_at": "2026-07-21T11:20:19.325173+00:00",
      "id": "CVE-2026-53565",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-21T11:20:19.325173+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Improper Privilege Management vulnerability in Citrix Secure Access Client for Windows, Citrix Citrix Endpoint Analysis Client for Windows. NVD: This issue affects Secure Access Client for Windows: before 26.6.1.20; Citrix Endpoint Analysis Client for Windows: before 26. NVD: 5.1.7.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260721T112231Z/items/CVE-2026-53565.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Improper Privilege Management vulnerability in Citrix Secure Access Client for Windows, Citrix Citrix Endpoint Analysis Client for Windows. NVD: This issue affects Secure Access Client for Windows: before 26.6.1.20; Citrix Endpoint Analysis Client for Windows: before 26. NVD: 5.1.7.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-53565/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-53566/",
      "current_public_safe_latest": false,
      "cvss_score": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.01485,
      "epss_score": 0.00109,
      "first_observed_at": "2026-07-21T11:20:19.325173+00:00",
      "id": "CVE-2026-53566",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-21T11:20:19.325173+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Out-of-bounds read vulnerability in Citrix Citrix Secure Access Client for Windows. NVD: This issue affects Citrix Secure Access Client for Windows: before 26.6.1.20.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260721T112231Z/items/CVE-2026-53566.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Out-of-bounds read vulnerability in Citrix Citrix Secure Access Client for Windows. NVD: This issue affects Citrix Secure Access Client for Windows: before 26.6.1.20.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-53566/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-53573/",
      "current_public_safe_latest": false,
      "cvss_score": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.30466,
      "epss_score": 0.00377,
      "first_observed_at": "2026-08-07T21:58:42.606809+00:00",
      "id": "CVE-2026-53573",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-07T21:58:42.606809+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: GeoNetwork is a catalog application to manage spatially referenced resources. NVD: From 3.12.0 until 4.2.16 and 4.4.11, unsafe redirect validation in GeonetworkOAuth2LoginAuthenticationFilter and KeycloakAuthenticationProcessingFilter permits an attacker-controlled external redirect after login. NVD: This issue is fixed in versions 4.2.16 and 4.4.11.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260807T220457Z/items/CVE-2026-53573.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: versions.",
      "source_published_summary": "NVD: GeoNetwork is a catalog application to manage spatially referenced resources. NVD: From 3.12.0 until 4.2.16 and 4.4.11, unsafe redirect validation in GeonetworkOAuth2LoginAuthenticationFilter and KeycloakAuthenticationProcessingFilter permits an attacker-controlled external redirect after login. NVD: This issue is fixed in versions 4.2.16 and 4.4.11.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-53573/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-53640/",
      "current_public_safe_latest": false,
      "cvss_score": 2.3,
      "cvss_severity": "LOW",
      "epss_percentile": 0.13273,
      "epss_score": 0.00226,
      "first_observed_at": "2026-07-13T22:14:02.217047+00:00",
      "id": "CVE-2026-53640",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-13T22:14:02.217047+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: FOSSBilling is a free, open-source billing and client management system. NVD: Prior to version 0.8.0, low-privileged staff accounts may read sensitive data via admin API endpoints that lack permission checks. NVD: While sibling write endpoints correctly enforce fine-grained permissions, the corresponding read endpoints have no authorization guards.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260714T042224Z/items/CVE-2026-53640.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: FOSSBilling is a free, open-source billing and client management system. NVD: Prior to version 0.8.0, low-privileged staff accounts may read sensitive data via admin API endpoints that lack permission checks. NVD: While sibling write endpoints correctly enforce fine-grained permissions, the corresponding read endpoints have no authorization guards.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-53640/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-53653/",
      "current_public_safe_latest": false,
      "cvss_score": 8.7,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.22062,
      "epss_score": 0.00301,
      "first_observed_at": "2026-07-17T16:36:32.072333+00:00",
      "id": "CVE-2026-53653",
      "impact_tags": [
        "service availability review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-17T16:36:32.072333+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Grav is a file-based Web platform. NVD: Prior to 1.7.53 and 2.0.0-rc.8, Grav allows an unauthenticated visitor to exhaust server memory and CPU by requesting image derivatives with oversized dimensions through URL query image actions such as forceResize in Grav::fallbackUrl, which passes request... NVD: This issue is fixed in versions 1.7.53 and 2.0.0-rc.8.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260717T164048Z/items/CVE-2026-53653.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes service availability risk. Possible impact: The affected service may become unavailable or unreliable.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: versions.",
      "source_published_summary": "NVD: Grav is a file-based Web platform. NVD: Prior to 1.7.53 and 2.0.0-rc.8, Grav allows an unauthenticated visitor to exhaust server memory and CPU by requesting image derivatives with oversized dimensions through URL query image actions such as forceResize in Grav::fallbackUrl, which passes request... NVD: This issue is fixed in versions 1.7.53 and 2.0.0-rc.8.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-53653/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-53657/",
      "current_public_safe_latest": false,
      "cvss_score": 8.2,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.09568,
      "epss_score": 0.00197,
      "first_observed_at": "2026-07-17T16:36:32.072333+00:00",
      "id": "CVE-2026-53657",
      "impact_tags": [
        "admin privilege risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-17T16:36:32.072333+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Lima launches Linux virtual machines, typically on macOS, for running containerd. NVD: Prior to 2.1.3, on an instance of Lima running with the qemu driver, an arbitrary user in the VM could access /run/lima-guestagent.sock when the guest agent is enabled, which could result in running arbitrary commands with root privileges in the VM because... NVD: This issue is fixed in version 2.1.3.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260717T164048Z/items/CVE-2026-53657.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes admin privilege risk. Possible impact: An attacker may gain root or administrative-level privileges on affected systems.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: Lima launches Linux virtual machines, typically on macOS, for running containerd. NVD: Prior to 2.1.3, on an instance of Lima running with the qemu driver, an arbitrary user in the VM could access /run/lima-guestagent.sock when the guest agent is enabled, which could result in running arbitrary commands with root privileges in the VM because... NVD: This issue is fixed in version 2.1.3.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-53657/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "djangoproject / django",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-53877/",
      "current_public_safe_latest": false,
      "cvss_score": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.20992,
      "epss_score": 0.00291,
      "first_observed_at": "2026-07-14T10:57:43.777280+00:00",
      "id": "CVE-2026-53877",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-14T10:57:43.777280+00:00",
      "latest_item_url": null,
      "product": "django",
      "public_safe_summary": "NVD: An issue was discovered in Django 6.0 before 6.0.7 and 5.2 before 5.2.16. NVD: django.contrib.gis.gdal.GDALRaster over-reads its in-memory buffer when constructed from a bytes object, which can disclose adjacent memory or cause service degradation via a potential segmentation fault when the vsi_buffer property is accessed. NVD: Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260714T110007Z/items/CVE-2026-53877.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: djangoproject / django",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: An issue was discovered in Django 6.0 before 6.0.7 and 5.2 before 5.2.16. NVD: django.contrib.gis.gdal.GDALRaster over-reads its in-memory buffer when constructed from a bytes object, which can disclose adjacent memory or cause service degradation via a potential segmentation fault when the vsi_buffer property is accessed. NVD: Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-53877/timeline.json",
      "vendor": "djangoproject"
    },
    {
      "affected_label": "djangoproject / django",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-53878/",
      "current_public_safe_latest": false,
      "cvss_score": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.12122,
      "epss_score": 0.00217,
      "first_observed_at": "2026-07-14T10:57:43.777280+00:00",
      "id": "CVE-2026-53878",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-14T10:57:43.777280+00:00",
      "latest_item_url": null,
      "product": "django",
      "public_safe_summary": "NVD: An issue was discovered in Django 6.0 before 6.0.7 and 5.2 before 5.2.16. NVD: DomainNameValidator does not prohibit newlines in domain names (unless used via a form field, since CharField strips newlines). NVD: If an application uses values with newlines in an HTTP response, header injection can occur.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260714T110007Z/items/CVE-2026-53878.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: djangoproject / django",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: An issue was discovered in Django 6.0 before 6.0.7 and 5.2 before 5.2.16. NVD: DomainNameValidator does not prohibit newlines in domain names (unless used via a form field, since CharField strips newlines). NVD: If an application uses values with newlines in an HTTP response, header injection can occur.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-53878/timeline.json",
      "vendor": "djangoproject"
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-53987/",
      "current_public_safe_latest": false,
      "cvss_score": 7.3,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.26293,
      "epss_score": 0.00341,
      "first_observed_at": "2026-07-16T16:44:59.414444+00:00",
      "id": "CVE-2026-53987",
      "impact_tags": [
        "XSS risk",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-16T16:44:59.414444+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Tag plugin for GLPI 11 before 2.14.4 stores the tag name without HTML sanitization and renders it into the Kanban badge markup via PluginTagTag::preKanbanContent() without output escaping, resulting in stored cross-site scripting. NVD: An authenticated user with TAG MANAGEMENT create or update rights can set a tag name containing HTML, which then executes in the browser of any user who opens the Kanban view of a ticket, problem, change, or project the tag is attached to. OSV: GLPI 11 before 2.14.4 Tag Plugin Stored Cross-Site Scripting in Kanban Badge Rendering",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260716T164706Z/items/CVE-2026-53987.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes XSS risk · authenticated boundary. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Tag plugin for GLPI 11 before 2.14.4 stores the tag name without HTML sanitization and renders it into the Kanban badge markup via PluginTagTag::preKanbanContent() without output escaping, resulting in stored cross-site scripting. NVD: An authenticated user with TAG MANAGEMENT create or update rights can set a tag name containing HTML, which then executes in the browser of any user who opens the Kanban view of a ticket, problem, change, or project the tag is attached to. OSV: GLPI 11 before 2.14.4 Tag Plugin Stored Cross-Site Scripting in Kanban Badge Rendering",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-53987/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "python / pillow",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-54059/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.27497,
      "epss_score": 0.00354,
      "first_observed_at": "2026-07-13T17:24:46.617207+00:00",
      "id": "CVE-2026-54059",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-13T17:24:46.617207+00:00",
      "latest_item_url": null,
      "product": "pillow",
      "public_safe_summary": "NVD: Pillow is a Python imaging library. NVD: Prior to 12.3.0, PIL/PcfFontFile.py _load_bitmaps() read glyph dimensions from the PCF METRICS section and passed them directly to Image.frombytes() without calling Image._decompression_bomb_check(), allowing crafted PCF font data to cause excessive memory... NVD: This issue is fixed in version 12.3.0.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260713T172750Z/items/CVE-2026-54059.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: python / pillow",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: Pillow is a Python imaging library. NVD: Prior to 12.3.0, PIL/PcfFontFile.py _load_bitmaps() read glyph dimensions from the PCF METRICS section and passed them directly to Image.frombytes() without calling Image._decompression_bomb_check(), allowing crafted PCF font data to cause excessive memory... NVD: This issue is fixed in version 12.3.0.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-54059/timeline.json",
      "vendor": "python"
    },
    {
      "affected_label": "python / pillow",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-54060/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.28223,
      "epss_score": 0.00361,
      "first_observed_at": "2026-07-13T17:24:46.617207+00:00",
      "id": "CVE-2026-54060",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-13T17:24:46.617207+00:00",
      "latest_item_url": null,
      "product": "pillow",
      "public_safe_summary": "NVD: Pillow is a Python imaging library. NVD: Prior to 12.3.0, PIL/FontFile.py FontFile.compile() assembled per-glyph images into a combined bitmap with Image.new(\"1\", (xsize, ysize)) without calling Image._decompression_bomb_check(), allowing a font to trigger excessive allocation during conversion or... NVD: This issue is fixed in version 12.3.0.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260713T172750Z/items/CVE-2026-54060.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: python / pillow",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: Pillow is a Python imaging library. NVD: Prior to 12.3.0, PIL/FontFile.py FontFile.compile() assembled per-glyph images into a combined bitmap with Image.new(\"1\", (xsize, ysize)) without calling Image._decompression_bomb_check(), allowing a font to trigger excessive allocation during conversion or... NVD: This issue is fixed in version 12.3.0.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-54060/timeline.json",
      "vendor": "python"
    },
    {
      "affected_label": "excelize / excelize",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-54063/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.4507,
      "epss_score": 0.00607,
      "first_observed_at": "2026-07-17T16:36:32.072333+00:00",
      "id": "CVE-2026-54063",
      "impact_tags": [
        "service availability review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-17T16:36:32.072333+00:00",
      "latest_item_url": null,
      "product": "excelize",
      "public_safe_summary": "NVD: Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. NVD: Prior to 2.11.0, the checkSheet() function in github.com/xuri/excelize/v2 uses an attacker-controlled <row r=\"N\"> XML attribute value directly as the length argument to make([]xlsxRow, row) without validating it against the Excel row limit (TotalRows =... NVD: A specially crafted XLSX file can trigger two denial-of-service variants: (A) an out-of-memory process kill when r=2147483647 forces a ~16 GB allocation attempt, and (B) a runtime panic via out-of-bounds slice indexing when r=-1.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260717T164048Z/items/CVE-2026-54063.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: excelize / excelize",
      "source_published_impact": "Source describes service availability risk. Possible impact: The affected service may become unavailable or unreliable.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. NVD: Prior to 2.11.0, the checkSheet() function in github.com/xuri/excelize/v2 uses an attacker-controlled <row r=\"N\"> XML attribute value directly as the length argument to make([]xlsxRow, row) without validating it against the Excel row limit (TotalRows =... NVD: A specially crafted XLSX file can trigger two denial-of-service variants: (A) an out-of-memory process kill when r=2147483647 forces a ~16 GB allocation attempt, and (B) a runtime panic via out-of-bounds slice indexing when r=-1.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-54063/timeline.json",
      "vendor": "excelize"
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-54120/",
      "current_public_safe_latest": false,
      "cvss_score": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.49874,
      "epss_score": 0.00708,
      "first_observed_at": "2026-07-30T22:30:38.166118+00:00",
      "id": "CVE-2026-54120",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-30T22:30:38.166118+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Improper input validation in Microsoft Surface allows an authorized attacker to execute code over a network.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260730T224832Z/items/CVE-2026-54120.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Improper input validation in Microsoft Surface allows an authorized attacker to execute code over a network.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-54120/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-54272/",
      "current_public_safe_latest": false,
      "cvss_score": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.16994,
      "epss_score": 0.00254,
      "first_observed_at": "2026-08-03T17:21:47.396014+00:00",
      "id": "CVE-2026-54272",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-03T17:21:47.396014+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. NVD: Versions 10.1.1 through 10.2.0 are vulnerable to SSRF through misclassification of IPv4-mapped/NAT64 IPv6 addresses. NVD: Address6.getType() classifies an address by matching it against a table of known IPv6 special-use prefixes, returning Global unicast when nothing matches.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260803T174717Z/items/CVE-2026-54272.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. NVD: Versions 10.1.1 through 10.2.0 are vulnerable to SSRF through misclassification of IPv4-mapped/NAT64 IPv6 addresses. NVD: Address6.getType() classifies an address by matching it against a table of known IPv6 special-use prefixes, returning Global unicast when nothing matches.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-54272/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "postgresql / postgresql_jdbc_driver",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-54291/",
      "current_public_safe_latest": false,
      "cvss_score": 8.2,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.14544,
      "epss_score": 0.00236,
      "first_observed_at": "2026-07-13T17:24:46.617207+00:00",
      "id": "CVE-2026-54291",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-13T17:24:46.617207+00:00",
      "latest_item_url": null,
      "product": "postgresql_jdbc_driver",
      "public_safe_summary": "NVD: pgjdbc is an open source postgresql JDBC Driver. NVD: In releases 42.7.4 through 42.7.11, channelBinding=require connections can be silently downgraded from SCRAM-SHA-256-PLUS with channel binding to plain SCRAM-SHA-256 without it, losing the man-in-the-middle protection the setting is meant to guarantee. NVD: An attacker who can intercept the TLS connection can trigger the downgrade with a certificate whose signature algorithm has no tls-server-end-point channel-binding hash, because the bundled com.ongres.scram:scram-client returns an empty byte array instead of...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260713T172750Z/items/CVE-2026-54291.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: postgresql / postgresql_jdbc_driver",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: pgjdbc is an open source postgresql JDBC Driver. NVD: In releases 42.7.4 through 42.7.11, channelBinding=require connections can be silently downgraded from SCRAM-SHA-256-PLUS with channel binding to plain SCRAM-SHA-256 without it, losing the man-in-the-middle protection the setting is meant to guarantee. NVD: An attacker who can intercept the TLS connection can trigger the downgrade with a certificate whose signature algorithm has no tls-server-end-point channel-binding hash, because the bundled com.ongres.scram:scram-client returns an empty byte array instead of...",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-54291/timeline.json",
      "vendor": "postgresql"
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-54332/",
      "current_public_safe_latest": false,
      "cvss_score": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.29416,
      "epss_score": 0.00367,
      "first_observed_at": "2026-08-04T17:06:52.325316+00:00",
      "id": "CVE-2026-54332",
      "impact_tags": [
        "service availability review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-04T17:06:52.325316+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: gopacket provides packet processing capabilities for Go. NVD: In version 1.6.0 and earlier, the sFlow ExtendedGatewayFlow decoder in layers/sflow.go reads an attacker-controlled 32-bit community count and AS path member count and sizes a slice allocation from those counts without bounding them against the bytes... NVD: This issue is fixed in version 1.6.1.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260804T171542Z/items/CVE-2026-54332.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes service availability risk. Possible impact: The affected service may become unavailable or unreliable.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: gopacket provides packet processing capabilities for Go. NVD: In version 1.6.0 and earlier, the sFlow ExtendedGatewayFlow decoder in layers/sflow.go reads an attacker-controlled 32-bit community count and AS path member count and sizes a slice allocation from those counts without bounding them against the bytes... NVD: This issue is fixed in version 1.6.1.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-54332/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-54340/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.20007,
      "epss_score": 0.00278,
      "first_observed_at": "2026-07-23T22:18:14.498937+00:00",
      "id": "CVE-2026-54340",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-23T22:18:14.498937+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: h2o is an HTTP server with support for HTTP/1.x, HTTP/2 and HTTP/3. NVD: Prior to commit 9265bdd, there is an HTTP/2 state amplification issue that combines HPACK decompression amplification with Slowloris-style stream stalling. NVD: Amplified decoded header state can be retained by stalled HTTP/2 streams, and depending on the configuration, additional limits are needed to bound decoded header state and prevent attack.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260723T222557Z/items/CVE-2026-54340.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: h2o is an HTTP server with support for HTTP/1.x, HTTP/2 and HTTP/3. NVD: Prior to commit 9265bdd, there is an HTTP/2 state amplification issue that combines HPACK decompression amplification with Slowloris-style stream stalling. NVD: Amplified decoded header state can be retained by stalled HTTP/2 streams, and depending on the configuration, additional limits are needed to bound decoded header state and prevent attack.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-54340/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-54342/",
      "current_public_safe_latest": false,
      "cvss_score": 8.1,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.02634,
      "epss_score": 0.00125,
      "first_observed_at": "2026-07-31T16:59:34.622526+00:00",
      "id": "CVE-2026-54342",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-31T16:59:34.622526+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: In epa4all, prior to version 2026-05-20, an attacker on the network path between epa4all and any backend (ePA Aktensystem, Konnektor, IDP, TSS) can present a self-signed TLS certificate and intercept the connection. NVD: For non-VAU connections (Konnektor, IDP), this allows direct read and modification of the inner traffic, including smartcard operations and OIDC authentication exchanges. NVD: For the ePA backend, the disabled TLS verification is the transport-level enabler for the VAU MITM described in GHSA-vvh7-x6c7-46gh.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260731T171256Z/items/CVE-2026-54342.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: In epa4all, prior to version 2026-05-20, an attacker on the network path between epa4all and any backend (ePA Aktensystem, Konnektor, IDP, TSS) can present a self-signed TLS certificate and intercept the connection. NVD: For non-VAU connections (Konnektor, IDP), this allows direct read and modification of the inner traffic, including smartcard operations and OIDC authentication exchanges. NVD: For the ePA backend, the disabled TLS verification is the transport-level enabler for the VAU MITM described in GHSA-vvh7-x6c7-46gh.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-54342/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-54345/",
      "current_public_safe_latest": false,
      "cvss_score": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.31574,
      "epss_score": 0.00388,
      "first_observed_at": "2026-08-04T17:06:52.325316+00:00",
      "id": "CVE-2026-54345",
      "impact_tags": [
        "service availability review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-04T17:06:52.325316+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: gopacket provides packet processing capabilities for Go. NVD: In version 1.6.0 and earlier, the Diameter AVP decoder computes an AVP data length by subtracting a fixed header size from an attacker-controlled AVP Length field, so a vendor-flagged AVP whose Length is smaller than the 12-byte header underflows the unsigned... NVD: This issue is fixed in version 1.6.1.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260804T171542Z/items/CVE-2026-54345.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes service availability risk. Possible impact: The affected service may become unavailable or unreliable.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: gopacket provides packet processing capabilities for Go. NVD: In version 1.6.0 and earlier, the Diameter AVP decoder computes an AVP data length by subtracting a fixed header size from an attacker-controlled AVP Length field, so a vendor-flagged AVP whose Length is smaller than the 12-byte header underflows the unsigned... NVD: This issue is fixed in version 1.6.1.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-54345/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-54363/",
      "current_public_safe_latest": false,
      "cvss_score": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.32107,
      "epss_score": 0.00394,
      "first_observed_at": "2026-08-06T11:35:20.545945+00:00",
      "id": "CVE-2026-54363",
      "impact_tags": [
        "code execution review",
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-06T11:35:20.545945+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: CentreStack before 17.5 contains a hardcoded cryptographic key vulnerability that allows unauthenticated attackers to forge arbitrary encrypted tokens by exploiting a static SysNumber value used as entropy for AccessTicket.Encrypt() and AccessTicket.Decrypt()... NVD: Attackers can use the hardcoded key to craft valid x-glad-auth headers and call privileged API endpoints such as acquiretenantbackuptoken to obtain a domain administrator IdentityTicket, enabling a complete unauthenticated remote code execution chain.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260806T114533Z/items/CVE-2026-54363.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes code execution review · remote exposure · authenticated boundary. Possible impact: A remote attacker may be able to run code or commands on affected systems.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: CentreStack before 17.5 contains a hardcoded cryptographic key vulnerability that allows unauthenticated attackers to forge arbitrary encrypted tokens by exploiting a static SysNumber value used as entropy for AccessTicket.Encrypt() and AccessTicket.Decrypt()... NVD: Attackers can use the hardcoded key to craft valid x-glad-auth headers and call privileged API endpoints such as acquiretenantbackuptoken to obtain a domain administrator IdentityTicket, enabling a complete unauthenticated remote code execution chain.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-54363/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-54364/",
      "current_public_safe_latest": false,
      "cvss_score": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.16584,
      "epss_score": 0.00252,
      "first_observed_at": "2026-08-06T11:35:20.545945+00:00",
      "id": "CVE-2026-54364",
      "impact_tags": [
        "unauthorized access risk",
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-06T11:35:20.545945+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: CentreStack before 17.4 contains a session variable injection vulnerability that allows unauthenticated attackers to inject arbitrary session variables by embedding newline and tab characters into a crafted AccountName parameter posted to the... NVD: Attackers can exploit the lack of input sanitization in the custom session serialization format to inject a resellerid session variable, bypassing the IsValidRSession authentication check and gaining unauthorized access to management pages.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260806T114533Z/items/CVE-2026-54364.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes unauthorized access risk · remote exposure · authenticated boundary. Possible impact: A remote attacker may access resources that should require stronger authorization.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: CentreStack before 17.4 contains a session variable injection vulnerability that allows unauthenticated attackers to inject arbitrary session variables by embedding newline and tab characters into a crafted AccountName parameter posted to the... NVD: Attackers can exploit the lack of input sanitization in the custom session serialization format to inject a resellerid session variable, bypassing the IsValidRSession authentication check and gaining unauthorized access to management pages.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-54364/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-54365/",
      "current_public_safe_latest": false,
      "cvss_score": 8.7,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.12123,
      "epss_score": 0.00216,
      "first_observed_at": "2026-08-06T11:35:20.545945+00:00",
      "id": "CVE-2026-54365",
      "impact_tags": [
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-06T11:35:20.545945+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: CentreStack before 17.3 contains an unauthenticated deserialization vulnerability in GSNamespace.dll that allows unauthenticated attackers to create arbitrary local OS user accounts by supplying a crafted base64-encoded XML string to exposed API endpoints. NVD: Attackers can send a malicious StorageConfigure parameter to the jsonimportuserbyupn, jsonimportuserbyupnex, or japiimportuserbyupn endpoints to trigger InternalImportAdUserByUPN(), causing GladinetCloudMonitor.exe to invoke the NetUserAdd Windows API with...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260806T114533Z/items/CVE-2026-54365.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes remote exposure · authenticated boundary. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: CentreStack before 17.3 contains an unauthenticated deserialization vulnerability in GSNamespace.dll that allows unauthenticated attackers to create arbitrary local OS user accounts by supplying a crafted base64-encoded XML string to exposed API endpoints. NVD: Attackers can send a malicious StorageConfigure parameter to the jsonimportuserbyupn, jsonimportuserbyupnex, or japiimportuserbyupn endpoints to trigger InternalImportAdUserByUPN(), causing GladinetCloudMonitor.exe to invoke the NetUserAdd Windows API with...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-54365/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-54366/",
      "current_public_safe_latest": false,
      "cvss_score": 8.7,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.20818,
      "epss_score": 0.00287,
      "first_observed_at": "2026-08-06T11:35:20.545945+00:00",
      "id": "CVE-2026-54366",
      "impact_tags": [
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-06T11:35:20.545945+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: CentreStack before 17.4 contains an XML external entity (XXE) injection vulnerability that allows unauthenticated attackers to exfiltrate arbitrary files by supplying a malicious URL to the SharePoint storage configuration handler. NVD: Attackers can send a crafted request to the unauthenticated StorageConfig endpoint causing the server to fetch and parse attacker-controlled XML containing external DTD references, resulting in out-of-band file exfiltration of sensitive files such as...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260806T114533Z/items/CVE-2026-54366.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes remote exposure · authenticated boundary. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: CentreStack before 17.4 contains an XML external entity (XXE) injection vulnerability that allows unauthenticated attackers to exfiltrate arbitrary files by supplying a malicious URL to the SharePoint storage configuration handler. NVD: Attackers can send a crafted request to the unauthenticated StorageConfig endpoint causing the server to fetch and parse attacker-controlled XML containing external DTD references, resulting in out-of-band file exfiltration of sensitive files such as...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-54366/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-54367/",
      "current_public_safe_latest": false,
      "cvss_score": 8.8,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.08575,
      "epss_score": 0.00188,
      "first_observed_at": "2026-08-06T11:35:20.545945+00:00",
      "id": "CVE-2026-54367",
      "impact_tags": [
        "authentication boundary review",
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-06T11:35:20.545945+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: CentreStack before 17.2 contains an authentication bypass vulnerability that allows unauthenticated attackers to read, write, or delete arbitrary account settings by exploiting exposed API endpoints that lack authorization checks. NVD: Attackers can generate valid encrypted EntAcctId values using the static shared encryption key to forge identifiers for any user GUID, including the system-wide cluster settings account, enabling enumeration of hosted tenant domains and administrator...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260806T114533Z/items/CVE-2026-54367.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes authentication boundary review · remote exposure · authenticated boundary. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authentication boundary review · remote exposure · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: CentreStack before 17.2 contains an authentication bypass vulnerability that allows unauthenticated attackers to read, write, or delete arbitrary account settings by exploiting exposed API endpoints that lack authorization checks. NVD: Attackers can generate valid encrypted EntAcctId values using the static shared encryption key to forge identifiers for any user GUID, including the system-wide cluster settings account, enabling enumeration of hosted tenant domains and administrator...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-54367/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-54368/",
      "current_public_safe_latest": false,
      "cvss_score": 8.7,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.31937,
      "epss_score": 0.00392,
      "first_observed_at": "2026-08-06T11:35:20.545945+00:00",
      "id": "CVE-2026-54368",
      "impact_tags": [
        "code execution review",
        "SQL injection risk",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-06T11:35:20.545945+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: CentreStack before 17.4 contains a SQL injection vulnerability in GladDBFiles.SearchEx() and SearchExUnder() that allows authenticated attackers to execute arbitrary SQL statements by supplying a crafted x-glad-filter request header through the jsondir API... NVD: Attackers can exploit unsanitized interpolation of the Field parameter directly into SQL query strings to write arbitrary files to the server filesystem via PostgreSQL lo_from_bytea() and lo_export() functions, enabling remote code execution.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260806T114533Z/items/CVE-2026-54368.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes code execution review · SQL injection risk · authenticated boundary. Possible impact: An attacker may be able to run code or commands on affected systems.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: CentreStack before 17.4 contains a SQL injection vulnerability in GladDBFiles.SearchEx() and SearchExUnder() that allows authenticated attackers to execute arbitrary SQL statements by supplying a crafted x-glad-filter request header through the jsondir API... NVD: Attackers can exploit unsanitized interpolation of the Field parameter directly into SQL query strings to write arbitrary files to the server filesystem via PostgreSQL lo_from_bytea() and lo_export() functions, enabling remote code execution.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-54368/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-54424/",
      "current_public_safe_latest": false,
      "cvss_score": 8.4,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.15581,
      "epss_score": 0.00245,
      "first_observed_at": "2026-07-10T22:27:53.208509+00:00",
      "id": "CVE-2026-54424",
      "impact_tags": [
        "privilege boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-10T22:27:53.208509+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: An Incorrect Use of Privileged APIs vulnerability in Unity Parsec on Windows hosts leads to a potential Elevation of Privilege. NVD: This issue affects Parsec through v2026-05-04.0. NVD: The patched version is Parsec for Windows version 150-104a.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260710T222920Z/items/CVE-2026-54424.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes privilege escalation risk. Possible impact: An attacker may cross a privilege boundary and gain more access than intended.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: An Incorrect Use of Privileged APIs vulnerability in Unity Parsec on Windows hosts leads to a potential Elevation of Privilege. NVD: This issue affects Parsec through v2026-05-04.0. NVD: The patched version is Parsec for Windows version 150-104a.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-54424/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "dell / unisphere_for_powermax",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-54468/",
      "current_public_safe_latest": false,
      "cvss_score": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.21452,
      "epss_score": 0.00295,
      "first_observed_at": "2026-07-17T10:59:18.822206+00:00",
      "id": "CVE-2026-54468",
      "impact_tags": [
        "path traversal review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-17T10:59:18.822206+00:00",
      "latest_item_url": null,
      "product": "unisphere_for_powermax",
      "public_safe_summary": "NVD: Dell Unisphere for PowerMax, version(s) 10.3.0.5 and prior, contain(s) a path traversal vulnerability. NVD: A low privileged attacker with remote access could potentially exploit this vulnerability to read arbitrary files.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260717T110142Z/items/CVE-2026-54468.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: dell / unisphere_for_powermax",
      "source_published_impact": "Source describes path traversal review. Possible impact: An attacker may be able to reach files outside the intended application path.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Dell Unisphere for PowerMax, version(s) 10.3.0.5 and prior, contain(s) a path traversal vulnerability. NVD: A low privileged attacker with remote access could potentially exploit this vulnerability to read arbitrary files.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-54468/timeline.json",
      "vendor": "dell"
    },
    {
      "affected_label": "dell / unisphere_for_powermax",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-54469/",
      "current_public_safe_latest": false,
      "cvss_score": 8.8,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.35794,
      "epss_score": 0.00442,
      "first_observed_at": "2026-07-17T10:59:18.822206+00:00",
      "id": "CVE-2026-54469",
      "impact_tags": [
        "command execution review",
        "admin privilege risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-17T10:59:18.822206+00:00",
      "latest_item_url": null,
      "product": "unisphere_for_powermax",
      "public_safe_summary": "NVD: Dell Unisphere for PowerMax, version(s) 10.3.0.5 and prior, contain(s) a Deserialization of Untrusted Data vulnerability. NVD: A low privileged attacker with remote access could potentially exploit this vulnerability, leading to arbitrary command execution with root privileges.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260717T110142Z/items/CVE-2026-54469.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: dell / unisphere_for_powermax",
      "source_published_impact": "Source describes command execution risk · admin privilege risk. Possible impact: An attacker may gain root or administrative-level privileges on affected systems.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Dell Unisphere for PowerMax, version(s) 10.3.0.5 and prior, contain(s) a Deserialization of Untrusted Data vulnerability. NVD: A low privileged attacker with remote access could potentially exploit this vulnerability, leading to arbitrary command execution with root privileges.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-54469/timeline.json",
      "vendor": "dell"
    },
    {
      "affected_label": "dell / unisphere_for_powermax",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-54470/",
      "current_public_safe_latest": false,
      "cvss_score": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.08861,
      "epss_score": 0.0019,
      "first_observed_at": "2026-07-17T10:59:18.822206+00:00",
      "id": "CVE-2026-54470",
      "impact_tags": [
        "unauthorized access risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-17T10:59:18.822206+00:00",
      "latest_item_url": null,
      "product": "unisphere_for_powermax",
      "public_safe_summary": "NVD: Dell Unisphere for PowerMax, version(s) 10.3.0.5 and prior contain(s) an Improper Restriction of XML External Entity Reference vulnerability. NVD: A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260717T110142Z/items/CVE-2026-54470.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: dell / unisphere_for_powermax",
      "source_published_impact": "Source describes unauthorized access risk. Possible impact: An attacker may access resources that should require stronger authorization.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Dell Unisphere for PowerMax, version(s) 10.3.0.5 and prior contain(s) an Improper Restriction of XML External Entity Reference vulnerability. NVD: A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-54470/timeline.json",
      "vendor": "dell"
    },
    {
      "affected_label": "dell / data_domain_operating_system",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-54483/",
      "current_public_safe_latest": false,
      "cvss_score": 6.7,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.36179,
      "epss_score": 0.00451,
      "first_observed_at": "2026-07-10T12:09:55.374028+00:00",
      "id": "CVE-2026-54483",
      "impact_tags": [
        "command execution review",
        "command injection risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-10T12:09:55.374028+00:00",
      "latest_item_url": null,
      "product": "data_domain_operating_system",
      "public_safe_summary": "NVD: Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an improper neutralization of special... NVD: A high privileged attacker with local access could potentially exploit this vulnerability, leading to Command execution.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260710T121119Z/items/CVE-2026-54483.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: dell / data_domain_operating_system",
      "source_published_impact": "Source describes command execution risk · command injection risk. Possible impact: An attacker may be able to run code or commands on affected systems.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an improper neutralization of special... NVD: A high privileged attacker with local access could potentially exploit this vulnerability, leading to Command execution.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-54483/timeline.json",
      "vendor": "dell"
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-54540/",
      "current_public_safe_latest": false,
      "cvss_score": 8.8,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.50036,
      "epss_score": 0.00712,
      "first_observed_at": "2026-08-03T17:21:47.396014+00:00",
      "id": "CVE-2026-54540",
      "impact_tags": [
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-03T17:21:47.396014+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Pheditor is a single-file editor and file manager written in PHP. NVD: Prior to version 2.0.5, there is an authenticated terminal command whitelist bypass. NVD: The terminal feature checks whether the submitted command starts with one of the configured TERMINAL_COMMANDS values, then passes the full command string to shell_exec().",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260803T174717Z/items/CVE-2026-54540.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes authenticated boundary. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: Pheditor is a single-file editor and file manager written in PHP. NVD: Prior to version 2.0.5, there is an authenticated terminal command whitelist bypass. NVD: The terminal feature checks whether the submitted command starts with one of the configured TERMINAL_COMMANDS values, then passes the full command string to shell_exec().",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-54540/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-54574/",
      "current_public_safe_latest": false,
      "cvss_score": 8.2,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.04255,
      "epss_score": 0.00145,
      "first_observed_at": "2026-08-05T16:55:08.588478+00:00",
      "id": "CVE-2026-54574",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-05T16:55:08.588478+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: proot-distro is a utility for managing proot containers. NVD: Prior to version 5.1.5, proot-distro install extracted plain tarball root filesystems through _extract_plain_tar() in proot_distro/commands/install.py and Docker layers through _apply_layer() in proot_distro/helpers/docker.py without validating... NVD: This issue is fixed in version 5.1.5.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260805T165944Z/items/CVE-2026-54574.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: proot-distro is a utility for managing proot containers. NVD: Prior to version 5.1.5, proot-distro install extracted plain tarball root filesystems through _extract_plain_tar() in proot_distro/commands/install.py and Docker layers through _apply_layer() in proot_distro/helpers/docker.py without validating... NVD: This issue is fixed in version 5.1.5.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-54574/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-5459/",
      "current_public_safe_latest": false,
      "cvss_score": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.08083,
      "epss_score": 0.00183,
      "first_observed_at": "2026-07-15T11:03:27.604769+00:00",
      "id": "CVE-2026-5459",
      "impact_tags": [
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-15T11:03:27.604769+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.3.1 via the payment_page() function due to... NVD: This makes it possible for unauthenticated attackers to activate a free subscription pack for any user on the site, overwriting their existing paid subscription and causing loss of paid features.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260715T110622Z/items/CVE-2026-5459.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes remote exposure · authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.3.1 via the payment_page() function due to... NVD: This makes it possible for unauthenticated attackers to activate a free subscription pack for any user on the site, overwriting their existing paid subscription and causing loss of paid features.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-5459/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-54603/",
      "current_public_safe_latest": false,
      "cvss_score": 8.6,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.18768,
      "epss_score": 0.00268,
      "first_observed_at": "2026-08-04T17:06:52.325316+00:00",
      "id": "CVE-2026-54603",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-04T17:06:52.325316+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: OAuth2 is a Ruby wrapper for the OAuth 2.0 and 2.1 authorization frameworks, including OpenID Connect (OIDC). NVD: From 0.4.0 to 2.0.21, a protocol-relative redirect Location returned to OAuth2::Client#request overrides the request authority, so the bearer Authorization header is sent to an attacker-controlled host, leaking the credential. NVD: This issue is fixed in version 2.0.22.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260804T171542Z/items/CVE-2026-54603.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: OAuth2 is a Ruby wrapper for the OAuth 2.0 and 2.1 authorization frameworks, including OpenID Connect (OIDC). NVD: From 0.4.0 to 2.0.21, a protocol-relative redirect Location returned to OAuth2::Client#request overrides the request authority, so the bearer Authorization header is sent to an attacker-controlled host, leaking the credential. NVD: This issue is fixed in version 2.0.22.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-54603/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-54605/",
      "current_public_safe_latest": false,
      "cvss_score": 7.2,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.03164,
      "epss_score": 0.00132,
      "first_observed_at": "2026-08-04T17:06:52.325316+00:00",
      "id": "CVE-2026-54605",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-04T17:06:52.325316+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: OAuth is a Ruby wrapper for the OAuth 1.0 and 1.0a protocols, providing clients and servers. NVD: From 0.5.5 to 1.1.5, OAuth::Consumer#token_request parses the raw Location header of a 300 to 399 redirect returned by the OAuth server and follows the redirect recursively, which can mutate the consumer's configuration and expose signed OAuth request... NVD: This issue is fixed in version 1.1.6.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260804T171542Z/items/CVE-2026-54605.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: OAuth is a Ruby wrapper for the OAuth 1.0 and 1.0a protocols, providing clients and servers. NVD: From 0.5.5 to 1.1.5, OAuth::Consumer#token_request parses the raw Location header of a 300 to 399 redirect returned by the OAuth server and follows the redirect recursively, which can mutate the consumer's configuration and expose signed OAuth request... NVD: This issue is fixed in version 1.1.6.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-54605/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-54609/",
      "current_public_safe_latest": false,
      "cvss_score": 8.6,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.17959,
      "epss_score": 0.00263,
      "first_observed_at": "2026-08-04T17:06:52.325316+00:00",
      "id": "CVE-2026-54609",
      "impact_tags": [
        "service availability review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-04T17:06:52.325316+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: QTI Neon is a minimal, game-agnostic, relay-based UDP multiplayer protocol library. NVD: In version 1.0.0, the relay's handleReconnectRequest forwards RECONNECT_REQUEST packets to the host without bounding them, so an unauthenticated client can drive relay-to-host amplification and cause a denial of service on the host. NVD: No fixed version is available as of this review.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260804T171542Z/items/CVE-2026-54609.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes service availability risk. Possible impact: The affected service may become unavailable or unreliable.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: is.",
      "source_published_summary": "NVD: QTI Neon is a minimal, game-agnostic, relay-based UDP multiplayer protocol library. NVD: In version 1.0.0, the relay's handleReconnectRequest forwards RECONNECT_REQUEST packets to the host without bounding them, so an unauthenticated client can drive relay-to-host amplification and cause a denial of service on the host. NVD: No fixed version is available as of this review.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-54609/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-54619/",
      "current_public_safe_latest": false,
      "cvss_score": 2.0,
      "cvss_severity": "LOW",
      "epss_percentile": 0.013,
      "epss_score": 0.00107,
      "first_observed_at": "2026-08-04T17:06:52.325316+00:00",
      "id": "CVE-2026-54619",
      "impact_tags": [
        "memory safety review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-04T17:06:52.325316+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: sqlite3 provides Ruby bindings for the SQLite3 embedded database. NVD: In version 2.9.4 and earlier, redefining a SQLite function with a different arity frees the previously registered function handler while SQLite may still reference it, resulting in a use-after-free. NVD: This issue is fixed in version 2.9.5.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260804T171542Z/items/CVE-2026-54619.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes memory safety review. Possible impact: The affected component has memory-safety risk that may lead to crash, privilege, or code-execution impact depending on exposure.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: sqlite3 provides Ruby bindings for the SQLite3 embedded database. NVD: In version 2.9.4 and earlier, redefining a SQLite function with a different arity frees the previously registered function handler while SQLite may still reference it, resulting in a use-after-free. NVD: This issue is fixed in version 2.9.5.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-54619/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-54620/",
      "current_public_safe_latest": false,
      "cvss_score": 2.0,
      "cvss_severity": "LOW",
      "epss_percentile": 0.013,
      "epss_score": 0.00107,
      "first_observed_at": "2026-08-04T17:06:52.325316+00:00",
      "id": "CVE-2026-54620",
      "impact_tags": [
        "memory safety review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-04T17:06:52.325316+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: sqlite3 provides Ruby bindings for the SQLite3 embedded database. NVD: From 2.1.0 to 2.9.4, the callbacks used for SQLite aggregate functions can be freed while still referenced during aggregation, resulting in a use-after-free. NVD: This issue is fixed in version 2.9.5.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260804T171542Z/items/CVE-2026-54620.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes memory safety review. Possible impact: The affected component has memory-safety risk that may lead to crash, privilege, or code-execution impact depending on exposure.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: sqlite3 provides Ruby bindings for the SQLite3 embedded database. NVD: From 2.1.0 to 2.9.4, the callbacks used for SQLite aggregate functions can be freed while still referenced during aggregation, resulting in a use-after-free. NVD: This issue is fixed in version 2.9.5.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-54620/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-54638/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.27231,
      "epss_score": 0.00346,
      "first_observed_at": "2026-08-04T22:31:51.932237+00:00",
      "id": "CVE-2026-54638",
      "impact_tags": [
        "service availability review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-04T22:31:51.932237+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: gotd/td is a T Telegram MTProto API client in Go. NVD: Prior to 0.145.1, proto.UnencryptedMessage.Decode in proto/unencrypted_message.go read attacker controlled dataLen from an unauthenticated MTProto unencrypted packet and allocated make([]byte, dataLen) before checking the remaining buffer, allowing remote... NVD: This issue is fixed in version 0.145.1.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260804T223546Z/items/CVE-2026-54638.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes service availability risk. Possible impact: The affected service may become unavailable or unreliable.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: gotd/td is a T Telegram MTProto API client in Go. NVD: Prior to 0.145.1, proto.UnencryptedMessage.Decode in proto/unencrypted_message.go read attacker controlled dataLen from an unauthenticated MTProto unencrypted packet and allocated make([]byte, dataLen) before checking the remaining buffer, allowing remote... NVD: This issue is fixed in version 0.145.1.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-54638/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-54650/",
      "current_public_safe_latest": false,
      "cvss_score": 8.6,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.28804,
      "epss_score": 0.00361,
      "first_observed_at": "2026-08-04T22:31:51.932237+00:00",
      "id": "CVE-2026-54650",
      "impact_tags": [
        "path traversal review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-04T22:31:51.932237+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: openhole exposes localhost to the internet in one command. NVD: In 0.1.1 and earlier, openhole-server in internal/server/public_proxy.go forwarded r.URL.Path instead of preserving the original request target with r.URL.EscapedPath(), allowing percent encoded dot segments %2e and separators %2f to reach tunneled local... NVD: This issue is fixed in version 0.1.2.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260804T223546Z/items/CVE-2026-54650.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes path traversal review. Possible impact: An attacker may be able to reach files outside the intended application path.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: openhole exposes localhost to the internet in one command. NVD: In 0.1.1 and earlier, openhole-server in internal/server/public_proxy.go forwarded r.URL.Path instead of preserving the original request target with r.URL.EscapedPath(), allowing percent encoded dot segments %2e and separators %2f to reach tunneled local... NVD: This issue is fixed in version 0.1.2.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-54650/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-54658/",
      "current_public_safe_latest": false,
      "cvss_score": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.32399,
      "epss_score": 0.00396,
      "first_observed_at": "2026-08-04T22:31:51.932237+00:00",
      "id": "CVE-2026-54658",
      "impact_tags": [
        "SQL injection risk"
      ],
      "kev": false,
      "last_observed_at": "2026-08-04T22:31:51.932237+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Hypequery is a TypeScript semantic layer for ClickHouse. NVD: Prior to 2.5.1, escapeValue() in packages/clickhouse/src/core/utils.ts did not escape backslashes before single quotes during parameter substitution, allowing attacker controlled query parameters with a trailing backslash to escape the closing quote and... NVD: This issue is fixed in version 2.0.2.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260804T223546Z/items/CVE-2026-54658.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes SQL injection risk. Possible impact: An attacker may be able to read or change database-backed application data.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: Hypequery is a TypeScript semantic layer for ClickHouse. NVD: Prior to 2.5.1, escapeValue() in packages/clickhouse/src/core/utils.ts did not escape backslashes before single quotes during parameter substitution, allowing attacker controlled query parameters with a trailing backslash to escape the closing quote and... NVD: This issue is fixed in version 2.0.2.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-54658/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-54659/",
      "current_public_safe_latest": false,
      "cvss_score": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.29518,
      "epss_score": 0.00368,
      "first_observed_at": "2026-08-04T22:31:51.932237+00:00",
      "id": "CVE-2026-54659",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-04T22:31:51.932237+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Pagy is agnostic pagination in plain Ruby. NVD: From 43.0.0 until 43.5.6, Pagy::I18n.locale= in gem/lib/pagy/modules/i18n/i18n.rb stored locale values verbatim and later used them as <locale>.yml path components, allowing untrusted params[:locale] values with absolute paths or ../ sequences to create a... NVD: This issue is fixed in version 43.5.6.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260804T223546Z/items/CVE-2026-54659.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: Pagy is agnostic pagination in plain Ruby. NVD: From 43.0.0 until 43.5.6, Pagy::I18n.locale= in gem/lib/pagy/modules/i18n/i18n.rb stored locale values verbatim and later used them as <locale>.yml path components, allowing untrusted params[:locale] values with absolute paths or ../ sequences to create a... NVD: This issue is fixed in version 43.5.6.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-54659/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-54680/",
      "current_public_safe_latest": false,
      "cvss_score": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.35038,
      "epss_score": 0.00426,
      "first_observed_at": "2026-08-05T16:55:08.588478+00:00",
      "id": "CVE-2026-54680",
      "impact_tags": [
        "code execution review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-05T16:55:08.588478+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Logging operator automates the deployment and configuration of Kubernetes logging pipelines. NVD: Prior to 6.6.0, the Fluentd configuration renderer FluentRender in pkg/sdk/logging/model/render/fluent.go writes CRD strings such as Flow record_transformer.records values directly into fluent.conf without escaping, allowing a user who can create Flow... NVD: This issue is fixed in version 6.6.0.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260805T165944Z/items/CVE-2026-54680.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes code execution review. Possible impact: An attacker may be able to run code or commands on affected systems.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: Logging operator automates the deployment and configuration of Kubernetes logging pipelines. NVD: Prior to 6.6.0, the Fluentd configuration renderer FluentRender in pkg/sdk/logging/model/render/fluent.go writes CRD strings such as Flow record_transformer.records values directly into fluent.conf without escaping, allowing a user who can create Flow... NVD: This issue is fixed in version 6.6.0.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-54680/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-54685/",
      "current_public_safe_latest": false,
      "cvss_score": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.18955,
      "epss_score": 0.0027,
      "first_observed_at": "2026-07-27T12:38:45.912501+00:00",
      "id": "CVE-2026-54685",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-27T12:38:45.912501+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: FileBrowser Quantum is a free, self-hosted, web-based file manager. NVD: Prior to version 1.3.2-beta, the /api/auth/login authentication endpoint does not execute in constant time. NVD: When a non-existent username is supplied, the server returns a 401/403 response almost immediately.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260727T124133Z/items/CVE-2026-54685.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: FileBrowser Quantum is a free, self-hosted, web-based file manager. NVD: Prior to version 1.3.2-beta, the /api/auth/login authentication endpoint does not execute in constant time. NVD: When a non-existent username is supplied, the server returns a 401/403 response almost immediately.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-54685/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-54693/",
      "current_public_safe_latest": false,
      "cvss_score": 8.2,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.26867,
      "epss_score": 0.00343,
      "first_observed_at": "2026-08-05T16:55:08.588478+00:00",
      "id": "CVE-2026-54693",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-05T16:55:08.588478+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: ZITADEL is an open source identity management platform. NVD: From 2.43.0 through 2.71.19, from 3.0.0 until 3.4.11, and from 4.0.0 until 4.15.1, the email and phone self-management API paths in internal/command/user_v2_email.go, internal/command/user_v2_phone.go, and internal/command/user_v2_human.go allowed users to... NVD: This issue is fixed in versions 3.4.11 and 4.15.1.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260805T165944Z/items/CVE-2026-54693.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: versions.",
      "source_published_summary": "NVD: ZITADEL is an open source identity management platform. NVD: From 2.43.0 through 2.71.19, from 3.0.0 until 3.4.11, and from 4.0.0 until 4.15.1, the email and phone self-management API paths in internal/command/user_v2_email.go, internal/command/user_v2_phone.go, and internal/command/user_v2_human.go allowed users to... NVD: This issue is fixed in versions 3.4.11 and 4.15.1.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-54693/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-54719/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.20571,
      "epss_score": 0.00283,
      "first_observed_at": "2026-08-04T22:31:51.932237+00:00",
      "id": "CVE-2026-54719",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-04T22:31:51.932237+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: goshs is a feature-rich single-binary file server for red teamers and developers. NVD: Prior to 2.1.1, the httpserver/updown.go bulkDownload handler for ?bulk&file= ZIP downloads did not call findEffectiveACL or applyCustomAuth, allowing unauthenticated reads of files protected only by .goshs folder ACLs and block lists. NVD: This issue is fixed in version 2.1.1.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260804T223546Z/items/CVE-2026-54719.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: goshs is a feature-rich single-binary file server for red teamers and developers. NVD: Prior to 2.1.1, the httpserver/updown.go bulkDownload handler for ?bulk&file= ZIP downloads did not call findEffectiveACL or applyCustomAuth, allowing unauthenticated reads of files protected only by .goshs folder ACLs and block lists. NVD: This issue is fixed in version 2.1.1.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-54719/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-54727/",
      "current_public_safe_latest": false,
      "cvss_score": 8.2,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.02235,
      "epss_score": 0.00121,
      "first_observed_at": "2026-08-05T16:55:08.588478+00:00",
      "id": "CVE-2026-54727",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-05T16:55:08.588478+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: proot-distro is a utility for managing proot containers. NVD: Prior to version 5.1.6, proot-distro restore accepted hardlink entries whose linkname referenced another installed container and did not verify that the hardlink source container matched the destination container being restored, allowing a crafted restore... NVD: This issue is fixed in version 5.1.6.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260805T165944Z/items/CVE-2026-54727.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: proot-distro is a utility for managing proot containers. NVD: Prior to version 5.1.6, proot-distro restore accepted hardlink entries whose linkname referenced another installed container and did not verify that the hardlink source container matched the destination container being restored, allowing a crafted restore... NVD: This issue is fixed in version 5.1.6.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-54727/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-54768/",
      "current_public_safe_latest": false,
      "cvss_score": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.1992,
      "epss_score": 0.00278,
      "first_observed_at": "2026-08-07T21:58:42.606809+00:00",
      "id": "CVE-2026-54768",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-07T21:58:42.606809+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: WPGraphQL provides a GraphQL API for WordPress sites. NVD: From 2.0.0 until 2.15.1, the deprecated user field on SendPasswordResetEmailPayload lets an unauthenticated caller distinguish existing author-class accounts through the sendPasswordResetEmail mutation and obtain public profile fields. NVD: This issue is fixed in version 2.15.1.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260807T220457Z/items/CVE-2026-54768.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: WPGraphQL provides a GraphQL API for WordPress sites. NVD: From 2.0.0 until 2.15.1, the deprecated user field on SendPasswordResetEmailPayload lets an unauthenticated caller distinguish existing author-class accounts through the sendPasswordResetEmail mutation and obtain public profile fields. NVD: This issue is fixed in version 2.15.1.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-54768/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-54777/",
      "current_public_safe_latest": false,
      "cvss_score": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.00499,
      "epss_score": 0.00088,
      "first_observed_at": "2026-07-15T22:16:59.245057+00:00",
      "id": "CVE-2026-54777",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-15T22:16:59.245057+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. NVD: Prior to 1.8.1 and 1.9.1, CoreWCF NetNamedPipe transport accepts attachment to a pre-existing named pipe instance, allowing local interception of NetNamedPipe traffic when an attacker races NamedPipeListener startup between shared memory GUID publication and... NVD: This issue is fixed in versions 1.8.1 and 1.9.1.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260715T221956Z/items/CVE-2026-54777.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: versions.",
      "source_published_summary": "NVD: CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. NVD: Prior to 1.8.1 and 1.9.1, CoreWCF NetNamedPipe transport accepts attachment to a pre-existing named pipe instance, allowing local interception of NetNamedPipe traffic when an attacker races NamedPipeListener startup between shared memory GUID publication and... NVD: This issue is fixed in versions 1.8.1 and 1.9.1.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-54777/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-54785/",
      "current_public_safe_latest": false,
      "cvss_score": 6.2,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.048,
      "epss_score": 0.00151,
      "first_observed_at": "2026-08-07T21:58:42.606809+00:00",
      "id": "CVE-2026-54785",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-07T21:58:42.606809+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: gemini-bridge is a lightweight MCP server bridging AI agents to Google's Gemini AI via the official CLI. NVD: From 1.0.0 until 1.3.1, consult_gemini_with_files in inline mode read any file path supplied in the files argument without confining it to the working directory, then forwarded the contents to the Gemini CLI. NVD: Because the caller also controls query, the file contents are echoed back through the Gemini round-trip (and sent to Google), making this an arbitrary local file read.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260807T220457Z/items/CVE-2026-54785.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: gemini-bridge is a lightweight MCP server bridging AI agents to Google's Gemini AI via the official CLI. NVD: From 1.0.0 until 1.3.1, consult_gemini_with_files in inline mode read any file path supplied in the files argument without confining it to the working directory, then forwarded the contents to the Gemini CLI. NVD: Because the caller also controls query, the file contents are echoed back through the Gemini round-trip (and sent to Google), making this an arbitrary local file read.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-54785/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-54787/",
      "current_public_safe_latest": false,
      "cvss_score": 3.1,
      "cvss_severity": "LOW",
      "epss_percentile": 0.0055,
      "epss_score": 0.0009,
      "first_observed_at": "2026-08-07T21:58:42.606809+00:00",
      "id": "CVE-2026-54787",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-07T21:58:42.606809+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: sigstore-go is a Go library for Sigstore signing and verification. NVD: Prior to 1.2.1, sigstore-go does not check a bundle signing timestamp against the validity window of an ExpiringKey wrapping a self-managed long-lived signing key without a certificate, which can allow an attacker holding expired key material to sign accepted... NVD: This issue is fixed in version 1.2.1.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260807T220457Z/items/CVE-2026-54787.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: sigstore-go is a Go library for Sigstore signing and verification. NVD: Prior to 1.2.1, sigstore-go does not check a bundle signing timestamp against the validity window of an ExpiringKey wrapping a self-managed long-lived signing key without a certificate, which can allow an attacker holding expired key material to sign accepted... NVD: This issue is fixed in version 1.2.1.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-54787/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-54798/",
      "current_public_safe_latest": false,
      "cvss_score": 7.1,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.14977,
      "epss_score": 0.0024,
      "first_observed_at": "2026-07-16T13:54:14.110513+00:00",
      "id": "CVE-2026-54798",
      "impact_tags": [
        "service availability review",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-16T13:54:14.110513+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V26.20), SICORE Base system (All versions < V26.20.0). NVD: The affected application includes a debugging interface that is accessible through HTTP endpoints. NVD: This could allow an authenticated attacker to disrupt the system by crashing the web process causing denial of service conditions.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260716T135621Z/items/CVE-2026-54798.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes service availability risk · authenticated boundary. Possible impact: The affected service may become unavailable or unreliable.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V26.20), SICORE Base system (All versions < V26.20.0). NVD: The affected application includes a debugging interface that is accessible through HTTP endpoints. NVD: This could allow an authenticated attacker to disrupt the system by crashing the web process causing denial of service conditions.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-54798/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-54799/",
      "current_public_safe_latest": false,
      "cvss_score": 8.4,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.0273,
      "epss_score": 0.00127,
      "first_observed_at": "2026-07-16T13:54:14.110513+00:00",
      "id": "CVE-2026-54799",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-16T13:54:14.110513+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V26.20), SICORE Base system (All versions < V26.20.0). NVD: The affected application contains a vulnerability in its firmware update mechanism's signature validation process. NVD: This could allow an attacker to install malicious firmware, leading to persistent code execution and system compromise.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260716T135621Z/items/CVE-2026-54799.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V26.20), SICORE Base system (All versions < V26.20.0). NVD: The affected application contains a vulnerability in its firmware update mechanism's signature validation process. NVD: This could allow an attacker to install malicious firmware, leading to persistent code execution and system compromise.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-54799/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-54800/",
      "current_public_safe_latest": false,
      "cvss_score": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.04249,
      "epss_score": 0.00146,
      "first_observed_at": "2026-07-16T13:54:14.110513+00:00",
      "id": "CVE-2026-54800",
      "impact_tags": [
        "unauthorized access risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-16T13:54:14.110513+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V26.20), SICORE Base system (All versions < V26.20.0). NVD: The affected application ships with a default configuration that disables all OPC UA security mechanisms. NVD: This could allow an attacker to gain unauthorized access and control over critical system functions.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260716T135621Z/items/CVE-2026-54800.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes unauthorized access risk. Possible impact: An attacker may access resources that should require stronger authorization.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V26.20), SICORE Base system (All versions < V26.20.0). NVD: The affected application ships with a default configuration that disables all OPC UA security mechanisms. NVD: This could allow an attacker to gain unauthorized access and control over critical system functions.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-54800/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-54801/",
      "current_public_safe_latest": false,
      "cvss_score": 8.6,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.26135,
      "epss_score": 0.0034,
      "first_observed_at": "2026-07-16T13:54:14.110513+00:00",
      "id": "CVE-2026-54801",
      "impact_tags": [
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-16T13:54:14.110513+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V26.20), SICORE Base system (All versions < V26.20.0). NVD: The affected application contains insufficient validation of authentication credentials when processing administrative account modifications through the web API. NVD: This could allow an authenticated attacker to bypass security controls and gain unauthorized elevated privileges.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260716T135621Z/items/CVE-2026-54801.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes authenticated boundary. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V26.20), SICORE Base system (All versions < V26.20.0). NVD: The affected application contains insufficient validation of authentication credentials when processing administrative account modifications through the web API. NVD: This could allow an authenticated attacker to bypass security controls and gain unauthorized elevated privileges.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-54801/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "ueberauth / guardian",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-54894/",
      "current_public_safe_latest": false,
      "cvss_score": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.19037,
      "epss_score": 0.00271,
      "first_observed_at": "2026-08-08T15:50:31.311576+00:00",
      "id": "CVE-2026-54894",
      "impact_tags": [
        "service availability review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-08T15:50:31.311576+00:00",
      "latest_item_url": null,
      "product": "guardian",
      "public_safe_summary": "NVD: Allocation of Resources Without Limits or Throttling in ueberauth guardian allows denial of service via unbounded atom creation from attacker-influenced binary input. NVD: Guardian.Plug.Keys derives connection and session namespace keys by passing arbitrary binaries to String.to_atom/1. NVD: base_key/1 in lib/guardian/plug/keys.ex converts any binary into the atom :\"guardian_<input>\", and the derived helpers claims_key/1, resource_key/1, and token_key/1 create a second atom on top of that.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260808T155819Z/items/CVE-2026-54894.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: ueberauth / guardian",
      "source_published_impact": "Source describes service availability risk. Possible impact: The affected service may become unavailable or unreliable.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Allocation of Resources Without Limits or Throttling in ueberauth guardian allows denial of service via unbounded atom creation from attacker-influenced binary input. NVD: Guardian.Plug.Keys derives connection and session namespace keys by passing arbitrary binaries to String.to_atom/1. NVD: base_key/1 in lib/guardian/plug/keys.ex converts any binary into the atom :\"guardian_<input>\", and the derived helpers claims_key/1, resource_key/1, and token_key/1 create a second atom on top of that.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-54894/timeline.json",
      "vendor": "ueberauth"
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-54909/",
      "current_public_safe_latest": false,
      "cvss_score": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.29874,
      "epss_score": 0.00371,
      "first_observed_at": "2026-08-07T21:58:42.606809+00:00",
      "id": "CVE-2026-54909",
      "impact_tags": [
        "service availability review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-07T21:58:42.606809+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: pion/stun is a Go implementation of STUN. NVD: Prior to 3.1.3, XORMappedAddress.GetFromAs can panic while parsing a malformed short XOR-MAPPED-ADDRESS attribute in STUN or ICE Binding-response parsing paths, allowing remote denial of service. NVD: This issue is fixed in version 3.1.3.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260807T220457Z/items/CVE-2026-54909.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes service availability risk. Possible impact: The affected service may become unavailable or unreliable.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: pion/stun is a Go implementation of STUN. NVD: Prior to 3.1.3, XORMappedAddress.GetFromAs can panic while parsing a malformed short XOR-MAPPED-ADDRESS attribute in STUN or ICE Binding-response parsing paths, allowing remote denial of service. NVD: This issue is fixed in version 3.1.3.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-54909/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-54910/",
      "current_public_safe_latest": false,
      "cvss_score": 7.7,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.22959,
      "epss_score": 0.00307,
      "first_observed_at": "2026-07-27T12:38:45.912501+00:00",
      "id": "CVE-2026-54910",
      "impact_tags": [
        "path traversal review",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-27T12:38:45.912501+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: FileBrowser Quantum is a free, self-hosted, web-based file manager. NVD: Prior to version 1.4.3-beta, the subtitlesHandler endpoint (GET /api/media/subtitles) accepts two user-controlled query parameters: path and name, both of which are used in filesystem operations without sanitization, creating two independent path traversal... NVD: The primary vector is the path parameter: it is passed directly to idx.GetRealPath() without calling SanitizeUserPath(), allowing an attacker to escape the storage root and set parentDir to any directory on the host.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260727T124133Z/items/CVE-2026-54910.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes path traversal review · authenticated boundary. Possible impact: An attacker may be able to reach files outside the intended application path.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: FileBrowser Quantum is a free, self-hosted, web-based file manager. NVD: Prior to version 1.4.3-beta, the subtitlesHandler endpoint (GET /api/media/subtitles) accepts two user-controlled query parameters: path and name, both of which are used in filesystem operations without sanitization, creating two independent path traversal... NVD: The primary vector is the path parameter: it is passed directly to idx.GetRealPath() without calling SanitizeUserPath(), allowing an attacker to escape the storage root and set parentDir to any directory on the host.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-54910/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "yhirose / cpp-httplib",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-54919/",
      "current_public_safe_latest": false,
      "cvss_score": 7.4,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.17954,
      "epss_score": 0.00264,
      "first_observed_at": "2026-07-17T16:36:32.072333+00:00",
      "id": "CVE-2026-54919",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-17T16:36:32.072333+00:00",
      "latest_item_url": null,
      "product": "cpp-httplib",
      "public_safe_summary": "NVD: cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. NVD: In affected Mbed TLS backend versions from 0.31.0 through 0.46.1 and wolfSSL backend versions from 0.33.0 through 0.46.1, when cpp-httplib is built with CPPHTTPLIB_MBEDTLS_SUPPORT or CPPHTTPLIB_WOLFSSL_SUPPORT and a client connects to an IP-literal host with... NVD: This issue is fixed in version 0.47.0.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260717T164048Z/items/CVE-2026-54919.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: yhirose / cpp-httplib",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. NVD: In affected Mbed TLS backend versions from 0.31.0 through 0.46.1 and wolfSSL backend versions from 0.33.0 through 0.46.1, when cpp-httplib is built with CPPHTTPLIB_MBEDTLS_SUPPORT or CPPHTTPLIB_WOLFSSL_SUPPORT and a client connects to an IP-literal host with... NVD: This issue is fixed in version 0.47.0.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-54919/timeline.json",
      "vendor": "yhirose"
    },
    {
      "affected_label": "microsoft / exchange_online",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-54998/",
      "current_public_safe_latest": false,
      "cvss_score": 8.8,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.45908,
      "epss_score": 0.0063,
      "first_observed_at": "2026-07-09T22:45:10.548837+00:00",
      "id": "CVE-2026-54998",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-09T22:45:10.548837+00:00",
      "latest_item_url": null,
      "product": "exchange_online",
      "public_safe_summary": "NVD: Incorrect authorization in Microsoft Exchange Online allows an authorized attacker to elevate privileges over a network.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260709T224554Z/items/CVE-2026-54998.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: microsoft / exchange_online; affected version context: -",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Incorrect authorization in Microsoft Exchange Online allows an authorized attacker to elevate privileges over a network.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-54998/timeline.json",
      "vendor": "microsoft"
    },
    {
      "affected_label": "coder / coder",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-55076/",
      "current_public_safe_latest": false,
      "cvss_score": 7.4,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.38056,
      "epss_score": 0.00479,
      "first_observed_at": "2026-07-14T22:16:58.989760+00:00",
      "id": "CVE-2026-55076",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-14T22:16:58.989760+00:00",
      "latest_item_url": null,
      "product": "coder",
      "public_safe_summary": "NVD: Coder allows organizations to provision remote development environments via Terraform. NVD: Prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2, Coder's OIDC callback checked email_verified with a direct Go bool type assertion. NVD: When an IdP returned the claim as a non-boolean (for example the string \"false\") or omitted it, the assertion failed open and the email was treated as verified.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260714T222111Z/items/CVE-2026-55076.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: coder / coder",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Coder allows organizations to provision remote development environments via Terraform. NVD: Prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2, Coder's OIDC callback checked email_verified with a direct Go bool type assertion. NVD: When an IdP returned the claim as a non-boolean (for example the string \"false\") or omitted it, the assertion failed open and the email was treated as verified.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-55076/timeline.json",
      "vendor": "coder"
    },
    {
      "affected_label": "coder / coder",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-55077/",
      "current_public_safe_latest": false,
      "cvss_score": 7.2,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.45318,
      "epss_score": 0.00615,
      "first_observed_at": "2026-07-14T22:16:58.989760+00:00",
      "id": "CVE-2026-55077",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-14T22:16:58.989760+00:00",
      "latest_item_url": null,
      "product": "coder",
      "public_safe_summary": "NVD: Coder allows organizations to provision remote development environments via Terraform. NVD: Prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2, the PUT /api/v2/users/{user}/password endpoint authorized only ActionUpdatePersonal and did not prevent a user-admin from resetting an owner account's password. NVD: It also did not require the current password when an admin reset another user's password.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260714T222111Z/items/CVE-2026-55077.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: coder / coder",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Coder allows organizations to provision remote development environments via Terraform. NVD: Prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2, the PUT /api/v2/users/{user}/password endpoint authorized only ActionUpdatePersonal and did not prevent a user-admin from resetting an owner account's password. NVD: It also did not require the current password when an admin reset another user's password.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-55077/timeline.json",
      "vendor": "coder"
    },
    {
      "affected_label": "coder / coder",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-55078/",
      "current_public_safe_latest": false,
      "cvss_score": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.44693,
      "epss_score": 0.00602,
      "first_observed_at": "2026-07-14T22:16:58.989760+00:00",
      "id": "CVE-2026-55078",
      "impact_tags": [
        "service availability review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-14T22:16:58.989760+00:00",
      "latest_item_url": null,
      "product": "coder",
      "public_safe_summary": "NVD: Coder allows organizations to provision remote development environments via Terraform. NVD: Starting in version 2.17.0 and prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2, POST /api/v2/files converts zip uploads to tar in memory via CreateTarFromZip, which enforced a per-entry size limit but no aggregate limit on total decompressed output... NVD: Exploitation requires authenticated file-upload access and the impact is limited to availability (denial of service).",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260714T222111Z/items/CVE-2026-55078.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: coder / coder",
      "source_published_impact": "Source describes service availability risk. Possible impact: The affected service may become unavailable or unreliable.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Coder allows organizations to provision remote development environments via Terraform. NVD: Starting in version 2.17.0 and prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2, POST /api/v2/files converts zip uploads to tar in memory via CreateTarFromZip, which enforced a per-entry size limit but no aggregate limit on total decompressed output... NVD: Exploitation requires authenticated file-upload access and the impact is limited to availability (denial of service).",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-55078/timeline.json",
      "vendor": "coder"
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-5523/",
      "current_public_safe_latest": false,
      "cvss_score": 8.8,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.22898,
      "epss_score": 0.00309,
      "first_observed_at": "2026-07-16T05:57:17.509937+00:00",
      "id": "CVE-2026-5523",
      "impact_tags": [
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-16T05:57:17.509937+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Divi Form Builder plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 5.1.8. NVD: This is due to the update_user() function accepting a user ID parameter from form submissions without verifying that the authenticated user has permission to edit that specific user account, and the handle_register_submission() function only checking if any... NVD: This makes it possible for authenticated attackers, with subscriber-level access and above, to change the email address and password of any user account, including administrators, resulting in complete account takeover.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260716T055845Z/items/CVE-2026-5523.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes authenticated boundary. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Divi Form Builder plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 5.1.8. NVD: This is due to the update_user() function accepting a user ID parameter from form submissions without verifying that the authenticated user has permission to edit that specific user account, and the handle_register_submission() function only checking if any... NVD: This makes it possible for authenticated attackers, with subscriber-level access and above, to change the email address and password of any user account, including administrators, resulting in complete account takeover.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-5523/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "python / pillow",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-55379/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.28535,
      "epss_score": 0.00364,
      "first_observed_at": "2026-07-13T17:24:46.617207+00:00",
      "id": "CVE-2026-55379",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-13T17:24:46.617207+00:00",
      "latest_item_url": null,
      "product": "pillow",
      "public_safe_summary": "NVD: Pillow is a Python imaging library. NVD: Prior to 12.3.0, PIL/BdfFontFile.py bdf_char() read the BBX width and height field from a BDF font file and passed attacker-controlled dimensions to Image.new() without calling Image._decompression_bomb_check(), bypassing Pillow's documented decompression... NVD: This issue is fixed in version 12.3.0.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260713T172750Z/items/CVE-2026-55379.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: python / pillow",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: Pillow is a Python imaging library. NVD: Prior to 12.3.0, PIL/BdfFontFile.py bdf_char() read the BBX width and height field from a BDF font file and passed attacker-controlled dimensions to Image.new() without calling Image._decompression_bomb_check(), bypassing Pillow's documented decompression... NVD: This issue is fixed in version 12.3.0.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-55379/timeline.json",
      "vendor": "python"
    },
    {
      "affected_label": "python / pillow",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-55380/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.28223,
      "epss_score": 0.00361,
      "first_observed_at": "2026-07-13T17:24:46.617207+00:00",
      "id": "CVE-2026-55380",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-13T17:24:46.617207+00:00",
      "latest_item_url": null,
      "product": "pillow",
      "public_safe_summary": "NVD: Pillow is a Python imaging library. NVD: Prior to 12.3.0, PIL/GdImageFile.py GdImageFile._open() read image dimensions from the GD 2.x header and stored them in self._size without calling Image._decompression_bomb_check(), allowing a crafted .gd file to trigger excessive C-heap allocation when... NVD: This issue is fixed in version 12.3.0.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260713T172750Z/items/CVE-2026-55380.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: python / pillow",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: Pillow is a Python imaging library. NVD: Prior to 12.3.0, PIL/GdImageFile.py GdImageFile._open() read image dimensions from the GD 2.x header and stored them in self._size without calling Image._decompression_bomb_check(), allowing a crafted .gd file to trigger excessive C-heap allocation when... NVD: This issue is fixed in version 12.3.0.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-55380/timeline.json",
      "vendor": "python"
    },
    {
      "affected_label": "coder / coder",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-55435/",
      "current_public_safe_latest": false,
      "cvss_score": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.23461,
      "epss_score": 0.00315,
      "first_observed_at": "2026-07-14T16:41:04.043226+00:00",
      "id": "CVE-2026-55435",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-14T16:41:04.043226+00:00",
      "latest_item_url": null,
      "product": "coder",
      "public_safe_summary": "NVD: Coder allows organizations to provision remote development environments via Terraform. NVD: Starting in version 2.30.0 and prior to versions 2.32.7, 2.33.8, and 2.34.2, AI Bridge proxy endpoints authenticate via Server.IsAuthorized in coderd/aibridgedserver, which validates key format, expiry, secret and deleted or system users but does not check... NVD: Because suspension does not revoke existing API keys, a suspended user's unexpired token keeps working.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260714T164406Z/items/CVE-2026-55435.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: coder / coder",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Coder allows organizations to provision remote development environments via Terraform. NVD: Starting in version 2.30.0 and prior to versions 2.32.7, 2.33.8, and 2.34.2, AI Bridge proxy endpoints authenticate via Server.IsAuthorized in coderd/aibridgedserver, which validates key format, expiry, secret and deleted or system users but does not check... NVD: Because suspension does not revoke existing API keys, a suspended user's unexpired token keeps working.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-55435/timeline.json",
      "vendor": "coder"
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-55470/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.27637,
      "epss_score": 0.00354,
      "first_observed_at": "2026-07-15T22:16:59.245057+00:00",
      "id": "CVE-2026-55470",
      "impact_tags": [
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-15T22:16:59.245057+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. NVD: Prior to 6.9.10, the fix for CVE-2026-45367 incompletely patched the DSTU2 module, leaving FHIRPathEngine.matches() in org.hl7.fhir.dstu2/utils/FHIRPathEngine.java to call raw String.matches(sw) without RegexTimeout protection while replaceMatches() was... NVD: This issue is fixed in version 6.9.10.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260715T221956Z/items/CVE-2026-55470.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes remote exposure · authenticated boundary. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. NVD: Prior to 6.9.10, the fix for CVE-2026-45367 incompletely patched the DSTU2 module, leaving FHIRPathEngine.matches() in org.hl7.fhir.dstu2/utils/FHIRPathEngine.java to call raw String.matches(sw) without RegexTimeout protection while replaceMatches() was... NVD: This issue is fixed in version 6.9.10.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-55470/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-55471/",
      "current_public_safe_latest": false,
      "cvss_score": 8.7,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.22821,
      "epss_score": 0.00309,
      "first_observed_at": "2026-07-15T22:16:59.245057+00:00",
      "id": "CVE-2026-55471",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-15T22:16:59.245057+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. NVD: Prior to 6.9.10, org.hl7.fhir.utilities.XsltUtilities saxonTransform(...) overloads instantiated a bare net.sf.saxon.TransformerFactoryImpl() without ACCESS_EXTERNAL_DTD or ACCESS_EXTERNAL_STYLESHEET restrictions, allowing an attacker who controls or can... NVD: This issue is fixed in version 6.9.10.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260715T221956Z/items/CVE-2026-55471.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. NVD: Prior to 6.9.10, org.hl7.fhir.utilities.XsltUtilities saxonTransform(...) overloads instantiated a bare net.sf.saxon.TransformerFactoryImpl() without ACCESS_EXTERNAL_DTD or ACCESS_EXTERNAL_STYLESHEET restrictions, allowing an attacker who controls or can... NVD: This issue is fixed in version 6.9.10.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-55471/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "openwrt / openwrt",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-55490/",
      "current_public_safe_latest": false,
      "cvss_score": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.48293,
      "epss_score": 0.00684,
      "first_observed_at": "2026-07-14T22:16:58.989760+00:00",
      "id": "CVE-2026-55490",
      "impact_tags": [
        "service availability review",
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-14T22:16:58.989760+00:00",
      "latest_item_url": null,
      "product": "openwrt",
      "public_safe_summary": "NVD: OpenWrt is a Linux operating system targeting embedded devices. NVD: Before v25.12.5, an integer underflow in handle_send_a() of the Emergency Access Daemon allows any unauthenticated attacker on the local network to crash the daemon by sending a single crafted UDP packet. NVD: The message length underflows before a bounds check and is then passed to memcpy as a very large size.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260714T222111Z/items/CVE-2026-55490.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: openwrt / openwrt",
      "source_published_impact": "Source describes service availability risk · remote exposure · authenticated boundary. Possible impact: The affected service may become unavailable or unreliable.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: OpenWrt is a Linux operating system targeting embedded devices. NVD: Before v25.12.5, an integer underflow in handle_send_a() of the Emergency Access Daemon allows any unauthenticated attacker on the local network to crash the daemon by sending a single crafted UDP packet. NVD: The message length underflows before a bounds check and is then passed to memcpy as a very large size.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-55490/timeline.json",
      "vendor": "openwrt"
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-55578/",
      "current_public_safe_latest": false,
      "cvss_score": 8.8,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.28909,
      "epss_score": 0.00362,
      "first_observed_at": "2026-08-03T17:21:47.396014+00:00",
      "id": "CVE-2026-55578",
      "impact_tags": [
        "code execution review",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-03T17:21:47.396014+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Pheditor is a single-file editor and file manager written in PHP. NVD: From version 2.0.1 to before version 2.0.6, the terminal feature in Pheditor uses an incomplete character blocklist to sanitize user-supplied commands before passing them to shell_exec(). NVD: After the fix for GHSA-9643-6xjp-vx57 (which added $ to the blocklist), the characters | (single pipe), (backtick), and the newline byte (0x0A) remain unblocked.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260803T174717Z/items/CVE-2026-55578.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes code execution review · authenticated boundary. Possible impact: An attacker may be able to run code or commands on affected systems.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: Pheditor is a single-file editor and file manager written in PHP. NVD: From version 2.0.1 to before version 2.0.6, the terminal feature in Pheditor uses an incomplete character blocklist to sanitize user-supplied commands before passing them to shell_exec(). NVD: After the fix for GHSA-9643-6xjp-vx57 (which added $ to the blocklist), the characters | (single pipe), (backtick), and the newline byte (0x0A) remain unblocked.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-55578/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-55579/",
      "current_public_safe_latest": false,
      "cvss_score": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.45473,
      "epss_score": 0.00603,
      "first_observed_at": "2026-08-03T17:21:47.396014+00:00",
      "id": "CVE-2026-55579",
      "impact_tags": [
        "code execution review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-03T17:21:47.396014+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Pheditor is a single-file editor and file manager written in PHP. NVD: From version 2.0.1 to before version 2.0.6, Pheditor ships with a hardcoded default password admin (SHA-512 hash stored at pheditor.php:11). NVD: There is no mechanism to force a password change on first login.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260803T174717Z/items/CVE-2026-55579.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes code execution review. Possible impact: An attacker may be able to run code or commands on affected systems.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: Pheditor is a single-file editor and file manager written in PHP. NVD: From version 2.0.1 to before version 2.0.6, Pheditor ships with a hardcoded default password admin (SHA-512 hash stored at pheditor.php:11). NVD: There is no mechanism to force a password change on first login.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-55579/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-55638/",
      "current_public_safe_latest": false,
      "cvss_score": 8.6,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.29447,
      "epss_score": 0.00372,
      "first_observed_at": "2026-07-17T16:36:32.072333+00:00",
      "id": "CVE-2026-55638",
      "impact_tags": [
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-17T16:36:32.072333+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: 9Router is an AI router & token saver. NVD: Prior to 0.5.2, 9router protects /v1, /v1beta, /api/v1, and /api/v1beta in src/dashboardGuard.js but omits /codex before next.config.mjs rewrites /codex/* to /api/v1/responses. NVD: A remote unauthenticated attacker can send requests to /codex/* to bypass the API-key gate and cause the server to make upstream provider calls using operator-stored LLM provider credentials.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260717T164048Z/items/CVE-2026-55638.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes remote exposure · authenticated boundary. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: 9Router is an AI router & token saver. NVD: Prior to 0.5.2, 9router protects /v1, /v1beta, /api/v1, and /api/v1beta in src/dashboardGuard.js but omits /codex before next.config.mjs rewrites /codex/* to /api/v1/responses. NVD: A remote unauthenticated attacker can send requests to /codex/* to bypass the API-key gate and cause the server to make upstream provider calls using operator-stored LLM provider credentials.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-55638/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-55641/",
      "current_public_safe_latest": false,
      "cvss_score": 8.2,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.15882,
      "epss_score": 0.00246,
      "first_observed_at": "2026-07-17T16:36:32.072333+00:00",
      "id": "CVE-2026-55641",
      "impact_tags": [
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-17T16:36:32.072333+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: 9Router is an AI router & token saver. NVD: Prior to 0.5.2, 9router determines whether a /v1 LLM proxy request is local by reading the client-controlled Host header, allowing a remote unauthenticated attacker to send Host: localhost and bypass API-key authentication. NVD: In the default configuration, this exposes the /v1 proxy to upstream provider calls using stored provider credentials and allows /v1/search with the searxng provider_options.baseUrl parameter to drive server-side requests to internal or cloud-metadata hosts.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260717T164048Z/items/CVE-2026-55641.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes remote exposure · authenticated boundary. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: 9Router is an AI router & token saver. NVD: Prior to 0.5.2, 9router determines whether a /v1 LLM proxy request is local by reading the client-controlled Host header, allowing a remote unauthenticated attacker to send Host: localhost and bypass API-key authentication. NVD: In the default configuration, this exposes the /v1 proxy to upstream provider calls using stored provider credentials and allows /v1/search with the searxng provider_options.baseUrl parameter to drive server-side requests to internal or cloud-metadata hosts.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-55641/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-55669/",
      "current_public_safe_latest": false,
      "cvss_score": 4.2,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.01645,
      "epss_score": 0.00112,
      "first_observed_at": "2026-07-17T16:36:32.072333+00:00",
      "id": "CVE-2026-55669",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-17T16:36:32.072333+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: ZITADEL is an open source identity management platform. NVD: Prior to 3.4.12 and 4.15.2, ZITADEL's external JWT Identity Provider validates a token's signature and issuer (iss) but not the audience (aud) claim, allowing a validly signed token from a trusted issuer for another relying party to be accepted by ZITADEL. NVD: This issue is fixed in versions 3.4.12 and 4.15.2.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260717T164048Z/items/CVE-2026-55669.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: versions.",
      "source_published_summary": "NVD: ZITADEL is an open source identity management platform. NVD: Prior to 3.4.12 and 4.15.2, ZITADEL's external JWT Identity Provider validates a token's signature and issuer (iss) but not the audience (aud) claim, allowing a validly signed token from a trusted issuer for another relying party to be accepted by ZITADEL. NVD: This issue is fixed in versions 3.4.12 and 4.15.2.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-55669/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-55687/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.30747,
      "epss_score": 0.00385,
      "first_observed_at": "2026-07-17T16:36:32.072333+00:00",
      "id": "CVE-2026-55687",
      "impact_tags": [
        "service availability review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-17T16:36:32.072333+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. NVD: Versions 6.0.1, 5.5.4, 5.4.4, 5.3.5, and possibly prior contain an out-of-bounds write in jpeg_parse_dqt_marker() in components/esp_driver_jpeg/jpeg_parse_marker.c because the attacker-controlled DQT marker Tq nibble is used as an index into the qt_tbl array... NVD: This issue is fixed in version 6.0.2 and is expected to be fixed in versions 5.5.5, 5.4.5, and 5.3.6.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260717T164048Z/items/CVE-2026-55687.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes service availability risk. Possible impact: The affected service may become unavailable or unreliable.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version, versions.",
      "source_published_summary": "NVD: ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. NVD: Versions 6.0.1, 5.5.4, 5.4.4, 5.3.5, and possibly prior contain an out-of-bounds write in jpeg_parse_dqt_marker() in components/esp_driver_jpeg/jpeg_parse_marker.c because the attacker-controlled DQT marker Tq nibble is used as an index into the qt_tbl array... NVD: This issue is fixed in version 6.0.2 and is expected to be fixed in versions 5.5.5, 5.4.5, and 5.3.6.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-55687/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-55707/",
      "current_public_safe_latest": false,
      "cvss_score": 7.1,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.39474,
      "epss_score": 0.00487,
      "first_observed_at": "2026-08-12T05:08:50.991993+00:00",
      "id": "CVE-2026-55707",
      "impact_tags": [
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-12T05:08:50.991993+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: In OpenStack Neutron before 28.0.2, the subnetpool onboarding API does not verify ownership of the target subnets. NVD: An authenticated user can onboard subnets from another project's shared network into their own subnetpool, mutating the victim's subnet state and altering L3 routing and address scope behavior for victim routers.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260812T051428Z/items/CVE-2026-55707.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes authenticated boundary. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: In OpenStack Neutron before 28.0.2, the subnetpool onboarding API does not verify ownership of the target subnets. NVD: An authenticated user can onboard subnets from another project's shared network into their own subnetpool, mutating the victim's subnet state and altering L3 routing and address scope behavior for victim routers.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-55707/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "ueberauth / guardian",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-55733/",
      "current_public_safe_latest": false,
      "cvss_score": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.19037,
      "epss_score": 0.00271,
      "first_observed_at": "2026-08-08T15:50:31.311576+00:00",
      "id": "CVE-2026-55733",
      "impact_tags": [
        "service availability review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-08T15:50:31.311576+00:00",
      "latest_item_url": null,
      "product": "guardian",
      "public_safe_summary": "NVD: Allocation of Resources Without Limits or Throttling in ueberauth guardian allows denial of service via unbounded atom creation from attacker-controlled binary input. NVD: Guardian.Permissions.AtomEncoding encodes permission scopes by passing arbitrary binaries to String.to_atom/1. NVD: When encode/3 in lib/guardian/permissions/atom_encoding.ex is called with a list, each binary entry is handled by the encode_value/3 binary clause, which calls String.to_atom(value) with no allow-list check.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260808T155819Z/items/CVE-2026-55733.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: ueberauth / guardian",
      "source_published_impact": "Source describes service availability risk. Possible impact: The affected service may become unavailable or unreliable.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Allocation of Resources Without Limits or Throttling in ueberauth guardian allows denial of service via unbounded atom creation from attacker-controlled binary input. NVD: Guardian.Permissions.AtomEncoding encodes permission scopes by passing arbitrary binaries to String.to_atom/1. NVD: When encode/3 in lib/guardian/permissions/atom_encoding.ex is called with a list, each binary entry is handled by the encode_value/3 binary clause, which calls String.to_atom(value) with no allow-list check.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-55733/timeline.json",
      "vendor": "ueberauth"
    },
    {
      "affected_label": "ueberauth / guardian",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-55734/",
      "current_public_safe_latest": false,
      "cvss_score": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.20827,
      "epss_score": 0.00286,
      "first_observed_at": "2026-08-08T15:50:31.311576+00:00",
      "id": "CVE-2026-55734",
      "impact_tags": [
        "service availability review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-08T15:50:31.311576+00:00",
      "latest_item_url": null,
      "product": "guardian",
      "public_safe_summary": "NVD: Allocation of Resources Without Limits or Throttling vulnerability in ueberauth guardian (Guardian.Permissions module) allows a denial of service via BEAM atom-table exhaustion. NVD: This vulnerability is associated with program file lib/guardian/permissions.ex and program routines 'Elixir.Guardian.Permissions':encode_permissions!/1, 'Elixir.Guardian.Permissions':encode_permissions_into_claims!/2... NVD: The Guardian.Permissions mixin installs a public encode_permissions!/1 function on every module that does use Guardian.Permissions.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260808T155819Z/items/CVE-2026-55734.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: ueberauth / guardian",
      "source_published_impact": "Source describes service availability risk. Possible impact: The affected service may become unavailable or unreliable.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Allocation of Resources Without Limits or Throttling vulnerability in ueberauth guardian (Guardian.Permissions module) allows a denial of service via BEAM atom-table exhaustion. NVD: This vulnerability is associated with program file lib/guardian/permissions.ex and program routines 'Elixir.Guardian.Permissions':encode_permissions!/1, 'Elixir.Guardian.Permissions':encode_permissions_into_claims!/2... NVD: The Guardian.Permissions mixin installs a public encode_permissions!/1 function on every module that does use Guardian.Permissions.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-55734/timeline.json",
      "vendor": "ueberauth"
    },
    {
      "affected_label": "ueberauth / guardian",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-55735/",
      "current_public_safe_latest": false,
      "cvss_score": 8.2,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.20374,
      "epss_score": 0.00282,
      "first_observed_at": "2026-08-08T15:50:31.311576+00:00",
      "id": "CVE-2026-55735",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-08T15:50:31.311576+00:00",
      "latest_item_url": null,
      "product": "guardian",
      "public_safe_summary": "NVD: Improper Verification of Cryptographic Signature in ueberauth guardian allows an unauthenticated attacker to revoke a victim's session with a forged token. NVD: The resulting unverified claims are forwarded directly to the configured token module's revoke callback and the implementation's on_revoke callback, a state-mutating sink. NVD: The sibling operations refresh/2 and exchange/4 both call decode_and_verify first, so the signature is checked before anything acts on the claims; revoke/3 is the only state-mutating path that acts on claims without verifying the signature.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260808T155819Z/items/CVE-2026-55735.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: ueberauth / guardian",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Improper Verification of Cryptographic Signature in ueberauth guardian allows an unauthenticated attacker to revoke a victim's session with a forged token. NVD: The resulting unverified claims are forwarded directly to the configured token module's revoke callback and the implementation's on_revoke callback, a state-mutating sink. NVD: The sibling operations refresh/2 and exchange/4 both call decode_and_verify first, so the signature is checked before anything acts on the claims; revoke/3 is the only state-mutating path that acts on claims without verifying the signature.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-55735/timeline.json",
      "vendor": "ueberauth"
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-55780/",
      "current_public_safe_latest": false,
      "cvss_score": 2.4,
      "cvss_severity": "LOW",
      "epss_percentile": 0.01623,
      "epss_score": 0.00112,
      "first_observed_at": "2026-07-17T16:36:32.072333+00:00",
      "id": "CVE-2026-55780",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-17T16:36:32.072333+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: NanaZip is the 7-Zip derivative intended for the modern Windows experience. NVD: Prior to 6.5.1749.0, NanaZip's .NET single-file bundle handler in NanaZip.Codecs.Archive.DotNetSingleFile.cpp sizes its extraction buffer from the bundle entry Size field, which is only checked for sign and is not validated against the real file size. NVD: A crafted bundle can cause an attacker-chosen allocation inside Extract, where std::bad_alloc or std::length_error can escape across the COM STDMETHODCALLTYPE boundary and crash the process.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260717T164048Z/items/CVE-2026-55780.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: NanaZip is the 7-Zip derivative intended for the modern Windows experience. NVD: Prior to 6.5.1749.0, NanaZip's .NET single-file bundle handler in NanaZip.Codecs.Archive.DotNetSingleFile.cpp sizes its extraction buffer from the bundle entry Size field, which is only checked for sign and is not validated against the real file size. NVD: A crafted bundle can cause an attacker-chosen allocation inside Extract, where std::bad_alloc or std::length_error can escape across the COM STDMETHODCALLTYPE boundary and crash the process.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-55780/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-55781/",
      "current_public_safe_latest": false,
      "cvss_score": 2.4,
      "cvss_severity": "LOW",
      "epss_percentile": 0.01624,
      "epss_score": 0.00112,
      "first_observed_at": "2026-07-17T16:36:32.072333+00:00",
      "id": "CVE-2026-55781",
      "impact_tags": [
        "service availability review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-17T16:36:32.072333+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: NanaZip is the 7-Zip derivative intended for the modern Windows experience. NVD: Prior to 6.5.1749.0, NanaZip's UFS and FFS image handler in NanaZip.Codecs.Archive.Ufs.cpp validates the superblock block size only against the MINBSIZE lower bound and does not validate the fs_fsize fragment size, allowing attacker-controlled 32-bit fields... NVD: A tiny crafted UFS image can force multi-gigabyte allocations during open or extraction, causing memory exhaustion or process termination.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260717T164048Z/items/CVE-2026-55781.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes service availability risk. Possible impact: The affected service may become unavailable or unreliable.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: NanaZip is the 7-Zip derivative intended for the modern Windows experience. NVD: Prior to 6.5.1749.0, NanaZip's UFS and FFS image handler in NanaZip.Codecs.Archive.Ufs.cpp validates the superblock block size only against the MINBSIZE lower bound and does not validate the fs_fsize fragment size, allowing attacker-controlled 32-bit fields... NVD: A tiny crafted UFS image can force multi-gigabyte allocations during open or extraction, causing memory exhaustion or process termination.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-55781/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-55782/",
      "current_public_safe_latest": false,
      "cvss_score": 2.4,
      "cvss_severity": "LOW",
      "epss_percentile": 0.01707,
      "epss_score": 0.00113,
      "first_observed_at": "2026-07-17T16:36:32.072333+00:00",
      "id": "CVE-2026-55782",
      "impact_tags": [
        "service availability review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-17T16:36:32.072333+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: NanaZip is the 7-Zip derivative intended for the modern Windows experience. NVD: Prior to 6.5.1749.0, NanaZip's WebAssembly archive handler in NanaZip.Codecs.Archive.WebAssembly.cpp allocates buffers from attacker-controlled 32-bit section and custom-name length fields without validating them against the data present in the file. NVD: A tiny crafted module can force multi-gigabyte allocations during listing or extraction through NameSize, Information.Size, and std::string or vector allocation paths, causing memory exhaustion or process termination.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260717T164048Z/items/CVE-2026-55782.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes service availability risk. Possible impact: The affected service may become unavailable or unreliable.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: NanaZip is the 7-Zip derivative intended for the modern Windows experience. NVD: Prior to 6.5.1749.0, NanaZip's WebAssembly archive handler in NanaZip.Codecs.Archive.WebAssembly.cpp allocates buffers from attacker-controlled 32-bit section and custom-name length fields without validating them against the data present in the file. NVD: A tiny crafted module can force multi-gigabyte allocations during listing or extraction through NameSize, Information.Size, and std::string or vector allocation paths, causing memory exhaustion or process termination.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-55782/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "python / pillow",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-55798/",
      "current_public_safe_latest": false,
      "cvss_score": 4.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.03469,
      "epss_score": 0.00136,
      "first_observed_at": "2026-07-13T17:24:46.617207+00:00",
      "id": "CVE-2026-55798",
      "impact_tags": [
        "command injection risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-13T17:24:46.617207+00:00",
      "latest_item_url": null,
      "product": "pillow",
      "public_safe_summary": "NVD: Pillow is a Python imaging library. NVD: Prior to 12.3.0, WindowsViewer.get_command() constructed a cmd.exe shell command by directly embedding a file path into an f-string without escaping and passed the result to subprocess.Popen(..., shell=True), allowing shell metacharacters in the file path to... NVD: This issue is fixed in version 12.3.0.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260713T172750Z/items/CVE-2026-55798.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: python / pillow",
      "source_published_impact": "Source describes command injection risk. Possible impact: An attacker may be able to run unintended system commands through the affected component.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: Pillow is a Python imaging library. NVD: Prior to 12.3.0, WindowsViewer.get_command() constructed a cmd.exe shell command by directly embedding a file path into an f-string without escaping and passed the result to subprocess.Popen(..., shell=True), allowing shell metacharacters in the file path to... NVD: This issue is fixed in version 12.3.0.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-55798/timeline.json",
      "vendor": "python"
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-5582/",
      "current_public_safe_latest": false,
      "cvss_score": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.0315,
      "epss_score": 0.00132,
      "first_observed_at": "2026-08-06T11:35:20.545945+00:00",
      "id": "CVE-2026-5582",
      "impact_tags": [
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-06T11:35:20.545945+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The FuseWP plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.24.2. NVD: This is due to missing nonce verification on the toggle_sync_status() function. NVD: This makes it possible for unauthenticated attackers to toggle the status of sync rules (enable/disable) via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260806T114533Z/items/CVE-2026-5582.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes remote exposure · authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The FuseWP plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.24.2. NVD: This is due to missing nonce verification on the toggle_sync_status() function. NVD: This makes it possible for unauthenticated attackers to toggle the status of sync rules (enable/disable) via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-5582/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-55830/",
      "current_public_safe_latest": false,
      "cvss_score": 8.3,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.13315,
      "epss_score": 0.00226,
      "first_observed_at": "2026-07-15T22:16:59.245057+00:00",
      "id": "CVE-2026-55830",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-15T22:16:59.245057+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: RestrictedPython is a tool that helps to define a subset of the Python language which allows to provide a program input into a trusted environment. NVD: Prior to 8.3, check_function_argument_names() rejected protected guard hook names for regular, variadic, and keyword-only arguments but omitted positional-only arguments, allowing __getattr__, _getitem_, _write_, or _print_ to be shadowed by a local parameter... NVD: This issue is fixed in version 8.3.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260715T221956Z/items/CVE-2026-55830.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: RestrictedPython is a tool that helps to define a subset of the Python language which allows to provide a program input into a trusted environment. NVD: Prior to 8.3, check_function_argument_names() rejected protected guard hook names for regular, variadic, and keyword-only arguments but omitted positional-only arguments, allowing __getattr__, _getitem_, _write_, or _print_ to be shadowed by a local parameter... NVD: This issue is fixed in version 8.3.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-55830/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "netty / netty",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-55831/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.34711,
      "epss_score": 0.00423,
      "first_observed_at": "2026-07-27T22:30:18.664011+00:00",
      "id": "CVE-2026-55831",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-27T22:30:18.664011+00:00",
      "latest_item_url": null,
      "product": "netty",
      "public_safe_summary": "NVD: Netty is a network application framework for development of protocol servers and clients. NVD: Prior to 4.1.136.Final and 4.2.16.Final, Netty's SPDY SETTINGS decoder accepts a peer-declared SETTINGS entry count up to the 24-bit frame-length limit and materializes every unique setting ID in DefaultSpdySettingsFrame, allowing a remote SPDY/3.1 peer to... NVD: This issue is fixed in versions 4.1.136.Final and 4.2.16.Final.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260727T223632Z/items/CVE-2026-55831.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: netty / netty",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: versions.",
      "source_published_summary": "NVD: Netty is a network application framework for development of protocol servers and clients. NVD: Prior to 4.1.136.Final and 4.2.16.Final, Netty's SPDY SETTINGS decoder accepts a peer-declared SETTINGS entry count up to the 24-bit frame-length limit and materializes every unique setting ID in DefaultSpdySettingsFrame, allowing a remote SPDY/3.1 peer to... NVD: This issue is fixed in versions 4.1.136.Final and 4.2.16.Final.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-55831/timeline.json",
      "vendor": "netty"
    },
    {
      "affected_label": "netty / netty",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-55833/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.34711,
      "epss_score": 0.00423,
      "first_observed_at": "2026-07-27T22:30:18.664011+00:00",
      "id": "CVE-2026-55833",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-27T22:30:18.664011+00:00",
      "latest_item_url": null,
      "product": "netty",
      "public_safe_summary": "NVD: Netty is a network application framework for development of protocol servers and clients. NVD: Prior to 4.1.136.Final and 4.2.16.Final, Netty SPDY header decoding continues inflating zlib-compressed header blocks after the raw header parser has exceeded maxHeaderSize and marked the frame truncated in SpdyFrameCodec, allowing a remote peer to send a... NVD: This issue is fixed in versions 4.1.136.Final and 4.2.16.Final.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260727T223632Z/items/CVE-2026-55833.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: netty / netty",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: versions.",
      "source_published_summary": "NVD: Netty is a network application framework for development of protocol servers and clients. NVD: Prior to 4.1.136.Final and 4.2.16.Final, Netty SPDY header decoding continues inflating zlib-compressed header blocks after the raw header parser has exceeded maxHeaderSize and marked the frame truncated in SpdyFrameCodec, allowing a remote peer to send a... NVD: This issue is fixed in versions 4.1.136.Final and 4.2.16.Final.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-55833/timeline.json",
      "vendor": "netty"
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-55849/",
      "current_public_safe_latest": false,
      "cvss_score": 8.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.05548,
      "epss_score": 0.0016,
      "first_observed_at": "2026-07-15T22:16:59.245057+00:00",
      "id": "CVE-2026-55849",
      "impact_tags": [
        "command execution review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-15T22:16:59.245057+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: @cyclonedx/cyclonedx-npm creates CycloneDX Software Bill of Materials from npm projects. NVD: From 2.1.0 before 5.0.0, the CLI passes user-supplied --workspace values to a subshell without proper sanitization when npm_execpath is unset or empty, allowing arbitrary OS command execution with the privileges of the invoking user. NVD: This issue is fixed in version 5.0.0.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260715T221956Z/items/CVE-2026-55849.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes command execution risk. Possible impact: An attacker may be able to run code or commands on affected systems.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: @cyclonedx/cyclonedx-npm creates CycloneDX Software Bill of Materials from npm projects. NVD: From 2.1.0 before 5.0.0, the CLI passes user-supplied --workspace values to a subshell without proper sanitization when npm_execpath is unset or empty, allowing arbitrary OS command execution with the privileges of the invoking user. NVD: This issue is fixed in version 5.0.0.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-55849/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-55877/",
      "current_public_safe_latest": false,
      "cvss_score": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.09234,
      "epss_score": 0.00194,
      "first_observed_at": "2026-07-15T22:16:59.245057+00:00",
      "id": "CVE-2026-55877",
      "impact_tags": [
        "XSS risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-15T22:16:59.245057+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Symfony UX is a JavaScript ecosystem for Symfony. NVD: From 2.17.0 before 2.36.1 and from 3.0.0 before 3.2.0, the ux_icon() Twig function is marked is_safe=['html'] and Icon::toHtml() inlines SVG source verbatim, allowing unsanitized local SVG files or Iconify on-demand JSON body responses containing nested... NVD: This issue is fixed in versions 2.36.1 and 3.2.0.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260715T221956Z/items/CVE-2026-55877.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes XSS risk. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: versions.",
      "source_published_summary": "NVD: Symfony UX is a JavaScript ecosystem for Symfony. NVD: From 2.17.0 before 2.36.1 and from 3.0.0 before 3.2.0, the ux_icon() Twig function is marked is_safe=['html'] and Icon::toHtml() inlines SVG source verbatim, allowing unsanitized local SVG files or Iconify on-demand JSON body responses containing nested... NVD: This issue is fixed in versions 2.36.1 and 3.2.0.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-55877/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-55878/",
      "current_public_safe_latest": false,
      "cvss_score": 7.8,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.04307,
      "epss_score": 0.00146,
      "first_observed_at": "2026-07-15T22:16:59.245057+00:00",
      "id": "CVE-2026-55878",
      "impact_tags": [
        "path traversal review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-15T22:16:59.245057+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Symfony UX is a JavaScript ecosystem for Symfony. NVD: From 2.32.0 before 2.36.1 and from 3.0.0 before 3.2.0, the ux:install console command installs files from a recipe kit by copying paths listed in a copy-files map, and because Path::isRelative() accepts paths like ../../../etc, a crafted or compromised kit... NVD: This issue is fixed in versions 2.36.1 and 3.2.0.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260715T221956Z/items/CVE-2026-55878.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes path traversal review. Possible impact: An attacker may be able to reach files outside the intended application path.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: versions.",
      "source_published_summary": "NVD: Symfony UX is a JavaScript ecosystem for Symfony. NVD: From 2.32.0 before 2.36.1 and from 3.0.0 before 3.2.0, the ux:install console command installs files from a recipe kit by copying paths listed in a copy-files map, and because Path::isRelative() accepts paths like ../../../etc, a crafted or compromised kit... NVD: This issue is fixed in versions 2.36.1 and 3.2.0.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-55878/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-55995/",
      "current_public_safe_latest": false,
      "cvss_score": 8.7,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.16635,
      "epss_score": 0.00252,
      "first_observed_at": "2026-08-05T11:32:09.387600+00:00",
      "id": "CVE-2026-55995",
      "impact_tags": [
        "service availability review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-05T11:32:09.387600+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A Double Free vulnerability in open-iscsi allows an unauthenticated MITM attacker to cause DoS. NVD: This issue affects open-iscsi: from ? NVD: through 56718d4e9d1a4f51c30697b5c0534144bb41c9bb.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260805T113552Z/items/CVE-2026-55995.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes service availability risk. Possible impact: The affected service may become unavailable or unreliable.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A Double Free vulnerability in open-iscsi allows an unauthenticated MITM attacker to cause DoS. NVD: This issue affects open-iscsi: from ? NVD: through 56718d4e9d1a4f51c30697b5c0534144bb41c9bb.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-55995/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "x.org / x_server",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-55999/",
      "current_public_safe_latest": false,
      "cvss_score": 8.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.11498,
      "epss_score": 0.00212,
      "first_observed_at": "2026-07-15T05:43:30.245469+00:00",
      "id": "CVE-2026-55999",
      "impact_tags": [
        "memory safety review",
        "local exposure relevant"
      ],
      "kev": false,
      "last_observed_at": "2026-07-15T05:43:30.245469+00:00",
      "latest_item_url": null,
      "product": "x_server",
      "public_safe_summary": "NVD: Local attackers with a X connection able to provide PCX fonts to the X server xorg-server before 21.2.24 and xwayland before 24.1.13 could cause a heap buffer overflow via SetFont due to missing glyph boundary checks. OSV: xorg-server / xwayland glamor font atlas Heap Buffer Overflow OSV: Local attackers with a X connection able to provide PCX fonts to the X server xorg-server before 21.2.24 and xwayland before 24.1.13 could cause a heap buffer overflow via SetFont due to missing glyph boundary checks.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260715T054459Z/items/CVE-2026-55999.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: x.org / x_server",
      "source_published_impact": "Source describes memory safety review · local exposure. Possible impact: The affected component has memory-safety risk that may lead to crash, privilege, or code-execution impact depending on exposure.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Local attackers with a X connection able to provide PCX fonts to the X server xorg-server before 21.2.24 and xwayland before 24.1.13 could cause a heap buffer overflow via SetFont due to missing glyph boundary checks. OSV: xorg-server / xwayland glamor font atlas Heap Buffer Overflow OSV: Local attackers with a X connection able to provide PCX fonts to the X server xorg-server before 21.2.24 and xwayland before 24.1.13 could cause a heap buffer overflow via SetFont due to missing glyph boundary checks.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-55999/timeline.json",
      "vendor": "x.org"
    },
    {
      "affected_label": "x.org / x_server",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-56000/",
      "current_public_safe_latest": false,
      "cvss_score": 9.0,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.09027,
      "epss_score": 0.00192,
      "first_observed_at": "2026-07-15T05:43:30.245469+00:00",
      "id": "CVE-2026-56000",
      "impact_tags": [
        "memory safety review",
        "local exposure relevant"
      ],
      "kev": false,
      "last_observed_at": "2026-07-15T05:43:30.245469+00:00",
      "latest_item_url": null,
      "product": "x_server",
      "public_safe_summary": "NVD: Local attackers with a X connection able to provide GLX commit to the X server xorg-server before 21.2.24 and xwayland before 24.1.13 could cause a Heap Use After Free, due to CommonMakeCurrent() pointing into potentially reallocated memory. OSV: xorg-x11-server / xwayland GLX contextTags Use-After-Free in CommonMakeCurrent() OSV: Local attackers with a X connection able to provide GLX commit to the X server xorg-server before 21.2.24 and xwayland before 24.1.13 could cause a Heap Use After Free, due to CommonMakeCurrent() pointing into potentially reallocated memory.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260715T054459Z/items/CVE-2026-56000.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: x.org / x_server",
      "source_published_impact": "Source describes memory safety review · local exposure. Possible impact: The affected component has memory-safety risk that may lead to crash, privilege, or code-execution impact depending on exposure.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Local attackers with a X connection able to provide GLX commit to the X server xorg-server before 21.2.24 and xwayland before 24.1.13 could cause a Heap Use After Free, due to CommonMakeCurrent() pointing into potentially reallocated memory. OSV: xorg-x11-server / xwayland GLX contextTags Use-After-Free in CommonMakeCurrent() OSV: Local attackers with a X connection able to provide GLX commit to the X server xorg-server before 21.2.24 and xwayland before 24.1.13 could cause a Heap Use After Free, due to CommonMakeCurrent() pointing into potentially reallocated memory.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-56000/timeline.json",
      "vendor": "x.org"
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-56015/",
      "current_public_safe_latest": false,
      "cvss_score": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.41385,
      "epss_score": 0.00537,
      "first_observed_at": "2026-07-10T12:09:55.374028+00:00",
      "id": "CVE-2026-56015",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-10T12:09:55.374028+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Net::IP::LPM versions through 1.10 for Perl allow a heap out-of-bounds read via an unbounded prefix length. NVD: add() passes the prefix string to the trie builder addPrefixToTrie() without checking it against the address width. NVD: addPrefixToTrie() then walks the prefix buffer by prefix_length bits, reading prefix[byte] for byte up to prefix_len/8, where prefix is the 4-byte (IPv4) or 16-byte (IPv6) packed address.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260710T121119Z/items/CVE-2026-56015.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Net::IP::LPM versions through 1.10 for Perl allow a heap out-of-bounds read via an unbounded prefix length. NVD: add() passes the prefix string to the trie builder addPrefixToTrie() without checking it against the address width. NVD: addPrefixToTrie() then walks the prefix buffer by prefix_length bits, reading prefix[byte] for byte up to prefix_len/8, where prefix is the 4-byte (IPv4) or 16-byte (IPv6) packed address.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-56015/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "dell / data_domain_operating_system",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-56085/",
      "current_public_safe_latest": false,
      "cvss_score": 3.3,
      "cvss_severity": "LOW",
      "epss_percentile": 0.00831,
      "epss_score": 0.00095,
      "first_observed_at": "2026-07-10T12:09:55.374028+00:00",
      "id": "CVE-2026-56085",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-10T12:09:55.374028+00:00",
      "latest_item_url": null,
      "product": "data_domain_operating_system",
      "public_safe_summary": "NVD: Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an use of uninitialized resource... NVD: A low privileged attacker with local access could potentially exploit this vulnerability, leading to information exposure.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260710T121119Z/items/CVE-2026-56085.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: dell / data_domain_operating_system",
      "source_published_impact": "This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an use of uninitialized resource... NVD: A low privileged attacker with local access could potentially exploit this vulnerability, leading to information exposure.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-56085/timeline.json",
      "vendor": "dell"
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-56160/",
      "current_public_safe_latest": false,
      "cvss_score": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.47642,
      "epss_score": 0.00652,
      "first_observed_at": "2026-07-30T22:30:38.166118+00:00",
      "id": "CVE-2026-56160",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-30T22:30:38.166118+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Improper authorization in Azure Red Hat OpenShift (ARO) allows an authorized attacker to elevate privileges over a network.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260730T224832Z/items/CVE-2026-56160.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Improper authorization in Azure Red Hat OpenShift (ARO) allows an authorized attacker to elevate privileges over a network.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-56160/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "microsoft / account",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-56165/",
      "current_public_safe_latest": false,
      "cvss_score": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.50879,
      "epss_score": 0.00736,
      "first_observed_at": "2026-07-30T22:30:38.166118+00:00",
      "id": "CVE-2026-56165",
      "impact_tags": [
        "memory safety review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-30T22:30:38.166118+00:00",
      "latest_item_url": null,
      "product": "account",
      "public_safe_summary": "NVD: Heap-based buffer overflow in Microsoft Account allows an unauthorized attacker to execute code over a network.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260730T224832Z/items/CVE-2026-56165.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: microsoft / account; affected version context: -",
      "source_published_impact": "Source describes memory safety review. Possible impact: The affected component has memory-safety risk that may lead to crash, privilege, or code-execution impact depending on exposure.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Heap-based buffer overflow in Microsoft Account allows an unauthorized attacker to execute code over a network.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-56165/timeline.json",
      "vendor": "microsoft"
    },
    {
      "affected_label": "microsoft / azure_ai_search",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-56167/",
      "current_public_safe_latest": false,
      "cvss_score": 8.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.33336,
      "epss_score": 0.00406,
      "first_observed_at": "2026-07-30T22:30:38.166118+00:00",
      "id": "CVE-2026-56167",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-30T22:30:38.166118+00:00",
      "latest_item_url": null,
      "product": "azure_ai_search",
      "public_safe_summary": "NVD: Server-side request forgery (ssrf) in Azure AI Search allows an authorized attacker to elevate privileges over a network.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260730T224832Z/items/CVE-2026-56167.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: microsoft / azure_ai_search; affected version context: -",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Server-side request forgery (ssrf) in Azure AI Search allows an authorized attacker to elevate privileges over a network.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-56167/timeline.json",
      "vendor": "microsoft"
    },
    {
      "affected_label": "microsoft / exchange_online",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-56191/",
      "current_public_safe_latest": false,
      "cvss_score": 10.0,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.48236,
      "epss_score": 0.00667,
      "first_observed_at": "2026-07-30T22:30:38.166118+00:00",
      "id": "CVE-2026-56191",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-30T22:30:38.166118+00:00",
      "latest_item_url": null,
      "product": "exchange_online",
      "public_safe_summary": "NVD: Improper authentication in Microsoft Exchange Online allows an unauthorized attacker to perform tampering over a network.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260730T224832Z/items/CVE-2026-56191.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: microsoft / exchange_online; affected version context: -",
      "source_published_impact": "This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Improper authentication in Microsoft Exchange Online allows an unauthorized attacker to perform tampering over a network.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-56191/timeline.json",
      "vendor": "microsoft"
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-56238/",
      "current_public_safe_latest": false,
      "cvss_score": 8.7,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.29028,
      "epss_score": 0.00368,
      "first_observed_at": "2026-07-19T10:46:12.896763+00:00",
      "id": "CVE-2026-56238",
      "impact_tags": [
        "information exposure review",
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-19T10:46:12.896763+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Capgo before 12.128.2 contains an information disclosure vulnerability in the Supabase PostgREST global_stats endpoint that allows unauthenticated attackers to read sensitive financial and operational metrics using only the public apikey. NVD: Remote attackers can query the /rest/v1/global_stats endpoint to expose MRR, total revenue, plan-tier revenue breakdown, customer counts, and operational telemetry. OSV: Capgo - Unauthenticated Information Disclosure via PostgREST global_stats Endpoint",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260719T105023Z/items/CVE-2026-56238.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes information exposure review · remote exposure · authenticated boundary. Possible impact: A remote attacker may be able to access information that should not be exposed.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Capgo before 12.128.2 contains an information disclosure vulnerability in the Supabase PostgREST global_stats endpoint that allows unauthenticated attackers to read sensitive financial and operational metrics using only the public apikey. NVD: Remote attackers can query the /rest/v1/global_stats endpoint to expose MRR, total revenue, plan-tier revenue breakdown, customer counts, and operational telemetry. OSV: Capgo - Unauthenticated Information Disclosure via PostgREST global_stats Endpoint",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-56238/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-56240/",
      "current_public_safe_latest": false,
      "cvss_score": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.08001,
      "epss_score": 0.00182,
      "first_observed_at": "2026-07-18T08:01:52.653915+00:00",
      "id": "CVE-2026-56240",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-18T10:42:57.422810+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Capgo before 12.128.12 contains a billing authorization bypass vulnerability in the plan_valid calculation that allows organizations with exhausted or expired usage credit grants to bypass billing gates. NVD: Attackers can exploit the divergence between the plugin hot-path plan_valid expression and the authoritative billing gate to gain continued access to /updates, /stats, /channel_self, and attachment upload endpoints after credit depletion. OSV: Capgo - Billing Authorization Bypass via Exhausted Usage Credits",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260718T104447Z/items/CVE-2026-56240.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 4,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Capgo before 12.128.12 contains a billing authorization bypass vulnerability in the plan_valid calculation that allows organizations with exhausted or expired usage credit grants to bypass billing gates. NVD: Attackers can exploit the divergence between the plugin hot-path plan_valid expression and the authoritative billing gate to gain continued access to /updates, /stats, /channel_self, and attachment upload endpoints after credit depletion. OSV: Capgo - Billing Authorization Bypass via Exhausted Usage Credits",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-56240/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-56241/",
      "current_public_safe_latest": false,
      "cvss_score": 7.2,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.11327,
      "epss_score": 0.00211,
      "first_observed_at": "2026-07-19T10:46:12.896763+00:00",
      "id": "CVE-2026-56241",
      "impact_tags": [
        "privilege boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-19T10:46:12.896763+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Capgo before 12.128.2 contains a privilege escalation vulnerability where demoted super_admin users retain access to delete_non_compliant_bundles and count_non_compliant_bundles RPCs due to stale org_users.user_right column not being cleared during role... NVD: Attackers can exploit this by maintaining a previously granted super_admin role to enumerate and bulk delete non-compliant bundles across the entire organization indefinitely. OSV: Capgo - RBAC Demotion Privilege Retention via Stale org_users.user_right",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260719T105023Z/items/CVE-2026-56241.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes privilege escalation risk. Possible impact: An attacker may cross a privilege boundary and gain more access than intended.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Capgo before 12.128.2 contains a privilege escalation vulnerability where demoted super_admin users retain access to delete_non_compliant_bundles and count_non_compliant_bundles RPCs due to stale org_users.user_right column not being cleared during role... NVD: Attackers can exploit this by maintaining a previously granted super_admin role to enumerate and bulk delete non-compliant bundles across the entire organization indefinitely. OSV: Capgo - RBAC Demotion Privilege Retention via Stale org_users.user_right",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-56241/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-56252/",
      "current_public_safe_latest": false,
      "cvss_score": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.06528,
      "epss_score": 0.00169,
      "first_observed_at": "2026-07-19T10:46:12.896763+00:00",
      "id": "CVE-2026-56252",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-19T10:46:12.896763+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Capgo before 12.128.2 contains a scope isolation vulnerability in the POST /webhooks/test endpoint that allows app-scoped API keys to invoke org-scoped webhook operations. NVD: Attackers with app-scoped credentials can trigger signed outbound webhook deliveries for arbitrary organization webhooks outside their declared app boundary, bypassing the limited_to_apps authorization check. OSV: Capgo - Scope Isolation Failure in Webhook Test Endpoint",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260719T105023Z/items/CVE-2026-56252.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Capgo before 12.128.2 contains a scope isolation vulnerability in the POST /webhooks/test endpoint that allows app-scoped API keys to invoke org-scoped webhook operations. NVD: Attackers with app-scoped credentials can trigger signed outbound webhook deliveries for arbitrary organization webhooks outside their declared app boundary, bypassing the limited_to_apps authorization check. OSV: Capgo - Scope Isolation Failure in Webhook Test Endpoint",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-56252/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-56254/",
      "current_public_safe_latest": false,
      "cvss_score": 8.3,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.04754,
      "epss_score": 0.00151,
      "first_observed_at": "2026-07-17T10:59:18.822206+00:00",
      "id": "CVE-2026-56254",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-17T10:59:18.822206+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: In @capgo/capacitor-updater (Cap-go/capgo) before 12.128.2, the end-to-end encryption scheme distributes the private key to each device that downloads the app. NVD: Because the public key can be derived from the private key, an attacker performing a man-in-the-middle attack or compromising the Capgo server can create a validly signed update bundle and cause devices to install an update not produced by the original app... OSV: capacitor-updater - End-to-End Encryption Bypass via Private Key Distribution",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260717T110142Z/items/CVE-2026-56254.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: In @capgo/capacitor-updater (Cap-go/capgo) before 12.128.2, the end-to-end encryption scheme distributes the private key to each device that downloads the app. NVD: Because the public key can be derived from the private key, an attacker performing a man-in-the-middle attack or compromising the Capgo server can create a validly signed update bundle and cause devices to install an update not produced by the original app... OSV: capacitor-updater - End-to-End Encryption Bypass via Private Key Distribution",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-56254/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "kidocode / crawl4ai",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-56259/",
      "current_public_safe_latest": false,
      "cvss_score": 8.8,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.16869,
      "epss_score": 0.00254,
      "first_observed_at": "2026-07-19T10:46:12.896763+00:00",
      "id": "CVE-2026-56259",
      "impact_tags": [
        "authentication boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-19T10:46:12.896763+00:00",
      "latest_item_url": null,
      "product": "crawl4ai",
      "public_safe_summary": "NVD: Crawl4AI before 0.8.8 contains credential exfiltration vulnerabilities in the Docker API server that allow attackers to redirect LLM API calls to attacker-controlled endpoints and read arbitrary environment variables. NVD: Attackers can exploit the unauthenticated /md, /llm, and /llm/job endpoints by supplying a malicious base_url parameter and setting api_token to env:VARIABLE_NAME to exfiltrate provider API keys and server secrets including JWT SECRET_KEY for authentication... OSV: Crawl4AI - LLM Credential Exfiltration via base_url and Environment Variable Resolution",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260719T105023Z/items/CVE-2026-56259.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: kidocode / crawl4ai",
      "source_published_impact": "Source describes authentication boundary review. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authentication boundary review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Crawl4AI before 0.8.8 contains credential exfiltration vulnerabilities in the Docker API server that allow attackers to redirect LLM API calls to attacker-controlled endpoints and read arbitrary environment variables. NVD: Attackers can exploit the unauthenticated /md, /llm, and /llm/job endpoints by supplying a malicious base_url parameter and setting api_token to env:VARIABLE_NAME to exfiltrate provider API keys and server secrets including JWT SECRET_KEY for authentication... OSV: Crawl4AI - LLM Credential Exfiltration via base_url and Environment Variable Resolution",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-56259/timeline.json",
      "vendor": "kidocode"
    },
    {
      "affected_label": "kidocode / crawl4ai",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-56260/",
      "current_public_safe_latest": false,
      "cvss_score": 8.8,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.34182,
      "epss_score": 0.00421,
      "first_observed_at": "2026-07-19T10:46:12.896763+00:00",
      "id": "CVE-2026-56260",
      "impact_tags": [
        "service availability review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-19T10:46:12.896763+00:00",
      "latest_item_url": null,
      "product": "crawl4ai",
      "public_safe_summary": "NVD: Crawl4AI before 0.8.7 contains an arbitrary file write vulnerability in the Docker API server's /screenshot and /pdf endpoints. NVD: The output_path parameter accepts arbitrary filesystem paths without validation, allowing an attacker to supply absolute or path-traversal values to write to any location writable by the application's user, overwriting server files and causing denial of... OSV: Crawl4AI - Arbitrary File Write via output_path Parameter",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260719T105023Z/items/CVE-2026-56260.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: kidocode / crawl4ai",
      "source_published_impact": "Source describes service availability risk. Possible impact: The affected service may become unavailable or unreliable.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Crawl4AI before 0.8.7 contains an arbitrary file write vulnerability in the Docker API server's /screenshot and /pdf endpoints. NVD: The output_path parameter accepts arbitrary filesystem paths without validation, allowing an attacker to supply absolute or path-traversal values to write to any location writable by the application's user, overwriting server files and causing denial of... OSV: Crawl4AI - Arbitrary File Write via output_path Parameter",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-56260/timeline.json",
      "vendor": "kidocode"
    },
    {
      "affected_label": "kidocode / crawl4ai",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-56261/",
      "current_public_safe_latest": false,
      "cvss_score": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.29391,
      "epss_score": 0.00371,
      "first_observed_at": "2026-07-17T10:59:18.822206+00:00",
      "id": "CVE-2026-56261",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-17T10:59:18.822206+00:00",
      "latest_item_url": null,
      "product": "crawl4ai",
      "public_safe_summary": "NVD: Crawl4AI before 0.8.7 contains a server-side request forgery (SSRF) vulnerability in the Docker API server's /crawl/job and /llm/job endpoints, which accept webhook URLs without destination validation. NVD: An attacker can supply webhook URLs pointing to private or internal IP ranges, Docker networks, or cloud metadata endpoints (e.g. NVD: 169.254.169.254), causing the server to make requests to internal services and potentially expose cloud metadata.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260717T110142Z/items/CVE-2026-56261.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: kidocode / crawl4ai",
      "source_published_impact": "This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Crawl4AI before 0.8.7 contains a server-side request forgery (SSRF) vulnerability in the Docker API server's /crawl/job and /llm/job endpoints, which accept webhook URLs without destination validation. NVD: An attacker can supply webhook URLs pointing to private or internal IP ranges, Docker networks, or cloud metadata endpoints (e.g. NVD: 169.254.169.254), causing the server to make requests to internal services and potentially expose cloud metadata.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-56261/timeline.json",
      "vendor": "kidocode"
    },
    {
      "affected_label": "flowiseai / flowise",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-56271/",
      "current_public_safe_latest": false,
      "cvss_score": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.29861,
      "epss_score": 0.00376,
      "first_observed_at": "2026-07-19T10:46:12.896763+00:00",
      "id": "CVE-2026-56271",
      "impact_tags": [
        "authentication boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-19T10:46:12.896763+00:00",
      "latest_item_url": null,
      "product": "flowise",
      "public_safe_summary": "NVD: Flowise before 3.1.0 (affected versions 3.0.13 and earlier) uses weak hardcoded default JWT secrets ('auth_token', 'refresh_token') and default audience and issuer values ('AUDIENCE', 'ISSUER') in the enterprise passport authentication middleware... NVD: When the corresponding environment variables (JWT_AUTH_TOKEN_SECRET, JWT_REFRESH_TOKEN_SECRET, JWT_AUDIENCE, JWT_ISSUER) are not set, the application silently falls back to these publicly known defaults, allowing an attacker to forge valid JWTs and... OSV: Flowise - Weak Default JWT Secrets in Authentication Middleware",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260719T105023Z/items/CVE-2026-56271.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: flowiseai / flowise",
      "source_published_impact": "Source describes authentication boundary review. Possible impact: This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authentication boundary review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Flowise before 3.1.0 (affected versions 3.0.13 and earlier) uses weak hardcoded default JWT secrets ('auth_token', 'refresh_token') and default audience and issuer values ('AUDIENCE', 'ISSUER') in the enterprise passport authentication middleware... NVD: When the corresponding environment variables (JWT_AUTH_TOKEN_SECRET, JWT_REFRESH_TOKEN_SECRET, JWT_AUDIENCE, JWT_ISSUER) are not set, the application silently falls back to these publicly known defaults, allowing an attacker to forge valid JWTs and... OSV: Flowise - Weak Default JWT Secrets in Authentication Middleware",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-56271/timeline.json",
      "vendor": "flowiseai"
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-56279/",
      "current_public_safe_latest": false,
      "cvss_score": 8.7,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.23314,
      "epss_score": 0.00313,
      "first_observed_at": "2026-07-17T10:59:18.822206+00:00",
      "id": "CVE-2026-56279",
      "impact_tags": [
        "information exposure review",
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-17T10:59:18.822206+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Capgo before 12.128.2 contains an information disclosure vulnerability in the get_orgs_v7(userid) RPC function that remains publicly invokable despite intended private access controls. NVD: Unauthenticated attackers can supply arbitrary user UUIDs to retrieve foreign users' organization membership, roles, management emails, and billing metadata. OSV: Capgo - Information Disclosure via get_orgs_v7 RPC Endpoint",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260717T110142Z/items/CVE-2026-56279.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes information exposure review · remote exposure · authenticated boundary. Possible impact: A remote attacker may be able to access information that should not be exposed.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Capgo before 12.128.2 contains an information disclosure vulnerability in the get_orgs_v7(userid) RPC function that remains publicly invokable despite intended private access controls. NVD: Unauthenticated attackers can supply arbitrary user UUIDs to retrieve foreign users' organization membership, roles, management emails, and billing metadata. OSV: Capgo - Information Disclosure via get_orgs_v7 RPC Endpoint",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-56279/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-56281/",
      "current_public_safe_latest": false,
      "cvss_score": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.09672,
      "epss_score": 0.00197,
      "first_observed_at": "2026-07-19T10:46:12.896763+00:00",
      "id": "CVE-2026-56281",
      "impact_tags": [
        "SQL injection risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-19T10:46:12.896763+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Capgo before 12.128.2 contains a sql injection vulnerability in the POST /private/admin_stats endpoint where the limit parameter is destructured from unvalidated request body and interpolated directly into Cloudflare Analytics Engine SQL queries via template... NVD: An attacker with platform admin credentials can inject SQL fragments to enumerate dataset schemas, extract analytics data, or cause denial-of-service against the analytics backend. OSV: Capgo - SQL Injection via Unvalidated limit Parameter in Admin Stats Endpoint",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260719T105023Z/items/CVE-2026-56281.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes SQL injection risk. Possible impact: An attacker may be able to read or change database-backed application data.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Capgo before 12.128.2 contains a sql injection vulnerability in the POST /private/admin_stats endpoint where the limit parameter is destructured from unvalidated request body and interpolated directly into Cloudflare Analytics Engine SQL queries via template... NVD: An attacker with platform admin credentials can inject SQL fragments to enumerate dataset schemas, extract analytics data, or cause denial-of-service against the analytics backend. OSV: Capgo - SQL Injection via Unvalidated limit Parameter in Admin Stats Endpoint",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-56281/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "apache / fineract",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-56287/",
      "current_public_safe_latest": false,
      "cvss_score": 8.1,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.48996,
      "epss_score": 0.00696,
      "first_observed_at": "2026-07-22T06:07:21.492959+00:00",
      "id": "CVE-2026-56287",
      "impact_tags": [
        "SQL injection risk",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-22T06:07:21.492959+00:00",
      "latest_item_url": null,
      "product": "fineract",
      "public_safe_summary": "NVD: A boolean-based SQL Injection vulnerability exists in Apache Fineract's Client Search API (GET /api/v1/clients) in versions up to and including 1.14.0. NVD: The orderBy and sortOrder request parameters are concatenated into a SQL query without sufficient validation, allowing an authenticated user with permission to view clients to inject arbitrary SQL via a crafted orderBy value. NVD: This can be leveraged to perform blind boolean-based data extraction and, on MySQL/MariaDB, to disclose arbitrary files readable by the database process via the LOAD_FILE() function.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260722T060931Z/items/CVE-2026-56287.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: apache / fineract",
      "source_published_impact": "Source describes SQL injection risk · authenticated boundary. Possible impact: An attacker may be able to read or change database-backed application data.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: a.",
      "source_published_summary": "NVD: A boolean-based SQL Injection vulnerability exists in Apache Fineract's Client Search API (GET /api/v1/clients) in versions up to and including 1.14.0. NVD: The orderBy and sortOrder request parameters are concatenated into a SQL query without sufficient validation, allowing an authenticated user with permission to view clients to inject arbitrary SQL via a crafted orderBy value. NVD: This can be leveraged to perform blind boolean-based data extraction and, on MySQL/MariaDB, to disclose arbitrary files readable by the database process via the LOAD_FILE() function.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-56287/timeline.json",
      "vendor": "apache"
    },
    {
      "affected_label": "gnu / patch",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-56288/",
      "current_public_safe_latest": false,
      "cvss_score": 4.6,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.01819,
      "epss_score": 0.00115,
      "first_observed_at": "2026-07-16T11:14:01.223847+00:00",
      "id": "CVE-2026-56288",
      "impact_tags": [
        "service availability review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-16T11:14:01.223847+00:00",
      "latest_item_url": null,
      "product": "patch",
      "public_safe_summary": "NVD: GNU patch is vulnerable to a NULL pointer dereference when processing a specially crafted unified-diff patch file. NVD: Improper handling of consecutive end-of-file newline markers can corrupt internal hunk (single block of changes in diff) data structures, causing the application to pass a NULL pointer to fwrite() during patch processing. NVD: An attacker can trigger this condition with a malicious patch file, causing the utility to crash and resulting in a denial of service.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260716T111601Z/items/CVE-2026-56288.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: gnu / patch",
      "source_published_impact": "Source describes service availability risk. Possible impact: The affected service may become unavailable or unreliable.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: the.",
      "source_published_summary": "NVD: GNU patch is vulnerable to a NULL pointer dereference when processing a specially crafted unified-diff patch file. NVD: Improper handling of consecutive end-of-file newline markers can corrupt internal hunk (single block of changes in diff) data structures, causing the application to pass a NULL pointer to fwrite() during patch processing. NVD: An attacker can trigger this condition with a malicious patch file, causing the utility to crash and resulting in a denial of service.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-56288/timeline.json",
      "vendor": "gnu"
    },
    {
      "affected_label": "gnu / patch",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-56289/",
      "current_public_safe_latest": false,
      "cvss_score": 4.6,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.0182,
      "epss_score": 0.00115,
      "first_observed_at": "2026-07-16T11:14:01.223847+00:00",
      "id": "CVE-2026-56289",
      "impact_tags": [
        "service availability review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-16T11:14:01.223847+00:00",
      "latest_item_url": null,
      "product": "patch",
      "public_safe_summary": "NVD: GNU patch is vulnerable to a denial of service (DoS) due to improper validation of hunk (single block of changes in diff) line offsets in unified-diff input. NVD: A specially crafted patch can specify an extremely large line number, causing the application to enter an effectively infinite processing loop while attempting to locate the requested position. NVD: This results in excessive CPU consumption and prevents the process from completing.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260716T111601Z/items/CVE-2026-56289.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: gnu / patch",
      "source_published_impact": "Source describes service availability risk. Possible impact: The affected service may become unavailable or unreliable.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: the.",
      "source_published_summary": "NVD: GNU patch is vulnerable to a denial of service (DoS) due to improper validation of hunk (single block of changes in diff) line offsets in unified-diff input. NVD: A specially crafted patch can specify an extremely large line number, causing the application to enter an effectively infinite processing loop while attempting to locate the requested position. NVD: This results in excessive CPU consumption and prevents the process from completing.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-56289/timeline.json",
      "vendor": "gnu"
    },
    {
      "affected_label": "balbooa / forms",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-56291/",
      "current_public_safe_latest": false,
      "cvss_score": 10.0,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.53597,
      "epss_score": 0.00836,
      "first_observed_at": "2026-07-16T11:14:01.223847+00:00",
      "id": "CVE-2026-56291",
      "impact_tags": [
        "code execution review"
      ],
      "kev": true,
      "last_observed_at": "2026-07-16T11:14:01.223847+00:00",
      "latest_item_url": null,
      "product": "forms",
      "public_safe_summary": "NVD: The Joomla extension Balbooa Forms is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE. CISA KEV: Balbooa Forms Unrestricted Upload of File with Dangerous Type Vulnerability",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260716T111601Z/items/CVE-2026-56291.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: balbooa / forms",
      "source_published_impact": "Source describes known exploited catalog listed · code execution review. Possible impact: An attacker may be able to run code or commands on affected systems.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Joomla extension Balbooa Forms is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE. CISA KEV: Balbooa Forms Unrestricted Upload of File with Dangerous Type Vulnerability",
      "sources": [
        "NVD",
        "CISA KEV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-56291/timeline.json",
      "vendor": "balbooa"
    },
    {
      "affected_label": "acymailing / acymailing",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-56292/",
      "current_public_safe_latest": false,
      "cvss_score": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.17781,
      "epss_score": 0.00263,
      "first_observed_at": "2026-07-16T13:54:14.110513+00:00",
      "id": "CVE-2026-56292",
      "impact_tags": [
        "SQL injection risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-16T13:54:14.110513+00:00",
      "latest_item_url": null,
      "product": "acymailing",
      "public_safe_summary": "NVD: A SQLi vulnerability in AcyMailing component < 10.11.1 for Joomla was discovered. NVD: Exploiting this flaw can lead to unauthorized database access and data leakage.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260716T135621Z/items/CVE-2026-56292.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: acymailing / acymailing",
      "source_published_impact": "Source describes SQL injection risk. Possible impact: An attacker may be able to read or change database-backed application data.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A SQLi vulnerability in AcyMailing component < 10.11.1 for Joomla was discovered. NVD: Exploiting this flaw can lead to unauthorized database access and data leakage.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-56292/timeline.json",
      "vendor": "acymailing"
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-56296/",
      "current_public_safe_latest": false,
      "cvss_score": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.14949,
      "epss_score": 0.00239,
      "first_observed_at": "2026-07-18T08:01:52.653915+00:00",
      "id": "CVE-2026-56296",
      "impact_tags": [
        "information exposure review",
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-18T10:42:57.422810+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Cap-go before 12.128.2 contains an information disclosure vulnerability in the public.transfer_app RPC function that returns distinct error messages for existing versus non-existing app IDs. NVD: Unauthenticated attackers can enumerate valid app IDs by observing error message differences when calling transfer_app with only the publishable API key. OSV: Cap-go - App Existence Oracle via Unauthenticated transfer_app RPC",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260718T104447Z/items/CVE-2026-56296.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 4,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes information exposure review · remote exposure · authenticated boundary. Possible impact: A remote attacker may be able to access information that should not be exposed.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Cap-go before 12.128.2 contains an information disclosure vulnerability in the public.transfer_app RPC function that returns distinct error messages for existing versus non-existing app IDs. NVD: Unauthenticated attackers can enumerate valid app IDs by observing error message differences when calling transfer_app with only the publishable API key. OSV: Cap-go - App Existence Oracle via Unauthenticated transfer_app RPC",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-56296/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-56303/",
      "current_public_safe_latest": false,
      "cvss_score": 8.7,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.22134,
      "epss_score": 0.00302,
      "first_observed_at": "2026-07-18T08:01:52.653915+00:00",
      "id": "CVE-2026-56303",
      "impact_tags": [
        "information exposure review",
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-18T10:42:57.422810+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Capgo before 12.128.2 contains an information disclosure vulnerability in the find_apikey_by_value PostgreSQL function marked SECURITY DEFINER and executable by the anon role. NVD: Unauthenticated attackers can call this function via the /rest/v1/rpc/find_apikey_by_value endpoint to retrieve sensitive API key metadata including user_id, mode, org scoping, and expiration details when supplied a valid key value. OSV: Capgo - Unauthenticated API Key Metadata Disclosure via SECURITY DEFINER RPC Function",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260718T104447Z/items/CVE-2026-56303.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 4,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes information exposure review · remote exposure · authenticated boundary. Possible impact: A remote attacker may be able to access information that should not be exposed.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Capgo before 12.128.2 contains an information disclosure vulnerability in the find_apikey_by_value PostgreSQL function marked SECURITY DEFINER and executable by the anon role. NVD: Unauthenticated attackers can call this function via the /rest/v1/rpc/find_apikey_by_value endpoint to retrieve sensitive API key metadata including user_id, mode, org scoping, and expiration details when supplied a valid key value. OSV: Capgo - Unauthenticated API Key Metadata Disclosure via SECURITY DEFINER RPC Function",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-56303/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-56308/",
      "current_public_safe_latest": false,
      "cvss_score": 8.4,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.15566,
      "epss_score": 0.00244,
      "first_observed_at": "2026-07-19T10:46:12.896763+00:00",
      "id": "CVE-2026-56308",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-19T10:46:12.896763+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Capgo before 12.128.2 allows email address changes without requiring current password re-authentication or verification of the existing email address. NVD: An attacker with access to a valid session cookie or authenticated browser can change the account email to gain control of account recovery and bypass multi-factor authentication protections. OSV: Capgo - Insufficient Authentication in Email Change Endpoint",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260719T105023Z/items/CVE-2026-56308.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Capgo before 12.128.2 allows email address changes without requiring current password re-authentication or verification of the existing email address. NVD: An attacker with access to a valid session cookie or authenticated browser can change the account email to gain control of account recovery and bypass multi-factor authentication protections. OSV: Capgo - Insufficient Authentication in Email Change Endpoint",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-56308/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-56313/",
      "current_public_safe_latest": false,
      "cvss_score": 7.2,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.19592,
      "epss_score": 0.00276,
      "first_observed_at": "2026-07-19T10:46:12.896763+00:00",
      "id": "CVE-2026-56313",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-19T10:46:12.896763+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Capgo before 12.128.2 contains a cross-organization account disruption vulnerability in the SSO prelink endpoint that allows enterprise administrators to delete password identities of users in foreign organizations. NVD: Attackers with org.update_settings permission and an active SSO provider can call the prelink-users endpoint to permanently remove email-based authentication for any user matching the provider's email domain, forcing victims to use the attacker's SSO provider... OSV: Capgo - Cross-Organization Account Disruption via SSO Prelink Endpoint",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260719T105023Z/items/CVE-2026-56313.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Capgo before 12.128.2 contains a cross-organization account disruption vulnerability in the SSO prelink endpoint that allows enterprise administrators to delete password identities of users in foreign organizations. NVD: Attackers with org.update_settings permission and an active SSO provider can call the prelink-users endpoint to permanently remove email-based authentication for any user matching the provider's email domain, forcing victims to use the attacker's SSO provider... OSV: Capgo - Cross-Organization Account Disruption via SSO Prelink Endpoint",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-56313/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-56336/",
      "current_public_safe_latest": false,
      "cvss_score": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.10596,
      "epss_score": 0.00205,
      "first_observed_at": "2026-07-19T10:46:12.896763+00:00",
      "id": "CVE-2026-56336",
      "impact_tags": [
        "information exposure review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-19T10:46:12.896763+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Capgo before 12.128.2 contains an information disclosure vulnerability in the unauthenticated /private/sso/check-domain endpoint that returns internal org_id and provider_id values. NVD: Attackers can enumerate email domains to build mappings of domains to organization UUIDs and SSO provider identifiers, enabling reconnaissance against Capgo tenants. OSV: Capgo - Information Disclosure via Unauthenticated SSO check-domain Endpoint",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260719T105023Z/items/CVE-2026-56336.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes information exposure review. Possible impact: An attacker may be able to access information that should not be exposed.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Capgo before 12.128.2 contains an information disclosure vulnerability in the unauthenticated /private/sso/check-domain endpoint that returns internal org_id and provider_id values. NVD: Attackers can enumerate email domains to build mappings of domains to organization UUIDs and SSO provider identifiers, enabling reconnaissance against Capgo tenants. OSV: Capgo - Information Disclosure via Unauthenticated SSO check-domain Endpoint",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-56336/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-56339/",
      "current_public_safe_latest": false,
      "cvss_score": 8.7,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.1969,
      "epss_score": 0.00276,
      "first_observed_at": "2026-07-22T06:07:21.492959+00:00",
      "id": "CVE-2026-56339",
      "impact_tags": [
        "information exposure review",
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-22T11:51:23.239908+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Capgo (Cap-go/capgo) before 12.128.2 contains an information disclosure vulnerability in the Supabase PostgREST SECURITY DEFINER RPC function public.rescind_invitation that allows unauthenticated attackers to enumerate organization existence. NVD: The function returns distinct error messages (NO_ORG vs NO_RIGHTS) when called with only a publishable API key, enabling attackers to discover valid organization IDs and increase the attack surface for targeted phishing or social engineering campaigns. OSV: Capgo - Unauthenticated Organization Existence Enumeration via rescind_invitation RPC",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260722T115421Z/items/CVE-2026-56339.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes information exposure review · remote exposure · authenticated boundary. Possible impact: A remote attacker may be able to access information that should not be exposed.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Capgo (Cap-go/capgo) before 12.128.2 contains an information disclosure vulnerability in the Supabase PostgREST SECURITY DEFINER RPC function public.rescind_invitation that allows unauthenticated attackers to enumerate organization existence. NVD: The function returns distinct error messages (NO_ORG vs NO_RIGHTS) when called with only a publishable API key, enabling attackers to discover valid organization IDs and increase the attack surface for targeted phishing or social engineering campaigns. OSV: Capgo - Unauthenticated Organization Existence Enumeration via rescind_invitation RPC",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-56339/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-56349/",
      "current_public_safe_latest": false,
      "cvss_score": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.26679,
      "epss_score": 0.00344,
      "first_observed_at": "2026-07-22T11:51:23.239908+00:00",
      "id": "CVE-2026-56349",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-22T11:51:23.239908+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: n8n before version 2.10.0 contains an input validation vulnerability in the Guardrail node that allows attackers to bypass default guardrail instructions. NVD: End users can craft malicious inputs to circumvent guardrail protections and compromise workflow integrity. OSV: n8n - Guardrail Node Bypass via Crafted Input",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260722T115421Z/items/CVE-2026-56349.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: n8n before version 2.10.0 contains an input validation vulnerability in the Guardrail node that allows attackers to bypass default guardrail instructions. NVD: End users can craft malicious inputs to circumvent guardrail protections and compromise workflow integrity. OSV: n8n - Guardrail Node Bypass via Crafted Input",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-56349/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-56352/",
      "current_public_safe_latest": false,
      "cvss_score": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.16223,
      "epss_score": 0.00248,
      "first_observed_at": "2026-07-22T11:51:23.239908+00:00",
      "id": "CVE-2026-56352",
      "impact_tags": [
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-22T11:51:23.239908+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: n8n before 2.19.3 contains a file path restriction bypass in the legacy ExecuteWorkflow node's localFile source option, which reads workflow files from disk without the file-access checks enforced by other file-reading nodes. NVD: Although hidden from the UI since v1.2, it remains reachable via the REST API. NVD: An authenticated user with permission to create or modify workflows can supply an arbitrary file path to bypass the N8N_RESTRICT_FILE_ACCESS_TO restriction and determine whether arbitrary files exist on the host; where the targeted path contains a valid...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260722T115421Z/items/CVE-2026-56352.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: n8n before 2.19.3 contains a file path restriction bypass in the legacy ExecuteWorkflow node's localFile source option, which reads workflow files from disk without the file-access checks enforced by other file-reading nodes. NVD: Although hidden from the UI since v1.2, it remains reachable via the REST API. NVD: An authenticated user with permission to create or modify workflows can supply an arbitrary file path to bypass the N8N_RESTRICT_FILE_ACCESS_TO restriction and determine whether arbitrary files exist on the host; where the targeted path contains a valid...",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-56352/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "n8n / n8n",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-56353/",
      "current_public_safe_latest": false,
      "cvss_score": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.14018,
      "epss_score": 0.00231,
      "first_observed_at": "2026-07-22T11:51:23.239908+00:00",
      "id": "CVE-2026-56353",
      "impact_tags": [
        "authentication boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-22T11:51:23.239908+00:00",
      "latest_item_url": null,
      "product": "n8n",
      "public_safe_summary": "NVD: n8n contains an authentication bypass in the Chat Trigger node when configured with n8n User Auth (a non-default configuration). NVD: In affected releases — before 1.123.22, the 2.0.0 through 2.9.2 line, and 2.10.0 — the authentication check on the Chat Trigger webhook endpoint can be circumvented, allowing access without valid credentials. NVD: Fixed in 1.123.22, 2.9.3, and 2.10.1.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260722T115421Z/items/CVE-2026-56353.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: n8n / n8n; affected version context: 2.10.0",
      "source_published_impact": "Source describes authentication boundary review. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authentication boundary review.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: 1.123.22.",
      "source_published_summary": "NVD: n8n contains an authentication bypass in the Chat Trigger node when configured with n8n User Auth (a non-default configuration). NVD: In affected releases — before 1.123.22, the 2.0.0 through 2.9.2 line, and 2.10.0 — the authentication check on the Chat Trigger webhook endpoint can be circumvented, allowing access without valid credentials. NVD: Fixed in 1.123.22, 2.9.3, and 2.10.1.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-56353/timeline.json",
      "vendor": "n8n"
    },
    {
      "affected_label": "imagemagick / imagemagick",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-56372/",
      "current_public_safe_latest": false,
      "cvss_score": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.09751,
      "epss_score": 0.00198,
      "first_observed_at": "2026-07-18T08:01:52.653915+00:00",
      "id": "CVE-2026-56372",
      "impact_tags": [
        "information exposure review",
        "service availability review",
        "memory safety review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-18T10:42:57.422810+00:00",
      "latest_item_url": null,
      "product": "imagemagick",
      "public_safe_summary": "NVD: ImageMagick before 7.1.2-19 contains a heap buffer overflow vulnerability in the magnify operation that allows attackers to read out of bounds memory. NVD: An unrecognized magnify:method value triggers an out of bounds read, potentially exposing sensitive information or causing denial of service. OSV: ImageMagick - Heap Buffer Overflow Read via Unrecognized Magnify Method",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260718T104447Z/items/CVE-2026-56372.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 4,
      "source_published_affected": "vendor/product: imagemagick / imagemagick",
      "source_published_impact": "Source describes information exposure review · service availability risk · memory safety review. Possible impact: An attacker may be able to access information that should not be exposed.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: ImageMagick before 7.1.2-19 contains a heap buffer overflow vulnerability in the magnify operation that allows attackers to read out of bounds memory. NVD: An unrecognized magnify:method value triggers an out of bounds read, potentially exposing sensitive information or causing denial of service. OSV: ImageMagick - Heap Buffer Overflow Read via Unrecognized Magnify Method",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-56372/timeline.json",
      "vendor": "imagemagick"
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-56375/",
      "current_public_safe_latest": false,
      "cvss_score": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.01554,
      "epss_score": 0.00111,
      "first_observed_at": "2026-07-22T11:51:23.239908+00:00",
      "id": "CVE-2026-56375",
      "impact_tags": [
        "service availability review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-22T11:51:23.239908+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: ImageMagick through 7.1.2-18 contains a memory leak vulnerability in the ASHLAR coder when an action fails. NVD: Attackers can trigger failed actions to exhaust memory resources and cause denial of service. OSV: ImageMagick - Memory Leak in ASHLAR Coder Action Failure",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260722T115421Z/items/CVE-2026-56375.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes service availability risk. Possible impact: The affected service may become unavailable or unreliable.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: ImageMagick through 7.1.2-18 contains a memory leak vulnerability in the ASHLAR coder when an action fails. NVD: Attackers can trigger failed actions to exhaust memory resources and cause denial of service. OSV: ImageMagick - Memory Leak in ASHLAR Coder Action Failure",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-56375/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "openwebui / open_webui",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-56398/",
      "current_public_safe_latest": false,
      "cvss_score": 8.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.26052,
      "epss_score": 0.00338,
      "first_observed_at": "2026-07-22T11:51:23.239908+00:00",
      "id": "CVE-2026-56398",
      "impact_tags": [
        "XSS risk",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-22T11:51:23.239908+00:00",
      "latest_item_url": null,
      "product": "open_webui",
      "public_safe_summary": "NVD: Open WebUI before 0.9.5 contains a stored cross-site scripting vulnerability in the OAuth authentication flow where the picture claim URL MIME type is inferred from file extension rather than Content-Type header, allowing SVG files to bypass the profile image... NVD: Authenticated users who visit the profile image endpoint receive attacker-controlled SVG content with inline disposition and no default security headers, enabling script execution in the same origin to steal authentication tokens and achieve account takeover. OSV: Open WebUI - Stored Cross-Site Scripting via OAuth Picture Claim SVG Data URI",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260722T115421Z/items/CVE-2026-56398.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: openwebui / open_webui",
      "source_published_impact": "Source describes XSS risk · authenticated boundary. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Open WebUI before 0.9.5 contains a stored cross-site scripting vulnerability in the OAuth authentication flow where the picture claim URL MIME type is inferred from file extension rather than Content-Type header, allowing SVG files to bypass the profile image... NVD: Authenticated users who visit the profile image endpoint receive attacker-controlled SVG content with inline disposition and no default security headers, enabling script execution in the same origin to steal authentication tokens and achieve account takeover. OSV: Open WebUI - Stored Cross-Site Scripting via OAuth Picture Claim SVG Data URI",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-56398/timeline.json",
      "vendor": "openwebui"
    },
    {
      "affected_label": "openwebui / open_webui",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-56400/",
      "current_public_safe_latest": false,
      "cvss_score": 9.0,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.20207,
      "epss_score": 0.00281,
      "first_observed_at": "2026-07-22T11:51:23.239908+00:00",
      "id": "CVE-2026-56400",
      "impact_tags": [
        "code execution review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-22T11:51:23.239908+00:00",
      "latest_item_url": null,
      "product": "open_webui",
      "public_safe_summary": "NVD: open-webui before 0.3.14 contains a cross-origin resource sharing misconfiguration allowing arbitrary origins with allow_origins=* and authenticated requests to the /api/v1/functions endpoint. NVD: Attackers can execute arbitrary code on the openwebui instance by crafting malicious cross-site requests from attacker-controlled websites when an admin user visits them. OSV: open-webui - Remote Code Execution via CORS Misconfiguration and Session Validation",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260722T115421Z/items/CVE-2026-56400.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: openwebui / open_webui",
      "source_published_impact": "Source describes code execution review. Possible impact: An attacker may be able to run code or commands on affected systems.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: open-webui before 0.3.14 contains a cross-origin resource sharing misconfiguration allowing arbitrary origins with allow_origins=* and authenticated requests to the /api/v1/functions endpoint. NVD: Attackers can execute arbitrary code on the openwebui instance by crafting malicious cross-site requests from attacker-controlled websites when an admin user visits them. OSV: open-webui - Remote Code Execution via CORS Misconfiguration and Session Validation",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-56400/timeline.json",
      "vendor": "openwebui"
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-56437/",
      "current_public_safe_latest": false,
      "cvss_score": 8.4,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.03286,
      "epss_score": 0.00134,
      "first_observed_at": "2026-07-15T05:43:30.245469+00:00",
      "id": "CVE-2026-56437",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-15T05:43:30.245469+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Uncontrolled search path element issue exists in Pupsman versions prior to 3.9.0. NVD: If a crafted DLL file is placed in the same folder as the affected installer and the installer is executed, arbitrary code may be executed with SYSTEM privilege.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260715T054459Z/items/CVE-2026-56437.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Uncontrolled search path element issue exists in Pupsman versions prior to 3.9.0. NVD: If a crafted DLL file is placed in the same folder as the affected installer and the installer is executed, arbitrary code may be executed with SYSTEM privilege.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-56437/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "hcltech / dfxanalytics",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-56453/",
      "current_public_safe_latest": false,
      "cvss_score": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.08539,
      "epss_score": 0.00187,
      "first_observed_at": "2026-07-23T11:21:51.498947+00:00",
      "id": "CVE-2026-56453",
      "impact_tags": [
        "unauthorized access risk",
        "remote exposure relevant"
      ],
      "kev": false,
      "last_observed_at": "2026-07-23T11:21:51.498947+00:00",
      "latest_item_url": null,
      "product": "dfxanalytics",
      "public_safe_summary": "NVD: HCL DFXAnalytics is affected by an Account Takeover via Response Manipulation vulnerability. NVD: A remote attacker can intercept and alter the contents of the server's HTTP responses before they reach the client application, allowing them to manipulate the authentication or authorization logic to bypass controls and gain unauthorized access to targeted...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260723T112431Z/items/CVE-2026-56453.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: hcltech / dfxanalytics",
      "source_published_impact": "Source describes unauthorized access risk · remote exposure. Possible impact: A remote attacker may access resources that should require stronger authorization.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: HCL DFXAnalytics is affected by an Account Takeover via Response Manipulation vulnerability. NVD: A remote attacker can intercept and alter the contents of the server's HTTP responses before they reach the client application, allowing them to manipulate the authentication or authorization logic to bypass controls and gain unauthorized access to targeted...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-56453/timeline.json",
      "vendor": "hcltech"
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-56537/",
      "current_public_safe_latest": false,
      "cvss_score": 3.5,
      "cvss_severity": "LOW",
      "epss_percentile": 0.05245,
      "epss_score": 0.00156,
      "first_observed_at": "2026-08-03T12:38:03.310457+00:00",
      "id": "CVE-2026-56537",
      "impact_tags": [
        "information exposure review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-03T12:38:03.310457+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: HCL Connections is vulnerable to information disclosure which could allow a user to obtain sensitive information they are not entitled to, caused by improper handling of request data.they are not entitled to, caused by improper handling of request data.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260803T124716Z/items/CVE-2026-56537.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes information exposure review. Possible impact: An attacker may be able to access information that should not be exposed.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: HCL Connections is vulnerable to information disclosure which could allow a user to obtain sensitive information they are not entitled to, caused by improper handling of request data.they are not entitled to, caused by improper handling of request data.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-56537/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-56538/",
      "current_public_safe_latest": false,
      "cvss_score": 3.5,
      "cvss_severity": "LOW",
      "epss_percentile": 0.05245,
      "epss_score": 0.00156,
      "first_observed_at": "2026-08-03T12:38:03.310457+00:00",
      "id": "CVE-2026-56538",
      "impact_tags": [
        "information exposure review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-03T12:38:03.310457+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: An endpoint in HCL Connections is vulnerable to information disclosure. NVD: In certain scenarios this might lead to disclosing sensitive information to unauthorized users.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260803T124716Z/items/CVE-2026-56538.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes information exposure review. Possible impact: An attacker may be able to access information that should not be exposed.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: An endpoint in HCL Connections is vulnerable to information disclosure. NVD: In certain scenarios this might lead to disclosing sensitive information to unauthorized users.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-56538/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "hcltech / icontrol",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-56567/",
      "current_public_safe_latest": false,
      "cvss_score": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.01042,
      "epss_score": 0.00101,
      "first_observed_at": "2026-08-07T16:11:58.676122+00:00",
      "id": "CVE-2026-56567",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-07T16:11:58.676122+00:00",
      "latest_item_url": null,
      "product": "icontrol",
      "public_safe_summary": "NVD: HCL iControl v4.3.0 was affected by Security Misconfiguration vulnerabilities. NVD: It involves the public exposure of internal configuration files due to improper web server or application hardening.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260807T162046Z/items/CVE-2026-56567.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: hcltech / icontrol; affected version context: 4.3.0",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: HCL iControl v4.3.0 was affected by Security Misconfiguration vulnerabilities. NVD: It involves the public exposure of internal configuration files due to improper web server or application hardening.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-56567/timeline.json",
      "vendor": "hcltech"
    },
    {
      "affected_label": "hcltech / icontrol",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-56568/",
      "current_public_safe_latest": false,
      "cvss_score": 3.7,
      "cvss_severity": "LOW",
      "epss_percentile": 0.09538,
      "epss_score": 0.00196,
      "first_observed_at": "2026-08-07T16:11:58.676122+00:00",
      "id": "CVE-2026-56568",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-07T16:11:58.676122+00:00",
      "latest_item_url": null,
      "product": "icontrol",
      "public_safe_summary": "NVD: HCL iControl was affected by Information Exposure Through Verbose Client-Side API Error Messages vulnerabilities. NVD: It involves application displays raw server/API error messages to users instead of generic error messages and exposes internal endpoint names, request parameters, error codes, and authentication status",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260807T162046Z/items/CVE-2026-56568.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: hcltech / icontrol; affected version context: 4.4.0",
      "source_published_impact": "This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: HCL iControl was affected by Information Exposure Through Verbose Client-Side API Error Messages vulnerabilities. NVD: It involves application displays raw server/API error messages to users instead of generic error messages and exposes internal endpoint names, request parameters, error codes, and authentication status",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-56568/timeline.json",
      "vendor": "hcltech"
    },
    {
      "affected_label": "hcltech / icontrol",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-56569/",
      "current_public_safe_latest": false,
      "cvss_score": 4.0,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.01054,
      "epss_score": 0.00101,
      "first_observed_at": "2026-08-07T16:11:58.676122+00:00",
      "id": "CVE-2026-56569",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-07T16:11:58.676122+00:00",
      "latest_item_url": null,
      "product": "icontrol",
      "public_safe_summary": "NVD: HCL iControl was affected by Sensitive Data Exposure vulnerabilities. NVD: It involves the public exposure of internal configuration files due to improper web server or application hardening.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260807T162046Z/items/CVE-2026-56569.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: hcltech / icontrol; affected version context: 4.3.0",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: HCL iControl was affected by Sensitive Data Exposure vulnerabilities. NVD: It involves the public exposure of internal configuration files due to improper web server or application hardening.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-56569/timeline.json",
      "vendor": "hcltech"
    },
    {
      "affected_label": "hcltech / icontrol",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-56570/",
      "current_public_safe_latest": false,
      "cvss_score": 3.7,
      "cvss_severity": "LOW",
      "epss_percentile": 0.07429,
      "epss_score": 0.00177,
      "first_observed_at": "2026-08-07T16:11:58.676122+00:00",
      "id": "CVE-2026-56570",
      "impact_tags": [
        "information exposure review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-07T16:11:58.676122+00:00",
      "latest_item_url": null,
      "product": "icontrol",
      "public_safe_summary": "NVD: HCL iControl was affected by Auto complete Enabled vulnerabilities. NVD: It involves expose sensitive information such as: Valid usernames, Email addresses used for login, Account identifiers If the system is accessed from shared environments, attackers may enumerate valid usernames through browser suggestions.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260807T162046Z/items/CVE-2026-56570.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: hcltech / icontrol; affected version context: 4.4.0",
      "source_published_impact": "Source describes information exposure review. Possible impact: An attacker may be able to access information that should not be exposed.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: HCL iControl was affected by Auto complete Enabled vulnerabilities. NVD: It involves expose sensitive information such as: Valid usernames, Email addresses used for login, Account identifiers If the system is accessed from shared environments, attackers may enumerate valid usernames through browser suggestions.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-56570/timeline.json",
      "vendor": "hcltech"
    },
    {
      "affected_label": "hcltech / icontrol",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-56571/",
      "current_public_safe_latest": false,
      "cvss_score": 3.7,
      "cvss_severity": "LOW",
      "epss_percentile": 0.06816,
      "epss_score": 0.00172,
      "first_observed_at": "2026-08-07T16:11:58.676122+00:00",
      "id": "CVE-2026-56571",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-07T16:11:58.676122+00:00",
      "latest_item_url": null,
      "product": "icontrol",
      "public_safe_summary": "NVD: HCL iControl was affected by Improper Error Handling vulnerabilities. NVD: It involves Out of memory, null pointer exceptions, system call failure, database unavailable, network timeout, and hundreds of other common conditions can cause errors to be generated.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260807T162046Z/items/CVE-2026-56571.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: hcltech / icontrol; affected version context: 4.4.0",
      "source_published_impact": "This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: HCL iControl was affected by Improper Error Handling vulnerabilities. NVD: It involves Out of memory, null pointer exceptions, system call failure, database unavailable, network timeout, and hundreds of other common conditions can cause errors to be generated.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-56571/timeline.json",
      "vendor": "hcltech"
    },
    {
      "affected_label": "hcltech / icontrol",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-56608/",
      "current_public_safe_latest": false,
      "cvss_score": 3.7,
      "cvss_severity": "LOW",
      "epss_percentile": 0.05925,
      "epss_score": 0.00163,
      "first_observed_at": "2026-08-10T10:38:36.347227+00:00",
      "id": "CVE-2026-56608",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-10T10:38:36.347227+00:00",
      "latest_item_url": null,
      "product": "icontrol",
      "public_safe_summary": "NVD: HCL iControl is affected by Missing Access Control vulnerability. NVD: The application failed to enforce proper granular access controls, allowing users to access or view administrator-level functionalities without appropriate authorization.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260810T105121Z/items/CVE-2026-56608.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: hcltech / icontrol; affected version context: 3.2.0",
      "source_published_impact": "This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: HCL iControl is affected by Missing Access Control vulnerability. NVD: The application failed to enforce proper granular access controls, allowing users to access or view administrator-level functionalities without appropriate authorization.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-56608/timeline.json",
      "vendor": "hcltech"
    },
    {
      "affected_label": "hcltech / icontrol",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-56609/",
      "current_public_safe_latest": false,
      "cvss_score": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.00861,
      "epss_score": 0.00097,
      "first_observed_at": "2026-08-10T10:38:36.347227+00:00",
      "id": "CVE-2026-56609",
      "impact_tags": [
        "information exposure review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-10T10:38:36.347227+00:00",
      "latest_item_url": null,
      "product": "icontrol",
      "public_safe_summary": "NVD: HCL iControl is affected by Weak SSL/TLS Version Supported vulnerability. NVD: It was observed that the application was using weak TLS versions such as TLS 1.0 and 1.1. NVD: These outdated protocols lack modern security features, making them vulnerable to known attacks and exposing sensitive information during data transmission.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260810T105121Z/items/CVE-2026-56609.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: hcltech / icontrol; affected version context: 3.2.0",
      "source_published_impact": "Source describes information exposure review. Possible impact: An attacker may be able to access information that should not be exposed.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: HCL iControl is affected by Weak SSL/TLS Version Supported vulnerability. NVD: It was observed that the application was using weak TLS versions such as TLS 1.0 and 1.1. NVD: These outdated protocols lack modern security features, making them vulnerable to known attacks and exposing sensitive information during data transmission.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-56609/timeline.json",
      "vendor": "hcltech"
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-56670/",
      "current_public_safe_latest": false,
      "cvss_score": 8.2,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.1307,
      "epss_score": 0.00224,
      "first_observed_at": "2026-08-07T05:06:11.845797+00:00",
      "id": "CVE-2026-56670",
      "impact_tags": [
        "XSS risk"
      ],
      "kev": false,
      "last_observed_at": "2026-08-07T05:06:11.845797+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: ComfyUI is a modular diffusion model GUI, api and backend with a graph/nodes interface. NVD: Prior to 0.28.0, the /view endpoint served uploaded SVG files inline because image/svg+xml and related XML content types were absent from the dangerous-content-type handling, allowing stored cross-site scripting in the ComfyUI origin. NVD: This issue is fixed in version 0.28.0.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260807T051140Z/items/CVE-2026-56670.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes XSS risk. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: ComfyUI is a modular diffusion model GUI, api and backend with a graph/nodes interface. NVD: Prior to 0.28.0, the /view endpoint served uploaded SVG files inline because image/svg+xml and related XML content types were absent from the dangerous-content-type handling, allowing stored cross-site scripting in the ComfyUI origin. NVD: This issue is fixed in version 0.28.0.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-56670/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-56671/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.4816,
      "epss_score": 0.00661,
      "first_observed_at": "2026-08-07T05:06:11.845797+00:00",
      "id": "CVE-2026-56671",
      "impact_tags": [
        "path traversal review",
        "remote exposure relevant"
      ],
      "kev": false,
      "last_observed_at": "2026-08-07T05:06:11.845797+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: ComfyUI is a modular diffusion model GUI, api and backend with a graph/nodes interface. NVD: Prior to 0.28.0, get_model_preview in app/model_manager.py joins an unrestricted filename route capture to a selected model directory without a containment check, allowing an unauthenticated remote attacker to use traversal, encoded traversal, absolute paths... NVD: get_model_preview (app/model_manager.py) built the path with os.path.join(folder, filename) where filename is an unrestricted {filename:.*} route capture.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260807T051140Z/items/CVE-2026-56671.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes path traversal review · remote exposure. Possible impact: A remote attacker may be able to reach files outside the intended application path.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: ComfyUI is a modular diffusion model GUI, api and backend with a graph/nodes interface. NVD: Prior to 0.28.0, get_model_preview in app/model_manager.py joins an unrestricted filename route capture to a selected model directory without a containment check, allowing an unauthenticated remote attacker to use traversal, encoded traversal, absolute paths... NVD: get_model_preview (app/model_manager.py) built the path with os.path.join(folder, filename) where filename is an unrestricted {filename:.*} route capture.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-56671/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-56672/",
      "current_public_safe_latest": false,
      "cvss_score": 8.2,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.14703,
      "epss_score": 0.00237,
      "first_observed_at": "2026-08-07T05:06:11.845797+00:00",
      "id": "CVE-2026-56672",
      "impact_tags": [
        "XSS risk"
      ],
      "kev": false,
      "last_observed_at": "2026-08-07T05:06:11.845797+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: ComfyUI is a node-based diffusion model GUI, API, and backend. NVD: Prior to 0.28.0, GET /userdata/{file} served user-controlled HTML and SVG files with extension-derived content types, allowing stored cross-site scripting in the ComfyUI origin and access to browser-stored API tokens, settings, workflows, and... NVD: The handler used web.FileResponse(path), so an uploaded .html/.svg was served as text/html/image/svg+xml.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260807T051140Z/items/CVE-2026-56672.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes XSS risk. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: ComfyUI is a node-based diffusion model GUI, API, and backend. NVD: Prior to 0.28.0, GET /userdata/{file} served user-controlled HTML and SVG files with extension-derived content types, allowing stored cross-site scripting in the ComfyUI origin and access to browser-stored API tokens, settings, workflows, and... NVD: The handler used web.FileResponse(path), so an uploaded .html/.svg was served as text/html/image/svg+xml.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-56672/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-56673/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.35398,
      "epss_score": 0.0043,
      "first_observed_at": "2026-08-07T05:06:11.845797+00:00",
      "id": "CVE-2026-56673",
      "impact_tags": [
        "path traversal review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-07T05:06:11.845797+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: ComfyUI is a modular diffusion model GUI, API, and backend with a graph-and-node interface. NVD: Prior to 0.28.0, folder_paths.get_annotated_filepath and exists_annotated_filepath join workflow-controlled annotated filenames to a base directory without a containment check, allowing an unauthenticated crafted POST /prompt workflow using LoadImage or... NVD: LoadImage defines a VALIDATE_INPUTS method, which causes the execution engine to skip COMBO (input-directory) validation.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260807T051140Z/items/CVE-2026-56673.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes path traversal review. Possible impact: An attacker may be able to reach files outside the intended application path.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: ComfyUI is a modular diffusion model GUI, API, and backend with a graph-and-node interface. NVD: Prior to 0.28.0, folder_paths.get_annotated_filepath and exists_annotated_filepath join workflow-controlled annotated filenames to a base directory without a containment check, allowing an unauthenticated crafted POST /prompt workflow using LoadImage or... NVD: LoadImage defines a VALIDATE_INPUTS method, which causes the execution engine to skip COMBO (input-directory) validation.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-56673/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "dell / powerflex_manager",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-56688/",
      "current_public_safe_latest": false,
      "cvss_score": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.66879,
      "epss_score": 0.01285,
      "first_observed_at": "2026-07-17T10:59:18.822206+00:00",
      "id": "CVE-2026-56688",
      "impact_tags": [
        "command execution review",
        "admin privilege risk",
        "command injection risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-17T10:59:18.822206+00:00",
      "latest_item_url": null,
      "product": "powerflex_manager",
      "public_safe_summary": "NVD: Dell PowerFlex Manager, Version prior to 5.1.0.1, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. NVD: A high privileged attacker with remote access could potentially exploit this vulnerability during OS Repository processing to achieve arbitrary command execution as root, potentially leading to full appliance compromise and lateral movement into managed...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260717T110142Z/items/CVE-2026-56688.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: dell / powerflex_manager",
      "source_published_impact": "Source describes command execution risk · admin privilege risk · command injection risk. Possible impact: An attacker may gain root or administrative-level privileges on affected systems.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Dell PowerFlex Manager, Version prior to 5.1.0.1, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. NVD: A high privileged attacker with remote access could potentially exploit this vulnerability during OS Repository processing to achieve arbitrary command execution as root, potentially leading to full appliance compromise and lateral movement into managed...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-56688/timeline.json",
      "vendor": "dell"
    },
    {
      "affected_label": "dell / powerflex_manager",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-56689/",
      "current_public_safe_latest": false,
      "cvss_score": 7.7,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.11919,
      "epss_score": 0.00215,
      "first_observed_at": "2026-07-17T10:59:18.822206+00:00",
      "id": "CVE-2026-56689",
      "impact_tags": [
        "SQL injection risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-17T10:59:18.822206+00:00",
      "latest_item_url": null,
      "product": "powerflex_manager",
      "public_safe_summary": "NVD: Dell PowerFlex Manager, Version prior to 5.1.0.1, contain(s) an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. NVD: A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information exposure.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260717T110142Z/items/CVE-2026-56689.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: dell / powerflex_manager",
      "source_published_impact": "Source describes SQL injection risk. Possible impact: An attacker may be able to read or change database-backed application data.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Dell PowerFlex Manager, Version prior to 5.1.0.1, contain(s) an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. NVD: A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information exposure.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-56689/timeline.json",
      "vendor": "dell"
    },
    {
      "affected_label": "dell / powerflex_manager",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-56690/",
      "current_public_safe_latest": false,
      "cvss_score": 8.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.13826,
      "epss_score": 0.0023,
      "first_observed_at": "2026-07-17T10:59:18.822206+00:00",
      "id": "CVE-2026-56690",
      "impact_tags": [
        "unauthorized access risk",
        "information exposure review",
        "SQL injection risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-17T10:59:18.822206+00:00",
      "latest_item_url": null,
      "product": "powerflex_manager",
      "public_safe_summary": "NVD: Dell PowerFlex Manager, Version prior to 5.1.0.1, contain(s) an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. NVD: A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure, Information exposure, and Unauthorized access.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260717T110142Z/items/CVE-2026-56690.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: dell / powerflex_manager",
      "source_published_impact": "Source describes unauthorized access risk · information exposure review · SQL injection risk. Possible impact: An attacker may be able to read or change database-backed application data.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Dell PowerFlex Manager, Version prior to 5.1.0.1, contain(s) an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. NVD: A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure, Information exposure, and Unauthorized access.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-56690/timeline.json",
      "vendor": "dell"
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-56699/",
      "current_public_safe_latest": false,
      "cvss_score": 10.0,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.27494,
      "epss_score": 0.00351,
      "first_observed_at": "2026-07-22T11:51:23.239908+00:00",
      "id": "CVE-2026-56699",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-22T11:51:23.239908+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Wazuh Manager before 5.0.0-beta3 fails to escape the DataValue.index field when constructing OpenSearch bulk requests, allowing enrolled agents to inject arbitrary NDJSON operations. NVD: Attackers can smuggle delete, index, or update operations into bulk requests executed under the manager's admin credentials, enabling document deletion, alert tampering, and cross-agent SIEM state manipulation. OSV: Wazuh Manager - NDJSON Injection in inventory_sync via Agent-Controlled DataValue.index",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260722T115421Z/items/CVE-2026-56699.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Wazuh Manager before 5.0.0-beta3 fails to escape the DataValue.index field when constructing OpenSearch bulk requests, allowing enrolled agents to inject arbitrary NDJSON operations. NVD: Attackers can smuggle delete, index, or update operations into bulk requests executed under the manager's admin credentials, enabling document deletion, alert tampering, and cross-agent SIEM state manipulation. OSV: Wazuh Manager - NDJSON Injection in inventory_sync via Agent-Controlled DataValue.index",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-56699/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-56763/",
      "current_public_safe_latest": false,
      "cvss_score": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.07394,
      "epss_score": 0.00177,
      "first_observed_at": "2026-07-18T08:01:52.653915+00:00",
      "id": "CVE-2026-56763",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-18T10:42:57.422810+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Hono before 4.12.7 allows __proto__ key in parseBody with dot option enabled, permitting specially crafted form field names to create objects with __proto__ properties. NVD: When parsed results are merged into regular JavaScript objects using unsafe merge patterns, attackers can exploit this to achieve prototype pollution and modify object behavior. OSV: Hono - Prototype Pollution via __proto__ Key in parseBody with dot Option",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260718T104447Z/items/CVE-2026-56763.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 4,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Hono before 4.12.7 allows __proto__ key in parseBody with dot option enabled, permitting specially crafted form field names to create objects with __proto__ properties. NVD: When parsed results are merged into regular JavaScript objects using unsafe merge patterns, attackers can exploit this to achieve prototype pollution and modify object behavior. OSV: Hono - Prototype Pollution via __proto__ Key in parseBody with dot Option",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-56763/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-56764/",
      "current_public_safe_latest": false,
      "cvss_score": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.13787,
      "epss_score": 0.00229,
      "first_observed_at": "2026-07-22T11:51:23.239908+00:00",
      "id": "CVE-2026-56764",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-22T11:51:23.239908+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Hono before 4.11.10 contains a timing attack vulnerability in the basicAuth and bearerAuth middlewares due to non-constant-time string comparison in the timingSafeEqual function. NVD: Attackers can exploit early termination of string equality checks to infer valid credentials through precise timing measurements. OSV: Hono - Timing Attack in basicAuth and bearerAuth Middleware",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260722T115421Z/items/CVE-2026-56764.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Hono before 4.11.10 contains a timing attack vulnerability in the basicAuth and bearerAuth middlewares due to non-constant-time string comparison in the timingSafeEqual function. NVD: Attackers can exploit early termination of string equality checks to infer valid credentials through precise timing measurements. OSV: Hono - Timing Attack in basicAuth and bearerAuth Middleware",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-56764/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "phoenixframework / phoenix",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-56811/",
      "current_public_safe_latest": false,
      "cvss_score": 8.7,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.33946,
      "epss_score": 0.0042,
      "first_observed_at": "2026-07-14T10:57:43.777280+00:00",
      "id": "CVE-2026-56811",
      "impact_tags": [
        "service availability review",
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-14T10:57:43.777280+00:00",
      "latest_item_url": null,
      "product": "phoenix",
      "public_safe_summary": "NVD: Allocation of Resources Without Limits or Throttling vulnerability in phoenixframework phoenix (Phoenix.Socket module) allows an unauthenticated attacker to cause a denial of service against any endpoint that mounts a Phoenix socket with a reachable channel... NVD: This vulnerability is associated with program files lib/phoenix/socket.ex and program routine 'Elixir.Phoenix.Socket':handle_in/4. NVD: Phoenix transports do not limit the number of channels that a single transport process may join.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260714T110007Z/items/CVE-2026-56811.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: phoenixframework / phoenix",
      "source_published_impact": "Source describes service availability risk · remote exposure · authenticated boundary. Possible impact: The affected service may become unavailable or unreliable.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Allocation of Resources Without Limits or Throttling vulnerability in phoenixframework phoenix (Phoenix.Socket module) allows an unauthenticated attacker to cause a denial of service against any endpoint that mounts a Phoenix socket with a reachable channel... NVD: This vulnerability is associated with program files lib/phoenix/socket.ex and program routine 'Elixir.Phoenix.Socket':handle_in/4. NVD: Phoenix transports do not limit the number of channels that a single transport process may join.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-56811/timeline.json",
      "vendor": "phoenixframework"
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-56813/",
      "current_public_safe_latest": false,
      "cvss_score": 2.1,
      "cvss_severity": "LOW",
      "epss_percentile": 0.04262,
      "epss_score": 0.00146,
      "first_observed_at": "2026-07-17T10:59:18.822206+00:00",
      "id": "CVE-2026-56813",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-17T10:59:18.822206+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Improper Neutralization of Parameter/Argument Delimiters vulnerability in elixir-plug plug allows an attacker to inject or override HTTP cookie attributes. NVD: The Plug.Conn.Cookies.encode/2 function in lib/plug/conn/cookies.ex builds the Set-Cookie response header by interpolating the cookie value and its path, domain, same_site, and extra attributes directly into the header without neutralizing the ';' delimiter... NVD: An application that places attacker-controlled data into a cookie value or attribute (for example via Plug.Conn.put_resp_cookie/4 when reflecting a username or preference) lets an attacker inject a ';' to append or override cookie attributes (such as Domain...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260717T110142Z/items/CVE-2026-56813.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Improper Neutralization of Parameter/Argument Delimiters vulnerability in elixir-plug plug allows an attacker to inject or override HTTP cookie attributes. NVD: The Plug.Conn.Cookies.encode/2 function in lib/plug/conn/cookies.ex builds the Set-Cookie response header by interpolating the cookie value and its path, domain, same_site, and extra attributes directly into the header without neutralizing the ';' delimiter... NVD: An application that places attacker-controlled data into a cookie value or attribute (for example via Plug.Conn.put_resp_cookie/4 when reflecting a username or preference) lets an attacker inject a ';' to append or override cookie attributes (such as Domain...",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-56813/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-56814/",
      "current_public_safe_latest": false,
      "cvss_score": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.43759,
      "epss_score": 0.00579,
      "first_observed_at": "2026-07-17T10:59:18.822206+00:00",
      "id": "CVE-2026-56814",
      "impact_tags": [
        "service availability review",
        "remote exposure relevant"
      ],
      "kev": false,
      "last_observed_at": "2026-07-17T10:59:18.822206+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Plug.Parsers.MULTIPART, the multipart request-body parser used to handle file uploads and multipart forms, does not enforce its :length budget against all consumed resources, allowing an unauthenticated remote attacker to cause denial of service. NVD: The parser charges the :length limit only for part body bytes; part header bytes are never counted, and a part with an empty body costs zero. NVD: Because every part whose Content-Disposition carries a non-empty filename creates a fresh temporary file (via Plug.Upload) and retains a Plug.Upload struct for the duration of the request, an attacker can send a single request composed of many empty-body file...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260717T110142Z/items/CVE-2026-56814.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes service availability risk · remote exposure. Possible impact: The affected service may become unavailable or unreliable.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Plug.Parsers.MULTIPART, the multipart request-body parser used to handle file uploads and multipart forms, does not enforce its :length budget against all consumed resources, allowing an unauthenticated remote attacker to cause denial of service. NVD: The parser charges the :length limit only for part body bytes; part header bytes are never counted, and a part with an empty body costs zero. NVD: Because every part whose Content-Disposition carries a non-empty filename creates a fresh temporary file (via Plug.Upload) and retains a Plug.Upload struct for the duration of the request, an attacker can send a single request composed of many empty-body file...",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-56814/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-56817/",
      "current_public_safe_latest": false,
      "cvss_score": 8.3,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.24359,
      "epss_score": 0.0032,
      "first_observed_at": "2026-07-28T22:27:58.188634+00:00",
      "id": "CVE-2026-56817",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-28T22:27:58.188634+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Netty is a network application framework for development of protocol servers and clients. NVD: In versions 4.2.0.Final through 4.2.15.Final and 4.1.0.Final through 4.1.135.Final, any caller that can deliver bytes to a Netty channel pipeline containing XmlDecoder can send XML with a DOCTYPE declaration to an AsyncXMLInputFactory instantiated with no... NVD: This issue is fixed in versions 4.1.136.Final and 4.2.16.Final.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260728T223134Z/items/CVE-2026-56817.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: versions.",
      "source_published_summary": "NVD: Netty is a network application framework for development of protocol servers and clients. NVD: In versions 4.2.0.Final through 4.2.15.Final and 4.1.0.Final through 4.1.135.Final, any caller that can deliver bytes to a Netty channel pipeline containing XmlDecoder can send XML with a DOCTYPE declaration to an AsyncXMLInputFactory instantiated with no... NVD: This issue is fixed in versions 4.1.136.Final and 4.2.16.Final.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-56817/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-56819/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.27177,
      "epss_score": 0.00346,
      "first_observed_at": "2026-07-28T22:27:58.188634+00:00",
      "id": "CVE-2026-56819",
      "impact_tags": [
        "service availability review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-28T22:27:58.188634+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Netty is a network application framework for development of protocol servers and clients. NVD: In versions 4.2.0.Final through 4.2.15.Final and 4.1.0.Final through 4.1.135.Final, a remote unauthenticated peer can leak one direct ByteBuf per HTTP/2 DATA frame in applications that enable HTTP/2 content decompression via... NVD: When a DATA frame is processed for a stream whose decompressor has already been closed, Http2Decompressor.decompress(...) calls decompressor.writeInbound(data.retain()) and does not release the retained buffer on the error path, eventually exhausting direct...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260728T223134Z/items/CVE-2026-56819.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes service availability risk. Possible impact: The affected service may become unavailable or unreliable.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: versions.",
      "source_published_summary": "NVD: Netty is a network application framework for development of protocol servers and clients. NVD: In versions 4.2.0.Final through 4.2.15.Final and 4.1.0.Final through 4.1.135.Final, a remote unauthenticated peer can leak one direct ByteBuf per HTTP/2 DATA frame in applications that enable HTTP/2 content decompression via... NVD: When a DATA frame is processed for a stream whose decompressor has already been closed, Http2Decompressor.decompress(...) calls decompressor.writeInbound(data.retain()) and does not release the retained buffer on the error path, eventually exhausting direct...",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-56819/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-56820/",
      "current_public_safe_latest": false,
      "cvss_score": 7.4,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.08239,
      "epss_score": 0.00183,
      "first_observed_at": "2026-07-28T22:27:58.188634+00:00",
      "id": "CVE-2026-56820",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-28T22:27:58.188634+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Netty is a network application framework for development of protocol servers and clients. NVD: In versions 4.2.0.Final through 4.2.15.Final and prior to 4.1.135.Final, OcspClient does not validate that the CertificateID in an OCSP response matches the requested CertificateID, which can lead to replay attack. NVD: OcspClient.validateResponse accepts a legitimately signed GOOD status response for an unrelated certificate issued by the same CA, allowing bypass of revocation checks for another certificate.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260728T223134Z/items/CVE-2026-56820.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: versions.",
      "source_published_summary": "NVD: Netty is a network application framework for development of protocol servers and clients. NVD: In versions 4.2.0.Final through 4.2.15.Final and prior to 4.1.135.Final, OcspClient does not validate that the CertificateID in an OCSP response matches the requested CertificateID, which can lead to replay attack. NVD: OcspClient.validateResponse accepts a legitimately signed GOOD status response for an unrelated certificate issued by the same CA, allowing bypass of revocation checks for another certificate.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-56820/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-56821/",
      "current_public_safe_latest": false,
      "cvss_score": 7.4,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.03821,
      "epss_score": 0.0014,
      "first_observed_at": "2026-08-04T22:31:51.932237+00:00",
      "id": "CVE-2026-56821",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-04T22:31:51.932237+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Netty is an asynchronous, event-driven network application framework. NVD: Prior to versions 4.1.136.Final and 4.2.16.Final, the OcspServerCertificateValidator flags an out-of-date OCSP response but does not stop processing it, so an expired GOOD response is still reported as VALID, letting an on-path attacker replay a stale GOOD... NVD: Exploitation can lead to certificate revocation bypass via replay of an expired OCSP response.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260804T223546Z/items/CVE-2026-56821.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: versions.",
      "source_published_summary": "NVD: Netty is an asynchronous, event-driven network application framework. NVD: Prior to versions 4.1.136.Final and 4.2.16.Final, the OcspServerCertificateValidator flags an out-of-date OCSP response but does not stop processing it, so an expired GOOD response is still reported as VALID, letting an on-path attacker replay a stale GOOD... NVD: Exploitation can lead to certificate revocation bypass via replay of an expired OCSP response.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-56821/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-56822/",
      "current_public_safe_latest": false,
      "cvss_score": 7.4,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.01606,
      "epss_score": 0.00112,
      "first_observed_at": "2026-08-04T22:31:51.932237+00:00",
      "id": "CVE-2026-56822",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-04T22:31:51.932237+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Netty is an asynchronous, event-driven network application framework. NVD: Prior to versions 4.1.136.Final and 4.2.16.Final, the OcspServerCertificateValidator forwards the SslHandshakeCompletionEvent before the asynchronous OCSP validation completes. NVD: This allows the client's downstream handlers to send sensitive application data (e.g., HTTP requests) to a revoked server before the channel is closed by the OCSP check.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260804T223546Z/items/CVE-2026-56822.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: versions.",
      "source_published_summary": "NVD: Netty is an asynchronous, event-driven network application framework. NVD: Prior to versions 4.1.136.Final and 4.2.16.Final, the OcspServerCertificateValidator forwards the SslHandshakeCompletionEvent before the asynchronous OCSP validation completes. NVD: This allows the client's downstream handlers to send sensitive application data (e.g., HTTP requests) to a revoked server before the channel is closed by the OCSP check.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-56822/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-56877/",
      "current_public_safe_latest": false,
      "cvss_score": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.33316,
      "epss_score": 0.0041,
      "first_observed_at": "2026-07-20T22:16:32.807845+00:00",
      "id": "CVE-2026-56877",
      "impact_tags": [
        "service availability review",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-20T22:16:32.807845+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The SCORM lab launch endpoint in Skillable (scorm.skillable.com) through 2026-07-13 does not validate the client-supplied userId parameter against the authenticated SCORM session token. NVD: An authenticated user can substitute arbitrary userId values to bypass per-user lab launch rate limits and consume other users' lab allocations, resulting in denial of service against targeted users' lab and exam access. NVD: Skillable was formerly named Learn on Demand Systems.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260720T222315Z/items/CVE-2026-56877.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes service availability risk · authenticated boundary. Possible impact: The affected service may become unavailable or unreliable.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The SCORM lab launch endpoint in Skillable (scorm.skillable.com) through 2026-07-13 does not validate the client-supplied userId parameter against the authenticated SCORM session token. NVD: An authenticated user can substitute arbitrary userId values to bypass per-user lab launch rate limits and consume other users' lab allocations, resulting in denial of service against targeted users' lab and exam access. NVD: Skillable was formerly named Learn on Demand Systems.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-56877/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "microsoft / entra_provisioning_service",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-57100/",
      "current_public_safe_latest": false,
      "cvss_score": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.45908,
      "epss_score": 0.0063,
      "first_observed_at": "2026-07-09T22:45:10.548837+00:00",
      "id": "CVE-2026-57100",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-09T22:45:10.548837+00:00",
      "latest_item_url": null,
      "product": "entra_provisioning_service",
      "public_safe_summary": "NVD: Server-side request forgery (ssrf) in Microsoft Entra Provisioning Service (SyncFabric) allows an authorized attacker to elevate privileges over a network.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260709T224554Z/items/CVE-2026-57100.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: microsoft / entra_provisioning_service; affected version context: -",
      "source_published_impact": "This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Server-side request forgery (ssrf) in Microsoft Entra Provisioning Service (SyncFabric) allows an authorized attacker to elevate privileges over a network.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-57100/timeline.json",
      "vendor": "microsoft"
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-5730/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.15799,
      "epss_score": 0.00246,
      "first_observed_at": "2026-07-14T05:42:23.241208+00:00",
      "id": "CVE-2026-5730",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-14T05:42:23.241208+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Authorization bypass through User-Controlled key vulnerability in Idvlabs Software and Consulting Services Inc. NVD: Ontime allows Exploitation of Trusted Identifiers. NVD: This issue affects Ontime: through 04052026.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260714T054512Z/items/CVE-2026-5730.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Authorization bypass through User-Controlled key vulnerability in Idvlabs Software and Consulting Services Inc. NVD: Ontime allows Exploitation of Trusted Identifiers. NVD: This issue affects Ontime: through 04052026.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-5730/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-57308/",
      "current_public_safe_latest": false,
      "cvss_score": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.30112,
      "epss_score": 0.00375,
      "first_observed_at": "2026-07-27T12:38:45.912501+00:00",
      "id": "CVE-2026-57308",
      "impact_tags": [
        "SQL injection risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-27T12:38:45.912501+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Syncope. NVD: An administrator with adequate entitlements can achieve execution of arbitrary SQL via stacked queries, leveraging unsanitized sort parameters. NVD: This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 Through 4.0.6, from 4.1.0-M0 through 4.1.1.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260727T124133Z/items/CVE-2026-57308.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes SQL injection risk. Possible impact: An attacker may be able to read or change database-backed application data.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Syncope. NVD: An administrator with adequate entitlements can achieve execution of arbitrary SQL via stacked queries, leveraging unsanitized sort parameters. NVD: This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 Through 4.0.6, from 4.1.0-M0 through 4.1.1.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-57308/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-57309/",
      "current_public_safe_latest": false,
      "cvss_score": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.23707,
      "epss_score": 0.00314,
      "first_observed_at": "2026-07-27T12:38:45.912501+00:00",
      "id": "CVE-2026-57309",
      "impact_tags": [
        "SQL injection risk",
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-27T12:38:45.912501+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A Blind SQL injection vulnerability has been identified in Windu CMS. NVD: A remote unauthenticated attacker is able to inject SQL syntax into URL path in HTTP header resulting in Blind SQL Injection. NVD: Because vendor contact attempts were unsuccessful, the vulnerability has only been confirmed in version 4.1 but may also affect other versions.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260727T124133Z/items/CVE-2026-57309.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes SQL injection risk · remote exposure · authenticated boundary. Possible impact: A remote attacker may be able to read or change database-backed application data.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A Blind SQL injection vulnerability has been identified in Windu CMS. NVD: A remote unauthenticated attacker is able to inject SQL syntax into URL path in HTTP header resulting in Blind SQL Injection. NVD: Because vendor contact attempts were unsuccessful, the vulnerability has only been confirmed in version 4.1 but may also affect other versions.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-57309/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-57310/",
      "current_public_safe_latest": false,
      "cvss_score": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.07132,
      "epss_score": 0.00174,
      "first_observed_at": "2026-07-27T12:38:45.912501+00:00",
      "id": "CVE-2026-57310",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-27T12:38:45.912501+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Windu CMS uses hashing algorithm based on MD5 and SHA1 with static salt to store user passwords. NVD: This allows an attacker who obtain password hash to decode user credentials. NVD: Because vendor contact attempts were unsuccessful, the vulnerability has only been confirmed in version 4.1 but may also affect other versions.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260727T124133Z/items/CVE-2026-57310.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Windu CMS uses hashing algorithm based on MD5 and SHA1 with static salt to store user passwords. NVD: This allows an attacker who obtain password hash to decode user credentials. NVD: Because vendor contact attempts were unsuccessful, the vulnerability has only been confirmed in version 4.1 but may also affect other versions.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-57310/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-57311/",
      "current_public_safe_latest": false,
      "cvss_score": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.29994,
      "epss_score": 0.00374,
      "first_observed_at": "2026-07-27T12:38:45.912501+00:00",
      "id": "CVE-2026-57311",
      "impact_tags": [
        "code execution review",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-27T12:38:45.912501+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Windu CMS does not validate types of uploaded files. NVD: An authenticated attacker can upload arbitrary files, including PHP. NVD: This can lead to Remote Code Execution.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260727T124133Z/items/CVE-2026-57311.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes code execution review · authenticated boundary. Possible impact: An attacker may be able to run code or commands on affected systems.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Windu CMS does not validate types of uploaded files. NVD: An authenticated attacker can upload arbitrary files, including PHP. NVD: This can lead to Remote Code Execution.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-57311/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-57349/",
      "current_public_safe_latest": false,
      "cvss_score": 7.1,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.08947,
      "epss_score": 0.00191,
      "first_observed_at": "2026-07-09T12:17:39.450457+00:00",
      "id": "CVE-2026-57349",
      "impact_tags": [
        "XSS risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-09T12:17:39.450457+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Unauthenticated Cross Site Scripting (XSS) in WPeMatico RSS Feed Fetcher <= 2.8.17 versions.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260709T121832Z/items/CVE-2026-57349.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes XSS risk. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Unauthenticated Cross Site Scripting (XSS) in WPeMatico RSS Feed Fetcher <= 2.8.17 versions.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-57349/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-57350/",
      "current_public_safe_latest": false,
      "cvss_score": 7.1,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.08947,
      "epss_score": 0.00191,
      "first_observed_at": "2026-07-09T12:17:39.450457+00:00",
      "id": "CVE-2026-57350",
      "impact_tags": [
        "XSS risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-09T12:17:39.450457+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Unauthenticated Cross Site Scripting (XSS) in WP Debugging <= 2.12.2 versions.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260709T121832Z/items/CVE-2026-57350.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes XSS risk. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Unauthenticated Cross Site Scripting (XSS) in WP Debugging <= 2.12.2 versions.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-57350/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-57351/",
      "current_public_safe_latest": false,
      "cvss_score": 7.1,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.08947,
      "epss_score": 0.00191,
      "first_observed_at": "2026-07-09T12:17:39.450457+00:00",
      "id": "CVE-2026-57351",
      "impact_tags": [
        "XSS risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-09T12:17:39.450457+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Unauthenticated Cross Site Scripting (XSS) in HandL UTM Grabber <= 2.9.2 versions.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260709T121832Z/items/CVE-2026-57351.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes XSS risk. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Unauthenticated Cross Site Scripting (XSS) in HandL UTM Grabber <= 2.9.2 versions.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-57351/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-57352/",
      "current_public_safe_latest": false,
      "cvss_score": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.1122,
      "epss_score": 0.0021,
      "first_observed_at": "2026-07-09T12:17:39.450457+00:00",
      "id": "CVE-2026-57352",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-09T12:17:39.450457+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Unauthenticated Broken Authentication in ALD – Dropshipping and Fulfillment for AliExpress and WooCommerce <= 2.2.0 versions.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260709T121832Z/items/CVE-2026-57352.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Unauthenticated Broken Authentication in ALD – Dropshipping and Fulfillment for AliExpress and WooCommerce <= 2.2.0 versions.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-57352/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-57353/",
      "current_public_safe_latest": false,
      "cvss_score": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.21691,
      "epss_score": 0.00299,
      "first_observed_at": "2026-07-09T12:17:39.450457+00:00",
      "id": "CVE-2026-57353",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-09T12:17:39.450457+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Subscriber Broken Access Control in Link Whisper Premium <= 2.9.0 versions.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260709T121832Z/items/CVE-2026-57353.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Subscriber Broken Access Control in Link Whisper Premium <= 2.9.0 versions.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-57353/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-57354/",
      "current_public_safe_latest": false,
      "cvss_score": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.13018,
      "epss_score": 0.00224,
      "first_observed_at": "2026-07-09T12:17:39.450457+00:00",
      "id": "CVE-2026-57354",
      "impact_tags": [
        "XSS risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-09T12:17:39.450457+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Subscriber Cross Site Scripting (XSS) in JetReviews <= 3.0.0.1 versions.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260709T121832Z/items/CVE-2026-57354.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes XSS risk. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Subscriber Cross Site Scripting (XSS) in JetReviews <= 3.0.0.1 versions.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-57354/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-57355/",
      "current_public_safe_latest": false,
      "cvss_score": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.2169,
      "epss_score": 0.00299,
      "first_observed_at": "2026-07-09T12:17:39.450457+00:00",
      "id": "CVE-2026-57355",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-09T12:17:39.450457+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Subscriber Broken Access Control in Classified Listing <= 5.4.2 versions.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260709T121832Z/items/CVE-2026-57355.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Subscriber Broken Access Control in Classified Listing <= 5.4.2 versions.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-57355/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-57356/",
      "current_public_safe_latest": false,
      "cvss_score": 7.1,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.08946,
      "epss_score": 0.00191,
      "first_observed_at": "2026-07-09T12:17:39.450457+00:00",
      "id": "CVE-2026-57356",
      "impact_tags": [
        "XSS risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-09T12:17:39.450457+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Unauthenticated Cross Site Scripting (XSS) in MC Woocommerce Wishlist <= 1.9.19 versions.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260709T121832Z/items/CVE-2026-57356.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes XSS risk. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Unauthenticated Cross Site Scripting (XSS) in MC Woocommerce Wishlist <= 1.9.19 versions.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-57356/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-57357/",
      "current_public_safe_latest": false,
      "cvss_score": 7.1,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.08946,
      "epss_score": 0.00191,
      "first_observed_at": "2026-07-09T12:17:39.450457+00:00",
      "id": "CVE-2026-57357",
      "impact_tags": [
        "XSS risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-09T12:17:39.450457+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Unauthenticated Cross Site Scripting (XSS) in Search Atlas SEO <= 2.6.6 versions.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260709T121832Z/items/CVE-2026-57357.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes XSS risk. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Unauthenticated Cross Site Scripting (XSS) in Search Atlas SEO <= 2.6.6 versions.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-57357/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-57358/",
      "current_public_safe_latest": false,
      "cvss_score": 7.1,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.08945,
      "epss_score": 0.00191,
      "first_observed_at": "2026-07-09T12:17:39.450457+00:00",
      "id": "CVE-2026-57358",
      "impact_tags": [
        "XSS risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-09T12:17:39.450457+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Unauthenticated Cross Site Scripting (XSS) in Customize My Account for WooCommerce <= 4.3.9 versions.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260709T121832Z/items/CVE-2026-57358.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes XSS risk. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Unauthenticated Cross Site Scripting (XSS) in Customize My Account for WooCommerce <= 4.3.9 versions.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-57358/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-57359/",
      "current_public_safe_latest": false,
      "cvss_score": 7.1,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.08949,
      "epss_score": 0.00191,
      "first_observed_at": "2026-07-09T12:17:39.450457+00:00",
      "id": "CVE-2026-57359",
      "impact_tags": [
        "XSS risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-09T12:17:39.450457+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Unauthenticated Cross Site Scripting (XSS) in ReviewX <= 2.3.10 versions.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260709T121832Z/items/CVE-2026-57359.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes XSS risk. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Unauthenticated Cross Site Scripting (XSS) in ReviewX <= 2.3.10 versions.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-57359/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-57360/",
      "current_public_safe_latest": false,
      "cvss_score": 7.1,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.08949,
      "epss_score": 0.00191,
      "first_observed_at": "2026-07-09T12:17:39.450457+00:00",
      "id": "CVE-2026-57360",
      "impact_tags": [
        "XSS risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-09T12:17:39.450457+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Unauthenticated Cross Site Scripting (XSS) in eCommerce Product Catalog <= 3.5.4 versions.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260709T121832Z/items/CVE-2026-57360.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes XSS risk. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Unauthenticated Cross Site Scripting (XSS) in eCommerce Product Catalog <= 3.5.4 versions.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-57360/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-57361/",
      "current_public_safe_latest": false,
      "cvss_score": 7.1,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.08951,
      "epss_score": 0.00191,
      "first_observed_at": "2026-07-09T12:17:39.450457+00:00",
      "id": "CVE-2026-57361",
      "impact_tags": [
        "XSS risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-09T12:17:39.450457+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Unauthenticated Cross Site Scripting (XSS) in Survey Maker <= 5.2.2.5 versions.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260709T121832Z/items/CVE-2026-57361.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes XSS risk. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Unauthenticated Cross Site Scripting (XSS) in Survey Maker <= 5.2.2.5 versions.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-57361/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-57362/",
      "current_public_safe_latest": false,
      "cvss_score": 7.1,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.08944,
      "epss_score": 0.00191,
      "first_observed_at": "2026-07-09T12:17:39.450457+00:00",
      "id": "CVE-2026-57362",
      "impact_tags": [
        "XSS risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-09T12:17:39.450457+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Unauthenticated Cross Site Scripting (XSS) in ChatBot <= 8.3.2 versions.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260709T121832Z/items/CVE-2026-57362.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes XSS risk. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Unauthenticated Cross Site Scripting (XSS) in ChatBot <= 8.3.2 versions.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-57362/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-57366/",
      "current_public_safe_latest": false,
      "cvss_score": 7.1,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.08943,
      "epss_score": 0.00191,
      "first_observed_at": "2026-07-09T12:17:39.450457+00:00",
      "id": "CVE-2026-57366",
      "impact_tags": [
        "XSS risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-09T12:17:39.450457+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Unauthenticated Cross Site Scripting (XSS) in WPAdverts <= 2.3.1 versions.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260709T121832Z/items/CVE-2026-57366.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes XSS risk. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Unauthenticated Cross Site Scripting (XSS) in WPAdverts <= 2.3.1 versions.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-57366/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-57426/",
      "current_public_safe_latest": false,
      "cvss_score": 7.1,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.08947,
      "epss_score": 0.00191,
      "first_observed_at": "2026-07-09T12:17:39.450457+00:00",
      "id": "CVE-2026-57426",
      "impact_tags": [
        "XSS risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-09T12:17:39.450457+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Unauthenticated Cross Site Scripting (XSS) in Modula - PRO <= 2.10.8 versions.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260709T121832Z/items/CVE-2026-57426.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes XSS risk. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Unauthenticated Cross Site Scripting (XSS) in Modula - PRO <= 2.10.8 versions.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-57426/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "perl / perl",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-57432/",
      "current_public_safe_latest": false,
      "cvss_score": 8.4,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.09527,
      "epss_score": 0.00196,
      "first_observed_at": "2026-07-20T11:59:42.107493+00:00",
      "id": "CVE-2026-57432",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-20T11:59:42.107493+00:00",
      "latest_item_url": null,
      "product": "perl",
      "public_safe_summary": "NVD: Perl versions through 5.43.10 have an integer overflow in S_measure_struct leading to an out-of-bounds heap read in pack and unpack. NVD: S_measure_struct adds each item's size times its repeat count to a running total with no overflow check, so a large repeat count in a pack or unpack template wraps the signed SSize_t total negative. NVD: The @, X, and x position codes then guard their moves with a signed length comparison that passes when the length is negative, advancing the buffer pointer out of bounds.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260720T120206Z/items/CVE-2026-57432.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: perl / perl",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Perl versions through 5.43.10 have an integer overflow in S_measure_struct leading to an out-of-bounds heap read in pack and unpack. NVD: S_measure_struct adds each item's size times its repeat count to a running total with no overflow check, so a large repeat count in a pack or unpack template wraps the signed SSize_t total negative. NVD: The @, X, and x position codes then guard their moves with a signed length comparison that passes when the length is negative, advancing the buffer pointer out of bounds.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-57432/timeline.json",
      "vendor": "perl"
    },
    {
      "affected_label": "nwclark / storable",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-57433/",
      "current_public_safe_latest": false,
      "cvss_score": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.26717,
      "epss_score": 0.00345,
      "first_observed_at": "2026-07-20T11:59:42.107493+00:00",
      "id": "CVE-2026-57433",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-20T11:59:42.107493+00:00",
      "latest_item_url": null,
      "product": "storable",
      "public_safe_summary": "NVD: Storable versions before 3.41 for Perl have a signed integer overflow when deserializing a crafted SX_HOOK record. NVD: retrieve_hook_common reads a signed 32-bit item count from an SX_HOOK record and calls av_extend with that count plus one. NVD: A count of I32_MAX wraps the addition to a negative value.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260720T120206Z/items/CVE-2026-57433.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: nwclark / storable",
      "source_published_impact": "This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Storable versions before 3.41 for Perl have a signed integer overflow when deserializing a crafted SX_HOOK record. NVD: retrieve_hook_common reads a signed 32-bit item count from an SX_HOOK record and calls av_extend with that count plus one. NVD: A count of I32_MAX wraps the addition to a negative value.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-57433/timeline.json",
      "vendor": "nwclark"
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-57501/",
      "current_public_safe_latest": false,
      "cvss_score": 0.0,
      "cvss_severity": "NONE",
      "epss_percentile": 0.20916,
      "epss_score": 0.0029,
      "first_observed_at": "2026-07-16T22:18:24.817461+00:00",
      "id": "CVE-2026-57501",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-16T22:18:24.817461+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Zen is a firefox-based browser. NVD: Prior to 1.21.5b, Zen's glance and split-view context-menu actions, Open link in glance and Split link in new tab, load a page-controlled link URL with the System principal instead of the originating page's principal, allowing a malicious web page to place a... NVD: This issue is fixed in version 1.21.5b.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260716T222035Z/items/CVE-2026-57501.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This none severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: Zen is a firefox-based browser. NVD: Prior to 1.21.5b, Zen's glance and split-view context-menu actions, Open link in glance and Split link in new tab, load a page-controlled link URL with the System principal instead of the originating page's principal, allowing a malicious web page to place a... NVD: This issue is fixed in version 1.21.5b.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-57501/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-57530/",
      "current_public_safe_latest": false,
      "cvss_score": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.07579,
      "epss_score": 0.00178,
      "first_observed_at": "2026-07-31T16:59:34.622526+00:00",
      "id": "CVE-2026-57530",
      "impact_tags": [
        "XSS risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-31T16:59:34.622526+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Milkdown before 7.21.3 contains a stored cross-site scripting vulnerability in the @milkdown/preset-commonmark and @milkdown/components packages that allows attackers with document write access to execute arbitrary JavaScript in the browser context of any... NVD: The parseMarkdown runner stores raw URL values from the remark AST as href mark attributes without URL scheme validation, and the ineffective DOMPurify.sanitize call in edit-view.ts treats the bare URL string as a text node and returns it unchanged, allowing... OSV: Milkdown < 7.21.3 Stored XSS via javascript: URL in link href",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260731T171256Z/items/CVE-2026-57530.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes XSS risk. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Milkdown before 7.21.3 contains a stored cross-site scripting vulnerability in the @milkdown/preset-commonmark and @milkdown/components packages that allows attackers with document write access to execute arbitrary JavaScript in the browser context of any... NVD: The parseMarkdown runner stores raw URL values from the remark AST as href mark attributes without URL scheme validation, and the ineffective DOMPurify.sanitize call in edit-view.ts treats the bare URL string as a text node and returns it unchanged, allowing... OSV: Milkdown < 7.21.3 Stored XSS via javascript: URL in link href",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-57530/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-57599/",
      "current_public_safe_latest": false,
      "cvss_score": 6.6,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.11497,
      "epss_score": 0.00211,
      "first_observed_at": "2026-07-29T11:36:18.065267+00:00",
      "id": "CVE-2026-57599",
      "impact_tags": [
        "privilege boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-29T11:36:18.065267+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: There is a privilege escalation vulnerability in some Hikvision cameras. NVD: Due to incorrect permission allocation in the device program, attackers can escalate privileges and gain full control of the device after authenticating via SSH.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260729T114432Z/items/CVE-2026-57599.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes privilege escalation risk. Possible impact: An attacker may cross a privilege boundary and gain more access than intended.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: There is a privilege escalation vulnerability in some Hikvision cameras. NVD: Due to incorrect permission allocation in the device program, attackers can escalate privileges and gain full control of the device after authenticating via SSH.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-57599/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-57600/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.16297,
      "epss_score": 0.00248,
      "first_observed_at": "2026-07-29T11:36:18.065267+00:00",
      "id": "CVE-2026-57600",
      "impact_tags": [
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-29T11:36:18.065267+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Insufficient validation of input parameters in the firmware of some Hikvision cameras allows unauthenticated attackers to retrieve partial sensitive data.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260729T114432Z/items/CVE-2026-57600.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes remote exposure · authenticated boundary. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Insufficient validation of input parameters in the firmware of some Hikvision cameras allows unauthenticated attackers to retrieve partial sensitive data.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-57600/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-57621/",
      "current_public_safe_latest": false,
      "cvss_score": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.25582,
      "epss_score": 0.00336,
      "first_observed_at": "2026-07-09T12:17:39.450457+00:00",
      "id": "CVE-2026-57621",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-09T12:17:39.450457+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Unauthenticated PHP Object Injection in Booktics <= 1.0.21 versions.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260709T121832Z/items/CVE-2026-57621.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Unauthenticated PHP Object Injection in Booktics <= 1.0.21 versions.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-57621/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-57623/",
      "current_public_safe_latest": false,
      "cvss_score": 9.0,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.25161,
      "epss_score": 0.00332,
      "first_observed_at": "2026-07-09T12:17:39.450457+00:00",
      "id": "CVE-2026-57623",
      "impact_tags": [
        "code execution review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-09T12:17:39.450457+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Unauthenticated Arbitrary Code Execution in W3 Total Cache <= 2.9.4 versions.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260709T121832Z/items/CVE-2026-57623.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes code execution review. Possible impact: An attacker may be able to run code or commands on affected systems.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Unauthenticated Arbitrary Code Execution in W3 Total Cache <= 2.9.4 versions.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-57623/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-57624/",
      "current_public_safe_latest": false,
      "cvss_score": 10.0,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.48601,
      "epss_score": 0.00697,
      "first_observed_at": "2026-07-09T12:17:39.450457+00:00",
      "id": "CVE-2026-57624",
      "impact_tags": [
        "code execution review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-09T12:17:39.450457+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Unauthenticated Remote Code Execution (RCE) in Blocksy Companion Pro <= 2.1.46 versions.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260709T121832Z/items/CVE-2026-57624.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes code execution review. Possible impact: An attacker may be able to run code or commands on affected systems.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Unauthenticated Remote Code Execution (RCE) in Blocksy Companion Pro <= 2.1.46 versions.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-57624/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-57625/",
      "current_public_safe_latest": false,
      "cvss_score": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.1848,
      "epss_score": 0.00269,
      "first_observed_at": "2026-07-09T12:17:39.450457+00:00",
      "id": "CVE-2026-57625",
      "impact_tags": [
        "XSS risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-09T12:17:39.450457+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Unauthenticated Cross Site Scripting (XSS) in Admin and Site Enhancements (ASE) Pro <= 8.8.5 versions.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260709T121832Z/items/CVE-2026-57625.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes XSS risk. Possible impact: This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Unauthenticated Cross Site Scripting (XSS) in Admin and Site Enhancements (ASE) Pro <= 8.8.5 versions.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-57625/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "apache / fineract",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-57821/",
      "current_public_safe_latest": false,
      "cvss_score": 8.1,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.52287,
      "epss_score": 0.00791,
      "first_observed_at": "2026-07-22T06:07:21.492959+00:00",
      "id": "CVE-2026-57821",
      "impact_tags": [
        "service availability review",
        "SQL injection risk",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-22T06:07:21.492959+00:00",
      "latest_item_url": null,
      "product": "fineract",
      "public_safe_summary": "NVD: A SQL Injection vulnerability exists in Apache Fineract's Office Search API (GET /api/v1/offices) in versions up to and including 1.14.0. NVD: The orderBy request parameter is concatenated into a SQL query without sufficient validation, allowing an authenticated user with permission to view offices to inject arbitrary SQL via a crafted orderBy value. NVD: This is a bypass of the ColumnValidator fix introduced for CVE-2024-32838, which does not detect bare subqueries in the ORDER BY position.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260722T060931Z/items/CVE-2026-57821.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: apache / fineract",
      "source_published_impact": "Source describes service availability risk · SQL injection risk · authenticated boundary. Possible impact: An attacker may be able to read or change database-backed application data.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: a.",
      "source_published_summary": "NVD: A SQL Injection vulnerability exists in Apache Fineract's Office Search API (GET /api/v1/offices) in versions up to and including 1.14.0. NVD: The orderBy request parameter is concatenated into a SQL query without sufficient validation, allowing an authenticated user with permission to view offices to inject arbitrary SQL via a crafted orderBy value. NVD: This is a bypass of the ColumnValidator fix introduced for CVE-2024-32838, which does not detect bare subqueries in the ORDER BY position.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-57821/timeline.json",
      "vendor": "apache"
    },
    {
      "affected_label": "rsjoomla / rsfiles\\!",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-57827/",
      "current_public_safe_latest": false,
      "cvss_score": 10.0,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.25336,
      "epss_score": 0.00332,
      "first_observed_at": "2026-07-18T08:01:52.653915+00:00",
      "id": "CVE-2026-57827",
      "impact_tags": [
        "code execution review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-18T08:45:22.939860+00:00",
      "latest_item_url": null,
      "product": "rsfiles\\!",
      "public_safe_summary": "NVD: The Joomla extension RSFiles is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260718T084855Z/items/CVE-2026-57827.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "vendor/product: rsjoomla / rsfiles\\!",
      "source_published_impact": "Source describes code execution review. Possible impact: An attacker may be able to run code or commands on affected systems.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Joomla extension RSFiles is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-57827/timeline.json",
      "vendor": "rsjoomla"
    },
    {
      "affected_label": "phoca / download",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-57828/",
      "current_public_safe_latest": false,
      "cvss_score": 9.0,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.22429,
      "epss_score": 0.00305,
      "first_observed_at": "2026-07-18T08:01:52.653915+00:00",
      "id": "CVE-2026-57828",
      "impact_tags": [
        "code execution review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-18T08:45:22.939860+00:00",
      "latest_item_url": null,
      "product": "download",
      "public_safe_summary": "NVD: The Joomla extension Phoca Downloads is vulnerable to an authenticated arbitrary file upload that allows registered users uploading executable files and leads to full RCE.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260718T084855Z/items/CVE-2026-57828.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "vendor/product: phoca / download",
      "source_published_impact": "Source describes code execution review. Possible impact: An attacker may be able to run code or commands on affected systems.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Joomla extension Phoca Downloads is vulnerable to an authenticated arbitrary file upload that allows registered users uploading executable files and leads to full RCE.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-57828/timeline.json",
      "vendor": "phoca"
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-57831/",
      "current_public_safe_latest": false,
      "cvss_score": 8.7,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.14718,
      "epss_score": 0.00237,
      "first_observed_at": "2026-07-22T06:07:21.492959+00:00",
      "id": "CVE-2026-57831",
      "impact_tags": [
        "SQL injection risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-22T06:07:21.492959+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Joomla extension DP Calendar is vulnerable to an unauthenticated SQL injection.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260722T060931Z/items/CVE-2026-57831.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes SQL injection risk. Possible impact: An attacker may be able to read or change database-backed application data.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Joomla extension DP Calendar is vulnerable to an unauthenticated SQL injection.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-57831/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-57832/",
      "current_public_safe_latest": false,
      "cvss_score": 8.7,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.14719,
      "epss_score": 0.00237,
      "first_observed_at": "2026-07-22T06:07:21.492959+00:00",
      "id": "CVE-2026-57832",
      "impact_tags": [
        "SQL injection risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-22T06:07:21.492959+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Joomla extension EDocman is vulnerable to an unauthenticated SQL injection.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260722T060931Z/items/CVE-2026-57832.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes SQL injection risk. Possible impact: An attacker may be able to read or change database-backed application data.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Joomla extension EDocman is vulnerable to an unauthenticated SQL injection.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-57832/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-57833/",
      "current_public_safe_latest": false,
      "cvss_score": 8.6,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.33976,
      "epss_score": 0.00418,
      "first_observed_at": "2026-07-22T06:07:21.492959+00:00",
      "id": "CVE-2026-57833",
      "impact_tags": [
        "XSS risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-22T06:07:21.492959+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Joomla extension 4Analytics is vulnerable to an unauthenticated stored XSS in relation to the AI analysis feature.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260722T060931Z/items/CVE-2026-57833.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes XSS risk. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Joomla extension 4Analytics is vulnerable to an unauthenticated stored XSS in relation to the AI analysis feature.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-57833/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-57851/",
      "current_public_safe_latest": false,
      "cvss_score": 8.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.06598,
      "epss_score": 0.0017,
      "first_observed_at": "2026-07-14T16:41:04.043226+00:00",
      "id": "CVE-2026-57851",
      "impact_tags": [
        "privilege boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-14T16:41:04.043226+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: MSI Feature Manager contains a local privilege escalation vulnerability in the KernCoreLib64.sys kernel driver that allows any locally logged-on user to perform arbitrary physical memory read/write and unrestricted I/O port operations by accessing exposed... NVD: Attackers can exploit the accessible device object through IOCTL handlers to manipulate kernel objects, tamper with kernel-mode callbacks, bypass Protected Process Light protections, and disable security software.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260714T164406Z/items/CVE-2026-57851.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes privilege escalation risk. Possible impact: An attacker may cross a privilege boundary and gain more access than intended.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: MSI Feature Manager contains a local privilege escalation vulnerability in the KernCoreLib64.sys kernel driver that allows any locally logged-on user to perform arbitrary physical memory read/write and unrestricted I/O port operations by accessing exposed... NVD: Attackers can exploit the accessible device object through IOCTL handlers to manipulate kernel objects, tamper with kernel-mode callbacks, bypass Protected Process Light protections, and disable security software.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-57851/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-57867/",
      "current_public_safe_latest": false,
      "cvss_score": 8.8,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.26334,
      "epss_score": 0.00342,
      "first_observed_at": "2026-07-14T05:42:23.241208+00:00",
      "id": "CVE-2026-57867",
      "impact_tags": [
        "authentication boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-14T05:42:23.241208+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: MicroRealEstate allows adversaries to bypass authentication due to a lack of token state management. NVD: This would permit adversaries targeting MicroRealEstate deployments to brute-force One-Time Passwords (OTP) to log in as any user. NVD: This issue affects MicroRealEstate: through 1.0.0-alpha3.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260714T054512Z/items/CVE-2026-57867.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes authentication boundary review. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authentication boundary review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: MicroRealEstate allows adversaries to bypass authentication due to a lack of token state management. NVD: This would permit adversaries targeting MicroRealEstate deployments to brute-force One-Time Passwords (OTP) to log in as any user. NVD: This issue affects MicroRealEstate: through 1.0.0-alpha3.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-57867/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-57868/",
      "current_public_safe_latest": false,
      "cvss_score": 7.1,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.11892,
      "epss_score": 0.00215,
      "first_observed_at": "2026-07-14T05:42:23.241208+00:00",
      "id": "CVE-2026-57868",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-14T05:42:23.241208+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: MicroRealEstate is affected by broken object-level access controls in PDF generator functionality. NVD: This issue affects MicroRealEstate: through 1.0.0-alpha3.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260714T054512Z/items/CVE-2026-57868.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: MicroRealEstate is affected by broken object-level access controls in PDF generator functionality. NVD: This issue affects MicroRealEstate: through 1.0.0-alpha3.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-57868/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-57869/",
      "current_public_safe_latest": false,
      "cvss_score": 7.1,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.11893,
      "epss_score": 0.00215,
      "first_observed_at": "2026-07-14T05:42:23.241208+00:00",
      "id": "CVE-2026-57869",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-14T05:42:23.241208+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Broken object-level access controls and the use of a deterministic pattern during random ID generation in MicroRealEstate allows attackers to access documents uploaded by landlords or tenants without authorization. NVD: This issue affects MicroRealEstate: through 1.0.0-alpha3.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260714T054512Z/items/CVE-2026-57869.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Broken object-level access controls and the use of a deterministic pattern during random ID generation in MicroRealEstate allows attackers to access documents uploaded by landlords or tenants without authorization. NVD: This issue affects MicroRealEstate: through 1.0.0-alpha3.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-57869/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-57870/",
      "current_public_safe_latest": false,
      "cvss_score": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.1189,
      "epss_score": 0.00215,
      "first_observed_at": "2026-07-14T05:42:23.241208+00:00",
      "id": "CVE-2026-57870",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-14T05:42:23.241208+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Broken object-level access control on the Template API in MicroRealEstate allows attackers to retrieve document templates used by other organizations without authorization. NVD: This issue affects MicroRealEstate: through 1.0.0-alpha3.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260714T054512Z/items/CVE-2026-57870.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Broken object-level access control on the Template API in MicroRealEstate allows attackers to retrieve document templates used by other organizations without authorization. NVD: This issue affects MicroRealEstate: through 1.0.0-alpha3.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-57870/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-57871/",
      "current_public_safe_latest": false,
      "cvss_score": 7.1,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.2823,
      "epss_score": 0.00361,
      "first_observed_at": "2026-07-14T05:42:23.241208+00:00",
      "id": "CVE-2026-57871",
      "impact_tags": [
        "path traversal review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-14T05:42:23.241208+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Relative path traversal vulnerability in MicroRealEstate file upload functionality allows attackers to potentially overwrite system files. NVD: This issue affects MicroRealEstate: through 1.0.0-alpha3.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260714T054512Z/items/CVE-2026-57871.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes path traversal review. Possible impact: An attacker may be able to reach files outside the intended application path.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Relative path traversal vulnerability in MicroRealEstate file upload functionality allows attackers to potentially overwrite system files. NVD: This issue affects MicroRealEstate: through 1.0.0-alpha3.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-57871/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-57895/",
      "current_public_safe_latest": false,
      "cvss_score": 8.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.01494,
      "epss_score": 0.0011,
      "first_observed_at": "2026-07-15T05:43:30.245469+00:00",
      "id": "CVE-2026-57895",
      "impact_tags": [
        "code execution review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-15T05:43:30.245469+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Incorrect default permissions issue exists in Pupsman versions prior to 3.9.0. NVD: An attacker can place a malicious executable in the installation folder, which results in arbitrary code execution with SYSTEM privilege",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260715T054459Z/items/CVE-2026-57895.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes code execution review. Possible impact: An attacker may be able to run code or commands on affected systems.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Incorrect default permissions issue exists in Pupsman versions prior to 3.9.0. NVD: An attacker can place a malicious executable in the installation folder, which results in arbitrary code execution with SYSTEM privilege",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-57895/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-57978/",
      "current_public_safe_latest": false,
      "cvss_score": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.12185,
      "epss_score": 0.00216,
      "first_observed_at": "2026-08-01T10:51:40.555213+00:00",
      "id": "CVE-2026-57978",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-02T16:16:56.676027+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260802T162719Z/items/CVE-2026-57978.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 6,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-57978/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-57989/",
      "current_public_safe_latest": false,
      "cvss_score": 7.4,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.36081,
      "epss_score": 0.00439,
      "first_observed_at": "2026-08-01T10:51:40.555213+00:00",
      "id": "CVE-2026-57989",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-02T16:16:56.676027+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260802T162719Z/items/CVE-2026-57989.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 6,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-57989/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-5799/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.15798,
      "epss_score": 0.00246,
      "first_observed_at": "2026-07-14T05:42:23.241208+00:00",
      "id": "CVE-2026-5799",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-14T05:42:23.241208+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Authorization bypass through User-Controlled key vulnerability in Idvlabs Software and Consulting Services Inc. NVD: Ontime allows Exploitation of Trusted Identifiers. NVD: This issue affects Ontime: through 04052026.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260714T054512Z/items/CVE-2026-5799.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Authorization bypass through User-Controlled key vulnerability in Idvlabs Software and Consulting Services Inc. NVD: Ontime allows Exploitation of Trusted Identifiers. NVD: This issue affects Ontime: through 04052026.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-5799/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-57990/",
      "current_public_safe_latest": false,
      "cvss_score": 7.4,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.57567,
      "epss_score": 0.00943,
      "first_observed_at": "2026-08-01T10:51:40.555213+00:00",
      "id": "CVE-2026-57990",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-02T16:16:56.676027+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Files or directories accessible to external parties in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260802T162719Z/items/CVE-2026-57990.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 6,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Files or directories accessible to external parties in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-57990/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-57996/",
      "current_public_safe_latest": false,
      "cvss_score": 8.7,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.15879,
      "epss_score": 0.00246,
      "first_observed_at": "2026-07-22T11:51:23.239908+00:00",
      "id": "CVE-2026-57996",
      "impact_tags": [
        "privilege boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-22T11:51:23.239908+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: phpMyFAQ before 4.1.5 contains a privilege escalation vulnerability in the user/add API endpoint that allows non-SuperAdmin administrators to create SuperAdmin accounts. NVD: A delegated administrator with USER_ADD/EDIT/DELETE permissions can call POST /admin/api/user/add with isSuperAdmin: true and attacker-chosen credentials to create a SuperAdmin account, then authenticate as that account to achieve full instance takeover. OSV: phpMyFAQ - Privilege Escalation via Missing SuperAdmin Guard in user/add Endpoint",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260722T115421Z/items/CVE-2026-57996.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes privilege escalation risk. Possible impact: An attacker may cross a privilege boundary and gain more access than intended.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: phpMyFAQ before 4.1.5 contains a privilege escalation vulnerability in the user/add API endpoint that allows non-SuperAdmin administrators to create SuperAdmin accounts. NVD: A delegated administrator with USER_ADD/EDIT/DELETE permissions can call POST /admin/api/user/add with isSuperAdmin: true and attacker-chosen credentials to create a SuperAdmin account, then authenticate as that account to achieve full instance takeover. OSV: phpMyFAQ - Privilege Escalation via Missing SuperAdmin Guard in user/add Endpoint",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-57996/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "apache / apache-airflow-providers-git",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-58065/",
      "current_public_safe_latest": false,
      "cvss_score": 8.1,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.37088,
      "epss_score": 0.00461,
      "first_observed_at": "2026-07-20T11:59:42.107493+00:00",
      "id": "CVE-2026-58065",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-20T11:59:42.107493+00:00",
      "latest_item_url": null,
      "product": "apache-airflow-providers-git",
      "public_safe_summary": "NVD: The Apache Airflow Git provider runs its git-over-SSH operations with StrictHostKeyChecking=no by default, disabling SSH host-key verification. NVD: An attacker who can intercept the network path between an Airflow worker and the Git server can impersonate the server (man-in-the-middle), capturing the SSH deploy key or injecting malicious repository content. NVD: Deployments that use the Git DAG bundle or Git provider to clone over SSH with a deploy key are affected.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260720T120206Z/items/CVE-2026-58065.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: apache / apache-airflow-providers-git",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: apache-airflow-providers-git.",
      "source_published_summary": "NVD: The Apache Airflow Git provider runs its git-over-SSH operations with StrictHostKeyChecking=no by default, disabling SSH host-key verification. NVD: An attacker who can intercept the network path between an Airflow worker and the Git server can impersonate the server (man-in-the-middle), capturing the SSH deploy key or injecting malicious repository content. NVD: Deployments that use the Git DAG bundle or Git provider to clone over SSH with a deploy key are affected.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-58065/timeline.json",
      "vendor": "apache"
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-58077/",
      "current_public_safe_latest": false,
      "cvss_score": 8.7,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.33975,
      "epss_score": 0.00418,
      "first_observed_at": "2026-07-22T06:07:21.492959+00:00",
      "id": "CVE-2026-58077",
      "impact_tags": [
        "XSS risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-22T06:07:21.492959+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Joomla extension 4Analytics is vulnerable to an unauthenticated stored XSS. NVD: A specially crafted unauthenticated request may result in website takeover under some circumstances.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260722T060931Z/items/CVE-2026-58077.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes XSS risk. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Joomla extension 4Analytics is vulnerable to an unauthenticated stored XSS. NVD: A specially crafted unauthenticated request may result in website takeover under some circumstances.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-58077/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "eclipse / milo",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-58080/",
      "current_public_safe_latest": false,
      "cvss_score": 8.8,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.18869,
      "epss_score": 0.00269,
      "first_observed_at": "2026-08-11T10:14:04.199465+00:00",
      "id": "CVE-2026-58080",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-11T10:14:04.199465+00:00",
      "latest_item_url": null,
      "product": "milo",
      "public_safe_summary": "NVD: In Eclipse Milo versions 1.0.0 through 1.1.4, OpcUaServerConfig.copy() fails to preserve a configured RoleMapper. NVD: On servers that rely on role permissions and construct the running configuration through copy(), sessions receive no role IDs and the default access controller skips role-permission checks, allowing an anonymous client where anonymous sessions are permitted... OSV: In Eclipse Milo versions 1.0.0 through 1.1.4, OpcUaServerConfig.copy() fails to preserve a configured RoleMapper.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260811T102539Z/items/CVE-2026-58080.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: eclipse / milo",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: In Eclipse Milo versions 1.0.0 through 1.1.4, OpcUaServerConfig.copy() fails to preserve a configured RoleMapper. NVD: On servers that rely on role permissions and construct the running configuration through copy(), sessions receive no role IDs and the default access controller skips role-permission checks, allowing an anonymous client where anonymous sessions are permitted... OSV: In Eclipse Milo versions 1.0.0 through 1.1.4, OpcUaServerConfig.copy() fails to preserve a configured RoleMapper.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-58080/timeline.json",
      "vendor": "eclipse"
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-58225/",
      "current_public_safe_latest": false,
      "cvss_score": 2.1,
      "cvss_severity": "LOW",
      "epss_percentile": 0.05863,
      "epss_score": 0.00163,
      "first_observed_at": "2026-07-17T10:59:18.822206+00:00",
      "id": "CVE-2026-58225",
      "impact_tags": [
        "service availability review",
        "SQL injection risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-17T10:59:18.822206+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: SQL Injection vulnerability in elixir-ecto postgrex allows an attacker who can influence a LISTEN channel name to inject SQL into the reconnect replay query, causing a denial of service of the notification connection. NVD: Postgrex.Notifications sanitizes channel names with quote_channel/1, which doubles double quotes so the name is safe inside a double-quoted identifier. NVD: This protects the single-statement LISTEN and UNLISTEN paths.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260717T110142Z/items/CVE-2026-58225.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes service availability risk · SQL injection risk. Possible impact: An attacker may be able to read or change database-backed application data.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: SQL Injection vulnerability in elixir-ecto postgrex allows an attacker who can influence a LISTEN channel name to inject SQL into the reconnect replay query, causing a denial of service of the notification connection. NVD: Postgrex.Notifications sanitizes channel names with quote_channel/1, which doubles double quotes so the name is safe inside a double-quoted identifier. NVD: This protects the single-statement LISTEN and UNLISTEN paths.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-58225/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-58266/",
      "current_public_safe_latest": false,
      "cvss_score": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.0649,
      "epss_score": 0.00169,
      "first_observed_at": "2026-07-14T22:16:58.989760+00:00",
      "id": "CVE-2026-58266",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-14T22:16:58.989760+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Anki is a program for creating and reviewing flashcards. NVD: Prior to 25.09.4, Anki's webview-based pages communicate with the Rust backend using an internal localhost API, and user scripts included via iframes in the editor can access this API despite protections intended to block reviewer and editor scripts. NVD: A malicious imported card package with an embedded iframe can use exposed API methods such as getImageForOcclusion to read arbitrary files accessible to the Anki process and exfiltrate them over the network.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260714T222111Z/items/CVE-2026-58266.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: Anki is a program for creating and reviewing flashcards. NVD: Prior to 25.09.4, Anki's webview-based pages communicate with the Rust backend using an internal localhost API, and user scripts included via iframes in the editor can access this API despite protections intended to block reviewer and editor scripts. NVD: A malicious imported card package with an embedded iframe can use exposed API methods such as getImageForOcclusion to read arbitrary files accessible to the Anki process and exfiltrate them over the network.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-58266/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-58275/",
      "current_public_safe_latest": false,
      "cvss_score": 10.0,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.4853,
      "epss_score": 0.00673,
      "first_observed_at": "2026-07-30T22:30:38.166118+00:00",
      "id": "CVE-2026-58275",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-30T22:30:38.166118+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Missing authorization in Azure DNS allows an unauthorized attacker to elevate privileges over a network.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260730T224832Z/items/CVE-2026-58275.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Missing authorization in Azure DNS allows an unauthorized attacker to elevate privileges over a network.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-58275/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "microsoft / edge_chromium",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-58281/",
      "current_public_safe_latest": false,
      "cvss_score": 8.3,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.48653,
      "epss_score": 0.00689,
      "first_observed_at": "2026-07-18T16:13:43.366233+00:00",
      "id": "CVE-2026-58281",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-18T16:13:43.366233+00:00",
      "latest_item_url": null,
      "product": "edge_chromium",
      "public_safe_summary": "NVD: Deserialization of untrusted data in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260718T161545Z/items/CVE-2026-58281.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: microsoft / edge_chromium",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Deserialization of untrusted data in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-58281/timeline.json",
      "vendor": "microsoft"
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-58303/",
      "current_public_safe_latest": false,
      "cvss_score": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.01905,
      "epss_score": 0.00116,
      "first_observed_at": "2026-07-16T11:14:01.223847+00:00",
      "id": "CVE-2026-58303",
      "impact_tags": [
        "memory safety review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-16T11:14:01.223847+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Stack-based buffer overflow vulnerability in Samsung Open Source Escargot allows Overflow Buffers. NVD: This issue affects Escargot: before b30b63fc63b403907d8137da1c65aaa4521fe74e.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260716T111601Z/items/CVE-2026-58303.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes memory safety review. Possible impact: The affected component has memory-safety risk that may lead to crash, privilege, or code-execution impact depending on exposure.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Stack-based buffer overflow vulnerability in Samsung Open Source Escargot allows Overflow Buffers. NVD: This issue affects Escargot: before b30b63fc63b403907d8137da1c65aaa4521fe74e.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-58303/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-58304/",
      "current_public_safe_latest": false,
      "cvss_score": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.01282,
      "epss_score": 0.00105,
      "first_observed_at": "2026-07-16T11:14:01.223847+00:00",
      "id": "CVE-2026-58304",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-16T11:14:01.223847+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Out-of-bounds read, Out-of-bounds write vulnerability in Samsung Open Source Escargot allows Overflow Buffers. NVD: This issue affects Escargot: before 779f6bedf58f334dec64b0a51ebb724b4708b84a.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260716T111601Z/items/CVE-2026-58304.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Out-of-bounds read, Out-of-bounds write vulnerability in Samsung Open Source Escargot allows Overflow Buffers. NVD: This issue affects Escargot: before 779f6bedf58f334dec64b0a51ebb724b4708b84a.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-58304/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-58305/",
      "current_public_safe_latest": false,
      "cvss_score": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.01282,
      "epss_score": 0.00105,
      "first_observed_at": "2026-07-16T11:14:01.223847+00:00",
      "id": "CVE-2026-58305",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-16T11:14:01.223847+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Access of resource using incompatible type ('type confusion') vulnerability in Samsung Open Source Escargot allows Pointer Manipulation. NVD: This issue affects Escargot: before 779f6bedf58f334dec64b0a51ebb724b4708b84a.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260716T111601Z/items/CVE-2026-58305.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Access of resource using incompatible type ('type confusion') vulnerability in Samsung Open Source Escargot allows Pointer Manipulation. NVD: This issue affects Escargot: before 779f6bedf58f334dec64b0a51ebb724b4708b84a.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-58305/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-58306/",
      "current_public_safe_latest": false,
      "cvss_score": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.01905,
      "epss_score": 0.00116,
      "first_observed_at": "2026-07-16T11:14:01.223847+00:00",
      "id": "CVE-2026-58306",
      "impact_tags": [
        "memory safety review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-16T11:14:01.223847+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Heap-based buffer overflow vulnerability in Samsung Open Source Escargot allows Overflow Buffers. NVD: This issue affects Escargot: before ef525f337fafddecde77a3c426212a84bb20cb98.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260716T111601Z/items/CVE-2026-58306.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes memory safety review. Possible impact: The affected component has memory-safety risk that may lead to crash, privilege, or code-execution impact depending on exposure.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Heap-based buffer overflow vulnerability in Samsung Open Source Escargot allows Overflow Buffers. NVD: This issue affects Escargot: before ef525f337fafddecde77a3c426212a84bb20cb98.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-58306/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-58307/",
      "current_public_safe_latest": false,
      "cvss_score": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.01379,
      "epss_score": 0.00107,
      "first_observed_at": "2026-07-16T11:14:01.223847+00:00",
      "id": "CVE-2026-58307",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-16T11:14:01.223847+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Out-of-bounds read, Reachable assertion vulnerability in Samsung Open Source Escargot allows Overread Buffers, Input Data Manipulation. NVD: This issue affects Escargot: before 2dee22f5c7b8bf31cb7252d7731fae8c07f2842c.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260716T111601Z/items/CVE-2026-58307.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Out-of-bounds read, Reachable assertion vulnerability in Samsung Open Source Escargot allows Overread Buffers, Input Data Manipulation. NVD: This issue affects Escargot: before 2dee22f5c7b8bf31cb7252d7731fae8c07f2842c.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-58307/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-58315/",
      "current_public_safe_latest": false,
      "cvss_score": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.0115,
      "epss_score": 0.00102,
      "first_observed_at": "2026-07-14T05:42:23.241208+00:00",
      "id": "CVE-2026-58315",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-14T05:42:23.241208+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Cross-site request forgery vulnerability exists in SEIKO EPSON Web Config. NVD: If a user views a malicious page while logged into Web Config, unintended operations may be performed.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260714T054512Z/items/CVE-2026-58315.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Cross-site request forgery vulnerability exists in SEIKO EPSON Web Config. NVD: If a user views a malicious page while logged into Web Config, unintended operations may be performed.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-58315/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "gimp / gimp",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-58384/",
      "current_public_safe_latest": false,
      "cvss_score": 7.3,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.12375,
      "epss_score": 0.00219,
      "first_observed_at": "2026-07-14T05:42:23.241208+00:00",
      "id": "CVE-2026-58384",
      "impact_tags": [
        "code execution review",
        "service availability review",
        "memory safety review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-14T05:42:23.241208+00:00",
      "latest_item_url": null,
      "product": "gimp",
      "public_safe_summary": "NVD: A flaw was found in GIMP's PSD parser. NVD: An integer overflow in read_RLE_channel() can cause an undersized heap allocation for the RLE row-length table, after which subsequent per-row writes corrupt heap memory. NVD: This could lead to memory corruption, potentially resulting in denial of service or arbitrary code execution.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260714T054512Z/items/CVE-2026-58384.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: gimp / gimp; affected version context: 3.2.4, 9.0",
      "source_published_impact": "Source describes code execution review · service availability risk · memory safety review. Possible impact: An attacker may be able to run code or commands on affected systems.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A flaw was found in GIMP's PSD parser. NVD: An integer overflow in read_RLE_channel() can cause an undersized heap allocation for the RLE row-length table, after which subsequent per-row writes corrupt heap memory. NVD: This could lead to memory corruption, potentially resulting in denial of service or arbitrary code execution.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-58384/timeline.json",
      "vendor": "gimp"
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-58411/",
      "current_public_safe_latest": false,
      "cvss_score": 7.0,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.27032,
      "epss_score": 0.00347,
      "first_observed_at": "2026-07-20T22:16:32.807845+00:00",
      "id": "CVE-2026-58411",
      "impact_tags": [
        "privilege boundary review",
        "XSS risk",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-20T22:16:32.807845+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: ChurchCRM is an open-source church management system. NVD: Prior to version 7.4.0, Cross-Site Scripting (XSS) vulnerabilities were identified due to insufficient output encoding of user-controlled request parameter names and parameter values. NVD: The application reflects attacker-controlled input into JavaScript string contexts and HTML attribute contexts without proper sanitization or contextual output encoding.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260720T222315Z/items/CVE-2026-58411.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes privilege escalation risk · XSS risk · authenticated boundary. Possible impact: An attacker may cross a privilege boundary and gain more access than intended.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: ChurchCRM is an open-source church management system. NVD: Prior to version 7.4.0, Cross-Site Scripting (XSS) vulnerabilities were identified due to insufficient output encoding of user-controlled request parameter names and parameter values. NVD: The application reflects attacker-controlled input into JavaScript string contexts and HTML attribute contexts without proper sanitization or contextual output encoding.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-58411/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "gpsd_project / gpsd",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-58459/",
      "current_public_safe_latest": false,
      "cvss_score": 8.4,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.75691,
      "epss_score": 0.01775,
      "first_observed_at": "2026-07-16T16:44:59.414444+00:00",
      "id": "CVE-2026-58459",
      "impact_tags": [
        "command execution review",
        "command injection risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-16T16:44:59.414444+00:00",
      "latest_item_url": null,
      "product": "gpsd",
      "public_safe_summary": "NVD: gpsd through release-3.27.5, fixed at commit 4c06658, contains a command injection vulnerability in gpsprof that allows attackers who control the GPS device subtype value to execute arbitrary shell commands by embedding backtick payloads in the gnuplot plot... NVD: The subtype field sourced from a DEVICES JSON log entry or NMEA PGRMT sentence is written into a generated gnuplot program via a set title statement with only double-quote characters escaped, enabling arbitrary shell command execution as the user running... OSV: gpsd gpsprof Command Injection via gnuplot plot title subtype field",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260716T164706Z/items/CVE-2026-58459.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: gpsd_project / gpsd",
      "source_published_impact": "Source describes command execution risk · command injection risk. Possible impact: An attacker may be able to run code or commands on affected systems.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: gpsd through release-3.27.5, fixed at commit 4c06658, contains a command injection vulnerability in gpsprof that allows attackers who control the GPS device subtype value to execute arbitrary shell commands by embedding backtick payloads in the gnuplot plot... NVD: The subtype field sourced from a DEVICES JSON log entry or NMEA PGRMT sentence is written into a generated gnuplot program via a set title statement with only double-quote characters escaped, enabling arbitrary shell command execution as the user running... OSV: gpsd gpsprof Command Injection via gnuplot plot title subtype field",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-58459/timeline.json",
      "vendor": "gpsd_project"
    },
    {
      "affected_label": "microsoft / edge_chromium",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-58596/",
      "current_public_safe_latest": false,
      "cvss_score": 8.3,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.36455,
      "epss_score": 0.00451,
      "first_observed_at": "2026-07-19T16:14:19.593713+00:00",
      "id": "CVE-2026-58596",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-19T16:14:19.593713+00:00",
      "latest_item_url": null,
      "product": "edge_chromium",
      "public_safe_summary": "NVD: Untrusted pointer dereference in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges over a network.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260719T161618Z/items/CVE-2026-58596.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: microsoft / edge_chromium",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Untrusted pointer dereference in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges over a network.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-58596/timeline.json",
      "vendor": "microsoft"
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-58655/",
      "current_public_safe_latest": false,
      "cvss_score": 8.7,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.61578,
      "epss_score": 0.01084,
      "first_observed_at": "2026-07-22T11:51:23.239908+00:00",
      "id": "CVE-2026-58655",
      "impact_tags": [
        "command execution review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-22T11:51:23.239908+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The bundled Grav Flex Objects plugin (getgrav/grav-plugin-flex-objects) before 1.4.0 contains a stored server-side template injection vulnerability. NVD: When rendering dynamic collection or object titles, the plugin passes user-controlled frontmatter values (page.header.flex.collection.title or page.header.flex.object.title) to Twig's template_from_string(), causing them to be evaluated as Twig code rather... NVD: This path bypasses Grav's Security::cleanDangerousTwig() sanitization.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260722T115421Z/items/CVE-2026-58655.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes command execution risk. Possible impact: An attacker may be able to run code or commands on affected systems.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The bundled Grav Flex Objects plugin (getgrav/grav-plugin-flex-objects) before 1.4.0 contains a stored server-side template injection vulnerability. NVD: When rendering dynamic collection or object titles, the plugin passes user-controlled frontmatter values (page.header.flex.collection.title or page.header.flex.object.title) to Twig's template_from_string(), causing them to be evaluated as Twig code rather... NVD: This path bypasses Grav's Security::cleanDangerousTwig() sanitization.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-58655/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-59153/",
      "current_public_safe_latest": false,
      "cvss_score": 2.1,
      "cvss_severity": "LOW",
      "epss_percentile": 0.07841,
      "epss_score": 0.00181,
      "first_observed_at": "2026-07-14T22:16:58.989760+00:00",
      "id": "CVE-2026-59153",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-14T22:16:58.989760+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Anki is a program for creating and reviewing flashcards. NVD: Prior to 25.09.3, Anki launches a local HTTP server to serve media files and web pages for parts of its interface, but requests from other origins were not sufficiently blocked. NVD: A malicious website could potentially trigger side-effecting requests to the local server, with severity varying by browser depending on Private Network Access protections.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260714T222111Z/items/CVE-2026-59153.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: Anki is a program for creating and reviewing flashcards. NVD: Prior to 25.09.3, Anki launches a local HTTP server to serve media files and web pages for parts of its interface, but requests from other origins were not sufficiently blocked. NVD: A malicious website could potentially trigger side-effecting requests to the local server, with severity varying by browser depending on Private Network Access protections.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-59153/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-59173/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.37032,
      "epss_score": 0.00455,
      "first_observed_at": "2026-07-25T10:46:49.898242+00:00",
      "id": "CVE-2026-59173",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-25T10:46:49.898242+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Uncontrolled Resource Consumption vulnerability in Apache Traffic Server. NVD: This issue affects Apache Traffic Server: from 9.0.0 through 9.1.13, from 10.0.0 through 10.1.2. NVD: Users are recommended to upgrade to version 9.1.14 or 10.1.3, which fixes the issue.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260725T104916Z/items/CVE-2026-59173.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: Uncontrolled Resource Consumption vulnerability in Apache Traffic Server. NVD: This issue affects Apache Traffic Server: from 9.0.0 through 9.1.13, from 10.0.0 through 10.1.2. NVD: Users are recommended to upgrade to version 9.1.14 or 10.1.3, which fixes the issue.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-59173/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-59231/",
      "current_public_safe_latest": false,
      "cvss_score": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.17428,
      "epss_score": 0.00259,
      "first_observed_at": "2026-08-07T16:11:58.676122+00:00",
      "id": "CVE-2026-59231",
      "impact_tags": [
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-07T16:11:58.676122+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Server-Side Request Forgery in the PDF export component in maalfer Pentestify before 1.1.0 allows authenticated users to cause outbound HTTP GET requests from the server to arbitrary attacker-chosen destinations via unvalidated URLs stored in the finding... OSV: Server-Side Request Forgery in Pentestify PDF export via unvalidated image URLs OSV: Server-Side Request Forgery in the PDF export component in maalfer Pentestify before 1.1.0 allows authenticated users to cause outbound HTTP GET requests from the server to arbitrary attacker-chosen destinations via unvalidated URLs stored in the finding...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260807T162046Z/items/CVE-2026-59231.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Server-Side Request Forgery in the PDF export component in maalfer Pentestify before 1.1.0 allows authenticated users to cause outbound HTTP GET requests from the server to arbitrary attacker-chosen destinations via unvalidated URLs stored in the finding... OSV: Server-Side Request Forgery in Pentestify PDF export via unvalidated image URLs OSV: Server-Side Request Forgery in the PDF export component in maalfer Pentestify before 1.1.0 allows authenticated users to cause outbound HTTP GET requests from the server to arbitrary attacker-chosen destinations via unvalidated URLs stored in the finding...",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-59231/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-59232/",
      "current_public_safe_latest": false,
      "cvss_score": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.22775,
      "epss_score": 0.00305,
      "first_observed_at": "2026-08-07T16:11:58.676122+00:00",
      "id": "CVE-2026-59232",
      "impact_tags": [
        "XSS risk",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-07T16:11:58.676122+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Cross-site Scripting in the lead index view in Roskus Prospero Flow CRM before 5.3.7 allows authenticated users holding the create or update lead permission to execute arbitrary JavaScript in the application origin via HTML markup stored in the lead name... OSV: Stored Cross-site Scripting in Prospero Flow CRM lead name field OSV: Cross-site Scripting in the lead index view in Roskus Prospero Flow CRM before 5.3.7 allows authenticated users holding the create or update lead permission to execute arbitrary JavaScript in the application origin via HTML markup stored in the lead name...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260807T162046Z/items/CVE-2026-59232.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes XSS risk · authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Cross-site Scripting in the lead index view in Roskus Prospero Flow CRM before 5.3.7 allows authenticated users holding the create or update lead permission to execute arbitrary JavaScript in the application origin via HTML markup stored in the lead name... OSV: Stored Cross-site Scripting in Prospero Flow CRM lead name field OSV: Cross-site Scripting in the lead index view in Roskus Prospero Flow CRM before 5.3.7 allows authenticated users holding the create or update lead permission to execute arbitrary JavaScript in the application origin via HTML markup stored in the lead name...",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-59232/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-59234/",
      "current_public_safe_latest": false,
      "cvss_score": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.32343,
      "epss_score": 0.00403,
      "first_observed_at": "2026-07-10T12:09:55.374028+00:00",
      "id": "CVE-2026-59234",
      "impact_tags": [
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-10T12:09:55.374028+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Authorization Bypass Through User-Controlled Key (CWE-639) in CalendarDeleteEventController (app/Http/Controllers/Calendar/CalendarDeleteEventController.php), exposed at GET /calendar/event/delete/{id}, in Prospero Flow CRM before 5.5.3 allows a remote... NVD: This results in unauthorized destruction of other users' calendar events across the platform. OSV: Authorization Bypass Through User-Controlled Key in Prospero Flow CRM calendar event deletion",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260710T121119Z/items/CVE-2026-59234.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Authorization Bypass Through User-Controlled Key (CWE-639) in CalendarDeleteEventController (app/Http/Controllers/Calendar/CalendarDeleteEventController.php), exposed at GET /calendar/event/delete/{id}, in Prospero Flow CRM before 5.5.3 allows a remote... NVD: This results in unauthorized destruction of other users' calendar events across the platform. OSV: Authorization Bypass Through User-Controlled Key in Prospero Flow CRM calendar event deletion",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-59234/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-59235/",
      "current_public_safe_latest": false,
      "cvss_score": 8.7,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.33579,
      "epss_score": 0.00413,
      "first_observed_at": "2026-07-22T06:07:21.492959+00:00",
      "id": "CVE-2026-59235",
      "impact_tags": [
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-22T06:07:21.492959+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Missing Authorization (CWE-862) in BankAccountListController (app/Http/Controllers/Api/BankAccount/BankAccountListController.php), exposed at GET /api/bank-account, in Prospero Flow CRM <5.5.3, which allows a remote, authenticated attacker holding a... NVD: the \"User\"/\"Usuario\" role) to read arbitrary bank account records belonging to their company by sending an authenticated request to the endpoint with a valid bearer token, because the API route is protected only by the auth:api middleware and carries no... NVD: This results in the unauthorized disclosure of sensitive banking information (e.g.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260722T060931Z/items/CVE-2026-59235.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes authenticated boundary. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Missing Authorization (CWE-862) in BankAccountListController (app/Http/Controllers/Api/BankAccount/BankAccountListController.php), exposed at GET /api/bank-account, in Prospero Flow CRM <5.5.3, which allows a remote, authenticated attacker holding a... NVD: the \"User\"/\"Usuario\" role) to read arbitrary bank account records belonging to their company by sending an authenticated request to the endpoint with a valid bearer token, because the API route is protected only by the auth:api middleware and carries no... NVD: This results in the unauthorized disclosure of sensitive banking information (e.g.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-59235/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-59236/",
      "current_public_safe_latest": false,
      "cvss_score": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.37736,
      "epss_score": 0.0047,
      "first_observed_at": "2026-07-22T11:51:23.239908+00:00",
      "id": "CVE-2026-59236",
      "impact_tags": [
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-22T11:51:23.239908+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Authorization Bypass Through User-Controlled Key (CWE-639) in the Excel import handlers (CustomerImport, LeadImport, ProductImport) in Roskus Prospero Flow CRM before 5.14.0 allows a remote, authenticated user of any role or company to create customer, lead... OSV: Authorization bypass in Prospero Flow CRM Excel import allows cross-tenant record injection OSV: Authorization Bypass Through User-Controlled Key (CWE-639) in the Excel import handlers (CustomerImport, LeadImport, ProductImport) in Roskus Prospero Flow CRM before 5.14.0 allows a remote, authenticated user of any role or company to create customer, lead...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260722T115421Z/items/CVE-2026-59236.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Authorization Bypass Through User-Controlled Key (CWE-639) in the Excel import handlers (CustomerImport, LeadImport, ProductImport) in Roskus Prospero Flow CRM before 5.14.0 allows a remote, authenticated user of any role or company to create customer, lead... OSV: Authorization bypass in Prospero Flow CRM Excel import allows cross-tenant record injection OSV: Authorization Bypass Through User-Controlled Key (CWE-639) in the Excel import handlers (CustomerImport, LeadImport, ProductImport) in Roskus Prospero Flow CRM before 5.14.0 allows a remote, authenticated user of any role or company to create customer, lead...",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-59236/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-59239/",
      "current_public_safe_latest": false,
      "cvss_score": 8.6,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.31089,
      "epss_score": 0.00383,
      "first_observed_at": "2026-08-03T17:21:47.396014+00:00",
      "id": "CVE-2026-59239",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-03T17:21:47.396014+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: $email->body !!} when the recipient opens the message. OSV: Stored XSS in Prospero Flow CRM email body allows administrator account takeover OSV: $email->body !!} when the recipient opens the message.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260803T174717Z/items/CVE-2026-59239.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: $email->body !!} when the recipient opens the message. OSV: Stored XSS in Prospero Flow CRM email body allows administrator account takeover OSV: $email->body !!} when the recipient opens the message.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-59239/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "apache / apache-airflow-providers-fab",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-59245/",
      "current_public_safe_latest": false,
      "cvss_score": 8.1,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.28238,
      "epss_score": 0.0036,
      "first_observed_at": "2026-07-20T11:59:42.107493+00:00",
      "id": "CVE-2026-59245",
      "impact_tags": [
        "privilege boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-20T11:59:42.107493+00:00",
      "latest_item_url": null,
      "product": "apache-airflow-providers-fab",
      "public_safe_summary": "NVD: In the Apache Airflow FAB auth manager, a DAG whose dag_id is DAGs collided with the global all-DAGs permission resource name produced by resource_name(), so a user granted per-DAG access_control on that one DAG was silently granted the global all-DAGs... NVD: The escalation triggers when a DAG named DAGs exists and a lower-privileged user is given per-DAG access to it, granting that user read/edit access to every DAG. NVD: Users are advised to upgrade to apache-airflow-providers-fab 3.7.2 or later, which disambiguates the resource-name collision.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260720T120206Z/items/CVE-2026-59245.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: apache / apache-airflow-providers-fab",
      "source_published_impact": "Source describes privilege escalation risk. Possible impact: An attacker may cross a privilege boundary and gain more access than intended.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: In the Apache Airflow FAB auth manager, a DAG whose dag_id is DAGs collided with the global all-DAGs permission resource name produced by resource_name(), so a user granted per-DAG access_control on that one DAG was silently granted the global all-DAGs... NVD: The escalation triggers when a DAG named DAGs exists and a lower-privileged user is given per-DAG access to it, granting that user read/edit access to every DAG. NVD: Users are advised to upgrade to apache-airflow-providers-fab 3.7.2 or later, which disambiguates the resource-name collision.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-59245/timeline.json",
      "vendor": "apache"
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-59249/",
      "current_public_safe_latest": false,
      "cvss_score": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.22281,
      "epss_score": 0.00301,
      "first_observed_at": "2026-07-23T11:21:51.498947+00:00",
      "id": "CVE-2026-59249",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-23T11:21:51.498947+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Inconsistent interpretation of HTTP requests (HTTP response smuggling) vulnerability in elixir-mint mint allows a malicious HTTP/1 server to desynchronize a strict intermediary and the Mint client on the same pooled connection, enabling response-queue... NVD: The Mint.HTTP1.decode_body/5 function in lib/mint/http1.ex parses the chunk-size line of a Transfer-Encoding: chunked response with Integer.parse(data, 16). NVD: RFC 7230 defines chunk-size = 1*HEXDIG and forbids any sign prefix, but Integer.parse/2 accepts an optional leading + or -.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260723T112431Z/items/CVE-2026-59249.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Inconsistent interpretation of HTTP requests (HTTP response smuggling) vulnerability in elixir-mint mint allows a malicious HTTP/1 server to desynchronize a strict intermediary and the Mint client on the same pooled connection, enabling response-queue... NVD: The Mint.HTTP1.decode_body/5 function in lib/mint/http1.ex parses the chunk-size line of a Transfer-Encoding: chunked response with Integer.parse(data, 16). NVD: RFC 7230 defines chunk-size = 1*HEXDIG and forbids any sign prefix, but Integer.parse/2 accepts an optional leading + or -.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-59249/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-59252/",
      "current_public_safe_latest": false,
      "cvss_score": 8.2,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.28729,
      "epss_score": 0.00362,
      "first_observed_at": "2026-07-24T06:06:41.160911+00:00",
      "id": "CVE-2026-59252",
      "impact_tags": [
        "service availability review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-24T11:14:35.780564+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Improper Validation of Specified Quantity in Input in ZenHive mpp allows an unauthenticated remote client to drain the fee-payer wallet, resulting in denial of service for legitimate clients. NVD: When the mpp Elixir library is configured as fee payer (fee_payer: true), the MPP.Methods.Tempo payment method co-signs and broadcasts a client-supplied EVM transaction without first validating that the client-supplied gas_limit is sufficient to complete the... NVD: A malicious client can submit a signed transferWithMemo transaction with gas_limit deliberately set just below the amount required for successful execution.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260724T111724Z/items/CVE-2026-59252.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes service availability risk. Possible impact: The affected service may become unavailable or unreliable.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Improper Validation of Specified Quantity in Input in ZenHive mpp allows an unauthenticated remote client to drain the fee-payer wallet, resulting in denial of service for legitimate clients. NVD: When the mpp Elixir library is configured as fee payer (fee_payer: true), the MPP.Methods.Tempo payment method co-signs and broadcasts a client-supplied EVM transaction without first validating that the client-supplied gas_limit is sufficient to complete the... NVD: A malicious client can submit a signed transferWithMemo transaction with gas_limit deliberately set just below the amount required for successful execution.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-59252/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-59254/",
      "current_public_safe_latest": false,
      "cvss_score": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.18157,
      "epss_score": 0.00265,
      "first_observed_at": "2026-07-22T11:51:23.239908+00:00",
      "id": "CVE-2026-59254",
      "impact_tags": [
        "information exposure review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-22T11:51:23.239908+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: n8n before 2.28.1 contains an information disclosure vulnerability where external secrets are incorrectly resolved in workflow node expressions outside credentials scope. NVD: Authenticated project editors can read plaintext external secret values by referencing them in node expressions without requiring explicit secrets access permissions. OSV: n8n - External Secrets Disclosure via Workflow Node Expressions",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260722T115421Z/items/CVE-2026-59254.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes information exposure review. Possible impact: An attacker may be able to access information that should not be exposed.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: n8n before 2.28.1 contains an information disclosure vulnerability where external secrets are incorrectly resolved in workflow node expressions outside credentials scope. NVD: Authenticated project editors can read plaintext external secret values by referencing them in node expressions without requiring explicit secrets access permissions. OSV: n8n - External Secrets Disclosure via Workflow Node Expressions",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-59254/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "n8n / n8n",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-59259/",
      "current_public_safe_latest": false,
      "cvss_score": 6.0,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.23645,
      "epss_score": 0.00315,
      "first_observed_at": "2026-07-22T11:51:23.239908+00:00",
      "id": "CVE-2026-59259",
      "impact_tags": [
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-22T11:51:23.239908+00:00",
      "latest_item_url": null,
      "product": "n8n",
      "public_safe_summary": "NVD: n8n before versions 1.123.61, 2.27.4, and 2.28.1 contains a permission bypass vulnerability in external secrets handling caused by a mismatch between the static validation check and the runtime expression engine. NVD: An authenticated user with credential create or update permissions but without the externalSecret:list scope can embed external secret references into credentials in forms the static validation does not detect; these references resolve at workflow execution... NVD: This issue only affects instances where an external secrets provider is configured and Advanced Permissions are in use.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260722T115421Z/items/CVE-2026-59259.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: n8n / n8n; affected version context: 2.28.0",
      "source_published_impact": "Source describes authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: n8n before versions 1.123.61, 2.27.4, and 2.28.1 contains a permission bypass vulnerability in external secrets handling caused by a mismatch between the static validation check and the runtime expression engine. NVD: An authenticated user with credential create or update permissions but without the externalSecret:list scope can embed external secret references into credentials in forms the static validation does not detect; these references resolve at workflow execution... NVD: This issue only affects instances where an external secrets provider is configured and Advanced Permissions are in use.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-59259/timeline.json",
      "vendor": "n8n"
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-59260/",
      "current_public_safe_latest": false,
      "cvss_score": 8.7,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.49543,
      "epss_score": 0.00714,
      "first_observed_at": "2026-07-19T10:46:12.896763+00:00",
      "id": "CVE-2026-59260",
      "impact_tags": [
        "command execution review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-19T10:46:12.896763+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: OpenWrt luci-app-samba4 read ACL grants file.exec permission on /usr/sbin/smbd, allowing authenticated delegated users to execute the Samba daemon with caller-controlled command-line arguments. NVD: Attackers can pass arbitrary Samba global options such as message command to a root smbd process, triggering command execution when SMB protocol messages are processed.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260719T105023Z/items/CVE-2026-59260.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes command execution risk. Possible impact: An attacker may be able to run code or commands on affected systems.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: OpenWrt luci-app-samba4 read ACL grants file.exec permission on /usr/sbin/smbd, allowing authenticated delegated users to execute the Samba daemon with caller-controlled command-line arguments. NVD: Attackers can pass arbitrary Samba global options such as message command to a root smbd process, triggering command execution when SMB protocol messages are processed.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-59260/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "openclaw / openclaw",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-59261/",
      "current_public_safe_latest": false,
      "cvss_score": 8.4,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.09062,
      "epss_score": 0.00192,
      "first_observed_at": "2026-07-15T16:47:57.605966+00:00",
      "id": "CVE-2026-59261",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-15T16:47:57.605966+00:00",
      "latest_item_url": null,
      "product": "openclaw",
      "public_safe_summary": "NVD: OpenClaw before 2026.5.28 contains a credential exposure vulnerability where workspace dotenv files can override provider credentials. NVD: Attackers with lower-trust access to configured input paths can expose sensitive data and credentials that should remain within trusted boundaries. OSV: OpenClaw < 2026.5.28 - Credential Override via Workspace Dotenv Files",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260715T164957Z/items/CVE-2026-59261.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: openclaw / openclaw",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: OpenClaw before 2026.5.28 contains a credential exposure vulnerability where workspace dotenv files can override provider credentials. NVD: Attackers with lower-trust access to configured input paths can expose sensitive data and credentials that should remain within trusted boundaries. OSV: OpenClaw < 2026.5.28 - Credential Override via Workspace Dotenv Files",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-59261/timeline.json",
      "vendor": "openclaw"
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-59309/",
      "current_public_safe_latest": false,
      "cvss_score": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.5123,
      "epss_score": 0.00744,
      "first_observed_at": "2026-08-06T11:35:20.545945+00:00",
      "id": "CVE-2026-59309",
      "impact_tags": [
        "unauthorized access risk",
        "authentication boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-06T11:35:20.545945+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: VMware vCenter contains an authentication bypass vulnerability in the VMware Directory Service. NVD: A malicious actor with network access to vCenter may exploit this issue to bypass authentication and gain unauthorized access to the system.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260806T114533Z/items/CVE-2026-59309.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes unauthorized access risk · authentication boundary review. Possible impact: An attacker may access resources that should require stronger authorization.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: VMware vCenter contains an authentication bypass vulnerability in the VMware Directory Service. NVD: A malicious actor with network access to vCenter may exploit this issue to bypass authentication and gain unauthorized access to the system.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-59309/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-59310/",
      "current_public_safe_latest": false,
      "cvss_score": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.63502,
      "epss_score": 0.0114,
      "first_observed_at": "2026-08-06T11:35:20.545945+00:00",
      "id": "CVE-2026-59310",
      "impact_tags": [
        "code execution review",
        "path traversal review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-06T11:35:20.545945+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: VMware vCenter contains a directory traversal vulnerability in the Syslog server. NVD: A malicious actor with network access to vCenter may exploit this issue to execute arbitrary code.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260806T114533Z/items/CVE-2026-59310.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes code execution review · path traversal review. Possible impact: An attacker may be able to run code or commands on affected systems.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: VMware vCenter contains a directory traversal vulnerability in the Syslog server. NVD: A malicious actor with network access to vCenter may exploit this issue to execute arbitrary code.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-59310/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-59509/",
      "current_public_safe_latest": false,
      "cvss_score": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.27053,
      "epss_score": 0.00349,
      "first_observed_at": "2026-07-12T10:46:01.700382+00:00",
      "id": "CVE-2026-59509",
      "impact_tags": [
        "remote exposure relevant"
      ],
      "kev": false,
      "last_observed_at": "2026-07-12T10:46:01.700382+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: An unauthenticated improper input validation vulnerability in the POST /fetch_cve_data endpoint in cve-search. NVD: A remote attacker can manipulate request parameters controlling the MongoDB collection, projected fields, and regular-expression filters to read arbitrary application MongoDB collections. NVD: This can expose administrative usernames and password hashes from the mgmt_users collection, enabling offline password cracking and potential administrative account compromise.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260712T104758Z/items/CVE-2026-59509.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes remote exposure. Possible impact: This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: An unauthenticated improper input validation vulnerability in the POST /fetch_cve_data endpoint in cve-search. NVD: A remote attacker can manipulate request parameters controlling the MongoDB collection, projected fields, and regular-expression filters to read arbitrary application MongoDB collections. NVD: This can expose administrative usernames and password hashes from the mgmt_users collection, enabling offline password cracking and potential administrative account compromise.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-59509/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-59510/",
      "current_public_safe_latest": false,
      "cvss_score": 7.1,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.29334,
      "epss_score": 0.00372,
      "first_observed_at": "2026-07-12T16:15:44.451858+00:00",
      "id": "CVE-2026-59510",
      "impact_tags": [
        "path traversal review",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-12T16:15:44.451858+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: AIL Framework contains a path traversal vulnerability in its PDF object handling. NVD: Prior to commit 14c618fce4d1df02358717c48ea903706abecdf2, the PDF.get_filepath() function constructed a file path by joining the configured PDF storage directory with a path derived from a PDF object identifier, without verifying that the resolved path... NVD: An authenticated attacker able to invoke PDF object operations with a crafted identifier could use relative traversal sequences or absolute path components to cause AIL Framework to open files located outside the PDF storage directory.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260712T161649Z/items/CVE-2026-59510.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes path traversal review · authenticated boundary. Possible impact: An attacker may be able to reach files outside the intended application path.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: AIL Framework contains a path traversal vulnerability in its PDF object handling. NVD: Prior to commit 14c618fce4d1df02358717c48ea903706abecdf2, the PDF.get_filepath() function constructed a file path by joining the configured PDF storage directory with a path derived from a PDF object identifier, without verifying that the resolved path... NVD: An authenticated attacker able to invoke PDF object operations with a crafted identifier could use relative traversal sequences or absolute path components to cause AIL Framework to open files located outside the PDF storage directory.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-59510/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-59511/",
      "current_public_safe_latest": false,
      "cvss_score": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.10144,
      "epss_score": 0.00201,
      "first_observed_at": "2026-07-12T16:15:44.451858+00:00",
      "id": "CVE-2026-59511",
      "impact_tags": [
        "information exposure review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-12T22:10:37.281882+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Insertion of Sensitive Information Into Sent Data vulnerability in Tim Strifler Exclusive Addons Elementor allows Retrieve Embedded Sensitive Data. NVD: This issue affects Exclusive Addons Elementor: from n/a through 2.7.9.9.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260712T221257Z/items/CVE-2026-59511.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes information exposure review. Possible impact: An attacker may be able to access information that should not be exposed.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Insertion of Sensitive Information Into Sent Data vulnerability in Tim Strifler Exclusive Addons Elementor allows Retrieve Embedded Sensitive Data. NVD: This issue affects Exclusive Addons Elementor: from n/a through 2.7.9.9.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-59511/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-59519/",
      "current_public_safe_latest": false,
      "cvss_score": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.10145,
      "epss_score": 0.00201,
      "first_observed_at": "2026-07-12T16:15:44.451858+00:00",
      "id": "CVE-2026-59519",
      "impact_tags": [
        "information exposure review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-12T22:10:37.281882+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Insertion of Sensitive Information Into Sent Data vulnerability in Softaculous FormLayer allows Retrieve Embedded Sensitive Data. NVD: This issue affects FormLayer: from n/a through 1.0.6.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260712T221257Z/items/CVE-2026-59519.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes information exposure review. Possible impact: An attacker may be able to access information that should not be exposed.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Insertion of Sensitive Information Into Sent Data vulnerability in Softaculous FormLayer allows Retrieve Embedded Sensitive Data. NVD: This issue affects FormLayer: from n/a through 1.0.6.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-59519/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-59520/",
      "current_public_safe_latest": false,
      "cvss_score": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.01038,
      "epss_score": 0.001,
      "first_observed_at": "2026-07-12T16:15:44.451858+00:00",
      "id": "CVE-2026-59520",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-12T22:10:37.281882+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Cross-Site Request Forgery (CSRF) vulnerability in properfraction CrawlWP SEO allows Cross Site Request Forgery. NVD: This issue affects CrawlWP SEO: from n/a through 3.0.16.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260712T221257Z/items/CVE-2026-59520.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Cross-Site Request Forgery (CSRF) vulnerability in properfraction CrawlWP SEO allows Cross Site Request Forgery. NVD: This issue affects CrawlWP SEO: from n/a through 3.0.16.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-59520/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-59638/",
      "current_public_safe_latest": false,
      "cvss_score": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.19771,
      "epss_score": 0.00276,
      "first_observed_at": "2026-08-09T15:51:11.168346+00:00",
      "id": "CVE-2026-59638",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-09T21:51:57.260007+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: In Bouncy Castle for Java before 1.85, JSSE hostname verifier CN-fallback enabled by default despite documented opt-in. NVD: This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bctls-fips 1.0.24 (1.0.X series), 2.0.24 (2.0.X series) and 2.1.24 (2.1.X series). OSV: JSSE hostname verifier CN-fallback enabled by default despite documented opt-in",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260809T215750Z/items/CVE-2026-59638.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: In Bouncy Castle for Java before 1.85, JSSE hostname verifier CN-fallback enabled by default despite documented opt-in. NVD: This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bctls-fips 1.0.24 (1.0.X series), 2.0.24 (2.0.X series) and 2.1.24 (2.1.X series). OSV: JSSE hostname verifier CN-fallback enabled by default despite documented opt-in",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-59638/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-59639/",
      "current_public_safe_latest": false,
      "cvss_score": 8.7,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.07045,
      "epss_score": 0.00174,
      "first_observed_at": "2026-08-09T15:51:11.168346+00:00",
      "id": "CVE-2026-59639",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-09T21:51:57.260007+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: In Bouncy Castle for Java before 1.85, CMS verifySignatures returns true for SignedData with zero signers. NVD: This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpkix-fips 1.0.12 (1.0.X series), 2.0.12 (2.0.X series) and 2.1.12 (2.1.X series). OSV: CMS verifySignatures returns true for SignedData with zero signers",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260809T215750Z/items/CVE-2026-59639.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: In Bouncy Castle for Java before 1.85, CMS verifySignatures returns true for SignedData with zero signers. NVD: This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpkix-fips 1.0.12 (1.0.X series), 2.0.12 (2.0.X series) and 2.1.12 (2.1.X series). OSV: CMS verifySignatures returns true for SignedData with zero signers",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-59639/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-59640/",
      "current_public_safe_latest": false,
      "cvss_score": 8.7,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.17887,
      "epss_score": 0.00263,
      "first_observed_at": "2026-08-09T15:51:11.168346+00:00",
      "id": "CVE-2026-59640",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-09T21:51:57.260007+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: In Bouncy Castle for Java before 1.85, OpenPGP CFB quick-check oracle active on symmetric/session-key paths. NVD: This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpg-fips 1.0.13 (1.0.X series), 2.0.13 (2.0.X series) and 2.1.13 (2.1.X series). OSV: OpenPGP CFB quick-check oracle active on symmetric/session-key paths",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260809T215750Z/items/CVE-2026-59640.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: In Bouncy Castle for Java before 1.85, OpenPGP CFB quick-check oracle active on symmetric/session-key paths. NVD: This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpg-fips 1.0.13 (1.0.X series), 2.0.13 (2.0.X series) and 2.1.13 (2.1.X series). OSV: OpenPGP CFB quick-check oracle active on symmetric/session-key paths",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-59640/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-59641/",
      "current_public_safe_latest": false,
      "cvss_score": 8.7,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.07004,
      "epss_score": 0.00174,
      "first_observed_at": "2026-08-09T15:51:11.168346+00:00",
      "id": "CVE-2026-59641",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-09T21:51:57.260007+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: In Bouncy Castle for Java before 1.85, S/MIME validator trusts signer-asserted signingTime for path validation. NVD: This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcmail-fips and bcjmail-fips 1.0.7 (1.0.X series), 2.0.7 (2.0.X series) and 2.1.7 (2.1.X series). OSV: S/MIME validator trusts signer-asserted signingTime for path validation",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260809T215750Z/items/CVE-2026-59641.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: In Bouncy Castle for Java before 1.85, S/MIME validator trusts signer-asserted signingTime for path validation. NVD: This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcmail-fips and bcjmail-fips 1.0.7 (1.0.X series), 2.0.7 (2.0.X series) and 2.1.7 (2.1.X series). OSV: S/MIME validator trusts signer-asserted signingTime for path validation",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-59641/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-59642/",
      "current_public_safe_latest": false,
      "cvss_score": 8.7,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.05283,
      "epss_score": 0.00157,
      "first_observed_at": "2026-08-09T15:51:11.168346+00:00",
      "id": "CVE-2026-59642",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-09T21:51:57.260007+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: In Bouncy Castle for Java before 1.85, CMS AuthenticatedData content not bound to MAC when authAttrs present. NVD: This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpkix-fips 1.0.12 (1.0.X series), 2.0.12 (2.0.X series) and 2.1.12 (2.1.X series). OSV: CMS AuthenticatedData content not bound to MAC when authAttrs present",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260809T215750Z/items/CVE-2026-59642.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: In Bouncy Castle for Java before 1.85, CMS AuthenticatedData content not bound to MAC when authAttrs present. NVD: This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpkix-fips 1.0.12 (1.0.X series), 2.0.12 (2.0.X series) and 2.1.12 (2.1.X series). OSV: CMS AuthenticatedData content not bound to MAC when authAttrs present",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-59642/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-59643/",
      "current_public_safe_latest": false,
      "cvss_score": 8.7,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.07045,
      "epss_score": 0.00174,
      "first_observed_at": "2026-08-09T15:51:11.168346+00:00",
      "id": "CVE-2026-59643",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-09T21:51:57.260007+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: In Bouncy Castle for Java before 1.85, OpenPGP inline-signature policy failures silently ignored. NVD: This issue also affects Bouncy Castle for Java FIPS (BC-FJA) before bcpg-fips 2.0.13. OSV: OpenPGP inline-signature policy failures silently ignored",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260809T215750Z/items/CVE-2026-59643.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: In Bouncy Castle for Java before 1.85, OpenPGP inline-signature policy failures silently ignored. NVD: This issue also affects Bouncy Castle for Java FIPS (BC-FJA) before bcpg-fips 2.0.13. OSV: OpenPGP inline-signature policy failures silently ignored",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-59643/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-59644/",
      "current_public_safe_latest": false,
      "cvss_score": 8.7,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.17887,
      "epss_score": 0.00263,
      "first_observed_at": "2026-08-09T15:51:11.168346+00:00",
      "id": "CVE-2026-59644",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-09T21:51:57.260007+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: In Bouncy Castle for Java before 1.85, MLS hash-ratchet honours arbitrary 32-bit generation counter from sender. OSV: MLS hash-ratchet honours arbitrary 32-bit generation counter from sender OSV: In Bouncy Castle for Java before 1.85, MLS hash-ratchet honours arbitrary 32-bit generation counter from sender.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260809T215750Z/items/CVE-2026-59644.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: In Bouncy Castle for Java before 1.85, MLS hash-ratchet honours arbitrary 32-bit generation counter from sender. OSV: MLS hash-ratchet honours arbitrary 32-bit generation counter from sender OSV: In Bouncy Castle for Java before 1.85, MLS hash-ratchet honours arbitrary 32-bit generation counter from sender.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-59644/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-59645/",
      "current_public_safe_latest": false,
      "cvss_score": 8.7,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.17883,
      "epss_score": 0.00263,
      "first_observed_at": "2026-08-09T15:51:11.168346+00:00",
      "id": "CVE-2026-59645",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-09T21:51:57.260007+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: In Bouncy Castle for Java before 1.85, OER parser recurses without depth limit on self-referential IEEE 1609.2 schema. NVD: This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcutil-fips 2.0.7 (2.0.X series) and 2.1.7 (2.1.X series). OSV: OER parser recurses without depth limit on self-referential IEEE 1609.2 schema",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260809T215750Z/items/CVE-2026-59645.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: In Bouncy Castle for Java before 1.85, OER parser recurses without depth limit on self-referential IEEE 1609.2 schema. NVD: This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcutil-fips 2.0.7 (2.0.X series) and 2.1.7 (2.1.X series). OSV: OER parser recurses without depth limit on self-referential IEEE 1609.2 schema",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-59645/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-59646/",
      "current_public_safe_latest": false,
      "cvss_score": 8.7,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.21344,
      "epss_score": 0.00291,
      "first_observed_at": "2026-08-09T15:51:11.168346+00:00",
      "id": "CVE-2026-59646",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-09T21:51:57.260007+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: In Bouncy Castle for Java before 1.85, DTLS handshake reassembler allocates buffer from unchecked 24-bit length. NVD: This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bctls-fips 1.0.24 (1.0.X series), 2.0.24 (2.0.X series) and 2.1.24 (2.1.X series). OSV: DTLS handshake reassembler allocates buffer from unchecked 24-bit length",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260809T215750Z/items/CVE-2026-59646.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: In Bouncy Castle for Java before 1.85, DTLS handshake reassembler allocates buffer from unchecked 24-bit length. NVD: This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bctls-fips 1.0.24 (1.0.X series), 2.0.24 (2.0.X series) and 2.1.24 (2.1.X series). OSV: DTLS handshake reassembler allocates buffer from unchecked 24-bit length",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-59646/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-59647/",
      "current_public_safe_latest": false,
      "cvss_score": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.17887,
      "epss_score": 0.00263,
      "first_observed_at": "2026-08-09T15:51:11.168346+00:00",
      "id": "CVE-2026-59647",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-09T21:51:57.260007+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: In Bouncy Castle for Java before 1.85, CRMF/CMP password-MAC honours unbounded iteration count. NVD: This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpkix-fips 1.0.12 (1.0.X series), 2.0.12 (2.0.X series) and 2.1.12 (2.1.X series). OSV: CRMF/CMP password-MAC honours unbounded iteration count",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260809T215750Z/items/CVE-2026-59647.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: In Bouncy Castle for Java before 1.85, CRMF/CMP password-MAC honours unbounded iteration count. NVD: This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpkix-fips 1.0.12 (1.0.X series), 2.0.12 (2.0.X series) and 2.1.12 (2.1.X series). OSV: CRMF/CMP password-MAC honours unbounded iteration count",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-59647/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-59648/",
      "current_public_safe_latest": false,
      "cvss_score": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.17888,
      "epss_score": 0.00263,
      "first_observed_at": "2026-08-09T15:51:11.168346+00:00",
      "id": "CVE-2026-59648",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-09T21:51:57.260007+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: In Bouncy Castle for Java before 1.85, OpenPGP Argon2 S2K honours attacker-chosen memory and passes. NVD: This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpg-fips 1.0.13 (1.0.X series), 2.0.13 (2.0.X series) and 2.1.13 (2.1.X series). OSV: OpenPGP Argon2 S2K honours attacker-chosen memory and passes",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260809T215750Z/items/CVE-2026-59648.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: In Bouncy Castle for Java before 1.85, OpenPGP Argon2 S2K honours attacker-chosen memory and passes. NVD: This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpg-fips 1.0.13 (1.0.X series), 2.0.13 (2.0.X series) and 2.1.13 (2.1.X series). OSV: OpenPGP Argon2 S2K honours attacker-chosen memory and passes",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-59648/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-59649/",
      "current_public_safe_latest": false,
      "cvss_score": 8.7,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.17888,
      "epss_score": 0.00263,
      "first_observed_at": "2026-08-09T15:51:11.168346+00:00",
      "id": "CVE-2026-59649",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-09T21:51:57.260007+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: In Bouncy Castle for Java before 1.85, OpenPGP user-attribute subpacket length bounded only by JVM max memory. NVD: This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpg-fips 1.0.13 (1.0.X series), 2.0.13 (2.0.X series) and 2.1.13 (2.1.X series). OSV: OpenPGP user-attribute subpacket length bounded only by JVM max memory",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260809T215750Z/items/CVE-2026-59649.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: In Bouncy Castle for Java before 1.85, OpenPGP user-attribute subpacket length bounded only by JVM max memory. NVD: This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpg-fips 1.0.13 (1.0.X series), 2.0.13 (2.0.X series) and 2.1.13 (2.1.X series). OSV: OpenPGP user-attribute subpacket length bounded only by JVM max memory",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-59649/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-59650/",
      "current_public_safe_latest": false,
      "cvss_score": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.17883,
      "epss_score": 0.00263,
      "first_observed_at": "2026-08-09T15:51:11.168346+00:00",
      "id": "CVE-2026-59650",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-09T21:51:57.260007+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: In Bouncy Castle for Java before 1.85, MTI/A0 DH agreement exponentiates unvalidated peer value. NVD: This issue also affects Bouncy Castle for Java LTS before 2.73.12. OSV: MTI/A0 DH agreement exponentiates unvalidated peer value",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260809T215750Z/items/CVE-2026-59650.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: In Bouncy Castle for Java before 1.85, MTI/A0 DH agreement exponentiates unvalidated peer value. NVD: This issue also affects Bouncy Castle for Java LTS before 2.73.12. OSV: MTI/A0 DH agreement exponentiates unvalidated peer value",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-59650/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-59651/",
      "current_public_safe_latest": false,
      "cvss_score": 7.1,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.07045,
      "epss_score": 0.00174,
      "first_observed_at": "2026-08-09T21:51:57.260007+00:00",
      "id": "CVE-2026-59651",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-09T21:51:57.260007+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: In Bouncy Castle for Java before 1.85, BKS keystore accepts legacy version with 16-bit integrity MAC key. NVD: This issue also affects Bouncy Castle for Java LTS before 2.73.12. OSV: BKS keystore accepts legacy version with 16-bit integrity MAC key",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260809T215750Z/items/CVE-2026-59651.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: In Bouncy Castle for Java before 1.85, BKS keystore accepts legacy version with 16-bit integrity MAC key. NVD: This issue also affects Bouncy Castle for Java LTS before 2.73.12. OSV: BKS keystore accepts legacy version with 16-bit integrity MAC key",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-59651/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-59652/",
      "current_public_safe_latest": false,
      "cvss_score": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.26753,
      "epss_score": 0.00341,
      "first_observed_at": "2026-08-09T21:51:57.260007+00:00",
      "id": "CVE-2026-59652",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-09T21:51:57.260007+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: In Bouncy Castle for Java before 1.85, LDAP filter injection in legacy jdk1.4 LDAPStoreHelper. OSV: LDAP filter injection in legacy jdk1.4 LDAPStoreHelper OSV: In Bouncy Castle for Java before 1.85, LDAP filter injection in legacy jdk1.4 LDAPStoreHelper.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260809T215750Z/items/CVE-2026-59652.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: In Bouncy Castle for Java before 1.85, LDAP filter injection in legacy jdk1.4 LDAPStoreHelper. OSV: LDAP filter injection in legacy jdk1.4 LDAPStoreHelper OSV: In Bouncy Castle for Java before 1.85, LDAP filter injection in legacy jdk1.4 LDAPStoreHelper.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-59652/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-59674/",
      "current_public_safe_latest": false,
      "cvss_score": 7.1,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.02947,
      "epss_score": 0.00129,
      "first_observed_at": "2026-07-21T06:08:28.817138+00:00",
      "id": "CVE-2026-59674",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-21T06:08:28.817138+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A UNIX Symbolic Link (Symlink) Following vulnerability in openSUSE Tumbleweed suricata package allows the suricata user to escalate to root. NVD: This issue affects openSUSE Tumbleweed: from ? NVD: before 8.0.5-2.1; openSUSE Tumbleweed: from ?",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260721T061518Z/items/CVE-2026-59674.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A UNIX Symbolic Link (Symlink) Following vulnerability in openSUSE Tumbleweed suricata package allows the suricata user to escalate to root. NVD: This issue affects openSUSE Tumbleweed: from ? NVD: before 8.0.5-2.1; openSUSE Tumbleweed: from ?",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-59674/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-59676/",
      "current_public_safe_latest": false,
      "cvss_score": 5.8,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.00439,
      "epss_score": 0.00087,
      "first_observed_at": "2026-07-30T06:01:44.452906+00:00",
      "id": "CVE-2026-59676",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-30T06:01:44.452906+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in seunshare of selinux policycoreutils allows a user calling seunshare that is running in the unconfined SELinux domain to delete arbitrary root-owned files, This issue affects policycoreutils...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260730T060504Z/items/CVE-2026-59676.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in seunshare of selinux policycoreutils allows a user calling seunshare that is running in the unconfined SELinux domain to delete arbitrary root-owned files, This issue affects policycoreutils...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-59676/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-59677/",
      "current_public_safe_latest": false,
      "cvss_score": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.01322,
      "epss_score": 0.00107,
      "first_observed_at": "2026-07-30T06:01:44.452906+00:00",
      "id": "CVE-2026-59677",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-30T06:01:44.452906+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A Missing Authorization vulnerability in selinux policycoreutils seunshares allows a user that is running in unconfined context to kill e.g. NVD: root-owned processes running also in unconfined context This issue affects policycoreutils through 3.10.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260730T060504Z/items/CVE-2026-59677.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A Missing Authorization vulnerability in selinux policycoreutils seunshares allows a user that is running in unconfined context to kill e.g. NVD: root-owned processes running also in unconfined context This issue affects policycoreutils through 3.10.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-59677/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-59678/",
      "current_public_safe_latest": false,
      "cvss_score": 7.1,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.01897,
      "epss_score": 0.00116,
      "first_observed_at": "2026-07-30T06:01:44.452906+00:00",
      "id": "CVE-2026-59678",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-30T06:01:44.452906+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: An Incorrect Authorization vulnerability in Linux-Gaming PortProtonQt allows any users to mount and unmount arbitrary file systems and modify the network configuration via NetworkManager. NVD: This issue affects PortProtonQt before 0d0f0950ebd948cdf82e8c3e1ebd2bcb9b8bafbe.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260730T060504Z/items/CVE-2026-59678.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: An Incorrect Authorization vulnerability in Linux-Gaming PortProtonQt allows any users to mount and unmount arbitrary file systems and modify the network configuration via NetworkManager. NVD: This issue affects PortProtonQt before 0d0f0950ebd948cdf82e8c3e1ebd2bcb9b8bafbe.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-59678/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-59686/",
      "current_public_safe_latest": false,
      "cvss_score": 8.4,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.50848,
      "epss_score": 0.00734,
      "first_observed_at": "2026-08-03T12:38:03.310457+00:00",
      "id": "CVE-2026-59686",
      "impact_tags": [
        "command injection risk",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-03T12:38:03.310457+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: An OS Command Injection vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows an authenticated attacker with high privileges to execute arbitrary operating system commands on the affected...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260803T124716Z/items/CVE-2026-59686.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes command injection risk · authenticated boundary. Possible impact: An attacker may be able to run unintended system commands through the affected component.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: An OS Command Injection vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows an authenticated attacker with high privileges to execute arbitrary operating system commands on the affected...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-59686/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-59687/",
      "current_public_safe_latest": false,
      "cvss_score": 8.4,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.50215,
      "epss_score": 0.00717,
      "first_observed_at": "2026-08-03T12:38:03.310457+00:00",
      "id": "CVE-2026-59687",
      "impact_tags": [
        "command injection risk",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-03T12:38:03.310457+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: An OS Command Injection vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows an authenticated attacker with high privileges to execute arbitrary operating system commands on the affected...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260803T124716Z/items/CVE-2026-59687.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes command injection risk · authenticated boundary. Possible impact: An attacker may be able to run unintended system commands through the affected component.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: An OS Command Injection vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows an authenticated attacker with high privileges to execute arbitrary operating system commands on the affected...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-59687/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-59688/",
      "current_public_safe_latest": false,
      "cvss_score": 8.4,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.50215,
      "epss_score": 0.00717,
      "first_observed_at": "2026-08-03T12:38:03.310457+00:00",
      "id": "CVE-2026-59688",
      "impact_tags": [
        "command injection risk",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-03T12:38:03.310457+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: An OS Command Injection vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows an authenticated attacker with high privileges to execute arbitrary operating system commands on the affected...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260803T124716Z/items/CVE-2026-59688.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes command injection risk · authenticated boundary. Possible impact: An attacker may be able to run unintended system commands through the affected component.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: An OS Command Injection vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows an authenticated attacker with high privileges to execute arbitrary operating system commands on the affected...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-59688/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-59689/",
      "current_public_safe_latest": false,
      "cvss_score": 8.0,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.06607,
      "epss_score": 0.00169,
      "first_observed_at": "2026-08-03T12:38:03.310457+00:00",
      "id": "CVE-2026-59689",
      "impact_tags": [
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-03T12:38:03.310457+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: An Incorrect Authorization vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows an authenticated attacker with low privileges to escalate privileges to root on the affected appliance...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260803T124716Z/items/CVE-2026-59689.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes authenticated boundary. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: An Incorrect Authorization vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows an authenticated attacker with low privileges to escalate privileges to root on the affected appliance...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-59689/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-59690/",
      "current_public_safe_latest": false,
      "cvss_score": 8.0,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.07245,
      "epss_score": 0.00175,
      "first_observed_at": "2026-08-03T12:38:03.310457+00:00",
      "id": "CVE-2026-59690",
      "impact_tags": [
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-03T12:38:03.310457+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A Missing Authorization vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, MOVEit WAF, and Multi Tenant allows an authenticated attacker with low privileges to perform privileged administrative operations...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260803T124716Z/items/CVE-2026-59690.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes authenticated boundary. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A Missing Authorization vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, MOVEit WAF, and Multi Tenant allows an authenticated attacker with low privileges to perform privileged administrative operations...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-59690/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-59691/",
      "current_public_safe_latest": false,
      "cvss_score": 7.1,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.15952,
      "epss_score": 0.00247,
      "first_observed_at": "2026-07-16T11:14:01.223847+00:00",
      "id": "CVE-2026-59691",
      "impact_tags": [
        "service availability review",
        "memory safety review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-16T11:14:01.223847+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A heap buffer overflow vulnerability was found in GStreamer's rfbsrc plugin. NVD: When a client connects to a malicious RFB/VNC server that advertises a 16bpp framebuffer and sends Hextile-encoded updates, the Hextile background fill path writes 32-bit pixel values into a buffer allocated for 16-bit pixels. NVD: This type mismatch causes an out-of-bounds heap write that can lead to denial of service (process crash) and potential memory corruption.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260716T111601Z/items/CVE-2026-59691.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes service availability risk · memory safety review. Possible impact: The affected service may become unavailable or unreliable.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A heap buffer overflow vulnerability was found in GStreamer's rfbsrc plugin. NVD: When a client connects to a malicious RFB/VNC server that advertises a 16bpp framebuffer and sends Hextile-encoded updates, the Hextile background fill path writes 32-bit pixel values into a buffer allocated for 16-bit pixels. NVD: This type mismatch causes an out-of-bounds heap write that can lead to denial of service (process crash) and potential memory corruption.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-59691/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-59692/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.23019,
      "epss_score": 0.0031,
      "first_observed_at": "2026-07-16T11:14:01.223847+00:00",
      "id": "CVE-2026-59692",
      "impact_tags": [
        "service availability review",
        "memory safety review",
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-16T11:14:01.223847+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A stack buffer overflow vulnerability was found in GStreamer's DTLS plugin. NVD: During a DTLS handshake, the peer certificate Subject Distinguished Name is printed into a fixed-size 2048-byte stack buffer without bounds checking. NVD: A remote unauthenticated attacker can send a certificate with an oversized Subject DN that exceeds the buffer, causing a stack buffer overflow and process crash, resulting in denial of service.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260716T111601Z/items/CVE-2026-59692.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes service availability risk · memory safety review · remote exposure. Possible impact: The affected service may become unavailable or unreliable.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A stack buffer overflow vulnerability was found in GStreamer's DTLS plugin. NVD: During a DTLS handshake, the peer certificate Subject Distinguished Name is printed into a fixed-size 2048-byte stack buffer without bounds checking. NVD: A remote unauthenticated attacker can send a certificate with an oversized Subject DN that exceeds the buffer, causing a stack buffer overflow and process crash, resulting in denial of service.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-59692/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-59694/",
      "current_public_safe_latest": false,
      "cvss_score": 8.3,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.22267,
      "epss_score": 0.00301,
      "first_observed_at": "2026-07-24T06:06:41.160911+00:00",
      "id": "CVE-2026-59694",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-24T11:14:35.780564+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Improper Validation of Specified Quantity in Input in ZenHive mpp allows an unauthenticated remote client to inflate the fee-payer's gas cost per payment by a large multiplier, degrading the sponsor's operating margin. NVD: When the mpp Elixir library is configured as fee payer (fee_payer: true), MPP.Tempo.Transaction.cosign_fee_payer/3 re-signs the client-supplied base fields of the 0x76 AASigned envelope verbatim, including the EIP-2930 access list, without validating its... NVD: EIP-2930 access list entries incur intrinsic gas (~2,400 gas per address, plus 1,900 gas per storage key) charged before any opcode executes, regardless of whether the listed addresses are ever touched.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260724T111724Z/items/CVE-2026-59694.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Improper Validation of Specified Quantity in Input in ZenHive mpp allows an unauthenticated remote client to inflate the fee-payer's gas cost per payment by a large multiplier, degrading the sponsor's operating margin. NVD: When the mpp Elixir library is configured as fee payer (fee_payer: true), MPP.Tempo.Transaction.cosign_fee_payer/3 re-signs the client-supplied base fields of the 0x76 AASigned envelope verbatim, including the EIP-2930 access list, without validating its... NVD: EIP-2930 access list entries incur intrinsic gas (~2,400 gas per address, plus 1,900 gas per storage key) charged before any opcode executes, regardless of whether the listed addresses are ever touched.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-59694/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-59695/",
      "current_public_safe_latest": false,
      "cvss_score": 8.3,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.22267,
      "epss_score": 0.00301,
      "first_observed_at": "2026-07-24T06:06:41.160911+00:00",
      "id": "CVE-2026-59695",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-24T11:14:35.780564+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Improper Validation of Specified Quantity in Input in ZenHive mpp allows an unauthenticated remote client to drain the fee-payer wallet in a single request by naming an arbitrarily high gas price. NVD: When the mpp Elixir library is configured as fee payer (fee_payer: true), MPP.Tempo.Transaction.cosign_fee_payer/3 re-signs the client-supplied base fields of the 0x76 AASigned envelope verbatim, including max_fee_per_gas and max_priority_fee_per_gas, without... NVD: A malicious client embeds arbitrarily large values for these fields in the signed envelope.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260724T111724Z/items/CVE-2026-59695.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Improper Validation of Specified Quantity in Input in ZenHive mpp allows an unauthenticated remote client to drain the fee-payer wallet in a single request by naming an arbitrarily high gas price. NVD: When the mpp Elixir library is configured as fee payer (fee_payer: true), MPP.Tempo.Transaction.cosign_fee_payer/3 re-signs the client-supplied base fields of the 0x76 AASigned envelope verbatim, including max_fee_per_gas and max_priority_fee_per_gas, without... NVD: A malicious client embeds arbitrarily large values for these fields in the signed envelope.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-59695/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-59704/",
      "current_public_safe_latest": false,
      "cvss_score": 7.1,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.12039,
      "epss_score": 0.00216,
      "first_observed_at": "2026-07-14T22:16:58.989760+00:00",
      "id": "CVE-2026-59704",
      "impact_tags": [
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-14T22:16:58.989760+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Cap's GET /api/video/ai endpoint fails to validate user ownership or membership before returning private video AI metadata including titles, summaries, and chapters. NVD: Authenticated attackers can supply arbitrary video IDs to read sensitive AI-generated content and trigger unauthorized AI generation that consumes the video owner's credits without consent. OSV: Cap - Missing Access Control in Video AI Metadata Endpoint",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260714T222111Z/items/CVE-2026-59704.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes authenticated boundary. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Cap's GET /api/video/ai endpoint fails to validate user ownership or membership before returning private video AI metadata including titles, summaries, and chapters. NVD: Authenticated attackers can supply arbitrary video IDs to read sensitive AI-generated content and trigger unauthorized AI generation that consumes the video owner's credits without consent. OSV: Cap - Missing Access Control in Video AI Metadata Endpoint",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-59704/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-59705/",
      "current_public_safe_latest": false,
      "cvss_score": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.39204,
      "epss_score": 0.00498,
      "first_observed_at": "2026-07-14T22:16:58.989760+00:00",
      "id": "CVE-2026-59705",
      "impact_tags": [
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-14T22:16:58.989760+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: mem0's openmemory/api component contains an unauthenticated access vulnerability that allows unauthenticated attackers to read, write, and delete arbitrary user memories by accessing API routers registered without authentication middleware. NVD: Attackers can supply arbitrary user_id parameters or directly access memory retrieval endpoints to expose private memory content, or invoke pause endpoints with global_pause=true to cause denial-of-service across all users. OSV: mem0 - OpenMemory API Unauthenticated Access via Memory Endpoints",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260714T222111Z/items/CVE-2026-59705.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes remote exposure · authenticated boundary. Possible impact: This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: mem0's openmemory/api component contains an unauthenticated access vulnerability that allows unauthenticated attackers to read, write, and delete arbitrary user memories by accessing API routers registered without authentication middleware. NVD: Attackers can supply arbitrary user_id parameters or directly access memory retrieval endpoints to expose private memory content, or invoke pause endpoints with global_pause=true to cause denial-of-service across all users. OSV: mem0 - OpenMemory API Unauthenticated Access via Memory Endpoints",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-59705/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-59706/",
      "current_public_safe_latest": false,
      "cvss_score": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.17333,
      "epss_score": 0.00259,
      "first_observed_at": "2026-07-14T22:16:58.989760+00:00",
      "id": "CVE-2026-59706",
      "impact_tags": [
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-14T22:16:58.989760+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: mem0 contains unauthenticated config API endpoints that expose LLM API keys in plaintext and allow server-side request forgery via attacker-controlled ollama_base_url parameter. NVD: Unauthenticated attackers can retrieve stored secrets like OpenAI API keys via GET /api/v1/config/ or trigger SSRF attacks by setting ollama_base_url to internal addresses like cloud IMDS via PUT /api/v1/config/mem0/llm endpoint. OSV: mem0 - Unauthenticated Config API Exposure and SSRF via ollama_base_url",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260714T222111Z/items/CVE-2026-59706.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes remote exposure · authenticated boundary. Possible impact: This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: mem0 contains unauthenticated config API endpoints that expose LLM API keys in plaintext and allow server-side request forgery via attacker-controlled ollama_base_url parameter. NVD: Unauthenticated attackers can retrieve stored secrets like OpenAI API keys via GET /api/v1/config/ or trigger SSRF attacks by setting ollama_base_url to internal addresses like cloud IMDS via PUT /api/v1/config/mem0/llm endpoint. OSV: mem0 - Unauthenticated Config API Exposure and SSRF via ollama_base_url",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-59706/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-59709/",
      "current_public_safe_latest": false,
      "cvss_score": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.09941,
      "epss_score": 0.002,
      "first_observed_at": "2026-07-14T10:57:43.777280+00:00",
      "id": "CVE-2026-59709",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-14T10:57:43.777280+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Ghostfolio's PUT /api/v1/portfolio/holding/:dataSource/:symbol/tags endpoint fails to verify Access.permissions field when processing the Impersonation-Id header, allowing read-only access grantees to modify portfolio holding tags. NVD: Attackers with valid read-only share tokens can assign or remove tags on victim holdings, corrupting portfolio categorization and reports. OSV: Ghostfolio - Unauthorized Portfolio Holding Tag Modification via Missing Permission Check",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260714T110007Z/items/CVE-2026-59709.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Ghostfolio's PUT /api/v1/portfolio/holding/:dataSource/:symbol/tags endpoint fails to verify Access.permissions field when processing the Impersonation-Id header, allowing read-only access grantees to modify portfolio holding tags. NVD: Attackers with valid read-only share tokens can assign or remove tags on victim holdings, corrupting portfolio categorization and reports. OSV: Ghostfolio - Unauthorized Portfolio Holding Tag Modification via Missing Permission Check",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-59709/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-59710/",
      "current_public_safe_latest": false,
      "cvss_score": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.09705,
      "epss_score": 0.00198,
      "first_observed_at": "2026-07-13T22:14:02.217047+00:00",
      "id": "CVE-2026-59710",
      "impact_tags": [
        "XSS risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-13T22:14:02.217047+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: showdown contains a stored cross-site scripting vulnerability in the parseHeaders function of src/subParsers/makehtml/tables.js that fails to properly escape table header ID attributes. NVD: Attackers can inject arbitrary HTML and script-executing SVG elements through double-quote characters in markdown table headers, achieving stored XSS when untrusted markdown is rendered with the default github flavor configuration. OSV: showdown - Stored XSS via Unescaped Table Header ID Attribute Injection",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260714T042224Z/items/CVE-2026-59710.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes XSS risk. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: showdown contains a stored cross-site scripting vulnerability in the parseHeaders function of src/subParsers/makehtml/tables.js that fails to properly escape table header ID attributes. NVD: Attackers can inject arbitrary HTML and script-executing SVG elements through double-quote characters in markdown table headers, achieving stored XSS when untrusted markdown is rendered with the default github flavor configuration. OSV: showdown - Stored XSS via Unescaped Table Header ID Attribute Injection",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-59710/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-59731/",
      "current_public_safe_latest": false,
      "cvss_score": 8.2,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.18485,
      "epss_score": 0.00267,
      "first_observed_at": "2026-07-15T16:47:57.605966+00:00",
      "id": "CVE-2026-59731",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-15T16:47:57.605966+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Astro is a web framework for content-driven websites. NVD: Version 6.4.7 performs authorization decisions on a partially decoded pathname after reaching the iterative URL decoder limit, while later rewrite route matching performs an additional decodeURI() operation and can resolve the request to a protected route. NVD: This issue is fixed in version 6.4.8.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260715T164957Z/items/CVE-2026-59731.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: Astro is a web framework for content-driven websites. NVD: Version 6.4.7 performs authorization decisions on a partially decoded pathname after reaching the iterative URL decoder limit, while later rewrite route matching performs an additional decodeURI() operation and can resolve the request to a protected route. NVD: This issue is fixed in version 6.4.8.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-59731/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-59776/",
      "current_public_safe_latest": false,
      "cvss_score": 7.0,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.04014,
      "epss_score": 0.00143,
      "first_observed_at": "2026-07-27T22:30:18.664011+00:00",
      "id": "CVE-2026-59776",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-27T22:30:18.664011+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Missing Cryptographic Step (CWE-325) vulnerability exists in certain FeliCa IC chips shipped in or before 2017. NVD: If the vulnerability is exploited, information stored in the IC chip may be read or tampered with.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260727T223632Z/items/CVE-2026-59776.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Missing Cryptographic Step (CWE-325) vulnerability exists in certain FeliCa IC chips shipped in or before 2017. NVD: If the vulnerability is exploited, information stored in the IC chip may be read or tampered with.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-59776/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-59831/",
      "current_public_safe_latest": false,
      "cvss_score": 4.4,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.09813,
      "epss_score": 0.00198,
      "first_observed_at": "2026-07-16T22:18:24.817461+00:00",
      "id": "CVE-2026-59831",
      "impact_tags": [
        "code execution review",
        "command execution review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-16T22:18:24.817461+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: GitHub CLI (gh) is GitHub’s official command line tool. NVD: From 2.10.0 through 2.95.0, connecting to a malicious Codespace with gh codespace jupyter can allow command execution because the command opens a JupyterLab URL supplied by a process inside the Codespace without validating that it is a loopback HTTP or HTTPS... NVD: This issue is fixed in version 2.96.0.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260716T222035Z/items/CVE-2026-59831.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes code execution review · command execution risk. Possible impact: An attacker may be able to run code or commands on affected systems.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: GitHub CLI (gh) is GitHub’s official command line tool. NVD: From 2.10.0 through 2.95.0, connecting to a malicious Codespace with gh codespace jupyter can allow command execution because the command opens a JupyterLab URL supplied by a process inside the Codespace without validating that it is a loopback HTTP or HTTPS... NVD: This issue is fixed in version 2.96.0.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-59831/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-59832/",
      "current_public_safe_latest": false,
      "cvss_score": 7.7,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.2367,
      "epss_score": 0.00316,
      "first_observed_at": "2026-07-16T22:18:24.817461+00:00",
      "id": "CVE-2026-59832",
      "impact_tags": [
        "path traversal review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-16T22:18:24.817461+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: SiYuan is an open-source personal knowledge management system. NVD: Prior to 3.7.1, the /snippets/*filepath route handler serveSnippets in kernel/server/serve.go joins a single-decoded request path with the snippets directory without subpath containment or sensitive-path checks, allowing an authenticated request such as... NVD: This issue is fixed in versions 3.7.1.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260716T222035Z/items/CVE-2026-59832.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes path traversal review. Possible impact: An attacker may be able to reach files outside the intended application path.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: versions.",
      "source_published_summary": "NVD: SiYuan is an open-source personal knowledge management system. NVD: Prior to 3.7.1, the /snippets/*filepath route handler serveSnippets in kernel/server/serve.go joins a single-decoded request path with the snippets directory without subpath containment or sensitive-path checks, allowing an authenticated request such as... NVD: This issue is fixed in versions 3.7.1.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-59832/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-59833/",
      "current_public_safe_latest": false,
      "cvss_score": 8.6,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.31073,
      "epss_score": 0.00388,
      "first_observed_at": "2026-07-16T22:18:24.817461+00:00",
      "id": "CVE-2026-59833",
      "impact_tags": [
        "code execution review",
        "XSS risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-16T22:18:24.817461+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: SiYuan is an open-source personal knowledge management system. NVD: Prior to 3.7.1, SiYuan renders note and package content to HTML through the Lute engine with sanitization enabled, but Lute's dangerous javascript scheme block does not check form action or SVG xlink:href attributes, allowing stored cross-site scripting in... NVD: This issue is fixed in versions 3.7.1.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260716T222035Z/items/CVE-2026-59833.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes code execution review · XSS risk. Possible impact: An attacker may be able to run code or commands on affected systems.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: versions.",
      "source_published_summary": "NVD: SiYuan is an open-source personal knowledge management system. NVD: Prior to 3.7.1, SiYuan renders note and package content to HTML through the Lute engine with sanitization enabled, but Lute's dangerous javascript scheme block does not check form action or SVG xlink:href attributes, allowing stored cross-site scripting in... NVD: This issue is fixed in versions 3.7.1.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-59833/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-59834/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.30267,
      "epss_score": 0.0038,
      "first_observed_at": "2026-07-16T22:18:24.817461+00:00",
      "id": "CVE-2026-59834",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-16T22:18:24.817461+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: SiYuan is an open-source personal knowledge management system. NVD: Prior to 3.7.1, the block search endpoint POST /api/search/fullTextSearchBlock concatenates attacker-controlled paths values into SQL predicates used by non-SQL search modes, allowing an unauthenticated publish visitor to inject a UNION SELECT and return rows... NVD: This issue is fixed in versions 3.7.1.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260716T222035Z/items/CVE-2026-59834.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: versions.",
      "source_published_summary": "NVD: SiYuan is an open-source personal knowledge management system. NVD: Prior to 3.7.1, the block search endpoint POST /api/search/fullTextSearchBlock concatenates attacker-controlled paths values into SQL predicates used by non-SQL search modes, allowing an unauthenticated publish visitor to inject a UNION SELECT and return rows... NVD: This issue is fixed in versions 3.7.1.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-59834/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-59842/",
      "current_public_safe_latest": false,
      "cvss_score": 3.7,
      "cvss_severity": "LOW",
      "epss_percentile": 0.3422,
      "epss_score": 0.00418,
      "first_observed_at": "2026-07-28T11:30:16.925551+00:00",
      "id": "CVE-2026-59842",
      "impact_tags": [
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-28T11:30:16.925551+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A flaw was found in libssh. NVD: During server-side GSSAPI key exchange, a client-supplied Curve25519 public key shorter than the expected length is copied without proper length validation, leading to an out-of-bounds heap read. NVD: This could allow a remote unauthenticated attacker to disclose small amounts of server memory.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260728T113720Z/items/CVE-2026-59842.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes remote exposure · authenticated boundary. Possible impact: This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A flaw was found in libssh. NVD: During server-side GSSAPI key exchange, a client-supplied Curve25519 public key shorter than the expected length is copied without proper length validation, leading to an out-of-bounds heap read. NVD: This could allow a remote unauthenticated attacker to disclose small amounts of server memory.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-59842/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-59843/",
      "current_public_safe_latest": false,
      "cvss_score": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.41997,
      "epss_score": 0.00536,
      "first_observed_at": "2026-07-28T11:30:16.925551+00:00",
      "id": "CVE-2026-59843",
      "impact_tags": [
        "service availability review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-28T11:30:16.925551+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A flaw was found in libssh. NVD: A remote authenticated peer can advertise a zero maximum packet size in SSH_MSG_CHANNEL_OPEN, causing later channel writes to loop indefinitely and consume CPU, leading to denial of service.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260728T113720Z/items/CVE-2026-59843.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes service availability risk. Possible impact: The affected service may become unavailable or unreliable.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A flaw was found in libssh. NVD: A remote authenticated peer can advertise a zero maximum packet size in SSH_MSG_CHANNEL_OPEN, causing later channel writes to loop indefinitely and consume CPU, leading to denial of service.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-59843/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-59844/",
      "current_public_safe_latest": false,
      "cvss_score": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.41998,
      "epss_score": 0.00536,
      "first_observed_at": "2026-07-28T11:30:16.925551+00:00",
      "id": "CVE-2026-59844",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-28T11:30:16.925551+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A flaw was found in libssh. NVD: A remote authenticated client can issue SSH_FXP_READ requests with an arbitrarily large length, causing a libssh SFTP server to allocate excessive memory and potentially exhaust it through repeated requests.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260728T113720Z/items/CVE-2026-59844.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A flaw was found in libssh. NVD: A remote authenticated client can issue SSH_FXP_READ requests with an arbitrarily large length, causing a libssh SFTP server to allocate excessive memory and potentially exhaust it through repeated requests.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-59844/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-59845/",
      "current_public_safe_latest": false,
      "cvss_score": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.01531,
      "epss_score": 0.00111,
      "first_observed_at": "2026-07-28T11:30:16.925551+00:00",
      "id": "CVE-2026-59845",
      "impact_tags": [
        "service availability review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-28T11:30:16.925551+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A flaw was found in libssh. NVD: When ProxyCommand is used, an unchecked fork() failure can be stored as process ID -1; during cleanup, signals may then be sent across the caller's accessible process tree, leading to local denial of service.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260728T113720Z/items/CVE-2026-59845.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes service availability risk. Possible impact: The affected service may become unavailable or unreliable.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A flaw was found in libssh. NVD: When ProxyCommand is used, an unchecked fork() failure can be stored as process ID -1; during cleanup, signals may then be sent across the caller's accessible process tree, leading to local denial of service.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-59845/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-59853/",
      "current_public_safe_latest": false,
      "cvss_score": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.14475,
      "epss_score": 0.00235,
      "first_observed_at": "2026-07-16T22:18:24.817461+00:00",
      "id": "CVE-2026-59853",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-16T22:18:24.817461+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: SiYuan is an open-source personal knowledge management system. NVD: Prior to 3.7.1, the /api/storage/getCriteria endpoint returns saved search criteria from data/storage/criteria.json without the publish-access filtering used by sibling storage endpoints, allowing a publish-mode Reader to read private document paths... NVD: This issue is fixed in versions 3.7.1.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260716T222035Z/items/CVE-2026-59853.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: versions.",
      "source_published_summary": "NVD: SiYuan is an open-source personal knowledge management system. NVD: Prior to 3.7.1, the /api/storage/getCriteria endpoint returns saved search criteria from data/storage/criteria.json without the publish-access filtering used by sibling storage endpoints, allowing a publish-mode Reader to read private document paths... NVD: This issue is fixed in versions 3.7.1.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-59853/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-59854/",
      "current_public_safe_latest": false,
      "cvss_score": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.19808,
      "epss_score": 0.00278,
      "first_observed_at": "2026-07-16T22:18:24.817461+00:00",
      "id": "CVE-2026-59854",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-16T22:18:24.817461+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: SiYuan is an open-source personal knowledge management system. NVD: Prior to 3.7.1, POST /api/file/globalCopyFiles accepts attacker-supplied absolute source paths and relies on util.IsSensitivePath in kernel/util/path.go, whose denylist misses common home-directory credential files such as .git-credentials, .netrc, .pgpass... NVD: This issue is fixed in versions 3.7.1-alpha.2 and 3.7.1.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260716T222035Z/items/CVE-2026-59854.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: versions.",
      "source_published_summary": "NVD: SiYuan is an open-source personal knowledge management system. NVD: Prior to 3.7.1, POST /api/file/globalCopyFiles accepts attacker-supplied absolute source paths and relies on util.IsSensitivePath in kernel/util/path.go, whose denylist misses common home-directory credential files such as .git-credentials, .netrc, .pgpass... NVD: This issue is fixed in versions 3.7.1-alpha.2 and 3.7.1.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-59854/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-59855/",
      "current_public_safe_latest": false,
      "cvss_score": 8.6,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.22409,
      "epss_score": 0.00305,
      "first_observed_at": "2026-07-16T22:18:24.817461+00:00",
      "id": "CVE-2026-59855",
      "impact_tags": [
        "code execution review",
        "XSS risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-16T22:18:24.817461+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: SiYuan is an open-source personal knowledge management system. NVD: Prior to 3.7.1, Asset.render in app/src/asset/index.ts interpolates the unsanitized this.path value into HTML assigned to innerHTML, allowing a crafted asset link containing a double quote to break out of the src attribute, inject an event handler, and... NVD: This issue is fixed in versions 3.7.1-alpha.2 and 3.7.1.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260716T222035Z/items/CVE-2026-59855.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes code execution review · XSS risk. Possible impact: An attacker may be able to run code or commands on affected systems.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: versions.",
      "source_published_summary": "NVD: SiYuan is an open-source personal knowledge management system. NVD: Prior to 3.7.1, Asset.render in app/src/asset/index.ts interpolates the unsanitized this.path value into HTML assigned to innerHTML, allowing a crafted asset link containing a double quote to break out of the src attribute, inject an event handler, and... NVD: This issue is fixed in versions 3.7.1-alpha.2 and 3.7.1.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-59855/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "vim / vim",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-59856/",
      "current_public_safe_latest": false,
      "cvss_score": 8.4,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.06512,
      "epss_score": 0.00169,
      "first_observed_at": "2026-07-16T22:18:24.817461+00:00",
      "id": "CVE-2026-59856",
      "impact_tags": [
        "code execution review",
        "command execution review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-16T22:18:24.817461+00:00",
      "latest_item_url": null,
      "product": "vim",
      "public_safe_summary": "NVD: Vim is an open source, command line text editor. NVD: Prior to 9.2.0736, the PHP omni-completion script in runtime/autoload/phpcomplete.vim interpolates a class or trait name, taken from the contents of the edited buffer, into a search() pattern that is run via win_execute() without escaping. NVD: A name containing a single quote can terminate the search() string argument early, and because the bar is honored as an Ex command separator, the remainder of the name is run as Ex commands; via the :!",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260716T222035Z/items/CVE-2026-59856.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: vim / vim",
      "source_published_impact": "Source describes code execution review · command execution risk. Possible impact: An attacker may be able to run code or commands on affected systems.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: Vim is an open source, command line text editor. NVD: Prior to 9.2.0736, the PHP omni-completion script in runtime/autoload/phpcomplete.vim interpolates a class or trait name, taken from the contents of the edited buffer, into a search() pattern that is run via win_execute() without escaping. NVD: A name containing a single quote can terminate the search() string argument early, and because the bar is honored as an Ex command separator, the remainder of the name is run as Ex commands; via the :!",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-59856/timeline.json",
      "vendor": "vim"
    },
    {
      "affected_label": "vim / vim",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-59857/",
      "current_public_safe_latest": false,
      "cvss_score": 5.6,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.01386,
      "epss_score": 0.00107,
      "first_observed_at": "2026-07-16T22:18:24.817461+00:00",
      "id": "CVE-2026-59857",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-16T22:18:24.817461+00:00",
      "latest_item_url": null,
      "product": "vim",
      "public_safe_summary": "NVD: Vim is an open source, command line text editor. NVD: Prior to 9.2.0725, the single-byte branch of spell_soundfold_sal() in src/spell.c translates a word through a spell file's SAL sound-folding rules into a caller-owned result buffer, but its result writes are guarded with reslen < MAXWLEN, allowing reslen to... NVD: A boundary-length word passed to soundfold(), or reached via sound-based spell suggestion while a SAL-based spell language is active under a non-multibyte 8-bit encoding, can corrupt the eval_soundfold() stack frame and crash the editor.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260716T222035Z/items/CVE-2026-59857.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: vim / vim",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: Vim is an open source, command line text editor. NVD: Prior to 9.2.0725, the single-byte branch of spell_soundfold_sal() in src/spell.c translates a word through a spell file's SAL sound-folding rules into a caller-owned result buffer, but its result writes are guarded with reslen < MAXWLEN, allowing reslen to... NVD: A boundary-length word passed to soundfold(), or reached via sound-based spell suggestion while a SAL-based spell language is active under a non-multibyte 8-bit encoding, can corrupt the eval_soundfold() stack frame and crash the editor.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-59857/timeline.json",
      "vendor": "vim"
    },
    {
      "affected_label": "vim / vim",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-59858/",
      "current_public_safe_latest": false,
      "cvss_score": 8.4,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.03525,
      "epss_score": 0.00137,
      "first_observed_at": "2026-07-16T22:18:24.817461+00:00",
      "id": "CVE-2026-59858",
      "impact_tags": [
        "code execution review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-16T22:18:24.817461+00:00",
      "latest_item_url": null,
      "product": "vim",
      "public_safe_summary": "NVD: Vim is an open source, command line text editor. NVD: Prior to 9.2.0735, the C omni-completion script in runtime/autoload/ccomplete.vim interpolates the typeref: or typename: extension field of a tags entry, without escaping, into a :vimgrep pattern that is run through :execute. NVD: Because :vimgrep honors the bar as a command separator, a crafted tag field can close the search pattern and append an arbitrary Ex command; opening a hostile .c file whose project tags file contains such an entry and invoking C omni-completion runs that...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260716T222035Z/items/CVE-2026-59858.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: vim / vim",
      "source_published_impact": "Source describes code execution review. Possible impact: An attacker may be able to run code or commands on affected systems.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: Vim is an open source, command line text editor. NVD: Prior to 9.2.0735, the C omni-completion script in runtime/autoload/ccomplete.vim interpolates the typeref: or typename: extension field of a tags entry, without escaping, into a :vimgrep pattern that is run through :execute. NVD: Because :vimgrep honors the bar as a command separator, a crafted tag field can close the search pattern and append an arbitrary Ex command; opening a hostile .c file whose project tags file contains such an entry and invoking C omni-completion runs that...",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-59858/timeline.json",
      "vendor": "vim"
    },
    {
      "affected_label": "immutable-js / immutable",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-59879/",
      "current_public_safe_latest": false,
      "cvss_score": 8.7,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.29219,
      "epss_score": 0.0037,
      "first_observed_at": "2026-07-15T16:47:57.605966+00:00",
      "id": "CVE-2026-59879",
      "impact_tags": [
        "service availability review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-15T16:47:57.605966+00:00",
      "latest_item_url": null,
      "product": "immutable",
      "public_safe_summary": "NVD: Immutable.js provides many Persistent Immutable data structures. NVD: Prior to 4.3.9 and 5.1.8, List#set, List#setSize, List#setIn, List#updateIn, and the functional set, setIn, and updateIn mishandle an index or size in the range 2 ** 30 to 2 ** 31 in setListBounds in src/List.js, causing an empty List to enter an uncatchable... NVD: This issue is fixed in versions 4.3.9 and 5.1.8.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260715T164957Z/items/CVE-2026-59879.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: immutable-js / immutable",
      "source_published_impact": "Source describes service availability risk. Possible impact: The affected service may become unavailable or unreliable.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: versions.",
      "source_published_summary": "NVD: Immutable.js provides many Persistent Immutable data structures. NVD: Prior to 4.3.9 and 5.1.8, List#set, List#setSize, List#setIn, List#updateIn, and the functional set, setIn, and updateIn mishandle an index or size in the range 2 ** 30 to 2 ** 31 in setListBounds in src/List.js, causing an empty List to enter an uncatchable... NVD: This issue is fixed in versions 4.3.9 and 5.1.8.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-59879/timeline.json",
      "vendor": "immutable-js"
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-59882/",
      "current_public_safe_latest": false,
      "cvss_score": 4.2,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.08404,
      "epss_score": 0.00186,
      "first_observed_at": "2026-07-15T16:47:57.605966+00:00",
      "id": "CVE-2026-59882",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-15T16:47:57.605966+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. NVD: Prior to 2.12.3, Uri::assertValidHost() does not reject URI host components containing authority delimiters, embedded ports, or malformed IPv6 brackets, allowing Uri::getHost() to disagree with the URI authority used for security or routing decisions. NVD: This issue is fixed in version 2.12.3.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260715T164957Z/items/CVE-2026-59882.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. NVD: Prior to 2.12.3, Uri::assertValidHost() does not reject URI host components containing authority delimiters, embedded ports, or malformed IPv6 brackets, allowing Uri::getHost() to disagree with the URI authority used for security or routing decisions. NVD: This issue is fixed in version 2.12.3.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-59882/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "guzzlephp / guzzle",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-59883/",
      "current_public_safe_latest": false,
      "cvss_score": 4.7,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.01827,
      "epss_score": 0.00115,
      "first_observed_at": "2026-07-15T16:47:57.605966+00:00",
      "id": "CVE-2026-59883",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-15T16:47:57.605966+00:00",
      "latest_item_url": null,
      "product": "guzzle",
      "public_safe_summary": "NVD: Guzzle is an extensible PHP HTTP client. NVD: Prior to 7.12.3, CookieJar did not restrict cookies scoped to IP-address or bare-numeric Domain values to the exact host that set them, because SetCookie::matchesDomain() applied ordinary suffix matching to domains such as 192.168.0.1, [::1], or 1, allowing... NVD: This issue is fixed in version 7.12.3.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260715T164957Z/items/CVE-2026-59883.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: guzzlephp / guzzle",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: Guzzle is an extensible PHP HTTP client. NVD: Prior to 7.12.3, CookieJar did not restrict cookies scoped to IP-address or bare-numeric Domain values to the exact host that set them, because SetCookie::matchesDomain() applied ordinary suffix matching to domains such as 192.168.0.1, [::1], or 1, allowing... NVD: This issue is fixed in version 7.12.3.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-59883/timeline.json",
      "vendor": "guzzlephp"
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-59887/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.26769,
      "epss_score": 0.00346,
      "first_observed_at": "2026-07-15T16:47:57.605966+00:00",
      "id": "CVE-2026-59887",
      "impact_tags": [
        "service availability review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-15T16:47:57.605966+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: linkify-it is a links recognition library with full Unicode support. NVD: Prior to 5.0.2, the mailto: schema validator used by .test() and .match() can be invoked at every mailto: occurrence and scan the remaining input through src_email_name in lib/re.mjs, causing O(n^2) CPU consumption on crafted user text. NVD: This issue is fixed in version 5.0.2.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260715T164957Z/items/CVE-2026-59887.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes service availability risk. Possible impact: The affected service may become unavailable or unreliable.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: linkify-it is a links recognition library with full Unicode support. NVD: Prior to 5.0.2, the mailto: schema validator used by .test() and .match() can be invoked at every mailto: occurrence and scan the remaining input through src_email_name in lib/re.mjs, causing O(n^2) CPU consumption on crafted user text. NVD: This issue is fixed in version 5.0.2.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-59887/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "python / setuptools",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-59890/",
      "current_public_safe_latest": false,
      "cvss_score": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.2094,
      "epss_score": 0.0029,
      "first_observed_at": "2026-07-15T16:47:57.605966+00:00",
      "id": "CVE-2026-59890",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-15T16:47:57.605966+00:00",
      "latest_item_url": null,
      "product": "setuptools",
      "public_safe_summary": "NVD: setuptools is a package that allows users to download, build, install, upgrade, and uninstall Python packages. NVD: Prior to 83.0.0, FileList applied MANIFEST.in exclude, global-exclude, recursive-exclude, and prune directives by matching compiled glob patterns against on-disk file names without Unicode normalization, so on macOS APFS or HFS+ an NFD file name could bypass... NVD: This issue is fixed in version 83.0.0.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260715T164957Z/items/CVE-2026-59890.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: python / setuptools",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: setuptools is a package that allows users to download, build, install, upgrade, and uninstall Python packages. NVD: Prior to 83.0.0, FileList applied MANIFEST.in exclude, global-exclude, recursive-exclude, and prune directives by matching compiled glob patterns against on-disk file names without Unicode normalization, so on macOS APFS or HFS+ an NFD file name could bypass... NVD: This issue is fixed in version 83.0.0.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-59890/timeline.json",
      "vendor": "python"
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-59892/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.35297,
      "epss_score": 0.00436,
      "first_observed_at": "2026-07-15T16:47:57.605966+00:00",
      "id": "CVE-2026-59892",
      "impact_tags": [
        "service availability review",
        "remote exposure relevant"
      ],
      "kev": false,
      "last_observed_at": "2026-07-15T16:47:57.605966+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: OpenTelemetry JavaScript is the OpenTelemetry JavaScript client. NVD: Prior to 2.9.0, @opentelemetry/propagator-jaeger decodes incoming uber-trace-id and uberctx-* HTTP header values with decodeURIComponent() without handling decode errors, allowing an unauthenticated remote attacker to send a malformed percent-encoded value... NVD: This issue is fixed in version 2.9.0.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260715T164957Z/items/CVE-2026-59892.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes service availability risk · remote exposure. Possible impact: The affected service may become unavailable or unreliable.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: OpenTelemetry JavaScript is the OpenTelemetry JavaScript client. NVD: Prior to 2.9.0, @opentelemetry/propagator-jaeger decodes incoming uber-trace-id and uberctx-* HTTP header values with decodeURIComponent() without handling decode errors, allowing an unauthenticated remote attacker to send a malformed percent-encoded value... NVD: This issue is fixed in version 2.9.0.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-59892/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "hono / hono",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-59895/",
      "current_public_safe_latest": false,
      "cvss_score": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.08506,
      "epss_score": 0.00187,
      "first_observed_at": "2026-07-15T16:47:57.605966+00:00",
      "id": "CVE-2026-59895",
      "impact_tags": [
        "XSS risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-15T16:47:57.605966+00:00",
      "latest_item_url": null,
      "product": "hono",
      "public_safe_summary": "NVD: Hono is a Web application framework that provides support for any JavaScript runtime. NVD: From 4.0.0 before 4.12.27, cx() in hono/css composes class names from plain strings but marks the result as already escaped without HTML-escaping the input, allowing untrusted className values used in a JSX class attribute during server-side rendering to... NVD: This issue is fixed in version 4.12.27.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260715T164957Z/items/CVE-2026-59895.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: hono / hono",
      "source_published_impact": "Source describes XSS risk. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: Hono is a Web application framework that provides support for any JavaScript runtime. NVD: From 4.0.0 before 4.12.27, cx() in hono/css composes class names from plain strings but marks the result as already escaped without HTML-escaping the input, allowing untrusted className values used in a JSX class attribute during server-side rendering to... NVD: This issue is fixed in version 4.12.27.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-59895/timeline.json",
      "vendor": "hono"
    },
    {
      "affected_label": "hono / hono",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-59896/",
      "current_public_safe_latest": false,
      "cvss_score": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.0893,
      "epss_score": 0.00191,
      "first_observed_at": "2026-07-15T16:47:57.605966+00:00",
      "id": "CVE-2026-59896",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-15T16:47:57.605966+00:00",
      "latest_item_url": null,
      "product": "hono",
      "public_safe_summary": "NVD: Hono is a Web application framework that provides support for any JavaScript runtime. NVD: From 4.11.8 before 4.12.27, hono/jsx did not isolate context values per request during server-side rendering, allowing createContext, useContext, jsxRenderer, or useRequestContext data from a different in-flight request to be used after an await in an async... NVD: This issue is fixed in version 4.12.27.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260715T164957Z/items/CVE-2026-59896.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: hono / hono",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: Hono is a Web application framework that provides support for any JavaScript runtime. NVD: From 4.11.8 before 4.12.27, hono/jsx did not isolate context values per request during server-side rendering, allowing createContext, useContext, jsxRenderer, or useRequestContext data from a different in-flight request to be used after an await in an async... NVD: This issue is fixed in version 4.12.27.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-59896/timeline.json",
      "vendor": "hono"
    },
    {
      "affected_label": "hono / hono",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-59897/",
      "current_public_safe_latest": false,
      "cvss_score": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.02625,
      "epss_score": 0.00126,
      "first_observed_at": "2026-07-15T16:47:57.605966+00:00",
      "id": "CVE-2026-59897",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-15T16:47:57.605966+00:00",
      "latest_item_url": null,
      "product": "hono",
      "public_safe_summary": "NVD: Hono is a Web application framework that provides support for any JavaScript runtime. NVD: From 4.3.3 before 4.12.27, the AWS API Gateway v1 adapter can drop a distinct repeated request header value because it de-duplicates values using a substring comparison instead of an exact match, so middleware or application logic that depends on the complete... NVD: This issue is fixed in version 4.12.27.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260715T164957Z/items/CVE-2026-59897.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: hono / hono",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: Hono is a Web application framework that provides support for any JavaScript runtime. NVD: From 4.3.3 before 4.12.27, the AWS API Gateway v1 adapter can drop a distinct repeated request header value because it de-duplicates values using a substring comparison instead of an exact match, so middleware or application logic that depends on the complete... NVD: This issue is fixed in version 4.12.27.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-59897/timeline.json",
      "vendor": "hono"
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-59921/",
      "current_public_safe_latest": false,
      "cvss_score": 5.7,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.20353,
      "epss_score": 0.00281,
      "first_observed_at": "2026-08-04T22:31:51.932237+00:00",
      "id": "CVE-2026-59921",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-04T22:31:51.932237+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Netty is an asynchronous, event-driven network application framework. NVD: Prior to versions 4.1.136.Final and 4.2.16.Final, HttpPostRequestEncoder constructs multipart HTTP request bodies by directly concatenating user-supplied filenames and field names into Content-Disposition MIME headers without validating or sanitizing CRLF... NVD: Since MIME headers are delimited by CRLF, an attacker who controls the filename can inject arbitrary MIME headers into the multipart body part.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260804T223546Z/items/CVE-2026-59921.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: versions.",
      "source_published_summary": "NVD: Netty is an asynchronous, event-driven network application framework. NVD: Prior to versions 4.1.136.Final and 4.2.16.Final, HttpPostRequestEncoder constructs multipart HTTP request bodies by directly concatenating user-supplied filenames and field names into Content-Disposition MIME headers without validating or sanitizing CRLF... NVD: Since MIME headers are delimited by CRLF, an attacker who controls the filename can inject arbitrary MIME headers into the multipart body part.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-59921/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "mistune_project / mistune",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-59922/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.28751,
      "epss_score": 0.00366,
      "first_observed_at": "2026-07-15T16:47:57.605966+00:00",
      "id": "CVE-2026-59922",
      "impact_tags": [
        "service availability review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-15T16:47:57.605966+00:00",
      "latest_item_url": null,
      "product": "mistune",
      "public_safe_summary": "NVD: Mistune is a Python Markdown parser with renderers and plugins. NVD: Prior to 3.3.0, a run of closed tilde, equals-sign, or caret marker pairs around a character causes quadratic work in src/mistune/plugins/formatting.py when the strikethrough, mark, or insert plugin scans for matching markers from each possible start... NVD: This issue is fixed in version 3.3.0.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260715T164957Z/items/CVE-2026-59922.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: mistune_project / mistune",
      "source_published_impact": "Source describes service availability risk. Possible impact: The affected service may become unavailable or unreliable.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: Mistune is a Python Markdown parser with renderers and plugins. NVD: Prior to 3.3.0, a run of closed tilde, equals-sign, or caret marker pairs around a character causes quadratic work in src/mistune/plugins/formatting.py when the strikethrough, mark, or insert plugin scans for matching markers from each possible start... NVD: This issue is fixed in version 3.3.0.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-59922/timeline.json",
      "vendor": "mistune_project"
    },
    {
      "affected_label": "mistune_project / mistune",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-59923/",
      "current_public_safe_latest": false,
      "cvss_score": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.09897,
      "epss_score": 0.00199,
      "first_observed_at": "2026-07-15T16:47:57.605966+00:00",
      "id": "CVE-2026-59923",
      "impact_tags": [
        "XSS risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-15T16:47:57.605966+00:00",
      "latest_item_url": null,
      "product": "mistune",
      "public_safe_summary": "NVD: Mistune is a Python Markdown parser with renderers and plugins. NVD: Prior to 3.3.0, HTMLRenderer.safe_url() does not block percent-encoded javascript URIs, allowing attacker-supplied Markdown links or images to bypass URL protections and execute script in rendered HTML. NVD: This issue is fixed in version 3.3.0.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260715T164957Z/items/CVE-2026-59923.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: mistune_project / mistune",
      "source_published_impact": "Source describes XSS risk. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: Mistune is a Python Markdown parser with renderers and plugins. NVD: Prior to 3.3.0, HTMLRenderer.safe_url() does not block percent-encoded javascript URIs, allowing attacker-supplied Markdown links or images to bypass URL protections and execute script in rendered HTML. NVD: This issue is fixed in version 3.3.0.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-59923/timeline.json",
      "vendor": "mistune_project"
    },
    {
      "affected_label": "mistune_project / mistune",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-59924/",
      "current_public_safe_latest": false,
      "cvss_score": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.26114,
      "epss_score": 0.0034,
      "first_observed_at": "2026-07-15T16:47:57.605966+00:00",
      "id": "CVE-2026-59924",
      "impact_tags": [
        "path traversal review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-15T16:47:57.605966+00:00",
      "latest_item_url": null,
      "product": "mistune",
      "public_safe_summary": "NVD: Mistune is a Python Markdown parser with renderers and plugins. NVD: Prior to 3.3.0, Include.parse() joins and normalizes user-supplied include paths without verifying that the result remains within the intended markdown directory, allowing crafted include paths to access files outside that directory when markdown files are... NVD: This issue is fixed in version 3.3.0.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260715T164957Z/items/CVE-2026-59924.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: mistune_project / mistune",
      "source_published_impact": "Source describes path traversal review. Possible impact: An attacker may be able to reach files outside the intended application path.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: Mistune is a Python Markdown parser with renderers and plugins. NVD: Prior to 3.3.0, Include.parse() joins and normalizes user-supplied include paths without verifying that the result remains within the intended markdown directory, allowing crafted include paths to access files outside that directory when markdown files are... NVD: This issue is fixed in version 3.3.0.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-59924/timeline.json",
      "vendor": "mistune_project"
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-59954/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.426,
      "epss_score": 0.00549,
      "first_observed_at": "2026-07-22T16:52:32.770874+00:00",
      "id": "CVE-2026-59954",
      "impact_tags": [
        "unauthorized access risk",
        "authentication boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-22T16:52:32.770874+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Apollo is a reliable configuration management system suitable for microservice configuration management scenarios. NVD: Prior to 2.5.2, Apollo ConfigService may allow unauthorized access to configuration data when AccessKey or management key authentication is enabled because ConfigService can accept a non-canonical appId variant during authentication while downstream request... NVD: This issue is fixed in version 2.5.2.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260722T165509Z/items/CVE-2026-59954.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes unauthorized access risk · authentication boundary review. Possible impact: An attacker may access resources that should require stronger authorization.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: Apollo is a reliable configuration management system suitable for microservice configuration management scenarios. NVD: Prior to 2.5.2, Apollo ConfigService may allow unauthorized access to configuration data when AccessKey or management key authentication is enabled because ConfigService can accept a non-canonical appId variant during authentication while downstream request... NVD: This issue is fixed in version 2.5.2.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-59954/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-59955/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.42601,
      "epss_score": 0.00549,
      "first_observed_at": "2026-07-22T16:52:32.770874+00:00",
      "id": "CVE-2026-59955",
      "impact_tags": [
        "unauthorized access risk",
        "authentication boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-22T16:52:32.770874+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Apollo is a reliable configuration management system suitable for microservice configuration management scenarios. NVD: Prior to 2.5.2, Apollo ConfigService may allow unauthorized access to raw configuration data when AccessKey or management key authentication is enabled because requests under /configfiles/raw/{appId}/{clusterName}/{namespace} are parsed for authentication as... NVD: This issue is fixed in version 2.5.2.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260722T165509Z/items/CVE-2026-59955.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes unauthorized access risk · authentication boundary review. Possible impact: An attacker may access resources that should require stronger authorization.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: Apollo is a reliable configuration management system suitable for microservice configuration management scenarios. NVD: Prior to 2.5.2, Apollo ConfigService may allow unauthorized access to raw configuration data when AccessKey or management key authentication is enabled because requests under /configfiles/raw/{appId}/{clusterName}/{namespace} are parsed for authentication as... NVD: This issue is fixed in version 2.5.2.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-59955/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "eclipse / milo",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-60007/",
      "current_public_safe_latest": false,
      "cvss_score": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.31124,
      "epss_score": 0.00383,
      "first_observed_at": "2026-08-11T10:14:04.199465+00:00",
      "id": "CVE-2026-60007",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-11T10:14:04.199465+00:00",
      "latest_item_url": null,
      "product": "milo",
      "public_safe_summary": "NVD: In Eclipse Milo versions 0.6.0 through 1.1.4, username-token processing returns distinguishable errors for invalid RSA PKCS#1 v1.5 padding and other authentication failures, allowing an on-path attacker who captures a victim's Basic128Rsa15-encrypted username... OSV: In Eclipse Milo versions 0.6.0 through 1.1.4, username-token processing returns distinguishable errors for invalid RSA PKCS#1 v1.5 padding and other authentication failures, allowing an on-path attacker who captures a victim's Basic128Rsa15-encrypted username...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260811T102539Z/items/CVE-2026-60007.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: eclipse / milo",
      "source_published_impact": "This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: In Eclipse Milo versions 0.6.0 through 1.1.4, username-token processing returns distinguishable errors for invalid RSA PKCS#1 v1.5 padding and other authentication failures, allowing an on-path attacker who captures a victim's Basic128Rsa15-encrypted username... OSV: In Eclipse Milo versions 0.6.0 through 1.1.4, username-token processing returns distinguishable errors for invalid RSA PKCS#1 v1.5 padding and other authentication failures, allowing an on-path attacker who captures a victim's Basic128Rsa15-encrypted username...",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-60007/timeline.json",
      "vendor": "eclipse"
    },
    {
      "affected_label": "eclipse / theia",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-60009/",
      "current_public_safe_latest": true,
      "cvss_score": 8.8,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.24854,
      "epss_score": 0.00323,
      "first_observed_at": "2026-08-12T10:29:37.194110+00:00",
      "id": "CVE-2026-60009",
      "impact_tags": [
        "code execution review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-12T10:29:37.194110+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-60009.json",
      "product": "theia",
      "public_safe_summary": "NVD: In Eclipse Theia versions up to and including 1.73.1, the @theia/filesystem backend binds POST /file-upload in every filesystem-enabled deployment. NVD: The handler takes an attacker-supplied absolute path from the multipart uri field and calls fs.move(tmp, target, { overwrite: true }) with no workspace confinement and no authentication. NVD: In browser (non-Electron) deployments the connection token is enforced only on WebSocket upgrades; the HTTP middleware in @theia/core re-issues the cookie and calls next() without rejecting tokenless HTTP requests.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260812T103932Z/items/CVE-2026-60009.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: eclipse / theia",
      "source_published_impact": "Source describes code execution review. Possible impact: An attacker may be able to run code or commands on affected systems.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: In Eclipse Theia versions up to and including 1.73.1, the @theia/filesystem backend binds POST /file-upload in every filesystem-enabled deployment. NVD: The handler takes an attacker-supplied absolute path from the multipart uri field and calls fs.move(tmp, target, { overwrite: true }) with no workspace confinement and no authentication. NVD: In browser (non-Electron) deployments the connection token is enforced only on WebSocket upgrades; the HTTP middleware in @theia/core re-issues the cookie and calls next() without rejecting tokenless HTTP requests.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-60009/timeline.json",
      "vendor": "eclipse"
    },
    {
      "affected_label": "apache / fory",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-60080/",
      "current_public_safe_latest": false,
      "cvss_score": 7.3,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.13177,
      "epss_score": 0.00224,
      "first_observed_at": "2026-07-28T11:30:16.925551+00:00",
      "id": "CVE-2026-60080",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-28T11:30:16.925551+00:00",
      "latest_item_url": null,
      "product": "fory",
      "public_safe_summary": "NVD: Use After Free vulnerability in the Rust deserialization logic of Apache Fory. NVD: This issue affects Apache Fory from 0.13.0 through 1.3.0. NVD: Users are recommended to upgrade to version 1.4.0, which fixes the issue.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260728T113720Z/items/CVE-2026-60080.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: apache / fory",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: Use After Free vulnerability in the Rust deserialization logic of Apache Fory. NVD: This issue affects Apache Fory from 0.13.0 through 1.3.0. NVD: Users are recommended to upgrade to version 1.4.0, which fixes the issue.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-60080/timeline.json",
      "vendor": "apache"
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-60085/",
      "current_public_safe_latest": false,
      "cvss_score": 8.7,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.15302,
      "epss_score": 0.00241,
      "first_observed_at": "2026-07-22T11:51:23.239908+00:00",
      "id": "CVE-2026-60085",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-22T11:51:23.239908+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: PraisonAI before 4.6.78 contains an unenforced security policy vulnerability in the default Subprocess Sandbox backend where blocked_commands, blocked_paths, blocked_imports, allow_subprocess, and allow_file_write restrictions are completely ignored. NVD: Attackers can execute arbitrary subprocess commands, read sensitive files, and perform destructive operations despite explicit security policy configuration. OSV: PraisonAI before 4.6.78 Unenforced Security Policy in Subprocess Sandbox",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260722T115421Z/items/CVE-2026-60085.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: PraisonAI before 4.6.78 contains an unenforced security policy vulnerability in the default Subprocess Sandbox backend where blocked_commands, blocked_paths, blocked_imports, allow_subprocess, and allow_file_write restrictions are completely ignored. NVD: Attackers can execute arbitrary subprocess commands, read sensitive files, and perform destructive operations despite explicit security policy configuration. OSV: PraisonAI before 4.6.78 Unenforced Security Policy in Subprocess Sandbox",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-60085/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-60087/",
      "current_public_safe_latest": false,
      "cvss_score": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.08759,
      "epss_score": 0.00189,
      "first_observed_at": "2026-07-22T11:51:23.239908+00:00",
      "id": "CVE-2026-60087",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-22T11:51:23.239908+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: PraisonAI before 1.6.78 caches tool approval decisions by tool name only, allowing attackers to reuse initial approvals for subsequent calls with arbitrary arguments. NVD: Attackers can exploit this by obtaining approval for a benign operation and then executing dangerous file write operations with unreviewed parameters in the same session.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260722T115421Z/items/CVE-2026-60087.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: PraisonAI before 1.6.78 caches tool approval decisions by tool name only, allowing attackers to reuse initial approvals for subsequent calls with arbitrary arguments. NVD: Attackers can exploit this by obtaining approval for a benign operation and then executing dangerous file write operations with unreviewed parameters in the same session.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-60087/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-60088/",
      "current_public_safe_latest": false,
      "cvss_score": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.04333,
      "epss_score": 0.00147,
      "first_observed_at": "2026-07-18T08:01:52.653915+00:00",
      "id": "CVE-2026-60088",
      "impact_tags": [
        "path traversal review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-18T10:42:57.422810+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: PraisonAI before 4.6.78 fails to validate file path references in custom command templates, allowing attackers to read files outside the workspace. NVD: Attackers can include path traversal sequences like @../outside_secret.txt or absolute paths in project command files to exfiltrate process-readable files into model prompts. OSV: PraisonAI before 4.6.78 Path Traversal via Custom Commands",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260718T104447Z/items/CVE-2026-60088.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 4,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes path traversal review. Possible impact: An attacker may be able to reach files outside the intended application path.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: PraisonAI before 4.6.78 fails to validate file path references in custom command templates, allowing attackers to read files outside the workspace. NVD: Attackers can include path traversal sequences like @../outside_secret.txt or absolute paths in project command files to exfiltrate process-readable files into model prompts. OSV: PraisonAI before 4.6.78 Path Traversal via Custom Commands",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-60088/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-60090/",
      "current_public_safe_latest": false,
      "cvss_score": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.3323,
      "epss_score": 0.0041,
      "first_observed_at": "2026-07-18T08:01:52.653915+00:00",
      "id": "CVE-2026-60090",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-18T10:42:57.422810+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: PraisonAI before 4.6.78 fails to validate the caller-controlled dimension argument in the PGVector and Cassandra knowledge-store create_collection() backends. NVD: Although schema, keyspace, and collection-name identifiers are validated, the dimension value (declared as int but not enforced at runtime) is interpolated directly into the vector column of the generated CREATE TABLE DDL. NVD: A caller able to influence collection-creation dimensions can pass a string such as '3); DROP TABLE tenant_secrets; --' to inject SQL/CQL tokens into the statement executed by the database driver.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260718T104447Z/items/CVE-2026-60090.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 4,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: PraisonAI before 4.6.78 fails to validate the caller-controlled dimension argument in the PGVector and Cassandra knowledge-store create_collection() backends. NVD: Although schema, keyspace, and collection-name identifiers are validated, the dimension value (declared as int but not enforced at runtime) is interpolated directly into the vector column of the generated CREATE TABLE DDL. NVD: A caller able to influence collection-creation dimensions can pass a string such as '3); DROP TABLE tenant_secrets; --' to inject SQL/CQL tokens into the statement executed by the database driver.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-60090/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-60094/",
      "current_public_safe_latest": false,
      "cvss_score": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.33231,
      "epss_score": 0.00411,
      "first_observed_at": "2026-07-16T13:54:14.110513+00:00",
      "id": "CVE-2026-60094",
      "impact_tags": [
        "memory safety review",
        "remote exposure relevant"
      ],
      "kev": false,
      "last_observed_at": "2026-07-16T13:54:14.110513+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Vinchin Backup & Recovery through 9.0.0.86562 contains a heap buffer overflow vulnerability that allows unauthenticated remote attackers to cause process crash or memory corruption by sending a malformed TCP packet with an unchecked body_len field to the... NVD: Attackers can craft a malicious packet that passes an attacker-controlled length directly to recv(), triggering a heap overflow of up to approximately 4 GiB and resulting in process crash or potential memory corruption.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260716T135621Z/items/CVE-2026-60094.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes memory safety review · remote exposure. Possible impact: The affected component has memory-safety risk that may lead to crash, privilege, or code-execution impact depending on exposure.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Vinchin Backup & Recovery through 9.0.0.86562 contains a heap buffer overflow vulnerability that allows unauthenticated remote attackers to cause process crash or memory corruption by sending a malformed TCP packet with an unchecked body_len field to the... NVD: Attackers can craft a malicious packet that passes an attacker-controlled length directly to recv(), triggering a heap overflow of up to approximately 4 GiB and resulting in process crash or potential memory corruption.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-60094/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-60095/",
      "current_public_safe_latest": false,
      "cvss_score": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.37184,
      "epss_score": 0.00463,
      "first_observed_at": "2026-07-16T13:54:14.110513+00:00",
      "id": "CVE-2026-60095",
      "impact_tags": [
        "memory safety review",
        "remote exposure relevant"
      ],
      "kev": false,
      "last_observed_at": "2026-07-16T13:54:14.110513+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Vinchin Backup & Recovery through 9.0.0.86562 contains a stack buffer overflow vulnerability in the ModuleHandShake function of the agentlink_server service that allows unauthenticated remote attackers to overwrite the saved return address by supplying an... NVD: Attackers can send a crafted request with a malicious _listen_uuid value to corrupt the stack and achieve process crash or potential control flow hijack without requiring authentication.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260716T135621Z/items/CVE-2026-60095.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes memory safety review · remote exposure. Possible impact: The affected component has memory-safety risk that may lead to crash, privilege, or code-execution impact depending on exposure.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Vinchin Backup & Recovery through 9.0.0.86562 contains a stack buffer overflow vulnerability in the ModuleHandShake function of the agentlink_server service that allows unauthenticated remote attackers to overwrite the saved return address by supplying an... NVD: Attackers can send a crafted request with a malicious _listen_uuid value to corrupt the stack and achieve process crash or potential control flow hijack without requiring authentication.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-60095/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "zeek / zeek",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-60108/",
      "current_public_safe_latest": false,
      "cvss_score": 8.7,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.35298,
      "epss_score": 0.00436,
      "first_observed_at": "2026-07-16T13:54:14.110513+00:00",
      "id": "CVE-2026-60108",
      "impact_tags": [
        "service availability review",
        "remote exposure relevant"
      ],
      "kev": false,
      "last_observed_at": "2026-07-16T13:54:14.110513+00:00",
      "latest_item_url": null,
      "product": "zeek",
      "public_safe_summary": "NVD: Zeek before 8.0.9 contains an uncontrolled memory consumption vulnerability in the FTP analyzer that allows unauthenticated remote attackers to cause process termination by sending a crafted FTP control session negotiating AUTH GSSAPI followed by a large ADAT... NVD: Attackers can exploit the NVT_Analyzer component's lack of a maximum line length check, causing it to continuously double its internal buffer without bounds during base64 decoding of an attacker-controlled ADAT token, resulting in denial of service of the... OSV: Zeek < 8.0.9 Uncontrolled Memory Consumption DoS via FTP Analyzer",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260716T135621Z/items/CVE-2026-60108.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: zeek / zeek",
      "source_published_impact": "Source describes service availability risk · remote exposure. Possible impact: The affected service may become unavailable or unreliable.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Zeek before 8.0.9 contains an uncontrolled memory consumption vulnerability in the FTP analyzer that allows unauthenticated remote attackers to cause process termination by sending a crafted FTP control session negotiating AUTH GSSAPI followed by a large ADAT... NVD: Attackers can exploit the NVT_Analyzer component's lack of a maximum line length check, causing it to continuously double its internal buffer without bounds during base64 decoding of an attacker-controlled ADAT token, resulting in denial of service of the... OSV: Zeek < 8.0.9 Uncontrolled Memory Consumption DoS via FTP Analyzer",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-60108/timeline.json",
      "vendor": "zeek"
    },
    {
      "affected_label": "zeek / zeek",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-60109/",
      "current_public_safe_latest": false,
      "cvss_score": 8.7,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.39531,
      "epss_score": 0.00502,
      "first_observed_at": "2026-07-16T13:54:14.110513+00:00",
      "id": "CVE-2026-60109",
      "impact_tags": [
        "service availability review",
        "remote exposure relevant"
      ],
      "kev": false,
      "last_observed_at": "2026-07-16T13:54:14.110513+00:00",
      "latest_item_url": null,
      "product": "zeek",
      "public_safe_summary": "NVD: Zeek before 8.0.9 contains a null pointer dereference vulnerability in its Kerberos protocol analyzer that allows unauthenticated remote attackers to crash the sensor by sending a crafted KRB_ERROR message with error-code 25 (KDC_ERR_PREAUTH_REQUIRED)... NVD: Attackers can exploit a parser and analyzer state mismatch where proc_padata() dereferences an uninitialized pa_data_element field selected by the wrong parsing arm, triggering a crash via a single UDP or TCP packet to port 88 without any credentials or prior... OSV: Zeek < 8.0.9 Null Pointer Dereference DoS via Kerberos KRB_ERROR Parsing",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260716T135621Z/items/CVE-2026-60109.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: zeek / zeek",
      "source_published_impact": "Source describes service availability risk · remote exposure. Possible impact: The affected service may become unavailable or unreliable.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Zeek before 8.0.9 contains a null pointer dereference vulnerability in its Kerberos protocol analyzer that allows unauthenticated remote attackers to crash the sensor by sending a crafted KRB_ERROR message with error-code 25 (KDC_ERR_PREAUTH_REQUIRED)... NVD: Attackers can exploit a parser and analyzer state mismatch where proc_padata() dereferences an uninitialized pa_data_element field selected by the wrong parsing arm, triggering a crash via a single UDP or TCP packet to port 88 without any credentials or prior... OSV: Zeek < 8.0.9 Null Pointer Dereference DoS via Kerberos KRB_ERROR Parsing",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-60109/timeline.json",
      "vendor": "zeek"
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-60121/",
      "current_public_safe_latest": false,
      "cvss_score": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.69253,
      "epss_score": 0.01389,
      "first_observed_at": "2026-07-20T11:59:42.107493+00:00",
      "id": "CVE-2026-60121",
      "impact_tags": [
        "admin privilege risk",
        "command injection risk",
        "remote exposure relevant"
      ],
      "kev": false,
      "last_observed_at": "2026-07-20T11:59:42.107493+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Vitec Flamingo 4.12.2 contains an unauthenticated OS command injection vulnerability in the admin/ajax/ping.php endpoint that allows remote attackers to execute arbitrary commands by exploiting a double-evaluation flaw in shell argument handling. NVD: The endpoint applies escapeshellarg() to the user-supplied host POST parameter before passing it to a system wrapper, but the wrapper retrieves the decoded value from argv and incorporates it into a second shell_exec() call without escaping, allowing injected...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260720T120206Z/items/CVE-2026-60121.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes admin privilege risk · command injection risk · remote exposure. Possible impact: A remote attacker may gain root or administrative-level privileges on affected systems.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Vitec Flamingo 4.12.2 contains an unauthenticated OS command injection vulnerability in the admin/ajax/ping.php endpoint that allows remote attackers to execute arbitrary commands by exploiting a double-evaluation flaw in shell argument handling. NVD: The endpoint applies escapeshellarg() to the user-supplied host POST parameter before passing it to a system wrapper, but the wrapper retrieves the decoded value from argv and incorporates it into a second shell_exec() call without escaping, allowing injected...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-60121/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-60134/",
      "current_public_safe_latest": false,
      "cvss_score": 8.7,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.23892,
      "epss_score": 0.00315,
      "first_observed_at": "2026-07-31T22:17:39.455090+00:00",
      "id": "CVE-2026-60134",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-31T22:17:39.455090+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Weintek cMT3092X HMI allows a non-privileged user to modify cookies to gain elevated privileges.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260731T222222Z/items/CVE-2026-60134.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Weintek cMT3092X HMI allows a non-privileged user to modify cookies to gain elevated privileges.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-60134/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-60135/",
      "current_public_safe_latest": false,
      "cvss_score": 7.1,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.11786,
      "epss_score": 0.00213,
      "first_observed_at": "2026-07-31T22:17:39.455090+00:00",
      "id": "CVE-2026-60135",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-31T22:17:39.455090+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: An attacker can modify data that should be restricted to read‑only access.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260731T222222Z/items/CVE-2026-60135.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: An attacker can modify data that should be restricted to read‑only access.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-60135/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "oracle / platform_security_for_java",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-60366/",
      "current_public_safe_latest": false,
      "cvss_score": 10.0,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.23403,
      "epss_score": 0.0031,
      "first_observed_at": "2026-07-29T22:16:26.828679+00:00",
      "id": "CVE-2026-60366",
      "impact_tags": [
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-29T22:16:26.828679+00:00",
      "latest_item_url": null,
      "product": "platform_security_for_java",
      "public_safe_summary": "NVD: Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). NVD: Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. NVD: Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Platform Security for Java.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260729T222441Z/items/CVE-2026-60366.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: oracle / platform_security_for_java; affected version context: 12.2.1.4.0, 14.1.2.0.0",
      "source_published_impact": "Source describes remote exposure · authenticated boundary. Possible impact: This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). NVD: Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. NVD: Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Platform Security for Java.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-60366/timeline.json",
      "vendor": "oracle"
    },
    {
      "affected_label": "oracle / platform_security_for_java",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-60367/",
      "current_public_safe_latest": false,
      "cvss_score": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.24062,
      "epss_score": 0.00317,
      "first_observed_at": "2026-07-29T22:16:26.828679+00:00",
      "id": "CVE-2026-60367",
      "impact_tags": [
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-29T22:16:26.828679+00:00",
      "latest_item_url": null,
      "product": "platform_security_for_java",
      "public_safe_summary": "NVD: Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). NVD: Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. NVD: Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Platform Security for Java.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260729T222441Z/items/CVE-2026-60367.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: oracle / platform_security_for_java; affected version context: 12.2.1.4.0, 14.1.2.0.0",
      "source_published_impact": "Source describes remote exposure · authenticated boundary. Possible impact: This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). NVD: Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. NVD: Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Platform Security for Java.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-60367/timeline.json",
      "vendor": "oracle"
    },
    {
      "affected_label": "oracle / platform_security_for_java",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-60368/",
      "current_public_safe_latest": false,
      "cvss_score": 8.8,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.2334,
      "epss_score": 0.0031,
      "first_observed_at": "2026-07-29T22:16:26.828679+00:00",
      "id": "CVE-2026-60368",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-29T22:16:26.828679+00:00",
      "latest_item_url": null,
      "product": "platform_security_for_java",
      "public_safe_summary": "NVD: Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). NVD: Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. NVD: Easily exploitable vulnerability allows low privileged attacker with network access via SOAP to compromise Oracle Platform Security for Java.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260729T222441Z/items/CVE-2026-60368.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: oracle / platform_security_for_java; affected version context: 12.2.1.4.0, 14.1.2.0.0",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). NVD: Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. NVD: Easily exploitable vulnerability allows low privileged attacker with network access via SOAP to compromise Oracle Platform Security for Java.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-60368/timeline.json",
      "vendor": "oracle"
    },
    {
      "affected_label": "oracle / platform_security_for_java",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-60369/",
      "current_public_safe_latest": false,
      "cvss_score": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.20167,
      "epss_score": 0.00279,
      "first_observed_at": "2026-07-29T22:16:26.828679+00:00",
      "id": "CVE-2026-60369",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-29T22:16:26.828679+00:00",
      "latest_item_url": null,
      "product": "platform_security_for_java",
      "public_safe_summary": "NVD: Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). NVD: Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. NVD: Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Platform Security for Java.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260729T222441Z/items/CVE-2026-60369.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: oracle / platform_security_for_java; affected version context: 12.2.1.4.0, 14.1.2.0.0",
      "source_published_impact": "This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). NVD: Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. NVD: Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Platform Security for Java.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-60369/timeline.json",
      "vendor": "oracle"
    },
    {
      "affected_label": "oracle / platform_security_for_java",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-60370/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.10198,
      "epss_score": 0.00201,
      "first_observed_at": "2026-07-29T22:16:26.828679+00:00",
      "id": "CVE-2026-60370",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-29T22:16:26.828679+00:00",
      "latest_item_url": null,
      "product": "platform_security_for_java",
      "public_safe_summary": "NVD: Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). NVD: Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. NVD: Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Platform Security for Java.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260729T222441Z/items/CVE-2026-60370.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: oracle / platform_security_for_java; affected version context: 12.2.1.4.0, 14.1.2.0.0",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). NVD: Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. NVD: Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Platform Security for Java.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-60370/timeline.json",
      "vendor": "oracle"
    },
    {
      "affected_label": "oracle / platform_security_for_java",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-60371/",
      "current_public_safe_latest": false,
      "cvss_score": 8.0,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.06691,
      "epss_score": 0.0017,
      "first_observed_at": "2026-07-29T22:16:26.828679+00:00",
      "id": "CVE-2026-60371",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-29T22:16:26.828679+00:00",
      "latest_item_url": null,
      "product": "platform_security_for_java",
      "public_safe_summary": "NVD: Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). NVD: Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. NVD: Difficult to exploit vulnerability allows low privileged attacker with access to the physical communication segment attached to the hardware where the Oracle Platform Security for Java executes to compromise Oracle Platform Security for Java.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260729T222441Z/items/CVE-2026-60371.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: oracle / platform_security_for_java; affected version context: 12.2.1.4.0, 14.1.2.0.0",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). NVD: Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. NVD: Difficult to exploit vulnerability allows low privileged attacker with access to the physical communication segment attached to the hardware where the Oracle Platform Security for Java executes to compromise Oracle Platform Security for Java.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-60371/timeline.json",
      "vendor": "oracle"
    },
    {
      "affected_label": "oracle / platform_security_for_java",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-60372/",
      "current_public_safe_latest": false,
      "cvss_score": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.23402,
      "epss_score": 0.0031,
      "first_observed_at": "2026-07-29T22:16:26.828679+00:00",
      "id": "CVE-2026-60372",
      "impact_tags": [
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-29T22:16:26.828679+00:00",
      "latest_item_url": null,
      "product": "platform_security_for_java",
      "public_safe_summary": "NVD: Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). NVD: Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. NVD: Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Platform Security for Java.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260729T222441Z/items/CVE-2026-60372.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: oracle / platform_security_for_java; affected version context: 12.2.1.4.0, 14.1.2.0.0",
      "source_published_impact": "Source describes remote exposure · authenticated boundary. Possible impact: This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). NVD: Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. NVD: Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Platform Security for Java.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-60372/timeline.json",
      "vendor": "oracle"
    },
    {
      "affected_label": "oracle / platform_security_for_java",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-60373/",
      "current_public_safe_latest": false,
      "cvss_score": 8.8,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.20167,
      "epss_score": 0.00279,
      "first_observed_at": "2026-07-29T22:16:26.828679+00:00",
      "id": "CVE-2026-60373",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-29T22:16:26.828679+00:00",
      "latest_item_url": null,
      "product": "platform_security_for_java",
      "public_safe_summary": "NVD: Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). NVD: Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. NVD: Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Platform Security for Java.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260729T222441Z/items/CVE-2026-60373.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: oracle / platform_security_for_java; affected version context: 12.2.1.4.0, 14.1.2.0.0",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). NVD: Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. NVD: Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Platform Security for Java.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-60373/timeline.json",
      "vendor": "oracle"
    },
    {
      "affected_label": "oracle / platform_security_for_java",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-60439/",
      "current_public_safe_latest": false,
      "cvss_score": 8.8,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.1896,
      "epss_score": 0.0027,
      "first_observed_at": "2026-07-29T22:16:26.828679+00:00",
      "id": "CVE-2026-60439",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-29T22:16:26.828679+00:00",
      "latest_item_url": null,
      "product": "platform_security_for_java",
      "public_safe_summary": "NVD: Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). NVD: Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. NVD: Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Platform Security for Java.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260729T222441Z/items/CVE-2026-60439.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: oracle / platform_security_for_java; affected version context: 12.2.1.4.0, 14.1.2.0.0",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). NVD: Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. NVD: Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Platform Security for Java.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-60439/timeline.json",
      "vendor": "oracle"
    },
    {
      "affected_label": "oracle / platform_security_for_java",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-60455/",
      "current_public_safe_latest": false,
      "cvss_score": 8.8,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.15776,
      "epss_score": 0.00244,
      "first_observed_at": "2026-07-29T22:16:26.828679+00:00",
      "id": "CVE-2026-60455",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-29T22:16:26.828679+00:00",
      "latest_item_url": null,
      "product": "platform_security_for_java",
      "public_safe_summary": "NVD: Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). NVD: Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. NVD: Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Platform Security for Java.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260729T222441Z/items/CVE-2026-60455.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: oracle / platform_security_for_java; affected version context: 12.2.1.4.0, 14.1.2.0.0",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). NVD: Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. NVD: Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Platform Security for Java.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-60455/timeline.json",
      "vendor": "oracle"
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-6101/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.46715,
      "epss_score": 0.00646,
      "first_observed_at": "2026-07-14T10:57:43.777280+00:00",
      "id": "CVE-2026-6101",
      "impact_tags": [
        "code execution review",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-14T10:57:43.777280+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The AMP for WP – Accelerated Mobile Pages plugin for WordPress is vulnerable to Arbitrary File Write in versions up to and including 1.1.12. NVD: This is due to unsafe ZIP file extraction in the ampforwp_save_local_font() function combined with inadequate cleanup that fails to remove nested directories and files. NVD: This makes it possible for authenticated attackers, with Author-level access and above, and permissions granted by an Administrator, to write arbitrary files to the server in a web-accessible location, potentially leading to remote code execution on hosts...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260714T110007Z/items/CVE-2026-6101.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes code execution review · authenticated boundary. Possible impact: An attacker may be able to run code or commands on affected systems.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The AMP for WP – Accelerated Mobile Pages plugin for WordPress is vulnerable to Arbitrary File Write in versions up to and including 1.1.12. NVD: This is due to unsafe ZIP file extraction in the ampforwp_save_local_font() function combined with inadequate cleanup that fails to remove nested directories and files. NVD: This makes it possible for authenticated attackers, with Author-level access and above, and permissions granted by an Administrator, to write arbitrary files to the server in a web-accessible location, potentially leading to remote code execution on hosts...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-6101/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "oracle / platform_security_for_java",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-61246/",
      "current_public_safe_latest": false,
      "cvss_score": 8.8,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.18178,
      "epss_score": 0.00264,
      "first_observed_at": "2026-07-29T22:16:26.828679+00:00",
      "id": "CVE-2026-61246",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-29T22:16:26.828679+00:00",
      "latest_item_url": null,
      "product": "platform_security_for_java",
      "public_safe_summary": "NVD: Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). NVD: Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. NVD: Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Platform Security for Java.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260729T222441Z/items/CVE-2026-61246.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: oracle / platform_security_for_java; affected version context: 12.2.1.4.0, 14.1.2.0.0",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). NVD: Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. NVD: Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Platform Security for Java.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-61246/timeline.json",
      "vendor": "oracle"
    },
    {
      "affected_label": "apache / jena_fuseki",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-61372/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.43954,
      "epss_score": 0.00568,
      "first_observed_at": "2026-08-10T16:12:24.021737+00:00",
      "id": "CVE-2026-61372",
      "impact_tags": [
        "path traversal review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-10T16:12:24.021737+00:00",
      "latest_item_url": null,
      "product": "jena_fuseki",
      "public_safe_summary": "NVD: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache Jena Fuseki. NVD: This issue affects Apache Jena Fuseki: through 6.1.0. NVD: Users are recommended to upgrade to version 6.2.0, which fixes the issue.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260810T162156Z/items/CVE-2026-61372.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: apache / jena_fuseki",
      "source_published_impact": "Source describes path traversal review. Possible impact: An attacker may be able to reach files outside the intended application path.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache Jena Fuseki. NVD: This issue affects Apache Jena Fuseki: through 6.1.0. NVD: Users are recommended to upgrade to version 6.2.0, which fixes the issue.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-61372/timeline.json",
      "vendor": "apache"
    },
    {
      "affected_label": "eclipse / milo",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-61387/",
      "current_public_safe_latest": false,
      "cvss_score": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.27156,
      "epss_score": 0.00345,
      "first_observed_at": "2026-08-11T10:14:04.199465+00:00",
      "id": "CVE-2026-61387",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-11T10:14:04.199465+00:00",
      "latest_item_url": null,
      "product": "milo",
      "public_safe_summary": "NVD: In Eclipse Milo versions 1.0.0 through 1.1.4, monitored-item quota accounting is not exception-safe: if item creation fails with an unchecked error, the server-global reservation is not restored. NVD: Deeply nested PubSub ExtensionObjects in a CreateMonitoredItems event filter can trigger a StackOverflowError during decoding, allowing an unauthenticated remote client to exhaust a finite global monitored-item quota and prevent all clients from creating new... NVD: Existing monitored items and other server functions remain unaffected.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260811T102539Z/items/CVE-2026-61387.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: eclipse / milo",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: In Eclipse Milo versions 1.0.0 through 1.1.4, monitored-item quota accounting is not exception-safe: if item creation fails with an unchecked error, the server-global reservation is not restored. NVD: Deeply nested PubSub ExtensionObjects in a CreateMonitoredItems event filter can trigger a StackOverflowError during decoding, allowing an unauthenticated remote client to exhaust a finite global monitored-item quota and prevent all clients from creating new... NVD: Existing monitored items and other server functions remain unaffected.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-61387/timeline.json",
      "vendor": "eclipse"
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-61390/",
      "current_public_safe_latest": false,
      "cvss_score": 7.7,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.13667,
      "epss_score": 0.00228,
      "first_observed_at": "2026-07-29T11:36:18.065267+00:00",
      "id": "CVE-2026-61390",
      "impact_tags": [
        "memory safety review",
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-29T11:36:18.065267+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: There is a heap buffer overflow vulnerability in some Hikvision cameras, which may allow unauthenticated attackers to cause device malfunction by sending specially crafted packets.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260729T114432Z/items/CVE-2026-61390.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes memory safety review · remote exposure · authenticated boundary. Possible impact: The affected component has memory-safety risk that may lead to crash, privilege, or code-execution impact depending on exposure.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: There is a heap buffer overflow vulnerability in some Hikvision cameras, which may allow unauthenticated attackers to cause device malfunction by sending specially crafted packets.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-61390/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-61391/",
      "current_public_safe_latest": false,
      "cvss_score": 7.2,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.22745,
      "epss_score": 0.00304,
      "first_observed_at": "2026-07-29T11:36:18.065267+00:00",
      "id": "CVE-2026-61391",
      "impact_tags": [
        "memory safety review",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-29T11:36:18.065267+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: There is a stack-based buffer overflow vulnerability in some Hikvision cameras, which may allow authenticated attackers to cause device malfunction by sending specially crafted packets.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260729T114432Z/items/CVE-2026-61391.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes memory safety review · authenticated boundary. Possible impact: The affected component has memory-safety risk that may lead to crash, privilege, or code-execution impact depending on exposure.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: There is a stack-based buffer overflow vulnerability in some Hikvision cameras, which may allow authenticated attackers to cause device malfunction by sending specially crafted packets.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-61391/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-61392/",
      "current_public_safe_latest": false,
      "cvss_score": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.10911,
      "epss_score": 0.00206,
      "first_observed_at": "2026-07-29T11:36:18.065267+00:00",
      "id": "CVE-2026-61392",
      "impact_tags": [
        "information exposure review",
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-29T11:36:18.065267+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: There is a information disclosure vulnerability in some Hikvision cameras, allowing unauthenticated attackers to obtain partial information from the device’s memory.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260729T114432Z/items/CVE-2026-61392.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes information exposure review · remote exposure · authenticated boundary. Possible impact: A remote attacker may be able to access information that should not be exposed.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: There is a information disclosure vulnerability in some Hikvision cameras, allowing unauthenticated attackers to obtain partial information from the device’s memory.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-61392/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-61426/",
      "current_public_safe_latest": false,
      "cvss_score": 8.8,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.24348,
      "epss_score": 0.00322,
      "first_observed_at": "2026-07-18T08:01:52.653915+00:00",
      "id": "CVE-2026-61426",
      "impact_tags": [
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-18T10:42:57.422810+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: PraisonAI before 1.7.3 contains an insecure default configuration that binds to all interfaces with no API key requirement and wildcard CORS. NVD: Unauthenticated attackers can call GET /api/agents to read agent instructions and system prompts, or POST /api/chat to invoke agents without authentication.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260718T104447Z/items/CVE-2026-61426.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 4,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes remote exposure · authenticated boundary. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: PraisonAI before 1.7.3 contains an insecure default configuration that binds to all interfaces with no API key requirement and wildcard CORS. NVD: Unauthenticated attackers can call GET /api/agents to read agent instructions and system prompts, or POST /api/chat to invoke agents without authentication.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-61426/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-61427/",
      "current_public_safe_latest": false,
      "cvss_score": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.26091,
      "epss_score": 0.00338,
      "first_observed_at": "2026-07-22T11:51:23.239908+00:00",
      "id": "CVE-2026-61427",
      "impact_tags": [
        "authentication boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-22T11:51:23.239908+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: PraisonAI before 4.6.78 exposes the MCP HTTP-stream transport without authentication by default: the CLI --api-key option defaults to None, and the server only enforces Authorization/Bearer checks when an API key is configured. NVD: When an operator runs 'praisonai mcp serve --transport http-stream' without an API key, an unauthenticated client (no Authorization header, and no Origin header, which is also permitted) can initialize a session, enumerate the available tools (tools/list)... NVD: Additionally, the dispatcher forwards tool-call arguments to handlers without validating them against the advertised inputSchema.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260722T115421Z/items/CVE-2026-61427.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes authentication boundary review. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authentication boundary review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: PraisonAI before 4.6.78 exposes the MCP HTTP-stream transport without authentication by default: the CLI --api-key option defaults to None, and the server only enforces Authorization/Bearer checks when an API key is configured. NVD: When an operator runs 'praisonai mcp serve --transport http-stream' without an API key, an unauthenticated client (no Authorization header, and no Origin header, which is also permitted) can initialize a session, enumerate the available tools (tools/list)... NVD: Additionally, the dispatcher forwards tool-call arguments to handlers without validating them against the advertised inputSchema.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-61427/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-61428/",
      "current_public_safe_latest": false,
      "cvss_score": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.15761,
      "epss_score": 0.00246,
      "first_observed_at": "2026-07-18T08:01:52.653915+00:00",
      "id": "CVE-2026-61428",
      "impact_tags": [
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-18T10:42:57.422810+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: PraisonAI AgentMail versions before 4.6.78 lack signature verification in webhook mode, allowing unauthenticated attackers to inject messages with spoofed sender addresses. NVD: Attackers can POST crafted message.received events to the webhook endpoint to inject arbitrary content into the agent and trigger replies to attacker-controlled addresses, bypassing sender allow/block lists. OSV: PraisonAI AgentMail before 4.6.78 Message Injection via Webhook",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260718T104447Z/items/CVE-2026-61428.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 4,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes remote exposure · authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: PraisonAI AgentMail versions before 4.6.78 lack signature verification in webhook mode, allowing unauthenticated attackers to inject messages with spoofed sender addresses. NVD: Attackers can POST crafted message.received events to the webhook endpoint to inject arbitrary content into the agent and trigger replies to attacker-controlled addresses, bypassing sender allow/block lists. OSV: PraisonAI AgentMail before 4.6.78 Message Injection via Webhook",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-61428/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-61429/",
      "current_public_safe_latest": false,
      "cvss_score": 8.4,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.12649,
      "epss_score": 0.00221,
      "first_observed_at": "2026-07-18T08:01:52.653915+00:00",
      "id": "CVE-2026-61429",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-18T10:42:57.422810+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: PraisonAI versions before 1.6.78 contain a server-side request forgery vulnerability in the Crawl4AI/Chromium backend that allows attackers to bypass SSRF validation by exploiting DNS rebinding and HTTP redirects. NVD: Attackers can craft URLs that resolve to internal services after the initial validation check, enabling the headless browser to follow redirects and read internal responses including sensitive canary values.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260718T104447Z/items/CVE-2026-61429.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 4,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: PraisonAI versions before 1.6.78 contain a server-side request forgery vulnerability in the Crawl4AI/Chromium backend that allows attackers to bypass SSRF validation by exploiting DNS rebinding and HTTP redirects. NVD: Attackers can craft URLs that resolve to internal services after the initial validation check, enabling the headless browser to follow redirects and read internal responses including sensitive canary values.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-61429/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-61430/",
      "current_public_safe_latest": false,
      "cvss_score": 8.4,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.10655,
      "epss_score": 0.00205,
      "first_observed_at": "2026-07-22T11:51:23.239908+00:00",
      "id": "CVE-2026-61430",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-22T11:51:23.239908+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: PraisonAI before 1.6.78 contains a server-side request forgery vulnerability in the web_crawl tool that validates hostnames at check time but re-resolves them at connection time without IP pinning. NVD: Attackers can use DNS rebinding to bypass SSRF protection and retrieve internal HTTP response bodies from private or loopback services.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260722T115421Z/items/CVE-2026-61430.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: PraisonAI before 1.6.78 contains a server-side request forgery vulnerability in the web_crawl tool that validates hostnames at check time but re-resolves them at connection time without IP pinning. NVD: Attackers can use DNS rebinding to bypass SSRF protection and retrieve internal HTTP response bodies from private or loopback services.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-61430/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-61433/",
      "current_public_safe_latest": false,
      "cvss_score": 8.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.04085,
      "epss_score": 0.00144,
      "first_observed_at": "2026-07-22T11:51:23.239908+00:00",
      "id": "CVE-2026-61433",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-22T11:51:23.239908+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: PraisonAI before 4.6.78 fails to safely encode deployment configuration values when generating Python source code for API servers. NVD: Attackers can inject arbitrary Python expressions through the deploy.api.host and agents_file configuration parameters that execute when the generated server starts or handles requests. OSV: PraisonAI before 4.6.78 Code Injection via API deployment generator",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260722T115421Z/items/CVE-2026-61433.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: PraisonAI before 4.6.78 fails to safely encode deployment configuration values when generating Python source code for API servers. NVD: Attackers can inject arbitrary Python expressions through the deploy.api.host and agents_file configuration parameters that execute when the generated server starts or handles requests. OSV: PraisonAI before 4.6.78 Code Injection via API deployment generator",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-61433/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-61435/",
      "current_public_safe_latest": false,
      "cvss_score": 8.8,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.30715,
      "epss_score": 0.00384,
      "first_observed_at": "2026-07-22T11:51:23.239908+00:00",
      "id": "CVE-2026-61435",
      "impact_tags": [
        "authentication boundary review",
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-22T11:51:23.239908+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: PraisonAI before 4.6.78 contains an authentication bypass in the Call API agent invocation endpoints (src/praisonai/praisonai/api/agent_invoke.py) when PRAISONAI_CALL_AUTH=disabled is configured. NVD: The safeguard intended to restrict the disabled-auth opt-out to localhost binding derives the bind host from request.url.hostname, which is taken from the client-controlled HTTP Host header. NVD: A remote, unauthenticated attacker who can reach the service over the network can send a spoofed 'Host: 127.0.0.1' header to bypass the localhost-only restriction and list (GET /api/v1/agents) and invoke (POST /api/v1/agents/{agent_id}/invoke) registered...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260722T115421Z/items/CVE-2026-61435.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes authentication boundary review · remote exposure · authenticated boundary. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authentication boundary review · remote exposure · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: PraisonAI before 4.6.78 contains an authentication bypass in the Call API agent invocation endpoints (src/praisonai/praisonai/api/agent_invoke.py) when PRAISONAI_CALL_AUTH=disabled is configured. NVD: The safeguard intended to restrict the disabled-auth opt-out to localhost binding derives the bind host from request.url.hostname, which is taken from the client-controlled HTTP Host header. NVD: A remote, unauthenticated attacker who can reach the service over the network can send a spoofed 'Host: 127.0.0.1' header to bypass the localhost-only restriction and list (GET /api/v1/agents) and invoke (POST /api/v1/agents/{agent_id}/invoke) registered...",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-61435/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-61439/",
      "current_public_safe_latest": false,
      "cvss_score": 8.7,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.17493,
      "epss_score": 0.0026,
      "first_observed_at": "2026-07-18T08:01:52.653915+00:00",
      "id": "CVE-2026-61439",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-18T10:42:57.422810+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: PraisonAI versions before 4.6.78 contain a prompt injection defense misconfiguration where the block threshold defaults to CRITICAL severity, allowing HIGH-level threats to pass through unblocked. NVD: Attackers can submit single-vector prompt injection attacks such as instruction overrides or financial manipulation that trigger HIGH severity detection but are logged without blocking, enabling system prompt extraction and unauthorized tool invocations. OSV: PraisonAI before 4.6.78 Prompt Injection Defense Bypass",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260718T104447Z/items/CVE-2026-61439.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 4,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: PraisonAI versions before 4.6.78 contain a prompt injection defense misconfiguration where the block threshold defaults to CRITICAL severity, allowing HIGH-level threats to pass through unblocked. NVD: Attackers can submit single-vector prompt injection attacks such as instruction overrides or financial manipulation that trigger HIGH severity detection but are logged without blocking, enabling system prompt extraction and unauthorized tool invocations. OSV: PraisonAI before 4.6.78 Prompt Injection Defense Bypass",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-61439/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-61442/",
      "current_public_safe_latest": false,
      "cvss_score": 7.1,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.17028,
      "epss_score": 0.00256,
      "first_observed_at": "2026-07-18T08:01:52.653915+00:00",
      "id": "CVE-2026-61442",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-18T10:42:57.422810+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: PraisonAI Platform (praisonai-platform) before 0.1.9 fails to enforce owner/admin authorization on the PATCH routes for projects, issues, and agents, which only require workspace-member role. NVD: A workspace member can modify owner-created records; for projects, a member can reassign lead_id to their own user id and then delete the owner-created project, bypassing the delete route's owner/admin permission check. OSV: PraisonAI Platform before 0.1.9 Authorization Bypass via PATCH",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260718T104447Z/items/CVE-2026-61442.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 4,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: PraisonAI Platform (praisonai-platform) before 0.1.9 fails to enforce owner/admin authorization on the PATCH routes for projects, issues, and agents, which only require workspace-member role. NVD: A workspace member can modify owner-created records; for projects, a member can reassign lead_id to their own user id and then delete the owner-created project, bypassing the delete route's owner/admin permission check. OSV: PraisonAI Platform before 0.1.9 Authorization Bypass via PATCH",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-61442/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-61445/",
      "current_public_safe_latest": false,
      "cvss_score": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.41687,
      "epss_score": 0.00538,
      "first_observed_at": "2026-07-18T08:01:52.653915+00:00",
      "id": "CVE-2026-61445",
      "impact_tags": [
        "command execution review",
        "admin privilege risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-18T10:42:57.422810+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: PraisonAI before 4.6.78 contains arbitrary file write and command execution vulnerabilities in the AICoder component due to missing path validation and command sanitization in LLM tool calls. NVD: Attackers can inject malicious prompts through the chat interface to write files to arbitrary filesystem locations and execute arbitrary shell commands with root privileges. OSV: PraisonAI before 4.6.78 Arbitrary File Write and Command Execution",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260718T104447Z/items/CVE-2026-61445.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 4,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes command execution risk · admin privilege risk. Possible impact: An attacker may gain root or administrative-level privileges on affected systems.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: PraisonAI before 4.6.78 contains arbitrary file write and command execution vulnerabilities in the AICoder component due to missing path validation and command sanitization in LLM tool calls. NVD: Attackers can inject malicious prompts through the chat interface to write files to arbitrary filesystem locations and execute arbitrary shell commands with root privileges. OSV: PraisonAI before 4.6.78 Arbitrary File Write and Command Execution",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-61445/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-61447/",
      "current_public_safe_latest": false,
      "cvss_score": 10.0,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.42021,
      "epss_score": 0.00544,
      "first_observed_at": "2026-07-18T08:01:52.653915+00:00",
      "id": "CVE-2026-61447",
      "impact_tags": [
        "code execution review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-18T10:42:57.422810+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: PraisonAI before 1.6.78 contains a remote code execution vulnerability in CodeAgent._execute_python() that executes LLM-generated Python code without AST validation, import restrictions, or sandbox enforcement. NVD: Attackers can influence LLM output through prompt injection to exfiltrate all environment secrets and execute arbitrary code on the host system.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260718T104447Z/items/CVE-2026-61447.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 4,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes code execution review. Possible impact: An attacker may be able to run code or commands on affected systems.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: PraisonAI before 1.6.78 contains a remote code execution vulnerability in CodeAgent._execute_python() that executes LLM-generated Python code without AST validation, import restrictions, or sandbox enforcement. NVD: Attackers can influence LLM output through prompt injection to exfiltrate all environment secrets and execute arbitrary code on the host system.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-61447/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-61448/",
      "current_public_safe_latest": false,
      "cvss_score": 2.1,
      "cvss_severity": "LOW",
      "epss_percentile": 0.15628,
      "epss_score": 0.00245,
      "first_observed_at": "2026-07-18T08:01:52.653915+00:00",
      "id": "CVE-2026-61448",
      "impact_tags": [
        "XSS risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-18T10:42:57.422810+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Parse Server is affected by a stored cross-site scripting (XSS) vulnerability in versions >= 9.0.0, < 9.10.0-alpha.2 and <= 8.6.83. NVD: When an uploaded file's extension is not recognized by the mime package, Parse Server preserves the client-supplied Content-Type. NVD: A malformed Content-Type that is not a valid type/subtype media type (e.g., 'image', 'image/', or 'image//svg+xml') bypasses the fileUpload.fileExtensions blocklist and is stored unchanged.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260718T104447Z/items/CVE-2026-61448.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 4,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes XSS risk. Possible impact: This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: 9.10.0-alpha.2.",
      "source_published_summary": "NVD: Parse Server is affected by a stored cross-site scripting (XSS) vulnerability in versions >= 9.0.0, < 9.10.0-alpha.2 and <= 8.6.83. NVD: When an uploaded file's extension is not recognized by the mime package, Parse Server preserves the client-supplied Content-Type. NVD: A malformed Content-Type that is not a valid type/subtype media type (e.g., 'image', 'image/', or 'image//svg+xml') bypasses the fileUpload.fileExtensions blocklist and is stored unchanged.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-61448/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-61454/",
      "current_public_safe_latest": false,
      "cvss_score": 8.7,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.14949,
      "epss_score": 0.00239,
      "first_observed_at": "2026-07-18T08:01:52.653915+00:00",
      "id": "CVE-2026-61454",
      "impact_tags": [
        "information exposure review",
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-18T10:42:57.422810+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Grav Admin2 plugin (getgrav/grav-plugin-admin2) before 2.0.4 embeds a global JavaScript variable window.__GRAV_CONFIG__ in the Admin2 SPA bootstrap page at /grav/admin (and its subroutes). NVD: This object is returned in every unauthenticated response and discloses the server URL, API prefix, admin base path, runtime environment type, and exact Grav and Admin2 version numbers, allowing an unauthenticated attacker to fingerprint the deployment and... OSV: Grav before 2.0.4 Information Disclosure via __GRAV_CONFIG__",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260718T104447Z/items/CVE-2026-61454.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 4,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes information exposure review · remote exposure · authenticated boundary. Possible impact: A remote attacker may be able to access information that should not be exposed.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Grav Admin2 plugin (getgrav/grav-plugin-admin2) before 2.0.4 embeds a global JavaScript variable window.__GRAV_CONFIG__ in the Admin2 SPA bootstrap page at /grav/admin (and its subroutes). NVD: This object is returned in every unauthenticated response and discloses the server URL, API prefix, admin base path, runtime environment type, and exact Grav and Admin2 version numbers, allowing an unauthenticated attacker to fingerprint the deployment and... OSV: Grav before 2.0.4 Information Disclosure via __GRAV_CONFIG__",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-61454/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "imagemagick / imagemagick",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-61465/",
      "current_public_safe_latest": false,
      "cvss_score": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.06905,
      "epss_score": 0.00173,
      "first_observed_at": "2026-07-18T08:01:52.653915+00:00",
      "id": "CVE-2026-61465",
      "impact_tags": [
        "service availability review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-18T10:42:57.422810+00:00",
      "latest_item_url": null,
      "product": "imagemagick",
      "public_safe_summary": "NVD: ImageMagick before 7.1.2-26 and 6.9.13-51 is missing a check for the allowed memory allocation limit in matrix-backed operations such as -canny. NVD: An attacker can supply a crafted image that causes ImageMagick to allocate more memory than permitted by the configured policy, resulting in a denial of service. OSV: ImageMagick before 7.1.2-26 Memory Allocation Policy Bypass",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260718T104447Z/items/CVE-2026-61465.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 4,
      "source_published_affected": "vendor/product: imagemagick / imagemagick",
      "source_published_impact": "Source describes service availability risk. Possible impact: The affected service may become unavailable or unreliable.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: ImageMagick before 7.1.2-26 and 6.9.13-51 is missing a check for the allowed memory allocation limit in matrix-backed operations such as -canny. NVD: An attacker can supply a crafted image that causes ImageMagick to allocate more memory than permitted by the configured policy, resulting in a denial of service. OSV: ImageMagick before 7.1.2-26 Memory Allocation Policy Bypass",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-61465/timeline.json",
      "vendor": "imagemagick"
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-61498/",
      "current_public_safe_latest": false,
      "cvss_score": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.80219,
      "epss_score": 0.02165,
      "first_observed_at": "2026-07-20T11:59:42.107493+00:00",
      "id": "CVE-2026-61498",
      "impact_tags": [
        "admin privilege risk",
        "command injection risk",
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-20T11:59:42.107493+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Vitec Flamingo 4.12.2 contains an unauthenticated OS command injection vulnerability in the admin/ajax/gen_graphs.php endpoint that allows remote unauthenticated attackers to execute arbitrary commands by supplying shell metacharacters in the start, end, key... NVD: Attackers can exploit the lack of input sanitization in the graph generation script, which passes user-supplied values directly to shell commands via passthru(), to execute arbitrary OS commands with root privileges due to the web server context having...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260720T120206Z/items/CVE-2026-61498.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes admin privilege risk · command injection risk · remote exposure. Possible impact: A remote attacker may gain root or administrative-level privileges on affected systems.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Vitec Flamingo 4.12.2 contains an unauthenticated OS command injection vulnerability in the admin/ajax/gen_graphs.php endpoint that allows remote unauthenticated attackers to execute arbitrary commands by supplying shell metacharacters in the start, end, key... NVD: Attackers can exploit the lack of input sanitization in the graph generation script, which passes user-supplied values directly to shell commands via passthru(), to execute arbitrary OS commands with root privileges due to the web server context having...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-61498/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-61511/",
      "current_public_safe_latest": false,
      "cvss_score": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.6703,
      "epss_score": 0.01274,
      "first_observed_at": "2026-08-03T12:38:03.310457+00:00",
      "id": "CVE-2026-61511",
      "impact_tags": [
        "remote exposure relevant"
      ],
      "kev": false,
      "last_observed_at": "2026-08-03T12:38:03.310457+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: vBulletin 5.x through 5.7.5 and 6.x through 6.2.1 contains an eval injection vulnerability in the vB5_Template_Runtime::runMaths() method within the template runtime that allows unauthenticated remote attackers to execute arbitrary PHP code by supplying... NVD: Attackers can exploit the insufficiently restrictive regex filter by using phpfuck-style encoding with permitted characters to inject and execute arbitrary PHP code via the unauthenticated ajax/render template route without any authentication.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260803T124716Z/items/CVE-2026-61511.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes remote exposure. Possible impact: This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: vBulletin 5.x through 5.7.5 and 6.x through 6.2.1 contains an eval injection vulnerability in the vB5_Template_Runtime::runMaths() method within the template runtime that allows unauthenticated remote attackers to execute arbitrary PHP code by supplying... NVD: Attackers can exploit the insufficiently restrictive regex filter by using phpfuck-style encoding with permitted characters to inject and execute arbitrary PHP code via the unauthenticated ajax/render template route without any authentication.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-61511/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "imagemagick / imagemagick",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-61857/",
      "current_public_safe_latest": false,
      "cvss_score": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.18101,
      "epss_score": 0.00265,
      "first_observed_at": "2026-07-18T10:34:17.263199+00:00",
      "id": "CVE-2026-61857",
      "impact_tags": [
        "memory safety review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-18T10:42:57.422810+00:00",
      "latest_item_url": null,
      "product": "imagemagick",
      "public_safe_summary": "NVD: ImageMagick before 7.1.2-26 contains a heap use-after-free vulnerability caused by missing null check when parsing XMP profiles. NVD: Attackers can craft malicious image files with specially crafted XMP data to trigger the vulnerability and cause application crashes. OSV: ImageMagick before 7.1.2-26 Heap Use-After-Free via XMP",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260718T104447Z/items/CVE-2026-61857.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "vendor/product: imagemagick / imagemagick",
      "source_published_impact": "Source describes memory safety review. Possible impact: The affected component has memory-safety risk that may lead to crash, privilege, or code-execution impact depending on exposure.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: ImageMagick before 7.1.2-26 contains a heap use-after-free vulnerability caused by missing null check when parsing XMP profiles. NVD: Attackers can craft malicious image files with specially crafted XMP data to trigger the vulnerability and cause application crashes. OSV: ImageMagick before 7.1.2-26 Heap Use-After-Free via XMP",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-61857/timeline.json",
      "vendor": "imagemagick"
    },
    {
      "affected_label": "imagemagick / imagemagick",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-61858/",
      "current_public_safe_latest": false,
      "cvss_score": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.15825,
      "epss_score": 0.00246,
      "first_observed_at": "2026-07-18T10:34:17.263199+00:00",
      "id": "CVE-2026-61858",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-18T10:42:57.422810+00:00",
      "latest_item_url": null,
      "product": "imagemagick",
      "public_safe_summary": "NVD: ImageMagick before 7.1.2-26 contains a policy bypass vulnerability in the APNG encoder and external delegates due to missing validation checks. NVD: Attackers can write files to disallowed paths by bypassing configured policy restrictions through the APNG encoding process. OSV: ImageMagick before 7.1.2-26 Policy Bypass via APNG encoder",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260718T104447Z/items/CVE-2026-61858.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "vendor/product: imagemagick / imagemagick",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: ImageMagick before 7.1.2-26 contains a policy bypass vulnerability in the APNG encoder and external delegates due to missing validation checks. NVD: Attackers can write files to disallowed paths by bypassing configured policy restrictions through the APNG encoding process. OSV: ImageMagick before 7.1.2-26 Policy Bypass via APNG encoder",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-61858/timeline.json",
      "vendor": "imagemagick"
    },
    {
      "affected_label": "imagemagick / imagemagick",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-61861/",
      "current_public_safe_latest": false,
      "cvss_score": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.24414,
      "epss_score": 0.00323,
      "first_observed_at": "2026-07-18T10:34:17.263199+00:00",
      "id": "CVE-2026-61861",
      "impact_tags": [
        "service availability review",
        "memory safety review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-18T10:42:57.422810+00:00",
      "latest_item_url": null,
      "product": "imagemagick",
      "public_safe_summary": "NVD: ImageMagick before 7.1.2-26 contains a use-after-free vulnerability in the FormatMagickCaption method when memory allocation fails. NVD: Attackers can trigger memory allocation failures to cause a dangling pointer to reference freed memory, potentially enabling denial of service or code execution. OSV: ImageMagick before 7.1.2-26 Use-After-Free in FormatMagickCaption",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260718T104447Z/items/CVE-2026-61861.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "vendor/product: imagemagick / imagemagick",
      "source_published_impact": "Source describes service availability risk · memory safety review. Possible impact: The affected service may become unavailable or unreliable.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: ImageMagick before 7.1.2-26 contains a use-after-free vulnerability in the FormatMagickCaption method when memory allocation fails. NVD: Attackers can trigger memory allocation failures to cause a dangling pointer to reference freed memory, potentially enabling denial of service or code execution. OSV: ImageMagick before 7.1.2-26 Use-After-Free in FormatMagickCaption",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-61861/timeline.json",
      "vendor": "imagemagick"
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-61886/",
      "current_public_safe_latest": false,
      "cvss_score": 7.1,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.14039,
      "epss_score": 0.00231,
      "first_observed_at": "2026-07-31T22:17:39.455090+00:00",
      "id": "CVE-2026-61886",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-31T22:17:39.455090+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Weintek cMT3092X HMI stores user account passwords in plaintext.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260731T222222Z/items/CVE-2026-61886.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Weintek cMT3092X HMI stores user account passwords in plaintext.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-61886/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-61892/",
      "current_public_safe_latest": false,
      "cvss_score": 8.7,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.19613,
      "epss_score": 0.00274,
      "first_observed_at": "2026-07-31T22:17:39.455090+00:00",
      "id": "CVE-2026-61892",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-31T22:17:39.455090+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Weintek cMT3092X HMI allows a non-privileged user to modify tokens to escalate privileges.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260731T222222Z/items/CVE-2026-61892.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Weintek cMT3092X HMI allows a non-privileged user to modify tokens to escalate privileges.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-61892/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-61953/",
      "current_public_safe_latest": false,
      "cvss_score": 7.2,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.05573,
      "epss_score": 0.00159,
      "first_observed_at": "2026-08-03T22:29:45.220405+00:00",
      "id": "CVE-2026-61953",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-03T22:29:45.220405+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Unauthenticated Server Side Request Forgery (SSRF) in Simple Link Directory Pro <= 15.0.6 versions.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260803T223322Z/items/CVE-2026-61953.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Unauthenticated Server Side Request Forgery (SSRF) in Simple Link Directory Pro <= 15.0.6 versions.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-61953/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-61957/",
      "current_public_safe_latest": false,
      "cvss_score": 7.1,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.04344,
      "epss_score": 0.00146,
      "first_observed_at": "2026-08-03T22:29:45.220405+00:00",
      "id": "CVE-2026-61957",
      "impact_tags": [
        "XSS risk"
      ],
      "kev": false,
      "last_observed_at": "2026-08-03T22:29:45.220405+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Unauthenticated Cross Site Scripting (XSS) in miniorange otp verification <= 5.5.1 versions.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260803T223322Z/items/CVE-2026-61957.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes XSS risk. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Unauthenticated Cross Site Scripting (XSS) in miniorange otp verification <= 5.5.1 versions.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-61957/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-62147/",
      "current_public_safe_latest": false,
      "cvss_score": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.11021,
      "epss_score": 0.00209,
      "first_observed_at": "2026-07-20T11:59:42.107493+00:00",
      "id": "CVE-2026-62147",
      "impact_tags": [
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-20T11:59:42.107493+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Tempo Operator's gateway component failed to consistently apply namespace-scoped redaction on some query API response paths when query RBAC was enabled, allowing an authenticated user to read span attributes belonging to other tenants' namespaces.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260720T120206Z/items/CVE-2026-62147.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Tempo Operator's gateway component failed to consistently apply namespace-scoped redaction on some query API response paths when query RBAC was enabled, allowing an authenticated user to read span attributes belonging to other tenants' namespaces.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-62147/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-6230/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.19145,
      "epss_score": 0.00273,
      "first_observed_at": "2026-07-15T11:03:27.604769+00:00",
      "id": "CVE-2026-6230",
      "impact_tags": [
        "information exposure review",
        "SQL injection risk",
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-15T11:03:27.604769+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Tainacan plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'geoquery' parameter in all versions up to and including 1.0.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the... NVD: This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. OSV: Tainacan <= 1.0.3 - Unauthenticated SQL Injection via 'geoquery' REST API Parameter",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260715T110622Z/items/CVE-2026-6230.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes information exposure review · SQL injection risk · remote exposure. Possible impact: A remote attacker may be able to read or change database-backed application data.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Tainacan plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'geoquery' parameter in all versions up to and including 1.0.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the... NVD: This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. OSV: Tainacan <= 1.0.3 - Unauthenticated SQL Injection via 'geoquery' REST API Parameter",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-6230/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-62325/",
      "current_public_safe_latest": false,
      "cvss_score": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.27041,
      "epss_score": 0.00344,
      "first_observed_at": "2026-08-04T22:31:51.932237+00:00",
      "id": "CVE-2026-62325",
      "impact_tags": [
        "authentication boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-04T22:31:51.932237+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: goshs is a feature-rich single-binary file server for red teamers and developers. NVD: From 2.1.3 until 2.1.4, the sftpserver/sftpserver.go password handler used Username != \"\" && Password != \"\", so running goshs with -b 'admin:' -sftp and no -fkf left both SFTP authentication handlers unset and allowed unauthenticated file access. NVD: This issue is fixed in version 2.1.4.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260804T223546Z/items/CVE-2026-62325.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes authentication boundary review. Possible impact: This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authentication boundary review.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: goshs is a feature-rich single-binary file server for red teamers and developers. NVD: From 2.1.3 until 2.1.4, the sftpserver/sftpserver.go password handler used Username != \"\" && Password != \"\", so running goshs with -b 'admin:' -sftp and no -fkf left both SFTP authentication handlers unset and allowed unauthenticated file access. NVD: This issue is fixed in version 2.1.4.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-62325/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "imagemagick / imagemagick",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-62343/",
      "current_public_safe_latest": false,
      "cvss_score": 4.7,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.02503,
      "epss_score": 0.00124,
      "first_observed_at": "2026-08-05T22:30:13.133185+00:00",
      "id": "CVE-2026-62343",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-05T22:30:13.133185+00:00",
      "latest_item_url": null,
      "product": "imagemagick",
      "public_safe_summary": "NVD: ImageMagick is free and open-source software used for editing and manipulating digital images. NVD: In versions prior to 6.9.13-51 and 7.0.1-0 and above prior to 7.1.2-26, an invalid kernel can cause a heap buffer over-write when performing a morphology operation with a user supplied kernel. NVD: This issue has been fixed in versions 6.9.13-51 and 7.1.2-26.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260805T223715Z/items/CVE-2026-62343.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: imagemagick / imagemagick",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: versions.",
      "source_published_summary": "NVD: ImageMagick is free and open-source software used for editing and manipulating digital images. NVD: In versions prior to 6.9.13-51 and 7.0.1-0 and above prior to 7.1.2-26, an invalid kernel can cause a heap buffer over-write when performing a morphology operation with a user supplied kernel. NVD: This issue has been fixed in versions 6.9.13-51 and 7.1.2-26.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-62343/timeline.json",
      "vendor": "imagemagick"
    },
    {
      "affected_label": "imagemagick / imagemagick",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-62363/",
      "current_public_safe_latest": false,
      "cvss_score": 5.0,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.03194,
      "epss_score": 0.00132,
      "first_observed_at": "2026-08-05T22:30:13.133185+00:00",
      "id": "CVE-2026-62363",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-05T22:30:13.133185+00:00",
      "latest_item_url": null,
      "product": "imagemagick",
      "public_safe_summary": "NVD: ImageMagick is free and open-source software used for editing and manipulating digital images. NVD: In versions prior to 7.1.2-27, a heap buffer over-write can occur in the fx operation by passing a crafted argument. NVD: This issue has been fixed in version 7.1.2-27.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260805T223715Z/items/CVE-2026-62363.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: imagemagick / imagemagick",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: ImageMagick is free and open-source software used for editing and manipulating digital images. NVD: In versions prior to 7.1.2-27, a heap buffer over-write can occur in the fx operation by passing a crafted argument. NVD: This issue has been fixed in version 7.1.2-27.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-62363/timeline.json",
      "vendor": "imagemagick"
    },
    {
      "affected_label": "apache / kylin",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-62390/",
      "current_public_safe_latest": false,
      "cvss_score": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.48394,
      "epss_score": 0.00681,
      "first_observed_at": "2026-07-21T11:20:19.325173+00:00",
      "id": "CVE-2026-62390",
      "impact_tags": [
        "SQL injection risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-21T11:20:19.325173+00:00",
      "latest_item_url": null,
      "product": "kylin",
      "public_safe_summary": "NVD: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Kylin. NVD: A backend API refreshing table catalog may cause the injection to the generated SQL. NVD: This issue affects Apache Kylin: from 4 through 5.0.3.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260721T112231Z/items/CVE-2026-62390.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: apache / kylin",
      "source_published_impact": "Source describes SQL injection risk. Possible impact: An attacker may be able to read or change database-backed application data.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Kylin. NVD: A backend API refreshing table catalog may cause the injection to the generated SQL. NVD: This issue affects Apache Kylin: from 4 through 5.0.3.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-62390/timeline.json",
      "vendor": "apache"
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-62391/",
      "current_public_safe_latest": false,
      "cvss_score": 8.1,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.32918,
      "epss_score": 0.00401,
      "first_observed_at": "2026-08-07T10:13:53.604723+00:00",
      "id": "CVE-2026-62391",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-07T10:13:53.604723+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The security fix for CVE-2025-66518 is incomplete. NVD: Any client who can access to Apache Kyuubi Server via Kyuubi frontend protocols can bypass server-side config kyuubi.session.local.dir.allowlist via unprefixed Spark config aliases. NVD: This issue affects Apache Kyuubi: from 1.6.0 before 1.12.0.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260807T102646Z/items/CVE-2026-62391.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: The security fix for CVE-2025-66518 is incomplete. NVD: Any client who can access to Apache Kyuubi Server via Kyuubi frontend protocols can bypass server-side config kyuubi.session.local.dir.allowlist via unprefixed Spark config aliases. NVD: This issue affects Apache Kyuubi: from 1.6.0 before 1.12.0.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-62391/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "apache / kylin",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-62392/",
      "current_public_safe_latest": false,
      "cvss_score": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.76472,
      "epss_score": 0.01828,
      "first_observed_at": "2026-07-21T11:20:19.325173+00:00",
      "id": "CVE-2026-62392",
      "impact_tags": [
        "command injection risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-21T11:20:19.325173+00:00",
      "latest_item_url": null,
      "product": "kylin",
      "public_safe_summary": "NVD: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache Kylin. NVD: A backend API may bring job config parameters to OS command line. NVD: This issue affects Apache Kylin: from 4 through 5.0.3.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260721T112231Z/items/CVE-2026-62392.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: apache / kylin",
      "source_published_impact": "Source describes command injection risk. Possible impact: An attacker may be able to run unintended system commands through the affected component.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache Kylin. NVD: A backend API may bring job config parameters to OS command line. NVD: This issue affects Apache Kylin: from 4 through 5.0.3.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-62392/timeline.json",
      "vendor": "apache"
    },
    {
      "affected_label": "apache / kylin",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-62393/",
      "current_public_safe_latest": false,
      "cvss_score": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.37329,
      "epss_score": 0.00463,
      "first_observed_at": "2026-07-21T11:20:19.325173+00:00",
      "id": "CVE-2026-62393",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-21T11:20:19.325173+00:00",
      "latest_item_url": null,
      "product": "kylin",
      "public_safe_summary": "NVD: Improper Handling of Insufficient Permissions or Privileges vulnerability in Apache Kylin. NVD: Improper authorization in job information retrieval, where an attacker may get access to unauthorized jobs in other projects. NVD: This issue affects Apache Kylin: from 4 through 5.0.3.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260721T112231Z/items/CVE-2026-62393.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: apache / kylin",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: Improper Handling of Insufficient Permissions or Privileges vulnerability in Apache Kylin. NVD: Improper authorization in job information retrieval, where an attacker may get access to unauthorized jobs in other projects. NVD: This issue affects Apache Kylin: from 4 through 5.0.3.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-62393/timeline.json",
      "vendor": "apache"
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-62423/",
      "current_public_safe_latest": false,
      "cvss_score": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.10711,
      "epss_score": 0.00205,
      "first_observed_at": "2026-08-04T11:35:47.800052+00:00",
      "id": "CVE-2026-62423",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-04T11:35:47.800052+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] The directory and Rock Ridge / SUSP walk in libfsimage's iso9660 driver derives several lengths directly from attacker-controlled... NVD: This is CVE-2026-42494. NVD: * The calculation of the System Use area may underflow.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260804T114328Z/items/CVE-2026-62423.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] The directory and Rock Ridge / SUSP walk in libfsimage's iso9660 driver derives several lengths directly from attacker-controlled... NVD: This is CVE-2026-42494. NVD: * The calculation of the System Use area may underflow.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-62423/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-6251/",
      "current_public_safe_latest": false,
      "cvss_score": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.16324,
      "epss_score": 0.00249,
      "first_observed_at": "2026-08-04T06:07:04.591309+00:00",
      "id": "CVE-2026-6251",
      "impact_tags": [
        "SQL injection risk",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-04T06:07:04.591309+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Chaty Pro plugin for WordPress is vulnerable to Authenticated Time-Based Blind SQL Injection in versions up to and including 3.5.5. NVD: This is due to the fetch_custom_field() function in admin/class-admin-base.php retrieving the widget_id POST parameter via filter_input(INPUT_POST, ...) and directly concatenating the value into a raw SQL query in a numeric context without using... NVD: Additionally, the nonce verification check is performed after the SQL query has already executed, providing no protection against the injection.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260804T061658Z/items/CVE-2026-6251.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes SQL injection risk · authenticated boundary. Possible impact: An attacker may be able to read or change database-backed application data.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Chaty Pro plugin for WordPress is vulnerable to Authenticated Time-Based Blind SQL Injection in versions up to and including 3.5.5. NVD: This is due to the fetch_custom_field() function in admin/class-admin-base.php retrieving the widget_id POST parameter via filter_input(INPUT_POST, ...) and directly concatenating the value into a raw SQL query in a numeric context without using... NVD: Additionally, the nonce verification check is performed after the SQL query has already executed, providing no protection against the injection.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-6251/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-62764/",
      "current_public_safe_latest": false,
      "cvss_score": 5.7,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.21615,
      "epss_score": 0.00295,
      "first_observed_at": "2026-07-24T06:06:41.160911+00:00",
      "id": "CVE-2026-62764",
      "impact_tags": [
        "service availability review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-24T06:06:41.160911+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Improper Handling of Insufficient Privileges vulnerability in Apache Accumulo. NVD: An authenticated, but low-privileged user without system permissions may issue a remote command to gracefully shutdown system components (compaction-coordinator, compactor, gc, manager, monitor, tserver, or sserver), leading to a denial of service. NVD: This issue affects Apache Accumulo 2.1.4 and 2.1.5.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260724T061150Z/items/CVE-2026-62764.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes service availability risk. Possible impact: The affected service may become unavailable or unreliable.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: Improper Handling of Insufficient Privileges vulnerability in Apache Accumulo. NVD: An authenticated, but low-privileged user without system permissions may issue a remote command to gracefully shutdown system components (compaction-coordinator, compactor, gc, manager, monitor, tserver, or sserver), leading to a denial of service. NVD: This issue affects Apache Accumulo 2.1.4 and 2.1.5.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-62764/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-62825/",
      "current_public_safe_latest": false,
      "cvss_score": 10.0,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.49437,
      "epss_score": 0.00697,
      "first_observed_at": "2026-07-30T22:30:38.166118+00:00",
      "id": "CVE-2026-62825",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-30T22:30:38.166118+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Improper authentication in Azure Key Vault allows an unauthorized attacker to elevate privileges over a network.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260730T224832Z/items/CVE-2026-62825.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Improper authentication in Azure Key Vault allows an unauthorized attacker to elevate privileges over a network.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-62825/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "imagemagick / imagemagick",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-62946/",
      "current_public_safe_latest": false,
      "cvss_score": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.02464,
      "epss_score": 0.00123,
      "first_observed_at": "2026-08-05T22:30:13.133185+00:00",
      "id": "CVE-2026-62946",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-05T22:30:13.133185+00:00",
      "latest_item_url": null,
      "product": "imagemagick",
      "public_safe_summary": "NVD: ImageMagick is free and open-source software used for editing and manipulating digital images. NVD: In versions prior to both 6.9.13-52 and 7.1.2-27, processing an extremely large JNX file on 32-bit platforms can cause an integer overflow, leading to a heap buffer over-write. NVD: This issue has been fixed in versions 6.9.13-52 and 7.1.2-27.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260805T223715Z/items/CVE-2026-62946.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: imagemagick / imagemagick",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: versions.",
      "source_published_summary": "NVD: ImageMagick is free and open-source software used for editing and manipulating digital images. NVD: In versions prior to both 6.9.13-52 and 7.1.2-27, processing an extremely large JNX file on 32-bit platforms can cause an integer overflow, leading to a heap buffer over-write. NVD: This issue has been fixed in versions 6.9.13-52 and 7.1.2-27.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-62946/timeline.json",
      "vendor": "imagemagick"
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-63047/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.14239,
      "epss_score": 0.00232,
      "first_observed_at": "2026-07-29T06:10:00.110927+00:00",
      "id": "CVE-2026-63047",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-29T06:10:00.110927+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Joomla Extension - joomdonation.com - Invoice data exfiltration via incorrect ACL check in Events Booking 5.0.0-5.8.1 - The Joomla extension Events Booking prior version 5.0-5.8.1 did not properly verify that an actor is allowed to download invoice...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260729T062752Z/items/CVE-2026-63047.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Joomla Extension - joomdonation.com - Invoice data exfiltration via incorrect ACL check in Events Booking 5.0.0-5.8.1 - The Joomla extension Events Booking prior version 5.0-5.8.1 did not properly verify that an actor is allowed to download invoice...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-63047/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-63048/",
      "current_public_safe_latest": false,
      "cvss_score": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.13435,
      "epss_score": 0.00226,
      "first_observed_at": "2026-07-29T06:10:00.110927+00:00",
      "id": "CVE-2026-63048",
      "impact_tags": [
        "code execution review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-29T06:10:00.110927+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Joomla Extension - joomlack.fr - Improper access control in Page Builder CK < 3.6.2 - The Joomla extension Page Builder CK is vulnerable to an authenticated arbitrary file upload, leading to RCE.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260729T062752Z/items/CVE-2026-63048.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes code execution review. Possible impact: An attacker may be able to run code or commands on affected systems.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Joomla Extension - joomlack.fr - Improper access control in Page Builder CK < 3.6.2 - The Joomla extension Page Builder CK is vulnerable to an authenticated arbitrary file upload, leading to RCE.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-63048/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-63142/",
      "current_public_safe_latest": false,
      "cvss_score": 5.0,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.07383,
      "epss_score": 0.00176,
      "first_observed_at": "2026-07-28T22:27:58.188634+00:00",
      "id": "CVE-2026-63142",
      "impact_tags": [
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-28T22:27:58.188634+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Incomplete List of Disallowed Inputs (CWE-184) in Kibana can allow an authenticated attacker with access to the Reporting feature to bypass outbound request restrictions configured by an administrator, causing the reporting service to send requests to network...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260728T223134Z/items/CVE-2026-63142.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Incomplete List of Disallowed Inputs (CWE-184) in Kibana can allow an authenticated attacker with access to the Reporting feature to bypass outbound request restrictions configured by an administrator, causing the reporting service to send requests to network...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-63142/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-63143/",
      "current_public_safe_latest": false,
      "cvss_score": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.10256,
      "epss_score": 0.00201,
      "first_observed_at": "2026-07-28T22:27:58.188634+00:00",
      "id": "CVE-2026-63143",
      "impact_tags": [
        "information exposure review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-28T22:27:58.188634+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Missing Authorization (CWE-862) in Kibana can lead to unauthorized information disclosure via Privilege Abuse (CAPEC-122). NVD: A user with limited feature privileges can access workflow execution outputs in their Kibana space without the authorization required to do so through the documented API. NVD: The accessible data may include sensitive information returned by workflow steps, such as results from connected data sources that the caller would not otherwise be authorized to access.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260728T223134Z/items/CVE-2026-63143.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes information exposure review. Possible impact: An attacker may be able to access information that should not be exposed.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Missing Authorization (CWE-862) in Kibana can lead to unauthorized information disclosure via Privilege Abuse (CAPEC-122). NVD: A user with limited feature privileges can access workflow execution outputs in their Kibana space without the authorization required to do so through the documented API. NVD: The accessible data may include sensitive information returned by workflow steps, such as results from connected data sources that the caller would not otherwise be authorized to access.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-63143/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-63221/",
      "current_public_safe_latest": false,
      "cvss_score": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.30423,
      "epss_score": 0.00377,
      "first_observed_at": "2026-08-07T05:06:11.845797+00:00",
      "id": "CVE-2026-63221",
      "impact_tags": [
        "SQL injection risk"
      ],
      "kev": false,
      "last_observed_at": "2026-08-07T05:06:11.845797+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: CodeIgniter is a PHP full-stack web framework. NVD: From 4.3.0 through 4.7.3, Query Builder deleteBatch() substitutes bound values from where() conditions into generated SQL while ignoring their escape flags, allowing user-controlled condition values to be interpreted as SQL. NVD: This affects only the deleteBatch() code path.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260807T051140Z/items/CVE-2026-63221.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes SQL injection risk. Possible impact: An attacker may be able to read or change database-backed application data.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: CodeIgniter is a PHP full-stack web framework. NVD: From 4.3.0 through 4.7.3, Query Builder deleteBatch() substitutes bound values from where() conditions into generated SQL while ignoring their escape flags, allowing user-controlled condition values to be interpreted as SQL. NVD: This affects only the deleteBatch() code path.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-63221/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-63222/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.36908,
      "epss_score": 0.0045,
      "first_observed_at": "2026-08-07T05:06:11.845797+00:00",
      "id": "CVE-2026-63222",
      "impact_tags": [
        "path traversal review",
        "remote exposure relevant"
      ],
      "kev": false,
      "last_observed_at": "2026-08-07T05:06:11.845797+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: CodeIgniter is a PHP full-stack web framework. NVD: Prior to 4.7.4, calling UploadedFile::move() without a second argument uses the client-provided filename without sanitization, allowing a remote attacker to use path traversal sequences to write uploaded content outside the intended directory when the... NVD: This issue is fixed in version 4.7.4.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260807T051140Z/items/CVE-2026-63222.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes path traversal review · remote exposure. Possible impact: A remote attacker may be able to reach files outside the intended application path.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: CodeIgniter is a PHP full-stack web framework. NVD: Prior to 4.7.4, calling UploadedFile::move() without a second argument uses the client-provided filename without sanitization, allowing a remote attacker to use path traversal sequences to write uploaded content outside the intended directory when the... NVD: This issue is fixed in version 4.7.4.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-63222/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-63223/",
      "current_public_safe_latest": false,
      "cvss_score": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.39687,
      "epss_score": 0.00493,
      "first_observed_at": "2026-08-07T05:06:11.845797+00:00",
      "id": "CVE-2026-63223",
      "impact_tags": [
        "remote exposure relevant"
      ],
      "kev": false,
      "last_observed_at": "2026-08-07T05:06:11.845797+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: CodeIgniter is a PHP full-stack web framework. NVD: Prior to 4.7.4, the is_image and mime_in upload validation rules do not independently enforce a safe client filename extension, allowing a remote attacker to upload executable content when an application preserves the client filename and stores uploads in a... NVD: Applications are impacted when they validate uploads using is_image or mime_in without an independent safe extension check (such as ext_in on patched versions), save uploaded files using the client-supplied filename, and place uploads in a web-accessible...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260807T051140Z/items/CVE-2026-63223.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes remote exposure. Possible impact: This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: CodeIgniter is a PHP full-stack web framework. NVD: Prior to 4.7.4, the is_image and mime_in upload validation rules do not independently enforce a safe client filename extension, allowing a remote attacker to upload executable content when an application preserves the client filename and stores uploads in a... NVD: Applications are impacted when they validate uploads using is_image or mime_in without an independent safe extension check (such as ext_in on patched versions), save uploaded files using the client-supplied filename, and place uploads in a web-accessible...",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-63223/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-63226/",
      "current_public_safe_latest": false,
      "cvss_score": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.13082,
      "epss_score": 0.00223,
      "first_observed_at": "2026-07-30T06:01:44.452906+00:00",
      "id": "CVE-2026-63226",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-30T06:01:44.452906+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Printers and Multifunction Printers (MFPs) provided by Ricoh Company, Ltd. NVD: do not implement restrictions on SSH port forwarding, allowing to connect to arbitrary destinations. NVD: When SSH is enabled on an affected product, SSH port forwarding may be leveraged to connect to other node on the LAN.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260730T060504Z/items/CVE-2026-63226.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Printers and Multifunction Printers (MFPs) provided by Ricoh Company, Ltd. NVD: do not implement restrictions on SSH port forwarding, allowing to connect to arbitrary destinations. NVD: When SSH is enabled on an affected product, SSH port forwarding may be leveraged to connect to other node on the LAN.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-63226/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-63227/",
      "current_public_safe_latest": false,
      "cvss_score": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.25339,
      "epss_score": 0.00328,
      "first_observed_at": "2026-08-05T06:03:49.171468+00:00",
      "id": "CVE-2026-63227",
      "impact_tags": [
        "code execution review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-05T06:03:49.171468+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: An unrestricted SCORM file upload vulnerability in Koollab LMS allowed an authenticated module designer to upload a SCORM package containing a PHP webshell to a publicly accessible directory and execute arbitrary code on the server.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260805T061218Z/items/CVE-2026-63227.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes code execution review. Possible impact: An attacker may be able to run code or commands on affected systems.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: An unrestricted SCORM file upload vulnerability in Koollab LMS allowed an authenticated module designer to upload a SCORM package containing a PHP webshell to a publicly accessible directory and execute arbitrary code on the server.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-63227/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-63228/",
      "current_public_safe_latest": false,
      "cvss_score": 2.6,
      "cvss_severity": "LOW",
      "epss_percentile": 0.0288,
      "epss_score": 0.00128,
      "first_observed_at": "2026-08-05T06:03:49.171468+00:00",
      "id": "CVE-2026-63228",
      "impact_tags": [
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-05T06:03:49.171468+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: An unrestricted image upload vulnerability in Koollab LMS allowed an authenticated attacker to upload malicious content disguised as an image file via the feedback mail registration endpoint, potentially enabling further attacks on the server.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260805T061218Z/items/CVE-2026-63228.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes authenticated boundary. Possible impact: This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: An unrestricted image upload vulnerability in Koollab LMS allowed an authenticated attacker to upload malicious content disguised as an image file via the feedback mail registration endpoint, potentially enabling further attacks on the server.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-63228/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-63229/",
      "current_public_safe_latest": false,
      "cvss_score": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.21854,
      "epss_score": 0.00296,
      "first_observed_at": "2026-08-05T06:03:49.171468+00:00",
      "id": "CVE-2026-63229",
      "impact_tags": [
        "SQL injection risk",
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-05T06:03:49.171468+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A pre-authentication blind SQL injection vulnerability in Koollab LMS allowed an unauthenticated attacker to use a time-based SQL oracle via the SSO OAuth endpoint to read sensitive database contents, including personally identifiable information...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260805T061218Z/items/CVE-2026-63229.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes SQL injection risk · remote exposure · authenticated boundary. Possible impact: A remote attacker may be able to read or change database-backed application data.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A pre-authentication blind SQL injection vulnerability in Koollab LMS allowed an unauthenticated attacker to use a time-based SQL oracle via the SSO OAuth endpoint to read sensitive database contents, including personally identifiable information...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-63229/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-63230/",
      "current_public_safe_latest": false,
      "cvss_score": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.21854,
      "epss_score": 0.00296,
      "first_observed_at": "2026-08-05T06:03:49.171468+00:00",
      "id": "CVE-2026-63230",
      "impact_tags": [
        "SQL injection risk",
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-05T06:03:49.171468+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A pre-authentication error-based SQL injection vulnerability in Koollab LMS allowed an unauthenticated attacker to read sensitive database contents, including personally identifiable information, credentials, and valid JWT tokens that may enable account...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260805T061218Z/items/CVE-2026-63230.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes SQL injection risk · remote exposure · authenticated boundary. Possible impact: A remote attacker may be able to read or change database-backed application data.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A pre-authentication error-based SQL injection vulnerability in Koollab LMS allowed an unauthenticated attacker to read sensitive database contents, including personally identifiable information, credentials, and valid JWT tokens that may enable account...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-63230/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-63231/",
      "current_public_safe_latest": false,
      "cvss_score": 8.1,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.16689,
      "epss_score": 0.00252,
      "first_observed_at": "2026-08-05T06:03:49.171468+00:00",
      "id": "CVE-2026-63231",
      "impact_tags": [
        "SQL injection risk",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-05T06:03:49.171468+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A post-authentication SQL injection vulnerability in Koollab LMS allowed an authenticated attacker to use an error-based SQL oracle via the face-to-face runs update endpoint to read the entire application database and obtain valid JWT tokens for account...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260805T061218Z/items/CVE-2026-63231.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes SQL injection risk · authenticated boundary. Possible impact: An attacker may be able to read or change database-backed application data.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A post-authentication SQL injection vulnerability in Koollab LMS allowed an authenticated attacker to use an error-based SQL oracle via the face-to-face runs update endpoint to read the entire application database and obtain valid JWT tokens for account...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-63231/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-63232/",
      "current_public_safe_latest": false,
      "cvss_score": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.21699,
      "epss_score": 0.00294,
      "first_observed_at": "2026-08-05T06:03:49.171468+00:00",
      "id": "CVE-2026-63232",
      "impact_tags": [
        "code execution review",
        "SQL injection risk",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-05T06:03:49.171468+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A SQL injection and unsafe deserialisation vulnerability in Koollab LMS allowed an authenticated attacker to inject through the assessment reinforcement endpoint, control data passed to unserialize(), write a webshell to a publicly accessible location, and...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260805T061218Z/items/CVE-2026-63232.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes code execution review · SQL injection risk · authenticated boundary. Possible impact: An attacker may be able to run code or commands on affected systems.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A SQL injection and unsafe deserialisation vulnerability in Koollab LMS allowed an authenticated attacker to inject through the assessment reinforcement endpoint, control data passed to unserialize(), write a webshell to a publicly accessible location, and...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-63232/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-63233/",
      "current_public_safe_latest": false,
      "cvss_score": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.21699,
      "epss_score": 0.00294,
      "first_observed_at": "2026-08-05T06:03:49.171468+00:00",
      "id": "CVE-2026-63233",
      "impact_tags": [
        "code execution review",
        "SQL injection risk",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-05T06:03:49.171468+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A SQL injection and unsafe deserialisation vulnerability in Koollab LMS allowed an authenticated attacker to inject through the assessment overall answer endpoint, control data passed to unserialize(), write a webshell to a publicly accessible location, and...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260805T061218Z/items/CVE-2026-63233.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes code execution review · SQL injection risk · authenticated boundary. Possible impact: An attacker may be able to run code or commands on affected systems.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A SQL injection and unsafe deserialisation vulnerability in Koollab LMS allowed an authenticated attacker to inject through the assessment overall answer endpoint, control data passed to unserialize(), write a webshell to a publicly accessible location, and...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-63233/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-63234/",
      "current_public_safe_latest": false,
      "cvss_score": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.21699,
      "epss_score": 0.00294,
      "first_observed_at": "2026-08-05T06:03:49.171468+00:00",
      "id": "CVE-2026-63234",
      "impact_tags": [
        "code execution review",
        "SQL injection risk",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-05T06:03:49.171468+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A SQL injection and unsafe deserialisation vulnerability in Koollab LMS allowed an authenticated attacker to inject through the manual mark assessment endpoint, control data passed to unserialize(), write a webshell to a publicly accessible location, and...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260805T061218Z/items/CVE-2026-63234.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes code execution review · SQL injection risk · authenticated boundary. Possible impact: An attacker may be able to run code or commands on affected systems.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A SQL injection and unsafe deserialisation vulnerability in Koollab LMS allowed an authenticated attacker to inject through the manual mark assessment endpoint, control data passed to unserialize(), write a webshell to a publicly accessible location, and...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-63234/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-63235/",
      "current_public_safe_latest": false,
      "cvss_score": 3.7,
      "cvss_severity": "LOW",
      "epss_percentile": 0.09497,
      "epss_score": 0.00196,
      "first_observed_at": "2026-08-05T06:03:49.171468+00:00",
      "id": "CVE-2026-63235",
      "impact_tags": [
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-05T06:03:49.171468+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: An improper access control vulnerability in Koollab LMS allowed an unauthenticated attacker to forcibly terminate the session of any user given their email address via the login kickout endpoint, resulting in a denial of service.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260805T061218Z/items/CVE-2026-63235.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes remote exposure · authenticated boundary. Possible impact: This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: An improper access control vulnerability in Koollab LMS allowed an unauthenticated attacker to forcibly terminate the session of any user given their email address via the login kickout endpoint, resulting in a denial of service.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-63235/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-63236/",
      "current_public_safe_latest": false,
      "cvss_score": 3.7,
      "cvss_severity": "LOW",
      "epss_percentile": 0.06285,
      "epss_score": 0.00166,
      "first_observed_at": "2026-08-05T06:03:49.171468+00:00",
      "id": "CVE-2026-63236",
      "impact_tags": [
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-05T06:03:49.171468+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: An improper access control vulnerability in Koollab LMS allowed an unauthenticated attacker to read another user's name, internal identifier, scores, lesson status, lesson position, and cached lesson state via the SCORM API endpoint.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260805T061218Z/items/CVE-2026-63236.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes remote exposure · authenticated boundary. Possible impact: This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: An improper access control vulnerability in Koollab LMS allowed an unauthenticated attacker to read another user's name, internal identifier, scores, lesson status, lesson position, and cached lesson state via the SCORM API endpoint.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-63236/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-63237/",
      "current_public_safe_latest": false,
      "cvss_score": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.0192,
      "epss_score": 0.00117,
      "first_observed_at": "2026-08-05T06:03:49.171468+00:00",
      "id": "CVE-2026-63237",
      "impact_tags": [
        "authentication boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-05T06:03:49.171468+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A TOTP two-factor authentication bypass vulnerability in Koollab LMS allowed an attacker to supply a client-controlled seed to generate a matching one-time password and bypass the second authentication factor, potentially enabling unauthorised access to...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260805T061218Z/items/CVE-2026-63237.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes authentication boundary review. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authentication boundary review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A TOTP two-factor authentication bypass vulnerability in Koollab LMS allowed an attacker to supply a client-controlled seed to generate a matching one-time password and bypass the second authentication factor, potentially enabling unauthorised access to...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-63237/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-63264/",
      "current_public_safe_latest": false,
      "cvss_score": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.17417,
      "epss_score": 0.00258,
      "first_observed_at": "2026-07-29T06:10:00.110927+00:00",
      "id": "CVE-2026-63264",
      "impact_tags": [
        "XSS risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-29T06:10:00.110927+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Joomla Extension - joomshopping.com - Reflective XSS in JoomShopping < 5.9.3 - The Joomla extension JoomShopping is vulnerable to an reflected XSS vulnerability in the product frontend controller.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260729T062752Z/items/CVE-2026-63264.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes XSS risk. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Joomla Extension - joomshopping.com - Reflective XSS in JoomShopping < 5.9.3 - The Joomla extension JoomShopping is vulnerable to an reflected XSS vulnerability in the product frontend controller.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-63264/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-63304/",
      "current_public_safe_latest": false,
      "cvss_score": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.68689,
      "epss_score": 0.01355,
      "first_observed_at": "2026-07-23T11:21:51.498947+00:00",
      "id": "CVE-2026-63304",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-23T11:21:51.498947+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: AVideo through 29.0 contains an OS command injection vulnerability in plugin/API/standAlone/functions.php where the listFFmpegProcesses() function interpolates unsanitized keyword parameters inside single quotes without escaping. OSV: AVideo through 29.0 OS Command Injection via listFFmpegProcesses OSV: AVideo through 29.0 contains an OS command injection vulnerability in plugin/API/standAlone/functions.php where the listFFmpegProcesses() function interpolates unsanitized keyword parameters inside single quotes without escaping.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260723T112431Z/items/CVE-2026-63304.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: AVideo through 29.0 contains an OS command injection vulnerability in plugin/API/standAlone/functions.php where the listFFmpegProcesses() function interpolates unsanitized keyword parameters inside single quotes without escaping. OSV: AVideo through 29.0 OS Command Injection via listFFmpegProcesses OSV: AVideo through 29.0 contains an OS command injection vulnerability in plugin/API/standAlone/functions.php where the listFFmpegProcesses() function interpolates unsanitized keyword parameters inside single quotes without escaping.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-63304/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-63305/",
      "current_public_safe_latest": false,
      "cvss_score": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.69292,
      "epss_score": 0.01383,
      "first_observed_at": "2026-07-23T11:21:51.498947+00:00",
      "id": "CVE-2026-63305",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-23T11:21:51.498947+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: AVideo through 29.0 contains an OS command injection vulnerability in the ffmpeg.json.php endpoint where notifyCode and callback parameters are concatenated into a shell command without escaping. OSV: AVideo through 29.0 OS Command Injection via ffmpeg.json.php OSV: AVideo through 29.0 contains an OS command injection vulnerability in the ffmpeg.json.php endpoint where notifyCode and callback parameters are concatenated into a shell command without escaping.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260723T112431Z/items/CVE-2026-63305.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: AVideo through 29.0 contains an OS command injection vulnerability in the ffmpeg.json.php endpoint where notifyCode and callback parameters are concatenated into a shell command without escaping. OSV: AVideo through 29.0 OS Command Injection via ffmpeg.json.php OSV: AVideo through 29.0 contains an OS command injection vulnerability in the ffmpeg.json.php endpoint where notifyCode and callback parameters are concatenated into a shell command without escaping.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-63305/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-63306/",
      "current_public_safe_latest": false,
      "cvss_score": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.15362,
      "epss_score": 0.00241,
      "first_observed_at": "2026-07-23T11:21:51.498947+00:00",
      "id": "CVE-2026-63306",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-23T11:21:51.498947+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: stoatchat before 0.13.5 contains an unauthenticated server-side request forgery vulnerability in the /proxy and /embed endpoints that accept arbitrary URLs without DNS resolution filtering or private IP range validation. NVD: Attackers can enumerate internal services, fingerprint applications, and reach instance metadata endpoints by supplying malicious URLs or leveraging redirect chains to access internal infrastructure. OSV: stoatchat before 0.13.5 Unauthenticated SSRF via proxy and embed endpoints",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260723T112431Z/items/CVE-2026-63306.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: stoatchat before 0.13.5 contains an unauthenticated server-side request forgery vulnerability in the /proxy and /embed endpoints that accept arbitrary URLs without DNS resolution filtering or private IP range validation. NVD: Attackers can enumerate internal services, fingerprint applications, and reach instance metadata endpoints by supplying malicious URLs or leveraging redirect chains to access internal infrastructure. OSV: stoatchat before 0.13.5 Unauthenticated SSRF via proxy and embed endpoints",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-63306/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-6371/",
      "current_public_safe_latest": false,
      "cvss_score": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.04473,
      "epss_score": 0.00148,
      "first_observed_at": "2026-07-15T11:03:27.604769+00:00",
      "id": "CVE-2026-6371",
      "impact_tags": [
        "XSS risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-15T11:03:27.604769+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Limatek System Inc. NVD: LimRAD NAC allows Stored XSS. NVD: This issue affects LimRAD NAC: through 08072026.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260715T110622Z/items/CVE-2026-6371.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes XSS risk. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Limatek System Inc. NVD: LimRAD NAC allows Stored XSS. NVD: This issue affects LimRAD NAC: through 08072026.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-6371/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-63720/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.3448,
      "epss_score": 0.00419,
      "first_observed_at": "2026-08-01T10:51:40.555213+00:00",
      "id": "CVE-2026-63720",
      "impact_tags": [
        "code execution review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-01T22:14:19.808804+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: datamodel-code-generator prior to version 0.70.0 contains a code injection vulnerability that allows attackers who control input schemas to achieve remote code execution by supplying a malicious customBasePath value containing embedded newlines and a dot-free... NVD: The crafted value is emitted verbatim into a generated 'from ... NVD: import ...' statement without identifier validation, causing arbitrary Python code to execute when the generated module is imported.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260801T221753Z/items/CVE-2026-63720.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 3,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes code execution review. Possible impact: An attacker may be able to run code or commands on affected systems.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: datamodel-code-generator prior to version 0.70.0 contains a code injection vulnerability that allows attackers who control input schemas to achieve remote code execution by supplying a malicious customBasePath value containing embedded newlines and a dot-free... NVD: The crafted value is emitted verbatim into a generated 'from ... NVD: import ...' statement without identifier validation, causing arbitrary Python code to execute when the generated module is imported.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-63720/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-63728/",
      "current_public_safe_latest": false,
      "cvss_score": 8.1,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.04225,
      "epss_score": 0.00145,
      "first_observed_at": "2026-07-27T22:30:18.664011+00:00",
      "id": "CVE-2026-63728",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-27T22:30:18.664011+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Gitleaks prior to 8.30.1 contains a template injection vulnerability that allows attackers who can supply or influence report templates to read arbitrary environment variables and exfiltrate sensitive data by leveraging non-hermetic Sprig template functions. NVD: Attackers can craft malicious report templates using the env, expandenv, and getHostByName functions to extract credentials, tokens, and API keys from the host process and exfiltrate them through DNS queries, including secrets discovered during the scan... OSV: Gitleaks Secret Exfiltration via Non-Hermetic Sprig Template Functions in Report Template Feature",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260727T223632Z/items/CVE-2026-63728.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Gitleaks prior to 8.30.1 contains a template injection vulnerability that allows attackers who can supply or influence report templates to read arbitrary environment variables and exfiltrate sensitive data by leveraging non-hermetic Sprig template functions. NVD: Attackers can craft malicious report templates using the env, expandenv, and getHostByName functions to extract credentials, tokens, and API keys from the host process and exfiltrate them through DNS queries, including secrets discovered during the scan... OSV: Gitleaks Secret Exfiltration via Non-Hermetic Sprig Template Functions in Report Template Feature",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-63728/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-63729/",
      "current_public_safe_latest": false,
      "cvss_score": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.02506,
      "epss_score": 0.00124,
      "first_observed_at": "2026-07-27T22:30:18.664011+00:00",
      "id": "CVE-2026-63729",
      "impact_tags": [
        "code execution review",
        "memory safety review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-27T22:30:18.664011+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The SyncTeX parser (synctex_parser.c) shipped with TeX Live and embedded by downstream consumers such as GNOME Evince contains a heap use-after-free vulnerability that allows attackers to crash applications or potentially execute arbitrary code by supplying a... NVD: A malformed SyncTeX file can construct a ref node with a NULL parent pointer, causing the replacement routine to fail to detach the node from its sibling chain, which triggers recursive freeing of live tree nodes and leaves dangling pointers that are later... OSV: TeX Live SyncTeX Parser Heap Use-After-Free via Malformed SyncTeX File",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260727T223632Z/items/CVE-2026-63729.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes code execution review · memory safety review. Possible impact: An attacker may be able to run code or commands on affected systems.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The SyncTeX parser (synctex_parser.c) shipped with TeX Live and embedded by downstream consumers such as GNOME Evince contains a heap use-after-free vulnerability that allows attackers to crash applications or potentially execute arbitrary code by supplying a... NVD: A malformed SyncTeX file can construct a ref node with a NULL parent pointer, causing the replacement routine to fail to detach the node from its sibling chain, which triggers recursive freeing of live tree nodes and leaves dangling pointers that are later... OSV: TeX Live SyncTeX Parser Heap Use-After-Free via Malformed SyncTeX File",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-63729/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-6382/",
      "current_public_safe_latest": false,
      "cvss_score": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.55521,
      "epss_score": 0.00902,
      "first_observed_at": "2026-07-13T06:32:51.098771+00:00",
      "id": "CVE-2026-6382",
      "impact_tags": [
        "command injection risk",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-13T06:32:51.098771+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The FileOrganizer WordPress plugin before 1.1.9, Advanced File Manager WordPress plugin before 5.4.12, File Manager Pro WordPress plugin before 2.1.1, File Manager WordPress plugin before 8.0.4 do not properly escape a parameter before passing it to a shell... NVD: This requires the server to have the ImageMagick convert CLI available without either the PHP imagick or GD extensions.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260713T063521Z/items/CVE-2026-6382.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes command injection risk · authenticated boundary. Possible impact: An attacker may be able to run unintended system commands through the affected component.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The FileOrganizer WordPress plugin before 1.1.9, Advanced File Manager WordPress plugin before 5.4.12, File Manager Pro WordPress plugin before 2.1.1, File Manager WordPress plugin before 8.0.4 do not properly escape a parameter before passing it to a shell... NVD: This requires the server to have the ImageMagick convert CLI available without either the PHP imagick or GD extensions.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-6382/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "Kernel",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-63875/",
      "current_public_safe_latest": false,
      "cvss_score": 7.8,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.06005,
      "epss_score": 0.00164,
      "first_observed_at": "2026-07-26T16:16:58.690321+00:00",
      "id": "CVE-2026-63875",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-26T16:16:58.690321+00:00",
      "latest_item_url": null,
      "product": "Kernel",
      "public_safe_summary": "NVD: In the Linux kernel, the following vulnerability has been resolved: arm64: tlb: Flush walk cache when unsharing PMD tables When huge_pmd_unshare() is called to unshare a PMD table, the tlb_unshare_pmd_ptdesc() function sets tlb->unshared_tables=true but the... NVD: This caused the stale PMD page table entry to remain in the walk cache after unshare, potentially leading to incorrect page table walks. NVD: Fix by including unshared_tables in the check, so that when unsharing tables, TLBF_NONE is used and the walk cache is properly invalidated.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260726T162003Z/items/CVE-2026-63875.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: Kernel; package/component: Kernel",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: In the Linux kernel, the following vulnerability has been resolved: arm64: tlb: Flush walk cache when unsharing PMD tables When huge_pmd_unshare() is called to unshare a PMD table, the tlb_unshare_pmd_ptdesc() function sets tlb->unshared_tables=true but the... NVD: This caused the stale PMD page table entry to remain in the walk cache after unshare, potentially leading to incorrect page table walks. NVD: Fix by including unshared_tables in the check, so that when unsharing tables, TLBF_NONE is used and the walk cache is properly invalidated.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-63875/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "Kernel",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-63876/",
      "current_public_safe_latest": false,
      "cvss_score": null,
      "cvss_severity": "UNKNOWN",
      "epss_percentile": 0.11231,
      "epss_score": 0.00209,
      "first_observed_at": "2026-07-26T16:16:58.690321+00:00",
      "id": "CVE-2026-63876",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-26T16:16:58.690321+00:00",
      "latest_item_url": null,
      "product": "Kernel",
      "public_safe_summary": "NVD: In the Linux kernel, the following vulnerability has been resolved: serial: zs: Convert to use a platform device Prevent a crash from happening as the first serial port is initialised: Console: switching to mono frame buffer device 160x64 fb0: PMAG-AA frame... NVD: Call Trace: [<803ab00c>] serial_base_ctrl_add+0x78/0xf4 [<803aa644>] serial_core_register_port+0x174/0x69c [<8077e9ac>] zs_init+0xc8/0xfc [<800404d4>] do_one_initcall+0x40/0x2ac [<8076cecc>] kernel_init_freeable+0x1e4/0x270 [<80605bec>] kernel_init+0x20/0x108... NVD: Since no device is available with legacy probing and it's not anymore a preferable way to discover devices anyway, switch the driver to using a platform device and use it as the port's parent device.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260726T162003Z/items/CVE-2026-63876.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: Kernel; package/component: Kernel",
      "source_published_impact": "This unknown severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: In the Linux kernel, the following vulnerability has been resolved: serial: zs: Convert to use a platform device Prevent a crash from happening as the first serial port is initialised: Console: switching to mono frame buffer device 160x64 fb0: PMAG-AA frame... NVD: Call Trace: [<803ab00c>] serial_base_ctrl_add+0x78/0xf4 [<803aa644>] serial_core_register_port+0x174/0x69c [<8077e9ac>] zs_init+0xc8/0xfc [<800404d4>] do_one_initcall+0x40/0x2ac [<8076cecc>] kernel_init_freeable+0x1e4/0x270 [<80605bec>] kernel_init+0x20/0x108... NVD: Since no device is available with legacy probing and it's not anymore a preferable way to discover devices anyway, switch the driver to using a platform device and use it as the port's parent device.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-63876/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "Kernel",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-63877/",
      "current_public_safe_latest": false,
      "cvss_score": null,
      "cvss_severity": "UNKNOWN",
      "epss_percentile": 0.11231,
      "epss_score": 0.00209,
      "first_observed_at": "2026-07-26T16:16:58.690321+00:00",
      "id": "CVE-2026-63877",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-26T16:16:58.690321+00:00",
      "latest_item_url": null,
      "product": "Kernel",
      "public_safe_summary": "NVD: In the Linux kernel, the following vulnerability has been resolved: serial: dz: Convert to use a platform device Prevent a crash from happening as the first serial port is initialised: Console: switching to colour frame buffer device 160x64 tgafb: SFB+... NVD: Call Trace: [<8048b3a4>] __dev_fwnode+0x0/0xc [<80470a78>] serial_base_ctrl_add+0xa0/0x168 [<8046fc84>] serial_core_register_port+0x1c8/0x974 [<808c6af0>] dz_init+0x74/0xc8 [<800470e0>] do_one_initcall+0x44/0x2d4 [<808b111c>] kernel_init_freeable+0x258/0x308... NVD: Since no device is available with legacy probing and it's not anymore a preferable way to discover devices anyway, switch the driver to using a platform device and use it as the port's parent device.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260726T162003Z/items/CVE-2026-63877.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: Kernel; package/component: Kernel",
      "source_published_impact": "This unknown severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: In the Linux kernel, the following vulnerability has been resolved: serial: dz: Convert to use a platform device Prevent a crash from happening as the first serial port is initialised: Console: switching to colour frame buffer device 160x64 tgafb: SFB+... NVD: Call Trace: [<8048b3a4>] __dev_fwnode+0x0/0xc [<80470a78>] serial_base_ctrl_add+0xa0/0x168 [<8046fc84>] serial_core_register_port+0x1c8/0x974 [<808c6af0>] dz_init+0x74/0xc8 [<800470e0>] do_one_initcall+0x44/0x2d4 [<808b111c>] kernel_init_freeable+0x258/0x308... NVD: Since no device is available with legacy probing and it's not anymore a preferable way to discover devices anyway, switch the driver to using a platform device and use it as the port's parent device.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-63877/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "Kernel",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-63878/",
      "current_public_safe_latest": false,
      "cvss_score": null,
      "cvss_severity": "UNKNOWN",
      "epss_percentile": 0.09859,
      "epss_score": 0.00198,
      "first_observed_at": "2026-07-26T16:16:58.690321+00:00",
      "id": "CVE-2026-63878",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-26T16:16:58.690321+00:00",
      "latest_item_url": null,
      "product": "Kernel",
      "public_safe_summary": "NVD: In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: check num_entries in GEM_OP GET_MAPPING_INFO kvcalloc(args->num_entries, sizeof(*vm_entries), GFP_KERNEL) at amdgpu_gem.c:1050 uses the user-supplied num_entries directly without... NVD: Since num_entries is a __u32 and sizeof(drm_amdgpu_gem_vm_entry) is 32 bytes, a large num_entries produces an allocation exceeding INT_MAX, triggering WARNING in __kvmalloc_node_noprof(), causing a kernel WARNING, TAINT_WARN, and panic on... NVD: Add a size bounds check before we invoke the kvzalloc() to reject oversized num_entries early with -EINVAL.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260726T162003Z/items/CVE-2026-63878.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: Kernel; package/component: Kernel",
      "source_published_impact": "This unknown severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: check num_entries in GEM_OP GET_MAPPING_INFO kvcalloc(args->num_entries, sizeof(*vm_entries), GFP_KERNEL) at amdgpu_gem.c:1050 uses the user-supplied num_entries directly without... NVD: Since num_entries is a __u32 and sizeof(drm_amdgpu_gem_vm_entry) is 32 bytes, a large num_entries produces an allocation exceeding INT_MAX, triggering WARNING in __kvmalloc_node_noprof(), causing a kernel WARNING, TAINT_WARN, and panic on... NVD: Add a size bounds check before we invoke the kvzalloc() to reject oversized num_entries early with -EINVAL.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-63878/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "Kernel",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-63879/",
      "current_public_safe_latest": false,
      "cvss_score": 7.8,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.06126,
      "epss_score": 0.00165,
      "first_observed_at": "2026-07-26T16:16:58.690321+00:00",
      "id": "CVE-2026-63879",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-26T16:16:58.690321+00:00",
      "latest_item_url": null,
      "product": "Kernel",
      "public_safe_summary": "NVD: In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: fix amdgpu_hmm_range_get_pages The notifier sequence must only be read once or otherwise we could work with invalid pages. NVD: While at it also fix the coding style, e.g. NVD: drop the pre-initialized return value and use the common define for 2G range.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260726T162003Z/items/CVE-2026-63879.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: Kernel; package/component: Kernel",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: fix amdgpu_hmm_range_get_pages The notifier sequence must only be read once or otherwise we could work with invalid pages. NVD: While at it also fix the coding style, e.g. NVD: drop the pre-initialized return value and use the common define for 2G range.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-63879/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "Kernel",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-63880/",
      "current_public_safe_latest": false,
      "cvss_score": null,
      "cvss_severity": "UNKNOWN",
      "epss_percentile": 0.09857,
      "epss_score": 0.00198,
      "first_observed_at": "2026-07-26T16:16:58.690321+00:00",
      "id": "CVE-2026-63880",
      "impact_tags": [
        "service availability review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-26T16:16:58.690321+00:00",
      "latest_item_url": null,
      "product": "Kernel",
      "public_safe_summary": "NVD: In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: fix lock leak on ENOMEM in AMDGPU_GEM_OP_GET_MAPPING_INFO The AMDGPU_GEM_OP_GET_MAPPING_INFO branch of amdgpu_gem_op_ioctl() holds three cleanup-tracked resources before calling... NVD: All three are released by the out_exec label that every other error path in this function jumps to. NVD: The kvcalloc() failure path returns -ENOMEM directly, skipping out_exec and leaking all three.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260726T162003Z/items/CVE-2026-63880.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: Kernel; package/component: Kernel",
      "source_published_impact": "Source describes service availability risk. Possible impact: The affected service may become unavailable or unreliable.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: fix lock leak on ENOMEM in AMDGPU_GEM_OP_GET_MAPPING_INFO The AMDGPU_GEM_OP_GET_MAPPING_INFO branch of amdgpu_gem_op_ioctl() holds three cleanup-tracked resources before calling... NVD: All three are released by the out_exec label that every other error path in this function jumps to. NVD: The kvcalloc() failure path returns -ENOMEM directly, skipping out_exec and leaking all three.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-63880/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "Kernel",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-63881/",
      "current_public_safe_latest": false,
      "cvss_score": 7.8,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.07481,
      "epss_score": 0.00177,
      "first_observed_at": "2026-07-26T16:16:58.690321+00:00",
      "id": "CVE-2026-63881",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-26T16:16:58.690321+00:00",
      "latest_item_url": null,
      "product": "Kernel",
      "public_safe_summary": "NVD: In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: fix a vulnerability of integer overflow in kfd debugger get_queue_ids() computes array_size = num_queues * sizeof(uint32_t), which could overflow on 32-bit size_t build. NVD: using array_size() instead, it saturates to SIZE_MAX on overflow. NVD: (cherry picked from commit 2d57a0475f085c08b49312dfd8edcb461845f285)",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260726T162003Z/items/CVE-2026-63881.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: Kernel; package/component: Kernel",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: fix a vulnerability of integer overflow in kfd debugger get_queue_ids() computes array_size = num_queues * sizeof(uint32_t), which could overflow on 32-bit size_t build. NVD: using array_size() instead, it saturates to SIZE_MAX on overflow. NVD: (cherry picked from commit 2d57a0475f085c08b49312dfd8edcb461845f285)",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-63881/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "Kernel",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-63882/",
      "current_public_safe_latest": false,
      "cvss_score": null,
      "cvss_severity": "UNKNOWN",
      "epss_percentile": 0.1082,
      "epss_score": 0.00206,
      "first_observed_at": "2026-07-26T16:16:58.690321+00:00",
      "id": "CVE-2026-63882",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-26T16:16:58.690321+00:00",
      "latest_item_url": null,
      "product": "Kernel",
      "public_safe_summary": "NVD: In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: fix NULL pointer bug in svm_range_set_attr The process_info could be NULL if user doesn't call kfd_ioctl_acquire_vm before calling kfd_ioctl_svm. NVD: (cherry picked from commit 83a26c812e0529eb040d31a76f73e33e637243d4) OSV: drm/amdkfd: fix NULL pointer bug in svm_range_set_attr",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260726T162003Z/items/CVE-2026-63882.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: Kernel; package/component: Kernel",
      "source_published_impact": "This unknown severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: fix NULL pointer bug in svm_range_set_attr The process_info could be NULL if user doesn't call kfd_ioctl_acquire_vm before calling kfd_ioctl_svm. NVD: (cherry picked from commit 83a26c812e0529eb040d31a76f73e33e637243d4) OSV: drm/amdkfd: fix NULL pointer bug in svm_range_set_attr",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-63882/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "Kernel",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-63883/",
      "current_public_safe_latest": false,
      "cvss_score": 7.3,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.05498,
      "epss_score": 0.00159,
      "first_observed_at": "2026-07-26T16:16:58.690321+00:00",
      "id": "CVE-2026-63883",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-26T16:16:58.690321+00:00",
      "latest_item_url": null,
      "product": "Kernel",
      "public_safe_summary": "NVD: In the Linux kernel, the following vulnerability has been resolved: serial: qcom_geni: fix kfifo underflow when flush precedes DMA completion IRQ When uart_flush_buffer() runs before the DMA completion IRQ is delivered, the following race can occur (all steps... NVD: DMA starts: tx_remaining = N, kfifo contains N bytes 2. NVD: DMA completes in hardware; IRQ is pending but not yet delivered 3.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260726T162003Z/items/CVE-2026-63883.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: Kernel; package/component: Kernel",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: In the Linux kernel, the following vulnerability has been resolved: serial: qcom_geni: fix kfifo underflow when flush precedes DMA completion IRQ When uart_flush_buffer() runs before the DMA completion IRQ is delivered, the following race can occur (all steps... NVD: DMA starts: tx_remaining = N, kfifo contains N bytes 2. NVD: DMA completes in hardware; IRQ is pending but not yet delivered 3.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-63883/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "Kernel",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-63884/",
      "current_public_safe_latest": false,
      "cvss_score": 7.8,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.06005,
      "epss_score": 0.00164,
      "first_observed_at": "2026-07-26T16:16:58.690321+00:00",
      "id": "CVE-2026-63884",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-26T16:16:58.690321+00:00",
      "latest_item_url": null,
      "product": "Kernel",
      "public_safe_summary": "NVD: In the Linux kernel, the following vulnerability has been resolved: drm/i915: Fix potential UAF in TTM object purge TLDR: The bo->ttm object might be changed by calling ttm_bo_validate(), move casting it to an i915_tt object later to actually get the right... NVD: A user reported hitting the following bug under heavy use on DG2: [26620.095550] Oops: general protection fault, probably for non-canonical address 0xa56b6b6b6b6b6b8b: 0000 1 SMP NOPTI [26620.095556] CPU: 2 UID: 0 PID: 631 Comm: Xorg Not tainted 6.18.8 #1... NVD: ttm_tt_init+0x65/0x80 [ttm] [26620.095644] ?",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260726T162003Z/items/CVE-2026-63884.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: Kernel; package/component: Kernel",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: In the Linux kernel, the following vulnerability has been resolved: drm/i915: Fix potential UAF in TTM object purge TLDR: The bo->ttm object might be changed by calling ttm_bo_validate(), move casting it to an i915_tt object later to actually get the right... NVD: A user reported hitting the following bug under heavy use on DG2: [26620.095550] Oops: general protection fault, probably for non-canonical address 0xa56b6b6b6b6b6b8b: 0000 1 SMP NOPTI [26620.095556] CPU: 2 UID: 0 PID: 631 Comm: Xorg Not tainted 6.18.8 #1... NVD: ttm_tt_init+0x65/0x80 [ttm] [26620.095644] ?",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-63884/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "Kernel",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-63885/",
      "current_public_safe_latest": false,
      "cvss_score": 8.8,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.05738,
      "epss_score": 0.00161,
      "first_observed_at": "2026-07-26T16:16:58.690321+00:00",
      "id": "CVE-2026-63885",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-26T16:16:58.690321+00:00",
      "latest_item_url": null,
      "product": "Kernel",
      "public_safe_summary": "NVD: In the Linux kernel, the following vulnerability has been resolved: drm/gem: fix race between change_handle and handle_delete drm_gem_change_handle_ioctl leaves the old handle live in the IDR during the window between spin_unlock(table_lock) and the final... NVD: A concurrent drm_gem_handle_delete on the old handle succeeds in this window, decrements handle_count to 0, and frees the GEM object while the new handle's IDR entry still references it. NVD: NULL the old handle's IDR entry before dropping table_lock so that any concurrent GEM_CLOSE on the old handle sees NULL and returns -EINVAL.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260726T162003Z/items/CVE-2026-63885.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: Kernel; package/component: Kernel",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: In the Linux kernel, the following vulnerability has been resolved: drm/gem: fix race between change_handle and handle_delete drm_gem_change_handle_ioctl leaves the old handle live in the IDR during the window between spin_unlock(table_lock) and the final... NVD: A concurrent drm_gem_handle_delete on the old handle succeeds in this window, decrements handle_count to 0, and frees the GEM object while the new handle's IDR entry still references it. NVD: NULL the old handle's IDR entry before dropping table_lock so that any concurrent GEM_CLOSE on the old handle sees NULL and returns -EINVAL.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-63885/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "Kernel",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-63886/",
      "current_public_safe_latest": false,
      "cvss_score": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.47973,
      "epss_score": 0.00664,
      "first_observed_at": "2026-07-26T16:16:58.690321+00:00",
      "id": "CVE-2026-63886",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-26T16:16:58.690321+00:00",
      "latest_item_url": null,
      "product": "Kernel",
      "public_safe_summary": "NVD: In the Linux kernel, the following vulnerability has been resolved: scsi: target: iscsi: Validate CHAP_R length before base64 decode chap_server_compute_hash() allocates client_digest as kzalloc(chap->digest_size) and then, for BASE64-encoded responses... NVD: chap_base64_decode() writes to the destination unconditionally as long as there is input to consume. NVD: With MAX_RESPONSE_LENGTH set to 128 and the \"0b\" prefix stripped by extract_param(), up to 127 base64 characters can reach the decoder.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260726T162003Z/items/CVE-2026-63886.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: Kernel; package/component: Kernel",
      "source_published_impact": "This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: In the Linux kernel, the following vulnerability has been resolved: scsi: target: iscsi: Validate CHAP_R length before base64 decode chap_server_compute_hash() allocates client_digest as kzalloc(chap->digest_size) and then, for BASE64-encoded responses... NVD: chap_base64_decode() writes to the destination unconditionally as long as there is input to consume. NVD: With MAX_RESPONSE_LENGTH set to 128 and the \"0b\" prefix stripped by extract_param(), up to 127 base64 characters can reach the decoder.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-63886/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "Kernel",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-63887/",
      "current_public_safe_latest": false,
      "cvss_score": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.51013,
      "epss_score": 0.00745,
      "first_observed_at": "2026-07-26T16:16:58.690321+00:00",
      "id": "CVE-2026-63887",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-26T16:16:58.690321+00:00",
      "latest_item_url": null,
      "product": "Kernel",
      "public_safe_summary": "NVD: In the Linux kernel, the following vulnerability has been resolved: scsi: target: iscsi: Bound iscsi_encode_text_output() appends to rsp_buf iscsi_encode_text_output() concatenates \"key=value\\0\" records into login->rsp_buf, an 8192-byte... NVD: 2048 * 16 = 32 KiB of output into an 8 KiB buffer, producing a ~24 KiB heap overrun in the kmalloc-8k slab. NVD: The fix introduces a static iscsi_encode_text_record() helper that uses snprintf() with a per-call bounds check against the remaining buffer, and threads a u32 textbuf_size parameter through iscsi_encode_text_output().",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260726T162003Z/items/CVE-2026-63887.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: Kernel; package/component: Kernel",
      "source_published_impact": "This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: In the Linux kernel, the following vulnerability has been resolved: scsi: target: iscsi: Bound iscsi_encode_text_output() appends to rsp_buf iscsi_encode_text_output() concatenates \"key=value\\0\" records into login->rsp_buf, an 8192-byte... NVD: 2048 * 16 = 32 KiB of output into an 8 KiB buffer, producing a ~24 KiB heap overrun in the kmalloc-8k slab. NVD: The fix introduces a static iscsi_encode_text_record() helper that uses snprintf() with a per-call bounds check against the remaining buffer, and threads a u32 textbuf_size parameter through iscsi_encode_text_output().",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-63887/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "Kernel",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-63888/",
      "current_public_safe_latest": false,
      "cvss_score": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.51014,
      "epss_score": 0.00745,
      "first_observed_at": "2026-07-26T16:16:58.690321+00:00",
      "id": "CVE-2026-63888",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-26T16:16:58.690321+00:00",
      "latest_item_url": null,
      "product": "Kernel",
      "public_safe_summary": "NVD: In the Linux kernel, the following vulnerability has been resolved: scsi: target: iscsi: Fix CRC overread and double-free in iscsit_handle_text_cmd() Two latent bugs in the Text-phase handler, both present since the original LIO integration in commit... NVD: text_in is kzalloc()'d at ALIGN(payload_length, 4). NVD: rx_size is then incremented by ISCSI_CRC_LEN to make room for the received DataDigest in the iovec, but the same (now-bumped) rx_size is passed as the buffer length to iscsit_crc_buf(): if (conn->conn_ops->DataDigest) { ...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260726T162003Z/items/CVE-2026-63888.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: Kernel; package/component: Kernel",
      "source_published_impact": "This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: In the Linux kernel, the following vulnerability has been resolved: scsi: target: iscsi: Fix CRC overread and double-free in iscsit_handle_text_cmd() Two latent bugs in the Text-phase handler, both present since the original LIO integration in commit... NVD: text_in is kzalloc()'d at ALIGN(payload_length, 4). NVD: rx_size is then incremented by ISCSI_CRC_LEN to make room for the received DataDigest in the iovec, but the same (now-bumped) rx_size is passed as the buffer length to iscsit_crc_buf(): if (conn->conn_ops->DataDigest) { ...",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-63888/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "Kernel",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-63889/",
      "current_public_safe_latest": false,
      "cvss_score": 8.1,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.25914,
      "epss_score": 0.00334,
      "first_observed_at": "2026-07-26T16:16:58.690321+00:00",
      "id": "CVE-2026-63889",
      "impact_tags": [
        "local exposure relevant"
      ],
      "kev": false,
      "last_observed_at": "2026-07-26T16:16:58.690321+00:00",
      "latest_item_url": null,
      "product": "Kernel",
      "public_safe_summary": "NVD: In the Linux kernel, the following vulnerability has been resolved: scsi: scsi_transport_fc: Widen FPIN pname walker counter to u32 An adjacent Fibre Channel fabric actor that can deliver an FPIN ELS frame to an lpfc or qla2xxx Linux initiator can trigger a... NVD: This is not a local userspace or IP network path; the attacker must be able to inject fabric traffic, for example as a compromised switch or fabric controller, or as a same-zone N_Port on a fabric that permits source spoofing. NVD: The Link-Integrity and Peer-Congestion FPIN walkers used a u8 loop counter against the 32-bit on-wire pname_count field, and did not bound pname_count by the descriptor body already validated by the TLV walker.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260726T162003Z/items/CVE-2026-63889.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: Kernel; package/component: Kernel",
      "source_published_impact": "Source describes local exposure. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for local exposure.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: In the Linux kernel, the following vulnerability has been resolved: scsi: scsi_transport_fc: Widen FPIN pname walker counter to u32 An adjacent Fibre Channel fabric actor that can deliver an FPIN ELS frame to an lpfc or qla2xxx Linux initiator can trigger a... NVD: This is not a local userspace or IP network path; the attacker must be able to inject fabric traffic, for example as a compromised switch or fabric controller, or as a same-zone N_Port on a fabric that permits source spoofing. NVD: The Link-Integrity and Peer-Congestion FPIN walkers used a u8 loop counter against the 32-bit on-wire pname_count field, and did not bound pname_count by the descriptor body already validated by the TLV walker.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-63889/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "Kernel",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-63890/",
      "current_public_safe_latest": false,
      "cvss_score": null,
      "cvss_severity": "UNKNOWN",
      "epss_percentile": 0.11445,
      "epss_score": 0.00211,
      "first_observed_at": "2026-07-26T16:16:58.690321+00:00",
      "id": "CVE-2026-63890",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-26T16:16:58.690321+00:00",
      "latest_item_url": null,
      "product": "Kernel",
      "public_safe_summary": "NVD: In the Linux kernel, the following vulnerability has been resolved: scsi: fcoe: Reject FIP descriptors with zero fip_dlen in CVL walker drivers/scsi/fcoe/fcoe_ctlr.c::fcoe_ctlr_recv_clr_vlink() advanced the descriptor cursor by an attacker-supplied fip_dlen... NVD: The named descriptor cases (FIP_DT_MAC, FIP_DT_NAME, FIP_DT_VN_ID) checked their per-type minimum lengths, but a FIP_DT_NON_CRITICAL descriptor (fip_dtype >= 128, which the standard requires receivers to silently ignore) skipped that check entirely. NVD: An unauthenticated L2 peer on the FCoE control VLAN could hang fcoe_ctlr_recv_work on an fcoe, qedf, or bnx2fc initiator indefinitely by emitting one FIP CVL frame whose single descriptor had fip_dtype == FIP_DT_NON_CRITICAL and fip_dlen == 0: the cursor...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260726T162003Z/items/CVE-2026-63890.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: Kernel; package/component: Kernel",
      "source_published_impact": "This unknown severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: In the Linux kernel, the following vulnerability has been resolved: scsi: fcoe: Reject FIP descriptors with zero fip_dlen in CVL walker drivers/scsi/fcoe/fcoe_ctlr.c::fcoe_ctlr_recv_clr_vlink() advanced the descriptor cursor by an attacker-supplied fip_dlen... NVD: The named descriptor cases (FIP_DT_MAC, FIP_DT_NAME, FIP_DT_VN_ID) checked their per-type minimum lengths, but a FIP_DT_NON_CRITICAL descriptor (fip_dtype >= 128, which the standard requires receivers to silently ignore) skipped that check entirely. NVD: An unauthenticated L2 peer on the FCoE control VLAN could hang fcoe_ctlr_recv_work on an fcoe, qedf, or bnx2fc initiator indefinitely by emitting one FIP CVL frame whose single descriptor had fip_dtype == FIP_DT_NON_CRITICAL and fip_dlen == 0: the cursor...",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-63890/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "Kernel",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-63891/",
      "current_public_safe_latest": false,
      "cvss_score": null,
      "cvss_severity": "UNKNOWN",
      "epss_percentile": 0.18072,
      "epss_score": 0.00263,
      "first_observed_at": "2026-07-26T16:16:58.690321+00:00",
      "id": "CVE-2026-63891",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-26T16:16:58.690321+00:00",
      "latest_item_url": null,
      "product": "Kernel",
      "public_safe_summary": "NVD: In the Linux kernel, the following vulnerability has been resolved: thunderbolt: property: Cap recursion depth in __tb_property_parse_dir() A DIRECTORY entry's value field is used as the dir_offset for a recursive call into __tb_property_parse_dir() with no... NVD: A crafted peer that chains DIRECTORY entries into a back-reference loop drives the parser until the kernel stack is exhausted and the guard page fires. NVD: Any untrusted XDomain peer (cable, dock, in-line inspector, adjacent host) that reaches the PROPERTIES_REQUEST control-plane exchange can trigger this without authentication.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260726T162003Z/items/CVE-2026-63891.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: Kernel; package/component: Kernel",
      "source_published_impact": "This unknown severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: In the Linux kernel, the following vulnerability has been resolved: thunderbolt: property: Cap recursion depth in __tb_property_parse_dir() A DIRECTORY entry's value field is used as the dir_offset for a recursive call into __tb_property_parse_dir() with no... NVD: A crafted peer that chains DIRECTORY entries into a back-reference loop drives the parser until the kernel stack is exhausted and the guard page fires. NVD: Any untrusted XDomain peer (cable, dock, in-line inspector, adjacent host) that reaches the PROPERTIES_REQUEST control-plane exchange can trigger this without authentication.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-63891/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "Kernel",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-63892/",
      "current_public_safe_latest": false,
      "cvss_score": null,
      "cvss_severity": "UNKNOWN",
      "epss_percentile": 0.12632,
      "epss_score": 0.0022,
      "first_observed_at": "2026-07-26T16:16:58.690321+00:00",
      "id": "CVE-2026-63892",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-26T16:16:58.690321+00:00",
      "latest_item_url": null,
      "product": "Kernel",
      "public_safe_summary": "NVD: In the Linux kernel, the following vulnerability has been resolved: thunderbolt: property: Reject dir_len < 4 to prevent size_t underflow On the non-root path, __tb_property_parse_dir() takes dir_len from entry->length (u16 widened to size_t). NVD: Two distinct OOB conditions follow when entry->length < 4: 1. NVD: The non-root path begins with kmemdup(&block[dir_offset], sizeof(*dir->uuid), ...) which always reads 4 dwords from dir_offset.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260726T162003Z/items/CVE-2026-63892.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: Kernel; package/component: Kernel",
      "source_published_impact": "This unknown severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: In the Linux kernel, the following vulnerability has been resolved: thunderbolt: property: Reject dir_len < 4 to prevent size_t underflow On the non-root path, __tb_property_parse_dir() takes dir_len from entry->length (u16 widened to size_t). NVD: Two distinct OOB conditions follow when entry->length < 4: 1. NVD: The non-root path begins with kmemdup(&block[dir_offset], sizeof(*dir->uuid), ...) which always reads 4 dwords from dir_offset.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-63892/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "Kernel",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-63893/",
      "current_public_safe_latest": false,
      "cvss_score": 8.1,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.28597,
      "epss_score": 0.0036,
      "first_observed_at": "2026-07-26T16:16:58.690321+00:00",
      "id": "CVE-2026-63893",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-26T16:16:58.690321+00:00",
      "latest_item_url": null,
      "product": "Kernel",
      "public_safe_summary": "NVD: In the Linux kernel, the following vulnerability has been resolved: thunderbolt: property: Reject u32 wrap in tb_property_entry_valid() entry->value is u32 and entry->length is u16; the sum is performed in u32 and wraps. NVD: A malicious XDomain peer can pick value = 0xffffff00, length = 0x100 so the sum 0x100000000 wraps to 0 and passes the > block_len check. NVD: tb_property_parse() then passes entry->value to parse_dwdata() as a dword offset into the property block, reading attacker-directed memory far past the allocation.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260726T162003Z/items/CVE-2026-63893.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: Kernel; package/component: Kernel",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: In the Linux kernel, the following vulnerability has been resolved: thunderbolt: property: Reject u32 wrap in tb_property_entry_valid() entry->value is u32 and entry->length is u16; the sum is performed in u32 and wraps. NVD: A malicious XDomain peer can pick value = 0xffffff00, length = 0x100 so the sum 0x100000000 wraps to 0 and passes the > block_len check. NVD: tb_property_parse() then passes entry->value to parse_dwdata() as a dword offset into the property block, reading attacker-directed memory far past the allocation.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-63893/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "Kernel",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-63894/",
      "current_public_safe_latest": false,
      "cvss_score": 7.8,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.05464,
      "epss_score": 0.00159,
      "first_observed_at": "2026-07-26T16:16:58.690321+00:00",
      "id": "CVE-2026-63894",
      "impact_tags": [
        "memory safety review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-26T16:16:58.690321+00:00",
      "latest_item_url": null,
      "product": "Kernel",
      "public_safe_summary": "NVD: In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_fs: serialize DMABUF cancel against request completion ffs_epfile_dmabuf_io_complete() calls usb_ep_free_request() on the completed request but leaves priv->req, the... NVD: A later FUNCTIONFS_DMABUF_DETACH ioctl or ffs_epfile_release() on the close path still sees priv->req non-NULL under ffs->eps_lock: if (priv->ep && priv->req) usb_ep_dequeue(priv->ep, priv->req); so usb_ep_dequeue() is called on a freed usb_request. NVD: On dummy_hcd the dequeue path only walks a live queue and pointer-compares, so the freed pointer reads without faulting and KASAN requires an explicit check at the FunctionFS call site to surface the use-after-free.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260726T162003Z/items/CVE-2026-63894.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: Kernel; package/component: Kernel",
      "source_published_impact": "Source describes memory safety review. Possible impact: The affected component has memory-safety risk that may lead to crash, privilege, or code-execution impact depending on exposure.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_fs: serialize DMABUF cancel against request completion ffs_epfile_dmabuf_io_complete() calls usb_ep_free_request() on the completed request but leaves priv->req, the... NVD: A later FUNCTIONFS_DMABUF_DETACH ioctl or ffs_epfile_release() on the close path still sees priv->req non-NULL under ffs->eps_lock: if (priv->ep && priv->req) usb_ep_dequeue(priv->ep, priv->req); so usb_ep_dequeue() is called on a freed usb_request. NVD: On dummy_hcd the dequeue path only walks a live queue and pointer-compares, so the freed pointer reads without faulting and KASAN requires an explicit check at the FunctionFS call site to surface the use-after-free.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-63894/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "Kernel",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-64256/",
      "current_public_safe_latest": false,
      "cvss_score": null,
      "cvss_severity": "UNKNOWN",
      "epss_percentile": 0.10108,
      "epss_score": 0.002,
      "first_observed_at": "2026-07-31T22:17:39.455090+00:00",
      "id": "CVE-2026-64256",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-01T06:11:07.668739+00:00",
      "latest_item_url": null,
      "product": "Kernel",
      "public_safe_summary": "NVD: In the Linux kernel, the following vulnerability has been resolved: xfs: don't wrap around quota ids in dqiterate LOLLM noticed that q_id is an unsigned 32-bit variable. NVD: If it happens to be set to XFS_DQ_ID_MAX due to a filesystem that actually has a dquot for ID_MAX, then this addition will truncate to zero and the iteration starts over. NVD: Fix this by casting to u64.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260801T061801Z/items/CVE-2026-64256.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "vendor/product: Kernel; package/component: Kernel",
      "source_published_impact": "This unknown severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: In the Linux kernel, the following vulnerability has been resolved: xfs: don't wrap around quota ids in dqiterate LOLLM noticed that q_id is an unsigned 32-bit variable. NVD: If it happens to be set to XFS_DQ_ID_MAX due to a filesystem that actually has a dquot for ID_MAX, then this addition will truncate to zero and the iteration starts over. NVD: Fix this by casting to u64.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-64256/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-64257/",
      "current_public_safe_latest": false,
      "cvss_score": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.48489,
      "epss_score": 0.00672,
      "first_observed_at": "2026-07-31T22:17:39.455090+00:00",
      "id": "CVE-2026-64257",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-01T06:11:07.668739+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: In the Linux kernel, the following vulnerability has been resolved: smb: client: reject overlapping data areas in SMB2 responses Commit 53b7c271f06b (\"smb: client: restrict implied bcc[0] exemption to responses without data area\") restricted the implied... NVD: However, the overlap handling in __smb2_calc_size() clears data_length, which can make an invalid response appear to have no data area and so qualify for the exception. NVD: Track data area overlap separately and reject such responses before applying the length compatibility exceptions.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260801T061801Z/items/CVE-2026-64257.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: In the Linux kernel, the following vulnerability has been resolved: smb: client: reject overlapping data areas in SMB2 responses Commit 53b7c271f06b (\"smb: client: restrict implied bcc[0] exemption to responses without data area\") restricted the implied... NVD: However, the overlap handling in __smb2_calc_size() clears data_length, which can make an invalid response appear to have no data area and so qualify for the exception. NVD: Track data area overlap separately and reject such responses before applying the length compatibility exceptions.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-64257/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "Kernel",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-64258/",
      "current_public_safe_latest": false,
      "cvss_score": null,
      "cvss_severity": "UNKNOWN",
      "epss_percentile": 0.09856,
      "epss_score": 0.00198,
      "first_observed_at": "2026-07-31T22:17:39.455090+00:00",
      "id": "CVE-2026-64258",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-01T06:11:07.668739+00:00",
      "latest_item_url": null,
      "product": "Kernel",
      "public_safe_summary": "NVD: In the Linux kernel, the following vulnerability has been resolved: fuse-uring: remove request-less entries from ent_w_req_queue to fix NULL deref If a copy into the userspace ring buffer fails, a request will be terminated and fuse_uring_req_end() will set... NVD: This can lead to a NULL deref if the request expiration logic scans ent_w_req_queue in the window before the entry is moved off it. NVD: Fix this by taking the entry off ent_w_req_queue and changing its state from FRRS_FUSE_REQ to FRRS_INVALID before terminating the request.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260801T061801Z/items/CVE-2026-64258.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "vendor/product: Kernel; package/component: Kernel",
      "source_published_impact": "This unknown severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: In the Linux kernel, the following vulnerability has been resolved: fuse-uring: remove request-less entries from ent_w_req_queue to fix NULL deref If a copy into the userspace ring buffer fails, a request will be terminated and fuse_uring_req_end() will set... NVD: This can lead to a NULL deref if the request expiration logic scans ent_w_req_queue in the window before the entry is moved off it. NVD: Fix this by taking the entry off ent_w_req_queue and changing its state from FRRS_FUSE_REQ to FRRS_INVALID before terminating the request.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-64258/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "Kernel",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-64259/",
      "current_public_safe_latest": false,
      "cvss_score": 7.8,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.05364,
      "epss_score": 0.00157,
      "first_observed_at": "2026-07-31T22:17:39.455090+00:00",
      "id": "CVE-2026-64259",
      "impact_tags": [
        "memory safety review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-01T06:11:07.668739+00:00",
      "latest_item_url": null,
      "product": "Kernel",
      "public_safe_summary": "NVD: In the Linux kernel, the following vulnerability has been resolved: fuse-uring: make a fuse_req on SQE commit only findable after memcpy Bad userspace might try to trick us and send commit SQEs request unique / commit-id of requests that are not even send to... NVD: fuse_uring_commit_fetch() ends the fuse request when the ring entry has a wrong state, but that could have caused a use-after-free with the memcpy operations in fuse_uring_send_in_task(). NVD: In order to avoid such races the call of fuse_uring_add_to_pq() is moved after the copy operations and just before completing the io-uring request - malicious userspace cannot find the request anymore until all prepration work in fuse-client/kernel is...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260801T061801Z/items/CVE-2026-64259.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "vendor/product: Kernel; package/component: Kernel",
      "source_published_impact": "Source describes memory safety review. Possible impact: The affected component has memory-safety risk that may lead to crash, privilege, or code-execution impact depending on exposure.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: In the Linux kernel, the following vulnerability has been resolved: fuse-uring: make a fuse_req on SQE commit only findable after memcpy Bad userspace might try to trick us and send commit SQEs request unique / commit-id of requests that are not even send to... NVD: fuse_uring_commit_fetch() ends the fuse request when the ring entry has a wrong state, but that could have caused a use-after-free with the memcpy operations in fuse_uring_send_in_task(). NVD: In order to avoid such races the call of fuse_uring_add_to_pq() is moved after the copy operations and just before completing the io-uring request - malicious userspace cannot find the request anymore until all prepration work in fuse-client/kernel is...",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-64259/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "Kernel",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-64260/",
      "current_public_safe_latest": false,
      "cvss_score": 7.8,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.05823,
      "epss_score": 0.00162,
      "first_observed_at": "2026-07-31T22:17:39.455090+00:00",
      "id": "CVE-2026-64260",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-01T06:11:07.668739+00:00",
      "latest_item_url": null,
      "product": "Kernel",
      "public_safe_summary": "NVD: In the Linux kernel, the following vulnerability has been resolved: fuse-uring: Avoid queue->stopped races and set/read that value under lock There are several readers of queue->stopped that check the value under lock, but fuse_uring_commit_fetch() did not... NVD: Especially in fuse_uring_commit_fetch it is important to check under a lock, because due to races 'struct fuse_req' might be freed with fuse_request_end, but another thread/cpu might already do teardown work. OSV: fuse-uring: Avoid queue->stopped races and set/read that value under lock",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260801T061801Z/items/CVE-2026-64260.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "vendor/product: Kernel; package/component: Kernel",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: In the Linux kernel, the following vulnerability has been resolved: fuse-uring: Avoid queue->stopped races and set/read that value under lock There are several readers of queue->stopped that check the value under lock, but fuse_uring_commit_fetch() did not... NVD: Especially in fuse_uring_commit_fetch it is important to check under a lock, because due to races 'struct fuse_req' might be freed with fuse_request_end, but another thread/cpu might already do teardown work. OSV: fuse-uring: Avoid queue->stopped races and set/read that value under lock",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-64260/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "Kernel",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-64261/",
      "current_public_safe_latest": false,
      "cvss_score": 7.8,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.05364,
      "epss_score": 0.00157,
      "first_observed_at": "2026-07-31T22:17:39.455090+00:00",
      "id": "CVE-2026-64261",
      "impact_tags": [
        "memory safety review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-01T06:11:07.668739+00:00",
      "latest_item_url": null,
      "product": "Kernel",
      "public_safe_summary": "NVD: In the Linux kernel, the following vulnerability has been resolved: fuse-uring: Avoid use-after-free in fuse_uring_async_stop_queues fuse_uring_async_stop_queues() might run when the last reference on ring->queue_refs was already dropped. NVD: In order to avoid an early destruction a reference on struct fuse_conn is now taken before starting fuse_uring_async_stop_queues() and that reference is only released when that delayed work queue terminates. OSV: fuse-uring: Avoid use-after-free in fuse_uring_async_stop_queues",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260801T061801Z/items/CVE-2026-64261.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "vendor/product: Kernel; package/component: Kernel",
      "source_published_impact": "Source describes memory safety review. Possible impact: The affected component has memory-safety risk that may lead to crash, privilege, or code-execution impact depending on exposure.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: In the Linux kernel, the following vulnerability has been resolved: fuse-uring: Avoid use-after-free in fuse_uring_async_stop_queues fuse_uring_async_stop_queues() might run when the last reference on ring->queue_refs was already dropped. NVD: In order to avoid an early destruction a reference on struct fuse_conn is now taken before starting fuse_uring_async_stop_queues() and that reference is only released when that delayed work queue terminates. OSV: fuse-uring: Avoid use-after-free in fuse_uring_async_stop_queues",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-64261/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "Kernel",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-64262/",
      "current_public_safe_latest": false,
      "cvss_score": null,
      "cvss_severity": "UNKNOWN",
      "epss_percentile": 0.09852,
      "epss_score": 0.00198,
      "first_observed_at": "2026-08-01T06:11:07.668739+00:00",
      "id": "CVE-2026-64262",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-01T06:11:07.668739+00:00",
      "latest_item_url": null,
      "product": "Kernel",
      "public_safe_summary": "NVD: In the Linux kernel, the following vulnerability has been resolved: fuse-uring: end fuse_req on io-uring cancel task work When io_uring delivers task work with tw.cancel set (PF_EXITING, PF_KTHREAD fallback, or percpu_ref_is_dying on the ring context)... NVD: That path only flips the entry to FRRS_USERSPACE and completes the io_uring cmd; it never discharges the ring entry's owning reference to the fuse_req that fuse_uring_add_req_to_ring_ent() handed it at dispatch time. NVD: fuse_uring_send_in_task() tw.cancel == true err = -ECANCELED fuse_uring_send(ent, cmd, err, issue_flags) ent->state = FRRS_USERSPACE list_move(&ent->list, &queue->ent_in_userspace) ent->cmd = NULL io_uring_cmd_done(-ECANCELED) /* ent->fuse_req still set, req...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260801T061801Z/items/CVE-2026-64262.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: Kernel; package/component: Kernel",
      "source_published_impact": "This unknown severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: In the Linux kernel, the following vulnerability has been resolved: fuse-uring: end fuse_req on io-uring cancel task work When io_uring delivers task work with tw.cancel set (PF_EXITING, PF_KTHREAD fallback, or percpu_ref_is_dying on the ring context)... NVD: That path only flips the entry to FRRS_USERSPACE and completes the io_uring cmd; it never discharges the ring entry's owning reference to the fuse_req that fuse_uring_add_req_to_ring_ent() handed it at dispatch time. NVD: fuse_uring_send_in_task() tw.cancel == true err = -ECANCELED fuse_uring_send(ent, cmd, err, issue_flags) ent->state = FRRS_USERSPACE list_move(&ent->list, &queue->ent_in_userspace) ent->cmd = NULL io_uring_cmd_done(-ECANCELED) /* ent->fuse_req still set, req...",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-64262/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "Kernel",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-64263/",
      "current_public_safe_latest": false,
      "cvss_score": null,
      "cvss_severity": "UNKNOWN",
      "epss_percentile": 0.09855,
      "epss_score": 0.00198,
      "first_observed_at": "2026-08-01T06:11:07.668739+00:00",
      "id": "CVE-2026-64263",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-01T06:11:07.668739+00:00",
      "latest_item_url": null,
      "product": "Kernel",
      "public_safe_summary": "NVD: In the Linux kernel, the following vulnerability has been resolved: fuse-uring: fix moving cancelled entry to ent_in_userspace list fuse_uring_cancel() moves entries that are available (these have no reqs attached) to the ent_in_userspace list. NVD: ent_list_request_expired() checks the first entry on ent_in_userspace and dereferences ent->fuse_req unconditionally, which will crash on a cancelled entry that was moved to this list. NVD: Fix this by freeing the entry and dropping queue_refs directly in fuse_uring_cancel().",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260801T061801Z/items/CVE-2026-64263.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: Kernel; package/component: Kernel",
      "source_published_impact": "This unknown severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: In the Linux kernel, the following vulnerability has been resolved: fuse-uring: fix moving cancelled entry to ent_in_userspace list fuse_uring_cancel() moves entries that are available (these have no reqs attached) to the ent_in_userspace list. NVD: ent_list_request_expired() checks the first entry on ent_in_userspace and dereferences ent->fuse_req unconditionally, which will crash on a cancelled entry that was moved to this list. NVD: Fix this by freeing the entry and dropping queue_refs directly in fuse_uring_cancel().",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-64263/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "Kernel",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-64264/",
      "current_public_safe_latest": false,
      "cvss_score": null,
      "cvss_severity": "UNKNOWN",
      "epss_percentile": 0.09855,
      "epss_score": 0.00198,
      "first_observed_at": "2026-08-01T06:11:07.668739+00:00",
      "id": "CVE-2026-64264",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-01T06:11:07.668739+00:00",
      "latest_item_url": null,
      "product": "Kernel",
      "public_safe_summary": "NVD: In the Linux kernel, the following vulnerability has been resolved: fuse-uring: fix EFAULT clobber in fuse_uring_commit copy_from_user() returns the number of bytes not copied as an unsigned residual on failure (1..sizeof(struct fuse_out_header)). NVD: fuse_uring_commit stores that residual in ssize_t err, sets req->out.h.error to -EFAULT, then jumps to out: with err still holding the positive residual. NVD: err = copy_from_user(&req->out.h, &ent->headers->in_out, sizeof(req->out.h)); if (err) { req->out.h.error = -EFAULT; goto out; /* err is the positive residual */ } ...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260801T061801Z/items/CVE-2026-64264.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: Kernel; package/component: Kernel",
      "source_published_impact": "This unknown severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: In the Linux kernel, the following vulnerability has been resolved: fuse-uring: fix EFAULT clobber in fuse_uring_commit copy_from_user() returns the number of bytes not copied as an unsigned residual on failure (1..sizeof(struct fuse_out_header)). NVD: fuse_uring_commit stores that residual in ssize_t err, sets req->out.h.error to -EFAULT, then jumps to out: with err still holding the positive residual. NVD: err = copy_from_user(&req->out.h, &ent->headers->in_out, sizeof(req->out.h)); if (err) { req->out.h.error = -EFAULT; goto out; /* err is the positive residual */ } ...",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-64264/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "Kernel",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-64265/",
      "current_public_safe_latest": false,
      "cvss_score": 7.8,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.05525,
      "epss_score": 0.00159,
      "first_observed_at": "2026-08-01T06:11:07.668739+00:00",
      "id": "CVE-2026-64265",
      "impact_tags": [
        "memory safety review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-01T06:11:07.668739+00:00",
      "latest_item_url": null,
      "product": "Kernel",
      "public_safe_summary": "NVD: In the Linux kernel, the following vulnerability has been resolved: fuse: clear intr_entry in fuse_resend and fuse_remove_pending_req When fuse_resend() moves a request from fpq->processing back to fiq->pending, it sets FR_PENDING and clears FR_SENT but does... NVD: If the request had FR_INTERRUPTED set from a prior signal, intr_entry remains dangling on fiq->interrupts. NVD: When the requesting task then receives a fatal signal, fuse_remove_pending_req() sees FR_PENDING=1, removes the request from fiq->pending and frees it via the refcount path, also without cleaning intr_entry.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260801T061801Z/items/CVE-2026-64265.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: Kernel; package/component: Kernel",
      "source_published_impact": "Source describes memory safety review. Possible impact: The affected component has memory-safety risk that may lead to crash, privilege, or code-execution impact depending on exposure.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: In the Linux kernel, the following vulnerability has been resolved: fuse: clear intr_entry in fuse_resend and fuse_remove_pending_req When fuse_resend() moves a request from fpq->processing back to fiq->pending, it sets FR_PENDING and clears FR_SENT but does... NVD: If the request had FR_INTERRUPTED set from a prior signal, intr_entry remains dangling on fiq->interrupts. NVD: When the requesting task then receives a fatal signal, fuse_remove_pending_req() sees FR_PENDING=1, removes the request from fiq->pending and frees it via the refcount path, also without cleaning intr_entry.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-64265/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "Kernel",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-64266/",
      "current_public_safe_latest": false,
      "cvss_score": 7.8,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.05601,
      "epss_score": 0.0016,
      "first_observed_at": "2026-08-01T06:11:07.668739+00:00",
      "id": "CVE-2026-64266",
      "impact_tags": [
        "memory safety review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-01T06:11:07.668739+00:00",
      "latest_item_url": null,
      "product": "Kernel",
      "public_safe_summary": "NVD: In the Linux kernel, the following vulnerability has been resolved: fuse: re-lock request before returning from fuse_ref_folio() fuse_ref_folio() unlocks the request but does not re-lock it before returning. NVD: fuse_chan_abort() can end the request and the async end callback (eg fuse_writepage_free()) can free the args while the subsequent copy chain logic after fuse_ref_folio() accesses them, leading to use-after-free issues. NVD: Fix this by locking the request in fuse_ref_folio() before returning.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260801T061801Z/items/CVE-2026-64266.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: Kernel; package/component: Kernel",
      "source_published_impact": "Source describes memory safety review. Possible impact: The affected component has memory-safety risk that may lead to crash, privilege, or code-execution impact depending on exposure.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: In the Linux kernel, the following vulnerability has been resolved: fuse: re-lock request before returning from fuse_ref_folio() fuse_ref_folio() unlocks the request but does not re-lock it before returning. NVD: fuse_chan_abort() can end the request and the async end callback (eg fuse_writepage_free()) can free the args while the subsequent copy chain logic after fuse_ref_folio() accesses them, leading to use-after-free issues. NVD: Fix this by locking the request in fuse_ref_folio() before returning.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-64266/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "Kernel",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-64267/",
      "current_public_safe_latest": false,
      "cvss_score": null,
      "cvss_severity": "UNKNOWN",
      "epss_percentile": 0.09854,
      "epss_score": 0.00198,
      "first_observed_at": "2026-08-01T06:11:07.668739+00:00",
      "id": "CVE-2026-64267",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-01T06:11:07.668739+00:00",
      "latest_item_url": null,
      "product": "Kernel",
      "public_safe_summary": "NVD: In QEMU this reaches the fuse_copy_fill() BUG_ON(!err) path. NVD: That accepts exactly the same valid messages, but avoids wrapping arithmetic before the copy loop consumes the count. OSV: fuse: avoid 32-bit prune notification count wrap",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260801T061801Z/items/CVE-2026-64267.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: Kernel; package/component: Kernel",
      "source_published_impact": "This unknown severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: In QEMU this reaches the fuse_copy_fill() BUG_ON(!err) path. NVD: That accepts exactly the same valid messages, but avoids wrapping arithmetic before the copy loop consumes the count. OSV: fuse: avoid 32-bit prune notification count wrap",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-64267/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "Kernel",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-64268/",
      "current_public_safe_latest": false,
      "cvss_score": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.49394,
      "epss_score": 0.00695,
      "first_observed_at": "2026-08-01T06:11:07.668739+00:00",
      "id": "CVE-2026-64268",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-01T06:11:07.668739+00:00",
      "latest_item_url": null,
      "product": "Kernel",
      "public_safe_summary": "NVD: In the Linux kernel, the following vulnerability has been resolved: RDMA/siw: bound Read Response placement to the RREAD length In drivers/infiniband/sw/siw/siw_qp_rx.c, siw_proc_rresp() places each inbound Read Response DDP segment at sge->laddr +... NVD: siw_check_sge() resolves and validates the sink memory only on the first fragment (the if (!*mem) branch), and siw_rresp_check_ntoh() compares the cumulative length against wqe->bytes only on the final segment (the !frx->more_ddp_segs guard). NVD: siw runs iWARP over ordinary routable TCP, so the peer is the remote end of an established RDMA connection and needs no local privilege.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260801T061801Z/items/CVE-2026-64268.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: Kernel; package/component: Kernel",
      "source_published_impact": "This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: In the Linux kernel, the following vulnerability has been resolved: RDMA/siw: bound Read Response placement to the RREAD length In drivers/infiniband/sw/siw/siw_qp_rx.c, siw_proc_rresp() places each inbound Read Response DDP segment at sge->laddr +... NVD: siw_check_sge() resolves and validates the sink memory only on the first fragment (the if (!*mem) branch), and siw_rresp_check_ntoh() compares the cumulative length against wqe->bytes only on the final segment (the !frx->more_ddp_segs guard). NVD: siw runs iWARP over ordinary routable TCP, so the peer is the remote end of an established RDMA connection and needs no local privilege.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-64268/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "Kernel",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-64269/",
      "current_public_safe_latest": false,
      "cvss_score": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.48786,
      "epss_score": 0.00679,
      "first_observed_at": "2026-08-01T06:11:07.668739+00:00",
      "id": "CVE-2026-64269",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-01T06:11:07.668739+00:00",
      "latest_item_url": null,
      "product": "Kernel",
      "public_safe_summary": "NVD: In the Linux kernel, the following vulnerability has been resolved: RDMA/rtrs-srv: Bound RDMA-Write length to chunk size in rdma_write_sg When the server answers an RTRS READ, rdma_write_sg() builds the source scatter/gather entry for the IB_WR_RDMA_WRITE... NVD: Its length is taken directly from the wire descriptor: plist->length = le32_to_cpu(id->rd_msg->desc[0].len); rd_msg points into the chunk buffer that the remote peer filled via RDMA-WRITE-WITH-IMM (rtrs_srv_rdma_done() -> process_io_req() -> process_read())... NVD: The source address is the fixed chunk start (dma_addr[msg_id]) and the source lkey is the PD-wide local_dma_lkey, which is not tied to the chunk's MR mapping, so the verbs layer does not constrain the transfer length to max_chunk_size.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260801T061801Z/items/CVE-2026-64269.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: Kernel; package/component: Kernel",
      "source_published_impact": "This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: In the Linux kernel, the following vulnerability has been resolved: RDMA/rtrs-srv: Bound RDMA-Write length to chunk size in rdma_write_sg When the server answers an RTRS READ, rdma_write_sg() builds the source scatter/gather entry for the IB_WR_RDMA_WRITE... NVD: Its length is taken directly from the wire descriptor: plist->length = le32_to_cpu(id->rd_msg->desc[0].len); rd_msg points into the chunk buffer that the remote peer filled via RDMA-WRITE-WITH-IMM (rtrs_srv_rdma_done() -> process_io_req() -> process_read())... NVD: The source address is the fixed chunk start (dma_addr[msg_id]) and the source lkey is the PD-wide local_dma_lkey, which is not tied to the chunk's MR mapping, so the verbs layer does not constrain the transfer length to max_chunk_size.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-64269/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "Kernel",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-64270/",
      "current_public_safe_latest": false,
      "cvss_score": null,
      "cvss_severity": "UNKNOWN",
      "epss_percentile": 0.10107,
      "epss_score": 0.002,
      "first_observed_at": "2026-08-01T06:11:07.668739+00:00",
      "id": "CVE-2026-64270",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-01T06:11:07.668739+00:00",
      "latest_item_url": null,
      "product": "Kernel",
      "public_safe_summary": "NVD: In the Linux kernel, the following vulnerability has been resolved: Input: mms114 - reject an oversized device packet size mms114_interrupt() reads a packet of touch data from the device into a fixed-size on-stack buffer struct mms114_touch... NVD: 80 bytes. NVD: The length of the I2C read into it is taken verbatim from the device: packet_size = mms114_read_reg(data, MMS114_PACKET_SIZE); if (packet_size <= 0) goto out; ...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260801T061801Z/items/CVE-2026-64270.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: Kernel; package/component: Kernel",
      "source_published_impact": "This unknown severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: In the Linux kernel, the following vulnerability has been resolved: Input: mms114 - reject an oversized device packet size mms114_interrupt() reads a packet of touch data from the device into a fixed-size on-stack buffer struct mms114_touch... NVD: 80 bytes. NVD: The length of the I2C read into it is taken verbatim from the device: packet_size = mms114_read_reg(data, MMS114_PACKET_SIZE); if (packet_size <= 0) goto out; ...",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-64270/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "Kernel",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-64271/",
      "current_public_safe_latest": false,
      "cvss_score": null,
      "cvss_severity": "UNKNOWN",
      "epss_percentile": 0.11443,
      "epss_score": 0.00211,
      "first_observed_at": "2026-08-01T06:11:07.668739+00:00",
      "id": "CVE-2026-64271",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-01T06:11:07.668739+00:00",
      "latest_item_url": null,
      "product": "Kernel",
      "public_safe_summary": "NVD: In the Linux kernel, the following vulnerability has been resolved: Input: touchwin - reset the packet index on every complete packet tw_interrupt() accumulates each non-zero serial byte into a fixed three-byte buffer with a running index that is only reset... NVD: tw->idx = 0; } The reset is gated on tw->data[1] == tw->data[2], a value the device controls. NVD: A malicious, malfunctioning or counterfeit Touchwindow peripheral can stream non-zero bytes whose 2nd and 3rd bytes differ: the index reaches TW_LENGTH without the equality holding, is never reset, and keeps growing, so tw->data[tw->idx++] walks off the end...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260801T061801Z/items/CVE-2026-64271.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: Kernel; package/component: Kernel",
      "source_published_impact": "This unknown severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: In the Linux kernel, the following vulnerability has been resolved: Input: touchwin - reset the packet index on every complete packet tw_interrupt() accumulates each non-zero serial byte into a fixed three-byte buffer with a running index that is only reset... NVD: tw->idx = 0; } The reset is gated on tw->data[1] == tw->data[2], a value the device controls. NVD: A malicious, malfunctioning or counterfeit Touchwindow peripheral can stream non-zero bytes whose 2nd and 3rd bytes differ: the index reaches TW_LENGTH without the equality holding, is never reset, and keeps growing, so tw->data[tw->idx++] walks off the end...",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-64271/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "Kernel",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-64530/",
      "current_public_safe_latest": false,
      "cvss_score": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.40616,
      "epss_score": 0.00509,
      "first_observed_at": "2026-08-01T10:51:40.555213+00:00",
      "id": "CVE-2026-64530",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-02T06:14:57.521051+00:00",
      "latest_item_url": null,
      "product": "Kernel",
      "public_safe_summary": "NVD: In the Linux kernel, the following vulnerability has been resolved: net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_handle tcf_classify() can return TC_ACT_CONSUMED while the skb is held by the defragmentation engine (e.g. NVD: act_ct on out-of-order fragments). NVD: When that happens the skb is no longer owned by the caller and must not be touched again.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260802T061806Z/items/CVE-2026-64530.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 4,
      "source_published_affected": "vendor/product: Kernel; package/component: Kernel",
      "source_published_impact": "This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: In the Linux kernel, the following vulnerability has been resolved: net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_handle tcf_classify() can return TC_ACT_CONSUMED while the skb is held by the defragmentation engine (e.g. NVD: act_ct on out-of-order fragments). NVD: When that happens the skb is no longer owned by the caller and must not be touched again.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-64530/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "Kernel",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-64558/",
      "current_public_safe_latest": false,
      "cvss_score": 7.8,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.02132,
      "epss_score": 0.0012,
      "first_observed_at": "2026-08-05T16:55:08.588478+00:00",
      "id": "CVE-2026-64558",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-05T16:55:08.588478+00:00",
      "latest_item_url": null,
      "product": "Kernel",
      "public_safe_summary": "NVD: In the Linux kernel, the following vulnerability has been resolved: s390/pkey: Check length in pkey_pckmo handler implementation Explicitly check the length of the target buffer in the pkey_pckmo implementation of the key_to_protkey() handler function. NVD: The handler function fails, if the generated output data exceeds the length of the provided target buffer. OSV: s390/pkey: Check length in pkey_pckmo handler implementation",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260805T165944Z/items/CVE-2026-64558.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: Kernel; package/component: Kernel",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: In the Linux kernel, the following vulnerability has been resolved: s390/pkey: Check length in pkey_pckmo handler implementation Explicitly check the length of the target buffer in the pkey_pckmo implementation of the key_to_protkey() handler function. NVD: The handler function fails, if the generated output data exceeds the length of the provided target buffer. OSV: s390/pkey: Check length in pkey_pckmo handler implementation",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-64558/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "Kernel",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-64559/",
      "current_public_safe_latest": false,
      "cvss_score": 7.8,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.02132,
      "epss_score": 0.0012,
      "first_observed_at": "2026-08-05T16:55:08.588478+00:00",
      "id": "CVE-2026-64559",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-05T16:55:08.588478+00:00",
      "latest_item_url": null,
      "product": "Kernel",
      "public_safe_summary": "NVD: In the Linux kernel, the following vulnerability has been resolved: s390/pkey: Check length in PKEY_VERIFYPROTK ioctl Explicitly check the buffer length request structure provided by user-space and fail, if it exceeds the buffer size. OSV: s390/pkey: Check length in PKEY_VERIFYPROTK ioctl OSV: In the Linux kernel, the following vulnerability has been resolved: s390/pkey: Check length in PKEY_VERIFYPROTK ioctl Explicitly check the buffer length request structure provided by user-space and fail, if it exceeds the buffer size.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260805T165944Z/items/CVE-2026-64559.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: Kernel; package/component: Kernel",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: In the Linux kernel, the following vulnerability has been resolved: s390/pkey: Check length in PKEY_VERIFYPROTK ioctl Explicitly check the buffer length request structure provided by user-space and fail, if it exceeds the buffer size. OSV: s390/pkey: Check length in PKEY_VERIFYPROTK ioctl OSV: In the Linux kernel, the following vulnerability has been resolved: s390/pkey: Check length in PKEY_VERIFYPROTK ioctl Explicitly check the buffer length request structure provided by user-space and fail, if it exceeds the buffer size.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-64559/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "Kernel",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-64560/",
      "current_public_safe_latest": false,
      "cvss_score": 7.8,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.0217,
      "epss_score": 0.0012,
      "first_observed_at": "2026-08-05T16:55:08.588478+00:00",
      "id": "CVE-2026-64560",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-05T16:55:08.588478+00:00",
      "latest_item_url": null,
      "product": "Kernel",
      "public_safe_summary": "NVD: In the Linux kernel, the following vulnerability has been resolved: posix-cpu-timers: Prevent UAF caused by non-leader exec() race Wongi and Jungwoo decoded and reported a non-leader exec() related race which can result in an UAF: sys_timer_delete() exec()... NVD: As sys_timer_delete() freed the underlying posix timer object run_posix_cpu_timers() or any timerqueue related add/delete operations on other timers will access the freed object's timerqueue node, which results in an UAF. NVD: There is a similar problem vs.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260805T165944Z/items/CVE-2026-64560.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: Kernel; package/component: Kernel",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: In the Linux kernel, the following vulnerability has been resolved: posix-cpu-timers: Prevent UAF caused by non-leader exec() race Wongi and Jungwoo decoded and reported a non-leader exec() related race which can result in an UAF: sys_timer_delete() exec()... NVD: As sys_timer_delete() freed the underlying posix timer object run_posix_cpu_timers() or any timerqueue related add/delete operations on other timers will access the freed object's timerqueue node, which results in an UAF. NVD: There is a similar problem vs.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-64560/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-6459/",
      "current_public_safe_latest": false,
      "cvss_score": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.08461,
      "epss_score": 0.00187,
      "first_observed_at": "2026-07-15T11:03:27.604769+00:00",
      "id": "CVE-2026-6459",
      "impact_tags": [
        "XSS risk",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-15T11:03:27.604769+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Event Calendar widget in all versions up to, and including, 6.6.2 due to insufficient input sanitization and... NVD: This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260715T110622Z/items/CVE-2026-6459.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes XSS risk · authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Event Calendar widget in all versions up to, and including, 6.6.2 due to insufficient input sanitization and... NVD: This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-6459/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "Kernel",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-64600/",
      "current_public_safe_latest": false,
      "cvss_score": 7.8,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.39289,
      "epss_score": 0.00488,
      "first_observed_at": "2026-07-30T06:01:44.452906+00:00",
      "id": "CVE-2026-64600",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-30T06:01:44.452906+00:00",
      "latest_item_url": null,
      "product": "Kernel",
      "public_safe_summary": "NVD: In the Linux kernel, the following vulnerability has been resolved: xfs: resample the data fork mapping after cycling ILOCK xfs_reflink_fill_{cow_hole,delalloc} are both presented with an inode, a data fork mapping, and a cow fork mapping. NVD: Unfortunately, these two helpers cycle the ILOCK to grab a transaction, which means that the mappings are stale as soon as we reacquire the ILOCK. NVD: Currently we refresh the cow fork mapping by re-calling xfs_find_trim_cow_extent, but we don't refresh the data fork mapping beforehand, which means that the xfs_bmap_trim_cow in that function queries the refcount btree about the wrong physical blocks and...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260730T060504Z/items/CVE-2026-64600.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: Kernel; package/component: Kernel",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: In the Linux kernel, the following vulnerability has been resolved: xfs: resample the data fork mapping after cycling ILOCK xfs_reflink_fill_{cow_hole,delalloc} are both presented with an inode, a data fork mapping, and a cow fork mapping. NVD: Unfortunately, these two helpers cycle the ILOCK to grab a transaction, which means that the mappings are stale as soon as we reacquire the ILOCK. NVD: Currently we refresh the cow fork mapping by re-calling xfs_find_trim_cow_extent, but we don't refresh the data fork mapping beforehand, which means that the xfs_bmap_trim_cow in that function queries the refcount btree about the wrong physical blocks and...",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-64600/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-64607/",
      "current_public_safe_latest": false,
      "cvss_score": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.14826,
      "epss_score": 0.00238,
      "first_observed_at": "2026-08-07T10:13:53.604723+00:00",
      "id": "CVE-2026-64607",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-07T10:13:53.604723+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: HttpClient based on the classic i/o model fails to correctly release the underlying connection back to the connection manager if it encounters an invalid or unsupported Content-Encoding header value in the response message. NVD: Please note this defect does not affect HttpClient based on the async i/o model. NVD: This issue affects Apache HttpComponents Client: from 5.0-alpha1 through 5.6.2.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260807T102646Z/items/CVE-2026-64607.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: HttpClient based on the classic i/o model fails to correctly release the underlying connection back to the connection manager if it encounters an invalid or unsupported Content-Encoding header value in the response message. NVD: Please note this defect does not affect HttpClient based on the async i/o model. NVD: This issue affects Apache HttpComponents Client: from 5.0-alpha1 through 5.6.2.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-64607/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-64627/",
      "current_public_safe_latest": false,
      "cvss_score": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.20073,
      "epss_score": 0.00279,
      "first_observed_at": "2026-07-28T11:30:16.925551+00:00",
      "id": "CVE-2026-64627",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-28T11:30:16.925551+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Parse Server versions >= 9.0.0 before 9.10.0-alpha.4 and versions before 8.6.85 contain a schema disclosure vulnerability. NVD: When the GraphQL API is mounted with public introspection disabled (graphQLPublicIntrospection: false, the default), schema-derived 'Did you mean ...?' suggestions were still returned in GraphQL error messages produced during variable coercion, which were not... NVD: An unauthenticated caller possessing only the public application id can iteratively recover hidden schema identifiers — including registered Cloud Code function names and Parse class and field names — by submitting queries or mutations whose variables contain...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260728T113720Z/items/CVE-2026-64627.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: 9.10.0-alpha.4.",
      "source_published_summary": "NVD: Parse Server versions >= 9.0.0 before 9.10.0-alpha.4 and versions before 8.6.85 contain a schema disclosure vulnerability. NVD: When the GraphQL API is mounted with public introspection disabled (graphQLPublicIntrospection: false, the default), schema-derived 'Did you mean ...?' suggestions were still returned in GraphQL error messages produced during variable coercion, which were not... NVD: An unauthenticated caller possessing only the public application id can iteratively recover hidden schema identifiers — including registered Cloud Code function names and Parse class and field names — by submitting queries or mutations whose variables contain...",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-64627/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-64628/",
      "current_public_safe_latest": false,
      "cvss_score": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.04655,
      "epss_score": 0.0015,
      "first_observed_at": "2026-07-28T11:30:16.925551+00:00",
      "id": "CVE-2026-64628",
      "impact_tags": [
        "XSS risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-28T11:30:16.925551+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Grav contains a stored cross-site scripting vulnerability in shortcode-core attribute handlers where the XSS detection scan only matches payloads containing literal angle brackets, allowing shortcode parameters to bypass validation. NVD: Attackers with admin.pages permission can inject malicious JavaScript through shortcode attributes that execute in any viewer's browser, including administrators, enabling session hijacking via admin nonce theft.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260728T113720Z/items/CVE-2026-64628.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes XSS risk. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Grav contains a stored cross-site scripting vulnerability in shortcode-core attribute handlers where the XSS detection scan only matches payloads containing literal angle brackets, allowing shortcode parameters to bypass validation. NVD: Attackers with admin.pages permission can inject malicious JavaScript through shortcode attributes that execute in any viewer's browser, including administrators, enabling session hijacking via admin nonce theft.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-64628/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "vercel / next.js",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-64641/",
      "current_public_safe_latest": false,
      "cvss_score": 8.2,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.45325,
      "epss_score": 0.00599,
      "first_observed_at": "2026-08-03T17:21:47.396014+00:00",
      "id": "CVE-2026-64641",
      "impact_tags": [
        "service availability review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-03T17:21:47.396014+00:00",
      "latest_item_url": null,
      "product": "next.js",
      "public_safe_summary": "NVD: Next.js is a React framework for building full-stack web applications. NVD: In versions 13.0.0 through 15.5.20 and 16.0.0 through 16.2.10, crafted requests targeting Next.js applications using App Router with at least one Server Action can lead to excessive CPU usage blocking processing of further requests in the same process. NVD: This issue has been fixed in versions 15.5.21 and 16.2.11.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260803T174717Z/items/CVE-2026-64641.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: vercel / next.js",
      "source_published_impact": "Source describes service availability risk. Possible impact: The affected service may become unavailable or unreliable.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: versions.",
      "source_published_summary": "NVD: Next.js is a React framework for building full-stack web applications. NVD: In versions 13.0.0 through 15.5.20 and 16.0.0 through 16.2.10, crafted requests targeting Next.js applications using App Router with at least one Server Action can lead to excessive CPU usage blocking processing of further requests in the same process. NVD: This issue has been fixed in versions 15.5.21 and 16.2.11.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-64641/timeline.json",
      "vendor": "vercel"
    },
    {
      "affected_label": "vercel / next.js",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-64642/",
      "current_public_safe_latest": false,
      "cvss_score": 8.3,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.57723,
      "epss_score": 0.00948,
      "first_observed_at": "2026-08-03T17:21:47.396014+00:00",
      "id": "CVE-2026-64642",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-03T17:21:47.396014+00:00",
      "latest_item_url": null,
      "product": "next.js",
      "public_safe_summary": "NVD: Next.js is a React framework for building full-stack web applications. NVD: In versions 16.0.0 through 16.2.10, crafted requests targeting Next.js applications using App Router built with Turbopack and a single entry in config.i18n.locales can bypass middleware/proxy based authentication. NVD: This issue has been fixed in version 16.2.11.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260803T174717Z/items/CVE-2026-64642.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: vercel / next.js",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: Next.js is a React framework for building full-stack web applications. NVD: In versions 16.0.0 through 16.2.10, crafted requests targeting Next.js applications using App Router built with Turbopack and a single entry in config.i18n.locales can bypass middleware/proxy based authentication. NVD: This issue has been fixed in version 16.2.11.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-64642/timeline.json",
      "vendor": "vercel"
    },
    {
      "affected_label": "vercel / next.js",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-64643/",
      "current_public_safe_latest": false,
      "cvss_score": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.41114,
      "epss_score": 0.00516,
      "first_observed_at": "2026-08-03T17:21:47.396014+00:00",
      "id": "CVE-2026-64643",
      "impact_tags": [
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-03T17:21:47.396014+00:00",
      "latest_item_url": null,
      "product": "next.js",
      "public_safe_summary": "NVD: Next.js is a React framework for building full-stack web applications. NVD: In versions 12.0.0 through 15.5.20 and 16.0.0 through 16.2.10, Next.js applications using App Router, Server Actions (use server) or use cache endpoints can be disclosed bypassing any authentication on the pages where these endpoints are usually used. NVD: Server Action IDs can be disclosed to unauthenticated users via publicly served client artifacts (for example, static chunks containing action references).",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260803T174717Z/items/CVE-2026-64643.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: vercel / next.js",
      "source_published_impact": "Source describes authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: versions.",
      "source_published_summary": "NVD: Next.js is a React framework for building full-stack web applications. NVD: In versions 12.0.0 through 15.5.20 and 16.0.0 through 16.2.10, Next.js applications using App Router, Server Actions (use server) or use cache endpoints can be disclosed bypassing any authentication on the pages where these endpoints are usually used. NVD: Server Action IDs can be disclosed to unauthenticated users via publicly served client artifacts (for example, static chunks containing action references).",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-64643/timeline.json",
      "vendor": "vercel"
    },
    {
      "affected_label": "vercel / next.js",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-64644/",
      "current_public_safe_latest": false,
      "cvss_score": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.48676,
      "epss_score": 0.00675,
      "first_observed_at": "2026-08-03T17:21:47.396014+00:00",
      "id": "CVE-2026-64644",
      "impact_tags": [
        "service availability review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-03T17:21:47.396014+00:00",
      "latest_item_url": null,
      "product": "next.js",
      "public_safe_summary": "NVD: Next.js is a React framework for building full-stack web applications. NVD: In versions 15.5.0 through 15.5.20 and 16.0.0 through 16.2.10, when self-hosting Next.js with the default image loader, the Image Optimization API can optimize remotely hosted images if configured (not enabled by default). NVD: If those images contain malicious content, they can cause CPU exhaustion in /_next/image endpoints.Only config.images.remotePatterns is affected, and just the patterns in that array, whereas config.images.unoptimized: true, config.images.loader: 'custom', and...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260803T174717Z/items/CVE-2026-64644.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: vercel / next.js",
      "source_published_impact": "Source describes service availability risk. Possible impact: The affected service may become unavailable or unreliable.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: versions.",
      "source_published_summary": "NVD: Next.js is a React framework for building full-stack web applications. NVD: In versions 15.5.0 through 15.5.20 and 16.0.0 through 16.2.10, when self-hosting Next.js with the default image loader, the Image Optimization API can optimize remotely hosted images if configured (not enabled by default). NVD: If those images contain malicious content, they can cause CPU exhaustion in /_next/image endpoints.Only config.images.remotePatterns is affected, and just the patterns in that array, whereas config.images.unoptimized: true, config.images.loader: 'custom', and...",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-64644/timeline.json",
      "vendor": "vercel"
    },
    {
      "affected_label": "vercel / next.js",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-64645/",
      "current_public_safe_latest": false,
      "cvss_score": 8.3,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.5243,
      "epss_score": 0.00782,
      "first_observed_at": "2026-08-03T17:21:47.396014+00:00",
      "id": "CVE-2026-64645",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-03T17:21:47.396014+00:00",
      "latest_item_url": null,
      "product": "next.js",
      "public_safe_summary": "NVD: Next.js is a React framework for building full-stack web applications. NVD: In versions 12.0.0 through 15.5.20 and 16.0.0 through 16.2.10, a rewrites() or redirects() rule that builds its external destination hostname from request-controlled input can be pointed at an arbitrary hostname, regardless of the rule's hostname suffix. NVD: For a rewrite, Next.js proxies the request to that arbitrary host and serves the response from the application's origin, leading to Server-Side Request forgery.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260803T174717Z/items/CVE-2026-64645.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: vercel / next.js",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: versions.",
      "source_published_summary": "NVD: Next.js is a React framework for building full-stack web applications. NVD: In versions 12.0.0 through 15.5.20 and 16.0.0 through 16.2.10, a rewrites() or redirects() rule that builds its external destination hostname from request-controlled input can be pointed at an arbitrary hostname, regardless of the rule's hostname suffix. NVD: For a rewrite, Next.js proxies the request to that arbitrary host and serves the response from the application's origin, leading to Server-Side Request forgery.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-64645/timeline.json",
      "vendor": "vercel"
    },
    {
      "affected_label": "imagemagick / imagemagick",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-64685/",
      "current_public_safe_latest": false,
      "cvss_score": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.09708,
      "epss_score": 0.00197,
      "first_observed_at": "2026-08-05T22:30:13.133185+00:00",
      "id": "CVE-2026-64685",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-05T22:30:13.133185+00:00",
      "latest_item_url": null,
      "product": "imagemagick",
      "public_safe_summary": "NVD: ImageMagick is free and open-source software used for editing and manipulating digital images. NVD: In versions prior to 7.1.2-27, the BGR decoder does not check for an end-of-file in every location so a crafted image could result in an heap buffer over-read. NVD: This issue has been fixed in version 7.1.2-27.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260805T223715Z/items/CVE-2026-64685.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: imagemagick / imagemagick",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: ImageMagick is free and open-source software used for editing and manipulating digital images. NVD: In versions prior to 7.1.2-27, the BGR decoder does not check for an end-of-file in every location so a crafted image could result in an heap buffer over-read. NVD: This issue has been fixed in version 7.1.2-27.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-64685/timeline.json",
      "vendor": "imagemagick"
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-64827/",
      "current_public_safe_latest": false,
      "cvss_score": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.35838,
      "epss_score": 0.00435,
      "first_observed_at": "2026-08-10T10:38:36.347227+00:00",
      "id": "CVE-2026-64827",
      "impact_tags": [
        "authentication boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-10T10:38:36.347227+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Telenia Software TVox 26.5.3 and prior 26.x versions, and 24.9.21 and prior 24.x versions, contain an authentication bypass vulnerability in set_env.php where the redirectToLoginAdminIRequestHaveAccessToken() function derives the current page name from... NVD: Attackers can append '/login_admin.php' to the path of any target PHP script to cause the authentication check to pass and gain unauthenticated access to all PHP scripts under the manager HTML directory.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260810T105121Z/items/CVE-2026-64827.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes authentication boundary review. Possible impact: This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authentication boundary review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Telenia Software TVox 26.5.3 and prior 26.x versions, and 24.9.21 and prior 24.x versions, contain an authentication bypass vulnerability in set_env.php where the redirectToLoginAdminIRequestHaveAccessToken() function derives the current page name from... NVD: Attackers can append '/login_admin.php' to the path of any target PHP script to cause the authentication check to pass and gain unauthenticated access to all PHP scripts under the manager HTML directory.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-64827/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "ffmpeg / ffmpeg",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-64830/",
      "current_public_safe_latest": false,
      "cvss_score": 8.7,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.27334,
      "epss_score": 0.00347,
      "first_observed_at": "2026-07-29T16:40:34.107276+00:00",
      "id": "CVE-2026-64830",
      "impact_tags": [
        "code execution review",
        "memory safety review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-29T16:40:34.107276+00:00",
      "latest_item_url": null,
      "product": "ffmpeg",
      "public_safe_summary": "NVD: FFmpeg versions 2.1 through 8.1.2 contains a heap buffer overflow vulnerability in the VobSub subtitle demuxer that allows attackers to corrupt adjacent heap memory by supplying a malicious .sub/.idx subtitle file declaring more distinct stream IDs than the... NVD: Attackers can craft a subtitle file with excessive distinct stream IDs to trigger unbounded writes beyond the vobsub->q[] array boundary via ff_subtitles_queue_insert(), potentially achieving arbitrary code execution in any application using FFmpeg's VobSub...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260729T164826Z/items/CVE-2026-64830.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: ffmpeg / ffmpeg",
      "source_published_impact": "Source describes code execution review · memory safety review. Possible impact: An attacker may be able to run code or commands on affected systems.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: FFmpeg versions 2.1 through 8.1.2 contains a heap buffer overflow vulnerability in the VobSub subtitle demuxer that allows attackers to corrupt adjacent heap memory by supplying a malicious .sub/.idx subtitle file declaring more distinct stream IDs than the... NVD: Attackers can craft a subtitle file with excessive distinct stream IDs to trigger unbounded writes beyond the vobsub->q[] array boundary via ff_subtitles_queue_insert(), potentially achieving arbitrary code execution in any application using FFmpeg's VobSub...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-64830/timeline.json",
      "vendor": "ffmpeg"
    },
    {
      "affected_label": "ffmpeg / ffmpeg",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-64831/",
      "current_public_safe_latest": false,
      "cvss_score": 8.7,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.37339,
      "epss_score": 0.00457,
      "first_observed_at": "2026-07-29T16:40:34.107276+00:00",
      "id": "CVE-2026-64831",
      "impact_tags": [
        "code execution review",
        "memory safety review",
        "remote exposure relevant"
      ],
      "kev": false,
      "last_observed_at": "2026-07-29T16:40:34.107276+00:00",
      "latest_item_url": null,
      "product": "ffmpeg",
      "public_safe_summary": "NVD: FFmpeg versions 8.0 through 8.1.2 contains a stack buffer overflow vulnerability in the Vulkan HEVC hardware decoder that allows remote attackers to overwrite return addresses and adjacent stack frames by supplying a crafted HEVC/H.265 bitstream. NVD: Attackers can embed a malicious vps_num_hrd_parameters value exceeding HEVC_MAX_SUB_LAYERS in any supported container format to overflow stack-allocated arrays in the vk_hevc_end_frame function, potentially achieving arbitrary code execution.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260729T164826Z/items/CVE-2026-64831.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: ffmpeg / ffmpeg",
      "source_published_impact": "Source describes code execution review · memory safety review · remote exposure. Possible impact: A remote attacker may be able to run code or commands on affected systems.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: FFmpeg versions 8.0 through 8.1.2 contains a stack buffer overflow vulnerability in the Vulkan HEVC hardware decoder that allows remote attackers to overwrite return addresses and adjacent stack frames by supplying a crafted HEVC/H.265 bitstream. NVD: Attackers can embed a malicious vps_num_hrd_parameters value exceeding HEVC_MAX_SUB_LAYERS in any supported container format to overflow stack-allocated arrays in the vk_hevc_end_frame function, potentially achieving arbitrary code execution.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-64831/timeline.json",
      "vendor": "ffmpeg"
    },
    {
      "affected_label": "ffmpeg / ffmpeg",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-64832/",
      "current_public_safe_latest": false,
      "cvss_score": 8.7,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.25751,
      "epss_score": 0.00332,
      "first_observed_at": "2026-07-29T16:40:34.107276+00:00",
      "id": "CVE-2026-64832",
      "impact_tags": [
        "memory safety review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-29T16:40:34.107276+00:00",
      "latest_item_url": null,
      "product": "ffmpeg",
      "public_safe_summary": "NVD: FFmpeg versions 4.4 through 8.1.2 contain a double-free vulnerability in the NVIDIA NVDEC hardware decoder within libavcodec/nvdec.c that allows attackers to trigger memory corruption by supplying a crafted video file. NVD: When no decoder surfaces remain, the ff_nvdec_start_frame_sep_ref error path frees memory via nvdec_fdd_priv_free while the calling layer subsequently frees the same frame description data, resulting in a double-free of the underlying decoder context in any...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260729T164826Z/items/CVE-2026-64832.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: ffmpeg / ffmpeg",
      "source_published_impact": "Source describes memory safety review. Possible impact: The affected component has memory-safety risk that may lead to crash, privilege, or code-execution impact depending on exposure.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: FFmpeg versions 4.4 through 8.1.2 contain a double-free vulnerability in the NVIDIA NVDEC hardware decoder within libavcodec/nvdec.c that allows attackers to trigger memory corruption by supplying a crafted video file. NVD: When no decoder surfaces remain, the ff_nvdec_start_frame_sep_ref error path frees memory via nvdec_fdd_priv_free while the calling layer subsequently frees the same frame description data, resulting in a double-free of the underlying decoder context in any...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-64832/timeline.json",
      "vendor": "ffmpeg"
    },
    {
      "affected_label": "ffmpeg / ffmpeg",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-64833/",
      "current_public_safe_latest": false,
      "cvss_score": 7.1,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.11903,
      "epss_score": 0.00214,
      "first_observed_at": "2026-07-29T16:40:34.107276+00:00",
      "id": "CVE-2026-64833",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-29T16:40:34.107276+00:00",
      "latest_item_url": null,
      "product": "ffmpeg",
      "public_safe_summary": "NVD: FFmpeg versions 0.7.1 through 8.1.2 contain an out-of-bounds read vulnerability in the S/PDIF muxer that allows attackers to access memory beyond buffer boundaries by supplying a crafted DTS stream with a core_size value larger than the actual packet length. NVD: Attackers can exploit the missing bounds check in the spdif_header_dts4 function by providing a malicious DTS-HD audio stream during S/PDIF re-muxing to trigger unauthorized memory reads beyond the packet buffer.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260729T164826Z/items/CVE-2026-64833.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: ffmpeg / ffmpeg",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: FFmpeg versions 0.7.1 through 8.1.2 contain an out-of-bounds read vulnerability in the S/PDIF muxer that allows attackers to access memory beyond buffer boundaries by supplying a crafted DTS stream with a core_size value larger than the actual packet length. NVD: Attackers can exploit the missing bounds check in the spdif_header_dts4 function by providing a malicious DTS-HD audio stream during S/PDIF re-muxing to trigger unauthorized memory reads beyond the packet buffer.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-64833/timeline.json",
      "vendor": "ffmpeg"
    },
    {
      "affected_label": "ffmpeg / ffmpeg",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-64834/",
      "current_public_safe_latest": false,
      "cvss_score": 8.7,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.40127,
      "epss_score": 0.00503,
      "first_observed_at": "2026-07-29T16:40:34.107276+00:00",
      "id": "CVE-2026-64834",
      "impact_tags": [
        "service availability review",
        "remote exposure relevant"
      ],
      "kev": false,
      "last_observed_at": "2026-07-29T16:40:34.107276+00:00",
      "latest_item_url": null,
      "product": "ffmpeg",
      "public_safe_summary": "NVD: FFmpeg versions 0.6.3 through 8.1.2 contain an infinite loop vulnerability in the RTP/ASF demuxer within libavformat/rtpdec_asf.c that allows remote attackers to cause denial of service by sending a crafted RTP/ASF stream. NVD: The rtp_asf_fix_header function fails to validate a minimum chunksize when iterating over ASF objects, causing the loop pointer to never advance when a chunksize is smaller than the 24-byte minimum ASF object header size, resulting in CPU exhaustion that...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260729T164826Z/items/CVE-2026-64834.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: ffmpeg / ffmpeg",
      "source_published_impact": "Source describes service availability risk · remote exposure. Possible impact: The affected service may become unavailable or unreliable.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: FFmpeg versions 0.6.3 through 8.1.2 contain an infinite loop vulnerability in the RTP/ASF demuxer within libavformat/rtpdec_asf.c that allows remote attackers to cause denial of service by sending a crafted RTP/ASF stream. NVD: The rtp_asf_fix_header function fails to validate a minimum chunksize when iterating over ASF objects, causing the loop pointer to never advance when a chunksize is smaller than the 24-byte minimum ASF object header size, resulting in CPU exhaustion that...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-64834/timeline.json",
      "vendor": "ffmpeg"
    },
    {
      "affected_label": "ffmpeg / ffmpeg",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-64835/",
      "current_public_safe_latest": false,
      "cvss_score": 8.7,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.25751,
      "epss_score": 0.00332,
      "first_observed_at": "2026-07-29T16:40:34.107276+00:00",
      "id": "CVE-2026-64835",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-29T16:40:34.107276+00:00",
      "latest_item_url": null,
      "product": "ffmpeg",
      "public_safe_summary": "NVD: FFmpeg versions 4.4 through 8.1.2 contain an out-of-bounds memory access vulnerability in the ADX audio decoder within libavcodec/adxdec.c that allows attackers to trigger both out-of-bounds reads and writes by supplying a crafted ADX or AAX audio file with a... NVD: When AV_PKT_DATA_NEW_EXTRADATA side data is received mid-stream, the adx_decode_frame function re-parses the stream header but fails to update the internal channel state, causing subsequent decoding operations to access the prev[] state array using a stale...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260729T164826Z/items/CVE-2026-64835.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: ffmpeg / ffmpeg",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: FFmpeg versions 4.4 through 8.1.2 contain an out-of-bounds memory access vulnerability in the ADX audio decoder within libavcodec/adxdec.c that allows attackers to trigger both out-of-bounds reads and writes by supplying a crafted ADX or AAX audio file with a... NVD: When AV_PKT_DATA_NEW_EXTRADATA side data is received mid-stream, the adx_decode_frame function re-parses the stream header but fails to update the internal channel state, causing subsequent decoding operations to access the prev[] state array using a stale...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-64835/timeline.json",
      "vendor": "ffmpeg"
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-64863/",
      "current_public_safe_latest": false,
      "cvss_score": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.26229,
      "epss_score": 0.00337,
      "first_observed_at": "2026-08-04T22:31:51.932237+00:00",
      "id": "CVE-2026-64863",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-04T22:31:51.932237+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: goshs is a feature-rich single-binary file server for red teamers and developers. NVD: Prior to 2.1.4, the httpserver/server.go wdGuard handled WebDAV MOVE as a write-only method and did not enforce --no-delete, allowing WebDAV clients to delete or overwrite files via MOVE with Overwrite: T. NVD: This issue is fixed in version 2.1.4.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260804T223546Z/items/CVE-2026-64863.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: goshs is a feature-rich single-binary file server for red teamers and developers. NVD: Prior to 2.1.4, the httpserver/server.go wdGuard handled WebDAV MOVE as a write-only method and did not enforce --no-delete, allowing WebDAV clients to delete or overwrite files via MOVE with Overwrite: T. NVD: This issue is fixed in version 2.1.4.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-64863/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-65007/",
      "current_public_safe_latest": false,
      "cvss_score": 8.7,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.18279,
      "epss_score": 0.00266,
      "first_observed_at": "2026-07-28T11:30:16.925551+00:00",
      "id": "CVE-2026-65007",
      "impact_tags": [
        "privilege boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-28T11:30:16.925551+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Grav api plugin (grav-plugin-api) before 1.0.8 fails to properly authorize API key generation and revocation: the plugin intercepts the apiKeyGenerate/apiKeyRevoke admin tasks before the account-management ACL runs and authorizes the caller on only the... NVD: This allows any user with admin.login to mint a persistent API key bound to any account, and the forged key inherits the target account's API permissions. NVD: On installs where an API-enabled account holds broader permissions, this enables account impersonation and privilege escalation up to account takeover.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260728T113720Z/items/CVE-2026-65007.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes privilege escalation risk. Possible impact: An attacker may cross a privilege boundary and gain more access than intended.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Grav api plugin (grav-plugin-api) before 1.0.8 fails to properly authorize API key generation and revocation: the plugin intercepts the apiKeyGenerate/apiKeyRevoke admin tasks before the account-management ACL runs and authorizes the caller on only the... NVD: This allows any user with admin.login to mint a persistent API key bound to any account, and the forged key inherits the target account's API permissions. NVD: On installs where an API-enabled account holds broader permissions, this enables account impersonation and privilege escalation up to account takeover.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-65007/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-65008/",
      "current_public_safe_latest": false,
      "cvss_score": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.47305,
      "epss_score": 0.00648,
      "first_observed_at": "2026-07-28T11:30:16.925551+00:00",
      "id": "CVE-2026-65008",
      "impact_tags": [
        "code execution review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-28T11:30:16.925551+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Grav 2.0.4 (fixed in 2.0.7) contains a remote code execution vulnerability in Blueprint::dynamicData() (system/src/Grav/Common/Data/Blueprint.php), which passes a Class::method callable string and its arguments directly to call_user_func_array() without any... NVD: Because the form plugin routes page frontmatter through this path, an authenticated account with the admin.pages (or api.pages.write) permission can plant a malicious callable directive in a page. NVD: The command then executes as the web-server user whenever anyone — including an unauthenticated visitor — accesses the page.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260728T113720Z/items/CVE-2026-65008.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes code execution review. Possible impact: An attacker may be able to run code or commands on affected systems.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: 2.0.7.",
      "source_published_summary": "NVD: Grav 2.0.4 (fixed in 2.0.7) contains a remote code execution vulnerability in Blueprint::dynamicData() (system/src/Grav/Common/Data/Blueprint.php), which passes a Class::method callable string and its arguments directly to call_user_func_array() without any... NVD: Because the form plugin routes page frontmatter through this path, an authenticated account with the admin.pages (or api.pages.write) permission can plant a malicious callable directive in a page. NVD: The command then executes as the web-server user whenever anyone — including an unauthenticated visitor — accesses the page.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-65008/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-65009/",
      "current_public_safe_latest": false,
      "cvss_score": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.08163,
      "epss_score": 0.00183,
      "first_observed_at": "2026-07-28T11:30:16.925551+00:00",
      "id": "CVE-2026-65009",
      "impact_tags": [
        "information exposure review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-28T11:30:16.925551+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: OpenRemote versions before 1.26.2 contain an information disclosure vulnerability in the SyslogResource REST endpoint that fails to filter operational logs by realm. NVD: Attackers with the read:rules role can access the GET /api/{realm}/syslog/event endpoint to retrieve operational logs from all tenants, exposing asset IDs, agent connection details, rule names, and protocol errors across the multi-tenant deployment. OSV: OpenRemote before 1.26.2 Information Disclosure via Syslog REST API",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260728T113720Z/items/CVE-2026-65009.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes information exposure review. Possible impact: An attacker may be able to access information that should not be exposed.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: OpenRemote versions before 1.26.2 contain an information disclosure vulnerability in the SyslogResource REST endpoint that fails to filter operational logs by realm. NVD: Attackers with the read:rules role can access the GET /api/{realm}/syslog/event endpoint to retrieve operational logs from all tenants, exposing asset IDs, agent connection details, rule names, and protocol errors across the multi-tenant deployment. OSV: OpenRemote before 1.26.2 Information Disclosure via Syslog REST API",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-65009/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-65011/",
      "current_public_safe_latest": false,
      "cvss_score": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.12361,
      "epss_score": 0.00218,
      "first_observed_at": "2026-07-29T16:40:34.107276+00:00",
      "id": "CVE-2026-65011",
      "impact_tags": [
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-29T16:40:34.107276+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Graylog2 Server before commit 46a2eeb contains a missing per-entity permission check in the POST /events/definitions/{definitionId}/duplicate endpoint that allows authenticated users to clone any event definition. NVD: Attackers with the low-privilege eventdefinitions:create capability can read private event definitions including detection queries, aggregation thresholds, grouping fields, schedules, and notification bindings by duplicating them. OSV: Graylog2 Server Missing Permission Check on Event Definition Duplicate",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260729T164826Z/items/CVE-2026-65011.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Graylog2 Server before commit 46a2eeb contains a missing per-entity permission check in the POST /events/definitions/{definitionId}/duplicate endpoint that allows authenticated users to clone any event definition. NVD: Attackers with the low-privilege eventdefinitions:create capability can read private event definitions including detection queries, aggregation thresholds, grouping fields, schedules, and notification bindings by duplicating them. OSV: Graylog2 Server Missing Permission Check on Event Definition Duplicate",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-65011/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-65012/",
      "current_public_safe_latest": false,
      "cvss_score": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.17277,
      "epss_score": 0.00257,
      "first_observed_at": "2026-07-29T16:40:34.107276+00:00",
      "id": "CVE-2026-65012",
      "impact_tags": [
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-29T16:40:34.107276+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: InvokeAI before 6.13.7 contains an unauthenticated directory enumeration vulnerability in the GET /api/v2/models/scan_folder endpoint that accepts attacker-controlled scan_path parameters. NVD: Unauthenticated attackers can recursively enumerate arbitrary server filesystem directories and use HTTP response codes to determine file existence and readability, bypassing multi-user mode access controls. OSV: InvokeAI < 6.13.7 Unauthenticated Directory Enumeration via scan_folder",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260729T164826Z/items/CVE-2026-65012.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes remote exposure · authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: InvokeAI before 6.13.7 contains an unauthenticated directory enumeration vulnerability in the GET /api/v2/models/scan_folder endpoint that accepts attacker-controlled scan_path parameters. NVD: Unauthenticated attackers can recursively enumerate arbitrary server filesystem directories and use HTTP response codes to determine file existence and readability, bypassing multi-user mode access controls. OSV: InvokeAI < 6.13.7 Unauthenticated Directory Enumeration via scan_folder",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-65012/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-65013/",
      "current_public_safe_latest": false,
      "cvss_score": 8.7,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.22213,
      "epss_score": 0.003,
      "first_observed_at": "2026-07-29T16:40:34.107276+00:00",
      "id": "CVE-2026-65013",
      "impact_tags": [
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-29T16:40:34.107276+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Onlook through 0.2.32, fixed in commit 423e2e9, contains a broken object level authorization vulnerability that allows authenticated attackers to access and manipulate other users' resources by supplying arbitrary UUID values to tRPC API procedures including... NVD: Attackers can provide arbitrary projectId or conversationId values without authorization validation to read, modify, and delete other users' project data, members, and conversation history. OSV: Onlook tRPC Insecure Direct Object Reference via multiple procedures",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260729T164826Z/items/CVE-2026-65013.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes authenticated boundary. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: commit.",
      "source_published_summary": "NVD: Onlook through 0.2.32, fixed in commit 423e2e9, contains a broken object level authorization vulnerability that allows authenticated attackers to access and manipulate other users' resources by supplying arbitrary UUID values to tRPC API procedures including... NVD: Attackers can provide arbitrary projectId or conversationId values without authorization validation to read, modify, and delete other users' project data, members, and conversation history. OSV: Onlook tRPC Insecure Direct Object Reference via multiple procedures",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-65013/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "n8n / n8n",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-65014/",
      "current_public_safe_latest": false,
      "cvss_score": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.20851,
      "epss_score": 0.00286,
      "first_observed_at": "2026-07-29T11:36:18.065267+00:00",
      "id": "CVE-2026-65014",
      "impact_tags": [
        "authentication boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-29T11:36:18.065267+00:00",
      "latest_item_url": null,
      "product": "n8n",
      "public_safe_summary": "NVD: n8n before 2.28.0 (and before 2.27.4 on the 2.27.x branch) registers the DELETE /${restEndpoint}/test-webhook/:id endpoint before authentication middleware is applied, allowing any unauthenticated network caller who knows a workflow ID to cancel that... NVD: The impact is limited to disrupting in-progress test sessions; production webhooks, persistent workflow state, and stored data are not affected. OSV: n8n before 2.28.0 Authentication Bypass via test-webhook",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260729T114432Z/items/CVE-2026-65014.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: n8n / n8n",
      "source_published_impact": "Source describes authentication boundary review. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authentication boundary review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: n8n before 2.28.0 (and before 2.27.4 on the 2.27.x branch) registers the DELETE /${restEndpoint}/test-webhook/:id endpoint before authentication middleware is applied, allowing any unauthenticated network caller who knows a workflow ID to cancel that... NVD: The impact is limited to disrupting in-progress test sessions; production webhooks, persistent workflow state, and stored data are not affected. OSV: n8n before 2.28.0 Authentication Bypass via test-webhook",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-65014/timeline.json",
      "vendor": "n8n"
    },
    {
      "affected_label": "n8n / n8n",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-65015/",
      "current_public_safe_latest": false,
      "cvss_score": 7.2,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.22138,
      "epss_score": 0.00299,
      "first_observed_at": "2026-07-29T11:36:18.065267+00:00",
      "id": "CVE-2026-65015",
      "impact_tags": [
        "privilege boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-29T11:36:18.065267+00:00",
      "latest_item_url": null,
      "product": "n8n",
      "public_safe_summary": "NVD: n8n versions before 2.30.1 contain a privilege escalation vulnerability in the AI Agents feature where the node-execution tool lacks proper authorization checks. NVD: A Project Viewer user can escalate privileges by chatting with an agent that has node tools enabled, executing arbitrary nodes and accessing credential secrets without proper authorization verification. OSV: n8n before 2.30.1 Privilege Escalation via run_node_tool",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260729T114432Z/items/CVE-2026-65015.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: n8n / n8n; affected version context: 2.30.0",
      "source_published_impact": "Source describes privilege escalation risk. Possible impact: An attacker may cross a privilege boundary and gain more access than intended.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: n8n versions before 2.30.1 contain a privilege escalation vulnerability in the AI Agents feature where the node-execution tool lacks proper authorization checks. NVD: A Project Viewer user can escalate privileges by chatting with an agent that has node tools enabled, executing arbitrary nodes and accessing credential secrets without proper authorization verification. OSV: n8n before 2.30.1 Privilege Escalation via run_node_tool",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-65015/timeline.json",
      "vendor": "n8n"
    },
    {
      "affected_label": "n8n / n8n",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-65016/",
      "current_public_safe_latest": false,
      "cvss_score": 7.7,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.23127,
      "epss_score": 0.00308,
      "first_observed_at": "2026-07-29T11:36:18.065267+00:00",
      "id": "CVE-2026-65016",
      "impact_tags": [
        "privilege boundary review",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-29T11:36:18.065267+00:00",
      "latest_item_url": null,
      "product": "n8n",
      "public_safe_summary": "NVD: n8n versions before 1.123.64, 2.29.8, and 2.30.1 contain a privilege escalation vulnerability in Enterprise SSO instance-role provisioning. NVD: The provisioning path maps an IdP-asserted role claim to an n8n global role but does not prevent assignment of the global:owner role (unlike the token-exchange identity path, which rejects it). NVD: An SSO-authenticated user whose instance-role claim resolves to global:owner is provisioned as instance owner, gaining full administrative control over workflows, credentials, users, and instance configuration.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260729T114432Z/items/CVE-2026-65016.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: n8n / n8n; affected version context: 2.30.0",
      "source_published_impact": "Source describes privilege escalation risk · authenticated boundary. Possible impact: An attacker may cross a privilege boundary and gain more access than intended.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: n8n versions before 1.123.64, 2.29.8, and 2.30.1 contain a privilege escalation vulnerability in Enterprise SSO instance-role provisioning. NVD: The provisioning path maps an IdP-asserted role claim to an n8n global role but does not prevent assignment of the global:owner role (unlike the token-exchange identity path, which rejects it). NVD: An SSO-authenticated user whose instance-role claim resolves to global:owner is provisioned as instance owner, gaining full administrative control over workflows, credentials, users, and instance configuration.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-65016/timeline.json",
      "vendor": "n8n"
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-65321/",
      "current_public_safe_latest": false,
      "cvss_score": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.37349,
      "epss_score": 0.00455,
      "first_observed_at": "2026-08-09T09:59:30.349754+00:00",
      "id": "CVE-2026-65321",
      "impact_tags": [
        "SQL injection risk",
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-09T09:59:30.349754+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: PyAthena prior to 3.35.4 contains a sql injection vulnerability that allows unauthenticated attackers to inject arbitrary SQL by exploiting improper quote-escaping in DefaultParameterFormatter.format(), which routes DELETE and CTAS statements to the... NVD: Because Athena and Trino do not treat backslashes as escape characters inside string literals, attacker-supplied input such as a single quote followed by SQL syntax causes the parser to terminate the string literal prematurely, enabling data exfiltration via... OSV: PyAthena SQL Injection via DefaultParameterFormatter DELETE/CTAS",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260809T101323Z/items/CVE-2026-65321.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes SQL injection risk · remote exposure · authenticated boundary. Possible impact: A remote attacker may be able to read or change database-backed application data.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: PyAthena prior to 3.35.4 contains a sql injection vulnerability that allows unauthenticated attackers to inject arbitrary SQL by exploiting improper quote-escaping in DefaultParameterFormatter.format(), which routes DELETE and CTAS statements to the... NVD: Because Athena and Trino do not treat backslashes as escape characters inside string literals, attacker-supplied input such as a single quote followed by SQL syntax causes the parser to terminate the string literal prematurely, enabling data exfiltration via... OSV: PyAthena SQL Injection via DefaultParameterFormatter DELETE/CTAS",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-65321/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-65437/",
      "current_public_safe_latest": false,
      "cvss_score": 7.1,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.04346,
      "epss_score": 0.00146,
      "first_observed_at": "2026-08-03T22:29:45.220405+00:00",
      "id": "CVE-2026-65437",
      "impact_tags": [
        "XSS risk"
      ],
      "kev": false,
      "last_observed_at": "2026-08-03T22:29:45.220405+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Unauthenticated Cross Site Scripting (XSS) in Spam protection, AntiSpam, FireWall by CleanTalk <= 6.82 versions.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260803T223322Z/items/CVE-2026-65437.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes XSS risk. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Unauthenticated Cross Site Scripting (XSS) in Spam protection, AntiSpam, FireWall by CleanTalk <= 6.82 versions.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-65437/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-65438/",
      "current_public_safe_latest": false,
      "cvss_score": 7.1,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.04352,
      "epss_score": 0.00146,
      "first_observed_at": "2026-08-03T22:29:45.220405+00:00",
      "id": "CVE-2026-65438",
      "impact_tags": [
        "XSS risk"
      ],
      "kev": false,
      "last_observed_at": "2026-08-03T22:29:45.220405+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Unauthenticated Cross Site Scripting (XSS) in Message Filter for Contact Form 7 <= 1.6.3.9 versions.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260803T223322Z/items/CVE-2026-65438.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes XSS risk. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Unauthenticated Cross Site Scripting (XSS) in Message Filter for Contact Form 7 <= 1.6.3.9 versions.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-65438/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-65439/",
      "current_public_safe_latest": false,
      "cvss_score": 7.1,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.04351,
      "epss_score": 0.00146,
      "first_observed_at": "2026-08-03T22:29:45.220405+00:00",
      "id": "CVE-2026-65439",
      "impact_tags": [
        "XSS risk"
      ],
      "kev": false,
      "last_observed_at": "2026-08-03T22:29:45.220405+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Unauthenticated Cross Site Scripting (XSS) in Ultimate Addons for Contact Form 7 <=3.5.45 versions.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260803T223322Z/items/CVE-2026-65439.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes XSS risk. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Unauthenticated Cross Site Scripting (XSS) in Ultimate Addons for Contact Form 7 <=3.5.45 versions.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-65439/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-65440/",
      "current_public_safe_latest": false,
      "cvss_score": 7.1,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.04352,
      "epss_score": 0.00146,
      "first_observed_at": "2026-08-03T22:29:45.220405+00:00",
      "id": "CVE-2026-65440",
      "impact_tags": [
        "XSS risk"
      ],
      "kev": false,
      "last_observed_at": "2026-08-03T22:29:45.220405+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Unauthenticated Cross Site Scripting (XSS) in GetGenie <= 4.4.3 versions.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260803T223322Z/items/CVE-2026-65440.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes XSS risk. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Unauthenticated Cross Site Scripting (XSS) in GetGenie <= 4.4.3 versions.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-65440/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-65441/",
      "current_public_safe_latest": false,
      "cvss_score": 7.1,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.04346,
      "epss_score": 0.00146,
      "first_observed_at": "2026-08-03T22:29:45.220405+00:00",
      "id": "CVE-2026-65441",
      "impact_tags": [
        "XSS risk"
      ],
      "kev": false,
      "last_observed_at": "2026-08-03T22:29:45.220405+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Unauthenticated Cross Site Scripting (XSS) in GiveWP <= 4.16.3 versions.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260803T223322Z/items/CVE-2026-65441.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes XSS risk. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Unauthenticated Cross Site Scripting (XSS) in GiveWP <= 4.16.3 versions.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-65441/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-65442/",
      "current_public_safe_latest": false,
      "cvss_score": 7.2,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.05572,
      "epss_score": 0.00159,
      "first_observed_at": "2026-08-03T22:29:45.220405+00:00",
      "id": "CVE-2026-65442",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-03T22:29:45.220405+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Unauthenticated Server Side Request Forgery (SSRF) in FormCraft <= 3.9.15 versions.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260803T223322Z/items/CVE-2026-65442.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Unauthenticated Server Side Request Forgery (SSRF) in FormCraft <= 3.9.15 versions.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-65442/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-65443/",
      "current_public_safe_latest": false,
      "cvss_score": 7.1,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.04349,
      "epss_score": 0.00146,
      "first_observed_at": "2026-08-03T22:29:45.220405+00:00",
      "id": "CVE-2026-65443",
      "impact_tags": [
        "XSS risk"
      ],
      "kev": false,
      "last_observed_at": "2026-08-03T22:29:45.220405+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Unauthenticated Cross Site Scripting (XSS) in BackWPup <= 5.7.4 versions.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260803T223322Z/items/CVE-2026-65443.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes XSS risk. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Unauthenticated Cross Site Scripting (XSS) in BackWPup <= 5.7.4 versions.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-65443/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-65445/",
      "current_public_safe_latest": false,
      "cvss_score": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.09607,
      "epss_score": 0.00196,
      "first_observed_at": "2026-08-03T22:29:45.220405+00:00",
      "id": "CVE-2026-65445",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-03T22:29:45.220405+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Unauthenticated Broken Access Control in Ad Invalid Click Protector (AICP) <= 1.3.0 versions.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260803T223322Z/items/CVE-2026-65445.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Unauthenticated Broken Access Control in Ad Invalid Click Protector (AICP) <= 1.3.0 versions.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-65445/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-65446/",
      "current_public_safe_latest": false,
      "cvss_score": 7.1,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.0435,
      "epss_score": 0.00146,
      "first_observed_at": "2026-08-03T22:29:45.220405+00:00",
      "id": "CVE-2026-65446",
      "impact_tags": [
        "XSS risk"
      ],
      "kev": false,
      "last_observed_at": "2026-08-03T22:29:45.220405+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Unauthenticated Cross Site Scripting (XSS) in Kali Forms <= 2.4.18 versions.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260803T223322Z/items/CVE-2026-65446.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes XSS risk. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Unauthenticated Cross Site Scripting (XSS) in Kali Forms <= 2.4.18 versions.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-65446/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-65447/",
      "current_public_safe_latest": false,
      "cvss_score": 7.1,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.04349,
      "epss_score": 0.00146,
      "first_observed_at": "2026-08-03T22:29:45.220405+00:00",
      "id": "CVE-2026-65447",
      "impact_tags": [
        "XSS risk"
      ],
      "kev": false,
      "last_observed_at": "2026-08-03T22:29:45.220405+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Unauthenticated Cross Site Scripting (XSS) in Contest Gallery <= 30.0.6 versions.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260803T223322Z/items/CVE-2026-65447.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes XSS risk. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Unauthenticated Cross Site Scripting (XSS) in Contest Gallery <= 30.0.6 versions.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-65447/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-65448/",
      "current_public_safe_latest": false,
      "cvss_score": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.03049,
      "epss_score": 0.0013,
      "first_observed_at": "2026-08-03T22:29:45.220405+00:00",
      "id": "CVE-2026-65448",
      "impact_tags": [
        "XSS risk"
      ],
      "kev": false,
      "last_observed_at": "2026-08-03T22:29:45.220405+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Unauthenticated Cross Site Scripting (XSS) in Anti Spam and list cleaner &#8211; AcyChecker <= 1.8.1 versions.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260803T223322Z/items/CVE-2026-65448.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes XSS risk. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Unauthenticated Cross Site Scripting (XSS) in Anti Spam and list cleaner &#8211; AcyChecker <= 1.8.1 versions.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-65448/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "n8n / n8n",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-65589/",
      "current_public_safe_latest": false,
      "cvss_score": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.29813,
      "epss_score": 0.00371,
      "first_observed_at": "2026-07-29T11:36:18.065267+00:00",
      "id": "CVE-2026-65589",
      "impact_tags": [
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-29T11:36:18.065267+00:00",
      "latest_item_url": null,
      "product": "n8n",
      "public_safe_summary": "NVD: n8n versions before 1.123.64 fail to properly mask custom HTTP header credentials in LLM sub-node execution data, writing plaintext API keys and secrets to workflow execution records. NVD: Authenticated users with access to execution data can read exposed header values and credentials that persist in the database and can be exported. OSV: n8n before 1.123.64 Credential Exposure via LLM Node Execution Data",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260729T114432Z/items/CVE-2026-65589.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: n8n / n8n; affected version context: 2.30.0",
      "source_published_impact": "Source describes authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: n8n versions before 1.123.64 fail to properly mask custom HTTP header credentials in LLM sub-node execution data, writing plaintext API keys and secrets to workflow execution records. NVD: Authenticated users with access to execution data can read exposed header values and credentials that persist in the database and can be exported. OSV: n8n before 1.123.64 Credential Exposure via LLM Node Execution Data",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-65589/timeline.json",
      "vendor": "n8n"
    },
    {
      "affected_label": "n8n / n8n",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-65590/",
      "current_public_safe_latest": false,
      "cvss_score": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.24569,
      "epss_score": 0.00322,
      "first_observed_at": "2026-07-29T11:36:18.065267+00:00",
      "id": "CVE-2026-65590",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-29T11:36:18.065267+00:00",
      "latest_item_url": null,
      "product": "n8n",
      "public_safe_summary": "NVD: n8n before 2.29.8 and 2.30.x before 2.30.1 does not enforce shell sandbox restrictions on Linux and Windows in the @n8n/computer-use package (sandboxing was applied only on macOS). NVD: Shell commands executed by the tool run without any filesystem or network restrictions, allowing unrestricted access to the host filesystem and network from within the computer-use agent process. NVD: This issue only affects deployments where the @n8n/computer-use package is explicitly installed and running; standard n8n installations are not affected.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260729T114432Z/items/CVE-2026-65590.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: n8n / n8n; affected version context: 2.30.0",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: n8n before 2.29.8 and 2.30.x before 2.30.1 does not enforce shell sandbox restrictions on Linux and Windows in the @n8n/computer-use package (sandboxing was applied only on macOS). NVD: Shell commands executed by the tool run without any filesystem or network restrictions, allowing unrestricted access to the host filesystem and network from within the computer-use agent process. NVD: This issue only affects deployments where the @n8n/computer-use package is explicitly installed and running; standard n8n installations are not affected.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-65590/timeline.json",
      "vendor": "n8n"
    },
    {
      "affected_label": "n8n / n8n",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-65591/",
      "current_public_safe_latest": false,
      "cvss_score": 8.9,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.3818,
      "epss_score": 0.00471,
      "first_observed_at": "2026-07-29T11:36:18.065267+00:00",
      "id": "CVE-2026-65591",
      "impact_tags": [
        "code execution review",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-29T11:36:18.065267+00:00",
      "latest_item_url": null,
      "product": "n8n",
      "public_safe_summary": "NVD: n8n contains a sanitizer bypass vulnerability in the legacy expression evaluator's computed-member handler. NVD: An authenticated user with workflow create or modify permissions can craft a malicious expression to bypass the sanitizer and achieve host-level code execution as the n8n process. NVD: The legacy expression engine is the default in affected versions.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260729T114432Z/items/CVE-2026-65591.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: n8n / n8n; affected version context: 2.30.0",
      "source_published_impact": "Source describes code execution review · authenticated boundary. Possible impact: An attacker may be able to run code or commands on affected systems.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: n8n.",
      "source_published_summary": "NVD: n8n contains a sanitizer bypass vulnerability in the legacy expression evaluator's computed-member handler. NVD: An authenticated user with workflow create or modify permissions can craft a malicious expression to bypass the sanitizer and achieve host-level code execution as the n8n process. NVD: The legacy expression engine is the default in affected versions.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-65591/timeline.json",
      "vendor": "n8n"
    },
    {
      "affected_label": "n8n / n8n",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-65592/",
      "current_public_safe_latest": false,
      "cvss_score": 8.4,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.06883,
      "epss_score": 0.00172,
      "first_observed_at": "2026-07-29T11:36:18.065267+00:00",
      "id": "CVE-2026-65592",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-29T11:36:18.065267+00:00",
      "latest_item_url": null,
      "product": "n8n",
      "public_safe_summary": "NVD: n8n before 1.123.64, 2.29.8, and 2.30.1 contains a stored DOM cross-site scripting vulnerability in the Resource Locator component, which passes the workflow-persisted cachedResultUrl parameter to window.open() without scheme validation. OSV: n8n before 1.123.64 Stored DOM XSS via cachedResultUrl OSV: n8n before 1.123.64, 2.29.8, and 2.30.1 contains a stored DOM cross-site scripting vulnerability in the Resource Locator component, which passes the workflow-persisted cachedResultUrl parameter to window.open() without scheme validation.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260729T114432Z/items/CVE-2026-65592.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: n8n / n8n; affected version context: 2.30.0",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: n8n before 1.123.64, 2.29.8, and 2.30.1 contains a stored DOM cross-site scripting vulnerability in the Resource Locator component, which passes the workflow-persisted cachedResultUrl parameter to window.open() without scheme validation. OSV: n8n before 1.123.64 Stored DOM XSS via cachedResultUrl OSV: n8n before 1.123.64, 2.29.8, and 2.30.1 contains a stored DOM cross-site scripting vulnerability in the Resource Locator component, which passes the workflow-persisted cachedResultUrl parameter to window.open() without scheme validation.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-65592/timeline.json",
      "vendor": "n8n"
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-65623/",
      "current_public_safe_latest": false,
      "cvss_score": 8.7,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.3194,
      "epss_score": 0.00392,
      "first_observed_at": "2026-07-31T16:59:34.622526+00:00",
      "id": "CVE-2026-65623",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-31T16:59:34.622526+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Inefficient Algorithmic Complexity vulnerability in mtrudel bandit allows unauthenticated remote denial of service via CPU exhaustion during WebSocket fragment reassembly. NVD: The size guard 'Elixir.Bandit.WebSocket.Connection':oversize_message?/2 called from handle_frame/3 in lib/bandit/websocket/connection.ex appends each non-final continuation frame to a left-nested iolist and then re-measures the entire accumulated buffer with... NVD: Because the buffer grows by one element per frame and is fully re-traversed each time, reassembly work is quadratic (O(n^2)) in the number of continuation frames.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260731T171256Z/items/CVE-2026-65623.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Inefficient Algorithmic Complexity vulnerability in mtrudel bandit allows unauthenticated remote denial of service via CPU exhaustion during WebSocket fragment reassembly. NVD: The size guard 'Elixir.Bandit.WebSocket.Connection':oversize_message?/2 called from handle_frame/3 in lib/bandit/websocket/connection.ex appends each non-final continuation frame to a left-nested iolist and then re-measures the entire accumulated buffer with... NVD: Because the buffer grows by one element per frame and is fully re-traversed each time, reassembly work is quadratic (O(n^2)) in the number of continuation frames.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-65623/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-65650/",
      "current_public_safe_latest": false,
      "cvss_score": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.31697,
      "epss_score": 0.0039,
      "first_observed_at": "2026-07-29T16:40:34.107276+00:00",
      "id": "CVE-2026-65650",
      "impact_tags": [
        "service availability review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-29T16:40:34.107276+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Elgg before 7.0.0 does not check image dimensions to prevent denial of service via a large avatar upload. OSV: Elgg before 7.0.0 does not check image dimensions to prevent denial of service via a large avatar upload.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260729T164826Z/items/CVE-2026-65650.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes service availability risk. Possible impact: The affected service may become unavailable or unreliable.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Elgg before 7.0.0 does not check image dimensions to prevent denial of service via a large avatar upload. OSV: Elgg before 7.0.0 does not check image dimensions to prevent denial of service via a large avatar upload.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-65650/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-65707/",
      "current_public_safe_latest": false,
      "cvss_score": 8.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.18413,
      "epss_score": 0.00266,
      "first_observed_at": "2026-07-31T16:59:34.622526+00:00",
      "id": "CVE-2026-65707",
      "impact_tags": [
        "SQL injection risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-31T16:59:34.622526+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Likeshop through 3.0.5 contains an authenticated SQL injection vulnerability that allows admin-level users to extract arbitrary database contents by submitting unsanitized POST parameters to the adjustAccount endpoint. NVD: The adjustAccount method in UserLogic.php concatenates the money, integral, growth, and earnings parameters directly into Db::raw() SQL fragments without type casting, numeric validation, or parameter binding, enabling boolean-based binary-search extraction... OSV: Likeshop 3.0.5 Authenticated SQL Injection via adjustAccount Endpoint",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260731T171256Z/items/CVE-2026-65707.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes SQL injection risk. Possible impact: An attacker may be able to read or change database-backed application data.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Likeshop through 3.0.5 contains an authenticated SQL injection vulnerability that allows admin-level users to extract arbitrary database contents by submitting unsanitized POST parameters to the adjustAccount endpoint. NVD: The adjustAccount method in UserLogic.php concatenates the money, integral, growth, and earnings parameters directly into Db::raw() SQL fragments without type casting, numeric validation, or parameter binding, enabling boolean-based binary-search extraction... OSV: Likeshop 3.0.5 Authenticated SQL Injection via adjustAccount Endpoint",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-65707/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-65708/",
      "current_public_safe_latest": false,
      "cvss_score": 8.6,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.12817,
      "epss_score": 0.00221,
      "first_observed_at": "2026-07-31T16:59:34.622526+00:00",
      "id": "CVE-2026-65708",
      "impact_tags": [
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-31T16:59:34.622526+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: sysPass through version 3.2.11 contains an insecure direct object reference vulnerability that allows any authenticated attacker to access account file attachments belonging to accounts they do not have ACL permissions for by exploiting missing authorization... NVD: Attackers can supply arbitrary numeric file IDs through the download, view, delete, upload, and list actions to enumerate and manipulate any attachment in the vault, bypassing account-level access controls entirely. OSV: sysPass 3.2.11 Insecure Direct Object Reference via AccountFileController",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260731T171256Z/items/CVE-2026-65708.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes authenticated boundary. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: sysPass through version 3.2.11 contains an insecure direct object reference vulnerability that allows any authenticated attacker to access account file attachments belonging to accounts they do not have ACL permissions for by exploiting missing authorization... NVD: Attackers can supply arbitrary numeric file IDs through the download, view, delete, upload, and list actions to enumerate and manipulate any attachment in the vault, bypassing account-level access controls entirely. OSV: sysPass 3.2.11 Insecure Direct Object Reference via AccountFileController",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-65708/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-65709/",
      "current_public_safe_latest": false,
      "cvss_score": 8.7,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.13082,
      "epss_score": 0.00223,
      "first_observed_at": "2026-07-31T16:59:34.622526+00:00",
      "id": "CVE-2026-65709",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-31T16:59:34.622526+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: sysPass through version 3.2.11 contains a missing object-level authorization vulnerability in the JSON-RPC API that allows API token holders to enumerate account metadata, overwrite passwords, and delete accounts across the entire vault without per-account... NVD: Attackers can invoke AccountController methods such as viewAction, editAction, deleteAction, and editPassAction without AccountFilterUser checks to modify or delete accounts beyond the scope of their assigned token permissions. OSV: sysPass 3.2.11 Missing Object-Level Authorization via JSON-RPC API",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260731T171256Z/items/CVE-2026-65709.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: sysPass through version 3.2.11 contains a missing object-level authorization vulnerability in the JSON-RPC API that allows API token holders to enumerate account metadata, overwrite passwords, and delete accounts across the entire vault without per-account... NVD: Attackers can invoke AccountController methods such as viewAction, editAction, deleteAction, and editPassAction without AccountFilterUser checks to modify or delete accounts beyond the scope of their assigned token permissions. OSV: sysPass 3.2.11 Missing Object-Level Authorization via JSON-RPC API",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-65709/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-65710/",
      "current_public_safe_latest": false,
      "cvss_score": 7.1,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.0756,
      "epss_score": 0.00178,
      "first_observed_at": "2026-07-31T16:59:34.622526+00:00",
      "id": "CVE-2026-65710",
      "impact_tags": [
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-31T16:59:34.622526+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: sysPass through version 3.2.11 contains a missing authorization vulnerability that allows authenticated users with the PUBLICLINK_CREATE profile flag to trigger unauthorized decryption and persistent storage of any vault account's password by exploiting the... NVD: Attackers can invoke the saveCreateFromAccountAction endpoint to cause AccountService::getDataForLink to load arbitrary target accounts without AccountFilterUser restrictions, decrypt credentials using the session master key, and serialize cleartext passwords... OSV: sysPass 3.2.11 Missing Authorization via PublicLinkController Account Decryption",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260731T171256Z/items/CVE-2026-65710.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes authenticated boundary. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: sysPass through version 3.2.11 contains a missing authorization vulnerability that allows authenticated users with the PUBLICLINK_CREATE profile flag to trigger unauthorized decryption and persistent storage of any vault account's password by exploiting the... NVD: Attackers can invoke the saveCreateFromAccountAction endpoint to cause AccountService::getDataForLink to load arbitrary target accounts without AccountFilterUser restrictions, decrypt credentials using the session master key, and serialize cleartext passwords... OSV: sysPass 3.2.11 Missing Authorization via PublicLinkController Account Decryption",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-65710/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-65711/",
      "current_public_safe_latest": false,
      "cvss_score": 8.6,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.82409,
      "epss_score": 0.02406,
      "first_observed_at": "2026-07-31T16:59:34.622526+00:00",
      "id": "CVE-2026-65711",
      "impact_tags": [
        "command injection risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-31T16:59:34.622526+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: sysPass through version 3.2.11 contains an OS command injection vulnerability that allows authenticated administrators to execute arbitrary commands as the web server process user by setting a malicious backup path and triggering a backup. NVD: The FileBackupService builds a tar shell command via string concatenation, inserting the admin-configurable siteBackupPath setting without escapeshellarg() or equivalent sanitization before passing it to exec(), causing injected commands to persist and... OSV: sysPass 3.2.11 Authenticated OS Command Injection via Backup Path",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260731T171256Z/items/CVE-2026-65711.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes command injection risk. Possible impact: An attacker may be able to run unintended system commands through the affected component.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: sysPass through version 3.2.11 contains an OS command injection vulnerability that allows authenticated administrators to execute arbitrary commands as the web server process user by setting a malicious backup path and triggering a backup. NVD: The FileBackupService builds a tar shell command via string concatenation, inserting the admin-configurable siteBackupPath setting without escapeshellarg() or equivalent sanitization before passing it to exec(), causing injected commands to persist and... OSV: sysPass 3.2.11 Authenticated OS Command Injection via Backup Path",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-65711/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-65766/",
      "current_public_safe_latest": false,
      "cvss_score": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.14818,
      "epss_score": 0.00237,
      "first_observed_at": "2026-08-03T12:38:03.310457+00:00",
      "id": "CVE-2026-65766",
      "impact_tags": [
        "SQL injection risk"
      ],
      "kev": false,
      "last_observed_at": "2026-08-03T12:38:03.310457+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Joomla Extension - joomshaper.com - Unauthenticated SQL injection in SP Page Builder < 6.7.1 - Improper validation of order parameters in the Dynamic Content endpoint leads to an SQL injection vector.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260803T124716Z/items/CVE-2026-65766.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes SQL injection risk. Possible impact: An attacker may be able to read or change database-backed application data.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Joomla Extension - joomshaper.com - Unauthenticated SQL injection in SP Page Builder < 6.7.1 - Improper validation of order parameters in the Dynamic Content endpoint leads to an SQL injection vector.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-65766/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-65876/",
      "current_public_safe_latest": false,
      "cvss_score": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.13661,
      "epss_score": 0.00228,
      "first_observed_at": "2026-08-03T12:38:03.310457+00:00",
      "id": "CVE-2026-65876",
      "impact_tags": [
        "SQL injection risk"
      ],
      "kev": false,
      "last_observed_at": "2026-08-03T12:38:03.310457+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Joomla Extension - joomshaper.com - Unauthenticated SQL injection in SP Page Builder < 6.7.1 - Improper validation of catid parameters in the loadMoreArticles endpoint leads to an SQL injection vector.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260803T124716Z/items/CVE-2026-65876.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes SQL injection risk. Possible impact: An attacker may be able to read or change database-backed application data.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Joomla Extension - joomshaper.com - Unauthenticated SQL injection in SP Page Builder < 6.7.1 - Improper validation of catid parameters in the loadMoreArticles endpoint leads to an SQL injection vector.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-65876/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-65877/",
      "current_public_safe_latest": false,
      "cvss_score": 8.2,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.1349,
      "epss_score": 0.00226,
      "first_observed_at": "2026-08-03T12:38:03.310457+00:00",
      "id": "CVE-2026-65877",
      "impact_tags": [
        "SQL injection risk"
      ],
      "kev": false,
      "last_observed_at": "2026-08-03T12:38:03.310457+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Joomla Extension - joomshaper.com - Authenticated SQL injection in SP Page Builder < 6.7.1 - Improper validation of various parameters in the media manager search and date filters lead to an SQL injection vector.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260803T124716Z/items/CVE-2026-65877.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes SQL injection risk. Possible impact: An attacker may be able to read or change database-backed application data.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Joomla Extension - joomshaper.com - Authenticated SQL injection in SP Page Builder < 6.7.1 - Improper validation of various parameters in the media manager search and date filters lead to an SQL injection vector.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-65877/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-65878/",
      "current_public_safe_latest": false,
      "cvss_score": 8.3,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.25006,
      "epss_score": 0.00325,
      "first_observed_at": "2026-08-03T12:38:03.310457+00:00",
      "id": "CVE-2026-65878",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-03T12:38:03.310457+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Joomla Extension - joomshaper.com - Authenticated arbitrary file delete in SP Page Builder < 6.7.1- Improper path validation and ACL checks lead to a file deletion vector in the media manager.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260803T124716Z/items/CVE-2026-65878.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Joomla Extension - joomshaper.com - Authenticated arbitrary file delete in SP Page Builder < 6.7.1- Improper path validation and ACL checks lead to a file deletion vector in the media manager.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-65878/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-65879/",
      "current_public_safe_latest": false,
      "cvss_score": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.20727,
      "epss_score": 0.00284,
      "first_observed_at": "2026-08-03T12:38:03.310457+00:00",
      "id": "CVE-2026-65879",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-03T12:38:03.310457+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Joomla Extension - joomshaper.com - Unauthenticated mail relay via a hardcoded, product-wide secret in SP Page Builder < 6.7.1 - A hardcoded secret allowed attackers to forge the mail from address of forms.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260803T124716Z/items/CVE-2026-65879.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Joomla Extension - joomshaper.com - Unauthenticated mail relay via a hardcoded, product-wide secret in SP Page Builder < 6.7.1 - A hardcoded secret allowed attackers to forge the mail from address of forms.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-65879/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-65884/",
      "current_public_safe_latest": false,
      "cvss_score": 10.0,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.16281,
      "epss_score": 0.00249,
      "first_observed_at": "2026-08-05T11:32:09.387600+00:00",
      "id": "CVE-2026-65884",
      "impact_tags": [
        "privilege boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-05T11:32:09.387600+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Joomla Extension - balbooa.com - Privilege Escalation in Gridbox < 2.20.2 - The registration method allows users provided usergroup IDs, allowing unauthenticated actors to register new accounts with administrative permissions.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260805T113552Z/items/CVE-2026-65884.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes privilege escalation risk. Possible impact: An attacker may cross a privilege boundary and gain more access than intended.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Joomla Extension - balbooa.com - Privilege Escalation in Gridbox < 2.20.2 - The registration method allows users provided usergroup IDs, allowing unauthenticated actors to register new accounts with administrative permissions.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-65884/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-65885/",
      "current_public_safe_latest": false,
      "cvss_score": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.1657,
      "epss_score": 0.00251,
      "first_observed_at": "2026-08-05T11:32:09.387600+00:00",
      "id": "CVE-2026-65885",
      "impact_tags": [
        "code execution review",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-05T11:32:09.387600+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Joomla Extension - balbooa.com - Authenticated arbitrary file upload in Gridbox < 2.20.2 - File upload methods allows authenticated attackers to upload arbitrary files. NVD: Turns into an authenticated RCE if combined with CVE-2026-65884 as the required account can be created by the attacker.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260805T113552Z/items/CVE-2026-65885.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes code execution review · authenticated boundary. Possible impact: An attacker may be able to run code or commands on affected systems.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Joomla Extension - balbooa.com - Authenticated arbitrary file upload in Gridbox < 2.20.2 - File upload methods allows authenticated attackers to upload arbitrary files. NVD: Turns into an authenticated RCE if combined with CVE-2026-65884 as the required account can be created by the attacker.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-65885/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-65889/",
      "current_public_safe_latest": false,
      "cvss_score": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.24779,
      "epss_score": 0.00323,
      "first_observed_at": "2026-08-05T11:32:09.387600+00:00",
      "id": "CVE-2026-65889",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-05T11:32:09.387600+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Joomla Extension - balbooa.com - Unauthenticated recursive directory deletion < 2.20.2 - The generateNewApp method allows actors to recursively delete directories.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260805T113552Z/items/CVE-2026-65889.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Joomla Extension - balbooa.com - Unauthenticated recursive directory deletion < 2.20.2 - The generateNewApp method allows actors to recursively delete directories.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-65889/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-65890/",
      "current_public_safe_latest": false,
      "cvss_score": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.1476,
      "epss_score": 0.00237,
      "first_observed_at": "2026-08-05T11:32:09.387600+00:00",
      "id": "CVE-2026-65890",
      "impact_tags": [
        "SQL injection risk"
      ],
      "kev": false,
      "last_observed_at": "2026-08-05T11:32:09.387600+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Joomla Extension - balbooa.com - Unauthenticated SQL injection in Gridbox < 2.20.2 - Multiple SQLi vectors allow unauthenticated actors to inject SQL in queries.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260805T113552Z/items/CVE-2026-65890.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes SQL injection risk. Possible impact: An attacker may be able to read or change database-backed application data.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Joomla Extension - balbooa.com - Unauthenticated SQL injection in Gridbox < 2.20.2 - Multiple SQLi vectors allow unauthenticated actors to inject SQL in queries.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-65890/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-65891/",
      "current_public_safe_latest": false,
      "cvss_score": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.09481,
      "epss_score": 0.00195,
      "first_observed_at": "2026-08-05T11:32:09.387600+00:00",
      "id": "CVE-2026-65891",
      "impact_tags": [
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-05T11:32:09.387600+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Joomla Extension - joomlacontenteditor.net - Creation of hidden files and unintended file overwrite via rename function in Joomla Content Editor (JCE) < 2.20.2 - Improper input validation in the file rename functionality allowed an authenticated user with... NVD: The issue also allowed existing files at the destination path to be unintentionally replaced.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260805T113552Z/items/CVE-2026-65891.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Joomla Extension - joomlacontenteditor.net - Creation of hidden files and unintended file overwrite via rename function in Joomla Content Editor (JCE) < 2.20.2 - Improper input validation in the file rename functionality allowed an authenticated user with... NVD: The issue also allowed existing files at the destination path to be unintentionally replaced.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-65891/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-65943/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.14165,
      "epss_score": 0.00232,
      "first_observed_at": "2026-08-05T11:32:09.387600+00:00",
      "id": "CVE-2026-65943",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-05T11:32:09.387600+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Joomla Extension - rolandd.com - Unauthenticated directory creation RO CSVI < 9.11.0",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260805T113552Z/items/CVE-2026-65943.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Joomla Extension - rolandd.com - Unauthenticated directory creation RO CSVI < 9.11.0",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-65943/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-65944/",
      "current_public_safe_latest": false,
      "cvss_score": 8.8,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.03057,
      "epss_score": 0.0013,
      "first_observed_at": "2026-08-05T11:32:09.387600+00:00",
      "id": "CVE-2026-65944",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-05T11:32:09.387600+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Joomla Extension - rolandd.com - CSRF vectors in AJAX endpoint handlers RO CSVI < 9.11.0",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260805T113552Z/items/CVE-2026-65944.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Joomla Extension - rolandd.com - CSRF vectors in AJAX endpoint handlers RO CSVI < 9.11.0",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-65944/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-65946/",
      "current_public_safe_latest": false,
      "cvss_score": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.04577,
      "epss_score": 0.00149,
      "first_observed_at": "2026-08-05T11:32:09.387600+00:00",
      "id": "CVE-2026-65946",
      "impact_tags": [
        "XSS risk"
      ],
      "kev": false,
      "last_observed_at": "2026-08-05T11:32:09.387600+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Joomla Extension - rolandd.com - XSS vectors in AJAX endpoint handlers RO CSVI < 9.11.0",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260805T113552Z/items/CVE-2026-65946.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes XSS risk. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Joomla Extension - rolandd.com - XSS vectors in AJAX endpoint handlers RO CSVI < 9.11.0",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-65946/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-66008/",
      "current_public_safe_latest": false,
      "cvss_score": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.24405,
      "epss_score": 0.0032,
      "first_observed_at": "2026-07-31T11:36:05.167842+00:00",
      "id": "CVE-2026-66008",
      "impact_tags": [
        "information exposure review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-31T11:36:05.167842+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Parse Server versions >= 9.0.0 before 9.10.0-alpha.6 and >= 8.2.2 before 8.6.87 disclose Pointer and Relation target class names through GraphQL validation and input-coercion error messages when public schema introspection is disabled... NVD: Because these errors are produced before authentication, authorization, or any resolver runs, an unauthenticated client possessing only the public application ID can trigger errors on Pointer or Relation fields to reconstruct hidden schema class names... NVD: Only schema metadata (class names) is exposed; no object data, credentials, or user records are disclosed.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260731T115001Z/items/CVE-2026-66008.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes information exposure review. Possible impact: An attacker may be able to access information that should not be exposed.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Parse Server versions >= 9.0.0 before 9.10.0-alpha.6 and >= 8.2.2 before 8.6.87 disclose Pointer and Relation target class names through GraphQL validation and input-coercion error messages when public schema introspection is disabled... NVD: Because these errors are produced before authentication, authorization, or any resolver runs, an unauthenticated client possessing only the public application ID can trigger errors on Pointer or Relation fields to reconstruct hidden schema class names... NVD: Only schema metadata (class names) is exposed; no object data, credentials, or user records are disclosed.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-66008/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-66009/",
      "current_public_safe_latest": false,
      "cvss_score": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.17993,
      "epss_score": 0.00263,
      "first_observed_at": "2026-07-31T11:36:05.167842+00:00",
      "id": "CVE-2026-66009",
      "impact_tags": [
        "information exposure review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-31T11:36:05.167842+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Parse Server versions >= 9.0.0 before 9.10.0-alpha.5 and >= 8.2.2 before 8.6.86 return GraphQL validation error messages that name required custom input fields even when public introspection is disabled (graphQLPublicIntrospection: false, the default). NVD: A client holding only the public application id — with no user session, master key, or maintenance key — can trigger validation errors to learn the names of required (non-null) custom fields on classes it already references by name, partially defeating the... NVD: No stored data, credentials, optional field names, unreferenced class names, or Cloud Code function names are exposed.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260731T115001Z/items/CVE-2026-66009.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes information exposure review. Possible impact: An attacker may be able to access information that should not be exposed.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Parse Server versions >= 9.0.0 before 9.10.0-alpha.5 and >= 8.2.2 before 8.6.86 return GraphQL validation error messages that name required custom input fields even when public introspection is disabled (graphQLPublicIntrospection: false, the default). NVD: A client holding only the public application id — with no user session, master key, or maintenance key — can trigger validation errors to learn the names of required (non-null) custom fields on classes it already references by name, partially defeating the... NVD: No stored data, credentials, optional field names, unreferenced class names, or Cloud Code function names are exposed.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-66009/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-66010/",
      "current_public_safe_latest": false,
      "cvss_score": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.06432,
      "epss_score": 0.00168,
      "first_observed_at": "2026-07-31T11:36:05.167842+00:00",
      "id": "CVE-2026-66010",
      "impact_tags": [
        "XSS risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-31T11:36:05.167842+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: DOMPurify before 3.4.12 fails to execute afterSanitizeElements hook for custom elements allowed via CUSTOM_ELEMENT_HANDLING.tagNameCheck, allowing attributes to bypass application security policies. NVD: Attackers can preserve sensitive attributes on custom elements that later re-inject them into innerHTML sinks, creating second-order XSS gadgets. OSV: DOMPurify before 3.4.12 Hook Bypass via CUSTOM_ELEMENT_HANDLING",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260731T115001Z/items/CVE-2026-66010.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes XSS risk. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: DOMPurify before 3.4.12 fails to execute afterSanitizeElements hook for custom elements allowed via CUSTOM_ELEMENT_HANDLING.tagNameCheck, allowing attributes to bypass application security policies. NVD: Attackers can preserve sensitive attributes on custom elements that later re-inject them into innerHTML sinks, creating second-order XSS gadgets. OSV: DOMPurify before 3.4.12 Hook Bypass via CUSTOM_ELEMENT_HANDLING",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-66010/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-66011/",
      "current_public_safe_latest": false,
      "cvss_score": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.01167,
      "epss_score": 0.00103,
      "first_observed_at": "2026-08-01T10:51:40.555213+00:00",
      "id": "CVE-2026-66011",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-01T10:51:40.555213+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: ImageMagick before 7.1.2-27 contains a memory leak vulnerability in the magick command-line interface when invalid options are provided. NVD: Attackers can trigger memory exhaustion by repeatedly supplying malformed command-line arguments to consume system resources. OSV: ImageMagick before 7.1.2-27 Memory Leak via Invalid CLI Options",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260801T105618Z/items/CVE-2026-66011.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: ImageMagick before 7.1.2-27 contains a memory leak vulnerability in the magick command-line interface when invalid options are provided. NVD: Attackers can trigger memory exhaustion by repeatedly supplying malformed command-line arguments to consume system resources. OSV: ImageMagick before 7.1.2-27 Memory Leak via Invalid CLI Options",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-66011/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-66012/",
      "current_public_safe_latest": false,
      "cvss_score": 10.0,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.35983,
      "epss_score": 0.00437,
      "first_observed_at": "2026-08-01T10:51:40.555213+00:00",
      "id": "CVE-2026-66012",
      "impact_tags": [
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-01T10:51:40.555213+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: SiYuan before v3.7.2 contains a missing authorization vulnerability in the POST /mcp kernel endpoint, which is gated only by a general auth check (model.CheckAuth) with no admin-role or read-only enforcement. NVD: This exposes 31 MCP tools, including a file tool with list/read/write/delete/rename/copy actions across the entire workspace. NVD: When the Publish server is enabled in anonymous mode (Conf.Publish.Enable=true and Conf.Publish.Auth.Enable=false), the Publish reverse proxy attaches an anonymous RoleReader JWT to proxied requests, allowing a remote unauthenticated attacker to reach /mcp.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260801T105618Z/items/CVE-2026-66012.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes remote exposure · authenticated boundary. Possible impact: This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: SiYuan before v3.7.2 contains a missing authorization vulnerability in the POST /mcp kernel endpoint, which is gated only by a general auth check (model.CheckAuth) with no admin-role or read-only enforcement. NVD: This exposes 31 MCP tools, including a file tool with list/read/write/delete/rename/copy actions across the entire workspace. NVD: When the Publish server is enabled in anonymous mode (Conf.Publish.Enable=true and Conf.Publish.Auth.Enable=false), the Publish reverse proxy attaches an anonymous RoleReader JWT to proxied requests, allowing a remote unauthenticated attacker to reach /mcp.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-66012/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-66013/",
      "current_public_safe_latest": false,
      "cvss_score": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.3161,
      "epss_score": 0.00388,
      "first_observed_at": "2026-08-01T10:51:40.555213+00:00",
      "id": "CVE-2026-66013",
      "impact_tags": [
        "authentication boundary review",
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-01T10:51:40.555213+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: OpenRemote before 1.26.2 contains an authentication bypass vulnerability in the console registration API that allows unauthenticated attackers to update existing console assets by supplying a known asset identifier. NVD: Attackers can overwrite push notification tokens and console metadata without authentication or ownership validation, redirecting notifications or denying delivery to legitimate consoles. OSV: OpenRemote before 1.26.2 Authentication Bypass via Console Registration",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260801T105618Z/items/CVE-2026-66013.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes authentication boundary review · remote exposure · authenticated boundary. Possible impact: This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authentication boundary review · remote exposure · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: OpenRemote before 1.26.2 contains an authentication bypass vulnerability in the console registration API that allows unauthenticated attackers to update existing console assets by supplying a known asset identifier. NVD: Attackers can overwrite push notification tokens and console metadata without authentication or ownership validation, redirecting notifications or denying delivery to legitimate consoles. OSV: OpenRemote before 1.26.2 Authentication Bypass via Console Registration",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-66013/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-66028/",
      "current_public_safe_latest": false,
      "cvss_score": 7.1,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.24607,
      "epss_score": 0.00321,
      "first_observed_at": "2026-08-03T17:21:47.396014+00:00",
      "id": "CVE-2026-66028",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-03T17:21:47.396014+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Ekushey Project Manager CRM through version 5.0 contains a missing uniqueness constraint vulnerability that allows authenticated administrators to create duplicate client accounts with identical email and password credentials. NVD: Attackers can exploit the lack of email field uniqueness enforcement to create conflicting account states where multiple accounts share the same email address with different passwords, resulting in unpredictable authentication behavior and unauthorized...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260803T174717Z/items/CVE-2026-66028.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Ekushey Project Manager CRM through version 5.0 contains a missing uniqueness constraint vulnerability that allows authenticated administrators to create duplicate client accounts with identical email and password credentials. NVD: Attackers can exploit the lack of email field uniqueness enforcement to create conflicting account states where multiple accounts share the same email address with different passwords, resulting in unpredictable authentication behavior and unauthorized...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-66028/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-66032/",
      "current_public_safe_latest": false,
      "cvss_score": 8.7,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.21091,
      "epss_score": 0.00288,
      "first_observed_at": "2026-07-31T16:59:34.622526+00:00",
      "id": "CVE-2026-66032",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-31T16:59:34.622526+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: libssh2 through 1.11.1, fixed in commit 5e47761, contains a double-free vulnerability in the sftp_open() function in src/sftp.c that allows a malicious SSH server to corrupt the heap of any authenticated client opening an SFTP session. NVD: When a server responds to SSH_FXP_OPEN with SSH_FXP_STATUS containing FX_OK, the response data buffer is freed, and if a subsequent sftp_packet_require() call returns a specific error such as LIBSSH2_ERROR_CHANNEL_PACKET_EXCEEDED, the same pointer is freed a... OSV: libssh2 Double-Free Heap Corruption via sftp_open()",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260731T171256Z/items/CVE-2026-66032.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: commit.",
      "source_published_summary": "NVD: libssh2 through 1.11.1, fixed in commit 5e47761, contains a double-free vulnerability in the sftp_open() function in src/sftp.c that allows a malicious SSH server to corrupt the heap of any authenticated client opening an SFTP session. NVD: When a server responds to SSH_FXP_OPEN with SSH_FXP_STATUS containing FX_OK, the response data buffer is freed, and if a subsequent sftp_packet_require() call returns a specific error such as LIBSSH2_ERROR_CHANNEL_PACKET_EXCEEDED, the same pointer is freed a... OSV: libssh2 Double-Free Heap Corruption via sftp_open()",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-66032/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "libssh2 / libssh2",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-66033/",
      "current_public_safe_latest": false,
      "cvss_score": 8.7,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.29728,
      "epss_score": 0.0037,
      "first_observed_at": "2026-07-31T16:59:34.622526+00:00",
      "id": "CVE-2026-66033",
      "impact_tags": [
        "service availability review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-31T16:59:34.622526+00:00",
      "latest_item_url": null,
      "product": "libssh2",
      "public_safe_summary": "NVD: libssh2 through 1.11.1, fixed in commit a2ed82d, contains a pre-authentication integer underflow vulnerability in the ssh2_cipher_crypt() function in src/openssl.c that allows a malicious SSH server to crash any connecting client by negotiating AES-GCM... NVD: Attackers can exploit the underflow in the expression computing blocksize minus aadlen minus authentication tag length to trigger an out-of-bounds read and a memcpy call with a near-SIZE_MAX length argument, causing immediate process crash before any... OSV: libssh2 Integer Underflow DoS via AES-GCM Cipher Negotiation",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260731T171256Z/items/CVE-2026-66033.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: libssh2 / libssh2",
      "source_published_impact": "Source describes service availability risk. Possible impact: The affected service may become unavailable or unreliable.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: commit.",
      "source_published_summary": "NVD: libssh2 through 1.11.1, fixed in commit a2ed82d, contains a pre-authentication integer underflow vulnerability in the ssh2_cipher_crypt() function in src/openssl.c that allows a malicious SSH server to crash any connecting client by negotiating AES-GCM... NVD: Attackers can exploit the underflow in the expression computing blocksize minus aadlen minus authentication tag length to trigger an out-of-bounds read and a memcpy call with a near-SIZE_MAX length argument, causing immediate process crash before any... OSV: libssh2 Integer Underflow DoS via AES-GCM Cipher Negotiation",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-66033/timeline.json",
      "vendor": "libssh2"
    },
    {
      "affected_label": "libssh2 / libssh2",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-66034/",
      "current_public_safe_latest": false,
      "cvss_score": 7.7,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.16757,
      "epss_score": 0.00252,
      "first_observed_at": "2026-07-31T16:59:34.622526+00:00",
      "id": "CVE-2026-66034",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-31T16:59:34.622526+00:00",
      "latest_item_url": null,
      "product": "libssh2",
      "public_safe_summary": "NVD: libssh2 through 1.11.1, fixed in commit a13bb6c, contains a missing bounds check vulnerability that allows a malicious SSH server to trigger an arbitrary-length heap out-of-bounds read and a free of an uninitialized pointer via the publickey subsystem. NVD: In libssh2_publickey_list_fetch(), the version 1 response parser reads a server-controlled comment_len value and advances the parse pointer without verifying sufficient bytes remain in the buffer, causing the out-of-bounds read to leak heap pointers from... OSV: libssh2 Heap Out-of-Bounds Read via publickey subsystem",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260731T171256Z/items/CVE-2026-66034.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: libssh2 / libssh2",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: commit.",
      "source_published_summary": "NVD: libssh2 through 1.11.1, fixed in commit a13bb6c, contains a missing bounds check vulnerability that allows a malicious SSH server to trigger an arbitrary-length heap out-of-bounds read and a free of an uninitialized pointer via the publickey subsystem. NVD: In libssh2_publickey_list_fetch(), the version 1 response parser reads a server-controlled comment_len value and advances the parse pointer without verifying sufficient bytes remain in the buffer, causing the out-of-bounds read to leak heap pointers from... OSV: libssh2 Heap Out-of-Bounds Read via publickey subsystem",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-66034/timeline.json",
      "vendor": "libssh2"
    },
    {
      "affected_label": "libssh2 / libssh2",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-66035/",
      "current_public_safe_latest": false,
      "cvss_score": 7.7,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.24218,
      "epss_score": 0.00318,
      "first_observed_at": "2026-07-31T16:59:34.622526+00:00",
      "id": "CVE-2026-66035",
      "impact_tags": [
        "memory safety review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-31T16:59:34.622526+00:00",
      "latest_item_url": null,
      "product": "libssh2",
      "public_safe_summary": "NVD: libssh2 through 1.11.1, fixed in commit 42e33d8, contains a pre-authentication heap buffer overflow vulnerability that allows a malicious SSH server to corrupt heap metadata in any connecting client by sending a packet with a packet_length smaller than the... NVD: In the fullpacket() function in src/transport.c, the ETM path allocates a buffer of packet_length bytes but copies blocksize minus one bytes via memcpy, causing an overflow that on 32-bit glibc writes attacker-controlled bytes into an adjacent chunk's SIZE... OSV: libssh2 Heap Buffer Overflow via ETM Cipher Negotiation",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260731T171256Z/items/CVE-2026-66035.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: libssh2 / libssh2",
      "source_published_impact": "Source describes memory safety review. Possible impact: The affected component has memory-safety risk that may lead to crash, privilege, or code-execution impact depending on exposure.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: commit.",
      "source_published_summary": "NVD: libssh2 through 1.11.1, fixed in commit 42e33d8, contains a pre-authentication heap buffer overflow vulnerability that allows a malicious SSH server to corrupt heap metadata in any connecting client by sending a packet with a packet_length smaller than the... NVD: In the fullpacket() function in src/transport.c, the ETM path allocates a buffer of packet_length bytes but copies blocksize minus one bytes via memcpy, causing an overflow that on 32-bit glibc writes attacker-controlled bytes into an adjacent chunk's SIZE... OSV: libssh2 Heap Buffer Overflow via ETM Cipher Negotiation",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-66035/timeline.json",
      "vendor": "libssh2"
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-66063/",
      "current_public_safe_latest": false,
      "cvss_score": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.14227,
      "epss_score": 0.00233,
      "first_observed_at": "2026-08-04T22:31:51.932237+00:00",
      "id": "CVE-2026-66063",
      "impact_tags": [
        "path traversal review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-04T22:31:51.932237+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: goshs is a feature-rich single-binary file server for red teamers and developers. NVD: Prior to 2.1.5, the httpserver/updown.go multipart upload handler split part.FileName() on / but did not reject .., allowing an unauthenticated upload with filename .. NVD: to create a file outside the served tree.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260804T223546Z/items/CVE-2026-66063.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes path traversal review. Possible impact: An attacker may be able to reach files outside the intended application path.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: goshs is a feature-rich single-binary file server for red teamers and developers. NVD: Prior to 2.1.5, the httpserver/updown.go multipart upload handler split part.FileName() on / but did not reject .., allowing an unauthenticated upload with filename .. NVD: to create a file outside the served tree.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-66063/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-66064/",
      "current_public_safe_latest": false,
      "cvss_score": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.2318,
      "epss_score": 0.00308,
      "first_observed_at": "2026-08-04T22:31:51.932237+00:00",
      "id": "CVE-2026-66064",
      "impact_tags": [
        "path traversal review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-04T22:31:51.932237+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: goshs is a feature-rich single-binary file server for red teamers and developers. NVD: Prior to 2.1.5, the httpserver/handler.go sendFile handler opened files using a cleaned path but derived the authorization filename from raw req.URL.Path, so a trailing slash could bypass .goshs ACL-file protection and block-list checks. NVD: This issue is fixed in version 2.1.5.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260804T223546Z/items/CVE-2026-66064.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes path traversal review. Possible impact: An attacker may be able to reach files outside the intended application path.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: goshs is a feature-rich single-binary file server for red teamers and developers. NVD: Prior to 2.1.5, the httpserver/handler.go sendFile handler opened files using a cleaned path but derived the authorization filename from raw req.URL.Path, so a trailing slash could bypass .goshs ACL-file protection and block-list checks. NVD: This issue is fixed in version 2.1.5.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-66064/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "apache / neethi",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-66142/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.3872,
      "epss_score": 0.00478,
      "first_observed_at": "2026-07-31T11:36:05.167842+00:00",
      "id": "CVE-2026-66142",
      "impact_tags": [
        "service availability review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-31T11:36:05.167842+00:00",
      "latest_item_url": null,
      "product": "neethi",
      "public_safe_summary": "NVD: Apache Neethi is vulnerable to uncontrolled recursion when parsing policies that lack policy Ids or with deeply nested structures, which may lead to a denial of service attack when parsing policies due to runtime memory exhaustion. NVD: Users are recommended to upgrade to version 3.2.3, which fixes this issue. OSV: Apache Neethi: Uncontrolled recursion in policy processing",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260731T115001Z/items/CVE-2026-66142.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: apache / neethi",
      "source_published_impact": "Source describes service availability risk. Possible impact: The affected service may become unavailable or unreliable.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: Apache Neethi is vulnerable to uncontrolled recursion when parsing policies that lack policy Ids or with deeply nested structures, which may lead to a denial of service attack when parsing policies due to runtime memory exhaustion. NVD: Users are recommended to upgrade to version 3.2.3, which fixes this issue. OSV: Apache Neethi: Uncontrolled recursion in policy processing",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-66142/timeline.json",
      "vendor": "apache"
    },
    {
      "affected_label": "apache / neethi",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-66143/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.40815,
      "epss_score": 0.00513,
      "first_observed_at": "2026-07-31T11:36:05.167842+00:00",
      "id": "CVE-2026-66143",
      "impact_tags": [
        "service availability review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-31T11:36:05.167842+00:00",
      "latest_item_url": null,
      "product": "neethi",
      "public_safe_summary": "NVD: It is possible to bypass the maximum number of normalized policy alternatives that was introduced in Apache Neethi 3.2.2 via certain crafted policies, which may lead to a denial of service attack via resource consumption. NVD: Users are recommended to upgrade to version 3.2.3, which fixes this issue. OSV: Apache Neethi: Missing global alternative-output budget across policy computation paths",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260731T115001Z/items/CVE-2026-66143.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: apache / neethi; affected version context: 3.2.2",
      "source_published_impact": "Source describes service availability risk. Possible impact: The affected service may become unavailable or unreliable.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: It is possible to bypass the maximum number of normalized policy alternatives that was introduced in Apache Neethi 3.2.2 via certain crafted policies, which may lead to a denial of service attack via resource consumption. NVD: Users are recommended to upgrade to version 3.2.3, which fixes this issue. OSV: Apache Neethi: Missing global alternative-output budget across policy computation paths",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-66143/timeline.json",
      "vendor": "apache"
    },
    {
      "affected_label": "apache / neethi",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-66144/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.3872,
      "epss_score": 0.00478,
      "first_observed_at": "2026-07-31T11:36:05.167842+00:00",
      "id": "CVE-2026-66144",
      "impact_tags": [
        "service availability review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-31T11:36:05.167842+00:00",
      "latest_item_url": null,
      "product": "neethi",
      "public_safe_summary": "NVD: Although remote policy references are not retrieved during policy normalization, if they are manually retrieved via the API it can cause a denial of service attack if a huge policy is retrieved. NVD: Users are recommended to upgrade to version 3.2.3, which fixes this issue by imposing a default maximum size on data read from remote policy references. OSV: Apache Neethi: Remote PolicyReference fetch lacks resource bounds",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260731T115001Z/items/CVE-2026-66144.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: apache / neethi",
      "source_published_impact": "Source describes service availability risk. Possible impact: The affected service may become unavailable or unreliable.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: Although remote policy references are not retrieved during policy normalization, if they are manually retrieved via the API it can cause a denial of service attack if a huge policy is retrieved. NVD: Users are recommended to upgrade to version 3.2.3, which fixes this issue by imposing a default maximum size on data read from remote policy references. OSV: Apache Neethi: Remote PolicyReference fetch lacks resource bounds",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-66144/timeline.json",
      "vendor": "apache"
    },
    {
      "affected_label": "apache / qpid_proton-j",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-66257/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.35249,
      "epss_score": 0.00426,
      "first_observed_at": "2026-08-12T05:08:50.991993+00:00",
      "id": "CVE-2026-66257",
      "impact_tags": [
        "service availability review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-12T05:08:50.991993+00:00",
      "latest_item_url": null,
      "product": "qpid_proton-j",
      "public_safe_summary": "NVD: A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service. NVD: This issue affects Apache Qpid Proton-J: through 0.34.1. NVD: Users are recommended to upgrade to version 0.35.0, which fixes the issue.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260812T051428Z/items/CVE-2026-66257.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: apache / qpid_proton-j",
      "source_published_impact": "Source describes service availability risk. Possible impact: The affected service may become unavailable or unreliable.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service. NVD: This issue affects Apache Qpid Proton-J: through 0.34.1. NVD: Users are recommended to upgrade to version 0.35.0, which fixes the issue.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-66257/timeline.json",
      "vendor": "apache"
    },
    {
      "affected_label": "apache / qpid_proton-j",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-66273/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.35249,
      "epss_score": 0.00426,
      "first_observed_at": "2026-08-12T05:08:50.991993+00:00",
      "id": "CVE-2026-66273",
      "impact_tags": [
        "service availability review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-12T05:08:50.991993+00:00",
      "latest_item_url": null,
      "product": "qpid_proton-j",
      "public_safe_summary": "NVD: A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service. NVD: This issue affects Apache Qpid Proton-J: through 0.34.1. NVD: Users are recommended to upgrade to version 0.35.0, which fixes the issue.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260812T051428Z/items/CVE-2026-66273.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: apache / qpid_proton-j",
      "source_published_impact": "Source describes service availability risk. Possible impact: The affected service may become unavailable or unreliable.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service. NVD: This issue affects Apache Qpid Proton-J: through 0.34.1. NVD: Users are recommended to upgrade to version 0.35.0, which fixes the issue.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-66273/timeline.json",
      "vendor": "apache"
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-66337/",
      "current_public_safe_latest": false,
      "cvss_score": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.13813,
      "epss_score": 0.00229,
      "first_observed_at": "2026-07-31T22:17:39.455090+00:00",
      "id": "CVE-2026-66337",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-31T22:17:39.455090+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A flaw was found in libsoup. NVD: An unsigned integer underflow in the soup_filter_input_stream_read_until() function causes a heap buffer over-read when parsing multipart HTTP responses. NVD: A malicious HTTP server can exploit this by sending a crafted multipart response, potentially causing the client application to crash or disclose sensitive heap memory.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260731T222222Z/items/CVE-2026-66337.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A flaw was found in libsoup. NVD: An unsigned integer underflow in the soup_filter_input_stream_read_until() function causes a heap buffer over-read when parsing multipart HTTP responses. NVD: A malicious HTTP server can exploit this by sending a crafted multipart response, potentially causing the client application to crash or disclose sensitive heap memory.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-66337/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-66338/",
      "current_public_safe_latest": false,
      "cvss_score": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.07059,
      "epss_score": 0.00174,
      "first_observed_at": "2026-07-31T22:17:39.455090+00:00",
      "id": "CVE-2026-66338",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-31T22:17:39.455090+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A flaw was found in libsoup. NVD: The chunked transfer encoding parser uses a permissive parsing function for chunk sizes that silently accepts inputs violating RFC 9112, including leading whitespace, plus sign prefixes, and trailing invalid characters. NVD: When libsoup operates behind a strict frontend proxy, this parsing differential can be exploited to smuggle HTTP requests.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260731T222222Z/items/CVE-2026-66338.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A flaw was found in libsoup. NVD: The chunked transfer encoding parser uses a permissive parsing function for chunk sizes that silently accepts inputs violating RFC 9112, including leading whitespace, plus sign prefixes, and trailing invalid characters. NVD: When libsoup operates behind a strict frontend proxy, this parsing differential can be exploited to smuggle HTTP requests.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-66338/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-66339/",
      "current_public_safe_latest": false,
      "cvss_score": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.13849,
      "epss_score": 0.00229,
      "first_observed_at": "2026-07-31T22:17:39.455090+00:00",
      "id": "CVE-2026-66339",
      "impact_tags": [
        "information exposure review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-31T22:17:39.455090+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A flaw was found in libsoup. NVD: After a CONNECT tunnel is established through an HTTP proxy, libsoup incorrectly attaches the Proxy-Authorization header to subsequent HTTPS requests sent through that tunnel to the destination server. NVD: This allows the destination server to capture proxy credentials, leading to information disclosure.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260731T222222Z/items/CVE-2026-66339.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes information exposure review. Possible impact: An attacker may be able to access information that should not be exposed.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A flaw was found in libsoup. NVD: After a CONNECT tunnel is established through an HTTP proxy, libsoup incorrectly attaches the Proxy-Authorization header to subsequent HTTPS requests sent through that tunnel to the destination server. NVD: This allows the destination server to capture proxy credentials, leading to information disclosure.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-66339/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-66344/",
      "current_public_safe_latest": false,
      "cvss_score": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.01883,
      "epss_score": 0.00116,
      "first_observed_at": "2026-08-12T05:08:50.991993+00:00",
      "id": "CVE-2026-66344",
      "impact_tags": [
        "code execution review",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-12T05:08:50.991993+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: NetKids iMark, provided by Integrated Systems Technologies, Inc., contains an Uncontrolled Search Path Element vulnerability (CWE-427). NVD: An authenticated attacker may exploit this vulnerability to execute arbitrary code with SYSTEM privileges.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260812T051428Z/items/CVE-2026-66344.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes code execution review · authenticated boundary. Possible impact: An attacker may be able to run code or commands on affected systems.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: NetKids iMark, provided by Integrated Systems Technologies, Inc., contains an Uncontrolled Search Path Element vulnerability (CWE-427). NVD: An authenticated attacker may exploit this vulnerability to execute arbitrary code with SYSTEM privileges.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-66344/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-66373/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.38371,
      "epss_score": 0.00472,
      "first_observed_at": "2026-07-31T22:17:39.455090+00:00",
      "id": "CVE-2026-66373",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-31T22:17:39.455090+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: NOTE: this issue exists because of an incomplete fix for CVE-2026-25243. OSV: NOTE: this issue exists because of an incomplete fix for CVE-2026-25243.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260731T222222Z/items/CVE-2026-66373.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: NOTE: this issue exists because of an incomplete fix for CVE-2026-25243. OSV: NOTE: this issue exists because of an incomplete fix for CVE-2026-25243.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-66373/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-66374/",
      "current_public_safe_latest": false,
      "cvss_score": 8.1,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.3166,
      "epss_score": 0.00389,
      "first_observed_at": "2026-07-31T22:17:39.455090+00:00",
      "id": "CVE-2026-66374",
      "impact_tags": [
        "code execution review",
        "memory safety review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-31T22:17:39.455090+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Knot Resolver before 6.4.1 allows remote code execution via a heap-based buffer overflow in the DoQ (DNS-over-QUIC) receive path.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260731T222222Z/items/CVE-2026-66374.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes code execution review · memory safety review. Possible impact: An attacker may be able to run code or commands on affected systems.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Knot Resolver before 6.4.1 allows remote code execution via a heap-based buffer overflow in the DoQ (DNS-over-QUIC) receive path.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-66374/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-66400/",
      "current_public_safe_latest": false,
      "cvss_score": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.04881,
      "epss_score": 0.00152,
      "first_observed_at": "2026-08-05T11:32:09.387600+00:00",
      "id": "CVE-2026-66400",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-05T11:32:09.387600+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Grav Login Plugin versions before 3.8.13 contain an insufficient session expiration vulnerability in TokenStorage.php where the findTriplet() method fails to properly validate Remember Me token timestamps. NVD: Attackers with a captured Remember Me cookie can authenticate indefinitely instead of the configured timeout period, as the expiry check compares an array to a scalar value which always evaluates incorrectly in PHP.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260805T113552Z/items/CVE-2026-66400.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Grav Login Plugin versions before 3.8.13 contain an insufficient session expiration vulnerability in TokenStorage.php where the findTriplet() method fails to properly validate Remember Me token timestamps. NVD: Attackers with a captured Remember Me cookie can authenticate indefinitely instead of the configured timeout period, as the expiry check compares an array to a scalar value which always evaluates incorrectly in PHP.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-66400/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-66401/",
      "current_public_safe_latest": false,
      "cvss_score": 2.4,
      "cvss_severity": "LOW",
      "epss_percentile": 0.0479,
      "epss_score": 0.00151,
      "first_observed_at": "2026-08-08T09:56:53.105288+00:00",
      "id": "CVE-2026-66401",
      "impact_tags": [
        "service availability review",
        "local exposure relevant"
      ],
      "kev": false,
      "last_observed_at": "2026-08-08T09:56:53.105288+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: FreeRDP before 3.29.0 contains an out-of-bounds heap read vulnerability in the UVC H.264 extension-unit parser that fails to validate descriptor length before accessing the GUID field. NVD: A local attacker with a malicious USB video camera can trigger a heap read beyond allocated bounds during camera stream setup, causing denial of service. OSV: FreeRDP before 3.29.0 Out-of-Bounds Read via UVC H.264",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260808T100051Z/items/CVE-2026-66401.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes service availability risk · local exposure. Possible impact: The affected service may become unavailable or unreliable.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: FreeRDP before 3.29.0 contains an out-of-bounds heap read vulnerability in the UVC H.264 extension-unit parser that fails to validate descriptor length before accessing the GUID field. NVD: A local attacker with a malicious USB video camera can trigger a heap read beyond allocated bounds during camera stream setup, causing denial of service. OSV: FreeRDP before 3.29.0 Out-of-Bounds Read via UVC H.264",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-66401/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-66402/",
      "current_public_safe_latest": false,
      "cvss_score": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.2122,
      "epss_score": 0.0029,
      "first_observed_at": "2026-08-08T09:56:53.105288+00:00",
      "id": "CVE-2026-66402",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-08T09:56:53.105288+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains multiple TLS certificate identity validation weaknesses in tls_verify_certificate(), tls_match_hostname(), and x509_utils_get_dns_names(). NVD: Because FreeRDP performs custom Common Name and DNS SAN string matching instead of using OpenSSL's length-aware identity validation APIs, it (1) truncates DNS SAN values at embedded NUL bytes (accepting e.g. NVD: 'victim.example\\0.attacker.example' as 'victim.example'), (2) accepts a matching Common Name even when non-matching DNS SAN entries are present, and (3) accepts IP-literal targets via DNS/CN matching without comparing iPAddress SANs.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260808T100051Z/items/CVE-2026-66402.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains multiple TLS certificate identity validation weaknesses in tls_verify_certificate(), tls_match_hostname(), and x509_utils_get_dns_names(). NVD: Because FreeRDP performs custom Common Name and DNS SAN string matching instead of using OpenSSL's length-aware identity validation APIs, it (1) truncates DNS SAN values at embedded NUL bytes (accepting e.g. NVD: 'victim.example\\0.attacker.example' as 'victim.example'), (2) accepts a matching Common Name even when non-matching DNS SAN entries are present, and (3) accepts IP-literal targets via DNS/CN matching without comparing iPAddress SANs.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-66402/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-66473/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.10302,
      "epss_score": 0.00202,
      "first_observed_at": "2026-08-03T22:29:45.220405+00:00",
      "id": "CVE-2026-66473",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-03T22:29:45.220405+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Unauthenticated Broken Access Control in Xendit Payment <= 7.1.0 versions.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260803T223322Z/items/CVE-2026-66473.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Unauthenticated Broken Access Control in Xendit Payment <= 7.1.0 versions.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-66473/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-6656/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.24005,
      "epss_score": 0.00317,
      "first_observed_at": "2026-07-27T06:45:51.031460+00:00",
      "id": "CVE-2026-6656",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-27T06:45:51.031460+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Crypt::Password versions through 0.28 for Perl are susceptible to timing attacks. NVD: The check_password method uses the built-in eq operator. NVD: This allows discrepancies in timing to be used to guess the underlying hash.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260727T065126Z/items/CVE-2026-6656.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Crypt::Password versions through 0.28 for Perl are susceptible to timing attacks. NVD: The check_password method uses the built-in eq operator. NVD: This allows discrepancies in timing to be used to guess the underlying hash.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-6656/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-66747/",
      "current_public_safe_latest": true,
      "cvss_score": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.44552,
      "epss_score": 0.00579,
      "first_observed_at": "2026-08-12T10:29:37.194110+00:00",
      "id": "CVE-2026-66747",
      "impact_tags": [
        "code execution review",
        "admin privilege risk"
      ],
      "kev": false,
      "last_observed_at": "2026-08-12T10:29:37.194110+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-66747.json",
      "product": null,
      "public_safe_summary": "NVD: Zbtlink router firmware ships an embedded remote-control implant, ENDLESSDOORS, present in every published build across the product line. NVD: It is the open-source ycsunjane/rctl tool built in as an OpenWrt package (librctl.so), started at boot and run as root under the process name kworker to blend in with the kernel's [kworker/*] threads. NVD: It opens no listening port; it phones home over cleartext TCP to a hardcoded command-and-control server (command channel 7000, interactive-shell callback 7001) with no authentication and no transport encryption, re-attempting contact roughly every 35 seconds.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260812T103932Z/items/CVE-2026-66747.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes code execution review · admin privilege risk. Possible impact: An attacker may gain root or administrative-level privileges on affected systems.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Zbtlink router firmware ships an embedded remote-control implant, ENDLESSDOORS, present in every published build across the product line. NVD: It is the open-source ycsunjane/rctl tool built in as an OpenWrt package (librctl.so), started at boot and run as root under the process name kworker to blend in with the kernel's [kworker/*] threads. NVD: It opens no listening port; it phones home over cleartext TCP to a hardcoded command-and-control server (command channel 7000, interactive-shell callback 7001) with no authentication and no transport encryption, re-attempting contact roughly every 35 seconds.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-66747/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-66839/",
      "current_public_safe_latest": false,
      "cvss_score": 8.4,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.034,
      "epss_score": 0.00135,
      "first_observed_at": "2026-08-12T05:08:50.991993+00:00",
      "id": "CVE-2026-66839",
      "impact_tags": [
        "code execution review",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-12T05:08:50.991993+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: NetKids iMark, provided by Integrated Systems Technologies, Inc., contains an Unquoted Search Path or Element vulnerability (CWE-428). NVD: An authenticated attacker may exploit this vulnerability to execute arbitrary code with SYSTEM privileges.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260812T051428Z/items/CVE-2026-66839.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes code execution review · authenticated boundary. Possible impact: An attacker may be able to run code or commands on affected systems.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: NetKids iMark, provided by Integrated Systems Technologies, Inc., contains an Unquoted Search Path or Element vulnerability (CWE-428). NVD: An authenticated attacker may exploit this vulnerability to execute arbitrary code with SYSTEM privileges.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-66839/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-66883/",
      "current_public_safe_latest": false,
      "cvss_score": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.21251,
      "epss_score": 0.0029,
      "first_observed_at": "2026-08-11T10:14:04.199465+00:00",
      "id": "CVE-2026-66883",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-11T10:14:04.199465+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Improper Handling of Case Sensitivity vulnerability in Erlang Ecosystem Foundation oidcc_plug (Oidcc.Plug.Authorize module) renders the user agent session binding inert, removing a defense in depth control against replay of a stolen session. NVD: This vulnerability is associated with program files lib/oidcc/plug/authorize.ex and lib/oidcc/plug/authorization_callback.ex, and program routines Oidcc.Plug.Authorize.call/2 and Oidcc.Plug.AuthorizationCallback.call/2. NVD: Oidcc.Plug.Authorize.call/2 reads the initiating client's user agent with get_req_header(conn, \"User-Agent\").",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260811T102539Z/items/CVE-2026-66883.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Improper Handling of Case Sensitivity vulnerability in Erlang Ecosystem Foundation oidcc_plug (Oidcc.Plug.Authorize module) renders the user agent session binding inert, removing a defense in depth control against replay of a stolen session. NVD: This vulnerability is associated with program files lib/oidcc/plug/authorize.ex and lib/oidcc/plug/authorization_callback.ex, and program routines Oidcc.Plug.Authorize.call/2 and Oidcc.Plug.AuthorizationCallback.call/2. NVD: Oidcc.Plug.Authorize.call/2 reads the initiating client's user agent with get_req_header(conn, \"User-Agent\").",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-66883/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-66884/",
      "current_public_safe_latest": false,
      "cvss_score": 2.1,
      "cvss_severity": "LOW",
      "epss_percentile": 0.11749,
      "epss_score": 0.00214,
      "first_observed_at": "2026-08-11T10:14:04.199465+00:00",
      "id": "CVE-2026-66884",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-11T10:14:04.199465+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Cross-Site Request Forgery vulnerability in Erlang Ecosystem Foundation oidcc_plug (Oidcc.Plug.AuthorizationCallback module) allows an attacker to make a victim's browser complete an authorization flow the victim never initiated. NVD: This vulnerability is associated with program file lib/oidcc/plug/authorization_callback.ex and program routine Oidcc.Plug.AuthorizationCallback.call/2. NVD: A callback request that carries no Oidcc.Plug.Authorize session is processed with every security check disabled rather than being rejected.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260811T102539Z/items/CVE-2026-66884.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Cross-Site Request Forgery vulnerability in Erlang Ecosystem Foundation oidcc_plug (Oidcc.Plug.AuthorizationCallback module) allows an attacker to make a victim's browser complete an authorization flow the victim never initiated. NVD: This vulnerability is associated with program file lib/oidcc/plug/authorization_callback.ex and program routine Oidcc.Plug.AuthorizationCallback.call/2. NVD: A callback request that carries no Oidcc.Plug.Authorize session is processed with every security check disabled rather than being rejected.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-66884/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-6694/",
      "current_public_safe_latest": false,
      "cvss_score": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.04618,
      "epss_score": 0.00149,
      "first_observed_at": "2026-08-10T04:58:31.923491+00:00",
      "id": "CVE-2026-6694",
      "impact_tags": [
        "service availability review",
        "memory safety review",
        "remote exposure relevant"
      ],
      "kev": false,
      "last_observed_at": "2026-08-10T04:58:31.923491+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A flaw was found in GIMP's file-png plugin. NVD: A remote attacker can exploit this by crafting a malicious Animated Portable Network Graphics (APNG) image containing an oversized tRNS chunk. NVD: This can lead to a stack-based buffer overflow (CWE-121), causing the file-png plugin to crash and resulting in a Denial of Service (DoS) for the user.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260810T050414Z/items/CVE-2026-6694.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes service availability risk · memory safety review · remote exposure. Possible impact: The affected service may become unavailable or unreliable.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A flaw was found in GIMP's file-png plugin. NVD: A remote attacker can exploit this by crafting a malicious Animated Portable Network Graphics (APNG) image containing an oversized tRNS chunk. NVD: This can lead to a stack-based buffer overflow (CWE-121), causing the file-png plugin to crash and resulting in a Denial of Service (DoS) for the user.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-6694/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-6695/",
      "current_public_safe_latest": false,
      "cvss_score": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.04815,
      "epss_score": 0.00152,
      "first_observed_at": "2026-08-10T04:58:31.923491+00:00",
      "id": "CVE-2026-6695",
      "impact_tags": [
        "code execution review",
        "remote exposure relevant"
      ],
      "kev": false,
      "last_observed_at": "2026-08-10T04:58:31.923491+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A flaw was found in GIMP. NVD: A remote attacker could exploit this by tricking a user into opening a specially crafted PAA (Paint Shop Pro Array) image file. NVD: This vulnerability, a heap-based out-of-bounds write in the decode_lzss() function of the PAA file format plugin, allows data to be written beyond the intended memory buffer.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260810T050414Z/items/CVE-2026-6695.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes code execution review · remote exposure. Possible impact: A remote attacker may be able to run code or commands on affected systems.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A flaw was found in GIMP. NVD: A remote attacker could exploit this by tricking a user into opening a specially crafted PAA (Paint Shop Pro Array) image file. NVD: This vulnerability, a heap-based out-of-bounds write in the decode_lzss() function of the PAA file format plugin, allows data to be written beyond the intended memory buffer.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-6695/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-67182/",
      "current_public_safe_latest": false,
      "cvss_score": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.34208,
      "epss_score": 0.00415,
      "first_observed_at": "2026-08-04T17:06:52.325316+00:00",
      "id": "CVE-2026-67182",
      "impact_tags": [
        "remote exposure relevant"
      ],
      "kev": false,
      "last_observed_at": "2026-08-04T17:06:52.325316+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Rouille 0.3.3 through 3.6.2 contains an HTTP request smuggling vulnerability that allows remote attackers to bypass access controls by injecting bare line feed characters (0x0A) into client-supplied request header values that are copied verbatim to upstream... NVD: Attackers can craft a header value containing a complete additional HTTP request that is interpreted as a separate request by backends such as Go net/http and Python http.server, causing the backend to process a smuggled request with attacker-chosen method... OSV: Rouille 0.3.3 - 3.6.2 HTTP Request Smuggling via proxy Header Injection",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260804T171542Z/items/CVE-2026-67182.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes remote exposure. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Rouille 0.3.3 through 3.6.2 contains an HTTP request smuggling vulnerability that allows remote attackers to bypass access controls by injecting bare line feed characters (0x0A) into client-supplied request header values that are copied verbatim to upstream... NVD: Attackers can craft a header value containing a complete additional HTTP request that is interpreted as a separate request by backends such as Go net/http and Python http.server, causing the backend to process a smuggled request with attacker-chosen method... OSV: Rouille 0.3.3 - 3.6.2 HTTP Request Smuggling via proxy Header Injection",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-67182/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-67183/",
      "current_public_safe_latest": false,
      "cvss_score": 8.7,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.2944,
      "epss_score": 0.00367,
      "first_observed_at": "2026-08-04T17:06:52.325316+00:00",
      "id": "CVE-2026-67183",
      "impact_tags": [
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-04T17:06:52.325316+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: TinyWeb through 0.0.8 contains a memory leak vulnerability that allows unauthenticated attackers to exhaust available memory by sending ordinary well-formed HTTP requests. NVD: Each request causes HttpParser::execute() to allocate Url objects, HttpHeaders objects, and HttpHeader instances via raw new expressions that are never freed due to missing destructors and unreachable delete calls, causing worker resident memory to grow...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260804T171542Z/items/CVE-2026-67183.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes remote exposure · authenticated boundary. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: TinyWeb through 0.0.8 contains a memory leak vulnerability that allows unauthenticated attackers to exhaust available memory by sending ordinary well-formed HTTP requests. NVD: Each request causes HttpParser::execute() to allocate Url objects, HttpHeaders objects, and HttpHeader instances via raw new expressions that are never freed due to missing destructors and unreachable delete calls, causing worker resident memory to grow...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-67183/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-67184/",
      "current_public_safe_latest": false,
      "cvss_score": 8.7,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.35517,
      "epss_score": 0.00432,
      "first_observed_at": "2026-08-04T17:06:52.325316+00:00",
      "id": "CVE-2026-67184",
      "impact_tags": [
        "remote exposure relevant"
      ],
      "kev": false,
      "last_observed_at": "2026-08-04T17:06:52.325316+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: TinyWeb through 0.0.8 contains a null pointer dereference vulnerability that allows unauthenticated remote attackers to crash worker processes by sending a malformed HTTP request line with an invalid version string. NVD: The HttpParser::execute() function fails to allocate the Url object when version parsing fails, leaving the url pointer NULL, and buildResponse() subsequently dereferences this NULL pointer without checking the valid_requ flag, producing a SIGSEGV that...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260804T171542Z/items/CVE-2026-67184.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes remote exposure. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: TinyWeb through 0.0.8 contains a null pointer dereference vulnerability that allows unauthenticated remote attackers to crash worker processes by sending a malformed HTTP request line with an invalid version string. NVD: The HttpParser::execute() function fails to allocate the Url object when version parsing fails, leaving the url pointer NULL, and buildResponse() subsequently dereferences this NULL pointer without checking the valid_requ flag, producing a SIGSEGV that...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-67184/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-67185/",
      "current_public_safe_latest": false,
      "cvss_score": 8.7,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.37112,
      "epss_score": 0.00453,
      "first_observed_at": "2026-08-04T17:06:52.325316+00:00",
      "id": "CVE-2026-67185",
      "impact_tags": [
        "admin privilege risk",
        "path traversal review",
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-04T17:06:52.325316+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: TinyWeb through 0.0.8 contains a path traversal vulnerability that allows unauthenticated attackers to read arbitrary files by submitting ../ sequences in the URL path, which are concatenated directly to the configured web root in HttpBuilder::buildResponse()... NVD: Attackers can craft a single request with ../ sequences that pass through the URL parser unchanged and reach the filesystem call via HttpFile::setFile(), exposing sensitive files such as credential stores and private keys when the server process runs as root.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260804T171542Z/items/CVE-2026-67185.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes admin privilege risk · path traversal review · remote exposure. Possible impact: A remote attacker may gain root or administrative-level privileges on affected systems.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: TinyWeb through 0.0.8 contains a path traversal vulnerability that allows unauthenticated attackers to read arbitrary files by submitting ../ sequences in the URL path, which are concatenated directly to the configured web root in HttpBuilder::buildResponse()... NVD: Attackers can craft a single request with ../ sequences that pass through the URL parser unchanged and reach the filesystem call via HttpFile::setFile(), exposing sensitive files such as credential stores and private keys when the server process runs as root.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-67185/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-67194/",
      "current_public_safe_latest": false,
      "cvss_score": 7.1,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.22805,
      "epss_score": 0.00305,
      "first_observed_at": "2026-08-05T16:55:08.588478+00:00",
      "id": "CVE-2026-67194",
      "impact_tags": [
        "service availability review",
        "memory safety review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-05T16:55:08.588478+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Courier IMAP before 6.0.1 and Courier Mail Server before 2.0.2 allow authenticated IMAP users to crash the imapd process via deeply nested parenthesized SEARCH queries. NVD: The SEARCH command parser (alloc_search_key in searchinfo.C) recursively descends on nested parenthesized groups through a mutual recursion chain with alloc_search_andlist() and alloc_search_notkey(), with no depth limit. NVD: Courier IMAP has no overall command line length limit, making exploitation trivial.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260805T165944Z/items/CVE-2026-67194.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes service availability risk · memory safety review. Possible impact: The affected service may become unavailable or unreliable.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Courier IMAP before 6.0.1 and Courier Mail Server before 2.0.2 allow authenticated IMAP users to crash the imapd process via deeply nested parenthesized SEARCH queries. NVD: The SEARCH command parser (alloc_search_key in searchinfo.C) recursively descends on nested parenthesized groups through a mutual recursion chain with alloc_search_andlist() and alloc_search_notkey(), with no depth limit. NVD: Courier IMAP has no overall command line length limit, making exploitation trivial.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-67194/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-67288/",
      "current_public_safe_latest": false,
      "cvss_score": 8.7,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.27726,
      "epss_score": 0.0035,
      "first_observed_at": "2026-08-08T09:56:53.105288+00:00",
      "id": "CVE-2026-67288",
      "impact_tags": [
        "service availability review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-08T09:56:53.105288+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: FreeRDP before 3.29.0 contains a null pointer dereference vulnerability in smartcard cache request decoders that accept NULL NDR pointers for LookupName in SCARD_IOCTL_READCACHEA and SCARD_IOCTL_WRITECACHEA operations. NVD: When smartcard emulation is enabled, attackers can send crafted smartcard cache requests with NULL lookup-name pointers to trigger strlen() on a null pointer, causing client process termination. OSV: FreeRDP before 3.29.0 Denial of Service via smartcard cache",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260808T100051Z/items/CVE-2026-67288.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes service availability risk. Possible impact: The affected service may become unavailable or unreliable.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: FreeRDP before 3.29.0 contains a null pointer dereference vulnerability in smartcard cache request decoders that accept NULL NDR pointers for LookupName in SCARD_IOCTL_READCACHEA and SCARD_IOCTL_WRITECACHEA operations. NVD: When smartcard emulation is enabled, attackers can send crafted smartcard cache requests with NULL lookup-name pointers to trigger strlen() on a null pointer, causing client process termination. OSV: FreeRDP before 3.29.0 Denial of Service via smartcard cache",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-67288/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-67289/",
      "current_public_safe_latest": false,
      "cvss_score": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.30796,
      "epss_score": 0.0038,
      "first_observed_at": "2026-08-08T09:56:53.105288+00:00",
      "id": "CVE-2026-67289",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-08T09:56:53.105288+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: FreeRDP before 3.29.0 (affected versions <= 3.28.0) does not validate CRLF and control characters in the server-controlled RDP redirection TargetNetAddress field. NVD: This value is copied into the client's ServerHostname and, when the client connects through an HTTP proxy, is written directly into the proxy CONNECT request line and Host header by http_proxy_connect() without filtering. NVD: A malicious or compromised RDP server can send a crafted redirection PDU containing embedded control characters to inject arbitrary headers/requests into the HTTP proxy CONNECT request.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260808T100051Z/items/CVE-2026-67289.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: FreeRDP before 3.29.0 (affected versions <= 3.28.0) does not validate CRLF and control characters in the server-controlled RDP redirection TargetNetAddress field. NVD: This value is copied into the client's ServerHostname and, when the client connects through an HTTP proxy, is written directly into the proxy CONNECT request line and Host header by http_proxy_connect() without filtering. NVD: A malicious or compromised RDP server can send a crafted redirection PDU containing embedded control characters to inject arbitrary headers/requests into the HTTP proxy CONNECT request.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-67289/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-67290/",
      "current_public_safe_latest": false,
      "cvss_score": 8.7,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.35546,
      "epss_score": 0.00432,
      "first_observed_at": "2026-08-08T09:56:53.105288+00:00",
      "id": "CVE-2026-67290",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-08T09:56:53.105288+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: FreeRDP before 3.29.0 contains a heap out-of-bounds read vulnerability in the TSMF FFmpeg decoder when parsing AVC1 MPEG2VIDEOINFO media types with insufficient ExtraData. NVD: Attackers can send malformed media format data from a server to trigger a crash by reading fixed offsets without validating source buffer length. OSV: FreeRDP before 3.29.0 Heap Out-of-Bounds Read via TSMF",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260808T100051Z/items/CVE-2026-67290.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: FreeRDP before 3.29.0 contains a heap out-of-bounds read vulnerability in the TSMF FFmpeg decoder when parsing AVC1 MPEG2VIDEOINFO media types with insufficient ExtraData. NVD: Attackers can send malformed media format data from a server to trigger a crash by reading fixed offsets without validating source buffer length. OSV: FreeRDP before 3.29.0 Heap Out-of-Bounds Read via TSMF",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-67290/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-67291/",
      "current_public_safe_latest": false,
      "cvss_score": 8.7,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.26494,
      "epss_score": 0.00339,
      "first_observed_at": "2026-08-08T09:56:53.105288+00:00",
      "id": "CVE-2026-67291",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-08T09:56:53.105288+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains a heap out-of-bounds read in update_process_glyph_fragments()/glyph_cache_fragment_put() in libfreerdp/cache/glyph.c. NVD: When handling a GLYPH_FRAGMENT_ADD update, the code reads a one-byte server-controlled declared fragment size but does not verify it fits within the remaining received buffer before allocating and copying that many bytes. NVD: A malicious RDP server can send a short fragment with an oversized declared size, causing the client to read beyond the allocated buffer, resulting in an out-of-bounds read and client crash.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260808T100051Z/items/CVE-2026-67291.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains a heap out-of-bounds read in update_process_glyph_fragments()/glyph_cache_fragment_put() in libfreerdp/cache/glyph.c. NVD: When handling a GLYPH_FRAGMENT_ADD update, the code reads a one-byte server-controlled declared fragment size but does not verify it fits within the remaining received buffer before allocating and copying that many bytes. NVD: A malicious RDP server can send a short fragment with an oversized declared size, causing the client to read beyond the allocated buffer, resulting in an out-of-bounds read and client crash.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-67291/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-67292/",
      "current_public_safe_latest": false,
      "cvss_score": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.18047,
      "epss_score": 0.00264,
      "first_observed_at": "2026-08-08T09:56:53.105288+00:00",
      "id": "CVE-2026-67292",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-08T09:56:53.105288+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: FreeRDP before 3.29.0 contains a buffer over-disclosure vulnerability in the gateway WebSocket transport (libfreerdp/core/gateway/websocket.c). NVD: A zero-length Ping reaches an assertion and terminates the client (denial of service). OSV: FreeRDP before 3.29.0 WebSocket Ping Buffer Over-disclosure",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260808T100051Z/items/CVE-2026-67292.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: FreeRDP before 3.29.0 contains a buffer over-disclosure vulnerability in the gateway WebSocket transport (libfreerdp/core/gateway/websocket.c). NVD: A zero-length Ping reaches an assertion and terminates the client (denial of service). OSV: FreeRDP before 3.29.0 WebSocket Ping Buffer Over-disclosure",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-67292/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-67293/",
      "current_public_safe_latest": false,
      "cvss_score": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.06168,
      "epss_score": 0.00166,
      "first_observed_at": "2026-08-08T09:56:53.105288+00:00",
      "id": "CVE-2026-67293",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-08T09:56:53.105288+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains an improper certificate hostname validation vulnerability. NVD: The TLS hostname matcher (tls_match_hostname() in libfreerdp/crypto/tls.c) treats a wildcard pattern such as *.example.com as matching any hostname ending in .example.com, so it incorrectly accepts a wildcard certificate for multi-label subdomains like... NVD: This weakens TLS server authentication under wildcard-certificate conditions.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260808T100051Z/items/CVE-2026-67293.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains an improper certificate hostname validation vulnerability. NVD: The TLS hostname matcher (tls_match_hostname() in libfreerdp/crypto/tls.c) treats a wildcard pattern such as *.example.com as matching any hostname ending in .example.com, so it incorrectly accepts a wildcard certificate for multi-label subdomains like... NVD: This weakens TLS server authentication under wildcard-certificate conditions.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-67293/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-67294/",
      "current_public_safe_latest": false,
      "cvss_score": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.19037,
      "epss_score": 0.00271,
      "first_observed_at": "2026-08-08T09:56:53.105288+00:00",
      "id": "CVE-2026-67294",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-08T09:56:53.105288+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: FreeRDP before 3.29.0 improperly validates the Extended Key Usage (EKU) purpose of the peer certificate during client-side server TLS authentication. NVD: In x509_utils_verify(), when server-purpose (X509_PURPOSE_SSL_SERVER) verification fails, the code falls back to client-purpose and any-purpose verification, so a trusted, hostname-matching certificate valid only for clientAuth can be accepted as the RDP... NVD: In environments relying on EKU separation between client and server certificates, this allows a clientAuth-only certificate issued by a trusted CA to bypass server certificate purpose validation.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260808T100051Z/items/CVE-2026-67294.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: FreeRDP before 3.29.0 improperly validates the Extended Key Usage (EKU) purpose of the peer certificate during client-side server TLS authentication. NVD: In x509_utils_verify(), when server-purpose (X509_PURPOSE_SSL_SERVER) verification fails, the code falls back to client-purpose and any-purpose verification, so a trusted, hostname-matching certificate valid only for clientAuth can be accepted as the RDP... NVD: In environments relying on EKU separation between client and server certificates, this allows a clientAuth-only certificate issued by a trusted CA to bypass server certificate purpose validation.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-67294/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-67295/",
      "current_public_safe_latest": false,
      "cvss_score": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.15669,
      "epss_score": 0.00245,
      "first_observed_at": "2026-08-08T09:56:53.105288+00:00",
      "id": "CVE-2026-67295",
      "impact_tags": [
        "path traversal review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-08T09:56:53.105288+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: FreeRDP before 3.29.0 fails to properly validate server-supplied RDPDR paths in drive redirection, allowing attackers to access prefix-sibling paths outside the configured shared root. NVD: A malicious RDP server can read, write, delete, and enumerate files in sibling directories by sending non-rooted paths that bypass the shared-root boundary check. OSV: FreeRDP before 3.29.0 Path Traversal via drive redirection",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260808T100051Z/items/CVE-2026-67295.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes path traversal review. Possible impact: An attacker may be able to reach files outside the intended application path.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: FreeRDP before 3.29.0 fails to properly validate server-supplied RDPDR paths in drive redirection, allowing attackers to access prefix-sibling paths outside the configured shared root. NVD: A malicious RDP server can read, write, delete, and enumerate files in sibling directories by sending non-rooted paths that bypass the shared-root boundary check. OSV: FreeRDP before 3.29.0 Path Traversal via drive redirection",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-67295/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-67296/",
      "current_public_safe_latest": false,
      "cvss_score": 8.7,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.2699,
      "epss_score": 0.00343,
      "first_observed_at": "2026-08-08T09:56:53.105288+00:00",
      "id": "CVE-2026-67296",
      "impact_tags": [
        "service availability review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-08T09:56:53.105288+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: FreeRDP before 3.29.0 contains a denial of service vulnerability in the RDPEI server channel handler that fails to validate maximum PDU body length before stream allocation. NVD: A malicious RDP client can send a header-only RDPEI message with a large declared body length to force excessive memory allocation on the server. OSV: FreeRDP before 3.29.0 Denial of Service via RDPEI PDU",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260808T100051Z/items/CVE-2026-67296.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes service availability risk. Possible impact: The affected service may become unavailable or unreliable.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: FreeRDP before 3.29.0 contains a denial of service vulnerability in the RDPEI server channel handler that fails to validate maximum PDU body length before stream allocation. NVD: A malicious RDP client can send a header-only RDPEI message with a large declared body length to force excessive memory allocation on the server. OSV: FreeRDP before 3.29.0 Denial of Service via RDPEI PDU",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-67296/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-67297/",
      "current_public_safe_latest": false,
      "cvss_score": 8.7,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.26993,
      "epss_score": 0.00343,
      "first_observed_at": "2026-08-08T09:56:53.105288+00:00",
      "id": "CVE-2026-67297",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-08T09:56:53.105288+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: FreeRDP before 3.29.0 fails to enforce the RESPONSE_SIZE_LIMIT when processing Transfer-Encoding: chunked HTTP responses in http_response_recv_body(). NVD: Attackers controlling a malicious RD Gateway endpoint can send oversized chunked response bodies to exhaust client memory resources without triggering the configured size limit. OSV: FreeRDP before 3.29.0 Resource Exhaustion via chunked HTTP response",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260808T100051Z/items/CVE-2026-67297.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: FreeRDP before 3.29.0 fails to enforce the RESPONSE_SIZE_LIMIT when processing Transfer-Encoding: chunked HTTP responses in http_response_recv_body(). NVD: Attackers controlling a malicious RD Gateway endpoint can send oversized chunked response bodies to exhaust client memory resources without triggering the configured size limit. OSV: FreeRDP before 3.29.0 Resource Exhaustion via chunked HTTP response",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-67297/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-67298/",
      "current_public_safe_latest": false,
      "cvss_score": 8.7,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.30833,
      "epss_score": 0.00381,
      "first_observed_at": "2026-08-08T09:56:53.105288+00:00",
      "id": "CVE-2026-67298",
      "impact_tags": [
        "memory safety review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-08T09:56:53.105288+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: FreeRDP versions 3.28.0 and earlier contain a heap buffer overflow in the server-side RAIL channel handler (rail_server_handle_messages() in channels/rail/server/rail_main.c). NVD: When processing a RAIL PDU header, the code subtracts RAIL_PDU_HEADER_LENGTH from the peer-controlled orderLength field without first verifying orderLength is at least the header length. NVD: For orderLength values 0..3 this causes an unsigned integer underflow to a very large size, which bypasses the Stream_EnsureRemainingCapacity() capacity check (due to pointer arithmetic wraparound) and is then passed to WTSVirtualChannelRead(), resulting in...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260808T100051Z/items/CVE-2026-67298.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes memory safety review. Possible impact: The affected component has memory-safety risk that may lead to crash, privilege, or code-execution impact depending on exposure.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: FreeRDP.",
      "source_published_summary": "NVD: FreeRDP versions 3.28.0 and earlier contain a heap buffer overflow in the server-side RAIL channel handler (rail_server_handle_messages() in channels/rail/server/rail_main.c). NVD: When processing a RAIL PDU header, the code subtracts RAIL_PDU_HEADER_LENGTH from the peer-controlled orderLength field without first verifying orderLength is at least the header length. NVD: For orderLength values 0..3 this causes an unsigned integer underflow to a very large size, which bypasses the Stream_EnsureRemainingCapacity() capacity check (due to pointer arithmetic wraparound) and is then passed to WTSVirtualChannelRead(), resulting in...",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-67298/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-67356/",
      "current_public_safe_latest": false,
      "cvss_score": 8.7,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.15837,
      "epss_score": 0.00246,
      "first_observed_at": "2026-08-09T09:59:30.349754+00:00",
      "id": "CVE-2026-67356",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-09T09:59:30.349754+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: ArcadeDB before 26.7.3 binds the real LocalDatabase object into JavaScript trigger contexts with HostAccess.ALL, allowing schema-admins to call getSecurity().createUser() without permission checks. NVD: Attackers with UPDATE_SCHEMA permission can create triggers that execute JavaScript to create server-wide admin users, escalating privileges beyond their authorization level.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260809T101323Z/items/CVE-2026-67356.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: ArcadeDB before 26.7.3 binds the real LocalDatabase object into JavaScript trigger contexts with HostAccess.ALL, allowing schema-admins to call getSecurity().createUser() without permission checks. NVD: Attackers with UPDATE_SCHEMA permission can create triggers that execute JavaScript to create server-wide admin users, escalating privileges beyond their authorization level.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-67356/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-67357/",
      "current_public_safe_latest": false,
      "cvss_score": 7.7,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.16365,
      "epss_score": 0.0025,
      "first_observed_at": "2026-08-09T09:59:30.349754+00:00",
      "id": "CVE-2026-67357",
      "impact_tags": [
        "information exposure review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-09T09:59:30.349754+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: ArcadeDB versions before 26.7.3 contain an information disclosure vulnerability in the MCP get_server_settings tool that leaks the arcadedb.ha.clusterToken in cleartext. NVD: Attackers with MCP access can retrieve the cluster token and use it with X-ArcadeDB-Cluster-Token and X-ArcadeDB-Forwarded-User headers to impersonate root and achieve full server compromise.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260809T101323Z/items/CVE-2026-67357.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes information exposure review. Possible impact: An attacker may be able to access information that should not be exposed.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: ArcadeDB versions before 26.7.3 contain an information disclosure vulnerability in the MCP get_server_settings tool that leaks the arcadedb.ha.clusterToken in cleartext. NVD: Attackers with MCP access can retrieve the cluster token and use it with X-ArcadeDB-Cluster-Token and X-ArcadeDB-Forwarded-User headers to impersonate root and achieve full server compromise.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-67357/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-6740/",
      "current_public_safe_latest": false,
      "cvss_score": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.05169,
      "epss_score": 0.00156,
      "first_observed_at": "2026-07-15T11:03:27.604769+00:00",
      "id": "CVE-2026-6740",
      "impact_tags": [
        "XSS risk",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-15T11:03:27.604769+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Nexter Blocks – Gutenberg Blocks, Page Builder & AI Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'commentIcon' parameter in all versions up to, and including, 4.7.4 due to insufficient input sanitization and... NVD: This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260715T110622Z/items/CVE-2026-6740.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes XSS risk · authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Nexter Blocks – Gutenberg Blocks, Page Builder & AI Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'commentIcon' parameter in all versions up to, and including, 4.7.4 due to insufficient input sanitization and... NVD: This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-6740/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-6742/",
      "current_public_safe_latest": false,
      "cvss_score": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.05169,
      "epss_score": 0.00156,
      "first_observed_at": "2026-07-15T11:03:27.604769+00:00",
      "id": "CVE-2026-6742",
      "impact_tags": [
        "XSS risk",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-15T11:03:27.604769+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Advanced iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'additional' parameter in all versions up to, and including, 2026.1 due to insufficient input sanitization and output escaping. NVD: This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260715T110622Z/items/CVE-2026-6742.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes XSS risk · authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Advanced iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'additional' parameter in all versions up to, and including, 2026.1 due to insufficient input sanitization and output escaping. NVD: This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-6742/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "apache / qpid_proton-dotnet",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-67465/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.39834,
      "epss_score": 0.00493,
      "first_observed_at": "2026-08-12T05:08:50.991993+00:00",
      "id": "CVE-2026-67465",
      "impact_tags": [
        "service availability review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-12T05:08:50.991993+00:00",
      "latest_item_url": null,
      "product": "qpid_proton-dotnet",
      "public_safe_summary": "NVD: A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service. NVD: This issue affects Apache Qpid Proton-Dotnet: through 1.0.0. NVD: Users are recommended to upgrade to version 1.1.0, which fixes the issue.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260812T051428Z/items/CVE-2026-67465.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: apache / qpid_proton-dotnet",
      "source_published_impact": "Source describes service availability risk. Possible impact: The affected service may become unavailable or unreliable.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service. NVD: This issue affects Apache Qpid Proton-Dotnet: through 1.0.0. NVD: Users are recommended to upgrade to version 1.1.0, which fixes the issue.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-67465/timeline.json",
      "vendor": "apache"
    },
    {
      "affected_label": "apache / qpid_proton-dotnet",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-67551/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.39835,
      "epss_score": 0.00493,
      "first_observed_at": "2026-08-12T05:08:50.991993+00:00",
      "id": "CVE-2026-67551",
      "impact_tags": [
        "service availability review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-12T05:08:50.991993+00:00",
      "latest_item_url": null,
      "product": "qpid_proton-dotnet",
      "public_safe_summary": "NVD: pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service. NVD: This issue affects Apache Qpid Proton-Dotnet: through 1.0.0. NVD: Users are recommended to upgrade to version 1.1.0, which fixes the issue.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260812T051428Z/items/CVE-2026-67551.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: apache / qpid_proton-dotnet",
      "source_published_impact": "Source describes service availability risk. Possible impact: The affected service may become unavailable or unreliable.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service. NVD: This issue affects Apache Qpid Proton-Dotnet: through 1.0.0. NVD: Users are recommended to upgrade to version 1.1.0, which fixes the issue.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-67551/timeline.json",
      "vendor": "apache"
    },
    {
      "affected_label": "apache / qpid_protonj2",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-67588/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.39222,
      "epss_score": 0.00483,
      "first_observed_at": "2026-08-12T05:08:50.991993+00:00",
      "id": "CVE-2026-67588",
      "impact_tags": [
        "service availability review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-12T05:08:50.991993+00:00",
      "latest_item_url": null,
      "product": "qpid_protonj2",
      "public_safe_summary": "NVD: A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service. NVD: This issue affects Apache Qpid ProtonJ2: through 1.1.0. NVD: Users are recommended to upgrade to version 1.2.0, which fixes the issue.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260812T051428Z/items/CVE-2026-67588.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: apache / qpid_protonj2",
      "source_published_impact": "Source describes service availability risk. Possible impact: The affected service may become unavailable or unreliable.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service. NVD: This issue affects Apache Qpid ProtonJ2: through 1.1.0. NVD: Users are recommended to upgrade to version 1.2.0, which fixes the issue.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-67588/timeline.json",
      "vendor": "apache"
    },
    {
      "affected_label": "apache / qpid_protonj2",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-67589/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.39836,
      "epss_score": 0.00493,
      "first_observed_at": "2026-08-12T05:08:50.991993+00:00",
      "id": "CVE-2026-67589",
      "impact_tags": [
        "service availability review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-12T05:08:50.991993+00:00",
      "latest_item_url": null,
      "product": "qpid_protonj2",
      "public_safe_summary": "NVD: A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service. NVD: This issue affects Apache Qpid ProtonJ2: through 1.1.0. NVD: Users are recommended to upgrade to version 1.2.0, which fixes the issue.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260812T051428Z/items/CVE-2026-67589.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: apache / qpid_protonj2",
      "source_published_impact": "Source describes service availability risk. Possible impact: The affected service may become unavailable or unreliable.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service. NVD: This issue affects Apache Qpid ProtonJ2: through 1.1.0. NVD: Users are recommended to upgrade to version 1.2.0, which fixes the issue.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-67589/timeline.json",
      "vendor": "apache"
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-67608/",
      "current_public_safe_latest": false,
      "cvss_score": 8.6,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.72197,
      "epss_score": 0.01522,
      "first_observed_at": "2026-08-10T10:38:36.347227+00:00",
      "id": "CVE-2026-67608",
      "impact_tags": [
        "command injection risk",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-10T10:38:36.347227+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Telenia Software TVox 26.5.3 and prior 26.x versions, and 24.9.21 and prior 24.x versions, contain an OS command injection vulnerability in action_audio.php that allows authenticated attackers to execute arbitrary operating system commands by passing an... NVD: Attackers can inject malicious OS commands through the pid request parameter to execute arbitrary commands with the privileges of the apache user.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260810T105121Z/items/CVE-2026-67608.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes command injection risk · authenticated boundary. Possible impact: An attacker may be able to run unintended system commands through the affected component.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Telenia Software TVox 26.5.3 and prior 26.x versions, and 24.9.21 and prior 24.x versions, contain an OS command injection vulnerability in action_audio.php that allows authenticated attackers to execute arbitrary operating system commands by passing an... NVD: Attackers can inject malicious OS commands through the pid request parameter to execute arbitrary commands with the privileges of the apache user.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-67608/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-67610/",
      "current_public_safe_latest": false,
      "cvss_score": 8.6,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.25103,
      "epss_score": 0.00326,
      "first_observed_at": "2026-08-10T16:12:24.021737+00:00",
      "id": "CVE-2026-67610",
      "impact_tags": [
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-10T16:12:24.021737+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: OpenEMR through 8.2.0 contains an improper authentication vulnerability in the OAuth2 dynamic client registration endpoint that allows unauthenticated attackers to register a malicious client with system-level FHIR scopes by supplying a self-generated RSA... NVD: Once an administrator approves the registered client, attackers can use the client_credentials grant with a self-signed JWT assertion to obtain access tokens granting read access to all FHIR resources across all patients in the system. OSV: OpenEMR 8.2.0 OAuth2 Dynamic Client Registration Unauthorized FHIR Access",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260810T162156Z/items/CVE-2026-67610.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes remote exposure · authenticated boundary. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: OpenEMR through 8.2.0 contains an improper authentication vulnerability in the OAuth2 dynamic client registration endpoint that allows unauthenticated attackers to register a malicious client with system-level FHIR scopes by supplying a self-generated RSA... NVD: Once an administrator approves the registered client, attackers can use the client_credentials grant with a self-signed JWT assertion to obtain access tokens granting read access to all FHIR resources across all patients in the system. OSV: OpenEMR 8.2.0 OAuth2 Dynamic Client Registration Unauthorized FHIR Access",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-67610/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-67616/",
      "current_public_safe_latest": false,
      "cvss_score": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.16753,
      "epss_score": 0.00253,
      "first_observed_at": "2026-08-10T22:01:27.436532+00:00",
      "id": "CVE-2026-67616",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-10T22:01:27.436532+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Camaleon CMS through 2.9.2, fixed in commit 88ab703, contains a missing authorization vulnerability on the drafts endpoint that allows any authenticated low-privileged user to create draft posts by bypassing role and permission checks. NVD: Attackers can send requests to the drafts endpoint using only session authentication to create unauthorized drafts that appear in the administrative drafts queue. OSV: Camaleon CMS 2.9.2 Missing Authorization via /admin/post_type drafts endpoint",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260810T220919Z/items/CVE-2026-67616.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: commit.",
      "source_published_summary": "NVD: Camaleon CMS through 2.9.2, fixed in commit 88ab703, contains a missing authorization vulnerability on the drafts endpoint that allows any authenticated low-privileged user to create draft posts by bypassing role and permission checks. NVD: Attackers can send requests to the drafts endpoint using only session authentication to create unauthorized drafts that appear in the administrative drafts queue. OSV: Camaleon CMS 2.9.2 Missing Authorization via /admin/post_type drafts endpoint",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-67616/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-67617/",
      "current_public_safe_latest": false,
      "cvss_score": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.05676,
      "epss_score": 0.00161,
      "first_observed_at": "2026-08-10T22:01:27.436532+00:00",
      "id": "CVE-2026-67617",
      "impact_tags": [
        "XSS risk",
        "authenticated boundary review",
        "user interaction review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-10T22:01:27.436532+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Microweber CMS through 2.0.20 contains a stored cross-site scripting vulnerability in the content tagging system that allows admin-authenticated attackers to inject arbitrary JavaScript by submitting malicious payloads via the tag_names parameter of the GET... NVD: Attackers can store malicious scripts that execute without user interaction for every visitor to the public blog page and within the admin post editor, enabling session riding through same-origin fetch requests using the CSRF token embedded in the page. OSV: Microweber CMS 2.0.20 Stored XSS via tag_names Parameter",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260810T220919Z/items/CVE-2026-67617.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes XSS risk · authenticated boundary · user interaction required. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk · authenticated boundary · user interaction required.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Microweber CMS through 2.0.20 contains a stored cross-site scripting vulnerability in the content tagging system that allows admin-authenticated attackers to inject arbitrary JavaScript by submitting malicious payloads via the tag_names parameter of the GET... NVD: Attackers can store malicious scripts that execute without user interaction for every visitor to the public blog page and within the admin post editor, enabling session riding through same-origin fetch requests using the CSRF token embedded in the page. OSV: Microweber CMS 2.0.20 Stored XSS via tag_names Parameter",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-67617/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-67855/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.21317,
      "epss_score": 0.0029,
      "first_observed_at": "2026-08-11T22:08:35.096641+00:00",
      "id": "CVE-2026-67855",
      "impact_tags": [
        "service availability review",
        "memory safety review",
        "remote exposure relevant"
      ],
      "kev": false,
      "last_observed_at": "2026-08-11T22:08:35.096641+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: open62541 contains a heap use-after-free in the GDS PushManagement certificate update workflow when UA_ENABLE_GDS_PUSHMANAGEMENT is enabled. NVD: This allows a remote attacker to cause a denial of service.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260811T221806Z/items/CVE-2026-67855.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes service availability risk · memory safety review · remote exposure. Possible impact: The affected service may become unavailable or unreliable.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: open62541 contains a heap use-after-free in the GDS PushManagement certificate update workflow when UA_ENABLE_GDS_PUSHMANAGEMENT is enabled. NVD: This allows a remote attacker to cause a denial of service.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-67855/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-67856/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.34925,
      "epss_score": 0.00422,
      "first_observed_at": "2026-08-11T22:08:35.096641+00:00",
      "id": "CVE-2026-67856",
      "impact_tags": [
        "service availability review",
        "remote exposure relevant"
      ],
      "kev": false,
      "last_observed_at": "2026-08-11T22:08:35.096641+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: An issue in open62541 v.1.5.5 and before allows a remote attacker to cause a denial of service via crafted CreateSubscription, CreateMonitoredItems(Sampling), Publish, TransferSubscriptions, and DeleteSubscriptions requests",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260811T221806Z/items/CVE-2026-67856.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes service availability risk · remote exposure. Possible impact: The affected service may become unavailable or unreliable.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: An issue in open62541 v.1.5.5 and before allows a remote attacker to cause a denial of service via crafted CreateSubscription, CreateMonitoredItems(Sampling), Publish, TransferSubscriptions, and DeleteSubscriptions requests",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-67856/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-67857/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.27826,
      "epss_score": 0.0035,
      "first_observed_at": "2026-08-11T22:08:35.096641+00:00",
      "id": "CVE-2026-67857",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-11T22:08:35.096641+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: open62541 1.5.5 contains an out-of-bounds read in the client-side function responseReadNamespacesArray() in src/client/ua_client_connect.c.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260811T221806Z/items/CVE-2026-67857.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: open62541 1.5.5 contains an out-of-bounds read in the client-side function responseReadNamespacesArray() in src/client/ua_client_connect.c.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-67857/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-67858/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.39453,
      "epss_score": 0.00487,
      "first_observed_at": "2026-08-11T22:08:35.096641+00:00",
      "id": "CVE-2026-67858",
      "impact_tags": [
        "service availability review",
        "memory safety review",
        "remote exposure relevant"
      ],
      "kev": false,
      "last_observed_at": "2026-08-11T22:08:35.096641+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Buffer Overflow vulnerability exists in open62541 1.5.5 when the Local Discovery Server (LDS) is built with multicast discovery enabled through the MDNSD backend. NVD: An unauthenticated remote attacker can send a RegisterServer or RegisterServer2 request containing many unique discoveryUrls. NVD: This allows remote attackers to cause a denial of service.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260811T221806Z/items/CVE-2026-67858.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes service availability risk · memory safety review · remote exposure. Possible impact: The affected service may become unavailable or unreliable.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Buffer Overflow vulnerability exists in open62541 1.5.5 when the Local Discovery Server (LDS) is built with multicast discovery enabled through the MDNSD backend. NVD: An unauthenticated remote attacker can send a RegisterServer or RegisterServer2 request containing many unique discoveryUrls. NVD: This allows remote attackers to cause a denial of service.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-67858/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-67859/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.38099,
      "epss_score": 0.00466,
      "first_observed_at": "2026-08-11T22:08:35.096641+00:00",
      "id": "CVE-2026-67859",
      "impact_tags": [
        "service availability review",
        "memory safety review",
        "remote exposure relevant"
      ],
      "kev": false,
      "last_observed_at": "2026-08-11T22:08:35.096641+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Buffer Overflow vulnerability in open62541 v1.5.5 allows a remote attacker to cause a denial of service via the Discovery/LDS handling.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260811T221806Z/items/CVE-2026-67859.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes service availability risk · memory safety review · remote exposure. Possible impact: The affected service may become unavailable or unreliable.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Buffer Overflow vulnerability in open62541 v1.5.5 allows a remote attacker to cause a denial of service via the Discovery/LDS handling.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-67859/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-67860/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.18692,
      "epss_score": 0.00267,
      "first_observed_at": "2026-08-11T22:08:35.096641+00:00",
      "id": "CVE-2026-67860",
      "impact_tags": [
        "memory safety review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-11T22:08:35.096641+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: open62541 1.5.5 contains a heap-based buffer overflow in the default HistoryRead path when the default history database is used with the memory backend.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260811T221806Z/items/CVE-2026-67860.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes memory safety review. Possible impact: The affected component has memory-safety risk that may lead to crash, privilege, or code-execution impact depending on exposure.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: open62541 1.5.5 contains a heap-based buffer overflow in the default HistoryRead path when the default history database is used with the memory backend.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-67860/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-67861/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.34511,
      "epss_score": 0.00417,
      "first_observed_at": "2026-08-11T22:08:35.096641+00:00",
      "id": "CVE-2026-67861",
      "impact_tags": [
        "service availability review",
        "remote exposure relevant"
      ],
      "kev": false,
      "last_observed_at": "2026-08-11T22:08:35.096641+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: An issue in open62541 v.1.5.5 and before allows a remote attacker to cause a denial of service via the UA_Client_getRemoteDataTypes component",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260811T221806Z/items/CVE-2026-67861.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes service availability risk · remote exposure. Possible impact: The affected service may become unavailable or unreliable.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: An issue in open62541 v.1.5.5 and before allows a remote attacker to cause a denial of service via the UA_Client_getRemoteDataTypes component",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-67861/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-67862/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.25865,
      "epss_score": 0.00332,
      "first_observed_at": "2026-08-11T22:08:35.096641+00:00",
      "id": "CVE-2026-67862",
      "impact_tags": [
        "service availability review",
        "remote exposure relevant"
      ],
      "kev": false,
      "last_observed_at": "2026-08-11T22:08:35.096641+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: open62541 1.5.5 contains a buffer-overflow in the high-level attribute reading logic in src/client/ua_client_highlevel.c. NVD: This allows a remote attacker to cause a denial of service.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260811T221806Z/items/CVE-2026-67862.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes service availability risk · remote exposure. Possible impact: The affected service may become unavailable or unreliable.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: open62541 1.5.5 contains a buffer-overflow in the high-level attribute reading logic in src/client/ua_client_highlevel.c. NVD: This allows a remote attacker to cause a denial of service.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-67862/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-67969/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.12682,
      "epss_score": 0.00221,
      "first_observed_at": "2026-08-10T22:01:27.436532+00:00",
      "id": "CVE-2026-67969",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-10T22:01:27.436532+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: An issue in the HS_MonitorApplications() component of NASA cFS v7.0.1 allows attackers to force the processor to reset via supplying a crafted HS.AppMon_Tbl entry.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260810T220919Z/items/CVE-2026-67969.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: An issue in the HS_MonitorApplications() component of NASA cFS v7.0.1 allows attackers to force the processor to reset via supplying a crafted HS.AppMon_Tbl entry.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-67969/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-67970/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.14077,
      "epss_score": 0.00232,
      "first_observed_at": "2026-08-10T22:01:27.436532+00:00",
      "id": "CVE-2026-67970",
      "impact_tags": [
        "path traversal review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-10T22:01:27.436532+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Incorrect access control in the DS_SetDestPathCmd() component of NASA cFS v7.0.1 allows attackers to access sensitive components via a path traversal.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260810T220919Z/items/CVE-2026-67970.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes path traversal review. Possible impact: An attacker may be able to reach files outside the intended application path.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Incorrect access control in the DS_SetDestPathCmd() component of NASA cFS v7.0.1 allows attackers to access sensitive components via a path traversal.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-67970/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-67973/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.20024,
      "epss_score": 0.00278,
      "first_observed_at": "2026-08-10T22:01:27.436532+00:00",
      "id": "CVE-2026-67973",
      "impact_tags": [
        "service availability review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-10T22:01:27.436532+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: An issue in the CFDP receive path of NASA cFS v7.0.1 allows attackers to cause a Denial of Service (DoS) via replaying final CFDP PDUs.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260810T220919Z/items/CVE-2026-67973.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes service availability risk. Possible impact: The affected service may become unavailable or unreliable.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: An issue in the CFDP receive path of NASA cFS v7.0.1 allows attackers to cause a Denial of Service (DoS) via replaying final CFDP PDUs.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-67973/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-67974/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.22335,
      "epss_score": 0.00301,
      "first_observed_at": "2026-08-10T22:01:27.436532+00:00",
      "id": "CVE-2026-67974",
      "impact_tags": [
        "service availability review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-10T22:01:27.436532+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A parser boundary flaw in the Software Bus Network (SBN) application's peer subscription message handling in NASA cFS v7.0.1 allows attackers to cause a Denial of Service (DoS) via sending a crafted packet.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260810T220919Z/items/CVE-2026-67974.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes service availability risk. Possible impact: The affected service may become unavailable or unreliable.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A parser boundary flaw in the Software Bus Network (SBN) application's peer subscription message handling in NASA cFS v7.0.1 allows attackers to cause a Denial of Service (DoS) via sending a crafted packet.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-67974/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-67975/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.11247,
      "epss_score": 0.0021,
      "first_observed_at": "2026-08-10T22:01:27.436532+00:00",
      "id": "CVE-2026-67975",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-10T22:01:27.436532+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Incorrect access control in NASA cFS v7.0.1 allows attackers to arbitrarily remove low-index subscriptions and add new streams via sending TO_LAB add/remove subscription commands.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260810T220919Z/items/CVE-2026-67975.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Incorrect access control in NASA cFS v7.0.1 allows attackers to arbitrarily remove low-index subscriptions and add new streams via sending TO_LAB add/remove subscription commands.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-67975/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-67977/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.20017,
      "epss_score": 0.00278,
      "first_observed_at": "2026-08-10T22:01:27.436532+00:00",
      "id": "CVE-2026-67977",
      "impact_tags": [
        "service availability review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-10T22:01:27.436532+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: An integer overflow in the Svc::FileDownlink::SendPartial component of fprime framework v4.2.2 allows attackers to cause a Denial of Service (DoS) via a crafted input.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260810T220919Z/items/CVE-2026-67977.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes service availability risk. Possible impact: The affected service may become unavailable or unreliable.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: An integer overflow in the Svc::FileDownlink::SendPartial component of fprime framework v4.2.2 allows attackers to cause a Denial of Service (DoS) via a crafted input.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-67977/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-6801/",
      "current_public_safe_latest": false,
      "cvss_score": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.14949,
      "epss_score": 0.00239,
      "first_observed_at": "2026-07-18T05:38:40.092323+00:00",
      "id": "CVE-2026-6801",
      "impact_tags": [
        "information exposure review",
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-18T07:15:27.585758+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Context Blog theme for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.3.5 via the context_blog_modal_popup. NVD: This makes it possible for unauthenticated attackers to extract the content of password-protected posts.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260718T071858Z/items/CVE-2026-6801.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes information exposure review · remote exposure · authenticated boundary. Possible impact: A remote attacker may be able to access information that should not be exposed.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Context Blog theme for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.3.5 via the context_blog_modal_popup. NVD: This makes it possible for unauthenticated attackers to extract the content of password-protected posts.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-6801/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-6803/",
      "current_public_safe_latest": false,
      "cvss_score": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.21638,
      "epss_score": 0.00297,
      "first_observed_at": "2026-07-18T05:13:28.850753+00:00",
      "id": "CVE-2026-6803",
      "impact_tags": [
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-18T05:13:28.850753+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The AI Chatbot & Workflow Automation by AIWU plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.4.12. NVD: This is due to missing capability checks and nonce verification on AJAX actions registered under both wp_ajax_ and wp_ajax_nopriv_ hooks, as the base controller's getPermissions() returns an empty array and neither removeGroup nor clear are added to... NVD: This makes it possible for unauthenticated attackers to delete specific records by ID or delete all records from any module's database table by unauthenticated attackers.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260718T051545Z/items/CVE-2026-6803.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes remote exposure · authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The AI Chatbot & Workflow Automation by AIWU plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.4.12. NVD: This is due to missing capability checks and nonce verification on AJAX actions registered under both wp_ajax_ and wp_ajax_nopriv_ hooks, as the base controller's getPermissions() returns an empty array and neither removeGroup nor clear are added to... NVD: This makes it possible for unauthenticated attackers to delete specific records by ID or delete all records from any module's database table by unauthenticated attackers.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-6803/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-6804/",
      "current_public_safe_latest": false,
      "cvss_score": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.27617,
      "epss_score": 0.00353,
      "first_observed_at": "2026-07-18T05:13:28.850753+00:00",
      "id": "CVE-2026-6804",
      "impact_tags": [
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-18T05:13:28.850753+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The AI Chatbot & Workflow Automation by AIWU plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.4.12. NVD: This is due to the plugin not properly verifying that a user is authorized to perform an action. NVD: This makes it possible for unauthenticated attackers to publish draft WordPress posts, exposing unpublished content, or unpublish live content, causing service disruption, by supplying arbitrary scenario IDs.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260718T051545Z/items/CVE-2026-6804.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes remote exposure · authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The AI Chatbot & Workflow Automation by AIWU plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.4.12. NVD: This is due to the plugin not properly verifying that a user is authorized to perform an action. NVD: This makes it possible for unauthenticated attackers to publish draft WordPress posts, exposing unpublished content, or unpublish live content, causing service disruption, by supplying arbitrary scenario IDs.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-6804/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "apache / qpid_broker-j",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-68060/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.39222,
      "epss_score": 0.00483,
      "first_observed_at": "2026-08-12T05:08:50.991993+00:00",
      "id": "CVE-2026-68060",
      "impact_tags": [
        "service availability review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-12T05:08:50.991993+00:00",
      "latest_item_url": null,
      "product": "qpid_broker-j",
      "public_safe_summary": "NVD: A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service. NVD: This issue affects Apache Qpid Broker-J: through 10.0.1. NVD: Users are recommended to upgrade to version 10.1.0, which fixes the issue.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260812T051428Z/items/CVE-2026-68060.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: apache / qpid_broker-j",
      "source_published_impact": "Source describes service availability risk. Possible impact: The affected service may become unavailable or unreliable.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service. NVD: This issue affects Apache Qpid Broker-J: through 10.0.1. NVD: Users are recommended to upgrade to version 10.1.0, which fixes the issue.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-68060/timeline.json",
      "vendor": "apache"
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-6818/",
      "current_public_safe_latest": false,
      "cvss_score": 7.2,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.1457,
      "epss_score": 0.00236,
      "first_observed_at": "2026-07-15T11:03:27.604769+00:00",
      "id": "CVE-2026-6818",
      "impact_tags": [
        "XSS risk",
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-15T11:03:27.604769+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'special_requests' parameter in all versions up to, and including, 1.8.8 due to insufficient input sanitization and output escaping. NVD: This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260715T110622Z/items/CVE-2026-6818.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes XSS risk · remote exposure · authenticated boundary. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk · remote exposure · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'special_requests' parameter in all versions up to, and including, 1.8.8 due to insufficient input sanitization and output escaping. NVD: This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-6818/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-6820/",
      "current_public_safe_latest": false,
      "cvss_score": 7.2,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.13624,
      "epss_score": 0.00229,
      "first_observed_at": "2026-07-15T11:03:27.604769+00:00",
      "id": "CVE-2026-6820",
      "impact_tags": [
        "XSS risk",
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-15T11:03:27.604769+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'email' parameter in all versions up to, and including, 1.8.8 due to insufficient input sanitization and output escaping. NVD: This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260715T110622Z/items/CVE-2026-6820.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes XSS risk · remote exposure · authenticated boundary. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk · remote exposure · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'email' parameter in all versions up to, and including, 1.8.8 due to insufficient input sanitization and output escaping. NVD: This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-6820/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-6847/",
      "current_public_safe_latest": false,
      "cvss_score": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.44025,
      "epss_score": 0.00584,
      "first_observed_at": "2026-07-20T11:59:42.107493+00:00",
      "id": "CVE-2026-6847",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-20T11:59:42.107493+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Remote Code Execution vulnerability exists in ThemisNETPanel due to missing authentication for a critical file upload function. NVD: This issue has been fixed by a patch released in April 2026.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260720T120206Z/items/CVE-2026-6847.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Remote Code Execution vulnerability exists in ThemisNETPanel due to missing authentication for a critical file upload function. NVD: This issue has been fixed by a patch released in April 2026.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-6847/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-6851/",
      "current_public_safe_latest": false,
      "cvss_score": 7.0,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.0227,
      "epss_score": 0.00121,
      "first_observed_at": "2026-07-21T06:08:28.817138+00:00",
      "id": "CVE-2026-6851",
      "impact_tags": [
        "local exposure relevant"
      ],
      "kev": false,
      "last_observed_at": "2026-07-21T06:08:28.817138+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: An Improper link resolution before file access ('link following') vulnerability in the File Shredder module as used in Bitdefender Total Security and Internet Security on Windows allows a less-privileged local user to elevate rights by leveraging a race... NVD: This issue affects Total Security: before 27.0.58.315; Internet Security: before 27.0.58.315.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260721T061518Z/items/CVE-2026-6851.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes local exposure. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for local exposure.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: An Improper link resolution before file access ('link following') vulnerability in the File Shredder module as used in Bitdefender Total Security and Internet Security on Windows allows a less-privileged local user to elevate rights by leveraging a race... NVD: This issue affects Total Security: before 27.0.58.315; Internet Security: before 27.0.58.315.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-6851/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-6854/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.19145,
      "epss_score": 0.00273,
      "first_observed_at": "2026-07-15T11:03:27.604769+00:00",
      "id": "CVE-2026-6854",
      "impact_tags": [
        "information exposure review",
        "SQL injection risk",
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-15T11:03:27.604769+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The My Calendar – Accessible Event Manager plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'mc_auth' parameter in all versions up to, and including, 3.7.8 due to insufficient escaping on the user supplied parameter and lack of... NVD: This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260715T110622Z/items/CVE-2026-6854.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes information exposure review · SQL injection risk · remote exposure. Possible impact: A remote attacker may be able to read or change database-backed application data.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The My Calendar – Accessible Event Manager plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'mc_auth' parameter in all versions up to, and including, 3.7.8 due to insufficient escaping on the user supplied parameter and lack of... NVD: This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-6854/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-68578/",
      "current_public_safe_latest": false,
      "cvss_score": 7.7,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.1179,
      "epss_score": 0.00214,
      "first_observed_at": "2026-08-09T09:59:30.349754+00:00",
      "id": "CVE-2026-68578",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-09T09:59:30.349754+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: ArcadeDB versions before 26.7.3 fail to bind the authenticated principal in the MCP HTTP transport, causing all engine permission checks to silently pass as no-ops. NVD: Non-root MCP-allowed users can perform arbitrary database writes, DDL, schema mutations, and execute arbitrary JavaScript code via the query tool.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260809T101323Z/items/CVE-2026-68578.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: ArcadeDB versions before 26.7.3 fail to bind the authenticated principal in the MCP HTTP transport, causing all engine permission checks to silently pass as no-ops. NVD: Non-root MCP-allowed users can perform arbitrary database writes, DDL, schema mutations, and execute arbitrary JavaScript code via the query tool.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-68578/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-68579/",
      "current_public_safe_latest": false,
      "cvss_score": 8.7,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.18791,
      "epss_score": 0.00269,
      "first_observed_at": "2026-08-09T09:59:30.349754+00:00",
      "id": "CVE-2026-68579",
      "impact_tags": [
        "memory safety review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-09T09:59:30.349754+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: FreeRDP before 3.30.0 (<= 3.29.0) contains a heap-based buffer overflow in the Windows clipboard client's CliprdrStream_Read function (client/Windows/wf_cliprdr.c). NVD: When an OLE paste consumer (e.g. NVD: explorer.exe) calls IStream::Read with a fixed-size buffer of cb bytes, CliprdrStream_Read requests file contents from the RDP server and then copies the response into the caller's buffer using the server-supplied length (req_fsize) instead of cb.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260809T101323Z/items/CVE-2026-68579.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes memory safety review. Possible impact: The affected component has memory-safety risk that may lead to crash, privilege, or code-execution impact depending on exposure.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: FreeRDP before 3.30.0 (<= 3.29.0) contains a heap-based buffer overflow in the Windows clipboard client's CliprdrStream_Read function (client/Windows/wf_cliprdr.c). NVD: When an OLE paste consumer (e.g. NVD: explorer.exe) calls IStream::Read with a fixed-size buffer of cb bytes, CliprdrStream_Read requests file contents from the RDP server and then copies the response into the caller's buffer using the server-supplied length (req_fsize) instead of cb.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-68579/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-68580/",
      "current_public_safe_latest": false,
      "cvss_score": 7.7,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.14802,
      "epss_score": 0.00238,
      "first_observed_at": "2026-08-09T09:59:30.349754+00:00",
      "id": "CVE-2026-68580",
      "impact_tags": [
        "service availability review",
        "memory safety review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-09T09:59:30.349754+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: FreeRDP before 3.29.0 contains integer overflow vulnerabilities in the audio input redirection channel (audin) across ALSA, sndio, WinMM, and OpenSL ES backends that fail to validate the FramesPerPacket parameter from RDP servers. NVD: Attackers can supply a malicious FramesPerPacket value causing allocation size wraparound, resulting in heap-based buffer overflow on ALSA or denial of service on all platforms. OSV: FreeRDP before 3.29.0 Integer Overflow via Audio Input Channel",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260809T101323Z/items/CVE-2026-68580.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes service availability risk · memory safety review. Possible impact: The affected service may become unavailable or unreliable.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: FreeRDP before 3.29.0 contains integer overflow vulnerabilities in the audio input redirection channel (audin) across ALSA, sndio, WinMM, and OpenSL ES backends that fail to validate the FramesPerPacket parameter from RDP servers. NVD: Attackers can supply a malicious FramesPerPacket value causing allocation size wraparound, resulting in heap-based buffer overflow on ALSA or denial of service on all platforms. OSV: FreeRDP before 3.29.0 Integer Overflow via Audio Input Channel",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-68580/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-68581/",
      "current_public_safe_latest": false,
      "cvss_score": 8.6,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.24561,
      "epss_score": 0.00321,
      "first_observed_at": "2026-08-09T09:59:30.349754+00:00",
      "id": "CVE-2026-68581",
      "impact_tags": [
        "authentication boundary review",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-09T09:59:30.349754+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Vikunja versions 0.22.0 through 2.3.0 fail to validate the principal type in API token management. NVD: Because user IDs and link-share IDs are independent numeric sequences and both resolve through a generic web.Auth.GetID() interface, a link-share JWT whose numeric ID equals a target user's ID is treated as that user by the /api/v1/tokens endpoints. NVD: An authenticated attacker can obtain a target's numeric user ID via authenticated user search, then create link shares on an attacker-writable project until the link-share sequence reaches that value, and use the resulting link-share JWT to list, create, and...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260809T101323Z/items/CVE-2026-68581.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes authentication boundary review · authenticated boundary. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authentication boundary review · authenticated boundary.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: Vikunja versions 0.22.0 through 2.3.0 fail to validate the principal type in API token management. NVD: Because user IDs and link-share IDs are independent numeric sequences and both resolve through a generic web.Auth.GetID() interface, a link-share JWT whose numeric ID equals a target user's ID is treated as that user by the /api/v1/tokens endpoints. NVD: An authenticated attacker can obtain a target's numeric user ID via authenticated user search, then create link shares on an attacker-writable project until the link-share sequence reaches that value, and use the resulting link-share JWT to list, create, and...",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-68581/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-68582/",
      "current_public_safe_latest": false,
      "cvss_score": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.11369,
      "epss_score": 0.00211,
      "first_observed_at": "2026-08-09T09:59:30.349754+00:00",
      "id": "CVE-2026-68582",
      "impact_tags": [
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-09T09:59:30.349754+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Vikunja versions >= 0.24.0 and <= 2.3.0 contain a broken object level authorization (BOLA) vulnerability in the task-collection endpoint (GET /api/v1/projects/{project}/views/{view}/tasks). NVD: The endpoint loads the requested project view from the URL path without verifying the caller is authorized for it. NVD: For a link-share token holder, the task scope is pinned to the share's own project, but the view is taken from the attacker-controlled path and never re-validated.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260809T101323Z/items/CVE-2026-68582.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes authenticated boundary. Possible impact: This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: 2.4.0..",
      "source_published_summary": "NVD: Vikunja versions >= 0.24.0 and <= 2.3.0 contain a broken object level authorization (BOLA) vulnerability in the task-collection endpoint (GET /api/v1/projects/{project}/views/{view}/tasks). NVD: The endpoint loads the requested project view from the URL path without verifying the caller is authorized for it. NVD: For a link-share token holder, the task scope is pinned to the share's own project, but the view is taken from the attacker-controlled path and never re-validated.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-68582/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-68583/",
      "current_public_safe_latest": false,
      "cvss_score": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.03629,
      "epss_score": 0.00138,
      "first_observed_at": "2026-08-09T09:59:30.349754+00:00",
      "id": "CVE-2026-68583",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-09T09:59:30.349754+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: luci-app-adblock-fast before 1.2.4-4 contains a stored cross-site scripting vulnerability in the blocklist name field that allows lower-privileged users to inject active HTML.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260809T101323Z/items/CVE-2026-68583.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: luci-app-adblock-fast before 1.2.4-4 contains a stored cross-site scripting vulnerability in the blocklist name field that allows lower-privileged users to inject active HTML.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-68583/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-68584/",
      "current_public_safe_latest": false,
      "cvss_score": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.23466,
      "epss_score": 0.00311,
      "first_observed_at": "2026-08-10T10:38:36.347227+00:00",
      "id": "CVE-2026-68584",
      "impact_tags": [
        "authentication boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-10T10:38:36.347227+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: SiYuan versions before v3.7.3 contain an authentication bypass vulnerability in publish mode where content-returning endpoints getHeadingChildrenDOM, getHeading*Transaction, and getBacklinkDoc perform no password check despite protecting the primary getDoc... NVD: Anonymous attackers can retrieve full content of password-protected documents by obtaining internal block IDs from reader-accessible endpoints and calling unprotected content endpoints to bypass the password gate. OSV: SiYuan before v3.7.3 Authentication Bypass via Content Endpoints",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260810T105121Z/items/CVE-2026-68584.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes authentication boundary review. Possible impact: This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authentication boundary review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: SiYuan versions before v3.7.3 contain an authentication bypass vulnerability in publish mode where content-returning endpoints getHeadingChildrenDOM, getHeading*Transaction, and getBacklinkDoc perform no password check despite protecting the primary getDoc... NVD: Anonymous attackers can retrieve full content of password-protected documents by obtaining internal block IDs from reader-accessible endpoints and calling unprotected content endpoints to bypass the password gate. OSV: SiYuan before v3.7.3 Authentication Bypass via Content Endpoints",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-68584/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-68585/",
      "current_public_safe_latest": false,
      "cvss_score": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.09309,
      "epss_score": 0.00194,
      "first_observed_at": "2026-08-10T10:38:36.347227+00:00",
      "id": "CVE-2026-68585",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-10T10:38:36.347227+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: SiYuan versions before v3.7.3 contain a metadata disclosure vulnerability in the /api/block/getBlockInfo endpoint that returns document root metadata including title for publish-forbidden documents without publish-access checks. NVD: Anonymous readers or publish RoleReader tokens can supply a block ID to retrieve the title, notebook, path, root ID, and icon of documents administrators marked as excluded from publishing. OSV: SiYuan before v3.7.3 Metadata Disclosure via getBlockInfo",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260810T105121Z/items/CVE-2026-68585.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: SiYuan versions before v3.7.3 contain a metadata disclosure vulnerability in the /api/block/getBlockInfo endpoint that returns document root metadata including title for publish-forbidden documents without publish-access checks. NVD: Anonymous readers or publish RoleReader tokens can supply a block ID to retrieve the title, notebook, path, root ID, and icon of documents administrators marked as excluded from publishing. OSV: SiYuan before v3.7.3 Metadata Disclosure via getBlockInfo",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-68585/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-68586/",
      "current_public_safe_latest": false,
      "cvss_score": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.1525,
      "epss_score": 0.00241,
      "first_observed_at": "2026-08-10T10:38:36.347227+00:00",
      "id": "CVE-2026-68586",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-10T10:38:36.347227+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: SiYuan before v3.7.3 fails to apply publish-access filters to the getBacklinkDoc and getBackmentionDoc content endpoints (/api/ref/getBacklinkDoc and /api/ref/getBackmentionDoc). NVD: While the corresponding backlink list endpoints filter publish-forbidden documents, the content endpoints (gated only by CheckAuth) do not. NVD: A publish-mode reader — including an anonymous reader when publish Basic Auth is disabled — can call these endpoints directly with a publish-forbidden document's ID to retrieve its rendered DOM content and to determine whether the document references a given...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260810T105121Z/items/CVE-2026-68586.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: SiYuan before v3.7.3 fails to apply publish-access filters to the getBacklinkDoc and getBackmentionDoc content endpoints (/api/ref/getBacklinkDoc and /api/ref/getBackmentionDoc). NVD: While the corresponding backlink list endpoints filter publish-forbidden documents, the content endpoints (gated only by CheckAuth) do not. NVD: A publish-mode reader — including an anonymous reader when publish Basic Auth is disabled — can call these endpoints directly with a publish-forbidden document's ID to retrieve its rendered DOM content and to determine whether the document references a given...",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-68586/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-68587/",
      "current_public_safe_latest": false,
      "cvss_score": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.15771,
      "epss_score": 0.00245,
      "first_observed_at": "2026-08-10T10:38:36.347227+00:00",
      "id": "CVE-2026-68587",
      "impact_tags": [
        "information exposure review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-10T10:38:36.347227+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: SiYuan versions before v3.7.3 contain an information disclosure vulnerability in the getHeadingDeleteTransaction, getHeadingLevelTransaction, and getHeadingInsertTransaction endpoints that return rendered block DOM without publish-access checks. NVD: Anonymous readers or publish RoleReader tokens can supply a heading block ID to read full rendered content of publish-disabled documents that should be restricted. OSV: SiYuan before v3.7.3 Information Disclosure via getHeading*Transaction",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260810T105121Z/items/CVE-2026-68587.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes information exposure review. Possible impact: An attacker may be able to access information that should not be exposed.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: SiYuan versions before v3.7.3 contain an information disclosure vulnerability in the getHeadingDeleteTransaction, getHeadingLevelTransaction, and getHeadingInsertTransaction endpoints that return rendered block DOM without publish-access checks. NVD: Anonymous readers or publish RoleReader tokens can supply a heading block ID to read full rendered content of publish-disabled documents that should be restricted. OSV: SiYuan before v3.7.3 Information Disclosure via getHeading*Transaction",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-68587/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-68744/",
      "current_public_safe_latest": false,
      "cvss_score": 3.3,
      "cvss_severity": "LOW",
      "epss_percentile": 0.0086,
      "epss_score": 0.00097,
      "first_observed_at": "2026-08-11T04:43:10.985977+00:00",
      "id": "CVE-2026-68744",
      "impact_tags": [
        "local exposure relevant"
      ],
      "kev": false,
      "last_observed_at": "2026-08-11T04:43:10.985977+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A flaw was found in SSSD. NVD: The sss_nss_protocol_fill_initgr() function in the NSS responder pre-allocates reply space for all group entries but does not shrink the packet when groups are skipped, causing uninitialized heap bytes to be transmitted to the client. NVD: A local attacker can exploit this to disclose cached directory data and heap layout information from the sssd_nss process.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260811T044729Z/items/CVE-2026-68744.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes local exposure. Possible impact: This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for local exposure.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A flaw was found in SSSD. NVD: The sss_nss_protocol_fill_initgr() function in the NSS responder pre-allocates reply space for all group entries but does not shrink the packet when groups are skipped, causing uninitialized heap bytes to be transmitted to the client. NVD: A local attacker can exploit this to disclose cached directory data and heap layout information from the sssd_nss process.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-68744/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-68771/",
      "current_public_safe_latest": false,
      "cvss_score": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.46565,
      "epss_score": 0.00623,
      "first_observed_at": "2026-08-07T21:58:42.606809+00:00",
      "id": "CVE-2026-68771",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-07T21:58:42.606809+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: ComfyUI v0.23.0 contains an unsafe deserialization vulnerability in the LoadTrainingDataset node that allows unauthenticated remote attackers to execute arbitrary Python code by uploading a crafted pickle file and triggering its deserialization. OSV: ComfyUI 0.23.0 Unauthenticated RCE via LoadTrainingDataset Pickle Deserialization OSV: ComfyUI v0.23.0 contains an unsafe deserialization vulnerability in the LoadTrainingDataset node that allows unauthenticated remote attackers to execute arbitrary Python code by uploading a crafted pickle file and triggering its deserialization.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260807T220457Z/items/CVE-2026-68771.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: ComfyUI v0.23.0 contains an unsafe deserialization vulnerability in the LoadTrainingDataset node that allows unauthenticated remote attackers to execute arbitrary Python code by uploading a crafted pickle file and triggering its deserialization. OSV: ComfyUI 0.23.0 Unauthenticated RCE via LoadTrainingDataset Pickle Deserialization OSV: ComfyUI v0.23.0 contains an unsafe deserialization vulnerability in the LoadTrainingDataset node that allows unauthenticated remote attackers to execute arbitrary Python code by uploading a crafted pickle file and triggering its deserialization.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-68771/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-69083/",
      "current_public_safe_latest": false,
      "cvss_score": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.27732,
      "epss_score": 0.0035,
      "first_observed_at": "2026-08-10T10:38:36.347227+00:00",
      "id": "CVE-2026-69083",
      "impact_tags": [
        "SQL injection risk",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-10T10:38:36.347227+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: SiYuan versions before v3.7.3 contain SQL injection vulnerabilities in the fullTextSearchAssetContent endpoint reachable by unauthenticated users and publish RoleReader tokens. NVD: Attackers can execute arbitrary SQL on the read-write asset-content database via unescaped method parameters and REGEXP clauses to read, modify, or delete cross-notebook data. OSV: SiYuan before v3.7.3 SQL Injection via fullTextSearchAssetContent",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260810T105121Z/items/CVE-2026-69083.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes SQL injection risk · authenticated boundary. Possible impact: An attacker may be able to read or change database-backed application data.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: SiYuan versions before v3.7.3 contain SQL injection vulnerabilities in the fullTextSearchAssetContent endpoint reachable by unauthenticated users and publish RoleReader tokens. NVD: Attackers can execute arbitrary SQL on the read-write asset-content database via unescaped method parameters and REGEXP clauses to read, modify, or delete cross-notebook data. OSV: SiYuan before v3.7.3 SQL Injection via fullTextSearchAssetContent",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-69083/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-69084/",
      "current_public_safe_latest": false,
      "cvss_score": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.21207,
      "epss_score": 0.0029,
      "first_observed_at": "2026-08-10T10:38:36.347227+00:00",
      "id": "CVE-2026-69084",
      "impact_tags": [
        "SQL injection risk"
      ],
      "kev": false,
      "last_observed_at": "2026-08-10T10:38:36.347227+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: SiYuan versions <= v3.7.2 expose the /api/search/searchEmbedBlock endpoint, which passes a client-supplied SQL statement verbatim to the main read-write siyuan.db handle with no single-statement, read-only, or admin restrictions. NVD: The endpoint is gated only by CheckAuth, making it reachable by the publish RoleReader token and by anonymous users when publish authentication is disabled. NVD: Because the underlying driver executes stacked statements, an attacker can read and modify content across all opened cleartext notebooks (encrypted per-box notebooks are excluded).",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260810T105121Z/items/CVE-2026-69084.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes SQL injection risk. Possible impact: An attacker may be able to read or change database-backed application data.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: v3.7.3..",
      "source_published_summary": "NVD: SiYuan versions <= v3.7.2 expose the /api/search/searchEmbedBlock endpoint, which passes a client-supplied SQL statement verbatim to the main read-write siyuan.db handle with no single-statement, read-only, or admin restrictions. NVD: The endpoint is gated only by CheckAuth, making it reachable by the publish RoleReader token and by anonymous users when publish authentication is disabled. NVD: Because the underlying driver executes stacked statements, an attacker can read and modify content across all opened cleartext notebooks (encrypted per-box notebooks are excluded).",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-69084/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-69247/",
      "current_public_safe_latest": false,
      "cvss_score": 8.2,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.07204,
      "epss_score": 0.00175,
      "first_observed_at": "2026-08-10T22:01:27.436532+00:00",
      "id": "CVE-2026-69247",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-10T22:01:27.436532+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. NVD: From 44.0.0 until 50.0.0, pkcs7_decrypt_der, pkcs7_decrypt_pem, and pkcs7_decrypt_smime reported the outcome of decrypting a RecipientInfo's encryptedKey in several distinguishable ways, one of which disclosed the exact length recovered from the RSA operation. NVD: The same distinction was also observable by timing.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260810T220919Z/items/CVE-2026-69247.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: 50.0.0..",
      "source_published_summary": "NVD: cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. NVD: From 44.0.0 until 50.0.0, pkcs7_decrypt_der, pkcs7_decrypt_pem, and pkcs7_decrypt_smime reported the outcome of decrypting a RecipientInfo's encryptedKey in several distinguishable ways, one of which disclosed the exact length recovered from the RSA operation. NVD: The same distinction was also observable by timing.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-69247/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-69248/",
      "current_public_safe_latest": false,
      "cvss_score": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.08254,
      "epss_score": 0.00185,
      "first_observed_at": "2026-08-10T22:01:27.436532+00:00",
      "id": "CVE-2026-69248",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-10T22:01:27.436532+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. NVD: Prior to 49.0.0, if an intermediate constrained CA permits the DNS name foo.example.com, and the leaf certificate has a wildcard in its DNS SAN of *.example.com, python-cryptography's verifier accepts which allows escaping outside of the permitted names. NVD: The core issue is in DNSConstraint::matches, where a wildcard pattern was treated as matching a more-specific permitted constraint even though *.example.com can expand to sibling names such as bar.example.com outside foo.example.com.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260810T220919Z/items/CVE-2026-69248.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: 49.0.0..",
      "source_published_summary": "NVD: cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. NVD: Prior to 49.0.0, if an intermediate constrained CA permits the DNS name foo.example.com, and the leaf certificate has a wildcard in its DNS SAN of *.example.com, python-cryptography's verifier accepts which allows escaping outside of the permitted names. NVD: The core issue is in DNSConstraint::matches, where a wildcard pattern was treated as matching a more-specific permitted constraint even though *.example.com can expand to sibling names such as bar.example.com outside foo.example.com.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-69248/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-69249/",
      "current_public_safe_latest": false,
      "cvss_score": 8.7,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.09067,
      "epss_score": 0.00192,
      "first_observed_at": "2026-08-10T22:01:27.436532+00:00",
      "id": "CVE-2026-69249",
      "impact_tags": [
        "service availability review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-10T22:01:27.436532+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: python-cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. NVD: Prior to 49.0.0, when resolving invalid certificate chains that include duplicate copies of self-signed certificates, the processing recursively invokes the same candidate, leading to an exponential blowup. NVD: Although the limitation that the chain depth cannot exceed a specified maximum depth prevents unbounded recursion and guarantees termination, an attacker-controlled certificate chain can lead the processing to easily take more than 5s to reject in testing.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260810T220919Z/items/CVE-2026-69249.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes service availability risk. Possible impact: The affected service may become unavailable or unreliable.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: 49.0.0..",
      "source_published_summary": "NVD: python-cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. NVD: Prior to 49.0.0, when resolving invalid certificate chains that include duplicate copies of self-signed certificates, the processing recursively invokes the same candidate, leading to an exponential blowup. NVD: Although the limitation that the chain depth cannot exceed a specified maximum depth prevents unbounded recursion and guarantees termination, an attacker-controlled certificate chain can lead the processing to easily take more than 5s to reject in testing.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-69249/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-6939/",
      "current_public_safe_latest": false,
      "cvss_score": 7.2,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.24492,
      "epss_score": 0.00324,
      "first_observed_at": "2026-07-18T05:38:40.092323+00:00",
      "id": "CVE-2026-6939",
      "impact_tags": [
        "XSS risk",
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-18T07:15:27.585758+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The CorvusPay WooCommerce Payment Gateway plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'approval_code' parameter in all versions up to, and including, 2.7.4 due to insufficient input sanitization and output escaping. NVD: This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. NVD: The unauthenticated REST endpoint POST /wp-json/corvuspay/success/ is registered with permission_callback set to __return_true, and although a signature validation step exists it only logs the result without halting execution, meaning an attacker can supply a...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260718T071858Z/items/CVE-2026-6939.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes XSS risk · remote exposure · authenticated boundary. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk · remote exposure · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The CorvusPay WooCommerce Payment Gateway plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'approval_code' parameter in all versions up to, and including, 2.7.4 due to insufficient input sanitization and output escaping. NVD: This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. NVD: The unauthenticated REST endpoint POST /wp-json/corvuspay/success/ is registered with permission_callback set to __return_true, and although a signature validation step exists it only logs the result without halting execution, meaning an attacker can supply a...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-6939/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-6952/",
      "current_public_safe_latest": false,
      "cvss_score": 7.2,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.57594,
      "epss_score": 0.0095,
      "first_observed_at": "2026-07-27T22:30:18.664011+00:00",
      "id": "CVE-2026-6952",
      "impact_tags": [
        "command injection risk",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-27T22:30:18.664011+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A post-authentication command injection vulnerability in the \"LogServer\" field of the syslog component in Zyxel AX7501-B1 firmware versions through 5.17(ABPC.7.2)C0 could allow an authenticated attacker with administrator privileges to execute OS commands on...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260727T223632Z/items/CVE-2026-6952.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes command injection risk · authenticated boundary. Possible impact: An attacker may be able to run unintended system commands through the affected component.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A post-authentication command injection vulnerability in the \"LogServer\" field of the syslog component in Zyxel AX7501-B1 firmware versions through 5.17(ABPC.7.2)C0 could allow an authenticated attacker with administrator privileges to execute OS commands on...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-6952/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-70589/",
      "current_public_safe_latest": false,
      "cvss_score": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.06787,
      "epss_score": 0.00171,
      "first_observed_at": "2026-08-11T22:08:35.096641+00:00",
      "id": "CVE-2026-70589",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-11T22:08:35.096641+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Ghost is a Node.js content management system. NVD: From 4.22.0 until 6.54.1, a missing validation check allowed users to redeem subscription offers that were no longer active. NVD: This issue is fixed in version 6.54.1.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260811T221806Z/items/CVE-2026-70589.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: Ghost is a Node.js content management system. NVD: From 4.22.0 until 6.54.1, a missing validation check allowed users to redeem subscription offers that were no longer active. NVD: This issue is fixed in version 6.54.1.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-70589/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-70590/",
      "current_public_safe_latest": false,
      "cvss_score": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.09396,
      "epss_score": 0.00195,
      "first_observed_at": "2026-08-11T22:08:35.096641+00:00",
      "id": "CVE-2026-70590",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-11T22:08:35.096641+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Ghost is a Node.js content management system. NVD: Prior to 6.54.1, any staff-level user was able to leak the hashed passwords of other staff users through the Ghost Admin API. NVD: An offline password-guessing attack against the hashes could lead to account takeover if successful, but Device Verification should have prevented an attacker from logging in with a recovered password.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260811T221806Z/items/CVE-2026-70590.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: Ghost is a Node.js content management system. NVD: Prior to 6.54.1, any staff-level user was able to leak the hashed passwords of other staff users through the Ghost Admin API. NVD: An offline password-guessing attack against the hashes could lead to account takeover if successful, but Device Verification should have prevented an attacker from logging in with a recovered password.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-70590/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-70591/",
      "current_public_safe_latest": false,
      "cvss_score": 4.1,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.13395,
      "epss_score": 0.00226,
      "first_observed_at": "2026-08-11T22:08:35.096641+00:00",
      "id": "CVE-2026-70591",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-11T22:08:35.096641+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Ghost is a Node.js content management system. NVD: From 0.10.0 until 6.54.1, a Server-Side Request Forgery in Ghost Admin image fetching allowed any staff-level user to perform a blind HTTP GET request against internal hosts. NVD: No output was returned, but this could have been used to probe open ports on internal hosts.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260811T221806Z/items/CVE-2026-70591.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: Ghost is a Node.js content management system. NVD: From 0.10.0 until 6.54.1, a Server-Side Request Forgery in Ghost Admin image fetching allowed any staff-level user to perform a blind HTTP GET request against internal hosts. NVD: No output was returned, but this could have been used to probe open ports on internal hosts.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-70591/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-70592/",
      "current_public_safe_latest": false,
      "cvss_score": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.22179,
      "epss_score": 0.00298,
      "first_observed_at": "2026-08-11T22:08:35.096641+00:00",
      "id": "CVE-2026-70592",
      "impact_tags": [
        "path traversal review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-11T22:08:35.096641+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Ghost is a Node.js content management system. NVD: From 1.20.1 until 6.54.1, an Administrator-level user could remotely overwrite certain files on the filesystem through the database backup filename, leading to integrity and availability issues. NVD: The database export endpoint failed to reject path separators in the caller-supplied filename.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260811T221806Z/items/CVE-2026-70592.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes path traversal review. Possible impact: An attacker may be able to reach files outside the intended application path.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: Ghost is a Node.js content management system. NVD: From 1.20.1 until 6.54.1, an Administrator-level user could remotely overwrite certain files on the filesystem through the database backup filename, leading to integrity and availability issues. NVD: The database export endpoint failed to reject path separators in the caller-supplied filename.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-70592/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-71231/",
      "current_public_safe_latest": true,
      "cvss_score": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.28595,
      "epss_score": 0.00358,
      "first_observed_at": "2026-08-12T10:29:37.194110+00:00",
      "id": "CVE-2026-71231",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-12T10:29:37.194110+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-71231.json",
      "product": null,
      "public_safe_summary": "NVD: IOTSmartHome's gui/login.php checkCookie function builds an authentication query as SELECT * FROM users WHERE ID='<decoded lastLogin cookie>' after base64-decoding the client-supplied lastLogin cookie via safe_decode, which performs URL-safe base64 decoding...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260812T103932Z/items/CVE-2026-71231.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: IOTSmartHome's gui/login.php checkCookie function builds an authentication query as SELECT * FROM users WHERE ID='<decoded lastLogin cookie>' after base64-decoding the client-supplied lastLogin cookie via safe_decode, which performs URL-safe base64 decoding...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-71231/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-71232/",
      "current_public_safe_latest": true,
      "cvss_score": 7.2,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.22368,
      "epss_score": 0.003,
      "first_observed_at": "2026-08-12T10:29:37.194110+00:00",
      "id": "CVE-2026-71232",
      "impact_tags": [
        "code execution review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-12T10:29:37.194110+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-71232.json",
      "product": null,
      "public_safe_summary": "NVD: MacCMS10's admin template editor (application/admin/controller/Template.php) blocks dangerous PHP functions in template content via a blacklist regex, but the blacklist omitted exec, passthru, popen, show_source, create_function, register_shutdown_function... OSV: MacCMS10 - Incomplete Function Blacklist in Template Editor Enables Authenticated RCE OSV: MacCMS10's admin template editor (application/admin/controller/Template.php) blocks dangerous PHP functions in template content via a blacklist regex, but the blacklist omitted exec, passthru, popen, show_source, create_function, register_shutdown_function...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260812T103932Z/items/CVE-2026-71232.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes code execution review. Possible impact: An attacker may be able to run code or commands on affected systems.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: MacCMS10's admin template editor (application/admin/controller/Template.php) blocks dangerous PHP functions in template content via a blacklist regex, but the blacklist omitted exec, passthru, popen, show_source, create_function, register_shutdown_function... OSV: MacCMS10 - Incomplete Function Blacklist in Template Editor Enables Authenticated RCE OSV: MacCMS10's admin template editor (application/admin/controller/Template.php) blocks dangerous PHP functions in template content via a blacklist regex, but the blacklist omitted exec, passthru, popen, show_source, create_function, register_shutdown_function...",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-71232/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-71233/",
      "current_public_safe_latest": true,
      "cvss_score": 8.7,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.0994,
      "epss_score": 0.00199,
      "first_observed_at": "2026-08-12T10:29:37.194110+00:00",
      "id": "CVE-2026-71233",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-12T10:29:37.194110+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-71233.json",
      "product": null,
      "public_safe_summary": "NVD: InvoiceNinja v5-stable renders an invoice or quote's \"terms\" field in the client portal using Laravel Blade's raw output directive {!! NVD: ->terms !!} (resources/views/portal/ninja2020/invoices/includes/terms.blade.php) with no HTML sanitization.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260812T103932Z/items/CVE-2026-71233.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: InvoiceNinja v5-stable renders an invoice or quote's \"terms\" field in the client portal using Laravel Blade's raw output directive {!! NVD: ->terms !!} (resources/views/portal/ninja2020/invoices/includes/terms.blade.php) with no HTML sanitization.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-71233/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-71234/",
      "current_public_safe_latest": true,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.15873,
      "epss_score": 0.00245,
      "first_observed_at": "2026-08-12T10:29:37.194110+00:00",
      "id": "CVE-2026-71234",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-12T10:29:37.194110+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-71234.json",
      "product": null,
      "public_safe_summary": "NVD: Documize Community's attachment download route (domain/attachment/endpoint.go, Download function, registered via AddPublic with no auth middleware) accepts a query parameter and grants access whenever the parameter is simply non-empty (len(secureToken) > 0)...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260812T103932Z/items/CVE-2026-71234.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Documize Community's attachment download route (domain/attachment/endpoint.go, Download function, registered via AddPublic with no auth middleware) accepts a query parameter and grants access whenever the parameter is simply non-empty (len(secureToken) > 0)...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-71234/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-71235/",
      "current_public_safe_latest": true,
      "cvss_score": 8.8,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.21126,
      "epss_score": 0.00288,
      "first_observed_at": "2026-08-12T10:29:37.194110+00:00",
      "id": "CVE-2026-71235",
      "impact_tags": [
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-12T10:29:37.194110+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-71235.json",
      "product": null,
      "public_safe_summary": "NVD: Magistrala's Rules Engine allows authenticated users to create rules with embedded Go or Lua scripts executed server-side when IoT messages arrive. NVD: The Lua script engine (re/lua.go) performs no input validation at all and preloads dangerous libraries: db (arbitrary database access), ioutil (file I/O), an HTTP client (SSRF), and filepath (traversal).",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260812T103932Z/items/CVE-2026-71235.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes authenticated boundary. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Magistrala's Rules Engine allows authenticated users to create rules with embedded Go or Lua scripts executed server-side when IoT messages arrive. NVD: The Lua script engine (re/lua.go) performs no input validation at all and preloads dangerous libraries: db (arbitrary database access), ioutil (file I/O), an HTTP client (SSRF), and filepath (traversal).",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-71235/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-71236/",
      "current_public_safe_latest": true,
      "cvss_score": 8.7,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.0994,
      "epss_score": 0.00199,
      "first_observed_at": "2026-08-12T10:29:37.194110+00:00",
      "id": "CVE-2026-71236",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-12T10:29:37.194110+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-71236.json",
      "product": null,
      "public_safe_summary": "NVD: Grocy's API request-body parser (controllers/Api/BaseApiController.php, GetParsedAndFilteredRequestBody) purifies incoming field values with HTMLPurifier, then manually reverses HTML-entity encoding of the resulting output by replacing &amp;lt;, &amp;gt;, and...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260812T103932Z/items/CVE-2026-71236.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Grocy's API request-body parser (controllers/Api/BaseApiController.php, GetParsedAndFilteredRequestBody) purifies incoming field values with HTMLPurifier, then manually reverses HTML-entity encoding of the resulting output by replacing &amp;lt;, &amp;gt;, and...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-71236/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-71237/",
      "current_public_safe_latest": true,
      "cvss_score": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.34766,
      "epss_score": 0.0042,
      "first_observed_at": "2026-08-12T10:29:37.194110+00:00",
      "id": "CVE-2026-71237",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-12T10:29:37.194110+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-71237.json",
      "product": null,
      "public_safe_summary": "NVD: Miantang/IoT-PHP's index.php implements a POST /userlogin route that reads the password directly from ['pwd'] with no sanitization and concatenates it into a raw SQL string: mysql_query(\"select * from userlists where username='' and password='' limit 1\").",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260812T103932Z/items/CVE-2026-71237.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Miantang/IoT-PHP's index.php implements a POST /userlogin route that reads the password directly from ['pwd'] with no sanitization and concatenates it into a raw SQL string: mysql_query(\"select * from userlists where username='' and password='' limit 1\").",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-71237/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-71238/",
      "current_public_safe_latest": true,
      "cvss_score": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.23765,
      "epss_score": 0.00313,
      "first_observed_at": "2026-08-12T10:29:37.194110+00:00",
      "id": "CVE-2026-71238",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-12T10:29:37.194110+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-71238.json",
      "product": null,
      "public_safe_summary": "NVD: DjangoCRM ships with its Django SECRET_KEY hardcoded directly in the committed webcrm/settings.py rather than read from an environment variable. NVD: Since this key is used for session signing, CSRF token generation, and password reset tokens, anyone who reads the public repository can forge valid session cookies (including for the superadmin account), forge CSRF tokens, and forge password reset tokens...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260812T103932Z/items/CVE-2026-71238.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: DjangoCRM ships with its Django SECRET_KEY hardcoded directly in the committed webcrm/settings.py rather than read from an environment variable. NVD: Since this key is used for session signing, CSRF token generation, and password reset tokens, anyone who reads the public repository can forge valid session cookies (including for the superadmin account), forge CSRF tokens, and forge password reset tokens...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-71238/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-71239/",
      "current_public_safe_latest": true,
      "cvss_score": 8.1,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.13231,
      "epss_score": 0.00225,
      "first_observed_at": "2026-08-12T10:29:37.194110+00:00",
      "id": "CVE-2026-71239",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-12T10:29:37.194110+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-71239.json",
      "product": null,
      "public_safe_summary": "NVD: DjangoCRM's massmail module renders user-controlled EmlMessage fields (subject, content) through Django's Template constructor with no sanitization, in at least three locations: message_previews.py builds an f-string embedding message.subject/message.content...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260812T103932Z/items/CVE-2026-71239.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: DjangoCRM's massmail module renders user-controlled EmlMessage fields (subject, content) through Django's Template constructor with no sanitization, in at least three locations: message_previews.py builds an f-string embedding message.subject/message.content...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-71239/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-71240/",
      "current_public_safe_latest": true,
      "cvss_score": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.08769,
      "epss_score": 0.00189,
      "first_observed_at": "2026-08-12T10:29:37.194110+00:00",
      "id": "CVE-2026-71240",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-12T10:29:37.194110+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-71240.json",
      "product": null,
      "public_safe_summary": "NVD: DjangoCRM's toggle_default_sorting view is the only route in common/urls.py that is not wrapped in login_required or staff_member_required, and it redirects to a caller-supplied next_url GET parameter after only checking secure_url(next_url), which merely...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260812T103932Z/items/CVE-2026-71240.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: DjangoCRM's toggle_default_sorting view is the only route in common/urls.py that is not wrapped in login_required or staff_member_required, and it redirects to a caller-supplied next_url GET parameter after only checking secure_url(next_url), which merely...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-71240/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-71241/",
      "current_public_safe_latest": true,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.20477,
      "epss_score": 0.00282,
      "first_observed_at": "2026-08-12T10:29:37.194110+00:00",
      "id": "CVE-2026-71241",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-12T10:29:37.194110+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-71241.json",
      "product": null,
      "public_safe_summary": "NVD: Book-Management-System's Flask API endpoints /student, /record, /books, /find_stu_book, and /find_not_return_book are missing the @login_required decorator that protects sibling routes (/search_student, /storage) in the same file. NVD: Because card_id values are sequential integers, the entire student database can be enumerated without authentication.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260812T103932Z/items/CVE-2026-71241.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Book-Management-System's Flask API endpoints /student, /record, /books, /find_stu_book, and /find_not_return_book are missing the @login_required decorator that protects sibling routes (/search_student, /storage) in the same file. NVD: Because card_id values are sequential integers, the entire student database can be enumerated without authentication.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-71241/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-71242/",
      "current_public_safe_latest": true,
      "cvss_score": 8.3,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.12013,
      "epss_score": 0.00215,
      "first_observed_at": "2026-08-12T10:29:37.194110+00:00",
      "id": "CVE-2026-71242",
      "impact_tags": [
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-12T10:29:37.194110+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-71242.json",
      "product": null,
      "public_safe_summary": "NVD: Crater's NotePolicy checks only a blanket Bouncer ability (manage-all-notes / view-all-notes) with no company-ownership comparison, unlike InvoicePolicy and other sibling policies which additionally verify ->hasCompany(->company_id). NVD: Any authenticated user of one company can read, edit, or delete another company's notes by ID. OSV: Crater - Cross-Company IDOR on Notes via Missing Company-Ownership Check in NotePolicy",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260812T103932Z/items/CVE-2026-71242.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes authenticated boundary. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Crater's NotePolicy checks only a blanket Bouncer ability (manage-all-notes / view-all-notes) with no company-ownership comparison, unlike InvoicePolicy and other sibling policies which additionally verify ->hasCompany(->company_id). NVD: Any authenticated user of one company can read, edit, or delete another company's notes by ID. OSV: Crater - Cross-Company IDOR on Notes via Missing Company-Ownership Check in NotePolicy",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-71242/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-71243/",
      "current_public_safe_latest": true,
      "cvss_score": 8.8,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.21081,
      "epss_score": 0.00288,
      "first_observed_at": "2026-08-12T10:29:37.194110+00:00",
      "id": "CVE-2026-71243",
      "impact_tags": [
        "command injection risk"
      ],
      "kev": false,
      "last_observed_at": "2026-08-12T10:29:37.194110+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-71243.json",
      "product": null,
      "public_safe_summary": "NVD: The backmeup npm package assembles shell command strings by directly concatenating its option values (name, source, destination, filter) - e.g. NVD: cmd = \"mkdir -p \" + path.join(info.destination, info.name) + \"; \" - and executes the resulting string through a shell via ssh2-exec (locally via child_process, or remotely via SSH when an ssh handle is supplied), rather than using execFile/spawn with an... OSV: backmeup (npm) - OS Command Injection via Backup Option Values",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260812T103932Z/items/CVE-2026-71243.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes command injection risk. Possible impact: An attacker may be able to run unintended system commands through the affected component.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The backmeup npm package assembles shell command strings by directly concatenating its option values (name, source, destination, filter) - e.g. NVD: cmd = \"mkdir -p \" + path.join(info.destination, info.name) + \"; \" - and executes the resulting string through a shell via ssh2-exec (locally via child_process, or remotely via SSH when an ssh handle is supplied), rather than using execFile/spawn with an... OSV: backmeup (npm) - OS Command Injection via Backup Option Values",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-71243/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-71244/",
      "current_public_safe_latest": true,
      "cvss_score": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.10156,
      "epss_score": 0.00201,
      "first_observed_at": "2026-08-12T10:29:37.194110+00:00",
      "id": "CVE-2026-71244",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-12T10:29:37.194110+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-71244.json",
      "product": null,
      "public_safe_summary": "NVD: Paperless-ngx's MailAccountViewSet.test action, when called with an existing account's ID and a masked password field, reuses the stored password, account_type, refresh_token, and expiration from that existing account while allowing the caller to supply a...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260812T103932Z/items/CVE-2026-71244.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Paperless-ngx's MailAccountViewSet.test action, when called with an existing account's ID and a masked password field, reuses the stored password, account_type, refresh_token, and expiration from that existing account while allowing the caller to supply a...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-71244/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-7189/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.15778,
      "epss_score": 0.00245,
      "first_observed_at": "2026-07-24T11:14:35.780564+00:00",
      "id": "CVE-2026-7189",
      "impact_tags": [
        "information exposure review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-24T11:14:35.780564+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Insertion of sensitive information into sent data vulnerability in Proliz Software Ltd. NVD: Co. NVD: Proliz's OBS allows Accessing Functionality Not Properly Constrained by ACLs.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260724T111724Z/items/CVE-2026-7189.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes information exposure review. Possible impact: An attacker may be able to access information that should not be exposed.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Insertion of sensitive information into sent data vulnerability in Proliz Software Ltd. NVD: Co. NVD: Proliz's OBS allows Accessing Functionality Not Properly Constrained by ACLs.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-7189/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-7232/",
      "current_public_safe_latest": false,
      "cvss_score": 7.2,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.10907,
      "epss_score": 0.00206,
      "first_observed_at": "2026-07-30T06:01:44.452906+00:00",
      "id": "CVE-2026-7232",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-30T06:01:44.452906+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The FormCraft plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '[parameter name]' parameter in all versions up to, and including, 3.9.14 due to insufficient input sanitization and output escaping. NVD: This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. NVD: The exploit chain combines a server-side gap — where composite matrix sub-field keys such as field2_0 and field2_1 are never passed through the sanitization loop and are stored raw via $wpdb->insert() — with a client-side gap where DOMPurify is only invoked...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260730T060504Z/items/CVE-2026-7232.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The FormCraft plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '[parameter name]' parameter in all versions up to, and including, 3.9.14 due to insufficient input sanitization and output escaping. NVD: This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. NVD: The exploit chain combines a server-side gap — where composite matrix sub-field keys such as field2_0 and field2_1 are never passed through the sanitization loop and are stored raw via $wpdb->insert() — with a client-side gap where DOMPurify is only invoked...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-7232/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "php / php",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-7260/",
      "current_public_safe_latest": false,
      "cvss_score": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.06438,
      "epss_score": 0.00168,
      "first_observed_at": "2026-08-06T11:35:20.545945+00:00",
      "id": "CVE-2026-7260",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-06T11:35:20.545945+00:00",
      "latest_item_url": null,
      "product": "php",
      "public_safe_summary": "NVD: Circular symbolic links in phar archives could lead to unbounded recursion, exhausting the C stack and crashing the PHP process, in PHP versions from 8.2.* before 8.2.33, from 8.3.* before 8.3.33, from 8.4.* before 8.4.24, and from 8.5.* before 8.5.9.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260806T114533Z/items/CVE-2026-7260.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: php / php",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Circular symbolic links in phar archives could lead to unbounded recursion, exhausting the C stack and crashing the PHP process, in PHP versions from 8.2.* before 8.2.33, from 8.3.* before 8.3.33, from 8.4.* before 8.4.24, and from 8.5.* before 8.5.9.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-7260/timeline.json",
      "vendor": "php"
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-7328/",
      "current_public_safe_latest": false,
      "cvss_score": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.0059,
      "epss_score": 0.00091,
      "first_observed_at": "2026-07-29T16:40:34.107276+00:00",
      "id": "CVE-2026-7328",
      "impact_tags": [
        "service availability review",
        "local exposure relevant"
      ],
      "kev": false,
      "last_observed_at": "2026-07-29T16:40:34.107276+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Missing authorization in Caliptra Core Runtime Firmware (INVOKE_DPE_MLDSA87, CM_AES_GCM_DECRYPT_DMA, EXTERNAL_MAILBOX_CMD commands) in subsystem mode allows a privileged local attacker to cause a denial of service via mailbox commands containing unverified... NVD: The security impact beyond availability is integration-specific. NVD: This issue affects Core Runtime Firmware: 2.1.0.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260729T164826Z/items/CVE-2026-7328.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes service availability risk · local exposure. Possible impact: The affected service may become unavailable or unreliable.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Missing authorization in Caliptra Core Runtime Firmware (INVOKE_DPE_MLDSA87, CM_AES_GCM_DECRYPT_DMA, EXTERNAL_MAILBOX_CMD commands) in subsystem mode allows a privileged local attacker to cause a denial of service via mailbox commands containing unverified... NVD: The security impact beyond availability is integration-specific. NVD: This issue affects Core Runtime Firmware: 2.1.0.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-7328/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-7380/",
      "current_public_safe_latest": false,
      "cvss_score": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.04501,
      "epss_score": 0.00149,
      "first_observed_at": "2026-07-14T05:42:23.241208+00:00",
      "id": "CVE-2026-7380",
      "impact_tags": [
        "XSS risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-14T05:42:23.241208+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in Armiya Information Technologies Ltd. NVD: Co. NVD: Access Control System (GKS) allows XSS Targeting HTML Attributes.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260714T054512Z/items/CVE-2026-7380.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes XSS risk. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in Armiya Information Technologies Ltd. NVD: Co. NVD: Access Control System (GKS) allows XSS Targeting HTML Attributes.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-7380/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-7484/",
      "current_public_safe_latest": false,
      "cvss_score": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.09785,
      "epss_score": 0.00197,
      "first_observed_at": "2026-07-31T11:36:05.167842+00:00",
      "id": "CVE-2026-7484",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-31T11:36:05.167842+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: External control of Assumed-Immutable web parameter vulnerability in ABIS Technology Ltd. NVD: Co. NVD: AVESİS allows Accessing Functionality Not Properly Constrained by ACLs.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260731T115001Z/items/CVE-2026-7484.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: External control of Assumed-Immutable web parameter vulnerability in ABIS Technology Ltd. NVD: Co. NVD: AVESİS allows Accessing Functionality Not Properly Constrained by ACLs.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-7484/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-7534/",
      "current_public_safe_latest": false,
      "cvss_score": 7.2,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.08964,
      "epss_score": 0.0019,
      "first_observed_at": "2026-07-30T06:01:44.452906+00:00",
      "id": "CVE-2026-7534",
      "impact_tags": [
        "XSS risk",
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-30T06:01:44.452906+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The SUMO Reward Points plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting via the REST API endpoint /wp-json/wc-srp/v1/earning in versions up to, and including, 32.7.0. NVD: This is due to the user_has_cap filter in the SRP_REST_Earning_Controller class unconditionally granting the custom rs_earning_read capability to all users — including unauthenticated visitors — combined with missing sanitization of the reason parameter in... NVD: This makes it possible for unauthenticated attackers to inject arbitrary web scripts into the reward points log that will execute whenever an administrator accesses the Master Log or User Reward Points admin pages.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260730T060504Z/items/CVE-2026-7534.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes XSS risk · remote exposure · authenticated boundary. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk · remote exposure · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The SUMO Reward Points plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting via the REST API endpoint /wp-json/wc-srp/v1/earning in versions up to, and including, 32.7.0. NVD: This is due to the user_has_cap filter in the SRP_REST_Earning_Controller class unconditionally granting the custom rs_earning_read capability to all users — including unauthenticated visitors — combined with missing sanitization of the reason parameter in... NVD: This makes it possible for unauthenticated attackers to inject arbitrary web scripts into the reward points log that will execute whenever an administrator accesses the Master Log or User Reward Points admin pages.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-7534/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-7559/",
      "current_public_safe_latest": false,
      "cvss_score": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.22367,
      "epss_score": 0.00304,
      "first_observed_at": "2026-07-18T05:13:28.850753+00:00",
      "id": "CVE-2026-7559",
      "impact_tags": [
        "unauthorized access risk",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-18T05:13:28.850753+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Affilia – Affiliate Program & Referral Tracking for WordPress plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 3.3.3. NVD: This is due to the plugin not properly verifying that a user is authorized to perform an action. NVD: This makes it possible for authenticated attackers, with subscriber-level access and above, to approve or reject affiliate referrals, credit commissions to affiliate wallets, delete referral records, and modify custom banner plugin options, enabling financial...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260718T051545Z/items/CVE-2026-7559.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes unauthorized access risk · authenticated boundary. Possible impact: An attacker may access resources that should require stronger authorization.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Affilia – Affiliate Program & Referral Tracking for WordPress plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 3.3.3. NVD: This is due to the plugin not properly verifying that a user is authorized to perform an action. NVD: This makes it possible for authenticated attackers, with subscriber-level access and above, to approve or reject affiliate referrals, credit commissions to affiliate wallets, delete referral records, and modify custom banner plugin options, enabling financial...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-7559/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-7620/",
      "current_public_safe_latest": false,
      "cvss_score": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.19151,
      "epss_score": 0.00272,
      "first_observed_at": "2026-07-18T05:13:28.850753+00:00",
      "id": "CVE-2026-7620",
      "impact_tags": [
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-18T05:13:28.850753+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Notification for Telegram plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.5.1. NVD: This is due to the plugin not properly verifying that a user is authorized to perform an action. NVD: This makes it possible for authenticated attackers, with subscriber-level access and above, to create, modify, or reschedule the nftb_cron_hook WordPress cron event, enabling unauthorized manipulation of the plugin's background task scheduling logic.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260718T051545Z/items/CVE-2026-7620.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Notification for Telegram plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.5.1. NVD: This is due to the plugin not properly verifying that a user is authorized to perform an action. NVD: This makes it possible for authenticated attackers, with subscriber-level access and above, to create, modify, or reschedule the nftb_cron_hook WordPress cron event, enabling unauthorized manipulation of the plugin's background task scheduling logic.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-7620/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-7655/",
      "current_public_safe_latest": false,
      "cvss_score": 8.1,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.222,
      "epss_score": 0.00302,
      "first_observed_at": "2026-07-18T05:13:28.850753+00:00",
      "id": "CVE-2026-7655",
      "impact_tags": [
        "privilege boundary review",
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-18T05:38:40.092323+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The SureCart plugin for WordPress is vulnerable to privilege escalation via account takeover in versions up to, and including, 4.2.3. NVD: This is due to the plugin not properly validating a user's identity prior to updating their details like email during customer profile synchronization from webhook events. NVD: This makes it possible for unauthenticated attackers to change linked user's email addresses, including administrators if the administrator account is linked to a SureCart customer record, and leverage that to reset the user's password and gain access to...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260718T054021Z/items/CVE-2026-7655.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes privilege escalation risk · remote exposure · authenticated boundary. Possible impact: A remote attacker may cross a privilege boundary and gain more access than intended.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The SureCart plugin for WordPress is vulnerable to privilege escalation via account takeover in versions up to, and including, 4.2.3. NVD: This is due to the plugin not properly validating a user's identity prior to updating their details like email during customer profile synchronization from webhook events. NVD: This makes it possible for unauthenticated attackers to change linked user's email addresses, including administrators if the administrator account is linked to a SureCart customer record, and leverage that to reset the user's password and gain access to...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-7655/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-8075/",
      "current_public_safe_latest": false,
      "cvss_score": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.14462,
      "epss_score": 0.00235,
      "first_observed_at": "2026-07-24T06:06:41.160911+00:00",
      "id": "CVE-2026-8075",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-24T11:14:35.780564+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Mattermost Desktop App versions <=6.2 5.5.13 6.0.2.0 fail to properly null check when checking for headers in the Mattermost Desktop App which allows any user to crash another channel members Desktop App via posting a malicious link with an embedded image... NVD: Mattermost Advisory ID: MMSA-2026-00668",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260724T111724Z/items/CVE-2026-8075.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Mattermost Desktop App versions <=6.2 5.5.13 6.0.2.0 fail to properly null check when checking for headers in the Mattermost Desktop App which allows any user to crash another channel members Desktop App via posting a malicious link with an embedded image... NVD: Mattermost Advisory ID: MMSA-2026-00668",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-8075/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-8082/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.17892,
      "epss_score": 0.00262,
      "first_observed_at": "2026-07-28T06:05:50.269125+00:00",
      "id": "CVE-2026-8082",
      "impact_tags": [
        "SQL injection risk",
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-28T06:05:50.269125+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The bpost-shipping-platform WordPress plugin before 3.2.3 does not properly sanitize a parameter before using it in a SQL query during WooCommerce order submission, allowing unauthenticated attackers to perform time-based blind SQL injection on stores running...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260728T060840Z/items/CVE-2026-8082.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes SQL injection risk · remote exposure · authenticated boundary. Possible impact: A remote attacker may be able to read or change database-backed application data.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The bpost-shipping-platform WordPress plugin before 3.2.3 does not properly sanitize a parameter before using it in a SQL query during WooCommerce order submission, allowing unauthenticated attackers to perform time-based blind SQL injection on stores running...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-8082/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "rockwellautomation / arena",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-8085/",
      "current_public_safe_latest": false,
      "cvss_score": 7.0,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.07723,
      "epss_score": 0.0018,
      "first_observed_at": "2026-07-21T11:20:19.325173+00:00",
      "id": "CVE-2026-8085",
      "impact_tags": [
        "code execution review",
        "memory safety review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-21T11:20:19.325173+00:00",
      "latest_item_url": null,
      "product": "arena",
      "public_safe_summary": "NVD: A security issue exists within Arena® Simulation due to a memory corruption vulnerability in the model.exe (Siman) component. NVD: The vulnerability stems from improper validation of user-supplied data, which can result in an out-of-bounds write. NVD: An attacker could leverage this vulnerability to execute arbitrary code in the context of the current process by convincing a user to open a malicious file.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260721T112231Z/items/CVE-2026-8085.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: rockwellautomation / arena",
      "source_published_impact": "Source describes code execution review · memory safety review. Possible impact: An attacker may be able to run code or commands on affected systems.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A security issue exists within Arena® Simulation due to a memory corruption vulnerability in the model.exe (Siman) component. NVD: The vulnerability stems from improper validation of user-supplied data, which can result in an out-of-bounds write. NVD: An attacker could leverage this vulnerability to execute arbitrary code in the context of the current process by convincing a user to open a malicious file.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-8085/timeline.json",
      "vendor": "rockwellautomation"
    },
    {
      "affected_label": "haxx / curl",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-8286/",
      "current_public_safe_latest": false,
      "cvss_score": 8.1,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.40458,
      "epss_score": 0.0052,
      "first_observed_at": "2026-07-10T06:57:55.339390+00:00",
      "id": "CVE-2026-8286",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-10T06:57:55.339390+00:00",
      "latest_item_url": null,
      "product": "curl",
      "public_safe_summary": "NVD: A vulnerability exists where a new transfer that uses STARTTLS to upgrade the connection might reuse an existing live connection even though the TLS configuration mismatches so it should not. OSV: wrong STARTTLS connection reuse OSV: A vulnerability exists where a new transfer that uses STARTTLS to upgrade the connection might reuse an existing live connection even though the TLS configuration mismatches so it should not.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260710T070012Z/items/CVE-2026-8286.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: haxx / curl",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability exists where a new transfer that uses STARTTLS to upgrade the connection might reuse an existing live connection even though the TLS configuration mismatches so it should not. OSV: wrong STARTTLS connection reuse OSV: A vulnerability exists where a new transfer that uses STARTTLS to upgrade the connection might reuse an existing live connection even though the TLS configuration mismatches so it should not.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-8286/timeline.json",
      "vendor": "haxx"
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-8306/",
      "current_public_safe_latest": false,
      "cvss_score": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.04503,
      "epss_score": 0.00149,
      "first_observed_at": "2026-07-14T05:42:23.241208+00:00",
      "id": "CVE-2026-8306",
      "impact_tags": [
        "XSS risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-14T05:42:23.241208+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Armiya Information Technologies Ltd. NVD: Co. NVD: Access Control System (GKS) allows Stored XSS.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260714T054512Z/items/CVE-2026-8306.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes XSS risk. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Armiya Information Technologies Ltd. NVD: Co. NVD: Access Control System (GKS) allows Stored XSS.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-8306/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-8307/",
      "current_public_safe_latest": false,
      "cvss_score": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.1806,
      "epss_score": 0.00266,
      "first_observed_at": "2026-07-15T11:03:27.604769+00:00",
      "id": "CVE-2026-8307",
      "impact_tags": [
        "SQL injection risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-15T11:03:27.604769+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Webbeyaz Web Design Mediküm Web allows SQL Injection. NVD: This issue affects Mediküm Web: through 08072026. NVD: NOTE: The vendor was contacted and it was learned that the product is not supported.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260715T110622Z/items/CVE-2026-8307.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes SQL injection risk. Possible impact: An attacker may be able to read or change database-backed application data.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Webbeyaz Web Design Mediküm Web allows SQL Injection. NVD: This issue affects Mediküm Web: through 08072026. NVD: NOTE: The vendor was contacted and it was learned that the product is not supported.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-8307/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-8309/",
      "current_public_safe_latest": false,
      "cvss_score": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.03185,
      "epss_score": 0.00133,
      "first_observed_at": "2026-07-14T05:42:23.241208+00:00",
      "id": "CVE-2026-8309",
      "impact_tags": [
        "XSS risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-14T05:42:23.241208+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Armiya Information Technologies Ltd. NVD: Co. NVD: Access Control System (GKS) allows Reflected XSS.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260714T054512Z/items/CVE-2026-8309.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes XSS risk. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Armiya Information Technologies Ltd. NVD: Co. NVD: Access Control System (GKS) allows Reflected XSS.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-8309/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-8310/",
      "current_public_safe_latest": false,
      "cvss_score": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.04504,
      "epss_score": 0.00149,
      "first_observed_at": "2026-07-15T11:03:27.604769+00:00",
      "id": "CVE-2026-8310",
      "impact_tags": [
        "XSS risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-15T11:03:27.604769+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Webbeyaz Web Design Mediküm Web allows Reflected XSS. NVD: This issue affects Mediküm Web: through 08072026. NVD: NOTE: The vendor was contacted and it was learned that the product is not supported.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260715T110622Z/items/CVE-2026-8310.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes XSS risk. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Webbeyaz Web Design Mediküm Web allows Reflected XSS. NVD: This issue affects Mediküm Web: through 08072026. NVD: NOTE: The vendor was contacted and it was learned that the product is not supported.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-8310/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "rockwellautomation / arena",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-8312/",
      "current_public_safe_latest": false,
      "cvss_score": 7.0,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.07723,
      "epss_score": 0.0018,
      "first_observed_at": "2026-07-21T11:20:19.325173+00:00",
      "id": "CVE-2026-8312",
      "impact_tags": [
        "code execution review",
        "memory safety review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-21T11:20:19.325173+00:00",
      "latest_item_url": null,
      "product": "arena",
      "public_safe_summary": "NVD: A security issue exists within Arena® Simulation due to a memory corruption vulnerability in the expmt.exe (Siman) component. NVD: The vulnerability stems from improper validation of user-supplied data, which can result in an out-of-bounds write. NVD: An attacker could leverage this vulnerability to execute arbitrary code in the context of the current process by convincing a user to open a malicious file.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260721T112231Z/items/CVE-2026-8312.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: rockwellautomation / arena",
      "source_published_impact": "Source describes code execution review · memory safety review. Possible impact: An attacker may be able to run code or commands on affected systems.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A security issue exists within Arena® Simulation due to a memory corruption vulnerability in the expmt.exe (Siman) component. NVD: The vulnerability stems from improper validation of user-supplied data, which can result in an out-of-bounds write. NVD: An attacker could leverage this vulnerability to execute arbitrary code in the context of the current process by convincing a user to open a malicious file.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-8312/timeline.json",
      "vendor": "rockwellautomation"
    },
    {
      "affected_label": "rockwellautomation / arena",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-8313/",
      "current_public_safe_latest": false,
      "cvss_score": 7.0,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.07723,
      "epss_score": 0.0018,
      "first_observed_at": "2026-07-21T11:20:19.325173+00:00",
      "id": "CVE-2026-8313",
      "impact_tags": [
        "code execution review",
        "memory safety review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-21T11:20:19.325173+00:00",
      "latest_item_url": null,
      "product": "arena",
      "public_safe_summary": "NVD: A security issue exists within Arena® Simulation due to a memory corruption vulnerability in the linker.exe (Siman) component. NVD: The vulnerability stems from improper validation of user-supplied data, which can result in an out-of-bounds write. NVD: An attacker could leverage this vulnerability to execute arbitrary code in the context of the current process by convincing a user to open a malicious file.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260721T112231Z/items/CVE-2026-8313.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: rockwellautomation / arena",
      "source_published_impact": "Source describes code execution review · memory safety review. Possible impact: An attacker may be able to run code or commands on affected systems.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A security issue exists within Arena® Simulation due to a memory corruption vulnerability in the linker.exe (Siman) component. NVD: The vulnerability stems from improper validation of user-supplied data, which can result in an out-of-bounds write. NVD: An attacker could leverage this vulnerability to execute arbitrary code in the context of the current process by convincing a user to open a malicious file.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-8313/timeline.json",
      "vendor": "rockwellautomation"
    },
    {
      "affected_label": "rockwellautomation / arena",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-8314/",
      "current_public_safe_latest": false,
      "cvss_score": 7.0,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.07724,
      "epss_score": 0.0018,
      "first_observed_at": "2026-07-21T11:20:19.325173+00:00",
      "id": "CVE-2026-8314",
      "impact_tags": [
        "code execution review",
        "memory safety review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-21T11:20:19.325173+00:00",
      "latest_item_url": null,
      "product": "arena",
      "public_safe_summary": "NVD: A security issue exists within Arena® Simulation due to a memory corruption vulnerability in the siman.exe (Siman) component. NVD: The vulnerability stems from improper validation of user-supplied data, which can result in an out-of-bounds write. NVD: An attacker could leverage this vulnerability to execute arbitrary code in the context of the current process by convincing a user to open a malicious file.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260721T112231Z/items/CVE-2026-8314.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: rockwellautomation / arena",
      "source_published_impact": "Source describes code execution review · memory safety review. Possible impact: An attacker may be able to run code or commands on affected systems.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A security issue exists within Arena® Simulation due to a memory corruption vulnerability in the siman.exe (Siman) component. NVD: The vulnerability stems from improper validation of user-supplied data, which can result in an out-of-bounds write. NVD: An attacker could leverage this vulnerability to execute arbitrary code in the context of the current process by convincing a user to open a malicious file.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-8314/timeline.json",
      "vendor": "rockwellautomation"
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-8338/",
      "current_public_safe_latest": false,
      "cvss_score": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.22216,
      "epss_score": 0.003,
      "first_observed_at": "2026-08-05T16:55:08.588478+00:00",
      "id": "CVE-2026-8338",
      "impact_tags": [
        "authentication boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-05T16:55:08.588478+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A Spring Security authentication and authorization bypass exists in Coverity Connect versions between 2023.6.0 and 2026.3.0. NVD: An unauthenticated malicious threat actor that can send a specially crafted HTTP request is able to bypass authentication and authorization controls on certain API endpoints to access data within Coverity.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260805T165944Z/items/CVE-2026-8338.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes authentication boundary review. Possible impact: This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authentication boundary review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A Spring Security authentication and authorization bypass exists in Coverity Connect versions between 2023.6.0 and 2026.3.0. NVD: An unauthenticated malicious threat actor that can send a specially crafted HTTP request is able to bypass authentication and authorization controls on certain API endpoints to access data within Coverity.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-8338/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-8339/",
      "current_public_safe_latest": false,
      "cvss_score": 8.7,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.10466,
      "epss_score": 0.00203,
      "first_observed_at": "2026-08-05T16:55:08.588478+00:00",
      "id": "CVE-2026-8339",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-05T16:55:08.588478+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A SQL injection vulnerability exists in the Coverity Connect SOAP API for versions between 2024.6.0 and 2026.3.0 (inclusive).",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260805T165944Z/items/CVE-2026-8339.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A SQL injection vulnerability exists in the Coverity Connect SOAP API for versions between 2024.6.0 and 2026.3.0 (inclusive).",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-8339/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-8377/",
      "current_public_safe_latest": false,
      "cvss_score": 8.2,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.09707,
      "epss_score": 0.00198,
      "first_observed_at": "2026-07-14T05:42:23.241208+00:00",
      "id": "CVE-2026-8377",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-14T05:42:23.241208+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Missing Authorization vulnerability in Armiya Information Technologies Ltd. NVD: Co. NVD: Access Control System (GKS) allows Collect Data from Common Resource Locations.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260714T054512Z/items/CVE-2026-8377.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Missing Authorization vulnerability in Armiya Information Technologies Ltd. NVD: Co. NVD: Access Control System (GKS) allows Collect Data from Common Resource Locations.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-8377/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-8396/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.17591,
      "epss_score": 0.0026,
      "first_observed_at": "2026-07-24T11:14:35.780564+00:00",
      "id": "CVE-2026-8396",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-24T11:14:35.780564+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Improper restriction of XML external entity reference vulnerability in Netcad Software Inc. NVD: NetGIS allows Serialized Data External Linking. NVD: This issue affects NetGIS: from 5.0.66 before 7.2.2.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260724T111724Z/items/CVE-2026-8396.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Improper restriction of XML external entity reference vulnerability in Netcad Software Inc. NVD: NetGIS allows Serialized Data External Linking. NVD: This issue affects NetGIS: from 5.0.66 before 7.2.2.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-8396/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-8457/",
      "current_public_safe_latest": false,
      "cvss_score": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.32861,
      "epss_score": 0.004,
      "first_observed_at": "2026-08-08T15:50:31.311576+00:00",
      "id": "CVE-2026-8457",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-08T21:49:51.726843+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The WooCommerce - Social Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to and including 2.8.7.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260808T215635Z/items/CVE-2026-8457.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The WooCommerce - Social Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to and including 2.8.7.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-8457/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "haxx / curl",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-8458/",
      "current_public_safe_latest": false,
      "cvss_score": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.41717,
      "epss_score": 0.00543,
      "first_observed_at": "2026-07-10T06:57:55.339390+00:00",
      "id": "CVE-2026-8458",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-10T06:57:55.339390+00:00",
      "latest_item_url": null,
      "product": "curl",
      "public_safe_summary": "NVD: libcurl might in some circumstances reuse the wrong connection when asked to do Negotiate-authenticated ones, even when they are set to use different 'services'. NVD: libcurl features a pool of recent connections so that subsequent requests can reuse an existing connection to avoid overhead. NVD: When reusing a connection a range of criteria must be met.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260710T070012Z/items/CVE-2026-8458.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: haxx / curl",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: libcurl might in some circumstances reuse the wrong connection when asked to do Negotiate-authenticated ones, even when they are set to use different 'services'. NVD: libcurl features a pool of recent connections so that subsequent requests can reuse an existing connection to avoid overhead. NVD: When reusing a connection a range of criteria must be met.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-8458/timeline.json",
      "vendor": "haxx"
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-8593/",
      "current_public_safe_latest": false,
      "cvss_score": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.10994,
      "epss_score": 0.00207,
      "first_observed_at": "2026-07-28T06:05:50.269125+00:00",
      "id": "CVE-2026-8593",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-28T06:05:50.269125+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Improper permission enforcement in Checkmk versions 2.5.0 before 2.5.0p9, 2.4.0 before 2.4.0p34, 2.3.0 before 2.3.0p49, and 2.2.0 (EOL) allows users without permissions to view and modify BI packs and rules",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260728T060840Z/items/CVE-2026-8593.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Improper permission enforcement in Checkmk versions 2.5.0 before 2.5.0p9, 2.4.0 before 2.4.0p34, 2.3.0 before 2.3.0p49, and 2.2.0 (EOL) allows users without permissions to view and modify BI packs and rules",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-8593/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-8825/",
      "current_public_safe_latest": false,
      "cvss_score": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.14491,
      "epss_score": 0.00234,
      "first_observed_at": "2026-07-27T06:45:51.031460+00:00",
      "id": "CVE-2026-8825",
      "impact_tags": [
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-27T06:45:51.031460+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Elementor Website Builder WordPress plugin before 4.1.4 does not properly check user permissions before returning post data through one of its REST endpoints, allowing authenticated users with Contributor-level access and above to retrieve the title, body...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260727T065126Z/items/CVE-2026-8825.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Elementor Website Builder WordPress plugin before 4.1.4 does not properly check user permissions before returning post data through one of its REST endpoints, allowing authenticated users with Contributor-level access and above to retrieve the title, body...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-8825/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "haxx / curl",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-8924/",
      "current_public_safe_latest": false,
      "cvss_score": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.46756,
      "epss_score": 0.00649,
      "first_observed_at": "2026-07-10T06:57:55.339390+00:00",
      "id": "CVE-2026-8924",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-10T06:57:55.339390+00:00",
      "latest_item_url": null,
      "product": "curl",
      "public_safe_summary": "NVD: A flaw in curl’s cookie parsing logic allows a malicious HTTP server to set 'super cookies' that bypass the Public Suffix List check. NVD: This enables an attacker-controlled origin to inject cookies that curl subsequently scopes and transmits to unrelated third-party domains. OSV: trailing dot domain super cookie",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260710T070012Z/items/CVE-2026-8924.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: haxx / curl",
      "source_published_impact": "This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A flaw in curl’s cookie parsing logic allows a malicious HTTP server to set 'super cookies' that bypass the Public Suffix List check. NVD: This enables an attacker-controlled origin to inject cookies that curl subsequently scopes and transmits to unrelated third-party domains. OSV: trailing dot domain super cookie",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-8924/timeline.json",
      "vendor": "haxx"
    },
    {
      "affected_label": "haxx / curl",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-8925/",
      "current_public_safe_latest": false,
      "cvss_score": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.61121,
      "epss_score": 0.0108,
      "first_observed_at": "2026-07-10T06:57:55.339390+00:00",
      "id": "CVE-2026-8925",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-10T06:57:55.339390+00:00",
      "latest_item_url": null,
      "product": "curl",
      "public_safe_summary": "NVD: The curl logic that works with SASL authentication could end up cleaning up the GSASL context *twice* without clearing the pointer in between, making it free() the same pointer twice. OSV: SASL double-free OSV: The curl logic that works with SASL authentication could end up cleaning up the GSASL context *twice* without clearing the pointer in between, making it free() the same pointer twice.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260710T070012Z/items/CVE-2026-8925.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: haxx / curl",
      "source_published_impact": "This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The curl logic that works with SASL authentication could end up cleaning up the GSASL context *twice* without clearing the pointer in between, making it free() the same pointer twice. OSV: SASL double-free OSV: The curl logic that works with SASL authentication could end up cleaning up the GSASL context *twice* without clearing the pointer in between, making it free() the same pointer twice.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-8925/timeline.json",
      "vendor": "haxx"
    },
    {
      "affected_label": "haxx / curl",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-8926/",
      "current_public_safe_latest": false,
      "cvss_score": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.44987,
      "epss_score": 0.0061,
      "first_observed_at": "2026-07-10T06:57:55.339390+00:00",
      "id": "CVE-2026-8926",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-10T06:57:55.339390+00:00",
      "latest_item_url": null,
      "product": "curl",
      "public_safe_summary": "NVD: When asking curl to use a .netrc file to find credentials and at the same time specifying a URL with a username(without a password), like curl could wrongly get and use the password for *another* user set in the .netrc file for that host if such a one exists... OSV: password leak with netrc and user in URL OSV: When asking curl to use a .netrc file to find credentials and at the same time specifying a URL with a username(without a password), like curl could wrongly get and use the password for *another* user set in the .netrc file for that host if such a one exists...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260710T070012Z/items/CVE-2026-8926.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: haxx / curl",
      "source_published_impact": "This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: When asking curl to use a .netrc file to find credentials and at the same time specifying a URL with a username(without a password), like curl could wrongly get and use the password for *another* user set in the .netrc file for that host if such a one exists... OSV: password leak with netrc and user in URL OSV: When asking curl to use a .netrc file to find credentials and at the same time specifying a URL with a username(without a password), like curl could wrongly get and use the password for *another* user set in the .netrc file for that host if such a one exists...",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-8926/timeline.json",
      "vendor": "haxx"
    },
    {
      "affected_label": "haxx / curl",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-8927/",
      "current_public_safe_latest": false,
      "cvss_score": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.5061,
      "epss_score": 0.00752,
      "first_observed_at": "2026-07-10T06:57:55.339390+00:00",
      "id": "CVE-2026-8927",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-10T06:57:55.339390+00:00",
      "latest_item_url": null,
      "product": "curl",
      "public_safe_summary": "NVD: When reusing a libcurl handle for sequential transfers driven by environment-variable proxy configuration, libcurl fails to clear the proxy authentication state between requests. NVD: Specifically, if the initial transfer authenticates against proxyA using Digest auth, a subsequent transfer routed through proxyB erroneously leaks the Proxy-Authorization: header intended solely for proxyA. OSV: env-set cross-proxy Digest auth state leak",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260710T070012Z/items/CVE-2026-8927.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: haxx / curl",
      "source_published_impact": "This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: When reusing a libcurl handle for sequential transfers driven by environment-variable proxy configuration, libcurl fails to clear the proxy authentication state between requests. NVD: Specifically, if the initial transfer authenticates against proxyA using Digest auth, a subsequent transfer routed through proxyB erroneously leaks the Proxy-Authorization: header intended solely for proxyA. OSV: env-set cross-proxy Digest auth state leak",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-8927/timeline.json",
      "vendor": "haxx"
    },
    {
      "affected_label": "haxx / curl",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-8932/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.28826,
      "epss_score": 0.00368,
      "first_observed_at": "2026-07-10T06:57:55.339390+00:00",
      "id": "CVE-2026-8932",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-10T06:57:55.339390+00:00",
      "latest_item_url": null,
      "product": "curl",
      "public_safe_summary": "NVD: libcurl would reuse a previously created connection even when some mTLS config related option had been changed that should have prohibited reuse. NVD: libcurl keeps previously used connections in a connection pool for subsequent transfers to reuse if one of them matches the setup. NVD: However, some TLS settings related to client certificates were left out from the configuration match checks, making them match too easily.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260710T070012Z/items/CVE-2026-8932.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: haxx / curl",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: libcurl would reuse a previously created connection even when some mTLS config related option had been changed that should have prohibited reuse. NVD: libcurl keeps previously used connections in a connection pool for subsequent transfers to reuse if one of them matches the setup. NVD: However, some TLS settings related to client certificates were left out from the configuration match checks, making them match too easily.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-8932/timeline.json",
      "vendor": "haxx"
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-9017/",
      "current_public_safe_latest": false,
      "cvss_score": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.19219,
      "epss_score": 0.00273,
      "first_observed_at": "2026-07-18T05:38:40.092323+00:00",
      "id": "CVE-2026-9017",
      "impact_tags": [
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-18T07:15:27.585758+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 9.2.2. NVD: This is due to the plugin not properly verifying that a user is authorized to perform an action. NVD: This makes it possible for unauthenticated attackers to overwrite the saved_admin_email, saved_user_email, and saved_user_email_address fields of arbitrary form entries belonging to other users, and cause the site to dispatch attacker-controlled email content...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260718T071858Z/items/CVE-2026-9017.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes remote exposure · authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 9.2.2. NVD: This is due to the plugin not properly verifying that a user is authorized to perform an action. NVD: This makes it possible for unauthenticated attackers to overwrite the saved_admin_email, saved_user_email, and saved_user_email_address fields of arbitrary form entries belonging to other users, and cause the site to dispatch attacker-controlled email content...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-9017/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-9021/",
      "current_public_safe_latest": false,
      "cvss_score": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.21597,
      "epss_score": 0.00297,
      "first_observed_at": "2026-07-16T11:14:01.223847+00:00",
      "id": "CVE-2026-9021",
      "impact_tags": [
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-16T11:14:01.223847+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Easy Invoice plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 2.1.19. NVD: This is due to the plugin registering the easy_invoice_accept_quote and easy_invoice_decline_quote AJAX actions via wp_ajax_nopriv_ hooks and relying solely on a quote-scoped nonce that is rendered into the publicly accessible single quote template, combined... NVD: This makes it possible for unauthenticated attackers to accept or decline arbitrary published quotes — and, depending on the configured accept action, automatically convert them into invoices (and even email them to the client) — by harvesting the per-quote...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260716T111601Z/items/CVE-2026-9021.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes remote exposure · authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Easy Invoice plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 2.1.19. NVD: This is due to the plugin registering the easy_invoice_accept_quote and easy_invoice_decline_quote AJAX actions via wp_ajax_nopriv_ hooks and relying solely on a quote-scoped nonce that is rendered into the publicly accessible single quote template, combined... NVD: This makes it possible for unauthenticated attackers to accept or decline arbitrary published quotes — and, depending on the configured accept action, automatically convert them into invoices (and even email them to the client) — by harvesting the per-quote...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-9021/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-9027/",
      "current_public_safe_latest": false,
      "cvss_score": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.12704,
      "epss_score": 0.00222,
      "first_observed_at": "2026-07-16T11:14:01.223847+00:00",
      "id": "CVE-2026-9027",
      "impact_tags": [
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-16T11:14:01.223847+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The CorvusPay WooCommerce Payment Gateway plugin for WordPress is vulnerable to Payment Bypass via Improper Verification of Cryptographic Signature in all versions up to, and including, 2.7.4. NVD: The corvuspay_success_handler function registers the REST endpoint POST /wp-json/corvuspay/success/ with 'permission_callback' => '__return_true', and while it calls $this->client->validate->signature() and stores the boolean result in $res, the result is... NVD: This makes it possible for unauthenticated attackers to mark any pending WooCommerce order as fully paid by sending a POST request to the success endpoint containing an arbitrary or forged signature value, allowing them to obtain goods or services without...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260716T111601Z/items/CVE-2026-9027.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes remote exposure · authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The CorvusPay WooCommerce Payment Gateway plugin for WordPress is vulnerable to Payment Bypass via Improper Verification of Cryptographic Signature in all versions up to, and including, 2.7.4. NVD: The corvuspay_success_handler function registers the REST endpoint POST /wp-json/corvuspay/success/ with 'permission_callback' => '__return_true', and while it calls $this->client->validate->signature() and stores the boolean result in $res, the result is... NVD: This makes it possible for unauthenticated attackers to mark any pending WooCommerce order as fully paid by sending a POST request to the success endpoint containing an arbitrary or forged signature value, allowing them to obtain goods or services without...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-9027/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-9028/",
      "current_public_safe_latest": false,
      "cvss_score": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.20763,
      "epss_score": 0.00288,
      "first_observed_at": "2026-07-16T11:14:01.223847+00:00",
      "id": "CVE-2026-9028",
      "impact_tags": [
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-16T11:14:01.223847+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The CorvusPay WooCommerce Payment Gateway plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.7.4. NVD: This is due to the plugin not properly verifying that a user is authorized to perform an action. NVD: This makes it possible for unauthenticated attackers to cancel any WooCommerce order placed via the CorvusPay payment method by supplying an arbitrary order number to the /wp-json/corvuspay/cancel/ REST endpoint.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260716T111601Z/items/CVE-2026-9028.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes remote exposure · authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The CorvusPay WooCommerce Payment Gateway plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.7.4. NVD: This is due to the plugin not properly verifying that a user is authorized to perform an action. NVD: This makes it possible for unauthenticated attackers to cancel any WooCommerce order placed via the CorvusPay payment method by supplying an arbitrary order number to the /wp-json/corvuspay/cancel/ REST endpoint.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-9028/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "tp-link / archer_axe75_firmware",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-9044/",
      "current_public_safe_latest": false,
      "cvss_score": 8.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.58661,
      "epss_score": 0.00973,
      "first_observed_at": "2026-08-07T21:58:42.606809+00:00",
      "id": "CVE-2026-9044",
      "impact_tags": [
        "command injection risk",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-07T21:58:42.606809+00:00",
      "latest_item_url": null,
      "product": "archer_axe75_firmware",
      "public_safe_summary": "NVD: An OS command injection vulnerability exists in the VPN module of TP-Link AXE75 V1 routers. NVD: This vulnerability allows an adjacent, authenticated attacker to execute arbitrary commands on the device by importing a specially crafted VPN client configuration file. NVD: The issue arises from improper filtering of special characters.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260807T220457Z/items/CVE-2026-9044.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: tp-link / archer_axe75_firmware; affected version context: 1.0",
      "source_published_impact": "Source describes command injection risk · authenticated boundary. Possible impact: An attacker may be able to run unintended system commands through the affected component.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: An OS command injection vulnerability exists in the VPN module of TP-Link AXE75 V1 routers. NVD: This vulnerability allows an adjacent, authenticated attacker to execute arbitrary commands on the device by importing a specially crafted VPN client configuration file. NVD: The issue arises from improper filtering of special characters.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-9044/timeline.json",
      "vendor": "tp-link"
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-9066/",
      "current_public_safe_latest": false,
      "cvss_score": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.04563,
      "epss_score": 0.00149,
      "first_observed_at": "2026-07-30T06:01:44.452906+00:00",
      "id": "CVE-2026-9066",
      "impact_tags": [
        "XSS risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-30T06:01:44.452906+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The WP Compress WordPress plugin before 7.10.04 does not validate the value of a query parameter that controls the asset CDN host before using it to build the URLs of JavaScript files emitted on the page, leading to Reflected XSS. NVD: When a visitor follows a crafted link, the WP Compress WordPress plugin before 7.10.04's loader injects script elements pointing to an attacker-controlled origin, which lets the attacker execute arbitrary JavaScript in the visitor's session on the target site.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260730T060504Z/items/CVE-2026-9066.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes XSS risk. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The WP Compress WordPress plugin before 7.10.04 does not validate the value of a query parameter that controls the asset CDN host before using it to build the URLs of JavaScript files emitted on the page, leading to Reflected XSS. NVD: When a visitor follows a crafted link, the WP Compress WordPress plugin before 7.10.04's loader injects script elements pointing to an attacker-controlled origin, which lets the attacker execute arbitrary JavaScript in the visitor's session on the target site.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-9066/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "haxx / curl",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-9079/",
      "current_public_safe_latest": false,
      "cvss_score": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.6067,
      "epss_score": 0.01064,
      "first_observed_at": "2026-07-10T06:57:55.339390+00:00",
      "id": "CVE-2026-9079",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-10T06:57:55.339390+00:00",
      "latest_item_url": null,
      "product": "curl",
      "public_safe_summary": "NVD: libcurl had a flaw that when instructed to clear proxy authentication credentials which made it not do so, leaving the old credentials around to get used for subsequent transfers that should not know nor use them. OSV: stale proxy password leak OSV: libcurl had a flaw that when instructed to clear proxy authentication credentials which made it not do so, leaving the old credentials around to get used for subsequent transfers that should not know nor use them.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260710T070012Z/items/CVE-2026-9079.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: haxx / curl",
      "source_published_impact": "This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: libcurl had a flaw that when instructed to clear proxy authentication credentials which made it not do so, leaving the old credentials around to get used for subsequent transfers that should not know nor use them. OSV: stale proxy password leak OSV: libcurl had a flaw that when instructed to clear proxy authentication credentials which made it not do so, leaving the old credentials around to get used for subsequent transfers that should not know nor use them.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-9079/timeline.json",
      "vendor": "haxx"
    },
    {
      "affected_label": "haxx / curl",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-9080/",
      "current_public_safe_latest": false,
      "cvss_score": 7.3,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.38911,
      "epss_score": 0.00494,
      "first_observed_at": "2026-07-10T06:57:55.339390+00:00",
      "id": "CVE-2026-9080",
      "impact_tags": [
        "memory safety review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-10T06:57:55.339390+00:00",
      "latest_item_url": null,
      "product": "curl",
      "public_safe_summary": "NVD: Calling curl_easy_pause() within the event-based CURLMOPT_SOCKETFUNCTION callback triggers a use-after-free vulnerability, where libcurl attempts to store a flag using a dangling struct pointer immediately after that pointer's memory has been freed. OSV: UAF after pause in socket callback OSV: Calling curl_easy_pause() within the event-based CURLMOPT_SOCKETFUNCTION callback triggers a use-after-free vulnerability, where libcurl attempts to store a flag using a dangling struct pointer immediately after that pointer's memory has been freed.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260710T070012Z/items/CVE-2026-9080.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: haxx / curl",
      "source_published_impact": "Source describes memory safety review. Possible impact: The affected component has memory-safety risk that may lead to crash, privilege, or code-execution impact depending on exposure.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Calling curl_easy_pause() within the event-based CURLMOPT_SOCKETFUNCTION callback triggers a use-after-free vulnerability, where libcurl attempts to store a flag using a dangling struct pointer immediately after that pointer's memory has been freed. OSV: UAF after pause in socket callback OSV: Calling curl_easy_pause() within the event-based CURLMOPT_SOCKETFUNCTION callback triggers a use-after-free vulnerability, where libcurl attempts to store a flag using a dangling struct pointer immediately after that pointer's memory has been freed.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-9080/timeline.json",
      "vendor": "haxx"
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-9147/",
      "current_public_safe_latest": false,
      "cvss_score": 8.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.04959,
      "epss_score": 0.00153,
      "first_observed_at": "2026-07-25T10:46:49.898242+00:00",
      "id": "CVE-2026-9147",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-25T10:46:49.898242+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: uproot dynamically generates Python class source code from ROOT TStreamerInfo records in a file and compiles it at runtime. NVD: Some file-controlled streamer metadata fields (for example, streamer element names) are interpolated into the generated Python source without safe quoting via repr() or the !r format specifier. NVD: An attacker who can supply a crafted ROOT file can place Python expression-breaking content into a streamer metadata field.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260725T104916Z/items/CVE-2026-9147.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: uproot dynamically generates Python class source code from ROOT TStreamerInfo records in a file and compiles it at runtime. NVD: Some file-controlled streamer metadata fields (for example, streamer element names) are interpolated into the generated Python source without safe quoting via repr() or the !r format specifier. NVD: An attacker who can supply a crafted ROOT file can place Python expression-breaking content into a streamer metadata field.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-9147/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "esri / arcgis_server",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-9181/",
      "current_public_safe_latest": false,
      "cvss_score": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.49877,
      "epss_score": 0.00727,
      "first_observed_at": "2026-07-13T17:24:46.617207+00:00",
      "id": "CVE-2026-9181",
      "impact_tags": [
        "path traversal review",
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-13T17:24:46.617207+00:00",
      "latest_item_url": null,
      "product": "arcgis_server",
      "public_safe_summary": "NVD: Esri ArcGIS Server contains a directory traversal vulnerability. NVD: ArcGIS Enterprise on Kubernetes is not impacted. NVD: An unauthenticated attacker could exploit this issue by sending crafted path parameters.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260713T172750Z/items/CVE-2026-9181.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: esri / arcgis_server; affected version context: -",
      "source_published_impact": "Source describes path traversal review · remote exposure · authenticated boundary. Possible impact: A remote attacker may be able to reach files outside the intended application path.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Esri ArcGIS Server contains a directory traversal vulnerability. NVD: ArcGIS Enterprise on Kubernetes is not impacted. NVD: An unauthenticated attacker could exploit this issue by sending crafted path parameters.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-9181/timeline.json",
      "vendor": "esri"
    },
    {
      "affected_label": "esri / arcgis_server",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-9182/",
      "current_public_safe_latest": false,
      "cvss_score": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.27332,
      "epss_score": 0.00352,
      "first_observed_at": "2026-07-13T17:24:46.617207+00:00",
      "id": "CVE-2026-9182",
      "impact_tags": [
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-13T17:24:46.617207+00:00",
      "latest_item_url": null,
      "product": "arcgis_server",
      "public_safe_summary": "NVD: Esri ArcGIS Server contains an unrestricted file upload vulnerability. NVD: An unauthenticated attacker could exploit this issue by uploading a crafted file to the affected endpoint. NVD: Successful exploitation could allow arbitrary file upload, potentially allowing for other attacks.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260713T172750Z/items/CVE-2026-9182.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: esri / arcgis_server; affected version context: -",
      "source_published_impact": "Source describes remote exposure · authenticated boundary. Possible impact: This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Esri ArcGIS Server contains an unrestricted file upload vulnerability. NVD: An unauthenticated attacker could exploit this issue by uploading a crafted file to the affected endpoint. NVD: Successful exploitation could allow arbitrary file upload, potentially allowing for other attacks.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-9182/timeline.json",
      "vendor": "esri"
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-9282/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.48116,
      "epss_score": 0.00676,
      "first_observed_at": "2026-07-18T07:15:27.585758+00:00",
      "id": "CVE-2026-9282",
      "impact_tags": [
        "information exposure review",
        "path traversal review",
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-18T07:15:27.585758+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The W3 Total Cache plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.9.4 via the setupSources function. NVD: This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information. NVD: Exploitation requires enabling manual minify mode and supplying a manual-format minify filename so that the hash is empty and the f_array[] entries are not overwritten before reaching setupSources().",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260718T071858Z/items/CVE-2026-9282.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes information exposure review · path traversal review · remote exposure. Possible impact: A remote attacker may be able to reach files outside the intended application path.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The W3 Total Cache plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.9.4 via the setupSources function. NVD: This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information. NVD: Exploitation requires enabling manual minify mode and supplying a manual-format minify filename so that the hash is empty and the f_array[] entries are not overwritten before reaching setupSources().",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-9282/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-9335/",
      "current_public_safe_latest": false,
      "cvss_score": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.47563,
      "epss_score": 0.00646,
      "first_observed_at": "2026-08-08T15:50:31.311576+00:00",
      "id": "CVE-2026-9335",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-09T04:40:09.231782+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A vulnerability in keras-team/keras versions <= 3.14.0 allows arbitrary local HDF5 file content disclosure due to improper handling of HDF5 ExternalLinks. NVD: The KerasFileEditor and keras.saving.load_weights functions bypass the safe_get_h5_group and safe_get_h5_dataset helpers, which are designed to reject ExternalLinks and SoftLinks. NVD: This results in automatic dereferencing of links to external HDF5 files, enabling attackers to disclose sensitive data from the victim's local filesystem.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260809T044412Z/items/CVE-2026-9335.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 3,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability in keras-team/keras versions <= 3.14.0 allows arbitrary local HDF5 file content disclosure due to improper handling of HDF5 ExternalLinks. NVD: The KerasFileEditor and keras.saving.load_weights functions bypass the safe_get_h5_group and safe_get_h5_dataset helpers, which are designed to reject ExternalLinks and SoftLinks. NVD: This results in automatic dereferencing of links to external HDF5 files, enabling attackers to disclose sensitive data from the victim's local filesystem.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-9335/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-9341/",
      "current_public_safe_latest": false,
      "cvss_score": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.17046,
      "epss_score": 0.00255,
      "first_observed_at": "2026-07-21T11:20:19.325173+00:00",
      "id": "CVE-2026-9341",
      "impact_tags": [
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-21T11:20:19.325173+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Academy LMS – WordPress LMS Plugin for Complete eLearning Solution plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.8.0 via the 'save_lesson_note', 'get_lesson_note', and... NVD: This makes it possible for authenticated attackers, with Subscriber-level access and above, to read, overwrite, or delete the private lesson notes of any other user (including administrators), and to falsify lesson-completion progress for arbitrary users.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260721T112231Z/items/CVE-2026-9341.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Academy LMS – WordPress LMS Plugin for Complete eLearning Solution plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.8.0 via the 'save_lesson_note', 'get_lesson_note', and... NVD: This makes it possible for authenticated attackers, with Subscriber-level access and above, to read, overwrite, or delete the private lesson notes of any other user (including administrators), and to falsify lesson-completion progress for arbitrary users.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-9341/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-9494/",
      "current_public_safe_latest": false,
      "cvss_score": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.01152,
      "epss_score": 0.00103,
      "first_observed_at": "2026-07-23T11:21:51.498947+00:00",
      "id": "CVE-2026-9494",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-23T11:21:51.498947+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: An information disclosure vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu-advantage-tools). NVD: The client validates Ubuntu Pro APT credentials by executing /usr/lib/apt/apt-helper using the download-file command. NVD: During this process, the secret bearer token is embedded directly in the cleartext URL component passed via the command-line arguments (argv), resulting in a URL format such as On systems utilizing a default-mounted /proc file system where process-hiding...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260723T112431Z/items/CVE-2026-9494.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: An information disclosure vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu-advantage-tools). NVD: The client validates Ubuntu Pro APT credentials by executing /usr/lib/apt/apt-helper using the download-file command. NVD: During this process, the secret bearer token is embedded directly in the cleartext URL component passed via the command-line arguments (argv), resulting in a URL format such as On systems utilizing a default-mounted /proc file system where process-hiding...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-9494/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "haxx / curl",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-9545/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.32807,
      "epss_score": 0.00408,
      "first_observed_at": "2026-07-10T06:57:55.339390+00:00",
      "id": "CVE-2026-9545",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-10T06:57:55.339390+00:00",
      "latest_item_url": null,
      "product": "curl",
      "public_safe_summary": "NVD: In this scenario, libcurl first uses a proper HTTP/3 server for the initial transfers, and when it makes a second transfer to the same site it has been replaced by the attacker's impostor machine - without a valid certificate. NVD: When libcurl returns to the hostname the second time with a cached SSL session (CURLOPT_SSL_SESSIONID_CACHE is not disabled) and early data enabled (the CURLSSLOPT_EARLYDATA bit is set in CURLOPT_SSL_OPTIONS), libcurl might send off the second request's bytes... NVD: Potentially leaking sensitive information.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260710T070012Z/items/CVE-2026-9545.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: haxx / curl",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: In this scenario, libcurl first uses a proper HTTP/3 server for the initial transfers, and when it makes a second transfer to the same site it has been replaced by the attacker's impostor machine - without a valid certificate. NVD: When libcurl returns to the hostname the second time with a cached SSL session (CURLOPT_SSL_SESSIONID_CACHE is not disabled) and early data enabled (the CURLSSLOPT_EARLYDATA bit is set in CURLOPT_SSL_OPTIONS), libcurl might send off the second request's bytes... NVD: Potentially leaking sensitive information.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-9545/timeline.json",
      "vendor": "haxx"
    },
    {
      "affected_label": "haxx / curl",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-9546/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.46863,
      "epss_score": 0.00652,
      "first_observed_at": "2026-07-10T06:57:55.339390+00:00",
      "id": "CVE-2026-9546",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-10T06:57:55.339390+00:00",
      "latest_item_url": null,
      "product": "curl",
      "public_safe_summary": "NVD: A vulnerability in libcurl caused the HTTP Referer: header to persist even when explicitly cleared. NVD: While the documentation states that passing NULL to CURLOPT_REFERER suppresses the header, the option failed to clear the internal state. NVD: As a result the previous referrer string was erroneously reused and sent in subsequent requests, potentially leaking sensitive information to unintended servers.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260710T070012Z/items/CVE-2026-9546.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: haxx / curl",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability in libcurl caused the HTTP Referer: header to persist even when explicitly cleared. NVD: While the documentation states that passing NULL to CURLOPT_REFERER suppresses the header, the option failed to clear the internal state. NVD: As a result the previous referrer string was erroneously reused and sent in subsequent requests, potentially leaking sensitive information to unintended servers.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-9546/timeline.json",
      "vendor": "haxx"
    },
    {
      "affected_label": "haxx / curl",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-9547/",
      "current_public_safe_latest": false,
      "cvss_score": 7.4,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.39699,
      "epss_score": 0.00508,
      "first_observed_at": "2026-07-10T06:57:55.339390+00:00",
      "id": "CVE-2026-9547",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-10T06:57:55.339390+00:00",
      "latest_item_url": null,
      "product": "curl",
      "public_safe_summary": "NVD: When a libcurl-based application performs transfers via SCP:// or SFTP:// and utilizes the CURLOPT_SSH_KEYFUNCTION callback, it may silently accept an untrusted server. NVD: This vulnerability occurs when a server presents a host key type that does not match the specific key type already recorded for that host in the known_hosts file. NVD: Instead of rejecting the mismatch, the callback mechanism fails to properly enforce the restriction, allowing the connection to succeed without warning and risking a potential man-in-the-middle attack.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260710T070012Z/items/CVE-2026-9547.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: haxx / curl",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: When a libcurl-based application performs transfers via SCP:// or SFTP:// and utilizes the CURLOPT_SSH_KEYFUNCTION callback, it may silently accept an untrusted server. NVD: This vulnerability occurs when a server presents a host key type that does not match the specific key type already recorded for that host in the known_hosts file. NVD: Instead of rejecting the mismatch, the callback mechanism fails to properly enforce the restriction, allowing the connection to succeed without warning and risking a potential man-in-the-middle attack.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-9547/timeline.json",
      "vendor": "haxx"
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-9577/",
      "current_public_safe_latest": false,
      "cvss_score": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.03984,
      "epss_score": 0.00142,
      "first_observed_at": "2026-07-30T06:01:44.452906+00:00",
      "id": "CVE-2026-9577",
      "impact_tags": [
        "XSS risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-30T06:01:44.452906+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Post Status Notifier Lite WordPress plugin before 1.13.0 does not properly escape the mod URL parameter before reflecting it into the admin settings page (admin.php?page=post-status-notifier-lite), leading to a Reflected Cross-Site Scripting vulnerability...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260730T060504Z/items/CVE-2026-9577.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes XSS risk. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Post Status Notifier Lite WordPress plugin before 1.13.0 does not properly escape the mod URL parameter before reflecting it into the admin settings page (admin.php?page=post-status-notifier-lite), leading to a Reflected Cross-Site Scripting vulnerability...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-9577/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-9602/",
      "current_public_safe_latest": false,
      "cvss_score": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.14461,
      "epss_score": 0.00235,
      "first_observed_at": "2026-07-24T11:14:35.780564+00:00",
      "id": "CVE-2026-9602",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-07-24T11:14:35.780564+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Mattermost Advisory ID: MMSA-2026-00678",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260724T111724Z/items/CVE-2026-9602.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Mattermost Advisory ID: MMSA-2026-00678",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-9602/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-9635/",
      "current_public_safe_latest": false,
      "cvss_score": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.08616,
      "epss_score": 0.00187,
      "first_observed_at": "2026-07-30T06:01:44.452906+00:00",
      "id": "CVE-2026-9635",
      "impact_tags": [
        "XSS risk",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-30T06:01:44.452906+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The WP Shortcode by MyThemeShop plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title' parameter of the [tab] shortcode in versions up to, and including, 1.4.17. NVD: This is due to insufficient input sanitization and output escaping in the mts_tabs() function, which outputs the title shortcode attribute directly into the HTML output between anchor tags without applying any escaping functions. NVD: This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260730T060504Z/items/CVE-2026-9635.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes XSS risk · authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The WP Shortcode by MyThemeShop plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title' parameter of the [tab] shortcode in versions up to, and including, 1.4.17. NVD: This is due to insufficient input sanitization and output escaping in the mts_tabs() function, which outputs the title shortcode attribute directly into the HTML output between anchor tags without applying any escaping functions. NVD: This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-9635/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-9656/",
      "current_public_safe_latest": false,
      "cvss_score": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.05397,
      "epss_score": 0.00158,
      "first_observed_at": "2026-07-24T06:06:41.160911+00:00",
      "id": "CVE-2026-9656",
      "impact_tags": [
        "information exposure review",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-24T06:06:41.160911+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The HubSpot All-In-One Marketing – Forms, Popups, Live Chat plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 11.3.62 via the wp_localize_script() / window.leadinConfig JavaScript object. NVD: This makes it possible for authenticated attackers, with contributor-level access and above, to extract the site's plaintext HubSpot OAuth refresh token exposed via the window.leadinConfig JavaScript object, which can then be used to access or modify data in... NVD: Although the refresh token is stored at rest with AES-256-CTR encryption, decryption occurs server-side before the plaintext value is passed to wp_localize_script(), rendering the at-rest encryption ineffective against this exposure path.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260724T061150Z/items/CVE-2026-9656.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes information exposure review · authenticated boundary. Possible impact: An attacker may be able to access information that should not be exposed.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The HubSpot All-In-One Marketing – Forms, Popups, Live Chat plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 11.3.62 via the wp_localize_script() / window.leadinConfig JavaScript object. NVD: This makes it possible for authenticated attackers, with contributor-level access and above, to extract the site's plaintext HubSpot OAuth refresh token exposed via the window.leadinConfig JavaScript object, which can then be used to access or modify data in... NVD: Although the refresh token is stored at rest with AES-256-CTR encryption, decryption occurs server-side before the plaintext value is passed to wp_localize_script(), rendering the at-rest encryption ineffective against this exposure path.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-9656/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-9695/",
      "current_public_safe_latest": false,
      "cvss_score": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.24617,
      "epss_score": 0.00326,
      "first_observed_at": "2026-07-15T05:43:30.245469+00:00",
      "id": "CVE-2026-9695",
      "impact_tags": [
        "privilege boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-15T05:43:30.245469+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: An Improper Authentication vulnerability affecting DELMIA Apriso from Release 2020 through Release 2026 could allow an attacker to gain privileged access to the server.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260715T054459Z/items/CVE-2026-9695.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes privilege escalation risk. Possible impact: An attacker may cross a privilege boundary and gain more access than intended.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: An Improper Authentication vulnerability affecting DELMIA Apriso from Release 2020 through Release 2026 could allow an attacker to gain privileged access to the server.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-9695/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-9700/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.19144,
      "epss_score": 0.00273,
      "first_observed_at": "2026-07-15T05:43:30.245469+00:00",
      "id": "CVE-2026-9700",
      "impact_tags": [
        "information exposure review",
        "SQL injection risk",
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-15T05:43:30.245469+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Eventer plugin for WordPress is vulnerable to time-based SQL Injection via the ‘code’ parameter in all versions up to, and including, 4.4.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL... NVD: This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260715T054459Z/items/CVE-2026-9700.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes information exposure review · SQL injection risk · remote exposure. Possible impact: A remote attacker may be able to read or change database-backed application data.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Eventer plugin for WordPress is vulnerable to time-based SQL Injection via the ‘code’ parameter in all versions up to, and including, 4.4.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL... NVD: This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-9700/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-9713/",
      "current_public_safe_latest": false,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.19479,
      "epss_score": 0.00273,
      "first_observed_at": "2026-07-30T06:01:44.452906+00:00",
      "id": "CVE-2026-9713",
      "impact_tags": [
        "information exposure review",
        "SQL injection risk",
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-30T06:01:44.452906+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Lumise Product Designer for WooCommerce plugin for WordPress is vulnerable to SQL Injection via the 'id' and 'table' parameters in the uploaded cart JSON file processed by the checkout AJAX action in versions up to, and including, 2.1.1. NVD: This is due to insufficient escaping on the user-supplied parameters before they are appended directly to a raw SQL query in the find_resource() function — the 'id' field is interpolated without quotes into a WHERE clause (numeric context) and 'table' is... NVD: This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260730T060504Z/items/CVE-2026-9713.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes information exposure review · SQL injection risk · remote exposure. Possible impact: A remote attacker may be able to read or change database-backed application data.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Lumise Product Designer for WooCommerce plugin for WordPress is vulnerable to SQL Injection via the 'id' and 'table' parameters in the uploaded cart JSON file processed by the checkout AJAX action in versions up to, and including, 2.1.1. NVD: This is due to insufficient escaping on the user-supplied parameters before they are appended directly to a raw SQL query in the find_resource() function — the 'id' field is interpolated without quotes into a WHERE clause (numeric context) and 'table' is... NVD: This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-9713/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-9729/",
      "current_public_safe_latest": false,
      "cvss_score": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.09321,
      "epss_score": 0.00193,
      "first_observed_at": "2026-07-30T06:01:44.452906+00:00",
      "id": "CVE-2026-9729",
      "impact_tags": [
        "XSS risk",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-30T06:01:44.452906+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Webpushr Push Notifications plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'webpushr_notification_title' and 'webpushr_notification_body' parameters in versions up to, and including, 4.39.0. NVD: This is due to insufficient input sanitization in the save_send_notification_flag() function and missing output escaping in the wpp_notification_box() function, which concatenates raw post meta values directly into HTML attribute and textarea contexts. NVD: This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260730T060504Z/items/CVE-2026-9729.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes XSS risk · authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Webpushr Push Notifications plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'webpushr_notification_title' and 'webpushr_notification_body' parameters in versions up to, and including, 4.39.0. NVD: This is due to insufficient input sanitization in the save_send_notification_flag() function and missing output escaping in the wpp_notification_box() function, which concatenates raw post meta values directly into HTML attribute and textarea contexts. NVD: This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-9729/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-9731/",
      "current_public_safe_latest": false,
      "cvss_score": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.02834,
      "epss_score": 0.00128,
      "first_observed_at": "2026-07-15T05:43:30.245469+00:00",
      "id": "CVE-2026-9731",
      "impact_tags": [
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-15T05:43:30.245469+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Wp Js Detect plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.9. NVD: This is due to missing or incorrect nonce validation on the plugin_settings function. NVD: This makes it possible for unauthenticated attackers to update the plugin's notification text and CSS settings (wp_non_js_notification_text and wp_non_js_notification_css), injecting arbitrary content that is echoed unescaped on the frontend via a forged...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260715T054459Z/items/CVE-2026-9731.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes remote exposure · authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Wp Js Detect plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.9. NVD: This is due to missing or incorrect nonce validation on the plugin_settings function. NVD: This makes it possible for unauthenticated attackers to update the plugin's notification text and CSS settings (wp_non_js_notification_text and wp_non_js_notification_css), injecting arbitrary content that is echoed unescaped on the frontend via a forged...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-9731/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-9734/",
      "current_public_safe_latest": false,
      "cvss_score": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.05236,
      "epss_score": 0.00156,
      "first_observed_at": "2026-07-24T22:30:22.773708+00:00",
      "id": "CVE-2026-9734",
      "impact_tags": [
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-24T22:30:22.773708+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The W3SC Elementor to Zoho CRM plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.2.0. NVD: This is due to missing or incorrect nonce validation on the storeInfo function. NVD: This makes it possible for unauthenticated attackers to modify the plugin's Zoho CRM integration settings, replacing the configured data center, client ID, client secret, and user email credentials with attacker-controlled values via a forged request granted...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260724T223254Z/items/CVE-2026-9734.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes remote exposure · authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The W3SC Elementor to Zoho CRM plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.2.0. NVD: This is due to missing or incorrect nonce validation on the storeInfo function. NVD: This makes it possible for unauthenticated attackers to modify the plugin's Zoho CRM integration settings, replacing the configured data center, client ID, client secret, and user email credentials with attacker-controlled values via a forged request granted...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-9734/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-9738/",
      "current_public_safe_latest": false,
      "cvss_score": 4.4,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.10924,
      "epss_score": 0.00208,
      "first_observed_at": "2026-07-18T05:13:28.850753+00:00",
      "id": "CVE-2026-9738",
      "impact_tags": [
        "XSS risk",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-18T05:13:28.850753+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Print, PDF, Email by PrintFriendly plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'content_position_css' parameter in all versions up to, and including, 5.5.10 due to insufficient input sanitization and output escaping. NVD: This makes it possible for authenticated attackers, with administrator-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260718T051545Z/items/CVE-2026-9738.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes XSS risk · authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Print, PDF, Email by PrintFriendly plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'content_position_css' parameter in all versions up to, and including, 5.5.10 due to insufficient input sanitization and output escaping. NVD: This makes it possible for authenticated attackers, with administrator-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-9738/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-9765/",
      "current_public_safe_latest": false,
      "cvss_score": 7.1,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.20923,
      "epss_score": 0.00287,
      "first_observed_at": "2026-07-31T11:36:05.167842+00:00",
      "id": "CVE-2026-9765",
      "impact_tags": [
        "privilege boundary review",
        "unauthorized access risk"
      ],
      "kev": false,
      "last_observed_at": "2026-07-31T11:36:05.167842+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: Note: The CVE and blog post don't exist because we determined this is actually a cloud-only issue. NVD: Access Controls are “Broken” when a user can access resources they are not authorized to access. NVD: An attacker can bypass any access control mechanisms in a web application, and gain unauthorized access to resources that are not available with their permissions.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260731T115001Z/items/CVE-2026-9765.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes privilege escalation risk · unauthorized access risk. Possible impact: An attacker may cross a privilege boundary and gain more access than intended.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Note: The CVE and blog post don't exist because we determined this is actually a cloud-only issue. NVD: Access Controls are “Broken” when a user can access resources they are not authorized to access. NVD: An attacker can bypass any access control mechanisms in a web application, and gain unauthorized access to resources that are not available with their permissions.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-9765/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-9810/",
      "current_public_safe_latest": false,
      "cvss_score": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.19832,
      "epss_score": 0.00277,
      "first_observed_at": "2026-07-24T06:06:41.160911+00:00",
      "id": "CVE-2026-9810",
      "impact_tags": [
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-24T06:06:41.160911+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The AI Copilot WordPress plugin before 1.5.4 does not bind OAuth access tokens to a WordPress user, and accepts any valid token as an administrator session, allowing unauthenticated attackers who complete the public OAuth flow to execute privileged MCP tools...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260724T061150Z/items/CVE-2026-9810.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes remote exposure · authenticated boundary. Possible impact: This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The AI Copilot WordPress plugin before 1.5.4 does not bind OAuth access tokens to a WordPress user, and accepts any valid token as an administrator session, allowing unauthenticated attackers who complete the public OAuth flow to execute privileged MCP tools...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-9810/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-9833/",
      "current_public_safe_latest": false,
      "cvss_score": 7.1,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.05959,
      "epss_score": 0.00164,
      "first_observed_at": "2026-07-27T06:45:51.031460+00:00",
      "id": "CVE-2026-9833",
      "impact_tags": [
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-07-27T06:45:51.031460+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: The Tag Groups is the Advanced Way to Display Your Taxonomy Terms WordPress plugin before 2.2.0 does not properly escape one of its AJAX parameters before reflecting it in the response body served with an HTML content type, allowing unauthenticated attackers...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260727T065126Z/items/CVE-2026-9833.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes remote exposure · authenticated boundary. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Tag Groups is the Advanced Way to Display Your Taxonomy Terms WordPress plugin before 2.2.0 does not properly escape one of its AJAX parameters before reflecting it in the response body served with an HTML content type, allowing unauthenticated attackers...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-9833/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-9856/",
      "current_public_safe_latest": false,
      "cvss_score": 7.1,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.21731,
      "epss_score": 0.00295,
      "first_observed_at": "2026-08-09T09:59:30.349754+00:00",
      "id": "CVE-2026-9856",
      "impact_tags": [
        "path traversal review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-09T15:51:11.168346+00:00",
      "latest_item_url": null,
      "product": null,
      "public_safe_summary": "NVD: A vulnerability in huggingface/transformers versions <=5.8.0.dev0 allows an attacker to perform arbitrary file writes via path traversal. NVD: The issue resides in the save_pretrained() methods of PreTrainedTokenizerBase and ProcessorMixin, where keys from the chat_template dictionary are used directly as filenames without proper validation. NVD: An attacker can exploit this by publishing a malicious Hugging Face Hub repository with a crafted tokenizer_config.json file.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260809T155523Z/items/CVE-2026-9856.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes path traversal review. Possible impact: An attacker may be able to reach files outside the intended application path.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability in huggingface/transformers versions <=5.8.0.dev0 allows an attacker to perform arbitrary file writes via path traversal. NVD: The issue resides in the save_pretrained() methods of PreTrainedTokenizerBase and ProcessorMixin, where keys from the chat_template dictionary are used directly as filenames without proper validation. NVD: An attacker can exploit this by publishing a malicious Hugging Face Hub repository with a crafted tokenizer_config.json file.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-9856/timeline.json",
      "vendor": null
    }
  ],
  "generated_at": "2026-08-12T10:39:32.977657+00:00",
  "latest_run_id": "20260812T103932Z",
  "latest_run_item_count": 20,
  "radar": "vuln",
  "read_only_static_data": true,
  "run_count": 167,
  "runs": [
    {
      "generated_at": "2026-07-03T08:50:42.985126+00:00",
      "index_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260703T085042Z/index.json",
      "item_count": 20,
      "manifest_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260703T085042Z/manifest.json",
      "run_id": "20260703T085042Z"
    },
    {
      "generated_at": "2026-07-03T13:33:11.834606+00:00",
      "index_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260703T133311Z/index.json",
      "item_count": 20,
      "manifest_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260703T133311Z/manifest.json",
      "run_id": "20260703T133311Z"
    },
    {
      "generated_at": "2026-07-03T13:38:00.806257+00:00",
      "index_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260703T133800Z/index.json",
      "item_count": 20,
      "manifest_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260703T133800Z/manifest.json",
      "run_id": "20260703T133800Z"
    },
    {
      "generated_at": "2026-07-03T15:20:36.980372+00:00",
      "index_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260703T152036Z/index.json",
      "item_count": 20,
      "manifest_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260703T152036Z/manifest.json",
      "run_id": "20260703T152036Z"
    },
    {
      "generated_at": "2026-07-03T15:28:17.290319+00:00",
      "index_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260703T152817Z/index.json",
      "item_count": 20,
      "manifest_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260703T152817Z/manifest.json",
      "run_id": "20260703T152817Z"
    },
    {
      "generated_at": "2026-07-03T16:48:24.777423+00:00",
      "index_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260703T164824Z/index.json",
      "item_count": 20,
      "manifest_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260703T164824Z/manifest.json",
      "run_id": "20260703T164824Z"
    },
    {
      "generated_at": "2026-07-03T22:28:43.876826+00:00",
      "index_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260703T222843Z/index.json",
      "item_count": 20,
      "manifest_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260703T222843Z/manifest.json",
      "run_id": "20260703T222843Z"
    },
    {
      "generated_at": "2026-07-04T06:31:22.236006+00:00",
      "index_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260704T063122Z/index.json",
      "item_count": 20,
      "manifest_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260704T063122Z/manifest.json",
      "run_id": "20260704T063122Z"
    },
    {
      "generated_at": "2026-07-04T09:20:30.718591+00:00",
      "index_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260704T092030Z/index.json",
      "item_count": 20,
      "manifest_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260704T092030Z/manifest.json",
      "run_id": "20260704T092030Z"
    },
    {
      "generated_at": "2026-07-04T11:02:41.838744+00:00",
      "index_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260704T110241Z/index.json",
      "item_count": 20,
      "manifest_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260704T110241Z/manifest.json",
      "run_id": "20260704T110241Z"
    },
    {
      "generated_at": "2026-07-04T16:21:15.391781+00:00",
      "index_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260704T162115Z/index.json",
      "item_count": 20,
      "manifest_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260704T162115Z/manifest.json",
      "run_id": "20260704T162115Z"
    },
    {
      "generated_at": "2026-07-04T22:14:50.374496+00:00",
      "index_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260704T221450Z/index.json",
      "item_count": 20,
      "manifest_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260704T221450Z/manifest.json",
      "run_id": "20260704T221450Z"
    },
    {
      "generated_at": "2026-07-05T06:52:52.694480+00:00",
      "index_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260705T065252Z/index.json",
      "item_count": 20,
      "manifest_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260705T065252Z/manifest.json",
      "run_id": "20260705T065252Z"
    },
    {
      "generated_at": "2026-07-05T11:15:43.328025+00:00",
      "index_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260705T111543Z/index.json",
      "item_count": 20,
      "manifest_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260705T111543Z/manifest.json",
      "run_id": "20260705T111543Z"
    },
    {
      "generated_at": "2026-07-05T16:30:51.110738+00:00",
      "index_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260705T163051Z/index.json",
      "item_count": 20,
      "manifest_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260705T163051Z/manifest.json",
      "run_id": "20260705T163051Z"
    },
    {
      "generated_at": "2026-07-05T22:16:56.345295+00:00",
      "index_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260705T221656Z/index.json",
      "item_count": 20,
      "manifest_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260705T221656Z/manifest.json",
      "run_id": "20260705T221656Z"
    },
    {
      "generated_at": "2026-07-06T07:58:27.241801+00:00",
      "index_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260706T075827Z/index.json",
      "item_count": 20,
      "manifest_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260706T075827Z/manifest.json",
      "run_id": "20260706T075827Z"
    },
    {
      "generated_at": "2026-07-06T13:01:50.774548+00:00",
      "index_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260706T130150Z/index.json",
      "item_count": 20,
      "manifest_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260706T130150Z/manifest.json",
      "run_id": "20260706T130150Z"
    },
    {
      "generated_at": "2026-07-06T17:56:37.335361+00:00",
      "index_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260706T175637Z/index.json",
      "item_count": 20,
      "manifest_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260706T175637Z/manifest.json",
      "run_id": "20260706T175637Z"
    },
    {
      "generated_at": "2026-07-06T22:41:41.994021+00:00",
      "index_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260706T224141Z/index.json",
      "item_count": 20,
      "manifest_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260706T224141Z/manifest.json",
      "run_id": "20260706T224141Z"
    },
    {
      "generated_at": "2026-07-07T06:59:22.047898+00:00",
      "index_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260707T065922Z/index.json",
      "item_count": 20,
      "manifest_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260707T065922Z/manifest.json",
      "run_id": "20260707T065922Z"
    },
    {
      "generated_at": "2026-07-07T12:13:20.902144+00:00",
      "index_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260707T121320Z/index.json",
      "item_count": 20,
      "manifest_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260707T121320Z/manifest.json",
      "run_id": "20260707T121320Z"
    },
    {
      "generated_at": "2026-07-07T17:29:14.832365+00:00",
      "index_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260707T172914Z/index.json",
      "item_count": 20,
      "manifest_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260707T172914Z/manifest.json",
      "run_id": "20260707T172914Z"
    },
    {
      "generated_at": "2026-07-07T22:34:30.519552+00:00",
      "index_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260707T223430Z/index.json",
      "item_count": 20,
      "manifest_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260707T223430Z/manifest.json",
      "run_id": "20260707T223430Z"
    },
    {
      "generated_at": "2026-07-08T03:43:17.030146+00:00",
      "index_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260708T034317Z/index.json",
      "item_count": 20,
      "manifest_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260708T034317Z/manifest.json",
      "run_id": "20260708T034317Z"
    },
    {
      "generated_at": "2026-07-08T06:11:13.898846+00:00",
      "index_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260708T061113Z/index.json",
      "item_count": 20,
      "manifest_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260708T061113Z/manifest.json",
      "run_id": "20260708T061113Z"
    },
    {
      "generated_at": "2026-07-08T11:19:57.541711+00:00",
      "index_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260708T111957Z/index.json",
      "item_count": 20,
      "manifest_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260708T111957Z/manifest.json",
      "run_id": "20260708T111957Z"
    },
    {
      "generated_at": "2026-07-08T16:54:06.319728+00:00",
      "index_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260708T165406Z/index.json",
      "item_count": 20,
      "manifest_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260708T165406Z/manifest.json",
      "run_id": "20260708T165406Z"
    },
    {
      "generated_at": "2026-07-08T22:28:15.678261+00:00",
      "index_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260708T222815Z/index.json",
      "item_count": 20,
      "manifest_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260708T222815Z/manifest.json",
      "run_id": "20260708T222815Z"
    },
    {
      "generated_at": "2026-07-09T07:02:53.364205+00:00",
      "index_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260709T070253Z/index.json",
      "item_count": 20,
      "manifest_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260709T070253Z/manifest.json",
      "run_id": "20260709T070253Z"
    },
    {
      "generated_at": "2026-07-09T11:52:59.428525+00:00",
      "index_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260709T115259Z/index.json",
      "item_count": 20,
      "manifest_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260709T115259Z/manifest.json",
      "run_id": "20260709T115259Z"
    },
    {
      "generated_at": "2026-07-09T12:18:32.045130+00:00",
      "index_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260709T121832Z/index.json",
      "item_count": 20,
      "manifest_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260709T121832Z/manifest.json",
      "run_id": "20260709T121832Z"
    },
    {
      "generated_at": "2026-07-09T22:45:54.779184+00:00",
      "index_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260709T224554Z/index.json",
      "item_count": 20,
      "manifest_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260709T224554Z/manifest.json",
      "run_id": "20260709T224554Z"
    },
    {
      "generated_at": "2026-07-10T07:00:12.878999+00:00",
      "index_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260710T070012Z/index.json",
      "item_count": 20,
      "manifest_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260710T070012Z/manifest.json",
      "run_id": "20260710T070012Z"
    },
    {
      "generated_at": "2026-07-10T12:11:19.009273+00:00",
      "index_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260710T121119Z/index.json",
      "item_count": 20,
      "manifest_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260710T121119Z/manifest.json",
      "run_id": "20260710T121119Z"
    },
    {
      "generated_at": "2026-07-10T22:29:20.755460+00:00",
      "index_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260710T222920Z/index.json",
      "item_count": 20,
      "manifest_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260710T222920Z/manifest.json",
      "run_id": "20260710T222920Z"
    },
    {
      "generated_at": "2026-07-11T02:09:15.365217+00:00",
      "index_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260711T020915Z/index.json",
      "item_count": 20,
      "manifest_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260711T020915Z/manifest.json",
      "run_id": "20260711T020915Z"
    },
    {
      "generated_at": "2026-07-11T05:57:49.533050+00:00",
      "index_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260711T055749Z/index.json",
      "item_count": 20,
      "manifest_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260711T055749Z/manifest.json",
      "run_id": "20260711T055749Z"
    },
    {
      "generated_at": "2026-07-11T10:38:06.218261+00:00",
      "index_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260711T103806Z/index.json",
      "item_count": 20,
      "manifest_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260711T103806Z/manifest.json",
      "run_id": "20260711T103806Z"
    },
    {
      "generated_at": "2026-07-11T16:14:47.177813+00:00",
      "index_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260711T161447Z/index.json",
      "item_count": 20,
      "manifest_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260711T161447Z/manifest.json",
      "run_id": "20260711T161447Z"
    },
    {
      "generated_at": "2026-07-11T22:12:57.492624+00:00",
      "index_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260711T221257Z/index.json",
      "item_count": 20,
      "manifest_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260711T221257Z/manifest.json",
      "run_id": "20260711T221257Z"
    },
    {
      "generated_at": "2026-07-12T06:16:43.399132+00:00",
      "index_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260712T061643Z/index.json",
      "item_count": 20,
      "manifest_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260712T061643Z/manifest.json",
      "run_id": "20260712T061643Z"
    },
    {
      "generated_at": "2026-07-12T10:47:58.759562+00:00",
      "index_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260712T104758Z/index.json",
      "item_count": 20,
      "manifest_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260712T104758Z/manifest.json",
      "run_id": "20260712T104758Z"
    },
    {
      "generated_at": "2026-07-12T16:16:49.945236+00:00",
      "index_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260712T161649Z/index.json",
      "item_count": 20,
      "manifest_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260712T161649Z/manifest.json",
      "run_id": "20260712T161649Z"
    },
    {
      "generated_at": "2026-07-12T22:12:57.050896+00:00",
      "index_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260712T221257Z/index.json",
      "item_count": 20,
      "manifest_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260712T221257Z/manifest.json",
      "run_id": "20260712T221257Z"
    },
    {
      "generated_at": "2026-07-13T06:35:21.024861+00:00",
      "index_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260713T063521Z/index.json",
      "item_count": 20,
      "manifest_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260713T063521Z/manifest.json",
      "run_id": "20260713T063521Z"
    },
    {
      "generated_at": "2026-07-13T17:27:50.920719+00:00",
      "index_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260713T172750Z/index.json",
      "item_count": 20,
      "manifest_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260713T172750Z/manifest.json",
      "run_id": "20260713T172750Z"
    },
    {
      "generated_at": "2026-07-13T22:15:51.711520+00:00",
      "index_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260713T221551Z/index.json",
      "item_count": 20,
      "manifest_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260713T221551Z/manifest.json",
      "run_id": "20260713T221551Z"
    },
    {
      "generated_at": "2026-07-14T04:22:24.027032+00:00",
      "index_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260714T042224Z/index.json",
      "item_count": 20,
      "manifest_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260714T042224Z/manifest.json",
      "run_id": "20260714T042224Z"
    },
    {
      "generated_at": "2026-07-14T05:45:12.987947+00:00",
      "index_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260714T054512Z/index.json",
      "item_count": 20,
      "manifest_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260714T054512Z/manifest.json",
      "run_id": "20260714T054512Z"
    },
    {
      "generated_at": "2026-07-14T11:00:07.935926+00:00",
      "index_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260714T110007Z/index.json",
      "item_count": 20,
      "manifest_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260714T110007Z/manifest.json",
      "run_id": "20260714T110007Z"
    },
    {
      "generated_at": "2026-07-14T16:44:06.039761+00:00",
      "index_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260714T164406Z/index.json",
      "item_count": 20,
      "manifest_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260714T164406Z/manifest.json",
      "run_id": "20260714T164406Z"
    },
    {
      "generated_at": "2026-07-14T22:21:11.921259+00:00",
      "index_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260714T222111Z/index.json",
      "item_count": 20,
      "manifest_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260714T222111Z/manifest.json",
      "run_id": "20260714T222111Z"
    },
    {
      "generated_at": "2026-07-15T05:44:59.132259+00:00",
      "index_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260715T054459Z/index.json",
      "item_count": 20,
      "manifest_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260715T054459Z/manifest.json",
      "run_id": "20260715T054459Z"
    },
    {
      "generated_at": "2026-07-15T11:06:22.729441+00:00",
      "index_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260715T110622Z/index.json",
      "item_count": 20,
      "manifest_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260715T110622Z/manifest.json",
      "run_id": "20260715T110622Z"
    },
    {
      "generated_at": "2026-07-15T16:49:57.721607+00:00",
      "index_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260715T164957Z/index.json",
      "item_count": 20,
      "manifest_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260715T164957Z/manifest.json",
      "run_id": "20260715T164957Z"
    },
    {
      "generated_at": "2026-07-15T22:19:56.716942+00:00",
      "index_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260715T221956Z/index.json",
      "item_count": 20,
      "manifest_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260715T221956Z/manifest.json",
      "run_id": "20260715T221956Z"
    },
    {
      "generated_at": "2026-07-16T05:58:45.622512+00:00",
      "index_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260716T055845Z/index.json",
      "item_count": 20,
      "manifest_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260716T055845Z/manifest.json",
      "run_id": "20260716T055845Z"
    },
    {
      "generated_at": "2026-07-16T11:16:01.044824+00:00",
      "index_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260716T111601Z/index.json",
      "item_count": 20,
      "manifest_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260716T111601Z/manifest.json",
      "run_id": "20260716T111601Z"
    },
    {
      "generated_at": "2026-07-16T13:56:21.183278+00:00",
      "index_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260716T135621Z/index.json",
      "item_count": 20,
      "manifest_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260716T135621Z/manifest.json",
      "run_id": "20260716T135621Z"
    },
    {
      "generated_at": "2026-07-16T16:47:06.335604+00:00",
      "index_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260716T164706Z/index.json",
      "item_count": 20,
      "manifest_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260716T164706Z/manifest.json",
      "run_id": "20260716T164706Z"
    },
    {
      "generated_at": "2026-07-16T22:20:35.950070+00:00",
      "index_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260716T222035Z/index.json",
      "item_count": 20,
      "manifest_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260716T222035Z/manifest.json",
      "run_id": "20260716T222035Z"
    },
    {
      "generated_at": "2026-07-17T06:03:36.743265+00:00",
      "index_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260717T060336Z/index.json",
      "item_count": 20,
      "manifest_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260717T060336Z/manifest.json",
      "run_id": "20260717T060336Z"
    },
    {
      "generated_at": "2026-07-17T11:01:42.936663+00:00",
      "index_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260717T110142Z/index.json",
      "item_count": 19,
      "manifest_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260717T110142Z/manifest.json",
      "run_id": "20260717T110142Z"
    },
    {
      "generated_at": "2026-07-17T16:40:48.535858+00:00",
      "index_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260717T164048Z/index.json",
      "item_count": 20,
      "manifest_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260717T164048Z/manifest.json",
      "run_id": "20260717T164048Z"
    },
    {
      "generated_at": "2026-07-17T22:11:01.848959+00:00",
      "index_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260717T221101Z/index.json",
      "item_count": 20,
      "manifest_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260717T221101Z/manifest.json",
      "run_id": "20260717T221101Z"
    },
    {
      "generated_at": "2026-07-18T05:15:45.435868+00:00",
      "index_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260718T051545Z/index.json",
      "item_count": 20,
      "manifest_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260718T051545Z/manifest.json",
      "run_id": "20260718T051545Z"
    },
    {
      "generated_at": "2026-07-18T05:40:21.085138+00:00",
      "index_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260718T054021Z/index.json",
      "item_count": 20,
      "manifest_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260718T054021Z/manifest.json",
      "run_id": "20260718T054021Z"
    },
    {
      "generated_at": "2026-07-18T07:18:58.163361+00:00",
      "index_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260718T071858Z/index.json",
      "item_count": 20,
      "manifest_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260718T071858Z/manifest.json",
      "run_id": "20260718T071858Z"
    },
    {
      "generated_at": "2026-07-18T08:06:28.393463+00:00",
      "index_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260718T080628Z/index.json",
      "item_count": 20,
      "manifest_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260718T080628Z/manifest.json",
      "run_id": "20260718T080628Z"
    },
    {
      "generated_at": "2026-07-18T08:48:55.358984+00:00",
      "index_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260718T084855Z/index.json",
      "item_count": 20,
      "manifest_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260718T084855Z/manifest.json",
      "run_id": "20260718T084855Z"
    },
    {
      "generated_at": "2026-07-18T10:36:07.879428+00:00",
      "index_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260718T103607Z/index.json",
      "item_count": 20,
      "manifest_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260718T103607Z/manifest.json",
      "run_id": "20260718T103607Z"
    },
    {
      "generated_at": "2026-07-18T10:44:47.144887+00:00",
      "index_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260718T104447Z/index.json",
      "item_count": 20,
      "manifest_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260718T104447Z/manifest.json",
      "run_id": "20260718T104447Z"
    },
    {
      "generated_at": "2026-07-18T16:15:45.753026+00:00",
      "index_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260718T161545Z/index.json",
      "item_count": 20,
      "manifest_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260718T161545Z/manifest.json",
      "run_id": "20260718T161545Z"
    },
    {
      "generated_at": "2026-07-18T22:12:35.316091+00:00",
      "index_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260718T221235Z/index.json",
      "item_count": 20,
      "manifest_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260718T221235Z/manifest.json",
      "run_id": "20260718T221235Z"
    },
    {
      "generated_at": "2026-07-19T06:12:21.404589+00:00",
      "index_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260719T061221Z/index.json",
      "item_count": 20,
      "manifest_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260719T061221Z/manifest.json",
      "run_id": "20260719T061221Z"
    },
    {
      "generated_at": "2026-07-19T10:50:23.865780+00:00",
      "index_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260719T105023Z/index.json",
      "item_count": 20,
      "manifest_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260719T105023Z/manifest.json",
      "run_id": "20260719T105023Z"
    },
    {
      "generated_at": "2026-07-19T16:16:18.196710+00:00",
      "index_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260719T161618Z/index.json",
      "item_count": 20,
      "manifest_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260719T161618Z/manifest.json",
      "run_id": "20260719T161618Z"
    },
    {
      "generated_at": "2026-07-19T22:18:23.760026+00:00",
      "index_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260719T221823Z/index.json",
      "item_count": 20,
      "manifest_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260719T221823Z/manifest.json",
      "run_id": "20260719T221823Z"
    },
    {
      "generated_at": "2026-07-20T06:30:49.294877+00:00",
      "index_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260720T063049Z/index.json",
      "item_count": 20,
      "manifest_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260720T063049Z/manifest.json",
      "run_id": "20260720T063049Z"
    },
    {
      "generated_at": "2026-07-20T12:02:06.248969+00:00",
      "index_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260720T120206Z/index.json",
      "item_count": 19,
      "manifest_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260720T120206Z/manifest.json",
      "run_id": "20260720T120206Z"
    },
    {
      "generated_at": "2026-07-20T22:23:15.724096+00:00",
      "index_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260720T222315Z/index.json",
      "item_count": 20,
      "manifest_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260720T222315Z/manifest.json",
      "run_id": "20260720T222315Z"
    },
    {
      "generated_at": "2026-07-21T06:15:18.878218+00:00",
      "index_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260721T061518Z/index.json",
      "item_count": 20,
      "manifest_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260721T061518Z/manifest.json",
      "run_id": "20260721T061518Z"
    },
    {
      "generated_at": "2026-07-21T11:22:31.092463+00:00",
      "index_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260721T112231Z/index.json",
      "item_count": 20,
      "manifest_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260721T112231Z/manifest.json",
      "run_id": "20260721T112231Z"
    },
    {
      "generated_at": "2026-07-21T16:54:42.631411+00:00",
      "index_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260721T165442Z/index.json",
      "item_count": 20,
      "manifest_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260721T165442Z/manifest.json",
      "run_id": "20260721T165442Z"
    },
    {
      "generated_at": "2026-07-21T22:16:55.202825+00:00",
      "index_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260721T221655Z/index.json",
      "item_count": 20,
      "manifest_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260721T221655Z/manifest.json",
      "run_id": "20260721T221655Z"
    },
    {
      "generated_at": "2026-07-22T06:09:31.116119+00:00",
      "index_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260722T060931Z/index.json",
      "item_count": 19,
      "manifest_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260722T060931Z/manifest.json",
      "run_id": "20260722T060931Z"
    },
    {
      "generated_at": "2026-07-22T11:54:21.205769+00:00",
      "index_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260722T115421Z/index.json",
      "item_count": 20,
      "manifest_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260722T115421Z/manifest.json",
      "run_id": "20260722T115421Z"
    },
    {
      "generated_at": "2026-07-22T16:55:09.676737+00:00",
      "index_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260722T165509Z/index.json",
      "item_count": 19,
      "manifest_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260722T165509Z/manifest.json",
      "run_id": "20260722T165509Z"
    },
    {
      "generated_at": "2026-07-22T22:34:43.488472+00:00",
      "index_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260722T223443Z/index.json",
      "item_count": 20,
      "manifest_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260722T223443Z/manifest.json",
      "run_id": "20260722T223443Z"
    },
    {
      "generated_at": "2026-07-23T06:15:47.910601+00:00",
      "index_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260723T061547Z/index.json",
      "item_count": 20,
      "manifest_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260723T061547Z/manifest.json",
      "run_id": "20260723T061547Z"
    },
    {
      "generated_at": "2026-07-23T11:24:31.912933+00:00",
      "index_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260723T112431Z/index.json",
      "item_count": 20,
      "manifest_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260723T112431Z/manifest.json",
      "run_id": "20260723T112431Z"
    },
    {
      "generated_at": "2026-07-23T17:12:17.074327+00:00",
      "index_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260723T171217Z/index.json",
      "item_count": 20,
      "manifest_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260723T171217Z/manifest.json",
      "run_id": "20260723T171217Z"
    },
    {
      "generated_at": "2026-07-23T22:25:57.500864+00:00",
      "index_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260723T222557Z/index.json",
      "item_count": 18,
      "manifest_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260723T222557Z/manifest.json",
      "run_id": "20260723T222557Z"
    },
    {
      "generated_at": "2026-07-24T06:11:50.488089+00:00",
      "index_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260724T061150Z/index.json",
      "item_count": 20,
      "manifest_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260724T061150Z/manifest.json",
      "run_id": "20260724T061150Z"
    },
    {
      "generated_at": "2026-07-24T11:17:24.450729+00:00",
      "index_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260724T111724Z/index.json",
      "item_count": 20,
      "manifest_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260724T111724Z/manifest.json",
      "run_id": "20260724T111724Z"
    },
    {
      "generated_at": "2026-07-24T17:03:51.674499+00:00",
      "index_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260724T170351Z/index.json",
      "item_count": 20,
      "manifest_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260724T170351Z/manifest.json",
      "run_id": "20260724T170351Z"
    },
    {
      "generated_at": "2026-07-24T22:32:54.590377+00:00",
      "index_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260724T223254Z/index.json",
      "item_count": 20,
      "manifest_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260724T223254Z/manifest.json",
      "run_id": "20260724T223254Z"
    },
    {
      "generated_at": "2026-07-25T06:01:25.157235+00:00",
      "index_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260725T060125Z/index.json",
      "item_count": 20,
      "manifest_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260725T060125Z/manifest.json",
      "run_id": "20260725T060125Z"
    },
    {
      "generated_at": "2026-07-25T10:49:16.264752+00:00",
      "index_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260725T104916Z/index.json",
      "item_count": 20,
      "manifest_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260725T104916Z/manifest.json",
      "run_id": "20260725T104916Z"
    },
    {
      "generated_at": "2026-07-25T22:18:48.592051+00:00",
      "index_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260725T221848Z/index.json",
      "item_count": 20,
      "manifest_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260725T221848Z/manifest.json",
      "run_id": "20260725T221848Z"
    },
    {
      "generated_at": "2026-07-26T06:20:24.762943+00:00",
      "index_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260726T062024Z/index.json",
      "item_count": 20,
      "manifest_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260726T062024Z/manifest.json",
      "run_id": "20260726T062024Z"
    },
    {
      "generated_at": "2026-07-26T11:02:35.080238+00:00",
      "index_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260726T110235Z/index.json",
      "item_count": 20,
      "manifest_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260726T110235Z/manifest.json",
      "run_id": "20260726T110235Z"
    },
    {
      "generated_at": "2026-07-26T16:20:03.607945+00:00",
      "index_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260726T162003Z/index.json",
      "item_count": 20,
      "manifest_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260726T162003Z/manifest.json",
      "run_id": "20260726T162003Z"
    },
    {
      "generated_at": "2026-07-26T22:19:42.106755+00:00",
      "index_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260726T221942Z/index.json",
      "item_count": 20,
      "manifest_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260726T221942Z/manifest.json",
      "run_id": "20260726T221942Z"
    },
    {
      "generated_at": "2026-07-27T06:51:26.039235+00:00",
      "index_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260727T065126Z/index.json",
      "item_count": 20,
      "manifest_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260727T065126Z/manifest.json",
      "run_id": "20260727T065126Z"
    },
    {
      "generated_at": "2026-07-27T12:41:33.722695+00:00",
      "index_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260727T124133Z/index.json",
      "item_count": 19,
      "manifest_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260727T124133Z/manifest.json",
      "run_id": "20260727T124133Z"
    },
    {
      "generated_at": "2026-07-27T17:19:33.896931+00:00",
      "index_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260727T171933Z/index.json",
      "item_count": 19,
      "manifest_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260727T171933Z/manifest.json",
      "run_id": "20260727T171933Z"
    },
    {
      "generated_at": "2026-07-27T22:36:32.864979+00:00",
      "index_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260727T223632Z/index.json",
      "item_count": 20,
      "manifest_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260727T223632Z/manifest.json",
      "run_id": "20260727T223632Z"
    },
    {
      "generated_at": "2026-07-28T06:08:40.757405+00:00",
      "index_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260728T060840Z/index.json",
      "item_count": 20,
      "manifest_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260728T060840Z/manifest.json",
      "run_id": "20260728T060840Z"
    },
    {
      "generated_at": "2026-07-28T11:37:20.744245+00:00",
      "index_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260728T113720Z/index.json",
      "item_count": 20,
      "manifest_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260728T113720Z/manifest.json",
      "run_id": "20260728T113720Z"
    },
    {
      "generated_at": "2026-07-28T17:03:14.398101+00:00",
      "index_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260728T170314Z/index.json",
      "item_count": 20,
      "manifest_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260728T170314Z/manifest.json",
      "run_id": "20260728T170314Z"
    },
    {
      "generated_at": "2026-07-28T22:31:34.667466+00:00",
      "index_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260728T223134Z/index.json",
      "item_count": 20,
      "manifest_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260728T223134Z/manifest.json",
      "run_id": "20260728T223134Z"
    },
    {
      "generated_at": "2026-07-29T06:27:52.585342+00:00",
      "index_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260729T062752Z/index.json",
      "item_count": 20,
      "manifest_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260729T062752Z/manifest.json",
      "run_id": "20260729T062752Z"
    },
    {
      "generated_at": "2026-07-29T11:44:32.545086+00:00",
      "index_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260729T114432Z/index.json",
      "item_count": 20,
      "manifest_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260729T114432Z/manifest.json",
      "run_id": "20260729T114432Z"
    },
    {
      "generated_at": "2026-07-29T16:48:26.356045+00:00",
      "index_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260729T164826Z/index.json",
      "item_count": 20,
      "manifest_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260729T164826Z/manifest.json",
      "run_id": "20260729T164826Z"
    },
    {
      "generated_at": "2026-07-29T22:24:41.581034+00:00",
      "index_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260729T222441Z/index.json",
      "item_count": 20,
      "manifest_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260729T222441Z/manifest.json",
      "run_id": "20260729T222441Z"
    },
    {
      "generated_at": "2026-07-30T06:05:04.983651+00:00",
      "index_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260730T060504Z/index.json",
      "item_count": 20,
      "manifest_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260730T060504Z/manifest.json",
      "run_id": "20260730T060504Z"
    },
    {
      "generated_at": "2026-07-30T11:26:43.206286+00:00",
      "index_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260730T112643Z/index.json",
      "item_count": 20,
      "manifest_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260730T112643Z/manifest.json",
      "run_id": "20260730T112643Z"
    },
    {
      "generated_at": "2026-07-30T22:48:32.264980+00:00",
      "index_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260730T224832Z/index.json",
      "item_count": 20,
      "manifest_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260730T224832Z/manifest.json",
      "run_id": "20260730T224832Z"
    },
    {
      "generated_at": "2026-07-31T06:30:57.677712+00:00",
      "index_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260731T063057Z/index.json",
      "item_count": 20,
      "manifest_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260731T063057Z/manifest.json",
      "run_id": "20260731T063057Z"
    },
    {
      "generated_at": "2026-07-31T11:50:01.825661+00:00",
      "index_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260731T115001Z/index.json",
      "item_count": 20,
      "manifest_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260731T115001Z/manifest.json",
      "run_id": "20260731T115001Z"
    },
    {
      "generated_at": "2026-07-31T17:12:56.689659+00:00",
      "index_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260731T171256Z/index.json",
      "item_count": 20,
      "manifest_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260731T171256Z/manifest.json",
      "run_id": "20260731T171256Z"
    },
    {
      "generated_at": "2026-07-31T22:22:22.468848+00:00",
      "index_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260731T222222Z/index.json",
      "item_count": 20,
      "manifest_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260731T222222Z/manifest.json",
      "run_id": "20260731T222222Z"
    },
    {
      "generated_at": "2026-08-01T06:18:01.437367+00:00",
      "index_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260801T061801Z/index.json",
      "item_count": 20,
      "manifest_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260801T061801Z/manifest.json",
      "run_id": "20260801T061801Z"
    },
    {
      "generated_at": "2026-08-01T10:56:18.926483+00:00",
      "index_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260801T105618Z/index.json",
      "item_count": 20,
      "manifest_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260801T105618Z/manifest.json",
      "run_id": "20260801T105618Z"
    },
    {
      "generated_at": "2026-08-01T16:19:24.418738+00:00",
      "index_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260801T161924Z/index.json",
      "item_count": 20,
      "manifest_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260801T161924Z/manifest.json",
      "run_id": "20260801T161924Z"
    },
    {
      "generated_at": "2026-08-01T22:17:53.422344+00:00",
      "index_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260801T221753Z/index.json",
      "item_count": 20,
      "manifest_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260801T221753Z/manifest.json",
      "run_id": "20260801T221753Z"
    },
    {
      "generated_at": "2026-08-02T06:18:06.892042+00:00",
      "index_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260802T061806Z/index.json",
      "item_count": 20,
      "manifest_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260802T061806Z/manifest.json",
      "run_id": "20260802T061806Z"
    },
    {
      "generated_at": "2026-08-02T11:02:40.592592+00:00",
      "index_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260802T110240Z/index.json",
      "item_count": 20,
      "manifest_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260802T110240Z/manifest.json",
      "run_id": "20260802T110240Z"
    },
    {
      "generated_at": "2026-08-02T16:27:19.206976+00:00",
      "index_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260802T162719Z/index.json",
      "item_count": 20,
      "manifest_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260802T162719Z/manifest.json",
      "run_id": "20260802T162719Z"
    },
    {
      "generated_at": "2026-08-02T22:16:59.926550+00:00",
      "index_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260802T221659Z/index.json",
      "item_count": 20,
      "manifest_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260802T221659Z/manifest.json",
      "run_id": "20260802T221659Z"
    },
    {
      "generated_at": "2026-08-03T06:43:56.527190+00:00",
      "index_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260803T064356Z/index.json",
      "item_count": 20,
      "manifest_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260803T064356Z/manifest.json",
      "run_id": "20260803T064356Z"
    },
    {
      "generated_at": "2026-08-03T12:47:16.166004+00:00",
      "index_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260803T124716Z/index.json",
      "item_count": 20,
      "manifest_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260803T124716Z/manifest.json",
      "run_id": "20260803T124716Z"
    },
    {
      "generated_at": "2026-08-03T17:47:17.844388+00:00",
      "index_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260803T174717Z/index.json",
      "item_count": 19,
      "manifest_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260803T174717Z/manifest.json",
      "run_id": "20260803T174717Z"
    },
    {
      "generated_at": "2026-08-03T22:33:22.644212+00:00",
      "index_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260803T223322Z/index.json",
      "item_count": 20,
      "manifest_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260803T223322Z/manifest.json",
      "run_id": "20260803T223322Z"
    },
    {
      "generated_at": "2026-08-04T06:16:58.850514+00:00",
      "index_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260804T061658Z/index.json",
      "item_count": 20,
      "manifest_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260804T061658Z/manifest.json",
      "run_id": "20260804T061658Z"
    },
    {
      "generated_at": "2026-08-04T11:43:28.510958+00:00",
      "index_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260804T114328Z/index.json",
      "item_count": 20,
      "manifest_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260804T114328Z/manifest.json",
      "run_id": "20260804T114328Z"
    },
    {
      "generated_at": "2026-08-04T17:15:42.522273+00:00",
      "index_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260804T171542Z/index.json",
      "item_count": 17,
      "manifest_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260804T171542Z/manifest.json",
      "run_id": "20260804T171542Z"
    },
    {
      "generated_at": "2026-08-04T22:35:46.184184+00:00",
      "index_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260804T223546Z/index.json",
      "item_count": 20,
      "manifest_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260804T223546Z/manifest.json",
      "run_id": "20260804T223546Z"
    },
    {
      "generated_at": "2026-08-05T06:12:18.214956+00:00",
      "index_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260805T061218Z/index.json",
      "item_count": 20,
      "manifest_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260805T061218Z/manifest.json",
      "run_id": "20260805T061218Z"
    },
    {
      "generated_at": "2026-08-05T11:35:52.472520+00:00",
      "index_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260805T113552Z/index.json",
      "item_count": 20,
      "manifest_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260805T113552Z/manifest.json",
      "run_id": "20260805T113552Z"
    },
    {
      "generated_at": "2026-08-05T16:59:44.293691+00:00",
      "index_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260805T165944Z/index.json",
      "item_count": 20,
      "manifest_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260805T165944Z/manifest.json",
      "run_id": "20260805T165944Z"
    },
    {
      "generated_at": "2026-08-05T22:37:15.181621+00:00",
      "index_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260805T223715Z/index.json",
      "item_count": 19,
      "manifest_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260805T223715Z/manifest.json",
      "run_id": "20260805T223715Z"
    },
    {
      "generated_at": "2026-08-06T06:17:54.813925+00:00",
      "index_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260806T061754Z/index.json",
      "item_count": 20,
      "manifest_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260806T061754Z/manifest.json",
      "run_id": "20260806T061754Z"
    },
    {
      "generated_at": "2026-08-06T11:45:33.138666+00:00",
      "index_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260806T114533Z/index.json",
      "item_count": 20,
      "manifest_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260806T114533Z/manifest.json",
      "run_id": "20260806T114533Z"
    },
    {
      "generated_at": "2026-08-07T05:11:40.794071+00:00",
      "index_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260807T051140Z/index.json",
      "item_count": 20,
      "manifest_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260807T051140Z/manifest.json",
      "run_id": "20260807T051140Z"
    },
    {
      "generated_at": "2026-08-07T10:26:46.514965+00:00",
      "index_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260807T102646Z/index.json",
      "item_count": 18,
      "manifest_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260807T102646Z/manifest.json",
      "run_id": "20260807T102646Z"
    },
    {
      "generated_at": "2026-08-07T16:20:46.934055+00:00",
      "index_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260807T162046Z/index.json",
      "item_count": 20,
      "manifest_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260807T162046Z/manifest.json",
      "run_id": "20260807T162046Z"
    },
    {
      "generated_at": "2026-08-07T22:04:57.622945+00:00",
      "index_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260807T220457Z/index.json",
      "item_count": 20,
      "manifest_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260807T220457Z/manifest.json",
      "run_id": "20260807T220457Z"
    },
    {
      "generated_at": "2026-08-08T04:37:50.292254+00:00",
      "index_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260808T043750Z/index.json",
      "item_count": 20,
      "manifest_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260808T043750Z/manifest.json",
      "run_id": "20260808T043750Z"
    },
    {
      "generated_at": "2026-08-08T10:00:51.860646+00:00",
      "index_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260808T100051Z/index.json",
      "item_count": 19,
      "manifest_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260808T100051Z/manifest.json",
      "run_id": "20260808T100051Z"
    },
    {
      "generated_at": "2026-08-08T15:58:19.032463+00:00",
      "index_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260808T155819Z/index.json",
      "item_count": 19,
      "manifest_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260808T155819Z/manifest.json",
      "run_id": "20260808T155819Z"
    },
    {
      "generated_at": "2026-08-08T21:56:35.450374+00:00",
      "index_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260808T215635Z/index.json",
      "item_count": 19,
      "manifest_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260808T215635Z/manifest.json",
      "run_id": "20260808T215635Z"
    },
    {
      "generated_at": "2026-08-09T04:44:12.838301+00:00",
      "index_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260809T044412Z/index.json",
      "item_count": 20,
      "manifest_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260809T044412Z/manifest.json",
      "run_id": "20260809T044412Z"
    },
    {
      "generated_at": "2026-08-09T10:13:23.532584+00:00",
      "index_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260809T101323Z/index.json",
      "item_count": 20,
      "manifest_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260809T101323Z/manifest.json",
      "run_id": "20260809T101323Z"
    },
    {
      "generated_at": "2026-08-09T15:55:23.290441+00:00",
      "index_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260809T155523Z/index.json",
      "item_count": 20,
      "manifest_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260809T155523Z/manifest.json",
      "run_id": "20260809T155523Z"
    },
    {
      "generated_at": "2026-08-09T21:57:50.074105+00:00",
      "index_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260809T215750Z/index.json",
      "item_count": 20,
      "manifest_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260809T215750Z/manifest.json",
      "run_id": "20260809T215750Z"
    },
    {
      "generated_at": "2026-08-10T05:04:14.185247+00:00",
      "index_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260810T050414Z/index.json",
      "item_count": 20,
      "manifest_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260810T050414Z/manifest.json",
      "run_id": "20260810T050414Z"
    },
    {
      "generated_at": "2026-08-10T10:51:21.063429+00:00",
      "index_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260810T105121Z/index.json",
      "item_count": 20,
      "manifest_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260810T105121Z/manifest.json",
      "run_id": "20260810T105121Z"
    },
    {
      "generated_at": "2026-08-10T16:21:56.094648+00:00",
      "index_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260810T162156Z/index.json",
      "item_count": 20,
      "manifest_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260810T162156Z/manifest.json",
      "run_id": "20260810T162156Z"
    },
    {
      "generated_at": "2026-08-10T22:09:19.106897+00:00",
      "index_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260810T220919Z/index.json",
      "item_count": 20,
      "manifest_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260810T220919Z/manifest.json",
      "run_id": "20260810T220919Z"
    },
    {
      "generated_at": "2026-08-11T04:47:29.424605+00:00",
      "index_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260811T044729Z/index.json",
      "item_count": 20,
      "manifest_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260811T044729Z/manifest.json",
      "run_id": "20260811T044729Z"
    },
    {
      "generated_at": "2026-08-11T10:25:39.592098+00:00",
      "index_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260811T102539Z/index.json",
      "item_count": 20,
      "manifest_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260811T102539Z/manifest.json",
      "run_id": "20260811T102539Z"
    },
    {
      "generated_at": "2026-08-11T22:18:06.707962+00:00",
      "index_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260811T221806Z/index.json",
      "item_count": 20,
      "manifest_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260811T221806Z/manifest.json",
      "run_id": "20260811T221806Z"
    },
    {
      "generated_at": "2026-08-12T05:14:28.122778+00:00",
      "index_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260812T051428Z/index.json",
      "item_count": 20,
      "manifest_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260812T051428Z/manifest.json",
      "run_id": "20260812T051428Z"
    },
    {
      "generated_at": "2026-08-12T10:39:32.977657+00:00",
      "index_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260812T103932Z/index.json",
      "item_count": 20,
      "manifest_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260812T103932Z/manifest.json",
      "run_id": "20260812T103932Z"
    }
  ],
  "safety": {
    "auto_remediation_allowed": false,
    "exploit_detail_allowed": false,
    "external_execution_allowed": false,
    "github_issue_creation_allowed": false,
    "indexing_allowed": true,
    "noindex_removal_allowed": true,
    "noindex_required": false,
    "patch_allowed": false,
    "public_launch_allowed": true,
    "public_safe_only": true,
    "raw_source_included": false,
    "read_only": true,
    "scan_allowed": false,
    "search_console_registered": true,
    "signal_radar_integration_allowed": false
  },
  "schema_version": "v0.1",
  "webmcp_future_contract": {
    "annotations": {
      "readOnlyHint": true,
      "untrustedContentHint": true
    },
    "api": "document.modelContext",
    "auto_remediation_allowed": false,
    "cross_origin_exposure_allowed": false,
    "deploy_allowed": false,
    "enabled": true,
    "endpoint": null,
    "exposed_to": [],
    "external_execution_allowed": false,
    "fallback_api": "navigator.modelContext",
    "fetch_allowed": false,
    "github_issue_creation_allowed": false,
    "mode": "browser_imperative_progressive_enhancement",
    "mutation_allowed": false,
    "notes": "Browser WebMCP tools are registered only when document.modelContext or navigator.modelContext is available. They read existing public-safe static JSON and perform no network fetch, deploy, scan, patch, or mutation.",
    "planned": false,
    "scan_allowed": false,
    "tool_output_max_items": 10,
    "tool_output_target_max_chars": 1500,
    "tools": [
      "vuln_signal_search",
      "vuln_signal_get_item",
      "vuln_signal_list_priority"
    ]
  }
}