<!doctype html><html lang="en"><head><meta charset="utf-8">
<meta name="viewport" content="width=device-width,initial-scale=1">
<title>Vuln Signal Radar | CVE, KEV &amp; EPSS Signals for Defenders</title><meta name="description" content="Track public-safe CVE, KEV, EPSS, and vendor-advisory signals for defender triage with source, freshness, and safety context."><meta name="robots" content="index,follow"><link rel="canonical" href="https://vuln.signal-radar.com/"><meta property="og:type" content="website"><meta property="og:site_name" content="Signal-Radar.com"><meta property="og:title" content="Vuln Signal Radar | CVE, KEV &amp; EPSS Signals for Defenders"><meta property="og:description" content="Track public-safe CVE, KEV, EPSS, and vendor-advisory signals for defender triage with source, freshness, and safety context."><meta property="og:url" content="https://vuln.signal-radar.com/"><meta property="og:image" content="https://vuln.signal-radar.com/assets/vuln/hero-vulnerability-intelligence.webp"><meta name="twitter:card" content="summary_large_image"><meta name="twitter:title" content="Vuln Signal Radar | CVE, KEV &amp; EPSS Signals for Defenders"><meta name="twitter:description" content="Track public-safe CVE, KEV, EPSS, and vendor-advisory signals for defender triage with source, freshness, and safety context."><meta name="twitter:image" content="https://vuln.signal-radar.com/assets/vuln/hero-vulnerability-intelligence.webp"><link rel="icon" href="/assets/vuln/favicon.webp" type="image/webp"><link rel="icon" href="/assets/vuln/favicon-32.png" type="image/png" sizes="32x32"><link rel="apple-touch-icon" href="/assets/vuln/apple-touch-icon.png"><link rel="agent" href="/agent.json" type="application/json"><link rel="alternate" type="application/ld+json" href="/data/v1/graph/latest.jsonld"><link rel="stylesheet" href="/assets/vuln/dashboard.css?v=20260708-vendor-wrap-1"><link rel="stylesheet" href="/assets/preview.css?v=20260708-vendor-wrap-1"></head><body>
<div class="app-shell public-dashboard" data-public-dashboard="true">
<header class="vsr-topnav">
<a class="brand" href="#dashboard" data-view-link="dashboard"><span class="radar-mark"><img src="/assets/vuln/logo-mark.svg" alt="" aria-hidden="true"></span><span>Vuln Signal Radar</span></a>
<nav class="top-tabs" aria-label="Primary"><a class="active" href="#dashboard" data-view-link="dashboard">Dashboard</a><a href="#signals" data-view-link="signals">Signals</a><a href="#sources" data-view-link="sources">Sources</a><a href="#watchlist" data-view-link="watchlist">Watchlist</a><a href="#reports" data-view-link="reports">Reports</a><a href="/about/">About</a></nav>
<label class="global-search" for="vuln-search"><span aria-hidden="true">⌕</span><input id="vuln-search" type="search" autocomplete="off" placeholder="Search CVE, vendor, product..."><kbd>⌘K</kbd></label>
</header>
<div class="dashboard-shell">
<aside class="vsr-sidebar">
<nav class="side-nav" aria-label="Dashboard sections"><a class="active" href="#dashboard" data-view-link="dashboard">▦ Overview</a><a href="#signals" data-view-link="signals">⌁ Live Feed <span id="side-feed-count">20</span></a><a href="#dashboard" data-view-link="dashboard" data-filter-shortcut="risk">♢ Risk Explorer</a><a href="#reports" data-view-link="reports">⌬ Defensive Paths</a><a href="#signals" data-view-link="signals" data-filter-shortcut="kev">⬡ KEV Tracker</a><a href="#dashboard" data-view-link="dashboard" data-filter-shortcut="epss">✣ EPSS Heatmap</a><a href="#sources" data-view-link="sources">⚭ Integrations</a><a href="#saved" data-view-link="saved">▱ Saved Views</a></nav>
<div class="side-meta" aria-label="Operational status">
<section class="side-card freshness"><h2>Data Freshness</h2><p><span class="live-dot"></span>Read-only public-safe data</p><div class="fresh-row generated-row"><span>Generated</span><div id="last-updated" class="compact-timestamp" title="Last generated 2026-07-08 12:43 JST / 2026-07-08 03:43 UTC" aria-label="Last generated 2026-07-08 12:43 JST / 2026-07-08 03:43 UTC"><strong>12:43 JST</strong><span>2026-07-08</span><small>UTC 03:43</small></div></div><div class="fresh-row"><span>Source health</span><strong>healthy</strong></div><div class="fresh-row"><span>Deploy mode</span><strong>fresh fetch</strong></div><div class="freshness-bars" id="age-histogram" aria-label="Age histogram"><div><span>0-24h</span><strong><i class="bar-fill bar-w-100"></i></strong><em>20</em></div><div><span>2-7d</span><strong><i class="bar-fill bar-w-0"></i></strong><em>0</em></div><div><span>8-30d</span><strong><i class="bar-fill bar-w-0"></i></strong><em>0</em></div><div><span>&gt;30d</span><strong><i class="bar-fill bar-w-0"></i></strong><em>0</em></div><div><span>unknown</span><strong><i class="bar-fill bar-w-0"></i></strong><em>0</em></div></div></section>
<section class="side-card archive-card"><h2>Archive</h2><p><span class="live-dot"></span>Static public-safe history surface</p><div class="fresh-row"><span>Latest run</span><strong id="archive-run-id">20260708T034317Z</strong></div><div class="fresh-row"><span>Archived CVEs</span><strong id="archive-count">74</strong></div><div class="fresh-row"><span>Timelines</span><strong>74</strong></div><div class="archive-links"><a href="https://vuln.signal-radar.com/archive/">Human archive</a><a href="https://vuln.signal-radar.com/data/vuln/archive/index.json" target="_blank" rel="noopener noreferrer">Archive index JSON</a><a href="https://vuln.signal-radar.com/data/vuln/archive/latest.json" target="_blank" rel="noopener noreferrer">Latest run JSON</a></div></section>
<section class="side-card"><h2>Safety Guardrails</h2><p><span class="live-dot"></span>Read-only public-safe controls are active</p><a class="inline-data-link" href="#settings" data-view-link="settings">View guardrails →</a></section>
</div>
</aside>
<main class="dashboard-main">
<section class="hero-panel view-panel" id="dashboard" data-view="dashboard">
<div><div class="demo-pill">public radar</div><h1>Prioritized Vulnerability Signals for Defenders</h1><p>Track CVE, KEV, EPSS, and vendor-advisory changes in one read-only radar—so teams can see what changed, why it matters, and what to verify next.</p></div>
<div class="radar-globe" aria-hidden="true"><span></span><span></span><span></span><i></i></div>
</section>
<section class="status-strip view-panel" id="status-strip" data-view="dashboard"><span class="status-chip on">indexable public surface</span><span class="status-chip on">read-only dataset</span><span class="status-chip on">public-safe sources</span><span class="status-chip on">external execution disabled</span><span class="status-chip on">auto remediation disabled</span></section>
<section class="private-stat-grid view-panel" id="private-stat-grid" data-view="dashboard"><article class="stat-card "><span class="stat-icon"><img src="/assets/vuln/kpi-new-cves.webp" alt="" aria-hidden="true" loading="lazy" decoding="async"></span><div><small>New CVEs</small><strong>20</strong><em>current public dataset</em></div></article><article class="stat-card critical"><span class="stat-icon"><img src="/assets/vuln/kpi-critical.webp" alt="" aria-hidden="true" loading="lazy" decoding="async"></span><div><small>Critical</small><strong>4</strong><em>canonical CVSS</em></div></article><article class="stat-card kev"><span class="stat-icon"><img src="/assets/vuln/kpi-kev.webp" alt="" aria-hidden="true" loading="lazy" decoding="async"></span><div><small>Known Exploited</small><strong>0</strong><em>KEV observed</em></div></article><article class="stat-card epss"><span class="stat-icon"><img src="/assets/vuln/kpi-high-epss.webp" alt="" aria-hidden="true" loading="lazy" decoding="async"></span><div><small>High EPSS percentile (≥70)</small><strong>7</strong><em>EPSS percentile observed</em></div></article><article class="stat-card "><span class="stat-icon"><img src="/assets/vuln/kpi-monitored-vendors.webp" alt="" aria-hidden="true" loading="lazy" decoding="async"></span><div><small>Monitored Vendors</small><strong>17</strong><em>from current data</em></div></article></section>
<section class="filter-toolbar view-panel" data-view="dashboard signals reports" aria-label="Signal filters">
<div class="filter-group search-group"><label class="feed-search" for="feed-search"><span>⌕</span><input id="feed-search" type="search" placeholder="Search in live feed..."></label></div>
<div class="filter-group chip-group" role="group" aria-label="Quick filters"><button class="filter-chip critical" data-severity-chip="CRITICAL" type="button" aria-label="Filter Critical severity">Critical</button><button class="filter-chip high" data-severity-chip="HIGH" type="button" aria-label="Filter High severity">High</button><button class="filter-chip kev" id="kev-chip" type="button" aria-label="Filter KEV listed">KEV</button><button class="filter-chip epss" id="epss-chip" type="button" aria-label="Filter EPSS percentile 70 or higher">EPSS ≥70</button></div>
<div class="filter-group select-group" role="group" aria-label="Structured filters"><select id="severity-filter" aria-label="Severity filter"><option value="all">Severity All</option><option value="CRITICAL">Critical</option><option value="HIGH">High</option><option value="MEDIUM">Medium</option><option value="LOW">Low</option><option value="NONE">None</option><option value="UNKNOWN">Unknown</option></select>
<select id="kev-filter" aria-label="KEV filter"><option value="all">KEV All</option><option value="yes">KEV listed</option><option value="no">Not listed</option></select>
<select id="source-filter" aria-label="Source filter"><option value="all">Source All</option><option value="NVD">NVD</option><option value="OSV">OSV</option><option value="CISA KEV">CISA KEV</option><option value="Vendor Advisory">Vendor Advisory</option></select>
<select id="vendor-filter" aria-label="Vendor filter"><option value="all">Vendor</option></select><select id="product-filter" aria-label="Product filter"><option value="all">Product</option></select><select id="time-filter" aria-label="Time range"><option value="all">Any time</option><option value="today">Today</option><option value="week">This week</option></select><select id="sort-select" aria-label="Sort"><option value="priority">Sort Priority</option><option value="updated">Observed</option><option value="epss">EPSS percentile</option><option value="cvss">CVSS Severity</option></select></div>
<div class="filter-group action-group"><button class="clear-button" id="filter-reset" type="button">Clear all</button><button class="icon-button" data-save-view type="button" aria-label="Save view">⚙</button></div>
</section>
<section class="dashboard-grid-mvp view-panel" id="signals" data-view="dashboard signals">
<div class="panel live-feed-panel view-panel" data-view="dashboard signals"><div class="panel-head"><h2>Live Vulnerability Feed <span class="live-label">READ-ONLY</span></h2><a href="#signals" data-view-link="signals">View all signals →</a></div><div id="live-feed" class="live-feed"><article class="feed-row" data-open-detail="CVE-2005-4459" tabindex="0"><span class="observed">2026-07-08</span><span class="live-dot"></span><div class="feed-title"><button class="linklike" data-open-detail="CVE-2005-4459" type="button">CVE-2005-4459</button><strong>defensive priority signal</strong></div><span class="severity-pill critical">CRITICAL</span><span class="epss-cell">EPSS <strong>0.1366 (96)</strong></span><span><span class="badge blue">NEW</span></span><span class="product-cell">vmware / ace</span><span class="summary-cell">NVD: Heap-based buffer overflow in the NAT networking components vmnat.exe and vmnet-natd in VMWare Workstation 5.5, GSX Server 3.2, ACE 1… <a class="handoff-link" href="https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2005-4459.md" target="_blank" rel="noopener noreferrer">Handoff</a></span><button class="bookmark" data-bookmark="CVE-2005-4459" type="button" aria-label="Toggle watchlist for CVE-2005-4459">♡</button><button class="kebab" data-open-detail="CVE-2005-4459" type="button" aria-label="Open CVE-2005-4459 detail">⋮</button></article><article class="feed-row" data-open-detail="CVE-2018-5353" tabindex="0"><span class="observed">2026-07-08</span><span class="live-dot"></span><div class="feed-title"><button class="linklike" data-open-detail="CVE-2018-5353" type="button">CVE-2018-5353</button><strong>defensive priority signal</strong></div><span class="severity-pill critical">CRITICAL</span><span class="epss-cell">EPSS <strong>0.0810 (94)</strong></span><span><span class="badge blue">NEW</span></span><span class="product-cell">zohocorp / manageengine_adselfservice_plus</span><span class="summary-cell">NVD: The custom GINA/CP module in Zoho ManageEngine ADSelfService Plus before 5.5 build 5517 allows remote attackers to execute code and es… <a class="handoff-link" href="https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2018-5353.md" target="_blank" rel="noopener noreferrer">Handoff</a></span><button class="bookmark" data-bookmark="CVE-2018-5353" type="button" aria-label="Toggle watchlist for CVE-2018-5353">♡</button><button class="kebab" data-open-detail="CVE-2018-5353" type="button" aria-label="Open CVE-2018-5353 detail">⋮</button></article><article class="feed-row" data-open-detail="CVE-2020-25466" tabindex="0"><span class="observed">2026-07-08</span><span class="live-dot"></span><div class="feed-title"><button class="linklike" data-open-detail="CVE-2020-25466" type="button">CVE-2020-25466</button><strong>defensive priority signal</strong></div><span class="severity-pill critical">CRITICAL</span><span class="epss-cell">EPSS <strong>0.0303 (86)</strong></span><span><span class="badge blue">NEW</span></span><span class="product-cell">crmeb / crmeb</span><span class="summary-cell">NVD: A SSRF vulnerability exists in the downloadimage interface of CRMEB 3.0, which can remotely download arbitrary files on the server and… <a class="handoff-link" href="https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-25466.md" target="_blank" rel="noopener noreferrer">Handoff</a></span><button class="bookmark" data-bookmark="CVE-2020-25466" type="button" aria-label="Toggle watchlist for CVE-2020-25466">♡</button><button class="kebab" data-open-detail="CVE-2020-25466" type="button" aria-label="Open CVE-2020-25466 detail">⋮</button></article><article class="feed-row" data-open-detail="CVE-2020-24193" tabindex="0"><span class="observed">2026-07-08</span><span class="live-dot"></span><div class="feed-title"><button class="linklike" data-open-detail="CVE-2020-24193" type="button">CVE-2020-24193</button><strong>defensive priority signal</strong></div><span class="severity-pill critical">CRITICAL</span><span class="epss-cell">EPSS <strong>0.0277 (85)</strong></span><span><span class="badge blue">NEW</span></span><span class="product-cell">daily_tracker_system_project / daily_tracker_system</span><span class="summary-cell">NVD: A SQL injection vulnerability in login in Sourcecodetester Daily Tracker System 1.0 allows unauthenticated user to execute authenticat… <a class="handoff-link" href="https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-24193.md" target="_blank" rel="noopener noreferrer">Handoff</a></span><button class="bookmark" data-bookmark="CVE-2020-24193" type="button" aria-label="Toggle watchlist for CVE-2020-24193">♡</button><button class="kebab" data-open-detail="CVE-2020-24193" type="button" aria-label="Open CVE-2020-24193 detail">⋮</button></article><article class="feed-row" data-open-detail="CVE-2018-5354" tabindex="0"><span class="observed">2026-07-08</span><span class="live-dot"></span><div class="feed-title"><button class="linklike" data-open-detail="CVE-2018-5354" type="button">CVE-2018-5354</button><strong>defensive priority signal</strong></div><span class="severity-pill high">HIGH</span><span class="epss-cell">EPSS <strong>0.0268 (84)</strong></span><span><span class="badge blue">NEW</span></span><span class="product-cell">anixis / password_reset_client</span><span class="summary-cell">NVD: The custom GINA/CP module in ANIXIS Password Reset Client before version 3.22 allows remote attackers to execute code and escalate pri… <a class="handoff-link" href="https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2018-5354.md" target="_blank" rel="noopener noreferrer">Handoff</a></span><button class="bookmark" data-bookmark="CVE-2018-5354" type="button" aria-label="Toggle watchlist for CVE-2018-5354">♡</button><button class="kebab" data-open-detail="CVE-2018-5354" type="button" aria-label="Open CVE-2018-5354 detail">⋮</button></article><article class="feed-row" data-open-detail="CVE-2020-23451" tabindex="0"><span class="observed">2026-07-08</span><span class="live-dot"></span><div class="feed-title"><button class="linklike" data-open-detail="CVE-2020-23451" type="button">CVE-2020-23451</button><strong>defensive priority signal</strong></div><span class="severity-pill high">HIGH</span><span class="epss-cell">EPSS <strong>0.0060 (44)</strong></span><span><span class="badge blue">NEW</span></span><span class="product-cell">spiceworks / spiceworks</span><span class="summary-cell">NVD: Spiceworks Version &lt;= 7.5.00107 is affected by CSRF which can lead to privilege escalation via &quot;/settings/v1/users&quot; function. <a class="handoff-link" href="https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-23451.md" target="_blank" rel="noopener noreferrer">Handoff</a></span><button class="bookmark" data-bookmark="CVE-2020-23451" type="button" aria-label="Toggle watchlist for CVE-2020-23451">♡</button><button class="kebab" data-open-detail="CVE-2020-23451" type="button" aria-label="Open CVE-2020-23451 detail">⋮</button></article><article class="feed-row" data-open-detail="CVE-2020-25514" tabindex="0"><span class="observed">2026-07-08</span><span class="live-dot"></span><div class="feed-title"><button class="linklike" data-open-detail="CVE-2020-25514" type="button">CVE-2020-25514</button><strong>defensive priority signal</strong></div><span class="severity-pill high">HIGH</span><span class="epss-cell">EPSS <strong>0.0063 (46)</strong></span><span><span class="badge blue">NEW</span></span><span class="product-cell">simple_library_management_system_project / simple_library_management_system</span><span class="summary-cell">NVD: Sourcecodester Simple Library Management System 1.0 is affected by Incorrect Access Control via the Login Panel, <a class="handoff-link" href="https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-25514.md" target="_blank" rel="noopener noreferrer">Handoff</a></span><button class="bookmark" data-bookmark="CVE-2020-25514" type="button" aria-label="Toggle watchlist for CVE-2020-25514">♡</button><button class="kebab" data-open-detail="CVE-2020-25514" type="button" aria-label="Open CVE-2020-25514 detail">⋮</button></article><article class="feed-row" data-open-detail="CVE-2020-23968" tabindex="0"><span class="observed">2026-07-08</span><span class="live-dot"></span><div class="feed-title"><button class="linklike" data-open-detail="CVE-2020-23968" type="button">CVE-2020-23968</button><strong>defensive priority signal</strong></div><span class="severity-pill high">HIGH</span><span class="epss-cell">EPSS <strong>0.0089 (55)</strong></span><span><span class="badge blue">NEW</span></span><span class="product-cell">ilex / international_sign\&amp;go</span><span class="summary-cell">NVD: Ilex International Sign&amp;go Workstation Security Suite 7.1 allows elevation of privileges via a symlink attack on ProgramData\Ilex\S&amp;G\… <a class="handoff-link" href="https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-23968.md" target="_blank" rel="noopener noreferrer">Handoff</a></span><button class="bookmark" data-bookmark="CVE-2020-23968" type="button" aria-label="Toggle watchlist for CVE-2020-23968">♡</button><button class="kebab" data-open-detail="CVE-2020-23968" type="button" aria-label="Open CVE-2020-23968 detail">⋮</button></article><article class="feed-row" data-open-detail="CVE-2020-25487" tabindex="0"><span class="observed">2026-07-08</span><span class="live-dot"></span><div class="feed-title"><button class="linklike" data-open-detail="CVE-2020-25487" type="button">CVE-2020-25487</button><strong>defensive priority signal</strong></div><span class="severity-pill high">HIGH</span><span class="epss-cell">EPSS <strong>0.0055 (42)</strong></span><span><span class="badge blue">NEW</span></span><span class="product-cell">phpgurukul / zoo_management_system</span><span class="summary-cell">NVD: PHPGURUKUL Zoo Management System Using PHP and MySQL version 1.0 is affected by: SQL Injection via zms/animal-detail.php. <a class="handoff-link" href="https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-25487.md" target="_blank" rel="noopener noreferrer">Handoff</a></span><button class="bookmark" data-bookmark="CVE-2020-25487" type="button" aria-label="Toggle watchlist for CVE-2020-25487">♡</button><button class="kebab" data-open-detail="CVE-2020-25487" type="button" aria-label="Open CVE-2020-25487 detail">⋮</button></article><article class="feed-row" data-open-detail="CVE-2020-25515" tabindex="0"><span class="observed">2026-07-08</span><span class="live-dot"></span><div class="feed-title"><button class="linklike" data-open-detail="CVE-2020-25515" type="button">CVE-2020-25515</button><strong>defensive priority signal</strong></div><span class="severity-pill high">HIGH</span><span class="epss-cell">EPSS <strong>0.0054 (42)</strong></span><span><span class="badge blue">NEW</span></span><span class="product-cell">simple_library_management_system_project / simple_library_management_system</span><span class="summary-cell">NVD: Sourcecodester Simple Library Management System 1.0 is affected by Insecure Permissions via Books &gt; New Book , <a class="handoff-link" href="https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-25515.md" target="_blank" rel="noopener noreferrer">Handoff</a></span><button class="bookmark" data-bookmark="CVE-2020-25515" type="button" aria-label="Toggle watchlist for CVE-2020-25515">♡</button><button class="kebab" data-open-detail="CVE-2020-25515" type="button" aria-label="Open CVE-2020-25515 detail">⋮</button></article><article class="feed-row" data-open-detail="CVE-2018-10902" tabindex="0"><span class="observed">2026-07-08</span><span class="live-dot"></span><div class="feed-title"><button class="linklike" data-open-detail="CVE-2018-10902" type="button">CVE-2018-10902</button><strong>defensive priority signal</strong></div><span class="severity-pill high">HIGH</span><span class="epss-cell">EPSS <strong>0.0052 (41)</strong></span><span><span class="badge blue">NEW</span></span><span class="product-cell">debian / debian_linux</span><span class="summary-cell">NVD: It was found that the raw midi kernel driver does not protect against concurrent access which leads to a double realloc (double free)… <a class="handoff-link" href="https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2018-10902.md" target="_blank" rel="noopener noreferrer">Handoff</a></span><button class="bookmark" data-bookmark="CVE-2018-10902" type="button" aria-label="Toggle watchlist for CVE-2018-10902">♡</button><button class="kebab" data-open-detail="CVE-2018-10902" type="button" aria-label="Open CVE-2018-10902 detail">⋮</button></article><article class="feed-row" data-open-detail="CVE-2020-22552" tabindex="0"><span class="observed">2026-07-08</span><span class="live-dot"></span><div class="feed-title"><button class="linklike" data-open-detail="CVE-2020-22552" type="button">CVE-2020-22552</button><strong>defensive priority signal</strong></div><span class="severity-pill high">HIGH</span><span class="epss-cell">EPSS <strong>0.0201 (79)</strong></span><span><span class="badge blue">NEW</span></span><span class="product-cell">snap7_project / snap7</span><span class="summary-cell">NVD: The Snap7 server component in version 1.4.1, when an attacker sends a crafted packet with COTP protocol the last-data-unit flag set to… <a class="handoff-link" href="https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-22552.md" target="_blank" rel="noopener noreferrer">Handoff</a></span><button class="bookmark" data-bookmark="CVE-2020-22552" type="button" aria-label="Toggle watchlist for CVE-2020-22552">♡</button><button class="kebab" data-open-detail="CVE-2020-22552" type="button" aria-label="Open CVE-2020-22552 detail">⋮</button></article><article class="feed-row" data-open-detail="CVE-2020-21733" tabindex="0"><span class="observed">2026-07-08</span><span class="live-dot"></span><div class="feed-title"><button class="linklike" data-open-detail="CVE-2020-21733" type="button">CVE-2020-21733</button><strong>defensive priority signal</strong></div><span class="severity-pill medium">MEDIUM</span><span class="epss-cell">EPSS <strong>0.0100 (58)</strong></span><span><span class="badge blue">NEW</span></span><span class="product-cell">sagemcom / f\@st_3686_firmware</span><span class="summary-cell">NVD: Sagemcom F@ST3686 v1.0 HUN 3.97.0 has XSS via RgDiagnostics.asp, RgDdns.asp, RgFirewallEL.asp, RgVpnL2tpPptp.asp. <a class="handoff-link" href="https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-21733.md" target="_blank" rel="noopener noreferrer">Handoff</a></span><button class="bookmark" data-bookmark="CVE-2020-21733" type="button" aria-label="Toggle watchlist for CVE-2020-21733">♡</button><button class="kebab" data-open-detail="CVE-2020-21733" type="button" aria-label="Open CVE-2020-21733 detail">⋮</button></article><article class="feed-row" data-open-detail="CVE-2020-21731" tabindex="0"><span class="observed">2026-07-08</span><span class="live-dot"></span><div class="feed-title"><button class="linklike" data-open-detail="CVE-2020-21731" type="button">CVE-2020-21731</button><strong>defensive priority signal</strong></div><span class="severity-pill medium">MEDIUM</span><span class="epss-cell">EPSS <strong>0.0086 (54)</strong></span><span><span class="badge blue">NEW</span></span><span class="product-cell">gazie_project / gazie</span><span class="summary-cell">NVD: Gazie 7.29 is affected by: Cross Site Scripting (XSS) via An attacker can inject JavaScript code, and the webapplication stores the in… <a class="handoff-link" href="https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-21731.md" target="_blank" rel="noopener noreferrer">Handoff</a></span><button class="bookmark" data-bookmark="CVE-2020-21731" type="button" aria-label="Toggle watchlist for CVE-2020-21731">♡</button><button class="kebab" data-open-detail="CVE-2020-21731" type="button" aria-label="Open CVE-2020-21731 detail">⋮</button></article><article class="feed-row" data-open-detail="CVE-2020-21732" tabindex="0"><span class="observed">2026-07-08</span><span class="live-dot"></span><div class="feed-title"><button class="linklike" data-open-detail="CVE-2020-21732" type="button">CVE-2020-21732</button><strong>defensive priority signal</strong></div><span class="severity-pill medium">MEDIUM</span><span class="epss-cell">EPSS <strong>0.0086 (54)</strong></span><span><span class="badge blue">NEW</span></span><span class="product-cell">rukovoditel / rukovoditel</span><span class="summary-cell">NVD: Rukovoditel Project Management app 2.6 is affected by: Cross Site Scripting (XSS). NVD: An attacker can add JavaScript code to the fil… <a class="handoff-link" href="https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-21732.md" target="_blank" rel="noopener noreferrer">Handoff</a></span><button class="bookmark" data-bookmark="CVE-2020-21732" type="button" aria-label="Toggle watchlist for CVE-2020-21732">♡</button><button class="kebab" data-open-detail="CVE-2020-21732" type="button" aria-label="Open CVE-2020-21732 detail">⋮</button></article><article class="feed-row" data-open-detail="CVE-2020-24194" tabindex="0"><span class="observed">2026-07-08</span><span class="live-dot"></span><div class="feed-title"><button class="linklike" data-open-detail="CVE-2020-24194" type="button">CVE-2020-24194</button><strong>defensive priority signal</strong></div><span class="severity-pill medium">MEDIUM</span><span class="epss-cell">EPSS <strong>0.0083 (53)</strong></span><span><span class="badge blue">NEW</span></span><span class="product-cell">daily_tracker_system_project / daily_tracker_system</span><span class="summary-cell">NVD: A Cross-site scripting (XSS) vulnerability in &#x27;user-profile.php&#x27; in SourceCodester Daily Tracker System v1.0 allows remote attackers t… <a class="handoff-link" href="https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-24194.md" target="_blank" rel="noopener noreferrer">Handoff</a></span><button class="bookmark" data-bookmark="CVE-2020-24194" type="button" aria-label="Toggle watchlist for CVE-2020-24194">♡</button><button class="kebab" data-open-detail="CVE-2020-24194" type="button" aria-label="Open CVE-2020-24194 detail">⋮</button></article><article class="feed-row" data-open-detail="CVE-2020-23136" tabindex="0"><span class="observed">2026-07-08</span><span class="live-dot"></span><div class="feed-title"><button class="linklike" data-open-detail="CVE-2020-23136" type="button">CVE-2020-23136</button><strong>defensive priority signal</strong></div><span class="severity-pill medium">MEDIUM</span><span class="epss-cell">EPSS <strong>0.0033 (25)</strong></span><span><span class="badge blue">NEW</span></span><span class="product-cell">microweber / microweber</span><span class="summary-cell">NVD: Microweber v1.1.18 is affected by no session expiry after log-out. <a class="handoff-link" href="https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-23136.md" target="_blank" rel="noopener noreferrer">Handoff</a></span><button class="bookmark" data-bookmark="CVE-2020-23136" type="button" aria-label="Toggle watchlist for CVE-2020-23136">♡</button><button class="kebab" data-open-detail="CVE-2020-23136" type="button" aria-label="Open CVE-2020-23136 detail">⋮</button></article><article class="feed-row" data-open-detail="CVE-2020-23450" tabindex="0"><span class="observed">2026-07-08</span><span class="live-dot"></span><div class="feed-title"><button class="linklike" data-open-detail="CVE-2020-23450" type="button">CVE-2020-23450</button><strong>defensive priority signal</strong></div><span class="severity-pill medium">MEDIUM</span><span class="epss-cell">EPSS <strong>0.0078 (52)</strong></span><span><span class="badge blue">NEW</span></span><span class="product-cell">spiceworks / spiceworks</span><span class="summary-cell">NVD: Spiceworks Version &lt;= 7.5.00107 is affected by XSS. NVD: Any name typed on Custom Groups function is vulnerable to stored XSS as they… <a class="handoff-link" href="https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-23450.md" target="_blank" rel="noopener noreferrer">Handoff</a></span><button class="bookmark" data-bookmark="CVE-2020-23450" type="button" aria-label="Toggle watchlist for CVE-2020-23450">♡</button><button class="kebab" data-open-detail="CVE-2020-23450" type="button" aria-label="Open CVE-2020-23450 detail">⋮</button></article><article class="feed-row" data-open-detail="CVE-2020-27388" tabindex="0"><span class="observed">2026-07-08</span><span class="live-dot"></span><div class="feed-title"><button class="linklike" data-open-detail="CVE-2020-27388" type="button">CVE-2020-27388</button><strong>defensive priority signal</strong></div><span class="severity-pill medium">MEDIUM</span><span class="epss-cell">EPSS <strong>0.0075 (51)</strong></span><span><span class="badge blue">NEW</span></span><span class="product-cell">yourls / yourls</span><span class="summary-cell">NVD: Multiple Stored Cross Site Scripting (XSS) vulnerabilities exist in the YOURLS Admin Panel, Versions 1.5 - 1.7.10. <a class="handoff-link" href="https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-27388.md" target="_blank" rel="noopener noreferrer">Handoff</a></span><button class="bookmark" data-bookmark="CVE-2020-27388" type="button" aria-label="Toggle watchlist for CVE-2020-27388">♡</button><button class="kebab" data-open-detail="CVE-2020-27388" type="button" aria-label="Open CVE-2020-27388 detail">⋮</button></article><article class="feed-row" data-open-detail="CVE-2020-23446" tabindex="0"><span class="observed">2026-07-08</span><span class="live-dot"></span><div class="feed-title"><button class="linklike" data-open-detail="CVE-2020-23446" type="button">CVE-2020-23446</button><strong>defensive priority signal</strong></div><span class="severity-pill medium">MEDIUM</span><span class="epss-cell">EPSS <strong>0.0146 (70)</strong></span><span><span class="badge blue">NEW</span></span><span class="product-cell">verint / workforce_optimization</span><span class="summary-cell">NVD: Verint Workforce Optimization suite 15.1 (15.1.0.37634) has Unauthenticated Information Disclosure via API <a class="handoff-link" href="https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-23446.md" target="_blank" rel="noopener noreferrer">Handoff</a></span><button class="bookmark" data-bookmark="CVE-2020-23446" type="button" aria-label="Toggle watchlist for CVE-2020-23446">♡</button><button class="kebab" data-open-detail="CVE-2020-23446" type="button" aria-label="Open CVE-2020-23446 detail">⋮</button></article></div><noscript><div class="noscript-feed"><h3>Public-safe defensive signals</h3><ul><li><a href="https://vuln.signal-radar.com/vuln/public-candidate/CVE-2005-4459/" target="_blank" rel="noopener noreferrer">CVE-2005-4459</a> <span class="severity-pill critical">CRITICAL</span> <span>CVSS 10.0</span> <span>vmware / ace</span><p>NVD: Heap-based buffer overflow in the NAT networking components vmnat.exe and vmnet-natd in VMWare Workstation 5.5, GSX Server 3.2, ACE 1.0.1, and Player 1.0 allows remote authenticated attackers, including guests, to execute arbitrary code via crafted (1) EPRT...</p><p>An attacker may be able to run code or commands on affected systems; CVSS 10.0 (CRITICAL); EPSS percentile 96; affected product context: vmware / ace; sources: NVD, Vendor Advisory.</p></li><li><a href="https://vuln.signal-radar.com/vuln/public-candidate/CVE-2018-5353/" target="_blank" rel="noopener noreferrer">CVE-2018-5353</a> <span class="severity-pill critical">CRITICAL</span> <span>CVSS 9.8</span> <span>zohocorp / manageengine_adselfservice_plus</span><p>NVD: The custom GINA/CP module in Zoho ManageEngine ADSelfService Plus before 5.5 build 5517 allows remote attackers to execute code and escalate privileges via spoofing. NVD: It does not authenticate the intended server before opening a browser window. NVD: An unauthenticated attacker capable of conducting a spoofing attack can redirect the browser to gain execution in the context of the WinLogon.exe process.</p><p>This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary; CVSS 9.8 (CRITICAL); EPSS percentile 94; affected product context: zohocorp /...</p></li><li><a href="https://vuln.signal-radar.com/vuln/public-candidate/CVE-2020-25466/" target="_blank" rel="noopener noreferrer">CVE-2020-25466</a> <span class="severity-pill critical">CRITICAL</span> <span>CVSS 9.8</span> <span>crmeb / crmeb</span><p>NVD: A SSRF vulnerability exists in the downloadimage interface of CRMEB 3.0, which can remotely download arbitrary files on the server and remotely execute arbitrary code. OSV: A SSRF vulnerability exists in the downloadimage interface of CRMEB 3.0, which can remotely download arbitrary files on the server and remotely execute arbitrary code.</p><p>An attacker may be able to run code or commands on affected systems; CVSS 9.8 (CRITICAL); EPSS percentile 86; affected product context: crmeb / crmeb; sources: NVD, OSV, Vendor Advisory.</p></li><li><a href="https://vuln.signal-radar.com/vuln/public-candidate/CVE-2020-24193/" target="_blank" rel="noopener noreferrer">CVE-2020-24193</a> <span class="severity-pill critical">CRITICAL</span> <span>CVSS 9.8</span> <span>daily_tracker_system_project / daily_tracker_system</span><p>NVD: A SQL injection vulnerability in login in Sourcecodetester Daily Tracker System 1.0 allows unauthenticated user to execute authentication bypass with SQL injection via the email parameter.</p><p>An attacker may be able to read or change database-backed application data; CVSS 9.8 (CRITICAL); EPSS percentile 85; affected product context: daily_tracker_system_project / daily_tracker_system; sources: NVD.</p></li><li><a href="https://vuln.signal-radar.com/vuln/public-candidate/CVE-2018-5354/" target="_blank" rel="noopener noreferrer">CVE-2018-5354</a> <span class="severity-pill high">HIGH</span> <span>CVSS 8.8</span> <span>anixis / password_reset_client</span><p>NVD: The custom GINA/CP module in ANIXIS Password Reset Client before version 3.22 allows remote attackers to execute code and escalate privileges via spoofing. NVD: When the client is configured to use HTTP, it does not authenticate the intended server before opening a browser window. NVD: An unauthenticated attacker capable of conducting a spoofing attack can redirect the browser to gain execution in the context of the WinLogon.exe process.</p><p>This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary; CVSS 8.8 (HIGH); EPSS percentile 84; affected product context: anixis / password_reset_client; sources: NVD...</p></li><li><a href="https://vuln.signal-radar.com/vuln/public-candidate/CVE-2020-23451/" target="_blank" rel="noopener noreferrer">CVE-2020-23451</a> <span class="severity-pill high">HIGH</span> <span>CVSS 8.8</span> <span>spiceworks / spiceworks</span><p>NVD: Spiceworks Version &lt;= 7.5.00107 is affected by CSRF which can lead to privilege escalation via &quot;/settings/v1/users&quot; function.</p><p>An attacker may cross a privilege boundary and gain more access than intended; CVSS 8.8 (HIGH); EPSS percentile 44; affected product context: spiceworks / spiceworks; sources: NVD.</p></li><li><a href="https://vuln.signal-radar.com/vuln/public-candidate/CVE-2020-25514/" target="_blank" rel="noopener noreferrer">CVE-2020-25514</a> <span class="severity-pill high">HIGH</span> <span>CVSS 8.4</span> <span>simple_library_management_system_project / simple_library_management_system</span><p>NVD: Sourcecodester Simple Library Management System 1.0 is affected by Incorrect Access Control via the Login Panel,</p><p>This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review; CVSS 8.4 (HIGH); EPSS percentile 46; affected product context: simple_library_management_system_project /...</p></li><li><a href="https://vuln.signal-radar.com/vuln/public-candidate/CVE-2020-23968/" target="_blank" rel="noopener noreferrer">CVE-2020-23968</a> <span class="severity-pill high">HIGH</span> <span>CVSS 7.8</span> <span>ilex / international_sign\&amp;go</span><p>NVD: Ilex International Sign&amp;go Workstation Security Suite 7.1 allows elevation of privileges via a symlink attack on ProgramData\Ilex\S&amp;G\Logs\000-sngWSService1.log.</p><p>An attacker may cross a privilege boundary and gain more access than intended; CVSS 7.8 (HIGH); EPSS percentile 55; affected product context: ilex / international_sign\&amp;go; sources: NVD, Vendor Advisory.</p></li><li><a href="https://vuln.signal-radar.com/vuln/public-candidate/CVE-2020-25487/" target="_blank" rel="noopener noreferrer">CVE-2020-25487</a> <span class="severity-pill high">HIGH</span> <span>CVSS 7.8</span> <span>phpgurukul / zoo_management_system</span><p>NVD: PHPGURUKUL Zoo Management System Using PHP and MySQL version 1.0 is affected by: SQL Injection via zms/animal-detail.php.</p><p>An attacker may be able to read or change database-backed application data; CVSS 7.8 (HIGH); EPSS percentile 42; affected product context: phpgurukul / zoo_management_system; sources: NVD.</p></li><li><a href="https://vuln.signal-radar.com/vuln/public-candidate/CVE-2020-25515/" target="_blank" rel="noopener noreferrer">CVE-2020-25515</a> <span class="severity-pill high">HIGH</span> <span>CVSS 7.8</span> <span>simple_library_management_system_project / simple_library_management_system</span><p>NVD: Sourcecodester Simple Library Management System 1.0 is affected by Insecure Permissions via Books &gt; New Book ,</p><p>This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review; CVSS 7.8 (HIGH); EPSS percentile 42; affected product context: simple_library_management_system_project /...</p></li><li><a href="https://vuln.signal-radar.com/vuln/public-candidate/CVE-2018-10902/" target="_blank" rel="noopener noreferrer">CVE-2018-10902</a> <span class="severity-pill high">HIGH</span> <span>CVSS 7.8</span> <span>debian / debian_linux</span><p>NVD: It was found that the raw midi kernel driver does not protect against concurrent access which leads to a double realloc (double free) in snd_rawmidi_input_params() and snd_rawmidi_output_status() which are part of snd_rawmidi_ioctl() handler in rawmidi.c file. NVD: A malicious local attacker could possibly use this for privilege escalation. OSV: It was found that the raw midi kernel driver does not protect against concurrent access which leads to a double realloc (double free) in snd_rawmidi_input_params() and snd_rawmidi_output_status() which are part of snd_rawmidi_ioctl() handler in rawmidi.c file.</p><p>A local user may cross a privilege boundary and gain more access than intended; CVSS 7.8 (HIGH); EPSS percentile 41; affected product context: debian / debian_linux; sources: NVD, OSV, Vendor Advisory.</p></li><li><a href="https://vuln.signal-radar.com/vuln/public-candidate/CVE-2020-22552/" target="_blank" rel="noopener noreferrer">CVE-2020-22552</a> <span class="severity-pill high">HIGH</span> <span>CVSS 7.5</span> <span>snap7_project / snap7</span><p>NVD: The Snap7 server component in version 1.4.1, when an attacker sends a crafted packet with COTP protocol the last-data-unit flag set to No and S7 writes a var function, the Snap7 server will be crashed.</p><p>This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review; CVSS 7.5 (HIGH); EPSS percentile 79; affected product context: snap7_project / snap7; sources: NVD.</p></li><li><a href="https://vuln.signal-radar.com/vuln/public-candidate/CVE-2020-21733/" target="_blank" rel="noopener noreferrer">CVE-2020-21733</a> <span class="severity-pill medium">MEDIUM</span> <span>CVSS 6.1</span> <span>sagemcom / f\@st_3686_firmware</span><p>NVD: Sagemcom F@ST3686 v1.0 HUN 3.97.0 has XSS via RgDiagnostics.asp, RgDdns.asp, RgFirewallEL.asp, RgVpnL2tpPptp.asp.</p><p>This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk; CVSS 6.1 (MEDIUM); EPSS percentile 58; affected product context: sagemcom / f\@st_3686_firmware; sources: NVD, Vendor Advisory.</p></li><li><a href="https://vuln.signal-radar.com/vuln/public-candidate/CVE-2020-21731/" target="_blank" rel="noopener noreferrer">CVE-2020-21731</a> <span class="severity-pill medium">MEDIUM</span> <span>CVSS 6.1</span> <span>gazie_project / gazie</span><p>NVD: Gazie 7.29 is affected by: Cross Site Scripting (XSS) via An attacker can inject JavaScript code, and the webapplication stores the injected code.</p><p>This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review; CVSS 6.1 (MEDIUM); EPSS percentile 54; affected product context: gazie_project / gazie; sources: NVD, Vendor Advisory.</p></li><li><a href="https://vuln.signal-radar.com/vuln/public-candidate/CVE-2020-21732/" target="_blank" rel="noopener noreferrer">CVE-2020-21732</a> <span class="severity-pill medium">MEDIUM</span> <span>CVSS 6.1</span> <span>rukovoditel / rukovoditel</span><p>NVD: Rukovoditel Project Management app 2.6 is affected by: Cross Site Scripting (XSS). NVD: An attacker can add JavaScript code to the filename.</p><p>This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk; CVSS 6.1 (MEDIUM); EPSS percentile 54; affected product context: rukovoditel / rukovoditel; sources: NVD, Vendor Advisory.</p></li><li><a href="https://vuln.signal-radar.com/vuln/public-candidate/CVE-2020-24194/" target="_blank" rel="noopener noreferrer">CVE-2020-24194</a> <span class="severity-pill medium">MEDIUM</span> <span>CVSS 6.1</span> <span>daily_tracker_system_project / daily_tracker_system</span><p>NVD: A Cross-site scripting (XSS) vulnerability in &#x27;user-profile.php&#x27; in SourceCodester Daily Tracker System v1.0 allows remote attackers to inject arbitrary web script or HTML via the &#x27;fullname&#x27; parameter.</p><p>This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk · remote exposure; CVSS 6.1 (MEDIUM); EPSS percentile 53; affected product context: daily_tracker_system_project / daily_tracker_system...</p></li><li><a href="https://vuln.signal-radar.com/vuln/public-candidate/CVE-2020-23136/" target="_blank" rel="noopener noreferrer">CVE-2020-23136</a> <span class="severity-pill medium">MEDIUM</span> <span>CVSS 5.5</span> <span>microweber / microweber</span><p>NVD: Microweber v1.1.18 is affected by no session expiry after log-out.</p><p>This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review; CVSS 5.5 (MEDIUM); EPSS percentile 25; affected product context: microweber / microweber; sources: NVD.</p></li><li><a href="https://vuln.signal-radar.com/vuln/public-candidate/CVE-2020-23450/" target="_blank" rel="noopener noreferrer">CVE-2020-23450</a> <span class="severity-pill medium">MEDIUM</span> <span>CVSS 5.4</span> <span>spiceworks / spiceworks</span><p>NVD: Spiceworks Version &lt;= 7.5.00107 is affected by XSS. NVD: Any name typed on Custom Groups function is vulnerable to stored XSS as they displayed on without output sanitization.</p><p>This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review; CVSS 5.4 (MEDIUM); EPSS percentile 52; affected product context: spiceworks / spiceworks; sources: NVD, Vendor Advisory.</p></li><li><a href="https://vuln.signal-radar.com/vuln/public-candidate/CVE-2020-27388/" target="_blank" rel="noopener noreferrer">CVE-2020-27388</a> <span class="severity-pill medium">MEDIUM</span> <span>CVSS 5.4</span> <span>yourls / yourls</span><p>NVD: Multiple Stored Cross Site Scripting (XSS) vulnerabilities exist in the YOURLS Admin Panel, Versions 1.5 - 1.7.10.</p><p>This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review; CVSS 5.4 (MEDIUM); EPSS percentile 51; affected product context: yourls / yourls; sources: NVD.</p></li><li><a href="https://vuln.signal-radar.com/vuln/public-candidate/CVE-2020-23446/" target="_blank" rel="noopener noreferrer">CVE-2020-23446</a> <span class="severity-pill medium">MEDIUM</span> <span>CVSS 5.3</span> <span>verint / workforce_optimization</span><p>NVD: Verint Workforce Optimization suite 15.1 (15.1.0.37634) has Unauthenticated Information Disclosure via API</p><p>An attacker may be able to access information that should not be exposed; CVSS 5.3 (MEDIUM); EPSS percentile 70; affected product context: verint / workforce_optimization; sources: NVD, Vendor Advisory.</p></li></ul></div></noscript><div id="empty-state" class="empty-state" hidden></div><div class="feed-legend"><span class="critical-dot"></span>Critical <span class="high-dot"></span>High <span class="medium-dot"></span>Medium <span class="low-dot"></span>Low <span class="badge mini">KEV</span>Known Exploited <span class="badge mini blue">NEW</span>Newly Observed</div></div>
<aside class="panel priority-panel view-panel" data-view="dashboard signals"><div class="panel-head"><h2>Top Risks <span>(Priority Queue)</span></h2><a href="#signals" data-view-link="signals">View all →</a></div><div id="priority-queue"><button class="risk-row" data-open-detail="CVE-2005-4459" type="button"><span class="rank">1</span><span><strong>CVE-2005-4459</strong><small>vmware / ace</small><small>CRITICAL CVSS · high EPSS percentile · official reference present</small></span><span class="score-bar"><i class="bar-fill bar-w-100"></i><em>101</em></span></button><button class="risk-row" data-open-detail="CVE-2018-5353" type="button"><span class="rank">2</span><span><strong>CVE-2018-5353</strong><small>zohocorp / manageengine_adselfservice_plus</small><small>CRITICAL CVSS · high EPSS percentile · official reference present</small></span><span class="score-bar"><i class="bar-fill bar-w-99"></i><em>99</em></span></button><button class="risk-row" data-open-detail="CVE-2020-25466" type="button"><span class="rank">3</span><span><strong>CVE-2020-25466</strong><small>crmeb / crmeb</small><small>CRITICAL CVSS · high EPSS percentile · official reference present</small></span><span class="score-bar"><i class="bar-fill bar-w-99"></i><em>99</em></span></button><button class="risk-row" data-open-detail="CVE-2020-24193" type="button"><span class="rank">4</span><span><strong>CVE-2020-24193</strong><small>daily_tracker_system_project / daily_tracker_system</small><small>CRITICAL CVSS · high EPSS percentile · official reference present</small></span><span class="score-bar"><i class="bar-fill bar-w-99"></i><em>99</em></span></button><button class="risk-row" data-open-detail="CVE-2018-5354" type="button"><span class="rank">5</span><span><strong>CVE-2018-5354</strong><small>anixis / password_reset_client</small><small>HIGH CVSS · high EPSS percentile · official reference present</small></span><span class="score-bar"><i class="bar-fill bar-w-89"></i><em>89</em></span></button></div></aside>
</section>
<section class="agent-surface-grid view-panel" data-view="dashboard sources"><article class="panel agent-panel"><div class="panel-head"><h2>Agent Access <span>Agent Data Surface</span></h2></div><p class="muted">Read-only static JSON for humans and AI agents. This is a data contract, not an execution surface.</p><div class="agent-link-grid"><a href="/archive/" target="_blank" rel="noopener noreferrer">Human Archive</a><a href="/data/v1/priority-queue.json" target="_blank" rel="noopener noreferrer">Priority Queue JSON</a><a href="/data/v1/diff/latest.json" target="_blank" rel="noopener noreferrer">Latest Diff Feed</a><a href="/data/v1/graph/latest.jsonld" target="_blank" rel="noopener noreferrer">Knowledge Graph</a><a href="/.well-known/rirastafab-trust.json" target="_blank" rel="noopener noreferrer">Trust Layer</a><a href="/data/v1/proof/latest.json" target="_blank" rel="noopener noreferrer">Proof Metadata</a><a href="/data/v1/proof/canonical-policy.json" target="_blank" rel="noopener noreferrer">Canonical Policy</a><a href="/data/v1/proof/canonical-envelope.json" target="_blank" rel="noopener noreferrer">Canonical Envelope</a><a href="/data/v1/proof/canonical-envelope-index.json" target="_blank" rel="noopener noreferrer">Envelope Index</a><a href="/data/v1/proof/eas-typed-payload.json" target="_blank" rel="noopener noreferrer">EAS Typed Payload</a><a href="/data/v1/attestations/vuln-signal-ledger.json" target="_blank" rel="noopener noreferrer">Attestation Ledger</a><a href="https://vuln.signal-radar.com/data/vuln/items/CVE-2005-4459.json" target="_blank" rel="noopener noreferrer">Signal Item JSON</a><a href="/data/v1/remediation-handoff/index.json" target="_blank" rel="noopener noreferrer">Remediation Handoff</a><a href="/agent.json" target="_blank" rel="noopener noreferrer">Agent Manifest</a><a href="/.well-known/signal-radar.json" target="_blank" rel="noopener noreferrer">Static Manifest</a><a href="/data/v1/schema/signal-item.schema.json" target="_blank" rel="noopener noreferrer">Schema</a></div><div class="trust-card-grid"><span><strong>Knowledge Graph / JSON-LD</strong><em>links CVE signals, sources, affected products, and provenance</em></span><span><strong>Local-first Vault</strong><em>browser-only personal review context; import/export/clear supported</em></span><span><strong>RirastaFab Trust Layer</strong><em>hash-only integrity metadata, canonical envelopes, and proof endpoints</em></span><span><strong>Canonical Envelope</strong><em>attestation-ready preflight metadata without onchain submission</em></span></div><p class="muted compact-copy">Agents should start with /agent.json, validate the signal item schema, use the JSON-LD graph for provenance, and treat the Local Vault as private browser state that is never uploaded.</p><div class="agent-rule-grid"><span><strong>WebMCP read-only tools</strong>Enabled</span><span><strong>Runtime server endpoints</strong>None</span><span><strong>Static agent JSON</strong>Enabled</span></div><div class="agent-rule-row"><strong>Allowed</strong><span>search / list / get / summarize / prioritize</span></div><div class="agent-rule-row disabled"><strong>Disabled</strong><span>scan / patch / exploit / external execution / auto remediation</span></div><p class="timestamp-note">Last generated: 2026-07-08 03:43 UTC / 2026-07-08 12:43 JST. Observed dates are per-source signal timestamps.</p></article><article class="panel agent-panel diff-panel"><div class="panel-head"><h2>Latest Changes <span>Diff Feed</span></h2></div><div class="diff-mode"><strong>previous successful latest</strong><span>public snapshot comparison</span></div><p class="muted">No material public-safe changes since the previous successful snapshot.</p><div class="diff-count-grid" aria-label="Latest diff summary"><div><span>Added</span><strong>0</strong></div><div><span>Changed</span><strong>0</strong></div><div><span>Removed</span><strong>0</strong></div></div><div class="fresh-row"><span>Previous snapshot</span><strong>2026-07-07 22:34 UTC / 2026-07-08 07:34 JST</strong></div><div class="fresh-row"><span>Items compared</span><strong>20 -> 20</strong></div><div class="fresh-row"><span>Feed generated</span><strong>2026-07-08 03:43 UTC / 2026-07-08 12:43 JST</strong></div><a class="inline-data-link" href="/data/v1/diff/latest.json" target="_blank" rel="noopener noreferrer">Open latest diff feed</a></article><article class="panel agent-panel enrichment-panel"><div class="panel-head"><h2>Enrichment Coverage <span>partial</span></h2></div><p class="muted">Coverage is shown from the current public dataset. CPE, PURL, and canonical vendor/product are partial and may be unknown.</p><div class="coverage-source-grid"><div><span>NVD</span><strong>20</strong></div><div><span>Vendor Advisory</span><strong>20</strong></div><div><span>OSV</span><strong>2</strong></div><div><span>CISA KEV</span><strong>0</strong></div></div><div class="coverage-partial-grid"><div><span>Affected products</span><strong>53</strong><em>partial</em></div><div><span>CPE</span><strong>53</strong><em>partial</em></div><div><span>PURL</span><strong>0</strong><em>partial</em></div><div><span>Canonical vendor/product</span><strong>53</strong><em>partial</em></div></div></article></section>
<section class="analytics-grid view-panel" data-view="dashboard"><div class="panel chart-panel"><h2>Observed Buckets <span>(current snapshot)</span></h2><div id="risk-trend"><p class="snapshot-note compact"><img src="/assets/vuln/empty-report.svg" alt="" aria-hidden="true">Current snapshot only. Historical trend appears after multiple generated runs.</p><div><span>2026-07-08</span><strong><i class="bar-fill bar-w-100"></i></strong><em>20</em></div></div></div><div class="panel chart-panel"><h2>Severity Distribution</h2><div id="severity-distribution"><div class="donut" data-label="Total 20"><svg viewBox="0 0 42 42" aria-hidden="true"><circle class="donut-bg" cx="21" cy="21" r="15.9155"></circle><circle class="donut-segment donut-critical" cx="21" cy="21" r="15.9155" pathLength="100" stroke-dasharray="20.00 80.00" stroke-dashoffset="-0.00"></circle><circle class="donut-segment donut-high" cx="21" cy="21" r="15.9155" pathLength="100" stroke-dasharray="40.00 60.00" stroke-dashoffset="-20.00"></circle><circle class="donut-segment donut-medium" cx="21" cy="21" r="15.9155" pathLength="100" stroke-dasharray="40.00 60.00" stroke-dashoffset="-60.00"></circle></svg></div><ul><li><span class="legend-dot critical"></span>CRITICAL <strong>4</strong></li><li><span class="legend-dot high"></span>HIGH <strong>8</strong></li><li><span class="legend-dot medium"></span>MEDIUM <strong>8</strong></li><li><span class="legend-dot low"></span>LOW <strong>0</strong></li><li><span class="legend-dot none"></span>NONE <strong>0</strong></li><li><span class="legend-dot unknown"></span>UNKNOWN <strong>0</strong></li></ul></div></div><div class="panel chart-panel signal-map"><h2>Source Distribution <span>(current snapshot)</span></h2><div id="activity-map"><div class="region-bars source-bars"><div><span>NVD</span><strong><i class="bar-fill bar-w-100"></i></strong><em>20</em></div><div><span>Vendor Advisory</span><strong><i class="bar-fill bar-w-100"></i></strong><em>20</em></div><div><span>OSV</span><strong><i class="bar-fill bar-w-10"></i></strong><em>2</em></div></div></div></div></section>
<section class="panel vendor-panel view-panel" data-view="dashboard sources"><div class="panel-head"><h2>Monitored Vendors</h2><a href="#sources" data-view-link="sources">View all vendors →</a></div><p class="muted vendor-note">Vendor distribution from the current public snapshot. Neutral badges are not official vendor logos.</p><div id="vendor-cards" class="vendor-cards"><button class="vendor-card" data-vendor="daily_tracker_system_project" type="button"><span class="vendor-logo"><img src="/assets/vuln/vendor-generic.svg" alt="" aria-hidden="true"></span><strong>daily_tracker_system_project</strong><small>2 CVEs</small><em>snapshot</em></button><button class="vendor-card" data-vendor="simple_library_management_system_project" type="button"><span class="vendor-logo"><img src="/assets/vuln/vendor-generic.svg" alt="" aria-hidden="true"></span><strong>simple_library_management_system_project</strong><small>2 CVEs</small><em>snapshot</em></button><button class="vendor-card" data-vendor="spiceworks" type="button"><span class="vendor-logo"><img src="/assets/vuln/vendor-generic.svg" alt="" aria-hidden="true"></span><strong>spiceworks</strong><small>2 CVEs</small><em>snapshot</em></button><button class="vendor-card" data-vendor="anixis" type="button"><span class="vendor-logo"><img src="/assets/vuln/vendor-generic.svg" alt="" aria-hidden="true"></span><strong>anixis</strong><small>1 CVEs</small><em>snapshot</em></button><button class="vendor-card" data-vendor="crmeb" type="button"><span class="vendor-logo"><img src="/assets/vuln/vendor-generic.svg" alt="" aria-hidden="true"></span><strong>crmeb</strong><small>1 CVEs</small><em>snapshot</em></button><button class="vendor-card" data-vendor="debian" type="button"><span class="vendor-logo"><img src="/assets/vuln/vendor-generic.svg" alt="" aria-hidden="true"></span><strong>debian</strong><small>1 CVEs</small><em>snapshot</em></button><button class="vendor-card" data-vendor="gazie_project" type="button"><span class="vendor-logo"><img src="/assets/vuln/vendor-generic.svg" alt="" aria-hidden="true"></span><strong>gazie_project</strong><small>1 CVEs</small><em>snapshot</em></button><button class="vendor-card" data-vendor="ilex" type="button"><span class="vendor-logo"><img src="/assets/vuln/vendor-generic.svg" alt="" aria-hidden="true"></span><strong>ilex</strong><small>1 CVEs</small><em>snapshot</em></button></div></section>
<section class="panel utility-view local-vault-panel view-panel" id="watchlist" data-view="watchlist"><h2>Local-first Personal Data Vault</h2><p class="muted">A browser-only vault for human review context. It stores vendor / product / package / CPE prefix / saved signals / muted signals / preferences in localStorage, supports import/export/clear, validates shape on import, and never uploads data.</p><div class="vault-form" aria-label="Local vault watch fields"><input id="vault-vendor" placeholder="Vendor" aria-label="Vault vendor"><input id="vault-product" placeholder="Product" aria-label="Vault product"><input id="vault-package" placeholder="Package" aria-label="Vault package"><input id="vault-cpe" placeholder="CPE prefix" aria-label="Vault CPE prefix"><button id="vault-add" type="button">Add</button></div><div class="vault-actions" role="group" aria-label="Local vault actions"><button id="vault-export" type="button">Export Vault JSON</button><label class="vault-import-label" for="vault-import">Import Vault JSON</label><input id="vault-import" type="file" accept="application/json,.json"><button id="vault-clear" type="button">Clear Vault</button></div><div id="vault-summary" class="vault-summary"></div><div id="watchlist-view"><p class="empty-copy"><img src="/assets/vuln/empty-watchlist.svg" alt="" aria-hidden="true">No watched signals yet. Use the heart control on a signal row to add one.</p></div></section>
<section class="panel utility-view view-panel" id="saved" data-view="saved"><h2>Saved Views</h2><p class="muted">Save and reapply local filter sets. Nothing is uploaded.</p><div class="save-view-row"><input id="saved-view-name" placeholder="View name" aria-label="Saved view name"><button data-save-view type="button">Save current view</button></div><div id="saved-views"><p class="empty-copy">No saved views. Enter a name and save the current filters.</p></div></section>
<section class="panel utility-view view-panel" id="reports" data-view="reports"><h2>Read-only Triage Report Preview</h2><p class="muted">Generated from the current filters. Defensive checklist only; no exploit or scanning detail.</p><div class="export-actions" role="group" aria-label="Export report"><button id="export-json" type="button">Export JSON</button><span class="button-gap" aria-hidden="true"></span><button id="export-csv" type="button">Export CSV</button></div><div id="report-summary" class="report-summary"><article><span>Filtered signals</span><strong>20</strong></article><article><span>Top priority candidate</span><strong>CVE-2005-4459</strong></article><article><span>Critical / High</span><strong>4 / 8</strong></article><article><span>Safety mode</span><strong>read-only, public indexable, public-safe</strong></article></div><details class="raw-json-details"><summary>Raw JSON details</summary><pre id="report-preview">{
  &quot;count&quot;: 20,
  &quot;defensive_checklist&quot;: [
    &quot;Confirm affected products&quot;,
    &quot;Review official source references&quot;,
    &quot;Prioritize KEV, critical CVSS, and high EPSS percentile items&quot;,
    &quot;Record human confirmation&quot;
  ],
  &quot;mode&quot;: &quot;read_only_public_beta_dashboard&quot;,
  &quot;safety&quot;: {
    &quot;procedural_detail&quot;: false,
    &quot;public_launch&quot;: true,
    &quot;scanner_execution&quot;: false
  },
  &quot;severity_distribution&quot;: {
    &quot;CRITICAL&quot;: 4,
    &quot;HIGH&quot;: 8,
    &quot;LOW&quot;: 0,
    &quot;MEDIUM&quot;: 8,
    &quot;NONE&quot;: 0,
    &quot;UNKNOWN&quot;: 0
  },
  &quot;top_risk&quot;: &quot;CVE-2005-4459&quot;
}</pre></details></section>
<section class="panel utility-view view-panel" id="sources" data-view="sources"><h2>Source Status</h2><div id="source-status" class="source-status-grid"><article><strong>NVD</strong><span>20 signals</span><small>Last observed: 2026-07-08</small><small>Status: healthy</small></article><article><strong>EPSS</strong><span>20 signals</span><small>Last observed: 2026-07-08</small><small>Status: healthy</small></article><article><strong>OSV</strong><span>2 signals</span><small>Last observed: 2026-07-08</small><small>Status: healthy</small></article><article><strong>CISA KEV</strong><span>0 signals</span><small>Last observed: 2026-07-08</small><small>Status: not observed</small></article><article><strong>Vendor Advisory</strong><span>20 signals</span><small>Last observed: 2026-07-08</small><small>Status: observed</small></article></div></section>
<section class="panel utility-view view-panel" id="settings" data-view="settings"><h2>Safety Guardrails</h2><div class="settings-grid"><div class="setting-card read-only"><i aria-hidden="true"></i><strong>Public indexing</strong><span>Enabled</span></div><div class="setting-card read-only"><i aria-hidden="true"></i><strong>Read-only surface</strong><span>Enabled</span></div><div class="setting-card locked"><i aria-hidden="true"></i><strong>Deploy controls</strong><span>Codex managed deploy only</span></div><div class="setting-card disabled"><i aria-hidden="true"></i><strong>External notification</strong><span>Disabled</span></div><div class="setting-card disabled"><i aria-hidden="true"></i><strong>Auto remediation</strong><span>Disabled</span></div><div class="setting-card read-only"><i aria-hidden="true"></i><strong>Runtime server endpoints</strong><span>None</span></div><div class="setting-card read-only"><i aria-hidden="true"></i><strong>WebMCP read-only tools</strong><span>Enabled</span></div><div class="setting-card read-only"><i aria-hidden="true"></i><strong>Static agent JSON</strong><span>Enabled</span></div></div></section>
</main>
</div>
<footer class="status-footer"><span>© 2026 <a href="https://signal-radar.com/" target="_blank" rel="noopener noreferrer">Signal-Radar.com</a></span><a href="/about/">About</a><a href="/about/#contact">Contact</a><a href="/about/#data-policy">Data Policy</a><a href="#sources" data-view-link="sources">Data sources</a><a href="#reports" data-view-link="reports">Report preview</a><a href="#settings" data-view-link="settings">Guardrails</a><span><span class="live-dot"></span>Data sources: <strong id="source-count">3</strong></span><span>Times: UTC / JST</span></footer>
<aside class="detail-drawer" id="detail-drawer" aria-hidden="true"><div id="drawer-content"></div></aside>
</div>
<template id="vuln-fallback-data">{"index": {"archive": {"append_only": true, "archive_index_url": "https://vuln.signal-radar.com/data/vuln/archive/index.json", "archive_latest_url": "https://vuln.signal-radar.com/data/vuln/archive/latest.json", "archive_version": "v0.1", "archived_cve_count": 74, "item_count": 20, "latest_run_id": "20260708T034317Z", "latest_run_index_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260708T034317Z/index.json", "latest_run_manifest_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260708T034317Z/manifest.json", "public_archive_cve_page_count": 74, "public_archive_url": "https://vuln.signal-radar.com/archive/", "timeline_count": 74, "webmcp_future_contract": {"annotations": {"readOnlyHint": true, "untrustedContentHint": true}, "api": "document.modelContext", "auto_remediation_allowed": false, "cross_origin_exposure_allowed": false, "deploy_allowed": false, "enabled": true, "endpoint": null, "exposed_to": [], "external_execution_allowed": false, "fallback_api": "navigator.modelContext", "fetch_allowed": false, "github_issue_creation_allowed": false, "mode": "browser_imperative_progressive_enhancement", "mutation_allowed": false, "notes": "Browser WebMCP tools are registered only when document.modelContext or navigator.modelContext is available. They read existing public-safe static JSON and perform no network fetch, deploy, scan, patch, or mutation.", "planned": false, "scan_allowed": false, "tool_output_max_items": 10, "tool_output_target_max_chars": 1500, "tools": ["vuln_signal_search", "vuln_signal_get_item", "vuln_signal_list_priority"]}}, "archive_index_url": "https://vuln.signal-radar.com/data/vuln/archive/index.json", "archive_latest_url": "https://vuln.signal-radar.com/data/vuln/archive/latest.json", "auto_remediation_allowed": false, "automated_public_launch_generation": true, "automated_publication_mode": true, "automated_publication_mode_deprecated": "public launch is complete; static generation remains read-only and safety-gated", "external_execution_allowed": false, "generated_at": "2026-07-08T03:43:17.030146+00:00", "human_review": {"required_for_external_action": true, "required_for_public_launch": false, "required_for_read_only_view": false, "required_for_signal_radar_integration": true}, "human_review_required": false, "indexing_allowed": true, "items": [{"affected_label": "vmware / ace", "affected_products": [{"canonicalProduct": "ace", "canonicalVendor": "vmware", "cpe": "cpe:2.3:a:vmware:ace:1.0.1:*:*:*:*:*:*:*", "ecosystem": null, "packageName": null, "product": "ace", "purl": null, "vendor": "vmware", "version": "1.0.1"}, {"canonicalProduct": "gsx_server", "canonicalVendor": "vmware", "cpe": "cpe:2.3:a:vmware:gsx_server:2.0:*:*:*:*:*:*:*", "ecosystem": null, "packageName": null, "product": "gsx_server", "purl": null, "vendor": "vmware", "version": "2.0"}, {"canonicalProduct": "gsx_server", "canonicalVendor": "vmware", "cpe": "cpe:2.3:a:vmware:gsx_server:2.0.1_build_2129:*:*:*:*:*:*:*", "ecosystem": null, "packageName": null, "product": "gsx_server", "purl": null, "vendor": "vmware", "version": "2.0.1_build_2129"}, {"canonicalProduct": "gsx_server", "canonicalVendor": "vmware", "cpe": "cpe:2.3:a:vmware:gsx_server:2.5.1:*:*:*:*:*:*:*", "ecosystem": null, "packageName": null, "product": "gsx_server", "purl": null, "vendor": "vmware", "version": "2.5.1"}, {"canonicalProduct": "gsx_server", "canonicalVendor": "vmware", "cpe": "cpe:2.3:a:vmware:gsx_server:2.5.1_build_5336:*:*:*:*:*:*:*", "ecosystem": null, "packageName": null, "product": "gsx_server", "purl": null, "vendor": "vmware", "version": "2.5.1_build_5336"}, {"canonicalProduct": "gsx_server", "canonicalVendor": "vmware", "cpe": "cpe:2.3:a:vmware:gsx_server:2.5.2:*:*:*:*:*:*:*", "ecosystem": null, "packageName": null, "product": "gsx_server", "purl": null, "vendor": "vmware", "version": "2.5.2"}, {"canonicalProduct": "gsx_server", "canonicalVendor": "vmware", "cpe": "cpe:2.3:a:vmware:gsx_server:3.0:*:*:*:*:*:*:*", "ecosystem": null, "packageName": null, "product": "gsx_server", "purl": null, "vendor": "vmware", "version": "3.0"}, {"canonicalProduct": "gsx_server", "canonicalVendor": "vmware", "cpe": "cpe:2.3:a:vmware:gsx_server:3.0_build_7592:*:*:*:*:*:*:*", "ecosystem": null, "packageName": null, "product": "gsx_server", "purl": null, "vendor": "vmware", "version": "3.0_build_7592"}, {"canonicalProduct": "gsx_server", "canonicalVendor": "vmware", "cpe": "cpe:2.3:a:vmware:gsx_server:3.1:*:*:*:*:*:*:*", "ecosystem": null, "packageName": null, "product": "gsx_server", "purl": null, "vendor": "vmware", "version": "3.1"}, {"canonicalProduct": "gsx_server", "canonicalVendor": "vmware", "cpe": "cpe:2.3:a:vmware:gsx_server:3.2:*:*:*:*:*:*:*", "ecosystem": null, "packageName": null, "product": "gsx_server", "purl": null, "vendor": "vmware", "version": "3.2"}, {"canonicalProduct": "player", "canonicalVendor": "vmware", "cpe": "cpe:2.3:a:vmware:player:1.0.0:*:*:*:*:*:*:*", "ecosystem": null, "packageName": null, "product": "player", "purl": null, "vendor": "vmware", "version": "1.0.0"}, {"canonicalProduct": "workstation", "canonicalVendor": "vmware", "cpe": "cpe:2.3:a:vmware:workstation:3.2.1:patch1:*:*:*:*:*:*", "ecosystem": null, "packageName": null, "product": "workstation", "purl": null, "vendor": "vmware", "version": "3.2.1"}, {"canonicalProduct": "workstation", "canonicalVendor": "vmware", "cpe": "cpe:2.3:a:vmware:workstation:3.4:*:*:*:*:*:*:*", "ecosystem": null, "packageName": null, "product": "workstation", "purl": null, "vendor": "vmware", "version": "3.4"}, {"canonicalProduct": "workstation", "canonicalVendor": "vmware", "cpe": "cpe:2.3:a:vmware:workstation:4.0:*:*:*:*:*:*:*", "ecosystem": null, "packageName": null, "product": "workstation", "purl": null, "vendor": "vmware", "version": "4.0"}, {"canonicalProduct": "workstation", "canonicalVendor": "vmware", "cpe": "cpe:2.3:a:vmware:workstation:4.0.1:*:*:*:*:*:*:*", "ecosystem": null, "packageName": null, "product": "workstation", "purl": null, "vendor": "vmware", "version": "4.0.1"}, {"canonicalProduct": "workstation", "canonicalVendor": "vmware", "cpe": "cpe:2.3:a:vmware:workstation:4.0.2:*:*:*:*:*:*:*", "ecosystem": null, "packageName": null, "product": "workstation", "purl": null, "vendor": "vmware", "version": "4.0.2"}, {"canonicalProduct": "workstation", "canonicalVendor": "vmware", "cpe": "cpe:2.3:a:vmware:workstation:4.5.2:*:*:*:*:*:*:*", "ecosystem": null, "packageName": null, "product": "workstation", "purl": null, "vendor": "vmware", "version": "4.5.2"}, {"canonicalProduct": "workstation", "canonicalVendor": "vmware", "cpe": "cpe:2.3:a:vmware:workstation:4.5.2_build_8848:r4:*:*:*:*:*:*", "ecosystem": null, "packageName": null, "product": "workstation", "purl": null, "vendor": "vmware", "version": "4.5.2_build_8848"}, {"canonicalProduct": "workstation", "canonicalVendor": "vmware", "cpe": "cpe:2.3:a:vmware:workstation:5.0.0_build_13124:*:*:*:*:*:*:*", "ecosystem": null, "packageName": null, "product": "workstation", "purl": null, "vendor": "vmware", "version": "5.0.0_build_13124"}, {"canonicalProduct": "workstation", "canonicalVendor": "vmware", "cpe": "cpe:2.3:a:vmware:workstation:5.5:*:*:*:*:*:*:*", "ecosystem": null, "packageName": null, "product": "workstation", "purl": null, "vendor": "vmware", "version": "5.5"}], "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2005-4459/", "cvss_score": 10.0, "cvss_severity": "CRITICAL", "data_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2005-4459.json", "defensive_priority": "Priority review candidate", "epss_percentile": 0.96028, "epss_score": 0.13661, "exposure_hint": "authenticated boundary", "human_consequence": "An attacker may be able to run code or commands on affected systems.", "human_impact_label": "code execution review · memory safety review · authenticated boundary", "human_risk_summary": "CVE-2005-4459 for vmware / ace: An attacker may be able to run code or commands on affected systems.", "id": "CVE-2005-4459", "impact_tags": ["code execution review", "memory safety review", "authenticated boundary review"], "kev": false, "observed_at": "2026-07-08T03:39:09.814067+00:00", "product": "ace", "public_human_impact": "Source describes code execution review · memory safety review · authenticated boundary. Possible impact: An attacker may be able to run code or commands on affected systems.", "public_human_summary": "NVD: Heap-based buffer overflow in the NAT networking components vmnat.exe and vmnet-natd in VMWare Workstation 5.5, GSX Server 3.2, ACE 1.0.1, and Player 1.0 allows remote authenticated attackers, including guests, to execute arbitrary code via crafted (1) EPRT...", "public_human_what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "public_human_why_it_matters": "Source describes code execution review · memory safety review · authenticated boundary. Possible impact: An attacker may be able to run code or commands on affected systems.; CVSS 10.0 (CRITICAL); EPSS percentile 96; not listed in KEV; Remediation reference present; patch status requires confirmation in the linked advisory; sources: NVD, Vendor Advisory.", "public_safe_summary": "NVD: Heap-based buffer overflow in the NAT networking components vmnat.exe and vmnet-natd in VMWare Workstation 5.5, GSX Server 3.2, ACE 1.0.1, and Player 1.0 allows remote authenticated attackers, including guests, to execute arbitrary code via crafted (1) EPRT...", "public_status": "public_safe", "published_at": null, "redaction_notes": ["source-published defensive context retained", "vulnerability class, impact, affected context, and remediation references remain displayable"], "remediation_handoff": {"auto_remediation_allowed": false, "codex_prompt_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2005-4459-codex-prompt.md", "external_execution_allowed": false, "human_approval_required": true, "json_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2005-4459.json", "markdown_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2005-4459.md", "scan_allowed": false}, "remediation_urls": ["http://secunia.com/advisories/18162", "http://secunia.com/advisories/18344", "http://securityreason.com/securityalert/282", "http://securityreason.com/securityalert/289", "http://securitytracker.com/id?1015401", "http://www.gentoo.org/security/en/glsa/glsa-200601-04.xml", "http://www.securityfocus.com/archive/1/419997/100/0/threaded", "http://www.securityfocus.com/archive/1/420017/100/0/threaded", "http://www.securityfocus.com/bid/15998", "http://www.vmware.com/support/kb/enduser/std_adp.php?p_faqid=2000"], "sort_priority": 100.96028, "source_copy_policy": {"allowed": "source-published defensive facts, vulnerability class, impact, affected context, version and remediation facts", "excluded": "exploit procedures, exploit strings, shell commands, scanner instructions, procedural bypass detail, and reproduction material", "summary": "Official or semi-official source descriptions may be summarized for defensive triage; exploit-enabling procedure is removed."}, "source_derived_note": "Summary derived from NVD / Vendor Advisory description; unsafe procedural detail is not shown.", "source_label": "NVD, Vendor Advisory", "source_published_affected": "vendor/product: vmware / ace; affected version context: 1.0.0, 1.0.1, 2.0, 2.0.1_build_2129, 2.5.1", "source_published_description": "NVD: Heap-based buffer overflow in the NAT networking components vmnat.exe and vmnet-natd in VMWare Workstation 5.5, GSX Server 3.2, ACE 1.0.1, and Player 1.0 allows remote authenticated attackers, including guests, to execute arbitrary code via crafted (1) EPRT...", "source_published_evidence_refs": [{"source": "NVD", "type": "source_description", "url": null}, {"source": "Vendor Advisory", "type": "source_description", "url": null}, {"source": "Reference", "type": "reference", "url": "http://lists.grok.org.uk/pipermail/full-disclosure/2005-December/040442.html"}, {"source": "Vendor Advisory", "type": "reference", "url": "http://secunia.com/advisories/18162"}, {"source": "Vendor Advisory", "type": "reference", "url": "http://secunia.com/advisories/18344"}, {"source": "Reference", "type": "reference", "url": "http://securityreason.com/securityalert/282"}, {"source": "Reference", "type": "reference", "url": "http://securityreason.com/securityalert/289"}, {"source": "Reference", "type": "reference", "url": "http://securitytracker.com/id?1015401"}, {"source": "Reference", "type": "reference", "url": "http://www.gentoo.org/security/en/glsa/glsa-200601-04.xml"}, {"source": "Reference", "type": "reference", "url": "http://www.kb.cert.org/vuls/id/856689"}], "source_published_impact": "Source describes code execution review · memory safety review · authenticated boundary. Possible impact: An attacker may be able to run code or commands on affected systems.", "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.", "source_published_summary": "NVD: Heap-based buffer overflow in the NAT networking components vmnat.exe and vmnet-natd in VMWare Workstation 5.5, GSX Server 3.2, ACE 1.0.1, and Player 1.0 allows remote authenticated attackers, including guests, to execute arbitrary code via crafted (1) EPRT...", "sources": ["NVD", "Vendor Advisory"], "summary": "CVE-2005-4459 is a defensive prioritization candidate. NVD lists CVSS severity as HIGH. CVSS score is 10.0. EPSS score is 0.1366 with percentile 0.9603. Known exploited catalog status is not listed in NVD for this record. Use official advisories and vendor remediation references for defensive review.", "summary_ja": null, "title": "CVE-2005-4459 defensive priority signal", "title_ja": null, "translation": null, "updated_at": null, "urgency_reasons": ["CVSS CRITICAL", "EPSS percentile high", "affected product present", "vendor advisory present", "recent update", "remediation reference present"], "vendor": "vmware", "what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "why_it_matters": "An attacker may be able to run code or commands on affected systems; CVSS 10.0 (CRITICAL); EPSS percentile 96; affected product context: vmware / ace; sources: NVD, Vendor Advisory."}, {"affected_label": "debian / debian_linux", "affected_products": [{"canonicalProduct": "debian_linux", "canonicalVendor": "debian", "cpe": "cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*", "ecosystem": null, "packageName": null, "product": "debian_linux", "purl": null, "vendor": "debian", "version": "8.0"}, {"canonicalProduct": "debian_linux", "canonicalVendor": "debian", "cpe": "cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*", "ecosystem": null, "packageName": null, "product": "debian_linux", "purl": null, "vendor": "debian", "version": "9.0"}, {"canonicalProduct": "ubuntu_linux", "canonicalVendor": "canonical", "cpe": "cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:esm:*:*:*", "ecosystem": null, "packageName": null, "product": "ubuntu_linux", "purl": null, "vendor": "canonical", "version": "12.04"}, {"canonicalProduct": "ubuntu_linux", "canonicalVendor": "canonical", "cpe": "cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*", "ecosystem": null, "packageName": null, "product": "ubuntu_linux", "purl": null, "vendor": "canonical", "version": "14.04"}, {"canonicalProduct": "ubuntu_linux", "canonicalVendor": "canonical", "cpe": "cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*", "ecosystem": null, "packageName": null, "product": "ubuntu_linux", "purl": null, "vendor": "canonical", "version": "16.04"}, {"canonicalProduct": "ubuntu_linux", "canonicalVendor": "canonical", "cpe": "cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*", "ecosystem": null, "packageName": null, "product": "ubuntu_linux", "purl": null, "vendor": "canonical", "version": "18.04"}, {"canonicalProduct": "linux_kernel", "canonicalVendor": "linux", "cpe": "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*", "ecosystem": null, "packageName": null, "product": "linux_kernel", "purl": null, "vendor": "linux", "version": "-"}, {"canonicalProduct": "enterprise_linux_desktop", "canonicalVendor": "redhat", "cpe": "cpe:2.3:o:redhat:enterprise_linux_desktop:6.0:*:*:*:*:*:*:*", "ecosystem": null, "packageName": null, "product": "enterprise_linux_desktop", "purl": null, "vendor": "redhat", "version": "6.0"}, {"canonicalProduct": "enterprise_linux_desktop", "canonicalVendor": "redhat", "cpe": "cpe:2.3:o:redhat:enterprise_linux_desktop:7.0:*:*:*:*:*:*:*", "ecosystem": null, "packageName": null, "product": "enterprise_linux_desktop", "purl": null, "vendor": "redhat", "version": "7.0"}, {"canonicalProduct": "enterprise_linux_server", "canonicalVendor": "redhat", "cpe": "cpe:2.3:o:redhat:enterprise_linux_server:6.0:*:*:*:*:*:*:*", "ecosystem": null, "packageName": null, "product": "enterprise_linux_server", "purl": null, "vendor": "redhat", "version": "6.0"}, {"canonicalProduct": "enterprise_linux_server", "canonicalVendor": "redhat", "cpe": "cpe:2.3:o:redhat:enterprise_linux_server:7.0:*:*:*:*:*:*:*", "ecosystem": null, "packageName": null, "product": "enterprise_linux_server", "purl": null, "vendor": "redhat", "version": "7.0"}, {"canonicalProduct": "enterprise_linux_workstation", "canonicalVendor": "redhat", "cpe": "cpe:2.3:o:redhat:enterprise_linux_workstation:6.0:*:*:*:*:*:*:*", "ecosystem": null, "packageName": null, "product": "enterprise_linux_workstation", "purl": null, "vendor": "redhat", "version": "6.0"}, {"canonicalProduct": "enterprise_linux_workstation", "canonicalVendor": "redhat", "cpe": "cpe:2.3:o:redhat:enterprise_linux_workstation:7.0:*:*:*:*:*:*:*", "ecosystem": null, "packageName": null, "product": "enterprise_linux_workstation", "purl": null, "vendor": "redhat", "version": "7.0"}], "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2018-10902/", "cvss_score": 7.8, "cvss_severity": "HIGH", "data_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2018-10902.json", "defensive_priority": "Continuous monitoring candidate", "epss_percentile": 0.40562, "epss_score": 0.00523, "exposure_hint": "local exposure", "human_consequence": "A local user may cross a privilege boundary and gain more access than intended.", "human_impact_label": "privilege escalation risk · local exposure", "human_risk_summary": "CVE-2018-10902 for debian / debian_linux: A local user may cross a privilege boundary and gain more access than intended.", "id": "CVE-2018-10902", "impact_tags": ["privilege boundary review", "local exposure relevant"], "kev": false, "observed_at": "2026-07-08T03:39:09.814067+00:00", "product": "debian_linux", "public_human_impact": "Source describes privilege escalation risk · local exposure. Possible impact: A local user may cross a privilege boundary and gain more access than intended.", "public_human_summary": "NVD: It was found that the raw midi kernel driver does not protect against concurrent access which leads to a double realloc (double free) in snd_rawmidi_input_params() and snd_rawmidi_output_status() which are part of snd_rawmidi_ioctl() handler in rawmidi.c file. NVD: A malicious local attacker could possibly use this for privilege escalation. OSV: It was found that the raw midi kernel driver does not protect against concurrent access which leads to a double realloc (double free) in snd_rawmidi_input_params() and snd_rawmidi_output_status() which are part of snd_rawmidi_ioctl() handler in rawmidi.c file.", "public_human_what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "public_human_why_it_matters": "Source describes privilege escalation risk · local exposure. Possible impact: A local user may cross a privilege boundary and gain more access than intended.; CVSS 7.8 (HIGH); EPSS percentile 41; not listed in KEV; Remediation reference present; patch status requires confirmation in the linked advisory; sources: NVD, OSV, Vendor Advisory.", "public_safe_summary": "NVD: It was found that the raw midi kernel driver does not protect against concurrent access which leads to a double realloc (double free) in snd_rawmidi_input_params() and snd_rawmidi_output_status() which are part of snd_rawmidi_ioctl() handler in rawmidi.c file. NVD: A malicious local attacker could possibly use this for privilege escalation. OSV: It was found that the raw midi kernel driver does not protect against concurrent access which leads to a double realloc (double free) in snd_rawmidi_input_params() and snd_rawmidi_output_status() which are part of snd_rawmidi_ioctl() handler in rawmidi.c file.", "public_status": "public_safe", "published_at": null, "redaction_notes": ["source-published defensive context retained", "vulnerability class, impact, affected context, and remediation references remain displayable"], "remediation_handoff": {"auto_remediation_allowed": false, "codex_prompt_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2018-10902-codex-prompt.md", "external_execution_allowed": false, "human_approval_required": true, "json_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2018-10902.json", "markdown_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2018-10902.md", "scan_allowed": false}, "remediation_urls": ["http://www.securityfocus.com/bid/105119", "http://www.securitytracker.com/id/1041529", "https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-10902", "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=39675f7a7c7e7702f7d5341f1e0d01db746543a0", "https://www.debian.org/security/2018/dsa-4308"], "sort_priority": 78.40562, "source_copy_policy": {"allowed": "source-published defensive facts, vulnerability class, impact, affected context, version and remediation facts", "excluded": "exploit procedures, exploit strings, shell commands, scanner instructions, procedural bypass detail, and reproduction material", "summary": "Official or semi-official source descriptions may be summarized for defensive triage; exploit-enabling procedure is removed."}, "source_derived_note": "Summary derived from NVD / OSV / Vendor Advisory description; unsafe procedural detail is not shown.", "source_label": "NVD, OSV, Vendor Advisory", "source_published_affected": "vendor/product: debian / debian_linux; affected version context: -, 12.04, 14.04, 16.04, 18.04", "source_published_description": "NVD: It was found that the raw midi kernel driver does not protect against concurrent access which leads to a double realloc (double free) in snd_rawmidi_input_params() and snd_rawmidi_output_status() which are part of snd_rawmidi_ioctl() handler in rawmidi.c file. NVD: A malicious local attacker could possibly use this for privilege escalation. OSV: It was found that the raw midi kernel driver does not protect against concurrent access which leads to a double realloc (double free) in snd_rawmidi_input_params() and snd_rawmidi_output_status() which are part of snd_rawmidi_ioctl() handler in rawmidi.c file.", "source_published_evidence_refs": [{"source": "NVD", "type": "source_description", "url": null}, {"source": "OSV", "type": "source_description", "url": null}, {"source": "Vendor Advisory", "type": "source_description", "url": null}, {"source": "Reference", "type": "reference", "url": "http://www.securityfocus.com/bid/105119"}, {"source": "Vendor Advisory", "type": "reference", "url": "http://www.securitytracker.com/id/1041529"}, {"source": "Reference", "type": "reference", "url": "https://access.redhat.com/errata/RHSA-2018:3083"}, {"source": "Reference", "type": "reference", "url": "https://access.redhat.com/errata/RHSA-2018:3096"}, {"source": "Reference", "type": "reference", "url": "https://access.redhat.com/errata/RHSA-2019:0415"}, {"source": "Reference", "type": "reference", "url": "https://access.redhat.com/errata/RHSA-2019:0641"}, {"source": "Reference", "type": "reference", "url": "https://access.redhat.com/errata/RHSA-2019:3217"}], "source_published_impact": "Source describes privilege escalation risk · local exposure. Possible impact: A local user may cross a privilege boundary and gain more access than intended.", "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.", "source_published_summary": "NVD: It was found that the raw midi kernel driver does not protect against concurrent access which leads to a double realloc (double free) in snd_rawmidi_input_params() and snd_rawmidi_output_status() which are part of snd_rawmidi_ioctl() handler in rawmidi.c file. NVD: A malicious local attacker could possibly use this for privilege escalation. OSV: It was found that the raw midi kernel driver does not protect against concurrent access which leads to a double realloc (double free) in snd_rawmidi_input_params() and snd_rawmidi_output_status() which are part of snd_rawmidi_ioctl() handler in rawmidi.c file.", "sources": ["NVD", "OSV", "Vendor Advisory"], "summary": "CVE-2018-10902 is a defensive prioritization candidate. NVD lists CVSS severity as HIGH. CVSS score is 7.8. EPSS score is 0.0052 with percentile 0.4056. Known exploited catalog status is not listed in NVD for this record. Use official advisories and vendor remediation references for defensive review.", "summary_ja": null, "title": "CVE-2018-10902 defensive priority signal", "title_ja": null, "translation": null, "updated_at": null, "urgency_reasons": ["CVSS HIGH", "affected product present", "vendor advisory present", "recent update", "remediation reference present"], "vendor": "debian", "what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "why_it_matters": "A local user may cross a privilege boundary and gain more access than intended; CVSS 7.8 (HIGH); EPSS percentile 41; affected product context: debian / debian_linux; sources: NVD, OSV, Vendor Advisory."}, {"affected_label": "spiceworks / spiceworks", "affected_products": [{"canonicalProduct": "spiceworks", "canonicalVendor": "spiceworks", "cpe": "cpe:2.3:a:spiceworks:spiceworks:*:*:*:*:*:*:*:*", "ecosystem": null, "packageName": null, "product": "spiceworks", "purl": null, "vendor": "spiceworks", "version": null}], "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2020-23450/", "cvss_score": 5.4, "cvss_severity": "MEDIUM", "data_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2020-23450.json", "defensive_priority": "Continuous monitoring candidate", "epss_percentile": 0.5158, "epss_score": 0.00783, "exposure_hint": "exposure unknown", "human_consequence": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.", "human_impact_label": "defensive exposure review", "human_risk_summary": "CVE-2020-23450 for spiceworks / spiceworks: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.", "id": "CVE-2020-23450", "impact_tags": [], "kev": false, "observed_at": "2026-07-08T03:39:09.814067+00:00", "product": "spiceworks", "public_human_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.", "public_human_summary": "NVD: Spiceworks Version <= 7.5.00107 is affected by XSS. NVD: Any name typed on Custom Groups function is vulnerable to stored XSS as they displayed on without output sanitization.", "public_human_what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "public_human_why_it_matters": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.; CVSS 5.4 (MEDIUM); EPSS percentile 52; not listed in KEV; Remediation reference present; patch status requires confirmation in the linked advisory; sources: NVD, Vendor Advisory.", "public_safe_summary": "NVD: Spiceworks Version <= 7.5.00107 is affected by XSS. NVD: Any name typed on Custom Groups function is vulnerable to stored XSS as they displayed on without output sanitization.", "public_status": "public_safe", "published_at": null, "redaction_notes": ["source-published defensive context retained", "vulnerability class, impact, affected context, and remediation references remain displayable"], "remediation_handoff": {"auto_remediation_allowed": false, "codex_prompt_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-23450-codex-prompt.md", "external_execution_allowed": false, "human_approval_required": true, "json_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-23450.json", "markdown_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-23450.md", "scan_allowed": false}, "remediation_urls": ["http://spiceworks.com"], "sort_priority": 54.5158, "source_copy_policy": {"allowed": "source-published defensive facts, vulnerability class, impact, affected context, version and remediation facts", "excluded": "exploit procedures, exploit strings, shell commands, scanner instructions, procedural bypass detail, and reproduction material", "summary": "Official or semi-official source descriptions may be summarized for defensive triage; exploit-enabling procedure is removed."}, "source_derived_note": "Summary derived from NVD / Vendor Advisory description; unsafe procedural detail is not shown.", "source_label": "NVD, Vendor Advisory", "source_published_affected": "vendor/product: spiceworks / spiceworks", "source_published_description": "NVD: Spiceworks Version <= 7.5.00107 is affected by XSS. NVD: Any name typed on Custom Groups function is vulnerable to stored XSS as they displayed on without output sanitization.", "source_published_evidence_refs": [{"source": "NVD", "type": "source_description", "url": null}, {"source": "Vendor Advisory", "type": "source_description", "url": null}, {"source": "Reference", "type": "reference", "url": "https://abuyv.com"}, {"source": "Reference", "type": "reference", "url": "https://abuyv.com/cve/spiceworks-stored-xss"}, {"source": "Vendor Advisory", "type": "reference", "url": "http://spiceworks.com"}, {"source": "Reference", "type": "reference", "url": "https://abuyv.com"}, {"source": "Reference", "type": "reference", "url": "https://abuyv.com/cve/spiceworks-stored-xss"}, {"source": "Official Reference", "type": "reference", "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-23450"}], "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.", "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.", "source_published_summary": "NVD: Spiceworks Version <= 7.5.00107 is affected by XSS. NVD: Any name typed on Custom Groups function is vulnerable to stored XSS as they displayed on without output sanitization.", "sources": ["NVD", "Vendor Advisory"], "summary": "CVE-2020-23450 is a defensive prioritization candidate. NVD lists CVSS severity as MEDIUM. CVSS score is 5.4. EPSS score is 0.0078 with percentile 0.5158. Known exploited catalog status is not listed in NVD for this record. Use official advisories and vendor remediation references for defensive review.", "summary_ja": null, "title": "CVE-2020-23450 defensive priority signal", "title_ja": null, "translation": null, "updated_at": null, "urgency_reasons": ["affected product present", "vendor advisory present", "recent update", "remediation reference present"], "vendor": "spiceworks", "what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "why_it_matters": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review; CVSS 5.4 (MEDIUM); EPSS percentile 52; affected product context: spiceworks / spiceworks; sources: NVD, Vendor Advisory."}, {"affected_label": "daily_tracker_system_project / daily_tracker_system", "affected_products": [{"canonicalProduct": "daily_tracker_system", "canonicalVendor": "daily_tracker_system_project", "cpe": "cpe:2.3:a:daily_tracker_system_project:daily_tracker_system:1.0:*:*:*:*:*:*:*", "ecosystem": null, "packageName": null, "product": "daily_tracker_system", "purl": null, "vendor": "daily_tracker_system_project", "version": "1.0"}], "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2020-24193/", "cvss_score": 9.8, "cvss_severity": "CRITICAL", "data_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2020-24193.json", "defensive_priority": "Priority review candidate", "epss_percentile": 0.84557, "epss_score": 0.0277, "exposure_hint": "authenticated boundary", "human_consequence": "An attacker may be able to read or change database-backed application data.", "human_impact_label": "authentication boundary review · SQL injection risk · authenticated boundary", "human_risk_summary": "CVE-2020-24193 for daily_tracker_system_project / daily_tracker_system: An attacker may be able to read or change database-backed application data.", "id": "CVE-2020-24193", "impact_tags": ["authentication boundary review", "SQL injection risk", "authenticated boundary review"], "kev": false, "observed_at": "2026-07-08T03:39:09.814067+00:00", "product": "daily_tracker_system", "public_human_impact": "Source describes authentication boundary review · SQL injection risk · authenticated boundary. Possible impact: An attacker may be able to read or change database-backed application data.", "public_human_summary": "NVD: A SQL injection vulnerability in login in Sourcecodetester Daily Tracker System 1.0 allows unauthenticated user to execute authentication bypass with SQL injection via the email parameter.", "public_human_what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "public_human_why_it_matters": "Source describes authentication boundary review · SQL injection risk · authenticated boundary. Possible impact: An attacker may be able to read or change database-backed application data.; CVSS 9.8 (CRITICAL); EPSS percentile 85; not listed in KEV; Remediation reference present; patch status requires confirmation in the linked advisory; sources: NVD.", "public_safe_summary": "NVD: A SQL injection vulnerability in login in Sourcecodetester Daily Tracker System 1.0 allows unauthenticated user to execute authentication bypass with SQL injection via the email parameter.", "public_status": "public_safe", "published_at": null, "redaction_notes": ["source-published defensive context retained", "vulnerability class, impact, affected context, and remediation references remain displayable"], "remediation_handoff": {"auto_remediation_allowed": false, "codex_prompt_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-24193-codex-prompt.md", "external_execution_allowed": false, "human_approval_required": true, "json_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-24193.json", "markdown_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-24193.md", "scan_allowed": false}, "remediation_urls": ["https://nvd.nist.gov/vuln/detail/CVE-2020-24193"], "sort_priority": 98.84557, "source_copy_policy": {"allowed": "source-published defensive facts, vulnerability class, impact, affected context, version and remediation facts", "excluded": "exploit procedures, exploit strings, shell commands, scanner instructions, procedural bypass detail, and reproduction material", "summary": "Official or semi-official source descriptions may be summarized for defensive triage; exploit-enabling procedure is removed."}, "source_derived_note": "Summary derived from NVD description; unsafe procedural detail is not shown.", "source_label": "NVD, Vendor Advisory", "source_published_affected": "vendor/product: daily_tracker_system_project / daily_tracker_system; affected version context: 1.0", "source_published_description": "NVD: A SQL injection vulnerability in login in Sourcecodetester Daily Tracker System 1.0 allows unauthenticated user to execute authentication bypass with SQL injection via the email parameter.", "source_published_evidence_refs": [{"source": "NVD", "type": "source_description", "url": null}, {"source": "Reference", "type": "reference", "url": "https://www.exploit-db.com/exploits/48787"}, {"source": "Reference", "type": "reference", "url": "http://sourcecodetester.com"}, {"source": "Reference", "type": "reference", "url": "https://www.exploit-db.com/exploits/48787"}, {"source": "Official Reference", "type": "reference", "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-24193"}], "source_published_impact": "Source describes authentication boundary review · SQL injection risk · authenticated boundary. Possible impact: An attacker may be able to read or change database-backed application data.", "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.", "source_published_summary": "NVD: A SQL injection vulnerability in login in Sourcecodetester Daily Tracker System 1.0 allows unauthenticated user to execute authentication bypass with SQL injection via the email parameter.", "sources": ["NVD", "Vendor Advisory"], "summary": "CVE-2020-24193 is a defensive prioritization candidate. NVD lists CVSS severity as CRITICAL. CVSS score is 9.8. EPSS score is 0.0277 with percentile 0.8456. Known exploited catalog status is not listed in NVD for this record. Use official advisories and vendor remediation references for defensive review.", "summary_ja": null, "title": "CVE-2020-24193 defensive priority signal", "title_ja": null, "translation": null, "updated_at": null, "urgency_reasons": ["CVSS CRITICAL", "affected product present", "vendor advisory present", "recent update"], "vendor": "daily_tracker_system_project", "what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "why_it_matters": "An attacker may be able to read or change database-backed application data; CVSS 9.8 (CRITICAL); EPSS percentile 85; affected product context: daily_tracker_system_project / daily_tracker_system; sources: NVD."}, {"affected_label": "daily_tracker_system_project / daily_tracker_system", "affected_products": [{"canonicalProduct": "daily_tracker_system", "canonicalVendor": "daily_tracker_system_project", "cpe": "cpe:2.3:a:daily_tracker_system_project:daily_tracker_system:1.0:*:*:*:*:*:*:*", "ecosystem": null, "packageName": null, "product": "daily_tracker_system", "purl": null, "vendor": "daily_tracker_system_project", "version": "1.0"}], "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2020-24194/", "cvss_score": 6.1, "cvss_severity": "MEDIUM", "data_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2020-24194.json", "defensive_priority": "Continuous monitoring candidate", "epss_percentile": 0.53283, "epss_score": 0.00835, "exposure_hint": "remote exposure", "human_consequence": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk · remote exposure.", "human_impact_label": "XSS risk · remote exposure", "human_risk_summary": "CVE-2020-24194 for daily_tracker_system_project / daily_tracker_system: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk · remote exposure.", "id": "CVE-2020-24194", "impact_tags": ["XSS risk", "remote exposure relevant"], "kev": false, "observed_at": "2026-07-08T03:39:09.814067+00:00", "product": "daily_tracker_system", "public_human_impact": "Source describes XSS risk · remote exposure. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk · remote exposure.", "public_human_summary": "NVD: A Cross-site scripting (XSS) vulnerability in 'user-profile.php' in SourceCodester Daily Tracker System v1.0 allows remote attackers to inject arbitrary web script or HTML via the 'fullname' parameter.", "public_human_what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "public_human_why_it_matters": "Source describes XSS risk · remote exposure. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk · remote exposure.; CVSS 6.1 (MEDIUM); EPSS percentile 53; not listed in KEV; Remediation reference present; patch status requires confirmation in the linked advisory; sources: NVD.", "public_safe_summary": "NVD: A Cross-site scripting (XSS) vulnerability in 'user-profile.php' in SourceCodester Daily Tracker System v1.0 allows remote attackers to inject arbitrary web script or HTML via the 'fullname' parameter.", "public_status": "public_safe", "published_at": null, "redaction_notes": ["source-published defensive context retained", "vulnerability class, impact, affected context, and remediation references remain displayable"], "remediation_handoff": {"auto_remediation_allowed": false, "codex_prompt_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-24194-codex-prompt.md", "external_execution_allowed": false, "human_approval_required": true, "json_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-24194.json", "markdown_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-24194.md", "scan_allowed": false}, "remediation_urls": ["https://cxsecurity.com/issue/WLB-2020090030"], "sort_priority": 61.53283, "source_copy_policy": {"allowed": "source-published defensive facts, vulnerability class, impact, affected context, version and remediation facts", "excluded": "exploit procedures, exploit strings, shell commands, scanner instructions, procedural bypass detail, and reproduction material", "summary": "Official or semi-official source descriptions may be summarized for defensive triage; exploit-enabling procedure is removed."}, "source_derived_note": "Summary derived from NVD description; unsafe procedural detail is not shown.", "source_label": "NVD, Vendor Advisory", "source_published_affected": "vendor/product: daily_tracker_system_project / daily_tracker_system; affected version context: 1.0", "source_published_description": "NVD: A Cross-site scripting (XSS) vulnerability in 'user-profile.php' in SourceCodester Daily Tracker System v1.0 allows remote attackers to inject arbitrary web script or HTML via the 'fullname' parameter.", "source_published_evidence_refs": [{"source": "NVD", "type": "source_description", "url": null}, {"source": "Reference", "type": "reference", "url": "https://cxsecurity.com/issue/WLB-2020090030"}, {"source": "Reference", "type": "reference", "url": "http://sourcecodetester.com"}, {"source": "Reference", "type": "reference", "url": "https://cxsecurity.com/issue/WLB-2020090030"}, {"source": "Official Reference", "type": "reference", "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-24194"}], "source_published_impact": "Source describes XSS risk · remote exposure. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk · remote exposure.", "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.", "source_published_summary": "NVD: A Cross-site scripting (XSS) vulnerability in 'user-profile.php' in SourceCodester Daily Tracker System v1.0 allows remote attackers to inject arbitrary web script or HTML via the 'fullname' parameter.", "sources": ["NVD", "Vendor Advisory"], "summary": "CVE-2020-24194 is a defensive prioritization candidate. NVD lists CVSS severity as MEDIUM. CVSS score is 6.1. EPSS score is 0.0083 with percentile 0.5328. Known exploited catalog status is not listed in NVD for this record. Use official advisories and vendor remediation references for defensive review.", "summary_ja": null, "title": "CVE-2020-24194 defensive priority signal", "title_ja": null, "translation": null, "updated_at": null, "urgency_reasons": ["affected product present", "vendor advisory present", "recent update", "remediation reference present"], "vendor": "daily_tracker_system_project", "what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "why_it_matters": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk · remote exposure; CVSS 6.1 (MEDIUM); EPSS percentile 53; affected product context: daily_tracker_system_project / daily_tracker_system..."}, {"affected_label": "gazie_project / gazie", "affected_products": [{"canonicalProduct": "gazie", "canonicalVendor": "gazie_project", "cpe": "cpe:2.3:a:gazie_project:gazie:7.29:*:*:*:*:*:*:*", "ecosystem": null, "packageName": null, "product": "gazie", "purl": null, "vendor": "gazie_project", "version": "7.29"}], "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2020-21731/", "cvss_score": 6.1, "cvss_severity": "MEDIUM", "data_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2020-21731.json", "defensive_priority": "Continuous monitoring candidate", "epss_percentile": 0.54231, "epss_score": 0.00864, "exposure_hint": "exposure unknown", "human_consequence": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.", "human_impact_label": "defensive exposure review", "human_risk_summary": "CVE-2020-21731 for gazie_project / gazie: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.", "id": "CVE-2020-21731", "impact_tags": [], "kev": false, "observed_at": "2026-07-08T03:39:09.814067+00:00", "product": "gazie", "public_human_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.", "public_human_summary": "NVD: Gazie 7.29 is affected by: Cross Site Scripting (XSS) via An attacker can inject JavaScript code, and the webapplication stores the injected code.", "public_human_what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "public_human_why_it_matters": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.; CVSS 6.1 (MEDIUM); EPSS percentile 54; not listed in KEV; Remediation reference present; patch status requires confirmation in the linked advisory; sources: NVD, Vendor Advisory.", "public_safe_summary": "NVD: Gazie 7.29 is affected by: Cross Site Scripting (XSS) via An attacker can inject JavaScript code, and the webapplication stores the injected code.", "public_status": "public_safe", "published_at": null, "redaction_notes": ["source-published defensive context retained", "vulnerability class, impact, affected context, and remediation references remain displayable"], "remediation_handoff": {"auto_remediation_allowed": false, "codex_prompt_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-21731-codex-prompt.md", "external_execution_allowed": false, "human_approval_required": true, "json_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-21731.json", "markdown_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-21731.md", "scan_allowed": false}, "remediation_urls": ["http://gazie.devincentiis.it/"], "sort_priority": 61.54231, "source_copy_policy": {"allowed": "source-published defensive facts, vulnerability class, impact, affected context, version and remediation facts", "excluded": "exploit procedures, exploit strings, shell commands, scanner instructions, procedural bypass detail, and reproduction material", "summary": "Official or semi-official source descriptions may be summarized for defensive triage; exploit-enabling procedure is removed."}, "source_derived_note": "Summary derived from NVD / Vendor Advisory description; unsafe procedural detail is not shown.", "source_label": "NVD, Vendor Advisory", "source_published_affected": "vendor/product: gazie_project / gazie; affected version context: 7.29", "source_published_description": "NVD: Gazie 7.29 is affected by: Cross Site Scripting (XSS) via An attacker can inject JavaScript code, and the webapplication stores the injected code.", "source_published_evidence_refs": [{"source": "NVD", "type": "source_description", "url": null}, {"source": "Vendor Advisory", "type": "source_description", "url": null}, {"source": "Vendor Advisory", "type": "reference", "url": "http://gazie.devincentiis.it/"}, {"source": "Reference", "type": "reference", "url": "https://github.com/Gr3gPr1est/BugReport/blob/master/CVE-2020-21731"}, {"source": "Reference", "type": "reference", "url": "http://gazie.com"}, {"source": "Vendor Advisory", "type": "reference", "url": "http://gazie.devincentiis.it/"}, {"source": "Reference", "type": "reference", "url": "https://github.com/Gr3gPr1est/BugReport/blob/master/CVE-2020-21731"}, {"source": "Official Reference", "type": "reference", "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-21731"}], "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.", "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.", "source_published_summary": "NVD: Gazie 7.29 is affected by: Cross Site Scripting (XSS) via An attacker can inject JavaScript code, and the webapplication stores the injected code.", "sources": ["NVD", "Vendor Advisory"], "summary": "CVE-2020-21731 is a defensive prioritization candidate. NVD lists CVSS severity as MEDIUM. CVSS score is 6.1. EPSS score is 0.0086 with percentile 0.5423. Known exploited catalog status is not listed in NVD for this record. Use official advisories and vendor remediation references for defensive review.", "summary_ja": null, "title": "CVE-2020-21731 defensive priority signal", "title_ja": null, "translation": null, "updated_at": null, "urgency_reasons": ["affected product present", "vendor advisory present", "recent update", "remediation reference present"], "vendor": "gazie_project", "what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "why_it_matters": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review; CVSS 6.1 (MEDIUM); EPSS percentile 54; affected product context: gazie_project / gazie; sources: NVD, Vendor Advisory."}, {"affected_label": "rukovoditel / rukovoditel", "affected_products": [{"canonicalProduct": "rukovoditel", "canonicalVendor": "rukovoditel", "cpe": "cpe:2.3:a:rukovoditel:rukovoditel:2.6:*:*:*:*:*:*:*", "ecosystem": null, "packageName": null, "product": "rukovoditel", "purl": null, "vendor": "rukovoditel", "version": "2.6"}], "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2020-21732/", "cvss_score": 6.1, "cvss_severity": "MEDIUM", "data_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2020-21732.json", "defensive_priority": "Continuous monitoring candidate", "epss_percentile": 0.54231, "epss_score": 0.00864, "exposure_hint": "exposure unknown", "human_consequence": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk.", "human_impact_label": "XSS risk", "human_risk_summary": "CVE-2020-21732 for rukovoditel / rukovoditel: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk.", "id": "CVE-2020-21732", "impact_tags": ["XSS risk"], "kev": false, "observed_at": "2026-07-08T03:39:09.814067+00:00", "product": "rukovoditel", "public_human_impact": "Source describes XSS risk. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk.", "public_human_summary": "NVD: Rukovoditel Project Management app 2.6 is affected by: Cross Site Scripting (XSS). NVD: An attacker can add JavaScript code to the filename.", "public_human_what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "public_human_why_it_matters": "Source describes XSS risk. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk.; CVSS 6.1 (MEDIUM); EPSS percentile 54; not listed in KEV; Remediation reference present; patch status requires confirmation in the linked advisory; sources: NVD, Vendor Advisory.", "public_safe_summary": "NVD: Rukovoditel Project Management app 2.6 is affected by: Cross Site Scripting (XSS). NVD: An attacker can add JavaScript code to the filename.", "public_status": "public_safe", "published_at": null, "redaction_notes": ["source-published defensive context retained", "vulnerability class, impact, affected context, and remediation references remain displayable"], "remediation_handoff": {"auto_remediation_allowed": false, "codex_prompt_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-21732-codex-prompt.md", "external_execution_allowed": false, "human_approval_required": true, "json_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-21732.json", "markdown_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-21732.md", "scan_allowed": false}, "remediation_urls": ["https://www.rukovoditel.net"], "sort_priority": 61.54231, "source_copy_policy": {"allowed": "source-published defensive facts, vulnerability class, impact, affected context, version and remediation facts", "excluded": "exploit procedures, exploit strings, shell commands, scanner instructions, procedural bypass detail, and reproduction material", "summary": "Official or semi-official source descriptions may be summarized for defensive triage; exploit-enabling procedure is removed."}, "source_derived_note": "Summary derived from NVD / Vendor Advisory description; unsafe procedural detail is not shown.", "source_label": "NVD, Vendor Advisory", "source_published_affected": "vendor/product: rukovoditel / rukovoditel; affected version context: 2.6", "source_published_description": "NVD: Rukovoditel Project Management app 2.6 is affected by: Cross Site Scripting (XSS). NVD: An attacker can add JavaScript code to the filename.", "source_published_evidence_refs": [{"source": "NVD", "type": "source_description", "url": null}, {"source": "Vendor Advisory", "type": "source_description", "url": null}, {"source": "Reference", "type": "reference", "url": "https://github.com/Gr3gPr1est/BugReport/blob/master/CVE-2020-21732"}, {"source": "Vendor Advisory", "type": "reference", "url": "https://www.rukovoditel.net"}, {"source": "Reference", "type": "reference", "url": "http://rukovoditel.com"}, {"source": "Reference", "type": "reference", "url": "https://github.com/Gr3gPr1est/BugReport/blob/master/CVE-2020-21732"}, {"source": "Vendor Advisory", "type": "reference", "url": "https://www.rukovoditel.net"}, {"source": "Official Reference", "type": "reference", "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-21732"}], "source_published_impact": "Source describes XSS risk. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk.", "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.", "source_published_summary": "NVD: Rukovoditel Project Management app 2.6 is affected by: Cross Site Scripting (XSS). NVD: An attacker can add JavaScript code to the filename.", "sources": ["NVD", "Vendor Advisory"], "summary": "CVE-2020-21732 is a defensive prioritization candidate. NVD lists CVSS severity as MEDIUM. CVSS score is 6.1. EPSS score is 0.0086 with percentile 0.5423. Known exploited catalog status is not listed in NVD for this record. Use official advisories and vendor remediation references for defensive review.", "summary_ja": null, "title": "CVE-2020-21732 defensive priority signal", "title_ja": null, "translation": null, "updated_at": null, "urgency_reasons": ["affected product present", "vendor advisory present", "recent update", "remediation reference present"], "vendor": "rukovoditel", "what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "why_it_matters": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk; CVSS 6.1 (MEDIUM); EPSS percentile 54; affected product context: rukovoditel / rukovoditel; sources: NVD, Vendor Advisory."}, {"affected_label": "sagemcom / f\\@st_3686_firmware", "affected_products": [{"canonicalProduct": "f\\@st_3686_firmware", "canonicalVendor": "sagemcom", "cpe": "cpe:2.3:o:sagemcom:f\\@st_3686_firmware:1.0_hun_3.97.0:*:*:*:*:*:*:*", "ecosystem": null, "packageName": null, "product": "f\\@st_3686_firmware", "purl": null, "vendor": "sagemcom", "version": "1.0_hun_3.97.0"}, {"canonicalProduct": "f\\@st_3686", "canonicalVendor": "sagemcom", "cpe": "cpe:2.3:h:sagemcom:f\\@st_3686:-:*:*:*:*:*:*:*", "ecosystem": null, "packageName": null, "product": "f\\@st_3686", "purl": null, "vendor": "sagemcom", "version": "-"}], "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2020-21733/", "cvss_score": 6.1, "cvss_severity": "MEDIUM", "data_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2020-21733.json", "defensive_priority": "Continuous monitoring candidate", "epss_percentile": 0.58423, "epss_score": 0.00995, "exposure_hint": "exposure unknown", "human_consequence": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk.", "human_impact_label": "XSS risk", "human_risk_summary": "CVE-2020-21733 for sagemcom / f\\@st_3686_firmware: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk.", "id": "CVE-2020-21733", "impact_tags": ["XSS risk"], "kev": false, "observed_at": "2026-07-08T03:39:09.814067+00:00", "product": "f\\@st_3686_firmware", "public_human_impact": "Source describes XSS risk. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk.", "public_human_summary": "NVD: Sagemcom F@ST3686 v1.0 HUN 3.97.0 has XSS via RgDiagnostics.asp, RgDdns.asp, RgFirewallEL.asp, RgVpnL2tpPptp.asp.", "public_human_what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "public_human_why_it_matters": "Source describes XSS risk. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk.; CVSS 6.1 (MEDIUM); EPSS percentile 58; not listed in KEV; Remediation reference present; patch status requires confirmation in the linked advisory; sources: NVD, Vendor Advisory.", "public_safe_summary": "NVD: Sagemcom F@ST3686 v1.0 HUN 3.97.0 has XSS via RgDiagnostics.asp, RgDdns.asp, RgFirewallEL.asp, RgVpnL2tpPptp.asp.", "public_status": "public_safe", "published_at": null, "redaction_notes": ["source-published defensive context retained", "vulnerability class, impact, affected context, and remediation references remain displayable"], "remediation_handoff": {"auto_remediation_allowed": false, "codex_prompt_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-21733-codex-prompt.md", "external_execution_allowed": false, "human_approval_required": true, "json_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-21733.json", "markdown_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-21733.md", "scan_allowed": false}, "remediation_urls": ["http://sagemcom.com"], "sort_priority": 61.58423, "source_copy_policy": {"allowed": "source-published defensive facts, vulnerability class, impact, affected context, version and remediation facts", "excluded": "exploit procedures, exploit strings, shell commands, scanner instructions, procedural bypass detail, and reproduction material", "summary": "Official or semi-official source descriptions may be summarized for defensive triage; exploit-enabling procedure is removed."}, "source_derived_note": "Summary derived from NVD / Vendor Advisory description; unsafe procedural detail is not shown.", "source_label": "NVD, Vendor Advisory", "source_published_affected": "vendor/product: sagemcom / f\\@st_3686_firmware; affected version context: -, 1.0_hun_3.97.0", "source_published_description": "NVD: Sagemcom F@ST3686 v1.0 HUN 3.97.0 has XSS via RgDiagnostics.asp, RgDdns.asp, RgFirewallEL.asp, RgVpnL2tpPptp.asp.", "source_published_evidence_refs": [{"source": "NVD", "type": "source_description", "url": null}, {"source": "Vendor Advisory", "type": "source_description", "url": null}, {"source": "Reference", "type": "reference", "url": "https://github.com/Gr3gPr1est/BugReport/blob/master/CVE-2020-21733"}, {"source": "Reference", "type": "reference", "url": "https://github.com/Gr3gPr1est/BugReport/blob/master/SAGEM_F%40ST3686_v1.0_HUN_3.97.0_XSS_Vuln..pdf"}, {"source": "Vendor Advisory", "type": "reference", "url": "http://sagemcom.com"}, {"source": "Reference", "type": "reference", "url": "http://sagemcomfst3686v10hun3970.com"}, {"source": "Reference", "type": "reference", "url": "https://github.com/Gr3gPr1est/BugReport/blob/master/CVE-2020-21733"}, {"source": "Reference", "type": "reference", "url": "https://github.com/Gr3gPr1est/BugReport/blob/master/SAGEM_F%40ST3686_v1.0_HUN_3.97.0_XSS_Vuln..pdf"}, {"source": "Official Reference", "type": "reference", "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-21733"}], "source_published_impact": "Source describes XSS risk. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk.", "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.", "source_published_summary": "NVD: Sagemcom F@ST3686 v1.0 HUN 3.97.0 has XSS via RgDiagnostics.asp, RgDdns.asp, RgFirewallEL.asp, RgVpnL2tpPptp.asp.", "sources": ["NVD", "Vendor Advisory"], "summary": "CVE-2020-21733 is a defensive prioritization candidate. NVD lists CVSS severity as MEDIUM. CVSS score is 6.1. EPSS score is 0.0100 with percentile 0.5842. Known exploited catalog status is not listed in NVD for this record. Use official advisories and vendor remediation references for defensive review.", "summary_ja": null, "title": "CVE-2020-21733 defensive priority signal", "title_ja": null, "translation": null, "updated_at": null, "urgency_reasons": ["affected product present", "vendor advisory present", "recent update", "remediation reference present"], "vendor": "sagemcom", "what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "why_it_matters": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk; CVSS 6.1 (MEDIUM); EPSS percentile 58; affected product context: sagemcom / f\\@st_3686_firmware; sources: NVD, Vendor Advisory."}, {"affected_label": "spiceworks / spiceworks", "affected_products": [{"canonicalProduct": "spiceworks", "canonicalVendor": "spiceworks", "cpe": "cpe:2.3:a:spiceworks:spiceworks:*:*:*:*:*:*:*:*", "ecosystem": null, "packageName": null, "product": "spiceworks", "purl": null, "vendor": "spiceworks", "version": null}], "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2020-23451/", "cvss_score": 8.8, "cvss_severity": "HIGH", "data_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2020-23451.json", "defensive_priority": "Continuous monitoring candidate", "epss_percentile": 0.44482, "epss_score": 0.00601, "exposure_hint": "exposure unknown", "human_consequence": "An attacker may cross a privilege boundary and gain more access than intended.", "human_impact_label": "privilege escalation risk", "human_risk_summary": "CVE-2020-23451 for spiceworks / spiceworks: An attacker may cross a privilege boundary and gain more access than intended.", "id": "CVE-2020-23451", "impact_tags": ["privilege boundary review"], "kev": false, "observed_at": "2026-07-08T03:39:09.814067+00:00", "product": "spiceworks", "public_human_impact": "Source describes privilege escalation risk. Possible impact: An attacker may cross a privilege boundary and gain more access than intended.", "public_human_summary": "NVD: Spiceworks Version <= 7.5.00107 is affected by CSRF which can lead to privilege escalation via \"/settings/v1/users\" function.", "public_human_what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "public_human_why_it_matters": "Source describes privilege escalation risk. Possible impact: An attacker may cross a privilege boundary and gain more access than intended.; CVSS 8.8 (HIGH); EPSS percentile 44; not listed in KEV; Remediation reference present; patch status requires confirmation in the linked advisory; sources: NVD.", "public_safe_summary": "NVD: Spiceworks Version <= 7.5.00107 is affected by CSRF which can lead to privilege escalation via \"/settings/v1/users\" function.", "public_status": "public_safe", "published_at": null, "redaction_notes": ["source-published defensive context retained", "vulnerability class, impact, affected context, and remediation references remain displayable"], "remediation_handoff": {"auto_remediation_allowed": false, "codex_prompt_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-23451-codex-prompt.md", "external_execution_allowed": false, "human_approval_required": true, "json_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-23451.json", "markdown_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-23451.md", "scan_allowed": false}, "remediation_urls": ["https://nvd.nist.gov/vuln/detail/CVE-2020-23451"], "sort_priority": 88.44481999999999, "source_copy_policy": {"allowed": "source-published defensive facts, vulnerability class, impact, affected context, version and remediation facts", "excluded": "exploit procedures, exploit strings, shell commands, scanner instructions, procedural bypass detail, and reproduction material", "summary": "Official or semi-official source descriptions may be summarized for defensive triage; exploit-enabling procedure is removed."}, "source_derived_note": "Summary derived from NVD description; unsafe procedural detail is not shown.", "source_label": "NVD, Vendor Advisory", "source_published_affected": "vendor/product: spiceworks / spiceworks", "source_published_description": "NVD: Spiceworks Version <= 7.5.00107 is affected by CSRF which can lead to privilege escalation via \"/settings/v1/users\" function.", "source_published_evidence_refs": [{"source": "NVD", "type": "source_description", "url": null}, {"source": "Reference", "type": "reference", "url": "https://abuyv.com/cve/spiceworks-csrf-via-xss"}, {"source": "Reference", "type": "reference", "url": "http://spiceworks.com"}, {"source": "Reference", "type": "reference", "url": "https://abuyv.com/cve/spiceworks-csrf-via-xss"}, {"source": "Official Reference", "type": "reference", "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-23451"}], "source_published_impact": "Source describes privilege escalation risk. Possible impact: An attacker may cross a privilege boundary and gain more access than intended.", "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.", "source_published_summary": "NVD: Spiceworks Version <= 7.5.00107 is affected by CSRF which can lead to privilege escalation via \"/settings/v1/users\" function.", "sources": ["NVD", "Vendor Advisory"], "summary": "CVE-2020-23451 is a defensive prioritization candidate. NVD lists CVSS severity as HIGH. CVSS score is 8.8. EPSS score is 0.0060 with percentile 0.4448. Known exploited catalog status is not listed in NVD for this record. Use official advisories and vendor remediation references for defensive review.", "summary_ja": null, "title": "CVE-2020-23451 defensive priority signal", "title_ja": null, "translation": null, "updated_at": null, "urgency_reasons": ["CVSS HIGH", "affected product present", "vendor advisory present", "recent update"], "vendor": "spiceworks", "what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "why_it_matters": "An attacker may cross a privilege boundary and gain more access than intended; CVSS 8.8 (HIGH); EPSS percentile 44; affected product context: spiceworks / spiceworks; sources: NVD."}, {"affected_label": "verint / workforce_optimization", "affected_products": [{"canonicalProduct": "workforce_optimization", "canonicalVendor": "verint", "cpe": "cpe:2.3:a:verint:workforce_optimization:15.1.0.37634:*:*:*:*:*:*:*", "ecosystem": null, "packageName": null, "product": "workforce_optimization", "purl": null, "vendor": "verint", "version": "15.1.0.37634"}], "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2020-23446/", "cvss_score": 5.3, "cvss_severity": "MEDIUM", "data_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2020-23446.json", "defensive_priority": "Continuous monitoring candidate", "epss_percentile": 0.70416, "epss_score": 0.0146, "exposure_hint": "exposure unknown", "human_consequence": "An attacker may be able to access information that should not be exposed.", "human_impact_label": "information exposure review", "human_risk_summary": "CVE-2020-23446 for verint / workforce_optimization: An attacker may be able to access information that should not be exposed.", "id": "CVE-2020-23446", "impact_tags": ["information exposure review"], "kev": false, "observed_at": "2026-07-08T03:39:09.814067+00:00", "product": "workforce_optimization", "public_human_impact": "Source describes information exposure review. Possible impact: An attacker may be able to access information that should not be exposed.", "public_human_summary": "NVD: Verint Workforce Optimization suite 15.1 (15.1.0.37634) has Unauthenticated Information Disclosure via API", "public_human_what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "public_human_why_it_matters": "Source describes information exposure review. Possible impact: An attacker may be able to access information that should not be exposed.; CVSS 5.3 (MEDIUM); EPSS percentile 70; not listed in KEV; Remediation reference present; patch status requires confirmation in the linked advisory; sources: NVD, Vendor Advisory.", "public_safe_summary": "NVD: Verint Workforce Optimization suite 15.1 (15.1.0.37634) has Unauthenticated Information Disclosure via API", "public_status": "public_safe", "published_at": null, "redaction_notes": ["source-published defensive context retained", "vulnerability class, impact, affected context, and remediation references remain displayable"], "remediation_handoff": {"auto_remediation_allowed": false, "codex_prompt_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-23446-codex-prompt.md", "external_execution_allowed": false, "human_approval_required": true, "json_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-23446.json", "markdown_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-23446.md", "scan_allowed": false}, "remediation_urls": ["http://verint.com"], "sort_priority": 53.70416, "source_copy_policy": {"allowed": "source-published defensive facts, vulnerability class, impact, affected context, version and remediation facts", "excluded": "exploit procedures, exploit strings, shell commands, scanner instructions, procedural bypass detail, and reproduction material", "summary": "Official or semi-official source descriptions may be summarized for defensive triage; exploit-enabling procedure is removed."}, "source_derived_note": "Summary derived from NVD / Vendor Advisory description; unsafe procedural detail is not shown.", "source_label": "NVD, Vendor Advisory", "source_published_affected": "vendor/product: verint / workforce_optimization; affected version context: 15.1.0.37634", "source_published_description": "NVD: Verint Workforce Optimization suite 15.1 (15.1.0.37634) has Unauthenticated Information Disclosure via API", "source_published_evidence_refs": [{"source": "NVD", "type": "source_description", "url": null}, {"source": "Vendor Advisory", "type": "source_description", "url": null}, {"source": "Reference", "type": "reference", "url": "http://cvewalkthrough.com/variant-unauthenticated-information-disclosure-via-api/"}, {"source": "Reference", "type": "reference", "url": "https://tejaspingulkar.blogspot.com/2020/09/cve-2020-23446-verint-workforce.html"}, {"source": "Reference", "type": "reference", "url": "http://cvewalkthrough.com/variant-unauthenticated-information-disclosure-via-api/"}, {"source": "Vendor Advisory", "type": "reference", "url": "http://verint.com"}, {"source": "Reference", "type": "reference", "url": "https://tejaspingulkar.blogspot.com/2020/09/cve-2020-23446-verint-workforce.html"}, {"source": "Official Reference", "type": "reference", "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-23446"}], "source_published_impact": "Source describes information exposure review. Possible impact: An attacker may be able to access information that should not be exposed.", "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.", "source_published_summary": "NVD: Verint Workforce Optimization suite 15.1 (15.1.0.37634) has Unauthenticated Information Disclosure via API", "sources": ["NVD", "Vendor Advisory"], "summary": "CVE-2020-23446 is a defensive prioritization candidate. NVD lists CVSS severity as MEDIUM. CVSS score is 5.3. EPSS score is 0.0146 with percentile 0.7042. Known exploited catalog status is not listed in NVD for this record. Use official advisories and vendor remediation references for defensive review.", "summary_ja": null, "title": "CVE-2020-23446 defensive priority signal", "title_ja": null, "translation": null, "updated_at": null, "urgency_reasons": ["affected product present", "vendor advisory present", "recent update", "remediation reference present"], "vendor": "verint", "what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "why_it_matters": "An attacker may be able to access information that should not be exposed; CVSS 5.3 (MEDIUM); EPSS percentile 70; affected product context: verint / workforce_optimization; sources: NVD, Vendor Advisory."}, {"affected_label": "phpgurukul / zoo_management_system", "affected_products": [{"canonicalProduct": "zoo_management_system", "canonicalVendor": "phpgurukul", "cpe": "cpe:2.3:a:phpgurukul:zoo_management_system:1.0:*:*:*:*:*:*:*", "ecosystem": null, "packageName": null, "product": "zoo_management_system", "purl": null, "vendor": "phpgurukul", "version": "1.0"}], "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2020-25487/", "cvss_score": 7.8, "cvss_severity": "HIGH", "data_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2020-25487.json", "defensive_priority": "Continuous monitoring candidate", "epss_percentile": 0.42196, "epss_score": 0.00553, "exposure_hint": "exposure unknown", "human_consequence": "An attacker may be able to read or change database-backed application data.", "human_impact_label": "SQL injection risk", "human_risk_summary": "CVE-2020-25487 for phpgurukul / zoo_management_system: An attacker may be able to read or change database-backed application data.", "id": "CVE-2020-25487", "impact_tags": ["SQL injection risk"], "kev": false, "observed_at": "2026-07-08T03:39:09.814067+00:00", "product": "zoo_management_system", "public_human_impact": "Source describes SQL injection risk. Possible impact: An attacker may be able to read or change database-backed application data.", "public_human_summary": "NVD: PHPGURUKUL Zoo Management System Using PHP and MySQL version 1.0 is affected by: SQL Injection via zms/animal-detail.php.", "public_human_what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "public_human_why_it_matters": "Source describes SQL injection risk. Possible impact: An attacker may be able to read or change database-backed application data.; CVSS 7.8 (HIGH); EPSS percentile 42; not listed in KEV; Remediation reference present; patch status requires confirmation in the linked advisory; sources: NVD.", "public_safe_summary": "NVD: PHPGURUKUL Zoo Management System Using PHP and MySQL version 1.0 is affected by: SQL Injection via zms/animal-detail.php.", "public_status": "public_safe", "published_at": null, "redaction_notes": ["source-published defensive context retained", "vulnerability class, impact, affected context, and remediation references remain displayable"], "remediation_handoff": {"auto_remediation_allowed": false, "codex_prompt_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-25487-codex-prompt.md", "external_execution_allowed": false, "human_approval_required": true, "json_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-25487.json", "markdown_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-25487.md", "scan_allowed": false}, "remediation_urls": ["https://nvd.nist.gov/vuln/detail/CVE-2020-25487"], "sort_priority": 78.42196, "source_copy_policy": {"allowed": "source-published defensive facts, vulnerability class, impact, affected context, version and remediation facts", "excluded": "exploit procedures, exploit strings, shell commands, scanner instructions, procedural bypass detail, and reproduction material", "summary": "Official or semi-official source descriptions may be summarized for defensive triage; exploit-enabling procedure is removed."}, "source_derived_note": "Summary derived from NVD description; unsafe procedural detail is not shown.", "source_label": "NVD, Vendor Advisory", "source_published_affected": "vendor/product: phpgurukul / zoo_management_system; affected version context: 1.0", "source_published_description": "NVD: PHPGURUKUL Zoo Management System Using PHP and MySQL version 1.0 is affected by: SQL Injection via zms/animal-detail.php.", "source_published_evidence_refs": [{"source": "NVD", "type": "source_description", "url": null}, {"source": "Reference", "type": "reference", "url": "https://github.com/Ko-kn3t/CVE-2020-25487"}, {"source": "Reference", "type": "reference", "url": "https://phpgurukul.com/zoo-management-system-using-php-and-mysql/"}, {"source": "Reference", "type": "reference", "url": "http://phpgurukul.com"}, {"source": "Reference", "type": "reference", "url": "https://github.com/Ko-kn3t/CVE-2020-25487"}, {"source": "Reference", "type": "reference", "url": "https://phpgurukul.com/zoo-management-system-using-php-and-mysql/"}, {"source": "Official Reference", "type": "reference", "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-25487"}], "source_published_impact": "Source describes SQL injection risk. Possible impact: An attacker may be able to read or change database-backed application data.", "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.", "source_published_summary": "NVD: PHPGURUKUL Zoo Management System Using PHP and MySQL version 1.0 is affected by: SQL Injection via zms/animal-detail.php.", "sources": ["NVD", "Vendor Advisory"], "summary": "CVE-2020-25487 is a defensive prioritization candidate. NVD lists CVSS severity as HIGH. CVSS score is 7.8. EPSS score is 0.0055 with percentile 0.4220. Known exploited catalog status is not listed in NVD for this record. Use official advisories and vendor remediation references for defensive review.", "summary_ja": null, "title": "CVE-2020-25487 defensive priority signal", "title_ja": null, "translation": null, "updated_at": null, "urgency_reasons": ["CVSS HIGH", "affected product present", "vendor advisory present", "recent update"], "vendor": "phpgurukul", "what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "why_it_matters": "An attacker may be able to read or change database-backed application data; CVSS 7.8 (HIGH); EPSS percentile 42; affected product context: phpgurukul / zoo_management_system; sources: NVD."}, {"affected_label": "simple_library_management_system_project / simple_library_management_system", "affected_products": [{"canonicalProduct": "simple_library_management_system", "canonicalVendor": "simple_library_management_system_project", "cpe": "cpe:2.3:a:simple_library_management_system_project:simple_library_management_system:1.0:*:*:*:*:*:*:*", "ecosystem": null, "packageName": null, "product": "simple_library_management_system", "purl": null, "vendor": "simple_library_management_system_project", "version": "1.0"}], "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2020-25514/", "cvss_score": 8.4, "cvss_severity": "HIGH", "data_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2020-25514.json", "defensive_priority": "Continuous monitoring candidate", "epss_percentile": 0.45772, "epss_score": 0.00629, "exposure_hint": "exposure unknown", "human_consequence": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.", "human_impact_label": "high severity review", "human_risk_summary": "CVE-2020-25514 for simple_library_management_system_project / simple_library_management_system: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.", "id": "CVE-2020-25514", "impact_tags": [], "kev": false, "observed_at": "2026-07-08T03:39:09.814067+00:00", "product": "simple_library_management_system", "public_human_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.", "public_human_summary": "NVD: Sourcecodester Simple Library Management System 1.0 is affected by Incorrect Access Control via the Login Panel,", "public_human_what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "public_human_why_it_matters": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.; CVSS 8.4 (HIGH); EPSS percentile 46; not listed in KEV; Remediation reference present; patch status requires confirmation in the linked advisory; sources: NVD.", "public_safe_summary": "NVD: Sourcecodester Simple Library Management System 1.0 is affected by Incorrect Access Control via the Login Panel,", "public_status": "public_safe", "published_at": null, "redaction_notes": ["source-published defensive context retained", "vulnerability class, impact, affected context, and remediation references remain displayable"], "remediation_handoff": {"auto_remediation_allowed": false, "codex_prompt_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-25514-codex-prompt.md", "external_execution_allowed": false, "human_approval_required": true, "json_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-25514.json", "markdown_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-25514.md", "scan_allowed": false}, "remediation_urls": ["https://nvd.nist.gov/vuln/detail/CVE-2020-25514"], "sort_priority": 84.45772, "source_copy_policy": {"allowed": "source-published defensive facts, vulnerability class, impact, affected context, version and remediation facts", "excluded": "exploit procedures, exploit strings, shell commands, scanner instructions, procedural bypass detail, and reproduction material", "summary": "Official or semi-official source descriptions may be summarized for defensive triage; exploit-enabling procedure is removed."}, "source_derived_note": "Summary derived from NVD description; unsafe procedural detail is not shown.", "source_label": "NVD, Vendor Advisory", "source_published_affected": "vendor/product: simple_library_management_system_project / simple_library_management_system; affected version context: 1.0", "source_published_description": "NVD: Sourcecodester Simple Library Management System 1.0 is affected by Incorrect Access Control via the Login Panel,", "source_published_evidence_refs": [{"source": "NVD", "type": "source_description", "url": null}, {"source": "Reference", "type": "reference", "url": "https://github.com/Ko-kn3t/CVE-2020-25514"}, {"source": "Reference", "type": "reference", "url": "https://www.sourcecodester.com"}, {"source": "Reference", "type": "reference", "url": "http://simple.com"}, {"source": "Reference", "type": "reference", "url": "https://github.com/Ko-kn3t/CVE-2020-25514"}, {"source": "Reference", "type": "reference", "url": "https://www.sourcecodester.com"}, {"source": "Official Reference", "type": "reference", "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-25514"}], "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.", "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.", "source_published_summary": "NVD: Sourcecodester Simple Library Management System 1.0 is affected by Incorrect Access Control via the Login Panel,", "sources": ["NVD", "Vendor Advisory"], "summary": "CVE-2020-25514 is a defensive prioritization candidate. NVD lists CVSS severity as HIGH. CVSS score is 8.4. EPSS score is 0.0063 with percentile 0.4577. Known exploited catalog status is not listed in NVD for this record. Use official advisories and vendor remediation references for defensive review.", "summary_ja": null, "title": "CVE-2020-25514 defensive priority signal", "title_ja": null, "translation": null, "updated_at": null, "urgency_reasons": ["CVSS HIGH", "affected product present", "vendor advisory present", "recent update"], "vendor": "simple_library_management_system_project", "what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "why_it_matters": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review; CVSS 8.4 (HIGH); EPSS percentile 46; affected product context: simple_library_management_system_project /..."}, {"affected_label": "simple_library_management_system_project / simple_library_management_system", "affected_products": [{"canonicalProduct": "simple_library_management_system", "canonicalVendor": "simple_library_management_system_project", "cpe": "cpe:2.3:a:simple_library_management_system_project:simple_library_management_system:1.0:*:*:*:*:*:*:*", "ecosystem": null, "packageName": null, "product": "simple_library_management_system", "purl": null, "vendor": "simple_library_management_system_project", "version": "1.0"}], "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2020-25515/", "cvss_score": 7.8, "cvss_severity": "HIGH", "data_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2020-25515.json", "defensive_priority": "Continuous monitoring candidate", "epss_percentile": 0.41554, "epss_score": 0.00541, "exposure_hint": "exposure unknown", "human_consequence": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.", "human_impact_label": "high severity review", "human_risk_summary": "CVE-2020-25515 for simple_library_management_system_project / simple_library_management_system: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.", "id": "CVE-2020-25515", "impact_tags": [], "kev": false, "observed_at": "2026-07-08T03:39:09.814067+00:00", "product": "simple_library_management_system", "public_human_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.", "public_human_summary": "NVD: Sourcecodester Simple Library Management System 1.0 is affected by Insecure Permissions via Books > New Book ,", "public_human_what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "public_human_why_it_matters": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.; CVSS 7.8 (HIGH); EPSS percentile 42; not listed in KEV; Remediation reference present; patch status requires confirmation in the linked advisory; sources: NVD.", "public_safe_summary": "NVD: Sourcecodester Simple Library Management System 1.0 is affected by Insecure Permissions via Books > New Book ,", "public_status": "public_safe", "published_at": null, "redaction_notes": ["source-published defensive context retained", "vulnerability class, impact, affected context, and remediation references remain displayable"], "remediation_handoff": {"auto_remediation_allowed": false, "codex_prompt_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-25515-codex-prompt.md", "external_execution_allowed": false, "human_approval_required": true, "json_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-25515.json", "markdown_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-25515.md", "scan_allowed": false}, "remediation_urls": ["https://nvd.nist.gov/vuln/detail/CVE-2020-25515"], "sort_priority": 78.41554, "source_copy_policy": {"allowed": "source-published defensive facts, vulnerability class, impact, affected context, version and remediation facts", "excluded": "exploit procedures, exploit strings, shell commands, scanner instructions, procedural bypass detail, and reproduction material", "summary": "Official or semi-official source descriptions may be summarized for defensive triage; exploit-enabling procedure is removed."}, "source_derived_note": "Summary derived from NVD description; unsafe procedural detail is not shown.", "source_label": "NVD, Vendor Advisory", "source_published_affected": "vendor/product: simple_library_management_system_project / simple_library_management_system; affected version context: 1.0", "source_published_description": "NVD: Sourcecodester Simple Library Management System 1.0 is affected by Insecure Permissions via Books > New Book ,", "source_published_evidence_refs": [{"source": "NVD", "type": "source_description", "url": null}, {"source": "Reference", "type": "reference", "url": "https://github.com/Ko-kn3t/CVE-2020-25515"}, {"source": "Reference", "type": "reference", "url": "https://www.sourcecodester.com"}, {"source": "Reference", "type": "reference", "url": "http://simple.com"}, {"source": "Reference", "type": "reference", "url": "https://github.com/Ko-kn3t/CVE-2020-25515"}, {"source": "Reference", "type": "reference", "url": "https://www.sourcecodester.com"}, {"source": "Official Reference", "type": "reference", "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-25515"}], "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.", "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.", "source_published_summary": "NVD: Sourcecodester Simple Library Management System 1.0 is affected by Insecure Permissions via Books > New Book ,", "sources": ["NVD", "Vendor Advisory"], "summary": "CVE-2020-25515 is a defensive prioritization candidate. NVD lists CVSS severity as HIGH. CVSS score is 7.8. EPSS score is 0.0054 with percentile 0.4155. Known exploited catalog status is not listed in NVD for this record. Use official advisories and vendor remediation references for defensive review.", "summary_ja": null, "title": "CVE-2020-25515 defensive priority signal", "title_ja": null, "translation": null, "updated_at": null, "urgency_reasons": ["CVSS HIGH", "affected product present", "vendor advisory present", "recent update"], "vendor": "simple_library_management_system_project", "what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "why_it_matters": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review; CVSS 7.8 (HIGH); EPSS percentile 42; affected product context: simple_library_management_system_project /..."}, {"affected_label": "zohocorp / manageengine_adselfservice_plus", "affected_products": [{"canonicalProduct": "manageengine_adselfservice_plus", "canonicalVendor": "zohocorp", "cpe": "cpe:2.3:a:zohocorp:manageengine_adselfservice_plus:*:*:*:*:*:*:*:*", "ecosystem": null, "packageName": null, "product": "manageengine_adselfservice_plus", "purl": null, "vendor": "zohocorp", "version": null}, {"canonicalProduct": "manageengine_adselfservice_plus", "canonicalVendor": "zohocorp", "cpe": "cpe:2.3:a:zohocorp:manageengine_adselfservice_plus:5.5:-:*:*:*:*:*:*", "ecosystem": null, "packageName": null, "product": "manageengine_adselfservice_plus", "purl": null, "vendor": "zohocorp", "version": "5.5"}], "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2018-5353/", "cvss_score": 9.8, "cvss_severity": "CRITICAL", "data_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2018-5353.json", "defensive_priority": "Priority review candidate", "epss_percentile": 0.94138, "epss_score": 0.08103, "exposure_hint": "remote exposure", "human_consequence": "This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary.", "human_impact_label": "remote exposure · authenticated boundary", "human_risk_summary": "CVE-2018-5353 for zohocorp / manageengine_adselfservice_plus: This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary.", "id": "CVE-2018-5353", "impact_tags": ["remote exposure relevant", "authenticated boundary review"], "kev": false, "observed_at": "2026-07-08T03:39:09.814067+00:00", "product": "manageengine_adselfservice_plus", "public_human_impact": "Source describes remote exposure · authenticated boundary. Possible impact: This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary.", "public_human_summary": "NVD: The custom GINA/CP module in Zoho ManageEngine ADSelfService Plus before 5.5 build 5517 allows remote attackers to execute code and escalate privileges via spoofing. NVD: It does not authenticate the intended server before opening a browser window. NVD: An unauthenticated attacker capable of conducting a spoofing attack can redirect the browser to gain execution in the context of the WinLogon.exe process.", "public_human_what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "public_human_why_it_matters": "Source describes remote exposure · authenticated boundary. Possible impact: This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary.; CVSS 9.8 (CRITICAL); EPSS percentile 94; not listed in KEV; Remediation reference present; patch status requires confirmation in the linked advisory; sources: NVD, Vendor Advisory.", "public_safe_summary": "NVD: The custom GINA/CP module in Zoho ManageEngine ADSelfService Plus before 5.5 build 5517 allows remote attackers to execute code and escalate privileges via spoofing. NVD: It does not authenticate the intended server before opening a browser window. NVD: An unauthenticated attacker capable of conducting a spoofing attack can redirect the browser to gain execution in the context of the WinLogon.exe process.", "public_status": "public_safe", "published_at": null, "redaction_notes": ["source-published defensive context retained", "vulnerability class, impact, affected context, and remediation references remain displayable"], "remediation_handoff": {"auto_remediation_allowed": false, "codex_prompt_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2018-5353-codex-prompt.md", "external_execution_allowed": false, "human_approval_required": true, "json_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2018-5353.json", "markdown_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2018-5353.md", "scan_allowed": false}, "remediation_urls": ["http://zoho.com", "https://www.manageengine.com/products/self-service-password/release-notes.html"], "sort_priority": 98.94138, "source_copy_policy": {"allowed": "source-published defensive facts, vulnerability class, impact, affected context, version and remediation facts", "excluded": "exploit procedures, exploit strings, shell commands, scanner instructions, procedural bypass detail, and reproduction material", "summary": "Official or semi-official source descriptions may be summarized for defensive triage; exploit-enabling procedure is removed."}, "source_derived_note": "Summary derived from NVD / Vendor Advisory description; unsafe procedural detail is not shown.", "source_label": "NVD, Vendor Advisory", "source_published_affected": "vendor/product: zohocorp / manageengine_adselfservice_plus; affected version context: 5.5", "source_published_description": "NVD: The custom GINA/CP module in Zoho ManageEngine ADSelfService Plus before 5.5 build 5517 allows remote attackers to execute code and escalate privileges via spoofing. NVD: It does not authenticate the intended server before opening a browser window. NVD: An unauthenticated attacker capable of conducting a spoofing attack can redirect the browser to gain execution in the context of the WinLogon.exe process.", "source_published_evidence_refs": [{"source": "NVD", "type": "source_description", "url": null}, {"source": "Vendor Advisory", "type": "source_description", "url": null}, {"source": "Reference", "type": "reference", "url": "https://github.com/missing0x00/CVE-2018-5353"}, {"source": "Vendor Advisory", "type": "reference", "url": "https://www.manageengine.com/products/self-service-password/release-notes.html"}, {"source": "Vendor Advisory", "type": "reference", "url": "http://zoho.com"}, {"source": "Reference", "type": "reference", "url": "https://github.com/missing0x00/CVE-2018-5353"}, {"source": "Vendor Advisory", "type": "reference", "url": "https://www.manageengine.com/products/self-service-password/release-notes.html"}, {"source": "Official Reference", "type": "reference", "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-5353"}], "source_published_impact": "Source describes remote exposure · authenticated boundary. Possible impact: This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary.", "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.", "source_published_summary": "NVD: The custom GINA/CP module in Zoho ManageEngine ADSelfService Plus before 5.5 build 5517 allows remote attackers to execute code and escalate privileges via spoofing. NVD: It does not authenticate the intended server before opening a browser window. NVD: An unauthenticated attacker capable of conducting a spoofing attack can redirect the browser to gain execution in the context of the WinLogon.exe process.", "sources": ["NVD", "Vendor Advisory"], "summary": "CVE-2018-5353 is a defensive prioritization candidate. NVD lists CVSS severity as CRITICAL. CVSS score is 9.8. EPSS score is 0.0810 with percentile 0.9414. Known exploited catalog status is not listed in NVD for this record. Use official advisories and vendor remediation references for defensive review.", "summary_ja": null, "title": "CVE-2018-5353 defensive priority signal", "title_ja": null, "translation": null, "updated_at": null, "urgency_reasons": ["CVSS CRITICAL", "EPSS percentile high", "affected product present", "vendor advisory present", "recent update", "remediation reference present"], "vendor": "zohocorp", "what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "why_it_matters": "This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary; CVSS 9.8 (CRITICAL); EPSS percentile 94; affected product context: zohocorp /..."}, {"affected_label": "anixis / password_reset_client", "affected_products": [{"canonicalProduct": "password_reset_client", "canonicalVendor": "anixis", "cpe": "cpe:2.3:a:anixis:password_reset_client:*:*:*:*:*:*:*:*", "ecosystem": null, "packageName": null, "product": "password_reset_client", "purl": null, "vendor": "anixis", "version": null}], "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2018-5354/", "cvss_score": 8.8, "cvss_severity": "HIGH", "data_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2018-5354.json", "defensive_priority": "Continuous monitoring candidate", "epss_percentile": 0.83994, "epss_score": 0.02678, "exposure_hint": "remote exposure", "human_consequence": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary.", "human_impact_label": "remote exposure · authenticated boundary", "human_risk_summary": "CVE-2018-5354 for anixis / password_reset_client: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary.", "id": "CVE-2018-5354", "impact_tags": ["remote exposure relevant", "authenticated boundary review"], "kev": false, "observed_at": "2026-07-08T03:39:09.814067+00:00", "product": "password_reset_client", "public_human_impact": "Source describes remote exposure · authenticated boundary. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary.", "public_human_summary": "NVD: The custom GINA/CP module in ANIXIS Password Reset Client before version 3.22 allows remote attackers to execute code and escalate privileges via spoofing. NVD: When the client is configured to use HTTP, it does not authenticate the intended server before opening a browser window. NVD: An unauthenticated attacker capable of conducting a spoofing attack can redirect the browser to gain execution in the context of the WinLogon.exe process.", "public_human_what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "public_human_why_it_matters": "Source describes remote exposure · authenticated boundary. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary.; CVSS 8.8 (HIGH); EPSS percentile 84; not listed in KEV; Remediation reference present; patch status requires confirmation in the linked advisory; sources: NVD, Vendor Advisory.", "public_safe_summary": "NVD: The custom GINA/CP module in ANIXIS Password Reset Client before version 3.22 allows remote attackers to execute code and escalate privileges via spoofing. NVD: When the client is configured to use HTTP, it does not authenticate the intended server before opening a browser window. NVD: An unauthenticated attacker capable of conducting a spoofing attack can redirect the browser to gain execution in the context of the WinLogon.exe process.", "public_status": "public_safe", "published_at": null, "redaction_notes": ["source-published defensive context retained", "vulnerability class, impact, affected context, and remediation references remain displayable"], "remediation_handoff": {"auto_remediation_allowed": false, "codex_prompt_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2018-5354-codex-prompt.md", "external_execution_allowed": false, "human_approval_required": true, "json_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2018-5354.json", "markdown_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2018-5354.md", "scan_allowed": false}, "remediation_urls": ["http://anixis.com"], "sort_priority": 88.83994, "source_copy_policy": {"allowed": "source-published defensive facts, vulnerability class, impact, affected context, version and remediation facts", "excluded": "exploit procedures, exploit strings, shell commands, scanner instructions, procedural bypass detail, and reproduction material", "summary": "Official or semi-official source descriptions may be summarized for defensive triage; exploit-enabling procedure is removed."}, "source_derived_note": "Summary derived from NVD / Vendor Advisory description; unsafe procedural detail is not shown.", "source_label": "NVD, Vendor Advisory", "source_published_affected": "vendor/product: anixis / password_reset_client", "source_published_description": "NVD: The custom GINA/CP module in ANIXIS Password Reset Client before version 3.22 allows remote attackers to execute code and escalate privileges via spoofing. NVD: When the client is configured to use HTTP, it does not authenticate the intended server before opening a browser window. NVD: An unauthenticated attacker capable of conducting a spoofing attack can redirect the browser to gain execution in the context of the WinLogon.exe process.", "source_published_evidence_refs": [{"source": "NVD", "type": "source_description", "url": null}, {"source": "Vendor Advisory", "type": "source_description", "url": null}, {"source": "Reference", "type": "reference", "url": "https://github.com/missing0x00/CVE-2018-5354"}, {"source": "Vendor Advisory", "type": "reference", "url": "http://anixis.com"}, {"source": "Reference", "type": "reference", "url": "https://github.com/missing0x00/CVE-2018-5354"}, {"source": "Official Reference", "type": "reference", "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-5354"}], "source_published_impact": "Source describes remote exposure · authenticated boundary. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary.", "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.", "source_published_summary": "NVD: The custom GINA/CP module in ANIXIS Password Reset Client before version 3.22 allows remote attackers to execute code and escalate privileges via spoofing. NVD: When the client is configured to use HTTP, it does not authenticate the intended server before opening a browser window. NVD: An unauthenticated attacker capable of conducting a spoofing attack can redirect the browser to gain execution in the context of the WinLogon.exe process.", "sources": ["NVD", "Vendor Advisory"], "summary": "CVE-2018-5354 is a defensive prioritization candidate. NVD lists CVSS severity as HIGH. CVSS score is 8.8. EPSS score is 0.0268 with percentile 0.8399. Known exploited catalog status is not listed in NVD for this record. Use official advisories and vendor remediation references for defensive review.", "summary_ja": null, "title": "CVE-2018-5354 defensive priority signal", "title_ja": null, "translation": null, "updated_at": null, "urgency_reasons": ["CVSS HIGH", "affected product present", "vendor advisory present", "recent update", "remediation reference present"], "vendor": "anixis", "what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "why_it_matters": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary; CVSS 8.8 (HIGH); EPSS percentile 84; affected product context: anixis / password_reset_client; sources: NVD..."}, {"affected_label": "crmeb / crmeb", "affected_products": [{"canonicalProduct": "crmeb", "canonicalVendor": "crmeb", "cpe": "cpe:2.3:a:crmeb:crmeb:3.0:*:*:*:*:*:*:*", "ecosystem": null, "packageName": null, "product": "crmeb", "purl": null, "vendor": "crmeb", "version": "3.0"}], "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2020-25466/", "cvss_score": 9.8, "cvss_severity": "CRITICAL", "data_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2020-25466.json", "defensive_priority": "Priority review candidate", "epss_percentile": 0.85894, "epss_score": 0.03033, "exposure_hint": "exposure unknown", "human_consequence": "An attacker may be able to run code or commands on affected systems.", "human_impact_label": "code execution review", "human_risk_summary": "CVE-2020-25466 for crmeb / crmeb: An attacker may be able to run code or commands on affected systems.", "id": "CVE-2020-25466", "impact_tags": ["code execution review"], "kev": false, "observed_at": "2026-07-08T03:39:09.814067+00:00", "product": "crmeb", "public_human_impact": "Source describes code execution review. Possible impact: An attacker may be able to run code or commands on affected systems.", "public_human_summary": "NVD: A SSRF vulnerability exists in the downloadimage interface of CRMEB 3.0, which can remotely download arbitrary files on the server and remotely execute arbitrary code. OSV: A SSRF vulnerability exists in the downloadimage interface of CRMEB 3.0, which can remotely download arbitrary files on the server and remotely execute arbitrary code.", "public_human_what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "public_human_why_it_matters": "Source describes code execution review. Possible impact: An attacker may be able to run code or commands on affected systems.; CVSS 9.8 (CRITICAL); EPSS percentile 86; not listed in KEV; Remediation reference present; patch status requires confirmation in the linked advisory; sources: NVD, OSV, Vendor Advisory.", "public_safe_summary": "NVD: A SSRF vulnerability exists in the downloadimage interface of CRMEB 3.0, which can remotely download arbitrary files on the server and remotely execute arbitrary code. OSV: A SSRF vulnerability exists in the downloadimage interface of CRMEB 3.0, which can remotely download arbitrary files on the server and remotely execute arbitrary code.", "public_status": "public_safe", "published_at": null, "redaction_notes": ["source-published defensive context retained", "vulnerability class, impact, affected context, and remediation references remain displayable"], "remediation_handoff": {"auto_remediation_allowed": false, "codex_prompt_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-25466-codex-prompt.md", "external_execution_allowed": false, "human_approval_required": true, "json_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-25466.json", "markdown_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-25466.md", "scan_allowed": false}, "remediation_urls": ["http://crmeb.com"], "sort_priority": 98.85894, "source_copy_policy": {"allowed": "source-published defensive facts, vulnerability class, impact, affected context, version and remediation facts", "excluded": "exploit procedures, exploit strings, shell commands, scanner instructions, procedural bypass detail, and reproduction material", "summary": "Official or semi-official source descriptions may be summarized for defensive triage; exploit-enabling procedure is removed."}, "source_derived_note": "Summary derived from NVD / OSV / Vendor Advisory description; unsafe procedural detail is not shown.", "source_label": "NVD, OSV, Vendor Advisory", "source_published_affected": "vendor/product: crmeb / crmeb; affected version context: 3.0", "source_published_description": "NVD: A SSRF vulnerability exists in the downloadimage interface of CRMEB 3.0, which can remotely download arbitrary files on the server and remotely execute arbitrary code. OSV: A SSRF vulnerability exists in the downloadimage interface of CRMEB 3.0, which can remotely download arbitrary files on the server and remotely execute arbitrary code.", "source_published_evidence_refs": [{"source": "NVD", "type": "source_description", "url": null}, {"source": "OSV", "type": "source_description", "url": null}, {"source": "Vendor Advisory", "type": "source_description", "url": null}, {"source": "Reference", "type": "reference", "url": "https://github.com/crmeb/CRMEB"}, {"source": "Reference", "type": "reference", "url": "https://github.com/crmeb/CRMEB/issues/22"}, {"source": "Vendor Advisory", "type": "reference", "url": "http://crmeb.com"}, {"source": "Reference", "type": "reference", "url": "https://github.com/crmeb/CRMEB"}, {"source": "Reference", "type": "reference", "url": "https://github.com/crmeb/CRMEB/issues/22"}, {"source": "Official Reference", "type": "reference", "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-25466"}, {"source": "Official Reference", "type": "reference", "url": "https://osv.dev/vulnerability/CVE-2020-25466"}], "source_published_impact": "Source describes code execution review. Possible impact: An attacker may be able to run code or commands on affected systems.", "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.", "source_published_summary": "NVD: A SSRF vulnerability exists in the downloadimage interface of CRMEB 3.0, which can remotely download arbitrary files on the server and remotely execute arbitrary code. OSV: A SSRF vulnerability exists in the downloadimage interface of CRMEB 3.0, which can remotely download arbitrary files on the server and remotely execute arbitrary code.", "sources": ["NVD", "OSV", "Vendor Advisory"], "summary": "CVE-2020-25466 is a defensive prioritization candidate. NVD lists CVSS severity as CRITICAL. CVSS score is 9.8. EPSS score is 0.0303 with percentile 0.8589. Known exploited catalog status is not listed in NVD for this record. Use official advisories and vendor remediation references for defensive review.", "summary_ja": null, "title": "CVE-2020-25466 defensive priority signal", "title_ja": null, "translation": null, "updated_at": null, "urgency_reasons": ["CVSS CRITICAL", "affected product present", "vendor advisory present", "recent update", "remediation reference present"], "vendor": "crmeb", "what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "why_it_matters": "An attacker may be able to run code or commands on affected systems; CVSS 9.8 (CRITICAL); EPSS percentile 86; affected product context: crmeb / crmeb; sources: NVD, OSV, Vendor Advisory."}, {"affected_label": "yourls / yourls", "affected_products": [{"canonicalProduct": "yourls", "canonicalVendor": "yourls", "cpe": "cpe:2.3:a:yourls:yourls:*:*:*:*:*:*:*:*", "ecosystem": null, "packageName": null, "product": "yourls", "purl": null, "vendor": "yourls", "version": null}], "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2020-27388/", "cvss_score": 5.4, "cvss_severity": "MEDIUM", "data_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2020-27388.json", "defensive_priority": "Continuous monitoring candidate", "epss_percentile": 0.50603, "epss_score": 0.00754, "exposure_hint": "exposure unknown", "human_consequence": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.", "human_impact_label": "defensive exposure review", "human_risk_summary": "CVE-2020-27388 for yourls / yourls: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.", "id": "CVE-2020-27388", "impact_tags": [], "kev": false, "observed_at": "2026-07-08T03:39:09.814067+00:00", "product": "yourls", "public_human_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.", "public_human_summary": "NVD: Multiple Stored Cross Site Scripting (XSS) vulnerabilities exist in the YOURLS Admin Panel, Versions 1.5 - 1.7.10.", "public_human_what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "public_human_why_it_matters": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.; CVSS 5.4 (MEDIUM); EPSS percentile 51; not listed in KEV; Remediation reference present; patch status requires confirmation in the linked advisory; sources: NVD.", "public_safe_summary": "NVD: Multiple Stored Cross Site Scripting (XSS) vulnerabilities exist in the YOURLS Admin Panel, Versions 1.5 - 1.7.10.", "public_status": "public_safe", "published_at": null, "redaction_notes": ["source-published defensive context retained", "exploit string, command, scanner, or code-like detail removed", "vulnerability class, impact, affected context, and remediation references remain displayable"], "remediation_handoff": {"auto_remediation_allowed": false, "codex_prompt_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-27388-codex-prompt.md", "external_execution_allowed": false, "human_approval_required": true, "json_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-27388.json", "markdown_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-27388.md", "scan_allowed": false}, "remediation_urls": ["https://nvd.nist.gov/vuln/detail/CVE-2020-27388"], "sort_priority": 54.50603, "source_copy_policy": {"allowed": "source-published defensive facts, vulnerability class, impact, affected context, version and remediation facts", "excluded": "exploit procedures, exploit strings, shell commands, scanner instructions, procedural bypass detail, and reproduction material", "summary": "Official or semi-official source descriptions may be summarized for defensive triage; exploit-enabling procedure is removed."}, "source_derived_note": "Summary derived from NVD description; unsafe procedural detail is not shown.", "source_label": "NVD, Vendor Advisory", "source_published_affected": "vendor/product: yourls / yourls", "source_published_description": "NVD: Multiple Stored Cross Site Scripting (XSS) vulnerabilities exist in the YOURLS Admin Panel, Versions 1.5 - 1.7.10.", "source_published_evidence_refs": [{"source": "NVD", "type": "source_description", "url": null}, {"source": "Reference", "type": "reference", "url": "https://github.com/YOURLS/YOURLS/pull/2761"}, {"source": "Reference", "type": "reference", "url": "https://johnjhacking.com/blog/cve-2020-27388/"}, {"source": "Reference", "type": "reference", "url": "http://yourls.com"}, {"source": "Reference", "type": "reference", "url": "https://github.com/YOURLS/YOURLS/pull/2761"}, {"source": "Reference", "type": "reference", "url": "https://johnjhacking.com/blog/cve-2020-27388/"}, {"source": "Official Reference", "type": "reference", "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-27388"}], "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.", "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.", "source_published_summary": "NVD: Multiple Stored Cross Site Scripting (XSS) vulnerabilities exist in the YOURLS Admin Panel, Versions 1.5 - 1.7.10.", "sources": ["NVD", "Vendor Advisory"], "summary": "CVE-2020-27388 is a defensive prioritization candidate. NVD lists CVSS severity as MEDIUM. CVSS score is 5.4. EPSS score is 0.0075 with percentile 0.5060. Known exploited catalog status is not listed in NVD for this record. Use official advisories and vendor remediation references for defensive review.", "summary_ja": null, "title": "CVE-2020-27388 defensive priority signal", "title_ja": null, "translation": null, "updated_at": null, "urgency_reasons": ["affected product present", "vendor advisory present", "recent update"], "vendor": "yourls", "what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "why_it_matters": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review; CVSS 5.4 (MEDIUM); EPSS percentile 51; affected product context: yourls / yourls; sources: NVD."}, {"affected_label": "snap7_project / snap7", "affected_products": [{"canonicalProduct": "snap7", "canonicalVendor": "snap7_project", "cpe": "cpe:2.3:a:snap7_project:snap7:1.4.1:*:*:*:*:*:*:*", "ecosystem": null, "packageName": null, "product": "snap7", "purl": null, "vendor": "snap7_project", "version": "1.4.1"}], "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2020-22552/", "cvss_score": 7.5, "cvss_severity": "HIGH", "data_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2020-22552.json", "defensive_priority": "Continuous monitoring candidate", "epss_percentile": 0.78525, "epss_score": 0.02011, "exposure_hint": "exposure unknown", "human_consequence": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.", "human_impact_label": "high severity review", "human_risk_summary": "CVE-2020-22552 for snap7_project / snap7: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.", "id": "CVE-2020-22552", "impact_tags": [], "kev": false, "observed_at": "2026-07-08T03:39:09.814067+00:00", "product": "snap7", "public_human_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.", "public_human_summary": "NVD: The Snap7 server component in version 1.4.1, when an attacker sends a crafted packet with COTP protocol the last-data-unit flag set to No and S7 writes a var function, the Snap7 server will be crashed.", "public_human_what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "public_human_why_it_matters": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.; CVSS 7.5 (HIGH); EPSS percentile 79; not listed in KEV; Remediation reference present; patch status requires confirmation in the linked advisory; sources: NVD.", "public_safe_summary": "NVD: The Snap7 server component in version 1.4.1, when an attacker sends a crafted packet with COTP protocol the last-data-unit flag set to No and S7 writes a var function, the Snap7 server will be crashed.", "public_status": "public_safe", "published_at": null, "redaction_notes": ["source-published defensive context retained", "vulnerability class, impact, affected context, and remediation references remain displayable"], "remediation_handoff": {"auto_remediation_allowed": false, "codex_prompt_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-22552-codex-prompt.md", "external_execution_allowed": false, "human_approval_required": true, "json_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-22552.json", "markdown_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-22552.md", "scan_allowed": false}, "remediation_urls": ["https://nvd.nist.gov/vuln/detail/CVE-2020-22552"], "sort_priority": 75.78525, "source_copy_policy": {"allowed": "source-published defensive facts, vulnerability class, impact, affected context, version and remediation facts", "excluded": "exploit procedures, exploit strings, shell commands, scanner instructions, procedural bypass detail, and reproduction material", "summary": "Official or semi-official source descriptions may be summarized for defensive triage; exploit-enabling procedure is removed."}, "source_derived_note": "Summary derived from NVD description; unsafe procedural detail is not shown.", "source_label": "NVD, Vendor Advisory", "source_published_affected": "vendor/product: snap7_project / snap7; affected version context: 1.4.1", "source_published_description": "NVD: The Snap7 server component in version 1.4.1, when an attacker sends a crafted packet with COTP protocol the last-data-unit flag set to No and S7 writes a var function, the Snap7 server will be crashed.", "source_published_evidence_refs": [{"source": "NVD", "type": "source_description", "url": null}, {"source": "Reference", "type": "reference", "url": "https://sourceforge.net/p/snap7/discussion/bugfix/thread/456d76fdde/"}, {"source": "Reference", "type": "reference", "url": "https://sourceforge.net/projects/snap7/"}, {"source": "Reference", "type": "reference", "url": "http://snap7.com"}, {"source": "Reference", "type": "reference", "url": "https://sourceforge.net/p/snap7/discussion/bugfix/thread/456d76fdde/"}, {"source": "Reference", "type": "reference", "url": "https://sourceforge.net/projects/snap7/"}, {"source": "Official Reference", "type": "reference", "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-22552"}], "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.", "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.", "source_published_summary": "NVD: The Snap7 server component in version 1.4.1, when an attacker sends a crafted packet with COTP protocol the last-data-unit flag set to No and S7 writes a var function, the Snap7 server will be crashed.", "sources": ["NVD", "Vendor Advisory"], "summary": "CVE-2020-22552 is a defensive prioritization candidate. NVD lists CVSS severity as HIGH. CVSS score is 7.5. EPSS score is 0.0201 with percentile 0.7853. Known exploited catalog status is not listed in NVD for this record. Use official advisories and vendor remediation references for defensive review.", "summary_ja": null, "title": "CVE-2020-22552 defensive priority signal", "title_ja": null, "translation": null, "updated_at": null, "urgency_reasons": ["CVSS HIGH", "affected product present", "vendor advisory present", "recent update"], "vendor": "snap7_project", "what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "why_it_matters": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review; CVSS 7.5 (HIGH); EPSS percentile 79; affected product context: snap7_project / snap7; sources: NVD."}, {"affected_label": "microweber / microweber", "affected_products": [{"canonicalProduct": "microweber", "canonicalVendor": "microweber", "cpe": "cpe:2.3:a:microweber:microweber:1.1.18:*:*:*:*:*:*:*", "ecosystem": null, "packageName": null, "product": "microweber", "purl": null, "vendor": "microweber", "version": "1.1.18"}], "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2020-23136/", "cvss_score": 5.5, "cvss_severity": "MEDIUM", "data_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2020-23136.json", "defensive_priority": "Routine monitoring candidate", "epss_percentile": 0.24698, "epss_score": 0.00328, "exposure_hint": "exposure unknown", "human_consequence": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.", "human_impact_label": "defensive exposure review", "human_risk_summary": "CVE-2020-23136 for microweber / microweber: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.", "id": "CVE-2020-23136", "impact_tags": [], "kev": false, "observed_at": "2026-07-08T03:39:09.814067+00:00", "product": "microweber", "public_human_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.", "public_human_summary": "NVD: Microweber v1.1.18 is affected by no session expiry after log-out.", "public_human_what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "public_human_why_it_matters": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.; CVSS 5.5 (MEDIUM); EPSS percentile 25; not listed in KEV; Remediation reference present; patch status requires confirmation in the linked advisory; sources: NVD.", "public_safe_summary": "NVD: Microweber v1.1.18 is affected by no session expiry after log-out.", "public_status": "public_safe", "published_at": null, "redaction_notes": ["source-published defensive context retained", "vulnerability class, impact, affected context, and remediation references remain displayable"], "remediation_handoff": {"auto_remediation_allowed": false, "codex_prompt_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-23136-codex-prompt.md", "external_execution_allowed": false, "human_approval_required": true, "json_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-23136.json", "markdown_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-23136.md", "scan_allowed": false}, "remediation_urls": ["https://nvd.nist.gov/vuln/detail/CVE-2020-23136"], "sort_priority": 55.24698, "source_copy_policy": {"allowed": "source-published defensive facts, vulnerability class, impact, affected context, version and remediation facts", "excluded": "exploit procedures, exploit strings, shell commands, scanner instructions, procedural bypass detail, and reproduction material", "summary": "Official or semi-official source descriptions may be summarized for defensive triage; exploit-enabling procedure is removed."}, "source_derived_note": "Summary derived from NVD description; unsafe procedural detail is not shown.", "source_label": "NVD, Vendor Advisory", "source_published_affected": "vendor/product: microweber / microweber; affected version context: 1.1.18", "source_published_description": "NVD: Microweber v1.1.18 is affected by no session expiry after log-out.", "source_published_evidence_refs": [{"source": "NVD", "type": "source_description", "url": null}, {"source": "Reference", "type": "reference", "url": "https://gist.github.com/virendratiwari03/0b0d161e1141fdd74122abbb02fefe17"}, {"source": "Reference", "type": "reference", "url": "http://microweber.com"}, {"source": "Reference", "type": "reference", "url": "https://gist.github.com/virendratiwari03/0b0d161e1141fdd74122abbb02fefe17"}, {"source": "Official Reference", "type": "reference", "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-23136"}], "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.", "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.", "source_published_summary": "NVD: Microweber v1.1.18 is affected by no session expiry after log-out.", "sources": ["NVD", "Vendor Advisory"], "summary": "CVE-2020-23136 is a defensive prioritization candidate. NVD lists CVSS severity as MEDIUM. CVSS score is 5.5. EPSS score is 0.0033 with percentile 0.2470. Known exploited catalog status is not listed in NVD for this record. Use official advisories and vendor remediation references for defensive review.", "summary_ja": null, "title": "CVE-2020-23136 defensive priority signal", "title_ja": null, "translation": null, "updated_at": null, "urgency_reasons": ["affected product present", "vendor advisory present", "recent update"], "vendor": "microweber", "what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "why_it_matters": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review; CVSS 5.5 (MEDIUM); EPSS percentile 25; affected product context: microweber / microweber; sources: NVD."}, {"affected_label": "ilex / international_sign\\&go", "affected_products": [{"canonicalProduct": "international_sign\\&go", "canonicalVendor": "ilex", "cpe": "cpe:2.3:a:ilex:international_sign\\&go:7.1:*:*:*:*:*:*:*", "ecosystem": null, "packageName": null, "product": "international_sign\\&go", "purl": null, "vendor": "ilex", "version": "7.1"}], "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2020-23968/", "cvss_score": 7.8, "cvss_severity": "HIGH", "data_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2020-23968.json", "defensive_priority": "Continuous monitoring candidate", "epss_percentile": 0.55043, "epss_score": 0.00891, "exposure_hint": "exposure unknown", "human_consequence": "An attacker may cross a privilege boundary and gain more access than intended.", "human_impact_label": "privilege escalation risk", "human_risk_summary": "CVE-2020-23968 for ilex / international_sign\\&go: An attacker may cross a privilege boundary and gain more access than intended.", "id": "CVE-2020-23968", "impact_tags": ["privilege boundary review"], "kev": false, "observed_at": "2026-07-08T03:39:09.814067+00:00", "product": "international_sign\\&go", "public_human_impact": "Source describes privilege escalation risk. Possible impact: An attacker may cross a privilege boundary and gain more access than intended.", "public_human_summary": "NVD: Ilex International Sign&go Workstation Security Suite 7.1 allows elevation of privileges via a symlink attack on ProgramData\\Ilex\\S&G\\Logs\\000-sngWSService1.log.", "public_human_what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "public_human_why_it_matters": "Source describes privilege escalation risk. Possible impact: An attacker may cross a privilege boundary and gain more access than intended.; CVSS 7.8 (HIGH); EPSS percentile 55; not listed in KEV; Remediation reference present; patch status requires confirmation in the linked advisory; sources: NVD, Vendor Advisory.", "public_safe_summary": "NVD: Ilex International Sign&go Workstation Security Suite 7.1 allows elevation of privileges via a symlink attack on ProgramData\\Ilex\\S&G\\Logs\\000-sngWSService1.log.", "public_status": "public_safe", "published_at": null, "redaction_notes": ["source-published defensive context retained", "vulnerability class, impact, affected context, and remediation references remain displayable"], "remediation_handoff": {"auto_remediation_allowed": false, "codex_prompt_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-23968-codex-prompt.md", "external_execution_allowed": false, "human_approval_required": true, "json_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-23968.json", "markdown_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-23968.md", "scan_allowed": false}, "remediation_urls": ["http://ilex.com"], "sort_priority": 78.55043, "source_copy_policy": {"allowed": "source-published defensive facts, vulnerability class, impact, affected context, version and remediation facts", "excluded": "exploit procedures, exploit strings, shell commands, scanner instructions, procedural bypass detail, and reproduction material", "summary": "Official or semi-official source descriptions may be summarized for defensive triage; exploit-enabling procedure is removed."}, "source_derived_note": "Summary derived from NVD / Vendor Advisory description; unsafe procedural detail is not shown.", "source_label": "NVD, Vendor Advisory", "source_published_affected": "vendor/product: ilex / international_sign\\&go; affected version context: 7.1", "source_published_description": "NVD: Ilex International Sign&go Workstation Security Suite 7.1 allows elevation of privileges via a symlink attack on ProgramData\\Ilex\\S&G\\Logs\\000-sngWSService1.log.", "source_published_evidence_refs": [{"source": "NVD", "type": "source_description", "url": null}, {"source": "Vendor Advisory", "type": "source_description", "url": null}, {"source": "Reference", "type": "reference", "url": "https://ricardojba.github.io/CVE-Pending-ILEX-SignGo-EoP/"}, {"source": "Vendor Advisory", "type": "reference", "url": "http://ilex.com"}, {"source": "Reference", "type": "reference", "url": "http://signgo.com"}, {"source": "Reference", "type": "reference", "url": "https://ricardojba.github.io/CVE-Pending-ILEX-SignGo-EoP/"}, {"source": "Official Reference", "type": "reference", "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-23968"}], "source_published_impact": "Source describes privilege escalation risk. Possible impact: An attacker may cross a privilege boundary and gain more access than intended.", "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.", "source_published_summary": "NVD: Ilex International Sign&go Workstation Security Suite 7.1 allows elevation of privileges via a symlink attack on ProgramData\\Ilex\\S&G\\Logs\\000-sngWSService1.log.", "sources": ["NVD", "Vendor Advisory"], "summary": "CVE-2020-23968 is a defensive prioritization candidate. NVD lists CVSS severity as HIGH. CVSS score is 7.8. EPSS score is 0.0089 with percentile 0.5504. Known exploited catalog status is not listed in NVD for this record. Use official advisories and vendor remediation references for defensive review.", "summary_ja": null, "title": "CVE-2020-23968 defensive priority signal", "title_ja": null, "translation": null, "updated_at": null, "urgency_reasons": ["CVSS HIGH", "affected product present", "vendor advisory present", "recent update", "remediation reference present"], "vendor": "ilex", "what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "why_it_matters": "An attacker may cross a privilege boundary and gain more access than intended; CVSS 7.8 (HIGH); EPSS percentile 55; affected product context: ilex / international_sign\\&go; sources: NVD, Vendor Advisory."}], "manual_public_launch_required": false, "public_launch_allowed": true, "public_safe_export_generated": true, "radar": "vuln", "read_only_static_data": true, "schema_url": "https://vuln.signal-radar.com/data/vuln/schema.json", "schema_version": "v0.1", "search_console_registered": true, "signal_radar_integration_allowed": false, "webmcp_future_contract": {"annotations": {"readOnlyHint": true, "untrustedContentHint": true}, "api": "document.modelContext", "auto_remediation_allowed": false, "cross_origin_exposure_allowed": false, "deploy_allowed": false, "enabled": true, "endpoint": null, "exposed_to": [], "external_execution_allowed": false, "fallback_api": "navigator.modelContext", "fetch_allowed": false, "github_issue_creation_allowed": false, "mode": "browser_imperative_progressive_enhancement", "mutation_allowed": false, "notes": "Browser WebMCP tools are registered only when document.modelContext or navigator.modelContext is available. They read existing public-safe static JSON and perform no network fetch, deploy, scan, patch, or mutation.", "planned": false, "scan_allowed": false, "tool_output_max_items": 10, "tool_output_target_max_chars": 1500, "tools": ["vuln_signal_search", "vuln_signal_get_item", "vuln_signal_list_priority"]}}, "itemsById": {"CVE-2005-4459": {"affected_label": "vmware / ace", "affected_products": [{"canonicalProduct": "ace", "canonicalVendor": "vmware", "cpe": "cpe:2.3:a:vmware:ace:1.0.1:*:*:*:*:*:*:*", "ecosystem": null, "packageName": null, "product": "ace", "purl": null, "vendor": "vmware", "version": "1.0.1"}, {"canonicalProduct": "gsx_server", "canonicalVendor": "vmware", "cpe": "cpe:2.3:a:vmware:gsx_server:2.0:*:*:*:*:*:*:*", "ecosystem": null, "packageName": null, "product": "gsx_server", "purl": null, "vendor": "vmware", "version": "2.0"}, {"canonicalProduct": "gsx_server", "canonicalVendor": "vmware", "cpe": "cpe:2.3:a:vmware:gsx_server:2.0.1_build_2129:*:*:*:*:*:*:*", "ecosystem": null, "packageName": null, "product": "gsx_server", "purl": null, "vendor": "vmware", "version": "2.0.1_build_2129"}, {"canonicalProduct": "gsx_server", "canonicalVendor": "vmware", "cpe": "cpe:2.3:a:vmware:gsx_server:2.5.1:*:*:*:*:*:*:*", "ecosystem": null, "packageName": null, "product": "gsx_server", "purl": null, "vendor": "vmware", "version": "2.5.1"}, {"canonicalProduct": "gsx_server", "canonicalVendor": "vmware", "cpe": "cpe:2.3:a:vmware:gsx_server:2.5.1_build_5336:*:*:*:*:*:*:*", "ecosystem": null, "packageName": null, "product": "gsx_server", "purl": null, "vendor": "vmware", "version": "2.5.1_build_5336"}, {"canonicalProduct": "gsx_server", "canonicalVendor": "vmware", "cpe": "cpe:2.3:a:vmware:gsx_server:2.5.2:*:*:*:*:*:*:*", "ecosystem": null, "packageName": null, "product": "gsx_server", "purl": null, "vendor": "vmware", "version": "2.5.2"}, {"canonicalProduct": "gsx_server", "canonicalVendor": "vmware", "cpe": "cpe:2.3:a:vmware:gsx_server:3.0:*:*:*:*:*:*:*", "ecosystem": null, "packageName": null, "product": "gsx_server", "purl": null, "vendor": "vmware", "version": "3.0"}, {"canonicalProduct": "gsx_server", "canonicalVendor": "vmware", "cpe": "cpe:2.3:a:vmware:gsx_server:3.0_build_7592:*:*:*:*:*:*:*", "ecosystem": null, "packageName": null, "product": "gsx_server", "purl": null, "vendor": "vmware", "version": "3.0_build_7592"}, {"canonicalProduct": "gsx_server", "canonicalVendor": "vmware", "cpe": "cpe:2.3:a:vmware:gsx_server:3.1:*:*:*:*:*:*:*", "ecosystem": null, "packageName": null, "product": "gsx_server", "purl": null, "vendor": "vmware", "version": "3.1"}, {"canonicalProduct": "gsx_server", "canonicalVendor": "vmware", "cpe": "cpe:2.3:a:vmware:gsx_server:3.2:*:*:*:*:*:*:*", "ecosystem": null, "packageName": null, "product": "gsx_server", "purl": null, "vendor": "vmware", "version": "3.2"}, {"canonicalProduct": "player", "canonicalVendor": "vmware", "cpe": "cpe:2.3:a:vmware:player:1.0.0:*:*:*:*:*:*:*", "ecosystem": null, "packageName": null, "product": "player", "purl": null, "vendor": "vmware", "version": "1.0.0"}, {"canonicalProduct": "workstation", "canonicalVendor": "vmware", "cpe": "cpe:2.3:a:vmware:workstation:3.2.1:patch1:*:*:*:*:*:*", "ecosystem": null, "packageName": null, "product": "workstation", "purl": null, "vendor": "vmware", "version": "3.2.1"}, {"canonicalProduct": "workstation", "canonicalVendor": "vmware", "cpe": "cpe:2.3:a:vmware:workstation:3.4:*:*:*:*:*:*:*", "ecosystem": null, "packageName": null, "product": "workstation", "purl": null, "vendor": "vmware", "version": "3.4"}, {"canonicalProduct": "workstation", "canonicalVendor": "vmware", "cpe": "cpe:2.3:a:vmware:workstation:4.0:*:*:*:*:*:*:*", "ecosystem": null, "packageName": null, "product": "workstation", "purl": null, "vendor": "vmware", "version": "4.0"}, {"canonicalProduct": "workstation", "canonicalVendor": "vmware", "cpe": "cpe:2.3:a:vmware:workstation:4.0.1:*:*:*:*:*:*:*", "ecosystem": null, "packageName": null, "product": "workstation", "purl": null, "vendor": "vmware", "version": "4.0.1"}, {"canonicalProduct": "workstation", "canonicalVendor": "vmware", "cpe": "cpe:2.3:a:vmware:workstation:4.0.2:*:*:*:*:*:*:*", "ecosystem": null, "packageName": null, "product": "workstation", "purl": null, "vendor": "vmware", "version": "4.0.2"}, {"canonicalProduct": "workstation", "canonicalVendor": "vmware", "cpe": "cpe:2.3:a:vmware:workstation:4.5.2:*:*:*:*:*:*:*", "ecosystem": null, "packageName": null, "product": "workstation", "purl": null, "vendor": "vmware", "version": "4.5.2"}, {"canonicalProduct": "workstation", "canonicalVendor": "vmware", "cpe": "cpe:2.3:a:vmware:workstation:4.5.2_build_8848:r4:*:*:*:*:*:*", "ecosystem": null, "packageName": null, "product": "workstation", "purl": null, "vendor": "vmware", "version": "4.5.2_build_8848"}, {"canonicalProduct": "workstation", "canonicalVendor": "vmware", "cpe": "cpe:2.3:a:vmware:workstation:5.0.0_build_13124:*:*:*:*:*:*:*", "ecosystem": null, "packageName": null, "product": "workstation", "purl": null, "vendor": "vmware", "version": "5.0.0_build_13124"}, {"canonicalProduct": "workstation", "canonicalVendor": "vmware", "cpe": "cpe:2.3:a:vmware:workstation:5.5:*:*:*:*:*:*:*", "ecosystem": null, "packageName": null, "product": "workstation", "purl": null, "vendor": "vmware", "version": "5.5"}], "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2005-4459/", "cvss_score": 10.0, "cvss_severity": "CRITICAL", "data_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2005-4459.json", "defensive_priority": "Priority review candidate", "epss_percentile": 0.96028, "epss_score": 0.13661, "exposure_hint": "authenticated boundary", "human_consequence": "An attacker may be able to run code or commands on affected systems.", "human_impact_label": "code execution review · memory safety review · authenticated boundary", "human_risk_summary": "CVE-2005-4459 for vmware / ace: An attacker may be able to run code or commands on affected systems.", "id": "CVE-2005-4459", "impact_tags": ["code execution review", "memory safety review", "authenticated boundary review"], "kev": false, "observed_at": "2026-07-08T03:39:09.814067+00:00", "product": "ace", "public_human_impact": "Source describes code execution review · memory safety review · authenticated boundary. Possible impact: An attacker may be able to run code or commands on affected systems.", "public_human_summary": "NVD: Heap-based buffer overflow in the NAT networking components vmnat.exe and vmnet-natd in VMWare Workstation 5.5, GSX Server 3.2, ACE 1.0.1, and Player 1.0 allows remote authenticated attackers, including guests, to execute arbitrary code via crafted (1) EPRT...", "public_human_what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "public_human_why_it_matters": "Source describes code execution review · memory safety review · authenticated boundary. Possible impact: An attacker may be able to run code or commands on affected systems.; CVSS 10.0 (CRITICAL); EPSS percentile 96; not listed in KEV; Remediation reference present; patch status requires confirmation in the linked advisory; sources: NVD, Vendor Advisory.", "public_safe_summary": "NVD: Heap-based buffer overflow in the NAT networking components vmnat.exe and vmnet-natd in VMWare Workstation 5.5, GSX Server 3.2, ACE 1.0.1, and Player 1.0 allows remote authenticated attackers, including guests, to execute arbitrary code via crafted (1) EPRT...", "public_status": "public_safe", "published_at": null, "redaction_notes": ["source-published defensive context retained", "vulnerability class, impact, affected context, and remediation references remain displayable"], "remediation_handoff": {"auto_remediation_allowed": false, "codex_prompt_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2005-4459-codex-prompt.md", "external_execution_allowed": false, "human_approval_required": true, "json_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2005-4459.json", "markdown_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2005-4459.md", "scan_allowed": false}, "remediation_urls": ["http://secunia.com/advisories/18162", "http://secunia.com/advisories/18344", "http://securityreason.com/securityalert/282", "http://securityreason.com/securityalert/289", "http://securitytracker.com/id?1015401", "http://www.gentoo.org/security/en/glsa/glsa-200601-04.xml", "http://www.securityfocus.com/archive/1/419997/100/0/threaded", "http://www.securityfocus.com/archive/1/420017/100/0/threaded", "http://www.securityfocus.com/bid/15998", "http://www.vmware.com/support/kb/enduser/std_adp.php?p_faqid=2000"], "sort_priority": 100.96028, "source_copy_policy": {"allowed": "source-published defensive facts, vulnerability class, impact, affected context, version and remediation facts", "excluded": "exploit procedures, exploit strings, shell commands, scanner instructions, procedural bypass detail, and reproduction material", "summary": "Official or semi-official source descriptions may be summarized for defensive triage; exploit-enabling procedure is removed."}, "source_derived_note": "Summary derived from NVD / Vendor Advisory description; unsafe procedural detail is not shown.", "source_label": "NVD, Vendor Advisory", "source_published_affected": "vendor/product: vmware / ace; affected version context: 1.0.0, 1.0.1, 2.0, 2.0.1_build_2129, 2.5.1", "source_published_description": "NVD: Heap-based buffer overflow in the NAT networking components vmnat.exe and vmnet-natd in VMWare Workstation 5.5, GSX Server 3.2, ACE 1.0.1, and Player 1.0 allows remote authenticated attackers, including guests, to execute arbitrary code via crafted (1) EPRT...", "source_published_evidence_refs": [{"source": "NVD", "type": "source_description", "url": null}, {"source": "Vendor Advisory", "type": "source_description", "url": null}, {"source": "Reference", "type": "reference", "url": "http://lists.grok.org.uk/pipermail/full-disclosure/2005-December/040442.html"}, {"source": "Vendor Advisory", "type": "reference", "url": "http://secunia.com/advisories/18162"}, {"source": "Vendor Advisory", "type": "reference", "url": "http://secunia.com/advisories/18344"}, {"source": "Reference", "type": "reference", "url": "http://securityreason.com/securityalert/282"}, {"source": "Reference", "type": "reference", "url": "http://securityreason.com/securityalert/289"}, {"source": "Reference", "type": "reference", "url": "http://securitytracker.com/id?1015401"}, {"source": "Reference", "type": "reference", "url": "http://www.gentoo.org/security/en/glsa/glsa-200601-04.xml"}, {"source": "Reference", "type": "reference", "url": "http://www.kb.cert.org/vuls/id/856689"}], "source_published_impact": "Source describes code execution review · memory safety review · authenticated boundary. Possible impact: An attacker may be able to run code or commands on affected systems.", "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.", "source_published_summary": "NVD: Heap-based buffer overflow in the NAT networking components vmnat.exe and vmnet-natd in VMWare Workstation 5.5, GSX Server 3.2, ACE 1.0.1, and Player 1.0 allows remote authenticated attackers, including guests, to execute arbitrary code via crafted (1) EPRT...", "sources": ["NVD", "Vendor Advisory"], "summary": "CVE-2005-4459 is a defensive prioritization candidate. NVD lists CVSS severity as HIGH. CVSS score is 10.0. EPSS score is 0.1366 with percentile 0.9603. Known exploited catalog status is not listed in NVD for this record. Use official advisories and vendor remediation references for defensive review.", "summary_ja": null, "title": "CVE-2005-4459 defensive priority signal", "title_ja": null, "translation": null, "updated_at": null, "urgency_reasons": ["CVSS CRITICAL", "EPSS percentile high", "affected product present", "vendor advisory present", "recent update", "remediation reference present"], "vendor": "vmware", "what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "why_it_matters": "An attacker may be able to run code or commands on affected systems; CVSS 10.0 (CRITICAL); EPSS percentile 96; affected product context: vmware / ace; sources: NVD, Vendor Advisory."}, "CVE-2018-10902": {"affected_label": "debian / debian_linux", "affected_products": [{"canonicalProduct": "debian_linux", "canonicalVendor": "debian", "cpe": "cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*", "ecosystem": null, "packageName": null, "product": "debian_linux", "purl": null, "vendor": "debian", "version": "8.0"}, {"canonicalProduct": "debian_linux", "canonicalVendor": "debian", "cpe": "cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*", "ecosystem": null, "packageName": null, "product": "debian_linux", "purl": null, "vendor": "debian", "version": "9.0"}, {"canonicalProduct": "ubuntu_linux", "canonicalVendor": "canonical", "cpe": "cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:esm:*:*:*", "ecosystem": null, "packageName": null, "product": "ubuntu_linux", "purl": null, "vendor": "canonical", "version": "12.04"}, {"canonicalProduct": "ubuntu_linux", "canonicalVendor": "canonical", "cpe": "cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*", "ecosystem": null, "packageName": null, "product": "ubuntu_linux", "purl": null, "vendor": "canonical", "version": "14.04"}, {"canonicalProduct": "ubuntu_linux", "canonicalVendor": "canonical", "cpe": "cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*", "ecosystem": null, "packageName": null, "product": "ubuntu_linux", "purl": null, "vendor": "canonical", "version": "16.04"}, {"canonicalProduct": "ubuntu_linux", "canonicalVendor": "canonical", "cpe": "cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*", "ecosystem": null, "packageName": null, "product": "ubuntu_linux", "purl": null, "vendor": "canonical", "version": "18.04"}, {"canonicalProduct": "linux_kernel", "canonicalVendor": "linux", "cpe": "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*", "ecosystem": null, "packageName": null, "product": "linux_kernel", "purl": null, "vendor": "linux", "version": "-"}, {"canonicalProduct": "enterprise_linux_desktop", "canonicalVendor": "redhat", "cpe": "cpe:2.3:o:redhat:enterprise_linux_desktop:6.0:*:*:*:*:*:*:*", "ecosystem": null, "packageName": null, "product": "enterprise_linux_desktop", "purl": null, "vendor": "redhat", "version": "6.0"}, {"canonicalProduct": "enterprise_linux_desktop", "canonicalVendor": "redhat", "cpe": "cpe:2.3:o:redhat:enterprise_linux_desktop:7.0:*:*:*:*:*:*:*", "ecosystem": null, "packageName": null, "product": "enterprise_linux_desktop", "purl": null, "vendor": "redhat", "version": "7.0"}, {"canonicalProduct": "enterprise_linux_server", "canonicalVendor": "redhat", "cpe": "cpe:2.3:o:redhat:enterprise_linux_server:6.0:*:*:*:*:*:*:*", "ecosystem": null, "packageName": null, "product": "enterprise_linux_server", "purl": null, "vendor": "redhat", "version": "6.0"}, {"canonicalProduct": "enterprise_linux_server", "canonicalVendor": "redhat", "cpe": "cpe:2.3:o:redhat:enterprise_linux_server:7.0:*:*:*:*:*:*:*", "ecosystem": null, "packageName": null, "product": "enterprise_linux_server", "purl": null, "vendor": "redhat", "version": "7.0"}, {"canonicalProduct": "enterprise_linux_workstation", "canonicalVendor": "redhat", "cpe": "cpe:2.3:o:redhat:enterprise_linux_workstation:6.0:*:*:*:*:*:*:*", "ecosystem": null, "packageName": null, "product": "enterprise_linux_workstation", "purl": null, "vendor": "redhat", "version": "6.0"}, {"canonicalProduct": "enterprise_linux_workstation", "canonicalVendor": "redhat", "cpe": "cpe:2.3:o:redhat:enterprise_linux_workstation:7.0:*:*:*:*:*:*:*", "ecosystem": null, "packageName": null, "product": "enterprise_linux_workstation", "purl": null, "vendor": "redhat", "version": "7.0"}], "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2018-10902/", "cvss_score": 7.8, "cvss_severity": "HIGH", "data_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2018-10902.json", "defensive_priority": "Continuous monitoring candidate", "epss_percentile": 0.40562, "epss_score": 0.00523, "exposure_hint": "local exposure", "human_consequence": "A local user may cross a privilege boundary and gain more access than intended.", "human_impact_label": "privilege escalation risk · local exposure", "human_risk_summary": "CVE-2018-10902 for debian / debian_linux: A local user may cross a privilege boundary and gain more access than intended.", "id": "CVE-2018-10902", "impact_tags": ["privilege boundary review", "local exposure relevant"], "kev": false, "observed_at": "2026-07-08T03:39:09.814067+00:00", "product": "debian_linux", "public_human_impact": "Source describes privilege escalation risk · local exposure. Possible impact: A local user may cross a privilege boundary and gain more access than intended.", "public_human_summary": "NVD: It was found that the raw midi kernel driver does not protect against concurrent access which leads to a double realloc (double free) in snd_rawmidi_input_params() and snd_rawmidi_output_status() which are part of snd_rawmidi_ioctl() handler in rawmidi.c file. NVD: A malicious local attacker could possibly use this for privilege escalation. OSV: It was found that the raw midi kernel driver does not protect against concurrent access which leads to a double realloc (double free) in snd_rawmidi_input_params() and snd_rawmidi_output_status() which are part of snd_rawmidi_ioctl() handler in rawmidi.c file.", "public_human_what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "public_human_why_it_matters": "Source describes privilege escalation risk · local exposure. Possible impact: A local user may cross a privilege boundary and gain more access than intended.; CVSS 7.8 (HIGH); EPSS percentile 41; not listed in KEV; Remediation reference present; patch status requires confirmation in the linked advisory; sources: NVD, OSV, Vendor Advisory.", "public_safe_summary": "NVD: It was found that the raw midi kernel driver does not protect against concurrent access which leads to a double realloc (double free) in snd_rawmidi_input_params() and snd_rawmidi_output_status() which are part of snd_rawmidi_ioctl() handler in rawmidi.c file. NVD: A malicious local attacker could possibly use this for privilege escalation. OSV: It was found that the raw midi kernel driver does not protect against concurrent access which leads to a double realloc (double free) in snd_rawmidi_input_params() and snd_rawmidi_output_status() which are part of snd_rawmidi_ioctl() handler in rawmidi.c file.", "public_status": "public_safe", "published_at": null, "redaction_notes": ["source-published defensive context retained", "vulnerability class, impact, affected context, and remediation references remain displayable"], "remediation_handoff": {"auto_remediation_allowed": false, "codex_prompt_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2018-10902-codex-prompt.md", "external_execution_allowed": false, "human_approval_required": true, "json_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2018-10902.json", "markdown_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2018-10902.md", "scan_allowed": false}, "remediation_urls": ["http://www.securityfocus.com/bid/105119", "http://www.securitytracker.com/id/1041529", "https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-10902", "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=39675f7a7c7e7702f7d5341f1e0d01db746543a0", "https://www.debian.org/security/2018/dsa-4308"], "sort_priority": 78.40562, "source_copy_policy": {"allowed": "source-published defensive facts, vulnerability class, impact, affected context, version and remediation facts", "excluded": "exploit procedures, exploit strings, shell commands, scanner instructions, procedural bypass detail, and reproduction material", "summary": "Official or semi-official source descriptions may be summarized for defensive triage; exploit-enabling procedure is removed."}, "source_derived_note": "Summary derived from NVD / OSV / Vendor Advisory description; unsafe procedural detail is not shown.", "source_label": "NVD, OSV, Vendor Advisory", "source_published_affected": "vendor/product: debian / debian_linux; affected version context: -, 12.04, 14.04, 16.04, 18.04", "source_published_description": "NVD: It was found that the raw midi kernel driver does not protect against concurrent access which leads to a double realloc (double free) in snd_rawmidi_input_params() and snd_rawmidi_output_status() which are part of snd_rawmidi_ioctl() handler in rawmidi.c file. NVD: A malicious local attacker could possibly use this for privilege escalation. OSV: It was found that the raw midi kernel driver does not protect against concurrent access which leads to a double realloc (double free) in snd_rawmidi_input_params() and snd_rawmidi_output_status() which are part of snd_rawmidi_ioctl() handler in rawmidi.c file.", "source_published_evidence_refs": [{"source": "NVD", "type": "source_description", "url": null}, {"source": "OSV", "type": "source_description", "url": null}, {"source": "Vendor Advisory", "type": "source_description", "url": null}, {"source": "Reference", "type": "reference", "url": "http://www.securityfocus.com/bid/105119"}, {"source": "Vendor Advisory", "type": "reference", "url": "http://www.securitytracker.com/id/1041529"}, {"source": "Reference", "type": "reference", "url": "https://access.redhat.com/errata/RHSA-2018:3083"}, {"source": "Reference", "type": "reference", "url": "https://access.redhat.com/errata/RHSA-2018:3096"}, {"source": "Reference", "type": "reference", "url": "https://access.redhat.com/errata/RHSA-2019:0415"}, {"source": "Reference", "type": "reference", "url": "https://access.redhat.com/errata/RHSA-2019:0641"}, {"source": "Reference", "type": "reference", "url": "https://access.redhat.com/errata/RHSA-2019:3217"}], "source_published_impact": "Source describes privilege escalation risk · local exposure. Possible impact: A local user may cross a privilege boundary and gain more access than intended.", "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.", "source_published_summary": "NVD: It was found that the raw midi kernel driver does not protect against concurrent access which leads to a double realloc (double free) in snd_rawmidi_input_params() and snd_rawmidi_output_status() which are part of snd_rawmidi_ioctl() handler in rawmidi.c file. NVD: A malicious local attacker could possibly use this for privilege escalation. OSV: It was found that the raw midi kernel driver does not protect against concurrent access which leads to a double realloc (double free) in snd_rawmidi_input_params() and snd_rawmidi_output_status() which are part of snd_rawmidi_ioctl() handler in rawmidi.c file.", "sources": ["NVD", "OSV", "Vendor Advisory"], "summary": "CVE-2018-10902 is a defensive prioritization candidate. NVD lists CVSS severity as HIGH. CVSS score is 7.8. EPSS score is 0.0052 with percentile 0.4056. Known exploited catalog status is not listed in NVD for this record. Use official advisories and vendor remediation references for defensive review.", "summary_ja": null, "title": "CVE-2018-10902 defensive priority signal", "title_ja": null, "translation": null, "updated_at": null, "urgency_reasons": ["CVSS HIGH", "affected product present", "vendor advisory present", "recent update", "remediation reference present"], "vendor": "debian", "what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "why_it_matters": "A local user may cross a privilege boundary and gain more access than intended; CVSS 7.8 (HIGH); EPSS percentile 41; affected product context: debian / debian_linux; sources: NVD, OSV, Vendor Advisory."}, "CVE-2018-5353": {"affected_label": "zohocorp / manageengine_adselfservice_plus", "affected_products": [{"canonicalProduct": "manageengine_adselfservice_plus", "canonicalVendor": "zohocorp", "cpe": "cpe:2.3:a:zohocorp:manageengine_adselfservice_plus:*:*:*:*:*:*:*:*", "ecosystem": null, "packageName": null, "product": "manageengine_adselfservice_plus", "purl": null, "vendor": "zohocorp", "version": null}, {"canonicalProduct": "manageengine_adselfservice_plus", "canonicalVendor": "zohocorp", "cpe": "cpe:2.3:a:zohocorp:manageengine_adselfservice_plus:5.5:-:*:*:*:*:*:*", "ecosystem": null, "packageName": null, "product": "manageengine_adselfservice_plus", "purl": null, "vendor": "zohocorp", "version": "5.5"}], "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2018-5353/", "cvss_score": 9.8, "cvss_severity": "CRITICAL", "data_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2018-5353.json", "defensive_priority": "Priority review candidate", "epss_percentile": 0.94138, "epss_score": 0.08103, "exposure_hint": "remote exposure", "human_consequence": "This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary.", "human_impact_label": "remote exposure · authenticated boundary", "human_risk_summary": "CVE-2018-5353 for zohocorp / manageengine_adselfservice_plus: This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary.", "id": "CVE-2018-5353", "impact_tags": ["remote exposure relevant", "authenticated boundary review"], "kev": false, "observed_at": "2026-07-08T03:39:09.814067+00:00", "product": "manageengine_adselfservice_plus", "public_human_impact": "Source describes remote exposure · authenticated boundary. Possible impact: This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary.", "public_human_summary": "NVD: The custom GINA/CP module in Zoho ManageEngine ADSelfService Plus before 5.5 build 5517 allows remote attackers to execute code and escalate privileges via spoofing. NVD: It does not authenticate the intended server before opening a browser window. NVD: An unauthenticated attacker capable of conducting a spoofing attack can redirect the browser to gain execution in the context of the WinLogon.exe process.", "public_human_what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "public_human_why_it_matters": "Source describes remote exposure · authenticated boundary. Possible impact: This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary.; CVSS 9.8 (CRITICAL); EPSS percentile 94; not listed in KEV; Remediation reference present; patch status requires confirmation in the linked advisory; sources: NVD, Vendor Advisory.", "public_safe_summary": "NVD: The custom GINA/CP module in Zoho ManageEngine ADSelfService Plus before 5.5 build 5517 allows remote attackers to execute code and escalate privileges via spoofing. NVD: It does not authenticate the intended server before opening a browser window. NVD: An unauthenticated attacker capable of conducting a spoofing attack can redirect the browser to gain execution in the context of the WinLogon.exe process.", "public_status": "public_safe", "published_at": null, "redaction_notes": ["source-published defensive context retained", "vulnerability class, impact, affected context, and remediation references remain displayable"], "remediation_handoff": {"auto_remediation_allowed": false, "codex_prompt_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2018-5353-codex-prompt.md", "external_execution_allowed": false, "human_approval_required": true, "json_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2018-5353.json", "markdown_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2018-5353.md", "scan_allowed": false}, "remediation_urls": ["http://zoho.com", "https://www.manageengine.com/products/self-service-password/release-notes.html"], "sort_priority": 98.94138, "source_copy_policy": {"allowed": "source-published defensive facts, vulnerability class, impact, affected context, version and remediation facts", "excluded": "exploit procedures, exploit strings, shell commands, scanner instructions, procedural bypass detail, and reproduction material", "summary": "Official or semi-official source descriptions may be summarized for defensive triage; exploit-enabling procedure is removed."}, "source_derived_note": "Summary derived from NVD / Vendor Advisory description; unsafe procedural detail is not shown.", "source_label": "NVD, Vendor Advisory", "source_published_affected": "vendor/product: zohocorp / manageengine_adselfservice_plus; affected version context: 5.5", "source_published_description": "NVD: The custom GINA/CP module in Zoho ManageEngine ADSelfService Plus before 5.5 build 5517 allows remote attackers to execute code and escalate privileges via spoofing. NVD: It does not authenticate the intended server before opening a browser window. NVD: An unauthenticated attacker capable of conducting a spoofing attack can redirect the browser to gain execution in the context of the WinLogon.exe process.", "source_published_evidence_refs": [{"source": "NVD", "type": "source_description", "url": null}, {"source": "Vendor Advisory", "type": "source_description", "url": null}, {"source": "Reference", "type": "reference", "url": "https://github.com/missing0x00/CVE-2018-5353"}, {"source": "Vendor Advisory", "type": "reference", "url": "https://www.manageengine.com/products/self-service-password/release-notes.html"}, {"source": "Vendor Advisory", "type": "reference", "url": "http://zoho.com"}, {"source": "Reference", "type": "reference", "url": "https://github.com/missing0x00/CVE-2018-5353"}, {"source": "Vendor Advisory", "type": "reference", "url": "https://www.manageengine.com/products/self-service-password/release-notes.html"}, {"source": "Official Reference", "type": "reference", "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-5353"}], "source_published_impact": "Source describes remote exposure · authenticated boundary. Possible impact: This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary.", "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.", "source_published_summary": "NVD: The custom GINA/CP module in Zoho ManageEngine ADSelfService Plus before 5.5 build 5517 allows remote attackers to execute code and escalate privileges via spoofing. NVD: It does not authenticate the intended server before opening a browser window. NVD: An unauthenticated attacker capable of conducting a spoofing attack can redirect the browser to gain execution in the context of the WinLogon.exe process.", "sources": ["NVD", "Vendor Advisory"], "summary": "CVE-2018-5353 is a defensive prioritization candidate. NVD lists CVSS severity as CRITICAL. CVSS score is 9.8. EPSS score is 0.0810 with percentile 0.9414. Known exploited catalog status is not listed in NVD for this record. Use official advisories and vendor remediation references for defensive review.", "summary_ja": null, "title": "CVE-2018-5353 defensive priority signal", "title_ja": null, "translation": null, "updated_at": null, "urgency_reasons": ["CVSS CRITICAL", "EPSS percentile high", "affected product present", "vendor advisory present", "recent update", "remediation reference present"], "vendor": "zohocorp", "what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "why_it_matters": "This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary; CVSS 9.8 (CRITICAL); EPSS percentile 94; affected product context: zohocorp /..."}, "CVE-2018-5354": {"affected_label": "anixis / password_reset_client", "affected_products": [{"canonicalProduct": "password_reset_client", "canonicalVendor": "anixis", "cpe": "cpe:2.3:a:anixis:password_reset_client:*:*:*:*:*:*:*:*", "ecosystem": null, "packageName": null, "product": "password_reset_client", "purl": null, "vendor": "anixis", "version": null}], "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2018-5354/", "cvss_score": 8.8, "cvss_severity": "HIGH", "data_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2018-5354.json", "defensive_priority": "Continuous monitoring candidate", "epss_percentile": 0.83994, "epss_score": 0.02678, "exposure_hint": "remote exposure", "human_consequence": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary.", "human_impact_label": "remote exposure · authenticated boundary", "human_risk_summary": "CVE-2018-5354 for anixis / password_reset_client: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary.", "id": "CVE-2018-5354", "impact_tags": ["remote exposure relevant", "authenticated boundary review"], "kev": false, "observed_at": "2026-07-08T03:39:09.814067+00:00", "product": "password_reset_client", "public_human_impact": "Source describes remote exposure · authenticated boundary. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary.", "public_human_summary": "NVD: The custom GINA/CP module in ANIXIS Password Reset Client before version 3.22 allows remote attackers to execute code and escalate privileges via spoofing. NVD: When the client is configured to use HTTP, it does not authenticate the intended server before opening a browser window. NVD: An unauthenticated attacker capable of conducting a spoofing attack can redirect the browser to gain execution in the context of the WinLogon.exe process.", "public_human_what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "public_human_why_it_matters": "Source describes remote exposure · authenticated boundary. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary.; CVSS 8.8 (HIGH); EPSS percentile 84; not listed in KEV; Remediation reference present; patch status requires confirmation in the linked advisory; sources: NVD, Vendor Advisory.", "public_safe_summary": "NVD: The custom GINA/CP module in ANIXIS Password Reset Client before version 3.22 allows remote attackers to execute code and escalate privileges via spoofing. NVD: When the client is configured to use HTTP, it does not authenticate the intended server before opening a browser window. NVD: An unauthenticated attacker capable of conducting a spoofing attack can redirect the browser to gain execution in the context of the WinLogon.exe process.", "public_status": "public_safe", "published_at": null, "redaction_notes": ["source-published defensive context retained", "vulnerability class, impact, affected context, and remediation references remain displayable"], "remediation_handoff": {"auto_remediation_allowed": false, "codex_prompt_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2018-5354-codex-prompt.md", "external_execution_allowed": false, "human_approval_required": true, "json_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2018-5354.json", "markdown_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2018-5354.md", "scan_allowed": false}, "remediation_urls": ["http://anixis.com"], "sort_priority": 88.83994, "source_copy_policy": {"allowed": "source-published defensive facts, vulnerability class, impact, affected context, version and remediation facts", "excluded": "exploit procedures, exploit strings, shell commands, scanner instructions, procedural bypass detail, and reproduction material", "summary": "Official or semi-official source descriptions may be summarized for defensive triage; exploit-enabling procedure is removed."}, "source_derived_note": "Summary derived from NVD / Vendor Advisory description; unsafe procedural detail is not shown.", "source_label": "NVD, Vendor Advisory", "source_published_affected": "vendor/product: anixis / password_reset_client", "source_published_description": "NVD: The custom GINA/CP module in ANIXIS Password Reset Client before version 3.22 allows remote attackers to execute code and escalate privileges via spoofing. NVD: When the client is configured to use HTTP, it does not authenticate the intended server before opening a browser window. NVD: An unauthenticated attacker capable of conducting a spoofing attack can redirect the browser to gain execution in the context of the WinLogon.exe process.", "source_published_evidence_refs": [{"source": "NVD", "type": "source_description", "url": null}, {"source": "Vendor Advisory", "type": "source_description", "url": null}, {"source": "Reference", "type": "reference", "url": "https://github.com/missing0x00/CVE-2018-5354"}, {"source": "Vendor Advisory", "type": "reference", "url": "http://anixis.com"}, {"source": "Reference", "type": "reference", "url": "https://github.com/missing0x00/CVE-2018-5354"}, {"source": "Official Reference", "type": "reference", "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-5354"}], "source_published_impact": "Source describes remote exposure · authenticated boundary. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary.", "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.", "source_published_summary": "NVD: The custom GINA/CP module in ANIXIS Password Reset Client before version 3.22 allows remote attackers to execute code and escalate privileges via spoofing. NVD: When the client is configured to use HTTP, it does not authenticate the intended server before opening a browser window. NVD: An unauthenticated attacker capable of conducting a spoofing attack can redirect the browser to gain execution in the context of the WinLogon.exe process.", "sources": ["NVD", "Vendor Advisory"], "summary": "CVE-2018-5354 is a defensive prioritization candidate. NVD lists CVSS severity as HIGH. CVSS score is 8.8. EPSS score is 0.0268 with percentile 0.8399. Known exploited catalog status is not listed in NVD for this record. Use official advisories and vendor remediation references for defensive review.", "summary_ja": null, "title": "CVE-2018-5354 defensive priority signal", "title_ja": null, "translation": null, "updated_at": null, "urgency_reasons": ["CVSS HIGH", "affected product present", "vendor advisory present", "recent update", "remediation reference present"], "vendor": "anixis", "what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "why_it_matters": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary; CVSS 8.8 (HIGH); EPSS percentile 84; affected product context: anixis / password_reset_client; sources: NVD..."}, "CVE-2020-21731": {"affected_label": "gazie_project / gazie", "affected_products": [{"canonicalProduct": "gazie", "canonicalVendor": "gazie_project", "cpe": "cpe:2.3:a:gazie_project:gazie:7.29:*:*:*:*:*:*:*", "ecosystem": null, "packageName": null, "product": "gazie", "purl": null, "vendor": "gazie_project", "version": "7.29"}], "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2020-21731/", "cvss_score": 6.1, "cvss_severity": "MEDIUM", "data_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2020-21731.json", "defensive_priority": "Continuous monitoring candidate", "epss_percentile": 0.54231, "epss_score": 0.00864, "exposure_hint": "exposure unknown", "human_consequence": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.", "human_impact_label": "defensive exposure review", "human_risk_summary": "CVE-2020-21731 for gazie_project / gazie: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.", "id": "CVE-2020-21731", "impact_tags": [], "kev": false, "observed_at": "2026-07-08T03:39:09.814067+00:00", "product": "gazie", "public_human_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.", "public_human_summary": "NVD: Gazie 7.29 is affected by: Cross Site Scripting (XSS) via An attacker can inject JavaScript code, and the webapplication stores the injected code.", "public_human_what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "public_human_why_it_matters": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.; CVSS 6.1 (MEDIUM); EPSS percentile 54; not listed in KEV; Remediation reference present; patch status requires confirmation in the linked advisory; sources: NVD, Vendor Advisory.", "public_safe_summary": "NVD: Gazie 7.29 is affected by: Cross Site Scripting (XSS) via An attacker can inject JavaScript code, and the webapplication stores the injected code.", "public_status": "public_safe", "published_at": null, "redaction_notes": ["source-published defensive context retained", "vulnerability class, impact, affected context, and remediation references remain displayable"], "remediation_handoff": {"auto_remediation_allowed": false, "codex_prompt_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-21731-codex-prompt.md", "external_execution_allowed": false, "human_approval_required": true, "json_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-21731.json", "markdown_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-21731.md", "scan_allowed": false}, "remediation_urls": ["http://gazie.devincentiis.it/"], "sort_priority": 61.54231, "source_copy_policy": {"allowed": "source-published defensive facts, vulnerability class, impact, affected context, version and remediation facts", "excluded": "exploit procedures, exploit strings, shell commands, scanner instructions, procedural bypass detail, and reproduction material", "summary": "Official or semi-official source descriptions may be summarized for defensive triage; exploit-enabling procedure is removed."}, "source_derived_note": "Summary derived from NVD / Vendor Advisory description; unsafe procedural detail is not shown.", "source_label": "NVD, Vendor Advisory", "source_published_affected": "vendor/product: gazie_project / gazie; affected version context: 7.29", "source_published_description": "NVD: Gazie 7.29 is affected by: Cross Site Scripting (XSS) via An attacker can inject JavaScript code, and the webapplication stores the injected code.", "source_published_evidence_refs": [{"source": "NVD", "type": "source_description", "url": null}, {"source": "Vendor Advisory", "type": "source_description", "url": null}, {"source": "Vendor Advisory", "type": "reference", "url": "http://gazie.devincentiis.it/"}, {"source": "Reference", "type": "reference", "url": "https://github.com/Gr3gPr1est/BugReport/blob/master/CVE-2020-21731"}, {"source": "Reference", "type": "reference", "url": "http://gazie.com"}, {"source": "Vendor Advisory", "type": "reference", "url": "http://gazie.devincentiis.it/"}, {"source": "Reference", "type": "reference", "url": "https://github.com/Gr3gPr1est/BugReport/blob/master/CVE-2020-21731"}, {"source": "Official Reference", "type": "reference", "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-21731"}], "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.", "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.", "source_published_summary": "NVD: Gazie 7.29 is affected by: Cross Site Scripting (XSS) via An attacker can inject JavaScript code, and the webapplication stores the injected code.", "sources": ["NVD", "Vendor Advisory"], "summary": "CVE-2020-21731 is a defensive prioritization candidate. NVD lists CVSS severity as MEDIUM. CVSS score is 6.1. EPSS score is 0.0086 with percentile 0.5423. Known exploited catalog status is not listed in NVD for this record. Use official advisories and vendor remediation references for defensive review.", "summary_ja": null, "title": "CVE-2020-21731 defensive priority signal", "title_ja": null, "translation": null, "updated_at": null, "urgency_reasons": ["affected product present", "vendor advisory present", "recent update", "remediation reference present"], "vendor": "gazie_project", "what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "why_it_matters": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review; CVSS 6.1 (MEDIUM); EPSS percentile 54; affected product context: gazie_project / gazie; sources: NVD, Vendor Advisory."}, "CVE-2020-21732": {"affected_label": "rukovoditel / rukovoditel", "affected_products": [{"canonicalProduct": "rukovoditel", "canonicalVendor": "rukovoditel", "cpe": "cpe:2.3:a:rukovoditel:rukovoditel:2.6:*:*:*:*:*:*:*", "ecosystem": null, "packageName": null, "product": "rukovoditel", "purl": null, "vendor": "rukovoditel", "version": "2.6"}], "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2020-21732/", "cvss_score": 6.1, "cvss_severity": "MEDIUM", "data_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2020-21732.json", "defensive_priority": "Continuous monitoring candidate", "epss_percentile": 0.54231, "epss_score": 0.00864, "exposure_hint": "exposure unknown", "human_consequence": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk.", "human_impact_label": "XSS risk", "human_risk_summary": "CVE-2020-21732 for rukovoditel / rukovoditel: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk.", "id": "CVE-2020-21732", "impact_tags": ["XSS risk"], "kev": false, "observed_at": "2026-07-08T03:39:09.814067+00:00", "product": "rukovoditel", "public_human_impact": "Source describes XSS risk. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk.", "public_human_summary": "NVD: Rukovoditel Project Management app 2.6 is affected by: Cross Site Scripting (XSS). NVD: An attacker can add JavaScript code to the filename.", "public_human_what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "public_human_why_it_matters": "Source describes XSS risk. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk.; CVSS 6.1 (MEDIUM); EPSS percentile 54; not listed in KEV; Remediation reference present; patch status requires confirmation in the linked advisory; sources: NVD, Vendor Advisory.", "public_safe_summary": "NVD: Rukovoditel Project Management app 2.6 is affected by: Cross Site Scripting (XSS). NVD: An attacker can add JavaScript code to the filename.", "public_status": "public_safe", "published_at": null, "redaction_notes": ["source-published defensive context retained", "vulnerability class, impact, affected context, and remediation references remain displayable"], "remediation_handoff": {"auto_remediation_allowed": false, "codex_prompt_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-21732-codex-prompt.md", "external_execution_allowed": false, "human_approval_required": true, "json_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-21732.json", "markdown_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-21732.md", "scan_allowed": false}, "remediation_urls": ["https://www.rukovoditel.net"], "sort_priority": 61.54231, "source_copy_policy": {"allowed": "source-published defensive facts, vulnerability class, impact, affected context, version and remediation facts", "excluded": "exploit procedures, exploit strings, shell commands, scanner instructions, procedural bypass detail, and reproduction material", "summary": "Official or semi-official source descriptions may be summarized for defensive triage; exploit-enabling procedure is removed."}, "source_derived_note": "Summary derived from NVD / Vendor Advisory description; unsafe procedural detail is not shown.", "source_label": "NVD, Vendor Advisory", "source_published_affected": "vendor/product: rukovoditel / rukovoditel; affected version context: 2.6", "source_published_description": "NVD: Rukovoditel Project Management app 2.6 is affected by: Cross Site Scripting (XSS). NVD: An attacker can add JavaScript code to the filename.", "source_published_evidence_refs": [{"source": "NVD", "type": "source_description", "url": null}, {"source": "Vendor Advisory", "type": "source_description", "url": null}, {"source": "Reference", "type": "reference", "url": "https://github.com/Gr3gPr1est/BugReport/blob/master/CVE-2020-21732"}, {"source": "Vendor Advisory", "type": "reference", "url": "https://www.rukovoditel.net"}, {"source": "Reference", "type": "reference", "url": "http://rukovoditel.com"}, {"source": "Reference", "type": "reference", "url": "https://github.com/Gr3gPr1est/BugReport/blob/master/CVE-2020-21732"}, {"source": "Vendor Advisory", "type": "reference", "url": "https://www.rukovoditel.net"}, {"source": "Official Reference", "type": "reference", "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-21732"}], "source_published_impact": "Source describes XSS risk. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk.", "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.", "source_published_summary": "NVD: Rukovoditel Project Management app 2.6 is affected by: Cross Site Scripting (XSS). NVD: An attacker can add JavaScript code to the filename.", "sources": ["NVD", "Vendor Advisory"], "summary": "CVE-2020-21732 is a defensive prioritization candidate. NVD lists CVSS severity as MEDIUM. CVSS score is 6.1. EPSS score is 0.0086 with percentile 0.5423. Known exploited catalog status is not listed in NVD for this record. Use official advisories and vendor remediation references for defensive review.", "summary_ja": null, "title": "CVE-2020-21732 defensive priority signal", "title_ja": null, "translation": null, "updated_at": null, "urgency_reasons": ["affected product present", "vendor advisory present", "recent update", "remediation reference present"], "vendor": "rukovoditel", "what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "why_it_matters": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk; CVSS 6.1 (MEDIUM); EPSS percentile 54; affected product context: rukovoditel / rukovoditel; sources: NVD, Vendor Advisory."}, "CVE-2020-21733": {"affected_label": "sagemcom / f\\@st_3686_firmware", "affected_products": [{"canonicalProduct": "f\\@st_3686_firmware", "canonicalVendor": "sagemcom", "cpe": "cpe:2.3:o:sagemcom:f\\@st_3686_firmware:1.0_hun_3.97.0:*:*:*:*:*:*:*", "ecosystem": null, "packageName": null, "product": "f\\@st_3686_firmware", "purl": null, "vendor": "sagemcom", "version": "1.0_hun_3.97.0"}, {"canonicalProduct": "f\\@st_3686", "canonicalVendor": "sagemcom", "cpe": "cpe:2.3:h:sagemcom:f\\@st_3686:-:*:*:*:*:*:*:*", "ecosystem": null, "packageName": null, "product": "f\\@st_3686", "purl": null, "vendor": "sagemcom", "version": "-"}], "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2020-21733/", "cvss_score": 6.1, "cvss_severity": "MEDIUM", "data_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2020-21733.json", "defensive_priority": "Continuous monitoring candidate", "epss_percentile": 0.58423, "epss_score": 0.00995, "exposure_hint": "exposure unknown", "human_consequence": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk.", "human_impact_label": "XSS risk", "human_risk_summary": "CVE-2020-21733 for sagemcom / f\\@st_3686_firmware: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk.", "id": "CVE-2020-21733", "impact_tags": ["XSS risk"], "kev": false, "observed_at": "2026-07-08T03:39:09.814067+00:00", "product": "f\\@st_3686_firmware", "public_human_impact": "Source describes XSS risk. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk.", "public_human_summary": "NVD: Sagemcom F@ST3686 v1.0 HUN 3.97.0 has XSS via RgDiagnostics.asp, RgDdns.asp, RgFirewallEL.asp, RgVpnL2tpPptp.asp.", "public_human_what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "public_human_why_it_matters": "Source describes XSS risk. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk.; CVSS 6.1 (MEDIUM); EPSS percentile 58; not listed in KEV; Remediation reference present; patch status requires confirmation in the linked advisory; sources: NVD, Vendor Advisory.", "public_safe_summary": "NVD: Sagemcom F@ST3686 v1.0 HUN 3.97.0 has XSS via RgDiagnostics.asp, RgDdns.asp, RgFirewallEL.asp, RgVpnL2tpPptp.asp.", "public_status": "public_safe", "published_at": null, "redaction_notes": ["source-published defensive context retained", "vulnerability class, impact, affected context, and remediation references remain displayable"], "remediation_handoff": {"auto_remediation_allowed": false, "codex_prompt_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-21733-codex-prompt.md", "external_execution_allowed": false, "human_approval_required": true, "json_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-21733.json", "markdown_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-21733.md", "scan_allowed": false}, "remediation_urls": ["http://sagemcom.com"], "sort_priority": 61.58423, "source_copy_policy": {"allowed": "source-published defensive facts, vulnerability class, impact, affected context, version and remediation facts", "excluded": "exploit procedures, exploit strings, shell commands, scanner instructions, procedural bypass detail, and reproduction material", "summary": "Official or semi-official source descriptions may be summarized for defensive triage; exploit-enabling procedure is removed."}, "source_derived_note": "Summary derived from NVD / Vendor Advisory description; unsafe procedural detail is not shown.", "source_label": "NVD, Vendor Advisory", "source_published_affected": "vendor/product: sagemcom / f\\@st_3686_firmware; affected version context: -, 1.0_hun_3.97.0", "source_published_description": "NVD: Sagemcom F@ST3686 v1.0 HUN 3.97.0 has XSS via RgDiagnostics.asp, RgDdns.asp, RgFirewallEL.asp, RgVpnL2tpPptp.asp.", "source_published_evidence_refs": [{"source": "NVD", "type": "source_description", "url": null}, {"source": "Vendor Advisory", "type": "source_description", "url": null}, {"source": "Reference", "type": "reference", "url": "https://github.com/Gr3gPr1est/BugReport/blob/master/CVE-2020-21733"}, {"source": "Reference", "type": "reference", "url": "https://github.com/Gr3gPr1est/BugReport/blob/master/SAGEM_F%40ST3686_v1.0_HUN_3.97.0_XSS_Vuln..pdf"}, {"source": "Vendor Advisory", "type": "reference", "url": "http://sagemcom.com"}, {"source": "Reference", "type": "reference", "url": "http://sagemcomfst3686v10hun3970.com"}, {"source": "Reference", "type": "reference", "url": "https://github.com/Gr3gPr1est/BugReport/blob/master/CVE-2020-21733"}, {"source": "Reference", "type": "reference", "url": "https://github.com/Gr3gPr1est/BugReport/blob/master/SAGEM_F%40ST3686_v1.0_HUN_3.97.0_XSS_Vuln..pdf"}, {"source": "Official Reference", "type": "reference", "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-21733"}], "source_published_impact": "Source describes XSS risk. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk.", "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.", "source_published_summary": "NVD: Sagemcom F@ST3686 v1.0 HUN 3.97.0 has XSS via RgDiagnostics.asp, RgDdns.asp, RgFirewallEL.asp, RgVpnL2tpPptp.asp.", "sources": ["NVD", "Vendor Advisory"], "summary": "CVE-2020-21733 is a defensive prioritization candidate. NVD lists CVSS severity as MEDIUM. CVSS score is 6.1. EPSS score is 0.0100 with percentile 0.5842. Known exploited catalog status is not listed in NVD for this record. Use official advisories and vendor remediation references for defensive review.", "summary_ja": null, "title": "CVE-2020-21733 defensive priority signal", "title_ja": null, "translation": null, "updated_at": null, "urgency_reasons": ["affected product present", "vendor advisory present", "recent update", "remediation reference present"], "vendor": "sagemcom", "what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "why_it_matters": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk; CVSS 6.1 (MEDIUM); EPSS percentile 58; affected product context: sagemcom / f\\@st_3686_firmware; sources: NVD, Vendor Advisory."}, "CVE-2020-22552": {"affected_label": "snap7_project / snap7", "affected_products": [{"canonicalProduct": "snap7", "canonicalVendor": "snap7_project", "cpe": "cpe:2.3:a:snap7_project:snap7:1.4.1:*:*:*:*:*:*:*", "ecosystem": null, "packageName": null, "product": "snap7", "purl": null, "vendor": "snap7_project", "version": "1.4.1"}], "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2020-22552/", "cvss_score": 7.5, "cvss_severity": "HIGH", "data_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2020-22552.json", "defensive_priority": "Continuous monitoring candidate", "epss_percentile": 0.78525, "epss_score": 0.02011, "exposure_hint": "exposure unknown", "human_consequence": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.", "human_impact_label": "high severity review", "human_risk_summary": "CVE-2020-22552 for snap7_project / snap7: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.", "id": "CVE-2020-22552", "impact_tags": [], "kev": false, "observed_at": "2026-07-08T03:39:09.814067+00:00", "product": "snap7", "public_human_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.", "public_human_summary": "NVD: The Snap7 server component in version 1.4.1, when an attacker sends a crafted packet with COTP protocol the last-data-unit flag set to No and S7 writes a var function, the Snap7 server will be crashed.", "public_human_what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "public_human_why_it_matters": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.; CVSS 7.5 (HIGH); EPSS percentile 79; not listed in KEV; Remediation reference present; patch status requires confirmation in the linked advisory; sources: NVD.", "public_safe_summary": "NVD: The Snap7 server component in version 1.4.1, when an attacker sends a crafted packet with COTP protocol the last-data-unit flag set to No and S7 writes a var function, the Snap7 server will be crashed.", "public_status": "public_safe", "published_at": null, "redaction_notes": ["source-published defensive context retained", "vulnerability class, impact, affected context, and remediation references remain displayable"], "remediation_handoff": {"auto_remediation_allowed": false, "codex_prompt_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-22552-codex-prompt.md", "external_execution_allowed": false, "human_approval_required": true, "json_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-22552.json", "markdown_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-22552.md", "scan_allowed": false}, "remediation_urls": ["https://nvd.nist.gov/vuln/detail/CVE-2020-22552"], "sort_priority": 75.78525, "source_copy_policy": {"allowed": "source-published defensive facts, vulnerability class, impact, affected context, version and remediation facts", "excluded": "exploit procedures, exploit strings, shell commands, scanner instructions, procedural bypass detail, and reproduction material", "summary": "Official or semi-official source descriptions may be summarized for defensive triage; exploit-enabling procedure is removed."}, "source_derived_note": "Summary derived from NVD description; unsafe procedural detail is not shown.", "source_label": "NVD, Vendor Advisory", "source_published_affected": "vendor/product: snap7_project / snap7; affected version context: 1.4.1", "source_published_description": "NVD: The Snap7 server component in version 1.4.1, when an attacker sends a crafted packet with COTP protocol the last-data-unit flag set to No and S7 writes a var function, the Snap7 server will be crashed.", "source_published_evidence_refs": [{"source": "NVD", "type": "source_description", "url": null}, {"source": "Reference", "type": "reference", "url": "https://sourceforge.net/p/snap7/discussion/bugfix/thread/456d76fdde/"}, {"source": "Reference", "type": "reference", "url": "https://sourceforge.net/projects/snap7/"}, {"source": "Reference", "type": "reference", "url": "http://snap7.com"}, {"source": "Reference", "type": "reference", "url": "https://sourceforge.net/p/snap7/discussion/bugfix/thread/456d76fdde/"}, {"source": "Reference", "type": "reference", "url": "https://sourceforge.net/projects/snap7/"}, {"source": "Official Reference", "type": "reference", "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-22552"}], "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.", "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.", "source_published_summary": "NVD: The Snap7 server component in version 1.4.1, when an attacker sends a crafted packet with COTP protocol the last-data-unit flag set to No and S7 writes a var function, the Snap7 server will be crashed.", "sources": ["NVD", "Vendor Advisory"], "summary": "CVE-2020-22552 is a defensive prioritization candidate. NVD lists CVSS severity as HIGH. CVSS score is 7.5. EPSS score is 0.0201 with percentile 0.7853. Known exploited catalog status is not listed in NVD for this record. Use official advisories and vendor remediation references for defensive review.", "summary_ja": null, "title": "CVE-2020-22552 defensive priority signal", "title_ja": null, "translation": null, "updated_at": null, "urgency_reasons": ["CVSS HIGH", "affected product present", "vendor advisory present", "recent update"], "vendor": "snap7_project", "what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "why_it_matters": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review; CVSS 7.5 (HIGH); EPSS percentile 79; affected product context: snap7_project / snap7; sources: NVD."}, "CVE-2020-23136": {"affected_label": "microweber / microweber", "affected_products": [{"canonicalProduct": "microweber", "canonicalVendor": "microweber", "cpe": "cpe:2.3:a:microweber:microweber:1.1.18:*:*:*:*:*:*:*", "ecosystem": null, "packageName": null, "product": "microweber", "purl": null, "vendor": "microweber", "version": "1.1.18"}], "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2020-23136/", "cvss_score": 5.5, "cvss_severity": "MEDIUM", "data_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2020-23136.json", "defensive_priority": "Routine monitoring candidate", "epss_percentile": 0.24698, "epss_score": 0.00328, "exposure_hint": "exposure unknown", "human_consequence": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.", "human_impact_label": "defensive exposure review", "human_risk_summary": "CVE-2020-23136 for microweber / microweber: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.", "id": "CVE-2020-23136", "impact_tags": [], "kev": false, "observed_at": "2026-07-08T03:39:09.814067+00:00", "product": "microweber", "public_human_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.", "public_human_summary": "NVD: Microweber v1.1.18 is affected by no session expiry after log-out.", "public_human_what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "public_human_why_it_matters": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.; CVSS 5.5 (MEDIUM); EPSS percentile 25; not listed in KEV; Remediation reference present; patch status requires confirmation in the linked advisory; sources: NVD.", "public_safe_summary": "NVD: Microweber v1.1.18 is affected by no session expiry after log-out.", "public_status": "public_safe", "published_at": null, "redaction_notes": ["source-published defensive context retained", "vulnerability class, impact, affected context, and remediation references remain displayable"], "remediation_handoff": {"auto_remediation_allowed": false, "codex_prompt_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-23136-codex-prompt.md", "external_execution_allowed": false, "human_approval_required": true, "json_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-23136.json", "markdown_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-23136.md", "scan_allowed": false}, "remediation_urls": ["https://nvd.nist.gov/vuln/detail/CVE-2020-23136"], "sort_priority": 55.24698, "source_copy_policy": {"allowed": "source-published defensive facts, vulnerability class, impact, affected context, version and remediation facts", "excluded": "exploit procedures, exploit strings, shell commands, scanner instructions, procedural bypass detail, and reproduction material", "summary": "Official or semi-official source descriptions may be summarized for defensive triage; exploit-enabling procedure is removed."}, "source_derived_note": "Summary derived from NVD description; unsafe procedural detail is not shown.", "source_label": "NVD, Vendor Advisory", "source_published_affected": "vendor/product: microweber / microweber; affected version context: 1.1.18", "source_published_description": "NVD: Microweber v1.1.18 is affected by no session expiry after log-out.", "source_published_evidence_refs": [{"source": "NVD", "type": "source_description", "url": null}, {"source": "Reference", "type": "reference", "url": "https://gist.github.com/virendratiwari03/0b0d161e1141fdd74122abbb02fefe17"}, {"source": "Reference", "type": "reference", "url": "http://microweber.com"}, {"source": "Reference", "type": "reference", "url": "https://gist.github.com/virendratiwari03/0b0d161e1141fdd74122abbb02fefe17"}, {"source": "Official Reference", "type": "reference", "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-23136"}], "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.", "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.", "source_published_summary": "NVD: Microweber v1.1.18 is affected by no session expiry after log-out.", "sources": ["NVD", "Vendor Advisory"], "summary": "CVE-2020-23136 is a defensive prioritization candidate. NVD lists CVSS severity as MEDIUM. CVSS score is 5.5. EPSS score is 0.0033 with percentile 0.2470. Known exploited catalog status is not listed in NVD for this record. Use official advisories and vendor remediation references for defensive review.", "summary_ja": null, "title": "CVE-2020-23136 defensive priority signal", "title_ja": null, "translation": null, "updated_at": null, "urgency_reasons": ["affected product present", "vendor advisory present", "recent update"], "vendor": "microweber", "what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "why_it_matters": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review; CVSS 5.5 (MEDIUM); EPSS percentile 25; affected product context: microweber / microweber; sources: NVD."}, "CVE-2020-23446": {"affected_label": "verint / workforce_optimization", "affected_products": [{"canonicalProduct": "workforce_optimization", "canonicalVendor": "verint", "cpe": "cpe:2.3:a:verint:workforce_optimization:15.1.0.37634:*:*:*:*:*:*:*", "ecosystem": null, "packageName": null, "product": "workforce_optimization", "purl": null, "vendor": "verint", "version": "15.1.0.37634"}], "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2020-23446/", "cvss_score": 5.3, "cvss_severity": "MEDIUM", "data_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2020-23446.json", "defensive_priority": "Continuous monitoring candidate", "epss_percentile": 0.70416, "epss_score": 0.0146, "exposure_hint": "exposure unknown", "human_consequence": "An attacker may be able to access information that should not be exposed.", "human_impact_label": "information exposure review", "human_risk_summary": "CVE-2020-23446 for verint / workforce_optimization: An attacker may be able to access information that should not be exposed.", "id": "CVE-2020-23446", "impact_tags": ["information exposure review"], "kev": false, "observed_at": "2026-07-08T03:39:09.814067+00:00", "product": "workforce_optimization", "public_human_impact": "Source describes information exposure review. Possible impact: An attacker may be able to access information that should not be exposed.", "public_human_summary": "NVD: Verint Workforce Optimization suite 15.1 (15.1.0.37634) has Unauthenticated Information Disclosure via API", "public_human_what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "public_human_why_it_matters": "Source describes information exposure review. Possible impact: An attacker may be able to access information that should not be exposed.; CVSS 5.3 (MEDIUM); EPSS percentile 70; not listed in KEV; Remediation reference present; patch status requires confirmation in the linked advisory; sources: NVD, Vendor Advisory.", "public_safe_summary": "NVD: Verint Workforce Optimization suite 15.1 (15.1.0.37634) has Unauthenticated Information Disclosure via API", "public_status": "public_safe", "published_at": null, "redaction_notes": ["source-published defensive context retained", "vulnerability class, impact, affected context, and remediation references remain displayable"], "remediation_handoff": {"auto_remediation_allowed": false, "codex_prompt_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-23446-codex-prompt.md", "external_execution_allowed": false, "human_approval_required": true, "json_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-23446.json", "markdown_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-23446.md", "scan_allowed": false}, "remediation_urls": ["http://verint.com"], "sort_priority": 53.70416, "source_copy_policy": {"allowed": "source-published defensive facts, vulnerability class, impact, affected context, version and remediation facts", "excluded": "exploit procedures, exploit strings, shell commands, scanner instructions, procedural bypass detail, and reproduction material", "summary": "Official or semi-official source descriptions may be summarized for defensive triage; exploit-enabling procedure is removed."}, "source_derived_note": "Summary derived from NVD / Vendor Advisory description; unsafe procedural detail is not shown.", "source_label": "NVD, Vendor Advisory", "source_published_affected": "vendor/product: verint / workforce_optimization; affected version context: 15.1.0.37634", "source_published_description": "NVD: Verint Workforce Optimization suite 15.1 (15.1.0.37634) has Unauthenticated Information Disclosure via API", "source_published_evidence_refs": [{"source": "NVD", "type": "source_description", "url": null}, {"source": "Vendor Advisory", "type": "source_description", "url": null}, {"source": "Reference", "type": "reference", "url": "http://cvewalkthrough.com/variant-unauthenticated-information-disclosure-via-api/"}, {"source": "Reference", "type": "reference", "url": "https://tejaspingulkar.blogspot.com/2020/09/cve-2020-23446-verint-workforce.html"}, {"source": "Reference", "type": "reference", "url": "http://cvewalkthrough.com/variant-unauthenticated-information-disclosure-via-api/"}, {"source": "Vendor Advisory", "type": "reference", "url": "http://verint.com"}, {"source": "Reference", "type": "reference", "url": "https://tejaspingulkar.blogspot.com/2020/09/cve-2020-23446-verint-workforce.html"}, {"source": "Official Reference", "type": "reference", "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-23446"}], "source_published_impact": "Source describes information exposure review. Possible impact: An attacker may be able to access information that should not be exposed.", "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.", "source_published_summary": "NVD: Verint Workforce Optimization suite 15.1 (15.1.0.37634) has Unauthenticated Information Disclosure via API", "sources": ["NVD", "Vendor Advisory"], "summary": "CVE-2020-23446 is a defensive prioritization candidate. NVD lists CVSS severity as MEDIUM. CVSS score is 5.3. EPSS score is 0.0146 with percentile 0.7042. Known exploited catalog status is not listed in NVD for this record. Use official advisories and vendor remediation references for defensive review.", "summary_ja": null, "title": "CVE-2020-23446 defensive priority signal", "title_ja": null, "translation": null, "updated_at": null, "urgency_reasons": ["affected product present", "vendor advisory present", "recent update", "remediation reference present"], "vendor": "verint", "what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "why_it_matters": "An attacker may be able to access information that should not be exposed; CVSS 5.3 (MEDIUM); EPSS percentile 70; affected product context: verint / workforce_optimization; sources: NVD, Vendor Advisory."}, "CVE-2020-23450": {"affected_label": "spiceworks / spiceworks", "affected_products": [{"canonicalProduct": "spiceworks", "canonicalVendor": "spiceworks", "cpe": "cpe:2.3:a:spiceworks:spiceworks:*:*:*:*:*:*:*:*", "ecosystem": null, "packageName": null, "product": "spiceworks", "purl": null, "vendor": "spiceworks", "version": null}], "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2020-23450/", "cvss_score": 5.4, "cvss_severity": "MEDIUM", "data_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2020-23450.json", "defensive_priority": "Continuous monitoring candidate", "epss_percentile": 0.5158, "epss_score": 0.00783, "exposure_hint": "exposure unknown", "human_consequence": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.", "human_impact_label": "defensive exposure review", "human_risk_summary": "CVE-2020-23450 for spiceworks / spiceworks: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.", "id": "CVE-2020-23450", "impact_tags": [], "kev": false, "observed_at": "2026-07-08T03:39:09.814067+00:00", "product": "spiceworks", "public_human_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.", "public_human_summary": "NVD: Spiceworks Version <= 7.5.00107 is affected by XSS. NVD: Any name typed on Custom Groups function is vulnerable to stored XSS as they displayed on without output sanitization.", "public_human_what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "public_human_why_it_matters": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.; CVSS 5.4 (MEDIUM); EPSS percentile 52; not listed in KEV; Remediation reference present; patch status requires confirmation in the linked advisory; sources: NVD, Vendor Advisory.", "public_safe_summary": "NVD: Spiceworks Version <= 7.5.00107 is affected by XSS. NVD: Any name typed on Custom Groups function is vulnerable to stored XSS as they displayed on without output sanitization.", "public_status": "public_safe", "published_at": null, "redaction_notes": ["source-published defensive context retained", "vulnerability class, impact, affected context, and remediation references remain displayable"], "remediation_handoff": {"auto_remediation_allowed": false, "codex_prompt_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-23450-codex-prompt.md", "external_execution_allowed": false, "human_approval_required": true, "json_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-23450.json", "markdown_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-23450.md", "scan_allowed": false}, "remediation_urls": ["http://spiceworks.com"], "sort_priority": 54.5158, "source_copy_policy": {"allowed": "source-published defensive facts, vulnerability class, impact, affected context, version and remediation facts", "excluded": "exploit procedures, exploit strings, shell commands, scanner instructions, procedural bypass detail, and reproduction material", "summary": "Official or semi-official source descriptions may be summarized for defensive triage; exploit-enabling procedure is removed."}, "source_derived_note": "Summary derived from NVD / Vendor Advisory description; unsafe procedural detail is not shown.", "source_label": "NVD, Vendor Advisory", "source_published_affected": "vendor/product: spiceworks / spiceworks", "source_published_description": "NVD: Spiceworks Version <= 7.5.00107 is affected by XSS. NVD: Any name typed on Custom Groups function is vulnerable to stored XSS as they displayed on without output sanitization.", "source_published_evidence_refs": [{"source": "NVD", "type": "source_description", "url": null}, {"source": "Vendor Advisory", "type": "source_description", "url": null}, {"source": "Reference", "type": "reference", "url": "https://abuyv.com"}, {"source": "Reference", "type": "reference", "url": "https://abuyv.com/cve/spiceworks-stored-xss"}, {"source": "Vendor Advisory", "type": "reference", "url": "http://spiceworks.com"}, {"source": "Reference", "type": "reference", "url": "https://abuyv.com"}, {"source": "Reference", "type": "reference", "url": "https://abuyv.com/cve/spiceworks-stored-xss"}, {"source": "Official Reference", "type": "reference", "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-23450"}], "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.", "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.", "source_published_summary": "NVD: Spiceworks Version <= 7.5.00107 is affected by XSS. NVD: Any name typed on Custom Groups function is vulnerable to stored XSS as they displayed on without output sanitization.", "sources": ["NVD", "Vendor Advisory"], "summary": "CVE-2020-23450 is a defensive prioritization candidate. NVD lists CVSS severity as MEDIUM. CVSS score is 5.4. EPSS score is 0.0078 with percentile 0.5158. Known exploited catalog status is not listed in NVD for this record. Use official advisories and vendor remediation references for defensive review.", "summary_ja": null, "title": "CVE-2020-23450 defensive priority signal", "title_ja": null, "translation": null, "updated_at": null, "urgency_reasons": ["affected product present", "vendor advisory present", "recent update", "remediation reference present"], "vendor": "spiceworks", "what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "why_it_matters": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review; CVSS 5.4 (MEDIUM); EPSS percentile 52; affected product context: spiceworks / spiceworks; sources: NVD, Vendor Advisory."}, "CVE-2020-23451": {"affected_label": "spiceworks / spiceworks", "affected_products": [{"canonicalProduct": "spiceworks", "canonicalVendor": "spiceworks", "cpe": "cpe:2.3:a:spiceworks:spiceworks:*:*:*:*:*:*:*:*", "ecosystem": null, "packageName": null, "product": "spiceworks", "purl": null, "vendor": "spiceworks", "version": null}], "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2020-23451/", "cvss_score": 8.8, "cvss_severity": "HIGH", "data_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2020-23451.json", "defensive_priority": "Continuous monitoring candidate", "epss_percentile": 0.44482, "epss_score": 0.00601, "exposure_hint": "exposure unknown", "human_consequence": "An attacker may cross a privilege boundary and gain more access than intended.", "human_impact_label": "privilege escalation risk", "human_risk_summary": "CVE-2020-23451 for spiceworks / spiceworks: An attacker may cross a privilege boundary and gain more access than intended.", "id": "CVE-2020-23451", "impact_tags": ["privilege boundary review"], "kev": false, "observed_at": "2026-07-08T03:39:09.814067+00:00", "product": "spiceworks", "public_human_impact": "Source describes privilege escalation risk. Possible impact: An attacker may cross a privilege boundary and gain more access than intended.", "public_human_summary": "NVD: Spiceworks Version <= 7.5.00107 is affected by CSRF which can lead to privilege escalation via \"/settings/v1/users\" function.", "public_human_what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "public_human_why_it_matters": "Source describes privilege escalation risk. Possible impact: An attacker may cross a privilege boundary and gain more access than intended.; CVSS 8.8 (HIGH); EPSS percentile 44; not listed in KEV; Remediation reference present; patch status requires confirmation in the linked advisory; sources: NVD.", "public_safe_summary": "NVD: Spiceworks Version <= 7.5.00107 is affected by CSRF which can lead to privilege escalation via \"/settings/v1/users\" function.", "public_status": "public_safe", "published_at": null, "redaction_notes": ["source-published defensive context retained", "vulnerability class, impact, affected context, and remediation references remain displayable"], "remediation_handoff": {"auto_remediation_allowed": false, "codex_prompt_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-23451-codex-prompt.md", "external_execution_allowed": false, "human_approval_required": true, "json_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-23451.json", "markdown_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-23451.md", "scan_allowed": false}, "remediation_urls": ["https://nvd.nist.gov/vuln/detail/CVE-2020-23451"], "sort_priority": 88.44481999999999, "source_copy_policy": {"allowed": "source-published defensive facts, vulnerability class, impact, affected context, version and remediation facts", "excluded": "exploit procedures, exploit strings, shell commands, scanner instructions, procedural bypass detail, and reproduction material", "summary": "Official or semi-official source descriptions may be summarized for defensive triage; exploit-enabling procedure is removed."}, "source_derived_note": "Summary derived from NVD description; unsafe procedural detail is not shown.", "source_label": "NVD, Vendor Advisory", "source_published_affected": "vendor/product: spiceworks / spiceworks", "source_published_description": "NVD: Spiceworks Version <= 7.5.00107 is affected by CSRF which can lead to privilege escalation via \"/settings/v1/users\" function.", "source_published_evidence_refs": [{"source": "NVD", "type": "source_description", "url": null}, {"source": "Reference", "type": "reference", "url": "https://abuyv.com/cve/spiceworks-csrf-via-xss"}, {"source": "Reference", "type": "reference", "url": "http://spiceworks.com"}, {"source": "Reference", "type": "reference", "url": "https://abuyv.com/cve/spiceworks-csrf-via-xss"}, {"source": "Official Reference", "type": "reference", "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-23451"}], "source_published_impact": "Source describes privilege escalation risk. Possible impact: An attacker may cross a privilege boundary and gain more access than intended.", "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.", "source_published_summary": "NVD: Spiceworks Version <= 7.5.00107 is affected by CSRF which can lead to privilege escalation via \"/settings/v1/users\" function.", "sources": ["NVD", "Vendor Advisory"], "summary": "CVE-2020-23451 is a defensive prioritization candidate. NVD lists CVSS severity as HIGH. CVSS score is 8.8. EPSS score is 0.0060 with percentile 0.4448. Known exploited catalog status is not listed in NVD for this record. Use official advisories and vendor remediation references for defensive review.", "summary_ja": null, "title": "CVE-2020-23451 defensive priority signal", "title_ja": null, "translation": null, "updated_at": null, "urgency_reasons": ["CVSS HIGH", "affected product present", "vendor advisory present", "recent update"], "vendor": "spiceworks", "what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "why_it_matters": "An attacker may cross a privilege boundary and gain more access than intended; CVSS 8.8 (HIGH); EPSS percentile 44; affected product context: spiceworks / spiceworks; sources: NVD."}, "CVE-2020-23968": {"affected_label": "ilex / international_sign\\&go", "affected_products": [{"canonicalProduct": "international_sign\\&go", "canonicalVendor": "ilex", "cpe": "cpe:2.3:a:ilex:international_sign\\&go:7.1:*:*:*:*:*:*:*", "ecosystem": null, "packageName": null, "product": "international_sign\\&go", "purl": null, "vendor": "ilex", "version": "7.1"}], "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2020-23968/", "cvss_score": 7.8, "cvss_severity": "HIGH", "data_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2020-23968.json", "defensive_priority": "Continuous monitoring candidate", "epss_percentile": 0.55043, "epss_score": 0.00891, "exposure_hint": "exposure unknown", "human_consequence": "An attacker may cross a privilege boundary and gain more access than intended.", "human_impact_label": "privilege escalation risk", "human_risk_summary": "CVE-2020-23968 for ilex / international_sign\\&go: An attacker may cross a privilege boundary and gain more access than intended.", "id": "CVE-2020-23968", "impact_tags": ["privilege boundary review"], "kev": false, "observed_at": "2026-07-08T03:39:09.814067+00:00", "product": "international_sign\\&go", "public_human_impact": "Source describes privilege escalation risk. Possible impact: An attacker may cross a privilege boundary and gain more access than intended.", "public_human_summary": "NVD: Ilex International Sign&go Workstation Security Suite 7.1 allows elevation of privileges via a symlink attack on ProgramData\\Ilex\\S&G\\Logs\\000-sngWSService1.log.", "public_human_what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "public_human_why_it_matters": "Source describes privilege escalation risk. Possible impact: An attacker may cross a privilege boundary and gain more access than intended.; CVSS 7.8 (HIGH); EPSS percentile 55; not listed in KEV; Remediation reference present; patch status requires confirmation in the linked advisory; sources: NVD, Vendor Advisory.", "public_safe_summary": "NVD: Ilex International Sign&go Workstation Security Suite 7.1 allows elevation of privileges via a symlink attack on ProgramData\\Ilex\\S&G\\Logs\\000-sngWSService1.log.", "public_status": "public_safe", "published_at": null, "redaction_notes": ["source-published defensive context retained", "vulnerability class, impact, affected context, and remediation references remain displayable"], "remediation_handoff": {"auto_remediation_allowed": false, "codex_prompt_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-23968-codex-prompt.md", "external_execution_allowed": false, "human_approval_required": true, "json_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-23968.json", "markdown_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-23968.md", "scan_allowed": false}, "remediation_urls": ["http://ilex.com"], "sort_priority": 78.55043, "source_copy_policy": {"allowed": "source-published defensive facts, vulnerability class, impact, affected context, version and remediation facts", "excluded": "exploit procedures, exploit strings, shell commands, scanner instructions, procedural bypass detail, and reproduction material", "summary": "Official or semi-official source descriptions may be summarized for defensive triage; exploit-enabling procedure is removed."}, "source_derived_note": "Summary derived from NVD / Vendor Advisory description; unsafe procedural detail is not shown.", "source_label": "NVD, Vendor Advisory", "source_published_affected": "vendor/product: ilex / international_sign\\&go; affected version context: 7.1", "source_published_description": "NVD: Ilex International Sign&go Workstation Security Suite 7.1 allows elevation of privileges via a symlink attack on ProgramData\\Ilex\\S&G\\Logs\\000-sngWSService1.log.", "source_published_evidence_refs": [{"source": "NVD", "type": "source_description", "url": null}, {"source": "Vendor Advisory", "type": "source_description", "url": null}, {"source": "Reference", "type": "reference", "url": "https://ricardojba.github.io/CVE-Pending-ILEX-SignGo-EoP/"}, {"source": "Vendor Advisory", "type": "reference", "url": "http://ilex.com"}, {"source": "Reference", "type": "reference", "url": "http://signgo.com"}, {"source": "Reference", "type": "reference", "url": "https://ricardojba.github.io/CVE-Pending-ILEX-SignGo-EoP/"}, {"source": "Official Reference", "type": "reference", "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-23968"}], "source_published_impact": "Source describes privilege escalation risk. Possible impact: An attacker may cross a privilege boundary and gain more access than intended.", "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.", "source_published_summary": "NVD: Ilex International Sign&go Workstation Security Suite 7.1 allows elevation of privileges via a symlink attack on ProgramData\\Ilex\\S&G\\Logs\\000-sngWSService1.log.", "sources": ["NVD", "Vendor Advisory"], "summary": "CVE-2020-23968 is a defensive prioritization candidate. NVD lists CVSS severity as HIGH. CVSS score is 7.8. EPSS score is 0.0089 with percentile 0.5504. Known exploited catalog status is not listed in NVD for this record. Use official advisories and vendor remediation references for defensive review.", "summary_ja": null, "title": "CVE-2020-23968 defensive priority signal", "title_ja": null, "translation": null, "updated_at": null, "urgency_reasons": ["CVSS HIGH", "affected product present", "vendor advisory present", "recent update", "remediation reference present"], "vendor": "ilex", "what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "why_it_matters": "An attacker may cross a privilege boundary and gain more access than intended; CVSS 7.8 (HIGH); EPSS percentile 55; affected product context: ilex / international_sign\\&go; sources: NVD, Vendor Advisory."}, "CVE-2020-24193": {"affected_label": "daily_tracker_system_project / daily_tracker_system", "affected_products": [{"canonicalProduct": "daily_tracker_system", "canonicalVendor": "daily_tracker_system_project", "cpe": "cpe:2.3:a:daily_tracker_system_project:daily_tracker_system:1.0:*:*:*:*:*:*:*", "ecosystem": null, "packageName": null, "product": "daily_tracker_system", "purl": null, "vendor": "daily_tracker_system_project", "version": "1.0"}], "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2020-24193/", "cvss_score": 9.8, "cvss_severity": "CRITICAL", "data_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2020-24193.json", "defensive_priority": "Priority review candidate", "epss_percentile": 0.84557, "epss_score": 0.0277, "exposure_hint": "authenticated boundary", "human_consequence": "An attacker may be able to read or change database-backed application data.", "human_impact_label": "authentication boundary review · SQL injection risk · authenticated boundary", "human_risk_summary": "CVE-2020-24193 for daily_tracker_system_project / daily_tracker_system: An attacker may be able to read or change database-backed application data.", "id": "CVE-2020-24193", "impact_tags": ["authentication boundary review", "SQL injection risk", "authenticated boundary review"], "kev": false, "observed_at": "2026-07-08T03:39:09.814067+00:00", "product": "daily_tracker_system", "public_human_impact": "Source describes authentication boundary review · SQL injection risk · authenticated boundary. Possible impact: An attacker may be able to read or change database-backed application data.", "public_human_summary": "NVD: A SQL injection vulnerability in login in Sourcecodetester Daily Tracker System 1.0 allows unauthenticated user to execute authentication bypass with SQL injection via the email parameter.", "public_human_what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "public_human_why_it_matters": "Source describes authentication boundary review · SQL injection risk · authenticated boundary. Possible impact: An attacker may be able to read or change database-backed application data.; CVSS 9.8 (CRITICAL); EPSS percentile 85; not listed in KEV; Remediation reference present; patch status requires confirmation in the linked advisory; sources: NVD.", "public_safe_summary": "NVD: A SQL injection vulnerability in login in Sourcecodetester Daily Tracker System 1.0 allows unauthenticated user to execute authentication bypass with SQL injection via the email parameter.", "public_status": "public_safe", "published_at": null, "redaction_notes": ["source-published defensive context retained", "vulnerability class, impact, affected context, and remediation references remain displayable"], "remediation_handoff": {"auto_remediation_allowed": false, "codex_prompt_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-24193-codex-prompt.md", "external_execution_allowed": false, "human_approval_required": true, "json_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-24193.json", "markdown_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-24193.md", "scan_allowed": false}, "remediation_urls": ["https://nvd.nist.gov/vuln/detail/CVE-2020-24193"], "sort_priority": 98.84557, "source_copy_policy": {"allowed": "source-published defensive facts, vulnerability class, impact, affected context, version and remediation facts", "excluded": "exploit procedures, exploit strings, shell commands, scanner instructions, procedural bypass detail, and reproduction material", "summary": "Official or semi-official source descriptions may be summarized for defensive triage; exploit-enabling procedure is removed."}, "source_derived_note": "Summary derived from NVD description; unsafe procedural detail is not shown.", "source_label": "NVD, Vendor Advisory", "source_published_affected": "vendor/product: daily_tracker_system_project / daily_tracker_system; affected version context: 1.0", "source_published_description": "NVD: A SQL injection vulnerability in login in Sourcecodetester Daily Tracker System 1.0 allows unauthenticated user to execute authentication bypass with SQL injection via the email parameter.", "source_published_evidence_refs": [{"source": "NVD", "type": "source_description", "url": null}, {"source": "Reference", "type": "reference", "url": "https://www.exploit-db.com/exploits/48787"}, {"source": "Reference", "type": "reference", "url": "http://sourcecodetester.com"}, {"source": "Reference", "type": "reference", "url": "https://www.exploit-db.com/exploits/48787"}, {"source": "Official Reference", "type": "reference", "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-24193"}], "source_published_impact": "Source describes authentication boundary review · SQL injection risk · authenticated boundary. Possible impact: An attacker may be able to read or change database-backed application data.", "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.", "source_published_summary": "NVD: A SQL injection vulnerability in login in Sourcecodetester Daily Tracker System 1.0 allows unauthenticated user to execute authentication bypass with SQL injection via the email parameter.", "sources": ["NVD", "Vendor Advisory"], "summary": "CVE-2020-24193 is a defensive prioritization candidate. NVD lists CVSS severity as CRITICAL. CVSS score is 9.8. EPSS score is 0.0277 with percentile 0.8456. Known exploited catalog status is not listed in NVD for this record. Use official advisories and vendor remediation references for defensive review.", "summary_ja": null, "title": "CVE-2020-24193 defensive priority signal", "title_ja": null, "translation": null, "updated_at": null, "urgency_reasons": ["CVSS CRITICAL", "affected product present", "vendor advisory present", "recent update"], "vendor": "daily_tracker_system_project", "what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "why_it_matters": "An attacker may be able to read or change database-backed application data; CVSS 9.8 (CRITICAL); EPSS percentile 85; affected product context: daily_tracker_system_project / daily_tracker_system; sources: NVD."}, "CVE-2020-24194": {"affected_label": "daily_tracker_system_project / daily_tracker_system", "affected_products": [{"canonicalProduct": "daily_tracker_system", "canonicalVendor": "daily_tracker_system_project", "cpe": "cpe:2.3:a:daily_tracker_system_project:daily_tracker_system:1.0:*:*:*:*:*:*:*", "ecosystem": null, "packageName": null, "product": "daily_tracker_system", "purl": null, "vendor": "daily_tracker_system_project", "version": "1.0"}], "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2020-24194/", "cvss_score": 6.1, "cvss_severity": "MEDIUM", "data_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2020-24194.json", "defensive_priority": "Continuous monitoring candidate", "epss_percentile": 0.53283, "epss_score": 0.00835, "exposure_hint": "remote exposure", "human_consequence": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk · remote exposure.", "human_impact_label": "XSS risk · remote exposure", "human_risk_summary": "CVE-2020-24194 for daily_tracker_system_project / daily_tracker_system: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk · remote exposure.", "id": "CVE-2020-24194", "impact_tags": ["XSS risk", "remote exposure relevant"], "kev": false, "observed_at": "2026-07-08T03:39:09.814067+00:00", "product": "daily_tracker_system", "public_human_impact": "Source describes XSS risk · remote exposure. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk · remote exposure.", "public_human_summary": "NVD: A Cross-site scripting (XSS) vulnerability in 'user-profile.php' in SourceCodester Daily Tracker System v1.0 allows remote attackers to inject arbitrary web script or HTML via the 'fullname' parameter.", "public_human_what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "public_human_why_it_matters": "Source describes XSS risk · remote exposure. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk · remote exposure.; CVSS 6.1 (MEDIUM); EPSS percentile 53; not listed in KEV; Remediation reference present; patch status requires confirmation in the linked advisory; sources: NVD.", "public_safe_summary": "NVD: A Cross-site scripting (XSS) vulnerability in 'user-profile.php' in SourceCodester Daily Tracker System v1.0 allows remote attackers to inject arbitrary web script or HTML via the 'fullname' parameter.", "public_status": "public_safe", "published_at": null, "redaction_notes": ["source-published defensive context retained", "vulnerability class, impact, affected context, and remediation references remain displayable"], "remediation_handoff": {"auto_remediation_allowed": false, "codex_prompt_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-24194-codex-prompt.md", "external_execution_allowed": false, "human_approval_required": true, "json_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-24194.json", "markdown_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-24194.md", "scan_allowed": false}, "remediation_urls": ["https://cxsecurity.com/issue/WLB-2020090030"], "sort_priority": 61.53283, "source_copy_policy": {"allowed": "source-published defensive facts, vulnerability class, impact, affected context, version and remediation facts", "excluded": "exploit procedures, exploit strings, shell commands, scanner instructions, procedural bypass detail, and reproduction material", "summary": "Official or semi-official source descriptions may be summarized for defensive triage; exploit-enabling procedure is removed."}, "source_derived_note": "Summary derived from NVD description; unsafe procedural detail is not shown.", "source_label": "NVD, Vendor Advisory", "source_published_affected": "vendor/product: daily_tracker_system_project / daily_tracker_system; affected version context: 1.0", "source_published_description": "NVD: A Cross-site scripting (XSS) vulnerability in 'user-profile.php' in SourceCodester Daily Tracker System v1.0 allows remote attackers to inject arbitrary web script or HTML via the 'fullname' parameter.", "source_published_evidence_refs": [{"source": "NVD", "type": "source_description", "url": null}, {"source": "Reference", "type": "reference", "url": "https://cxsecurity.com/issue/WLB-2020090030"}, {"source": "Reference", "type": "reference", "url": "http://sourcecodetester.com"}, {"source": "Reference", "type": "reference", "url": "https://cxsecurity.com/issue/WLB-2020090030"}, {"source": "Official Reference", "type": "reference", "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-24194"}], "source_published_impact": "Source describes XSS risk · remote exposure. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk · remote exposure.", "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.", "source_published_summary": "NVD: A Cross-site scripting (XSS) vulnerability in 'user-profile.php' in SourceCodester Daily Tracker System v1.0 allows remote attackers to inject arbitrary web script or HTML via the 'fullname' parameter.", "sources": ["NVD", "Vendor Advisory"], "summary": "CVE-2020-24194 is a defensive prioritization candidate. NVD lists CVSS severity as MEDIUM. CVSS score is 6.1. EPSS score is 0.0083 with percentile 0.5328. Known exploited catalog status is not listed in NVD for this record. Use official advisories and vendor remediation references for defensive review.", "summary_ja": null, "title": "CVE-2020-24194 defensive priority signal", "title_ja": null, "translation": null, "updated_at": null, "urgency_reasons": ["affected product present", "vendor advisory present", "recent update", "remediation reference present"], "vendor": "daily_tracker_system_project", "what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "why_it_matters": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk · remote exposure; CVSS 6.1 (MEDIUM); EPSS percentile 53; affected product context: daily_tracker_system_project / daily_tracker_system..."}, "CVE-2020-25466": {"affected_label": "crmeb / crmeb", "affected_products": [{"canonicalProduct": "crmeb", "canonicalVendor": "crmeb", "cpe": "cpe:2.3:a:crmeb:crmeb:3.0:*:*:*:*:*:*:*", "ecosystem": null, "packageName": null, "product": "crmeb", "purl": null, "vendor": "crmeb", "version": "3.0"}], "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2020-25466/", "cvss_score": 9.8, "cvss_severity": "CRITICAL", "data_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2020-25466.json", "defensive_priority": "Priority review candidate", "epss_percentile": 0.85894, "epss_score": 0.03033, "exposure_hint": "exposure unknown", "human_consequence": "An attacker may be able to run code or commands on affected systems.", "human_impact_label": "code execution review", "human_risk_summary": "CVE-2020-25466 for crmeb / crmeb: An attacker may be able to run code or commands on affected systems.", "id": "CVE-2020-25466", "impact_tags": ["code execution review"], "kev": false, "observed_at": "2026-07-08T03:39:09.814067+00:00", "product": "crmeb", "public_human_impact": "Source describes code execution review. Possible impact: An attacker may be able to run code or commands on affected systems.", "public_human_summary": "NVD: A SSRF vulnerability exists in the downloadimage interface of CRMEB 3.0, which can remotely download arbitrary files on the server and remotely execute arbitrary code. OSV: A SSRF vulnerability exists in the downloadimage interface of CRMEB 3.0, which can remotely download arbitrary files on the server and remotely execute arbitrary code.", "public_human_what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "public_human_why_it_matters": "Source describes code execution review. Possible impact: An attacker may be able to run code or commands on affected systems.; CVSS 9.8 (CRITICAL); EPSS percentile 86; not listed in KEV; Remediation reference present; patch status requires confirmation in the linked advisory; sources: NVD, OSV, Vendor Advisory.", "public_safe_summary": "NVD: A SSRF vulnerability exists in the downloadimage interface of CRMEB 3.0, which can remotely download arbitrary files on the server and remotely execute arbitrary code. OSV: A SSRF vulnerability exists in the downloadimage interface of CRMEB 3.0, which can remotely download arbitrary files on the server and remotely execute arbitrary code.", "public_status": "public_safe", "published_at": null, "redaction_notes": ["source-published defensive context retained", "vulnerability class, impact, affected context, and remediation references remain displayable"], "remediation_handoff": {"auto_remediation_allowed": false, "codex_prompt_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-25466-codex-prompt.md", "external_execution_allowed": false, "human_approval_required": true, "json_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-25466.json", "markdown_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-25466.md", "scan_allowed": false}, "remediation_urls": ["http://crmeb.com"], "sort_priority": 98.85894, "source_copy_policy": {"allowed": "source-published defensive facts, vulnerability class, impact, affected context, version and remediation facts", "excluded": "exploit procedures, exploit strings, shell commands, scanner instructions, procedural bypass detail, and reproduction material", "summary": "Official or semi-official source descriptions may be summarized for defensive triage; exploit-enabling procedure is removed."}, "source_derived_note": "Summary derived from NVD / OSV / Vendor Advisory description; unsafe procedural detail is not shown.", "source_label": "NVD, OSV, Vendor Advisory", "source_published_affected": "vendor/product: crmeb / crmeb; affected version context: 3.0", "source_published_description": "NVD: A SSRF vulnerability exists in the downloadimage interface of CRMEB 3.0, which can remotely download arbitrary files on the server and remotely execute arbitrary code. OSV: A SSRF vulnerability exists in the downloadimage interface of CRMEB 3.0, which can remotely download arbitrary files on the server and remotely execute arbitrary code.", "source_published_evidence_refs": [{"source": "NVD", "type": "source_description", "url": null}, {"source": "OSV", "type": "source_description", "url": null}, {"source": "Vendor Advisory", "type": "source_description", "url": null}, {"source": "Reference", "type": "reference", "url": "https://github.com/crmeb/CRMEB"}, {"source": "Reference", "type": "reference", "url": "https://github.com/crmeb/CRMEB/issues/22"}, {"source": "Vendor Advisory", "type": "reference", "url": "http://crmeb.com"}, {"source": "Reference", "type": "reference", "url": "https://github.com/crmeb/CRMEB"}, {"source": "Reference", "type": "reference", "url": "https://github.com/crmeb/CRMEB/issues/22"}, {"source": "Official Reference", "type": "reference", "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-25466"}, {"source": "Official Reference", "type": "reference", "url": "https://osv.dev/vulnerability/CVE-2020-25466"}], "source_published_impact": "Source describes code execution review. Possible impact: An attacker may be able to run code or commands on affected systems.", "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.", "source_published_summary": "NVD: A SSRF vulnerability exists in the downloadimage interface of CRMEB 3.0, which can remotely download arbitrary files on the server and remotely execute arbitrary code. OSV: A SSRF vulnerability exists in the downloadimage interface of CRMEB 3.0, which can remotely download arbitrary files on the server and remotely execute arbitrary code.", "sources": ["NVD", "OSV", "Vendor Advisory"], "summary": "CVE-2020-25466 is a defensive prioritization candidate. NVD lists CVSS severity as CRITICAL. CVSS score is 9.8. EPSS score is 0.0303 with percentile 0.8589. Known exploited catalog status is not listed in NVD for this record. Use official advisories and vendor remediation references for defensive review.", "summary_ja": null, "title": "CVE-2020-25466 defensive priority signal", "title_ja": null, "translation": null, "updated_at": null, "urgency_reasons": ["CVSS CRITICAL", "affected product present", "vendor advisory present", "recent update", "remediation reference present"], "vendor": "crmeb", "what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "why_it_matters": "An attacker may be able to run code or commands on affected systems; CVSS 9.8 (CRITICAL); EPSS percentile 86; affected product context: crmeb / crmeb; sources: NVD, OSV, Vendor Advisory."}, "CVE-2020-25487": {"affected_label": "phpgurukul / zoo_management_system", "affected_products": [{"canonicalProduct": "zoo_management_system", "canonicalVendor": "phpgurukul", "cpe": "cpe:2.3:a:phpgurukul:zoo_management_system:1.0:*:*:*:*:*:*:*", "ecosystem": null, "packageName": null, "product": "zoo_management_system", "purl": null, "vendor": "phpgurukul", "version": "1.0"}], "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2020-25487/", "cvss_score": 7.8, "cvss_severity": "HIGH", "data_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2020-25487.json", "defensive_priority": "Continuous monitoring candidate", "epss_percentile": 0.42196, "epss_score": 0.00553, "exposure_hint": "exposure unknown", "human_consequence": "An attacker may be able to read or change database-backed application data.", "human_impact_label": "SQL injection risk", "human_risk_summary": "CVE-2020-25487 for phpgurukul / zoo_management_system: An attacker may be able to read or change database-backed application data.", "id": "CVE-2020-25487", "impact_tags": ["SQL injection risk"], "kev": false, "observed_at": "2026-07-08T03:39:09.814067+00:00", "product": "zoo_management_system", "public_human_impact": "Source describes SQL injection risk. Possible impact: An attacker may be able to read or change database-backed application data.", "public_human_summary": "NVD: PHPGURUKUL Zoo Management System Using PHP and MySQL version 1.0 is affected by: SQL Injection via zms/animal-detail.php.", "public_human_what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "public_human_why_it_matters": "Source describes SQL injection risk. Possible impact: An attacker may be able to read or change database-backed application data.; CVSS 7.8 (HIGH); EPSS percentile 42; not listed in KEV; Remediation reference present; patch status requires confirmation in the linked advisory; sources: NVD.", "public_safe_summary": "NVD: PHPGURUKUL Zoo Management System Using PHP and MySQL version 1.0 is affected by: SQL Injection via zms/animal-detail.php.", "public_status": "public_safe", "published_at": null, "redaction_notes": ["source-published defensive context retained", "vulnerability class, impact, affected context, and remediation references remain displayable"], "remediation_handoff": {"auto_remediation_allowed": false, "codex_prompt_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-25487-codex-prompt.md", "external_execution_allowed": false, "human_approval_required": true, "json_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-25487.json", "markdown_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-25487.md", "scan_allowed": false}, "remediation_urls": ["https://nvd.nist.gov/vuln/detail/CVE-2020-25487"], "sort_priority": 78.42196, "source_copy_policy": {"allowed": "source-published defensive facts, vulnerability class, impact, affected context, version and remediation facts", "excluded": "exploit procedures, exploit strings, shell commands, scanner instructions, procedural bypass detail, and reproduction material", "summary": "Official or semi-official source descriptions may be summarized for defensive triage; exploit-enabling procedure is removed."}, "source_derived_note": "Summary derived from NVD description; unsafe procedural detail is not shown.", "source_label": "NVD, Vendor Advisory", "source_published_affected": "vendor/product: phpgurukul / zoo_management_system; affected version context: 1.0", "source_published_description": "NVD: PHPGURUKUL Zoo Management System Using PHP and MySQL version 1.0 is affected by: SQL Injection via zms/animal-detail.php.", "source_published_evidence_refs": [{"source": "NVD", "type": "source_description", "url": null}, {"source": "Reference", "type": "reference", "url": "https://github.com/Ko-kn3t/CVE-2020-25487"}, {"source": "Reference", "type": "reference", "url": "https://phpgurukul.com/zoo-management-system-using-php-and-mysql/"}, {"source": "Reference", "type": "reference", "url": "http://phpgurukul.com"}, {"source": "Reference", "type": "reference", "url": "https://github.com/Ko-kn3t/CVE-2020-25487"}, {"source": "Reference", "type": "reference", "url": "https://phpgurukul.com/zoo-management-system-using-php-and-mysql/"}, {"source": "Official Reference", "type": "reference", "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-25487"}], "source_published_impact": "Source describes SQL injection risk. Possible impact: An attacker may be able to read or change database-backed application data.", "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.", "source_published_summary": "NVD: PHPGURUKUL Zoo Management System Using PHP and MySQL version 1.0 is affected by: SQL Injection via zms/animal-detail.php.", "sources": ["NVD", "Vendor Advisory"], "summary": "CVE-2020-25487 is a defensive prioritization candidate. NVD lists CVSS severity as HIGH. CVSS score is 7.8. EPSS score is 0.0055 with percentile 0.4220. Known exploited catalog status is not listed in NVD for this record. Use official advisories and vendor remediation references for defensive review.", "summary_ja": null, "title": "CVE-2020-25487 defensive priority signal", "title_ja": null, "translation": null, "updated_at": null, "urgency_reasons": ["CVSS HIGH", "affected product present", "vendor advisory present", "recent update"], "vendor": "phpgurukul", "what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "why_it_matters": "An attacker may be able to read or change database-backed application data; CVSS 7.8 (HIGH); EPSS percentile 42; affected product context: phpgurukul / zoo_management_system; sources: NVD."}, "CVE-2020-25514": {"affected_label": "simple_library_management_system_project / simple_library_management_system", "affected_products": [{"canonicalProduct": "simple_library_management_system", "canonicalVendor": "simple_library_management_system_project", "cpe": "cpe:2.3:a:simple_library_management_system_project:simple_library_management_system:1.0:*:*:*:*:*:*:*", "ecosystem": null, "packageName": null, "product": "simple_library_management_system", "purl": null, "vendor": "simple_library_management_system_project", "version": "1.0"}], "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2020-25514/", "cvss_score": 8.4, "cvss_severity": "HIGH", "data_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2020-25514.json", "defensive_priority": "Continuous monitoring candidate", "epss_percentile": 0.45772, "epss_score": 0.00629, "exposure_hint": "exposure unknown", "human_consequence": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.", "human_impact_label": "high severity review", "human_risk_summary": "CVE-2020-25514 for simple_library_management_system_project / simple_library_management_system: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.", "id": "CVE-2020-25514", "impact_tags": [], "kev": false, "observed_at": "2026-07-08T03:39:09.814067+00:00", "product": "simple_library_management_system", "public_human_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.", "public_human_summary": "NVD: Sourcecodester Simple Library Management System 1.0 is affected by Incorrect Access Control via the Login Panel,", "public_human_what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "public_human_why_it_matters": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.; CVSS 8.4 (HIGH); EPSS percentile 46; not listed in KEV; Remediation reference present; patch status requires confirmation in the linked advisory; sources: NVD.", "public_safe_summary": "NVD: Sourcecodester Simple Library Management System 1.0 is affected by Incorrect Access Control via the Login Panel,", "public_status": "public_safe", "published_at": null, "redaction_notes": ["source-published defensive context retained", "vulnerability class, impact, affected context, and remediation references remain displayable"], "remediation_handoff": {"auto_remediation_allowed": false, "codex_prompt_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-25514-codex-prompt.md", "external_execution_allowed": false, "human_approval_required": true, "json_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-25514.json", "markdown_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-25514.md", "scan_allowed": false}, "remediation_urls": ["https://nvd.nist.gov/vuln/detail/CVE-2020-25514"], "sort_priority": 84.45772, "source_copy_policy": {"allowed": "source-published defensive facts, vulnerability class, impact, affected context, version and remediation facts", "excluded": "exploit procedures, exploit strings, shell commands, scanner instructions, procedural bypass detail, and reproduction material", "summary": "Official or semi-official source descriptions may be summarized for defensive triage; exploit-enabling procedure is removed."}, "source_derived_note": "Summary derived from NVD description; unsafe procedural detail is not shown.", "source_label": "NVD, Vendor Advisory", "source_published_affected": "vendor/product: simple_library_management_system_project / simple_library_management_system; affected version context: 1.0", "source_published_description": "NVD: Sourcecodester Simple Library Management System 1.0 is affected by Incorrect Access Control via the Login Panel,", "source_published_evidence_refs": [{"source": "NVD", "type": "source_description", "url": null}, {"source": "Reference", "type": "reference", "url": "https://github.com/Ko-kn3t/CVE-2020-25514"}, {"source": "Reference", "type": "reference", "url": "https://www.sourcecodester.com"}, {"source": "Reference", "type": "reference", "url": "http://simple.com"}, {"source": "Reference", "type": "reference", "url": "https://github.com/Ko-kn3t/CVE-2020-25514"}, {"source": "Reference", "type": "reference", "url": "https://www.sourcecodester.com"}, {"source": "Official Reference", "type": "reference", "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-25514"}], "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.", "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.", "source_published_summary": "NVD: Sourcecodester Simple Library Management System 1.0 is affected by Incorrect Access Control via the Login Panel,", "sources": ["NVD", "Vendor Advisory"], "summary": "CVE-2020-25514 is a defensive prioritization candidate. NVD lists CVSS severity as HIGH. CVSS score is 8.4. EPSS score is 0.0063 with percentile 0.4577. Known exploited catalog status is not listed in NVD for this record. Use official advisories and vendor remediation references for defensive review.", "summary_ja": null, "title": "CVE-2020-25514 defensive priority signal", "title_ja": null, "translation": null, "updated_at": null, "urgency_reasons": ["CVSS HIGH", "affected product present", "vendor advisory present", "recent update"], "vendor": "simple_library_management_system_project", "what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "why_it_matters": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review; CVSS 8.4 (HIGH); EPSS percentile 46; affected product context: simple_library_management_system_project /..."}, "CVE-2020-25515": {"affected_label": "simple_library_management_system_project / simple_library_management_system", "affected_products": [{"canonicalProduct": "simple_library_management_system", "canonicalVendor": "simple_library_management_system_project", "cpe": "cpe:2.3:a:simple_library_management_system_project:simple_library_management_system:1.0:*:*:*:*:*:*:*", "ecosystem": null, "packageName": null, "product": "simple_library_management_system", "purl": null, "vendor": "simple_library_management_system_project", "version": "1.0"}], "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2020-25515/", "cvss_score": 7.8, "cvss_severity": "HIGH", "data_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2020-25515.json", "defensive_priority": "Continuous monitoring candidate", "epss_percentile": 0.41554, "epss_score": 0.00541, "exposure_hint": "exposure unknown", "human_consequence": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.", "human_impact_label": "high severity review", "human_risk_summary": "CVE-2020-25515 for simple_library_management_system_project / simple_library_management_system: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.", "id": "CVE-2020-25515", "impact_tags": [], "kev": false, "observed_at": "2026-07-08T03:39:09.814067+00:00", "product": "simple_library_management_system", "public_human_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.", "public_human_summary": "NVD: Sourcecodester Simple Library Management System 1.0 is affected by Insecure Permissions via Books > New Book ,", "public_human_what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "public_human_why_it_matters": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.; CVSS 7.8 (HIGH); EPSS percentile 42; not listed in KEV; Remediation reference present; patch status requires confirmation in the linked advisory; sources: NVD.", "public_safe_summary": "NVD: Sourcecodester Simple Library Management System 1.0 is affected by Insecure Permissions via Books > New Book ,", "public_status": "public_safe", "published_at": null, "redaction_notes": ["source-published defensive context retained", "vulnerability class, impact, affected context, and remediation references remain displayable"], "remediation_handoff": {"auto_remediation_allowed": false, "codex_prompt_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-25515-codex-prompt.md", "external_execution_allowed": false, "human_approval_required": true, "json_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-25515.json", "markdown_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-25515.md", "scan_allowed": false}, "remediation_urls": ["https://nvd.nist.gov/vuln/detail/CVE-2020-25515"], "sort_priority": 78.41554, "source_copy_policy": {"allowed": "source-published defensive facts, vulnerability class, impact, affected context, version and remediation facts", "excluded": "exploit procedures, exploit strings, shell commands, scanner instructions, procedural bypass detail, and reproduction material", "summary": "Official or semi-official source descriptions may be summarized for defensive triage; exploit-enabling procedure is removed."}, "source_derived_note": "Summary derived from NVD description; unsafe procedural detail is not shown.", "source_label": "NVD, Vendor Advisory", "source_published_affected": "vendor/product: simple_library_management_system_project / simple_library_management_system; affected version context: 1.0", "source_published_description": "NVD: Sourcecodester Simple Library Management System 1.0 is affected by Insecure Permissions via Books > New Book ,", "source_published_evidence_refs": [{"source": "NVD", "type": "source_description", "url": null}, {"source": "Reference", "type": "reference", "url": "https://github.com/Ko-kn3t/CVE-2020-25515"}, {"source": "Reference", "type": "reference", "url": "https://www.sourcecodester.com"}, {"source": "Reference", "type": "reference", "url": "http://simple.com"}, {"source": "Reference", "type": "reference", "url": "https://github.com/Ko-kn3t/CVE-2020-25515"}, {"source": "Reference", "type": "reference", "url": "https://www.sourcecodester.com"}, {"source": "Official Reference", "type": "reference", "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-25515"}], "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.", "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.", "source_published_summary": "NVD: Sourcecodester Simple Library Management System 1.0 is affected by Insecure Permissions via Books > New Book ,", "sources": ["NVD", "Vendor Advisory"], "summary": "CVE-2020-25515 is a defensive prioritization candidate. NVD lists CVSS severity as HIGH. CVSS score is 7.8. EPSS score is 0.0054 with percentile 0.4155. Known exploited catalog status is not listed in NVD for this record. Use official advisories and vendor remediation references for defensive review.", "summary_ja": null, "title": "CVE-2020-25515 defensive priority signal", "title_ja": null, "translation": null, "updated_at": null, "urgency_reasons": ["CVSS HIGH", "affected product present", "vendor advisory present", "recent update"], "vendor": "simple_library_management_system_project", "what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "why_it_matters": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review; CVSS 7.8 (HIGH); EPSS percentile 42; affected product context: simple_library_management_system_project /..."}, "CVE-2020-27388": {"affected_label": "yourls / yourls", "affected_products": [{"canonicalProduct": "yourls", "canonicalVendor": "yourls", "cpe": "cpe:2.3:a:yourls:yourls:*:*:*:*:*:*:*:*", "ecosystem": null, "packageName": null, "product": "yourls", "purl": null, "vendor": "yourls", "version": null}], "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2020-27388/", "cvss_score": 5.4, "cvss_severity": "MEDIUM", "data_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2020-27388.json", "defensive_priority": "Continuous monitoring candidate", "epss_percentile": 0.50603, "epss_score": 0.00754, "exposure_hint": "exposure unknown", "human_consequence": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.", "human_impact_label": "defensive exposure review", "human_risk_summary": "CVE-2020-27388 for yourls / yourls: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.", "id": "CVE-2020-27388", "impact_tags": [], "kev": false, "observed_at": "2026-07-08T03:39:09.814067+00:00", "product": "yourls", "public_human_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.", "public_human_summary": "NVD: Multiple Stored Cross Site Scripting (XSS) vulnerabilities exist in the YOURLS Admin Panel, Versions 1.5 - 1.7.10.", "public_human_what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "public_human_why_it_matters": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.; CVSS 5.4 (MEDIUM); EPSS percentile 51; not listed in KEV; Remediation reference present; patch status requires confirmation in the linked advisory; sources: NVD.", "public_safe_summary": "NVD: Multiple Stored Cross Site Scripting (XSS) vulnerabilities exist in the YOURLS Admin Panel, Versions 1.5 - 1.7.10.", "public_status": "public_safe", "published_at": null, "redaction_notes": ["source-published defensive context retained", "exploit string, command, scanner, or code-like detail removed", "vulnerability class, impact, affected context, and remediation references remain displayable"], "remediation_handoff": {"auto_remediation_allowed": false, "codex_prompt_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-27388-codex-prompt.md", "external_execution_allowed": false, "human_approval_required": true, "json_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-27388.json", "markdown_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-27388.md", "scan_allowed": false}, "remediation_urls": ["https://nvd.nist.gov/vuln/detail/CVE-2020-27388"], "sort_priority": 54.50603, "source_copy_policy": {"allowed": "source-published defensive facts, vulnerability class, impact, affected context, version and remediation facts", "excluded": "exploit procedures, exploit strings, shell commands, scanner instructions, procedural bypass detail, and reproduction material", "summary": "Official or semi-official source descriptions may be summarized for defensive triage; exploit-enabling procedure is removed."}, "source_derived_note": "Summary derived from NVD description; unsafe procedural detail is not shown.", "source_label": "NVD, Vendor Advisory", "source_published_affected": "vendor/product: yourls / yourls", "source_published_description": "NVD: Multiple Stored Cross Site Scripting (XSS) vulnerabilities exist in the YOURLS Admin Panel, Versions 1.5 - 1.7.10.", "source_published_evidence_refs": [{"source": "NVD", "type": "source_description", "url": null}, {"source": "Reference", "type": "reference", "url": "https://github.com/YOURLS/YOURLS/pull/2761"}, {"source": "Reference", "type": "reference", "url": "https://johnjhacking.com/blog/cve-2020-27388/"}, {"source": "Reference", "type": "reference", "url": "http://yourls.com"}, {"source": "Reference", "type": "reference", "url": "https://github.com/YOURLS/YOURLS/pull/2761"}, {"source": "Reference", "type": "reference", "url": "https://johnjhacking.com/blog/cve-2020-27388/"}, {"source": "Official Reference", "type": "reference", "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-27388"}], "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.", "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.", "source_published_summary": "NVD: Multiple Stored Cross Site Scripting (XSS) vulnerabilities exist in the YOURLS Admin Panel, Versions 1.5 - 1.7.10.", "sources": ["NVD", "Vendor Advisory"], "summary": "CVE-2020-27388 is a defensive prioritization candidate. NVD lists CVSS severity as MEDIUM. CVSS score is 5.4. EPSS score is 0.0075 with percentile 0.5060. Known exploited catalog status is not listed in NVD for this record. Use official advisories and vendor remediation references for defensive review.", "summary_ja": null, "title": "CVE-2020-27388 defensive priority signal", "title_ja": null, "translation": null, "updated_at": null, "urgency_reasons": ["affected product present", "vendor advisory present", "recent update"], "vendor": "yourls", "what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "why_it_matters": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review; CVSS 5.4 (MEDIUM); EPSS percentile 51; affected product context: yourls / yourls; sources: NVD."}}, "readModel": {"ageDistribution": {"0-24h": 20, "2-7d": 0, "8-30d": 0, ">30d": 0, "unknown": 0}, "enrichmentCoverage": {"affected_products": 53, "canonical_vendor_product": 53, "coverage_label": "partial", "cpe": 53, "purl": 0, "sources": {"CISA KEV": 0, "NVD": 20, "OSV": 2, "Vendor Advisory": 20}}, "feedItems": [{"affected_label": "vmware / ace", "affected_products": [{"canonicalProduct": "ace", "canonicalVendor": "vmware", "cpe": "cpe:2.3:a:vmware:ace:1.0.1:*:*:*:*:*:*:*", "ecosystem": null, "packageName": null, "product": "ace", "purl": null, "vendor": "vmware", "version": "1.0.1"}, {"canonicalProduct": "gsx_server", "canonicalVendor": "vmware", "cpe": "cpe:2.3:a:vmware:gsx_server:2.0:*:*:*:*:*:*:*", "ecosystem": null, "packageName": null, "product": "gsx_server", "purl": null, "vendor": "vmware", "version": "2.0"}, {"canonicalProduct": "gsx_server", "canonicalVendor": "vmware", "cpe": "cpe:2.3:a:vmware:gsx_server:2.0.1_build_2129:*:*:*:*:*:*:*", "ecosystem": null, "packageName": null, "product": "gsx_server", "purl": null, "vendor": "vmware", "version": "2.0.1_build_2129"}, {"canonicalProduct": "gsx_server", "canonicalVendor": "vmware", "cpe": "cpe:2.3:a:vmware:gsx_server:2.5.1:*:*:*:*:*:*:*", "ecosystem": null, "packageName": null, "product": "gsx_server", "purl": null, "vendor": "vmware", "version": "2.5.1"}, {"canonicalProduct": "gsx_server", "canonicalVendor": "vmware", "cpe": "cpe:2.3:a:vmware:gsx_server:2.5.1_build_5336:*:*:*:*:*:*:*", "ecosystem": null, "packageName": null, "product": "gsx_server", "purl": null, "vendor": "vmware", "version": "2.5.1_build_5336"}, {"canonicalProduct": "gsx_server", "canonicalVendor": "vmware", "cpe": "cpe:2.3:a:vmware:gsx_server:2.5.2:*:*:*:*:*:*:*", "ecosystem": null, "packageName": null, "product": "gsx_server", "purl": null, "vendor": "vmware", "version": "2.5.2"}, {"canonicalProduct": "gsx_server", "canonicalVendor": "vmware", "cpe": "cpe:2.3:a:vmware:gsx_server:3.0:*:*:*:*:*:*:*", "ecosystem": null, "packageName": null, "product": "gsx_server", "purl": null, "vendor": "vmware", "version": "3.0"}, {"canonicalProduct": "gsx_server", "canonicalVendor": "vmware", "cpe": "cpe:2.3:a:vmware:gsx_server:3.0_build_7592:*:*:*:*:*:*:*", "ecosystem": null, "packageName": null, "product": "gsx_server", "purl": null, "vendor": "vmware", "version": "3.0_build_7592"}, {"canonicalProduct": "gsx_server", "canonicalVendor": "vmware", "cpe": "cpe:2.3:a:vmware:gsx_server:3.1:*:*:*:*:*:*:*", "ecosystem": null, "packageName": null, "product": "gsx_server", "purl": null, "vendor": "vmware", "version": "3.1"}, {"canonicalProduct": "gsx_server", "canonicalVendor": "vmware", "cpe": "cpe:2.3:a:vmware:gsx_server:3.2:*:*:*:*:*:*:*", "ecosystem": null, "packageName": null, "product": "gsx_server", "purl": null, "vendor": "vmware", "version": "3.2"}, {"canonicalProduct": "player", "canonicalVendor": "vmware", "cpe": "cpe:2.3:a:vmware:player:1.0.0:*:*:*:*:*:*:*", "ecosystem": null, "packageName": null, "product": "player", "purl": null, "vendor": "vmware", "version": "1.0.0"}, {"canonicalProduct": "workstation", "canonicalVendor": "vmware", "cpe": "cpe:2.3:a:vmware:workstation:3.2.1:patch1:*:*:*:*:*:*", "ecosystem": null, "packageName": null, "product": "workstation", "purl": null, "vendor": "vmware", "version": "3.2.1"}, {"canonicalProduct": "workstation", "canonicalVendor": "vmware", "cpe": "cpe:2.3:a:vmware:workstation:3.4:*:*:*:*:*:*:*", "ecosystem": null, "packageName": null, "product": "workstation", "purl": null, "vendor": "vmware", "version": "3.4"}, {"canonicalProduct": "workstation", "canonicalVendor": "vmware", "cpe": "cpe:2.3:a:vmware:workstation:4.0:*:*:*:*:*:*:*", "ecosystem": null, "packageName": null, "product": "workstation", "purl": null, "vendor": "vmware", "version": "4.0"}, {"canonicalProduct": "workstation", "canonicalVendor": "vmware", "cpe": "cpe:2.3:a:vmware:workstation:4.0.1:*:*:*:*:*:*:*", "ecosystem": null, "packageName": null, "product": "workstation", "purl": null, "vendor": "vmware", "version": "4.0.1"}, {"canonicalProduct": "workstation", "canonicalVendor": "vmware", "cpe": "cpe:2.3:a:vmware:workstation:4.0.2:*:*:*:*:*:*:*", "ecosystem": null, "packageName": null, "product": "workstation", "purl": null, "vendor": "vmware", "version": "4.0.2"}, {"canonicalProduct": "workstation", "canonicalVendor": "vmware", "cpe": "cpe:2.3:a:vmware:workstation:4.5.2:*:*:*:*:*:*:*", "ecosystem": null, "packageName": null, "product": "workstation", "purl": null, "vendor": "vmware", "version": "4.5.2"}, {"canonicalProduct": "workstation", "canonicalVendor": "vmware", "cpe": "cpe:2.3:a:vmware:workstation:4.5.2_build_8848:r4:*:*:*:*:*:*", "ecosystem": null, "packageName": null, "product": "workstation", "purl": null, "vendor": "vmware", "version": "4.5.2_build_8848"}, {"canonicalProduct": "workstation", "canonicalVendor": "vmware", "cpe": "cpe:2.3:a:vmware:workstation:5.0.0_build_13124:*:*:*:*:*:*:*", "ecosystem": null, "packageName": null, "product": "workstation", "purl": null, "vendor": "vmware", "version": "5.0.0_build_13124"}, {"canonicalProduct": "workstation", "canonicalVendor": "vmware", "cpe": "cpe:2.3:a:vmware:workstation:5.5:*:*:*:*:*:*:*", "ecosystem": null, "packageName": null, "product": "workstation", "purl": null, "vendor": "vmware", "version": "5.5"}], "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2005-4459/", "cvss_score": 10.0, "cvss_severity": "CRITICAL", "data_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2005-4459.json", "defensive_priority": "Priority review candidate", "epss_percentile": 0.96028, "epss_score": 0.13661, "exposure_hint": "authenticated boundary", "human_consequence": "An attacker may be able to run code or commands on affected systems.", "human_impact_label": "code execution review · memory safety review · authenticated boundary", "human_risk_summary": "CVE-2005-4459 for vmware / ace: An attacker may be able to run code or commands on affected systems.", "id": "CVE-2005-4459", "impact_tags": ["code execution review", "memory safety review", "authenticated boundary review"], "kev": false, "observed_at": "2026-07-08T03:39:09.814067+00:00", "product": "ace", "public_human_impact": "Source describes code execution review · memory safety review · authenticated boundary. Possible impact: An attacker may be able to run code or commands on affected systems.", "public_human_summary": "NVD: Heap-based buffer overflow in the NAT networking components vmnat.exe and vmnet-natd in VMWare Workstation 5.5, GSX Server 3.2, ACE 1.0.1, and Player 1.0 allows remote authenticated attackers, including guests, to execute arbitrary code via crafted (1) EPRT...", "public_human_what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "public_human_why_it_matters": "Source describes code execution review · memory safety review · authenticated boundary. Possible impact: An attacker may be able to run code or commands on affected systems.; CVSS 10.0 (CRITICAL); EPSS percentile 96; not listed in KEV; Remediation reference present; patch status requires confirmation in the linked advisory; sources: NVD, Vendor Advisory.", "public_safe_summary": "NVD: Heap-based buffer overflow in the NAT networking components vmnat.exe and vmnet-natd in VMWare Workstation 5.5, GSX Server 3.2, ACE 1.0.1, and Player 1.0 allows remote authenticated attackers, including guests, to execute arbitrary code via crafted (1) EPRT...", "public_status": "public_safe", "published_at": null, "redaction_notes": ["source-published defensive context retained", "vulnerability class, impact, affected context, and remediation references remain displayable"], "remediation_handoff": {"auto_remediation_allowed": false, "codex_prompt_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2005-4459-codex-prompt.md", "external_execution_allowed": false, "human_approval_required": true, "json_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2005-4459.json", "markdown_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2005-4459.md", "scan_allowed": false}, "remediation_urls": ["http://secunia.com/advisories/18162", "http://secunia.com/advisories/18344", "http://securityreason.com/securityalert/282", "http://securityreason.com/securityalert/289", "http://securitytracker.com/id?1015401", "http://www.gentoo.org/security/en/glsa/glsa-200601-04.xml", "http://www.securityfocus.com/archive/1/419997/100/0/threaded", "http://www.securityfocus.com/archive/1/420017/100/0/threaded", "http://www.securityfocus.com/bid/15998", "http://www.vmware.com/support/kb/enduser/std_adp.php?p_faqid=2000"], "sort_priority": 100.96028, "source_copy_policy": {"allowed": "source-published defensive facts, vulnerability class, impact, affected context, version and remediation facts", "excluded": "exploit procedures, exploit strings, shell commands, scanner instructions, procedural bypass detail, and reproduction material", "summary": "Official or semi-official source descriptions may be summarized for defensive triage; exploit-enabling procedure is removed."}, "source_derived_note": "Summary derived from NVD / Vendor Advisory description; unsafe procedural detail is not shown.", "source_label": "NVD, Vendor Advisory", "source_published_affected": "vendor/product: vmware / ace; affected version context: 1.0.0, 1.0.1, 2.0, 2.0.1_build_2129, 2.5.1", "source_published_description": "NVD: Heap-based buffer overflow in the NAT networking components vmnat.exe and vmnet-natd in VMWare Workstation 5.5, GSX Server 3.2, ACE 1.0.1, and Player 1.0 allows remote authenticated attackers, including guests, to execute arbitrary code via crafted (1) EPRT...", "source_published_evidence_refs": [{"source": "NVD", "type": "source_description", "url": null}, {"source": "Vendor Advisory", "type": "source_description", "url": null}, {"source": "Reference", "type": "reference", "url": "http://lists.grok.org.uk/pipermail/full-disclosure/2005-December/040442.html"}, {"source": "Vendor Advisory", "type": "reference", "url": "http://secunia.com/advisories/18162"}, {"source": "Vendor Advisory", "type": "reference", "url": "http://secunia.com/advisories/18344"}, {"source": "Reference", "type": "reference", "url": "http://securityreason.com/securityalert/282"}, {"source": "Reference", "type": "reference", "url": "http://securityreason.com/securityalert/289"}, {"source": "Reference", "type": "reference", "url": "http://securitytracker.com/id?1015401"}, {"source": "Reference", "type": "reference", "url": "http://www.gentoo.org/security/en/glsa/glsa-200601-04.xml"}, {"source": "Reference", "type": "reference", "url": "http://www.kb.cert.org/vuls/id/856689"}], "source_published_impact": "Source describes code execution review · memory safety review · authenticated boundary. Possible impact: An attacker may be able to run code or commands on affected systems.", "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.", "source_published_summary": "NVD: Heap-based buffer overflow in the NAT networking components vmnat.exe and vmnet-natd in VMWare Workstation 5.5, GSX Server 3.2, ACE 1.0.1, and Player 1.0 allows remote authenticated attackers, including guests, to execute arbitrary code via crafted (1) EPRT...", "sources": ["NVD", "Vendor Advisory"], "summary": "CVE-2005-4459 is a defensive prioritization candidate. NVD lists CVSS severity as HIGH. CVSS score is 10.0. EPSS score is 0.1366 with percentile 0.9603. Known exploited catalog status is not listed in NVD for this record. Use official advisories and vendor remediation references for defensive review.", "summary_ja": null, "title": "CVE-2005-4459 defensive priority signal", "title_ja": null, "translation": null, "updated_at": null, "urgency_reasons": ["CVSS CRITICAL", "EPSS percentile high", "affected product present", "vendor advisory present", "recent update", "remediation reference present"], "vendor": "vmware", "what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "why_it_matters": "An attacker may be able to run code or commands on affected systems; CVSS 10.0 (CRITICAL); EPSS percentile 96; affected product context: vmware / ace; sources: NVD, Vendor Advisory."}, {"affected_label": "zohocorp / manageengine_adselfservice_plus", "affected_products": [{"canonicalProduct": "manageengine_adselfservice_plus", "canonicalVendor": "zohocorp", "cpe": "cpe:2.3:a:zohocorp:manageengine_adselfservice_plus:*:*:*:*:*:*:*:*", "ecosystem": null, "packageName": null, "product": "manageengine_adselfservice_plus", "purl": null, "vendor": "zohocorp", "version": null}, {"canonicalProduct": "manageengine_adselfservice_plus", "canonicalVendor": "zohocorp", "cpe": "cpe:2.3:a:zohocorp:manageengine_adselfservice_plus:5.5:-:*:*:*:*:*:*", "ecosystem": null, "packageName": null, "product": "manageengine_adselfservice_plus", "purl": null, "vendor": "zohocorp", "version": "5.5"}], "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2018-5353/", "cvss_score": 9.8, "cvss_severity": "CRITICAL", "data_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2018-5353.json", "defensive_priority": "Priority review candidate", "epss_percentile": 0.94138, "epss_score": 0.08103, "exposure_hint": "remote exposure", "human_consequence": "This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary.", "human_impact_label": "remote exposure · authenticated boundary", "human_risk_summary": "CVE-2018-5353 for zohocorp / manageengine_adselfservice_plus: This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary.", "id": "CVE-2018-5353", "impact_tags": ["remote exposure relevant", "authenticated boundary review"], "kev": false, "observed_at": "2026-07-08T03:39:09.814067+00:00", "product": "manageengine_adselfservice_plus", "public_human_impact": "Source describes remote exposure · authenticated boundary. Possible impact: This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary.", "public_human_summary": "NVD: The custom GINA/CP module in Zoho ManageEngine ADSelfService Plus before 5.5 build 5517 allows remote attackers to execute code and escalate privileges via spoofing. NVD: It does not authenticate the intended server before opening a browser window. NVD: An unauthenticated attacker capable of conducting a spoofing attack can redirect the browser to gain execution in the context of the WinLogon.exe process.", "public_human_what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "public_human_why_it_matters": "Source describes remote exposure · authenticated boundary. Possible impact: This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary.; CVSS 9.8 (CRITICAL); EPSS percentile 94; not listed in KEV; Remediation reference present; patch status requires confirmation in the linked advisory; sources: NVD, Vendor Advisory.", "public_safe_summary": "NVD: The custom GINA/CP module in Zoho ManageEngine ADSelfService Plus before 5.5 build 5517 allows remote attackers to execute code and escalate privileges via spoofing. NVD: It does not authenticate the intended server before opening a browser window. NVD: An unauthenticated attacker capable of conducting a spoofing attack can redirect the browser to gain execution in the context of the WinLogon.exe process.", "public_status": "public_safe", "published_at": null, "redaction_notes": ["source-published defensive context retained", "vulnerability class, impact, affected context, and remediation references remain displayable"], "remediation_handoff": {"auto_remediation_allowed": false, "codex_prompt_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2018-5353-codex-prompt.md", "external_execution_allowed": false, "human_approval_required": true, "json_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2018-5353.json", "markdown_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2018-5353.md", "scan_allowed": false}, "remediation_urls": ["http://zoho.com", "https://www.manageengine.com/products/self-service-password/release-notes.html"], "sort_priority": 98.94138, "source_copy_policy": {"allowed": "source-published defensive facts, vulnerability class, impact, affected context, version and remediation facts", "excluded": "exploit procedures, exploit strings, shell commands, scanner instructions, procedural bypass detail, and reproduction material", "summary": "Official or semi-official source descriptions may be summarized for defensive triage; exploit-enabling procedure is removed."}, "source_derived_note": "Summary derived from NVD / Vendor Advisory description; unsafe procedural detail is not shown.", "source_label": "NVD, Vendor Advisory", "source_published_affected": "vendor/product: zohocorp / manageengine_adselfservice_plus; affected version context: 5.5", "source_published_description": "NVD: The custom GINA/CP module in Zoho ManageEngine ADSelfService Plus before 5.5 build 5517 allows remote attackers to execute code and escalate privileges via spoofing. NVD: It does not authenticate the intended server before opening a browser window. NVD: An unauthenticated attacker capable of conducting a spoofing attack can redirect the browser to gain execution in the context of the WinLogon.exe process.", "source_published_evidence_refs": [{"source": "NVD", "type": "source_description", "url": null}, {"source": "Vendor Advisory", "type": "source_description", "url": null}, {"source": "Reference", "type": "reference", "url": "https://github.com/missing0x00/CVE-2018-5353"}, {"source": "Vendor Advisory", "type": "reference", "url": "https://www.manageengine.com/products/self-service-password/release-notes.html"}, {"source": "Vendor Advisory", "type": "reference", "url": "http://zoho.com"}, {"source": "Reference", "type": "reference", "url": "https://github.com/missing0x00/CVE-2018-5353"}, {"source": "Vendor Advisory", "type": "reference", "url": "https://www.manageengine.com/products/self-service-password/release-notes.html"}, {"source": "Official Reference", "type": "reference", "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-5353"}], "source_published_impact": "Source describes remote exposure · authenticated boundary. Possible impact: This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary.", "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.", "source_published_summary": "NVD: The custom GINA/CP module in Zoho ManageEngine ADSelfService Plus before 5.5 build 5517 allows remote attackers to execute code and escalate privileges via spoofing. NVD: It does not authenticate the intended server before opening a browser window. NVD: An unauthenticated attacker capable of conducting a spoofing attack can redirect the browser to gain execution in the context of the WinLogon.exe process.", "sources": ["NVD", "Vendor Advisory"], "summary": "CVE-2018-5353 is a defensive prioritization candidate. NVD lists CVSS severity as CRITICAL. CVSS score is 9.8. EPSS score is 0.0810 with percentile 0.9414. Known exploited catalog status is not listed in NVD for this record. Use official advisories and vendor remediation references for defensive review.", "summary_ja": null, "title": "CVE-2018-5353 defensive priority signal", "title_ja": null, "translation": null, "updated_at": null, "urgency_reasons": ["CVSS CRITICAL", "EPSS percentile high", "affected product present", "vendor advisory present", "recent update", "remediation reference present"], "vendor": "zohocorp", "what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "why_it_matters": "This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary; CVSS 9.8 (CRITICAL); EPSS percentile 94; affected product context: zohocorp /..."}, {"affected_label": "crmeb / crmeb", "affected_products": [{"canonicalProduct": "crmeb", "canonicalVendor": "crmeb", "cpe": "cpe:2.3:a:crmeb:crmeb:3.0:*:*:*:*:*:*:*", "ecosystem": null, "packageName": null, "product": "crmeb", "purl": null, "vendor": "crmeb", "version": "3.0"}], "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2020-25466/", "cvss_score": 9.8, "cvss_severity": "CRITICAL", "data_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2020-25466.json", "defensive_priority": "Priority review candidate", "epss_percentile": 0.85894, "epss_score": 0.03033, "exposure_hint": "exposure unknown", "human_consequence": "An attacker may be able to run code or commands on affected systems.", "human_impact_label": "code execution review", "human_risk_summary": "CVE-2020-25466 for crmeb / crmeb: An attacker may be able to run code or commands on affected systems.", "id": "CVE-2020-25466", "impact_tags": ["code execution review"], "kev": false, "observed_at": "2026-07-08T03:39:09.814067+00:00", "product": "crmeb", "public_human_impact": "Source describes code execution review. Possible impact: An attacker may be able to run code or commands on affected systems.", "public_human_summary": "NVD: A SSRF vulnerability exists in the downloadimage interface of CRMEB 3.0, which can remotely download arbitrary files on the server and remotely execute arbitrary code. OSV: A SSRF vulnerability exists in the downloadimage interface of CRMEB 3.0, which can remotely download arbitrary files on the server and remotely execute arbitrary code.", "public_human_what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "public_human_why_it_matters": "Source describes code execution review. Possible impact: An attacker may be able to run code or commands on affected systems.; CVSS 9.8 (CRITICAL); EPSS percentile 86; not listed in KEV; Remediation reference present; patch status requires confirmation in the linked advisory; sources: NVD, OSV, Vendor Advisory.", "public_safe_summary": "NVD: A SSRF vulnerability exists in the downloadimage interface of CRMEB 3.0, which can remotely download arbitrary files on the server and remotely execute arbitrary code. OSV: A SSRF vulnerability exists in the downloadimage interface of CRMEB 3.0, which can remotely download arbitrary files on the server and remotely execute arbitrary code.", "public_status": "public_safe", "published_at": null, "redaction_notes": ["source-published defensive context retained", "vulnerability class, impact, affected context, and remediation references remain displayable"], "remediation_handoff": {"auto_remediation_allowed": false, "codex_prompt_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-25466-codex-prompt.md", "external_execution_allowed": false, "human_approval_required": true, "json_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-25466.json", "markdown_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-25466.md", "scan_allowed": false}, "remediation_urls": ["http://crmeb.com"], "sort_priority": 98.85894, "source_copy_policy": {"allowed": "source-published defensive facts, vulnerability class, impact, affected context, version and remediation facts", "excluded": "exploit procedures, exploit strings, shell commands, scanner instructions, procedural bypass detail, and reproduction material", "summary": "Official or semi-official source descriptions may be summarized for defensive triage; exploit-enabling procedure is removed."}, "source_derived_note": "Summary derived from NVD / OSV / Vendor Advisory description; unsafe procedural detail is not shown.", "source_label": "NVD, OSV, Vendor Advisory", "source_published_affected": "vendor/product: crmeb / crmeb; affected version context: 3.0", "source_published_description": "NVD: A SSRF vulnerability exists in the downloadimage interface of CRMEB 3.0, which can remotely download arbitrary files on the server and remotely execute arbitrary code. OSV: A SSRF vulnerability exists in the downloadimage interface of CRMEB 3.0, which can remotely download arbitrary files on the server and remotely execute arbitrary code.", "source_published_evidence_refs": [{"source": "NVD", "type": "source_description", "url": null}, {"source": "OSV", "type": "source_description", "url": null}, {"source": "Vendor Advisory", "type": "source_description", "url": null}, {"source": "Reference", "type": "reference", "url": "https://github.com/crmeb/CRMEB"}, {"source": "Reference", "type": "reference", "url": "https://github.com/crmeb/CRMEB/issues/22"}, {"source": "Vendor Advisory", "type": "reference", "url": "http://crmeb.com"}, {"source": "Reference", "type": "reference", "url": "https://github.com/crmeb/CRMEB"}, {"source": "Reference", "type": "reference", "url": "https://github.com/crmeb/CRMEB/issues/22"}, {"source": "Official Reference", "type": "reference", "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-25466"}, {"source": "Official Reference", "type": "reference", "url": "https://osv.dev/vulnerability/CVE-2020-25466"}], "source_published_impact": "Source describes code execution review. Possible impact: An attacker may be able to run code or commands on affected systems.", "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.", "source_published_summary": "NVD: A SSRF vulnerability exists in the downloadimage interface of CRMEB 3.0, which can remotely download arbitrary files on the server and remotely execute arbitrary code. OSV: A SSRF vulnerability exists in the downloadimage interface of CRMEB 3.0, which can remotely download arbitrary files on the server and remotely execute arbitrary code.", "sources": ["NVD", "OSV", "Vendor Advisory"], "summary": "CVE-2020-25466 is a defensive prioritization candidate. NVD lists CVSS severity as CRITICAL. CVSS score is 9.8. EPSS score is 0.0303 with percentile 0.8589. Known exploited catalog status is not listed in NVD for this record. Use official advisories and vendor remediation references for defensive review.", "summary_ja": null, "title": "CVE-2020-25466 defensive priority signal", "title_ja": null, "translation": null, "updated_at": null, "urgency_reasons": ["CVSS CRITICAL", "affected product present", "vendor advisory present", "recent update", "remediation reference present"], "vendor": "crmeb", "what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "why_it_matters": "An attacker may be able to run code or commands on affected systems; CVSS 9.8 (CRITICAL); EPSS percentile 86; affected product context: crmeb / crmeb; sources: NVD, OSV, Vendor Advisory."}, {"affected_label": "daily_tracker_system_project / daily_tracker_system", "affected_products": [{"canonicalProduct": "daily_tracker_system", "canonicalVendor": "daily_tracker_system_project", "cpe": "cpe:2.3:a:daily_tracker_system_project:daily_tracker_system:1.0:*:*:*:*:*:*:*", "ecosystem": null, "packageName": null, "product": "daily_tracker_system", "purl": null, "vendor": "daily_tracker_system_project", "version": "1.0"}], "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2020-24193/", "cvss_score": 9.8, "cvss_severity": "CRITICAL", "data_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2020-24193.json", "defensive_priority": "Priority review candidate", "epss_percentile": 0.84557, "epss_score": 0.0277, "exposure_hint": "authenticated boundary", "human_consequence": "An attacker may be able to read or change database-backed application data.", "human_impact_label": "authentication boundary review · SQL injection risk · authenticated boundary", "human_risk_summary": "CVE-2020-24193 for daily_tracker_system_project / daily_tracker_system: An attacker may be able to read or change database-backed application data.", "id": "CVE-2020-24193", "impact_tags": ["authentication boundary review", "SQL injection risk", "authenticated boundary review"], "kev": false, "observed_at": "2026-07-08T03:39:09.814067+00:00", "product": "daily_tracker_system", "public_human_impact": "Source describes authentication boundary review · SQL injection risk · authenticated boundary. Possible impact: An attacker may be able to read or change database-backed application data.", "public_human_summary": "NVD: A SQL injection vulnerability in login in Sourcecodetester Daily Tracker System 1.0 allows unauthenticated user to execute authentication bypass with SQL injection via the email parameter.", "public_human_what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "public_human_why_it_matters": "Source describes authentication boundary review · SQL injection risk · authenticated boundary. Possible impact: An attacker may be able to read or change database-backed application data.; CVSS 9.8 (CRITICAL); EPSS percentile 85; not listed in KEV; Remediation reference present; patch status requires confirmation in the linked advisory; sources: NVD.", "public_safe_summary": "NVD: A SQL injection vulnerability in login in Sourcecodetester Daily Tracker System 1.0 allows unauthenticated user to execute authentication bypass with SQL injection via the email parameter.", "public_status": "public_safe", "published_at": null, "redaction_notes": ["source-published defensive context retained", "vulnerability class, impact, affected context, and remediation references remain displayable"], "remediation_handoff": {"auto_remediation_allowed": false, "codex_prompt_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-24193-codex-prompt.md", "external_execution_allowed": false, "human_approval_required": true, "json_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-24193.json", "markdown_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-24193.md", "scan_allowed": false}, "remediation_urls": ["https://nvd.nist.gov/vuln/detail/CVE-2020-24193"], "sort_priority": 98.84557, "source_copy_policy": {"allowed": "source-published defensive facts, vulnerability class, impact, affected context, version and remediation facts", "excluded": "exploit procedures, exploit strings, shell commands, scanner instructions, procedural bypass detail, and reproduction material", "summary": "Official or semi-official source descriptions may be summarized for defensive triage; exploit-enabling procedure is removed."}, "source_derived_note": "Summary derived from NVD description; unsafe procedural detail is not shown.", "source_label": "NVD, Vendor Advisory", "source_published_affected": "vendor/product: daily_tracker_system_project / daily_tracker_system; affected version context: 1.0", "source_published_description": "NVD: A SQL injection vulnerability in login in Sourcecodetester Daily Tracker System 1.0 allows unauthenticated user to execute authentication bypass with SQL injection via the email parameter.", "source_published_evidence_refs": [{"source": "NVD", "type": "source_description", "url": null}, {"source": "Reference", "type": "reference", "url": "https://www.exploit-db.com/exploits/48787"}, {"source": "Reference", "type": "reference", "url": "http://sourcecodetester.com"}, {"source": "Reference", "type": "reference", "url": "https://www.exploit-db.com/exploits/48787"}, {"source": "Official Reference", "type": "reference", "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-24193"}], "source_published_impact": "Source describes authentication boundary review · SQL injection risk · authenticated boundary. Possible impact: An attacker may be able to read or change database-backed application data.", "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.", "source_published_summary": "NVD: A SQL injection vulnerability in login in Sourcecodetester Daily Tracker System 1.0 allows unauthenticated user to execute authentication bypass with SQL injection via the email parameter.", "sources": ["NVD", "Vendor Advisory"], "summary": "CVE-2020-24193 is a defensive prioritization candidate. NVD lists CVSS severity as CRITICAL. CVSS score is 9.8. EPSS score is 0.0277 with percentile 0.8456. Known exploited catalog status is not listed in NVD for this record. Use official advisories and vendor remediation references for defensive review.", "summary_ja": null, "title": "CVE-2020-24193 defensive priority signal", "title_ja": null, "translation": null, "updated_at": null, "urgency_reasons": ["CVSS CRITICAL", "affected product present", "vendor advisory present", "recent update"], "vendor": "daily_tracker_system_project", "what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "why_it_matters": "An attacker may be able to read or change database-backed application data; CVSS 9.8 (CRITICAL); EPSS percentile 85; affected product context: daily_tracker_system_project / daily_tracker_system; sources: NVD."}, {"affected_label": "anixis / password_reset_client", "affected_products": [{"canonicalProduct": "password_reset_client", "canonicalVendor": "anixis", "cpe": "cpe:2.3:a:anixis:password_reset_client:*:*:*:*:*:*:*:*", "ecosystem": null, "packageName": null, "product": "password_reset_client", "purl": null, "vendor": "anixis", "version": null}], "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2018-5354/", "cvss_score": 8.8, "cvss_severity": "HIGH", "data_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2018-5354.json", "defensive_priority": "Continuous monitoring candidate", "epss_percentile": 0.83994, "epss_score": 0.02678, "exposure_hint": "remote exposure", "human_consequence": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary.", "human_impact_label": "remote exposure · authenticated boundary", "human_risk_summary": "CVE-2018-5354 for anixis / password_reset_client: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary.", "id": "CVE-2018-5354", "impact_tags": ["remote exposure relevant", "authenticated boundary review"], "kev": false, "observed_at": "2026-07-08T03:39:09.814067+00:00", "product": "password_reset_client", "public_human_impact": "Source describes remote exposure · authenticated boundary. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary.", "public_human_summary": "NVD: The custom GINA/CP module in ANIXIS Password Reset Client before version 3.22 allows remote attackers to execute code and escalate privileges via spoofing. NVD: When the client is configured to use HTTP, it does not authenticate the intended server before opening a browser window. NVD: An unauthenticated attacker capable of conducting a spoofing attack can redirect the browser to gain execution in the context of the WinLogon.exe process.", "public_human_what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "public_human_why_it_matters": "Source describes remote exposure · authenticated boundary. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary.; CVSS 8.8 (HIGH); EPSS percentile 84; not listed in KEV; Remediation reference present; patch status requires confirmation in the linked advisory; sources: NVD, Vendor Advisory.", "public_safe_summary": "NVD: The custom GINA/CP module in ANIXIS Password Reset Client before version 3.22 allows remote attackers to execute code and escalate privileges via spoofing. NVD: When the client is configured to use HTTP, it does not authenticate the intended server before opening a browser window. NVD: An unauthenticated attacker capable of conducting a spoofing attack can redirect the browser to gain execution in the context of the WinLogon.exe process.", "public_status": "public_safe", "published_at": null, "redaction_notes": ["source-published defensive context retained", "vulnerability class, impact, affected context, and remediation references remain displayable"], "remediation_handoff": {"auto_remediation_allowed": false, "codex_prompt_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2018-5354-codex-prompt.md", "external_execution_allowed": false, "human_approval_required": true, "json_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2018-5354.json", "markdown_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2018-5354.md", "scan_allowed": false}, "remediation_urls": ["http://anixis.com"], "sort_priority": 88.83994, "source_copy_policy": {"allowed": "source-published defensive facts, vulnerability class, impact, affected context, version and remediation facts", "excluded": "exploit procedures, exploit strings, shell commands, scanner instructions, procedural bypass detail, and reproduction material", "summary": "Official or semi-official source descriptions may be summarized for defensive triage; exploit-enabling procedure is removed."}, "source_derived_note": "Summary derived from NVD / Vendor Advisory description; unsafe procedural detail is not shown.", "source_label": "NVD, Vendor Advisory", "source_published_affected": "vendor/product: anixis / password_reset_client", "source_published_description": "NVD: The custom GINA/CP module in ANIXIS Password Reset Client before version 3.22 allows remote attackers to execute code and escalate privileges via spoofing. NVD: When the client is configured to use HTTP, it does not authenticate the intended server before opening a browser window. NVD: An unauthenticated attacker capable of conducting a spoofing attack can redirect the browser to gain execution in the context of the WinLogon.exe process.", "source_published_evidence_refs": [{"source": "NVD", "type": "source_description", "url": null}, {"source": "Vendor Advisory", "type": "source_description", "url": null}, {"source": "Reference", "type": "reference", "url": "https://github.com/missing0x00/CVE-2018-5354"}, {"source": "Vendor Advisory", "type": "reference", "url": "http://anixis.com"}, {"source": "Reference", "type": "reference", "url": "https://github.com/missing0x00/CVE-2018-5354"}, {"source": "Official Reference", "type": "reference", "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-5354"}], "source_published_impact": "Source describes remote exposure · authenticated boundary. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary.", "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.", "source_published_summary": "NVD: The custom GINA/CP module in ANIXIS Password Reset Client before version 3.22 allows remote attackers to execute code and escalate privileges via spoofing. NVD: When the client is configured to use HTTP, it does not authenticate the intended server before opening a browser window. NVD: An unauthenticated attacker capable of conducting a spoofing attack can redirect the browser to gain execution in the context of the WinLogon.exe process.", "sources": ["NVD", "Vendor Advisory"], "summary": "CVE-2018-5354 is a defensive prioritization candidate. NVD lists CVSS severity as HIGH. CVSS score is 8.8. EPSS score is 0.0268 with percentile 0.8399. Known exploited catalog status is not listed in NVD for this record. Use official advisories and vendor remediation references for defensive review.", "summary_ja": null, "title": "CVE-2018-5354 defensive priority signal", "title_ja": null, "translation": null, "updated_at": null, "urgency_reasons": ["CVSS HIGH", "affected product present", "vendor advisory present", "recent update", "remediation reference present"], "vendor": "anixis", "what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "why_it_matters": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary; CVSS 8.8 (HIGH); EPSS percentile 84; affected product context: anixis / password_reset_client; sources: NVD..."}, {"affected_label": "spiceworks / spiceworks", "affected_products": [{"canonicalProduct": "spiceworks", "canonicalVendor": "spiceworks", "cpe": "cpe:2.3:a:spiceworks:spiceworks:*:*:*:*:*:*:*:*", "ecosystem": null, "packageName": null, "product": "spiceworks", "purl": null, "vendor": "spiceworks", "version": null}], "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2020-23451/", "cvss_score": 8.8, "cvss_severity": "HIGH", "data_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2020-23451.json", "defensive_priority": "Continuous monitoring candidate", "epss_percentile": 0.44482, "epss_score": 0.00601, "exposure_hint": "exposure unknown", "human_consequence": "An attacker may cross a privilege boundary and gain more access than intended.", "human_impact_label": "privilege escalation risk", "human_risk_summary": "CVE-2020-23451 for spiceworks / spiceworks: An attacker may cross a privilege boundary and gain more access than intended.", "id": "CVE-2020-23451", "impact_tags": ["privilege boundary review"], "kev": false, "observed_at": "2026-07-08T03:39:09.814067+00:00", "product": "spiceworks", "public_human_impact": "Source describes privilege escalation risk. Possible impact: An attacker may cross a privilege boundary and gain more access than intended.", "public_human_summary": "NVD: Spiceworks Version <= 7.5.00107 is affected by CSRF which can lead to privilege escalation via \"/settings/v1/users\" function.", "public_human_what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "public_human_why_it_matters": "Source describes privilege escalation risk. Possible impact: An attacker may cross a privilege boundary and gain more access than intended.; CVSS 8.8 (HIGH); EPSS percentile 44; not listed in KEV; Remediation reference present; patch status requires confirmation in the linked advisory; sources: NVD.", "public_safe_summary": "NVD: Spiceworks Version <= 7.5.00107 is affected by CSRF which can lead to privilege escalation via \"/settings/v1/users\" function.", "public_status": "public_safe", "published_at": null, "redaction_notes": ["source-published defensive context retained", "vulnerability class, impact, affected context, and remediation references remain displayable"], "remediation_handoff": {"auto_remediation_allowed": false, "codex_prompt_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-23451-codex-prompt.md", "external_execution_allowed": false, "human_approval_required": true, "json_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-23451.json", "markdown_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-23451.md", "scan_allowed": false}, "remediation_urls": ["https://nvd.nist.gov/vuln/detail/CVE-2020-23451"], "sort_priority": 88.44481999999999, "source_copy_policy": {"allowed": "source-published defensive facts, vulnerability class, impact, affected context, version and remediation facts", "excluded": "exploit procedures, exploit strings, shell commands, scanner instructions, procedural bypass detail, and reproduction material", "summary": "Official or semi-official source descriptions may be summarized for defensive triage; exploit-enabling procedure is removed."}, "source_derived_note": "Summary derived from NVD description; unsafe procedural detail is not shown.", "source_label": "NVD, Vendor Advisory", "source_published_affected": "vendor/product: spiceworks / spiceworks", "source_published_description": "NVD: Spiceworks Version <= 7.5.00107 is affected by CSRF which can lead to privilege escalation via \"/settings/v1/users\" function.", "source_published_evidence_refs": [{"source": "NVD", "type": "source_description", "url": null}, {"source": "Reference", "type": "reference", "url": "https://abuyv.com/cve/spiceworks-csrf-via-xss"}, {"source": "Reference", "type": "reference", "url": "http://spiceworks.com"}, {"source": "Reference", "type": "reference", "url": "https://abuyv.com/cve/spiceworks-csrf-via-xss"}, {"source": "Official Reference", "type": "reference", "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-23451"}], "source_published_impact": "Source describes privilege escalation risk. Possible impact: An attacker may cross a privilege boundary and gain more access than intended.", "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.", "source_published_summary": "NVD: Spiceworks Version <= 7.5.00107 is affected by CSRF which can lead to privilege escalation via \"/settings/v1/users\" function.", "sources": ["NVD", "Vendor Advisory"], "summary": "CVE-2020-23451 is a defensive prioritization candidate. NVD lists CVSS severity as HIGH. CVSS score is 8.8. EPSS score is 0.0060 with percentile 0.4448. Known exploited catalog status is not listed in NVD for this record. Use official advisories and vendor remediation references for defensive review.", "summary_ja": null, "title": "CVE-2020-23451 defensive priority signal", "title_ja": null, "translation": null, "updated_at": null, "urgency_reasons": ["CVSS HIGH", "affected product present", "vendor advisory present", "recent update"], "vendor": "spiceworks", "what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "why_it_matters": "An attacker may cross a privilege boundary and gain more access than intended; CVSS 8.8 (HIGH); EPSS percentile 44; affected product context: spiceworks / spiceworks; sources: NVD."}, {"affected_label": "simple_library_management_system_project / simple_library_management_system", "affected_products": [{"canonicalProduct": "simple_library_management_system", "canonicalVendor": "simple_library_management_system_project", "cpe": "cpe:2.3:a:simple_library_management_system_project:simple_library_management_system:1.0:*:*:*:*:*:*:*", "ecosystem": null, "packageName": null, "product": "simple_library_management_system", "purl": null, "vendor": "simple_library_management_system_project", "version": "1.0"}], "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2020-25514/", "cvss_score": 8.4, "cvss_severity": "HIGH", "data_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2020-25514.json", "defensive_priority": "Continuous monitoring candidate", "epss_percentile": 0.45772, "epss_score": 0.00629, "exposure_hint": "exposure unknown", "human_consequence": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.", "human_impact_label": "high severity review", "human_risk_summary": "CVE-2020-25514 for simple_library_management_system_project / simple_library_management_system: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.", "id": "CVE-2020-25514", "impact_tags": [], "kev": false, "observed_at": "2026-07-08T03:39:09.814067+00:00", "product": "simple_library_management_system", "public_human_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.", "public_human_summary": "NVD: Sourcecodester Simple Library Management System 1.0 is affected by Incorrect Access Control via the Login Panel,", "public_human_what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "public_human_why_it_matters": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.; CVSS 8.4 (HIGH); EPSS percentile 46; not listed in KEV; Remediation reference present; patch status requires confirmation in the linked advisory; sources: NVD.", "public_safe_summary": "NVD: Sourcecodester Simple Library Management System 1.0 is affected by Incorrect Access Control via the Login Panel,", "public_status": "public_safe", "published_at": null, "redaction_notes": ["source-published defensive context retained", "vulnerability class, impact, affected context, and remediation references remain displayable"], "remediation_handoff": {"auto_remediation_allowed": false, "codex_prompt_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-25514-codex-prompt.md", "external_execution_allowed": false, "human_approval_required": true, "json_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-25514.json", "markdown_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-25514.md", "scan_allowed": false}, "remediation_urls": ["https://nvd.nist.gov/vuln/detail/CVE-2020-25514"], "sort_priority": 84.45772, "source_copy_policy": {"allowed": "source-published defensive facts, vulnerability class, impact, affected context, version and remediation facts", "excluded": "exploit procedures, exploit strings, shell commands, scanner instructions, procedural bypass detail, and reproduction material", "summary": "Official or semi-official source descriptions may be summarized for defensive triage; exploit-enabling procedure is removed."}, "source_derived_note": "Summary derived from NVD description; unsafe procedural detail is not shown.", "source_label": "NVD, Vendor Advisory", "source_published_affected": "vendor/product: simple_library_management_system_project / simple_library_management_system; affected version context: 1.0", "source_published_description": "NVD: Sourcecodester Simple Library Management System 1.0 is affected by Incorrect Access Control via the Login Panel,", "source_published_evidence_refs": [{"source": "NVD", "type": "source_description", "url": null}, {"source": "Reference", "type": "reference", "url": "https://github.com/Ko-kn3t/CVE-2020-25514"}, {"source": "Reference", "type": "reference", "url": "https://www.sourcecodester.com"}, {"source": "Reference", "type": "reference", "url": "http://simple.com"}, {"source": "Reference", "type": "reference", "url": "https://github.com/Ko-kn3t/CVE-2020-25514"}, {"source": "Reference", "type": "reference", "url": "https://www.sourcecodester.com"}, {"source": "Official Reference", "type": "reference", "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-25514"}], "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.", "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.", "source_published_summary": "NVD: Sourcecodester Simple Library Management System 1.0 is affected by Incorrect Access Control via the Login Panel,", "sources": ["NVD", "Vendor Advisory"], "summary": "CVE-2020-25514 is a defensive prioritization candidate. NVD lists CVSS severity as HIGH. CVSS score is 8.4. EPSS score is 0.0063 with percentile 0.4577. Known exploited catalog status is not listed in NVD for this record. Use official advisories and vendor remediation references for defensive review.", "summary_ja": null, "title": "CVE-2020-25514 defensive priority signal", "title_ja": null, "translation": null, "updated_at": null, "urgency_reasons": ["CVSS HIGH", "affected product present", "vendor advisory present", "recent update"], "vendor": "simple_library_management_system_project", "what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "why_it_matters": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review; CVSS 8.4 (HIGH); EPSS percentile 46; affected product context: simple_library_management_system_project /..."}, {"affected_label": "ilex / international_sign\\&go", "affected_products": [{"canonicalProduct": "international_sign\\&go", "canonicalVendor": "ilex", "cpe": "cpe:2.3:a:ilex:international_sign\\&go:7.1:*:*:*:*:*:*:*", "ecosystem": null, "packageName": null, "product": "international_sign\\&go", "purl": null, "vendor": "ilex", "version": "7.1"}], "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2020-23968/", "cvss_score": 7.8, "cvss_severity": "HIGH", "data_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2020-23968.json", "defensive_priority": "Continuous monitoring candidate", "epss_percentile": 0.55043, "epss_score": 0.00891, "exposure_hint": "exposure unknown", "human_consequence": "An attacker may cross a privilege boundary and gain more access than intended.", "human_impact_label": "privilege escalation risk", "human_risk_summary": "CVE-2020-23968 for ilex / international_sign\\&go: An attacker may cross a privilege boundary and gain more access than intended.", "id": "CVE-2020-23968", "impact_tags": ["privilege boundary review"], "kev": false, "observed_at": "2026-07-08T03:39:09.814067+00:00", "product": "international_sign\\&go", "public_human_impact": "Source describes privilege escalation risk. Possible impact: An attacker may cross a privilege boundary and gain more access than intended.", "public_human_summary": "NVD: Ilex International Sign&go Workstation Security Suite 7.1 allows elevation of privileges via a symlink attack on ProgramData\\Ilex\\S&G\\Logs\\000-sngWSService1.log.", "public_human_what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "public_human_why_it_matters": "Source describes privilege escalation risk. Possible impact: An attacker may cross a privilege boundary and gain more access than intended.; CVSS 7.8 (HIGH); EPSS percentile 55; not listed in KEV; Remediation reference present; patch status requires confirmation in the linked advisory; sources: NVD, Vendor Advisory.", "public_safe_summary": "NVD: Ilex International Sign&go Workstation Security Suite 7.1 allows elevation of privileges via a symlink attack on ProgramData\\Ilex\\S&G\\Logs\\000-sngWSService1.log.", "public_status": "public_safe", "published_at": null, "redaction_notes": ["source-published defensive context retained", "vulnerability class, impact, affected context, and remediation references remain displayable"], "remediation_handoff": {"auto_remediation_allowed": false, "codex_prompt_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-23968-codex-prompt.md", "external_execution_allowed": false, "human_approval_required": true, "json_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-23968.json", "markdown_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-23968.md", "scan_allowed": false}, "remediation_urls": ["http://ilex.com"], "sort_priority": 78.55043, "source_copy_policy": {"allowed": "source-published defensive facts, vulnerability class, impact, affected context, version and remediation facts", "excluded": "exploit procedures, exploit strings, shell commands, scanner instructions, procedural bypass detail, and reproduction material", "summary": "Official or semi-official source descriptions may be summarized for defensive triage; exploit-enabling procedure is removed."}, "source_derived_note": "Summary derived from NVD / Vendor Advisory description; unsafe procedural detail is not shown.", "source_label": "NVD, Vendor Advisory", "source_published_affected": "vendor/product: ilex / international_sign\\&go; affected version context: 7.1", "source_published_description": "NVD: Ilex International Sign&go Workstation Security Suite 7.1 allows elevation of privileges via a symlink attack on ProgramData\\Ilex\\S&G\\Logs\\000-sngWSService1.log.", "source_published_evidence_refs": [{"source": "NVD", "type": "source_description", "url": null}, {"source": "Vendor Advisory", "type": "source_description", "url": null}, {"source": "Reference", "type": "reference", "url": "https://ricardojba.github.io/CVE-Pending-ILEX-SignGo-EoP/"}, {"source": "Vendor Advisory", "type": "reference", "url": "http://ilex.com"}, {"source": "Reference", "type": "reference", "url": "http://signgo.com"}, {"source": "Reference", "type": "reference", "url": "https://ricardojba.github.io/CVE-Pending-ILEX-SignGo-EoP/"}, {"source": "Official Reference", "type": "reference", "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-23968"}], "source_published_impact": "Source describes privilege escalation risk. Possible impact: An attacker may cross a privilege boundary and gain more access than intended.", "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.", "source_published_summary": "NVD: Ilex International Sign&go Workstation Security Suite 7.1 allows elevation of privileges via a symlink attack on ProgramData\\Ilex\\S&G\\Logs\\000-sngWSService1.log.", "sources": ["NVD", "Vendor Advisory"], "summary": "CVE-2020-23968 is a defensive prioritization candidate. NVD lists CVSS severity as HIGH. CVSS score is 7.8. EPSS score is 0.0089 with percentile 0.5504. Known exploited catalog status is not listed in NVD for this record. Use official advisories and vendor remediation references for defensive review.", "summary_ja": null, "title": "CVE-2020-23968 defensive priority signal", "title_ja": null, "translation": null, "updated_at": null, "urgency_reasons": ["CVSS HIGH", "affected product present", "vendor advisory present", "recent update", "remediation reference present"], "vendor": "ilex", "what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "why_it_matters": "An attacker may cross a privilege boundary and gain more access than intended; CVSS 7.8 (HIGH); EPSS percentile 55; affected product context: ilex / international_sign\\&go; sources: NVD, Vendor Advisory."}, {"affected_label": "phpgurukul / zoo_management_system", "affected_products": [{"canonicalProduct": "zoo_management_system", "canonicalVendor": "phpgurukul", "cpe": "cpe:2.3:a:phpgurukul:zoo_management_system:1.0:*:*:*:*:*:*:*", "ecosystem": null, "packageName": null, "product": "zoo_management_system", "purl": null, "vendor": "phpgurukul", "version": "1.0"}], "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2020-25487/", "cvss_score": 7.8, "cvss_severity": "HIGH", "data_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2020-25487.json", "defensive_priority": "Continuous monitoring candidate", "epss_percentile": 0.42196, "epss_score": 0.00553, "exposure_hint": "exposure unknown", "human_consequence": "An attacker may be able to read or change database-backed application data.", "human_impact_label": "SQL injection risk", "human_risk_summary": "CVE-2020-25487 for phpgurukul / zoo_management_system: An attacker may be able to read or change database-backed application data.", "id": "CVE-2020-25487", "impact_tags": ["SQL injection risk"], "kev": false, "observed_at": "2026-07-08T03:39:09.814067+00:00", "product": "zoo_management_system", "public_human_impact": "Source describes SQL injection risk. Possible impact: An attacker may be able to read or change database-backed application data.", "public_human_summary": "NVD: PHPGURUKUL Zoo Management System Using PHP and MySQL version 1.0 is affected by: SQL Injection via zms/animal-detail.php.", "public_human_what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "public_human_why_it_matters": "Source describes SQL injection risk. Possible impact: An attacker may be able to read or change database-backed application data.; CVSS 7.8 (HIGH); EPSS percentile 42; not listed in KEV; Remediation reference present; patch status requires confirmation in the linked advisory; sources: NVD.", "public_safe_summary": "NVD: PHPGURUKUL Zoo Management System Using PHP and MySQL version 1.0 is affected by: SQL Injection via zms/animal-detail.php.", "public_status": "public_safe", "published_at": null, "redaction_notes": ["source-published defensive context retained", "vulnerability class, impact, affected context, and remediation references remain displayable"], "remediation_handoff": {"auto_remediation_allowed": false, "codex_prompt_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-25487-codex-prompt.md", "external_execution_allowed": false, "human_approval_required": true, "json_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-25487.json", "markdown_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-25487.md", "scan_allowed": false}, "remediation_urls": ["https://nvd.nist.gov/vuln/detail/CVE-2020-25487"], "sort_priority": 78.42196, "source_copy_policy": {"allowed": "source-published defensive facts, vulnerability class, impact, affected context, version and remediation facts", "excluded": "exploit procedures, exploit strings, shell commands, scanner instructions, procedural bypass detail, and reproduction material", "summary": "Official or semi-official source descriptions may be summarized for defensive triage; exploit-enabling procedure is removed."}, "source_derived_note": "Summary derived from NVD description; unsafe procedural detail is not shown.", "source_label": "NVD, Vendor Advisory", "source_published_affected": "vendor/product: phpgurukul / zoo_management_system; affected version context: 1.0", "source_published_description": "NVD: PHPGURUKUL Zoo Management System Using PHP and MySQL version 1.0 is affected by: SQL Injection via zms/animal-detail.php.", "source_published_evidence_refs": [{"source": "NVD", "type": "source_description", "url": null}, {"source": "Reference", "type": "reference", "url": "https://github.com/Ko-kn3t/CVE-2020-25487"}, {"source": "Reference", "type": "reference", "url": "https://phpgurukul.com/zoo-management-system-using-php-and-mysql/"}, {"source": "Reference", "type": "reference", "url": "http://phpgurukul.com"}, {"source": "Reference", "type": "reference", "url": "https://github.com/Ko-kn3t/CVE-2020-25487"}, {"source": "Reference", "type": "reference", "url": "https://phpgurukul.com/zoo-management-system-using-php-and-mysql/"}, {"source": "Official Reference", "type": "reference", "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-25487"}], "source_published_impact": "Source describes SQL injection risk. Possible impact: An attacker may be able to read or change database-backed application data.", "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.", "source_published_summary": "NVD: PHPGURUKUL Zoo Management System Using PHP and MySQL version 1.0 is affected by: SQL Injection via zms/animal-detail.php.", "sources": ["NVD", "Vendor Advisory"], "summary": "CVE-2020-25487 is a defensive prioritization candidate. NVD lists CVSS severity as HIGH. CVSS score is 7.8. EPSS score is 0.0055 with percentile 0.4220. Known exploited catalog status is not listed in NVD for this record. Use official advisories and vendor remediation references for defensive review.", "summary_ja": null, "title": "CVE-2020-25487 defensive priority signal", "title_ja": null, "translation": null, "updated_at": null, "urgency_reasons": ["CVSS HIGH", "affected product present", "vendor advisory present", "recent update"], "vendor": "phpgurukul", "what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "why_it_matters": "An attacker may be able to read or change database-backed application data; CVSS 7.8 (HIGH); EPSS percentile 42; affected product context: phpgurukul / zoo_management_system; sources: NVD."}, {"affected_label": "simple_library_management_system_project / simple_library_management_system", "affected_products": [{"canonicalProduct": "simple_library_management_system", "canonicalVendor": "simple_library_management_system_project", "cpe": "cpe:2.3:a:simple_library_management_system_project:simple_library_management_system:1.0:*:*:*:*:*:*:*", "ecosystem": null, "packageName": null, "product": "simple_library_management_system", "purl": null, "vendor": "simple_library_management_system_project", "version": "1.0"}], "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2020-25515/", "cvss_score": 7.8, "cvss_severity": "HIGH", "data_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2020-25515.json", "defensive_priority": "Continuous monitoring candidate", "epss_percentile": 0.41554, "epss_score": 0.00541, "exposure_hint": "exposure unknown", "human_consequence": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.", "human_impact_label": "high severity review", "human_risk_summary": "CVE-2020-25515 for simple_library_management_system_project / simple_library_management_system: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.", "id": "CVE-2020-25515", "impact_tags": [], "kev": false, "observed_at": "2026-07-08T03:39:09.814067+00:00", "product": "simple_library_management_system", "public_human_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.", "public_human_summary": "NVD: Sourcecodester Simple Library Management System 1.0 is affected by Insecure Permissions via Books > New Book ,", "public_human_what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "public_human_why_it_matters": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.; CVSS 7.8 (HIGH); EPSS percentile 42; not listed in KEV; Remediation reference present; patch status requires confirmation in the linked advisory; sources: NVD.", "public_safe_summary": "NVD: Sourcecodester Simple Library Management System 1.0 is affected by Insecure Permissions via Books > New Book ,", "public_status": "public_safe", "published_at": null, "redaction_notes": ["source-published defensive context retained", "vulnerability class, impact, affected context, and remediation references remain displayable"], "remediation_handoff": {"auto_remediation_allowed": false, "codex_prompt_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-25515-codex-prompt.md", "external_execution_allowed": false, "human_approval_required": true, "json_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-25515.json", "markdown_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-25515.md", "scan_allowed": false}, "remediation_urls": ["https://nvd.nist.gov/vuln/detail/CVE-2020-25515"], "sort_priority": 78.41554, "source_copy_policy": {"allowed": "source-published defensive facts, vulnerability class, impact, affected context, version and remediation facts", "excluded": "exploit procedures, exploit strings, shell commands, scanner instructions, procedural bypass detail, and reproduction material", "summary": "Official or semi-official source descriptions may be summarized for defensive triage; exploit-enabling procedure is removed."}, "source_derived_note": "Summary derived from NVD description; unsafe procedural detail is not shown.", "source_label": "NVD, Vendor Advisory", "source_published_affected": "vendor/product: simple_library_management_system_project / simple_library_management_system; affected version context: 1.0", "source_published_description": "NVD: Sourcecodester Simple Library Management System 1.0 is affected by Insecure Permissions via Books > New Book ,", "source_published_evidence_refs": [{"source": "NVD", "type": "source_description", "url": null}, {"source": "Reference", "type": "reference", "url": "https://github.com/Ko-kn3t/CVE-2020-25515"}, {"source": "Reference", "type": "reference", "url": "https://www.sourcecodester.com"}, {"source": "Reference", "type": "reference", "url": "http://simple.com"}, {"source": "Reference", "type": "reference", "url": "https://github.com/Ko-kn3t/CVE-2020-25515"}, {"source": "Reference", "type": "reference", "url": "https://www.sourcecodester.com"}, {"source": "Official Reference", "type": "reference", "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-25515"}], "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.", "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.", "source_published_summary": "NVD: Sourcecodester Simple Library Management System 1.0 is affected by Insecure Permissions via Books > New Book ,", "sources": ["NVD", "Vendor Advisory"], "summary": "CVE-2020-25515 is a defensive prioritization candidate. NVD lists CVSS severity as HIGH. CVSS score is 7.8. EPSS score is 0.0054 with percentile 0.4155. Known exploited catalog status is not listed in NVD for this record. Use official advisories and vendor remediation references for defensive review.", "summary_ja": null, "title": "CVE-2020-25515 defensive priority signal", "title_ja": null, "translation": null, "updated_at": null, "urgency_reasons": ["CVSS HIGH", "affected product present", "vendor advisory present", "recent update"], "vendor": "simple_library_management_system_project", "what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "why_it_matters": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review; CVSS 7.8 (HIGH); EPSS percentile 42; affected product context: simple_library_management_system_project /..."}, {"affected_label": "debian / debian_linux", "affected_products": [{"canonicalProduct": "debian_linux", "canonicalVendor": "debian", "cpe": "cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*", "ecosystem": null, "packageName": null, "product": "debian_linux", "purl": null, "vendor": "debian", "version": "8.0"}, {"canonicalProduct": "debian_linux", "canonicalVendor": "debian", "cpe": "cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*", "ecosystem": null, "packageName": null, "product": "debian_linux", "purl": null, "vendor": "debian", "version": "9.0"}, {"canonicalProduct": "ubuntu_linux", "canonicalVendor": "canonical", "cpe": "cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:esm:*:*:*", "ecosystem": null, "packageName": null, "product": "ubuntu_linux", "purl": null, "vendor": "canonical", "version": "12.04"}, {"canonicalProduct": "ubuntu_linux", "canonicalVendor": "canonical", "cpe": "cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*", "ecosystem": null, "packageName": null, "product": "ubuntu_linux", "purl": null, "vendor": "canonical", "version": "14.04"}, {"canonicalProduct": "ubuntu_linux", "canonicalVendor": "canonical", "cpe": "cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*", "ecosystem": null, "packageName": null, "product": "ubuntu_linux", "purl": null, "vendor": "canonical", "version": "16.04"}, {"canonicalProduct": "ubuntu_linux", "canonicalVendor": "canonical", "cpe": "cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*", "ecosystem": null, "packageName": null, "product": "ubuntu_linux", "purl": null, "vendor": "canonical", "version": "18.04"}, {"canonicalProduct": "linux_kernel", "canonicalVendor": "linux", "cpe": "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*", "ecosystem": null, "packageName": null, "product": "linux_kernel", "purl": null, "vendor": "linux", "version": "-"}, {"canonicalProduct": "enterprise_linux_desktop", "canonicalVendor": "redhat", "cpe": "cpe:2.3:o:redhat:enterprise_linux_desktop:6.0:*:*:*:*:*:*:*", "ecosystem": null, "packageName": null, "product": "enterprise_linux_desktop", "purl": null, "vendor": "redhat", "version": "6.0"}, {"canonicalProduct": "enterprise_linux_desktop", "canonicalVendor": "redhat", "cpe": "cpe:2.3:o:redhat:enterprise_linux_desktop:7.0:*:*:*:*:*:*:*", "ecosystem": null, "packageName": null, "product": "enterprise_linux_desktop", "purl": null, "vendor": "redhat", "version": "7.0"}, {"canonicalProduct": "enterprise_linux_server", "canonicalVendor": "redhat", "cpe": "cpe:2.3:o:redhat:enterprise_linux_server:6.0:*:*:*:*:*:*:*", "ecosystem": null, "packageName": null, "product": "enterprise_linux_server", "purl": null, "vendor": "redhat", "version": "6.0"}, {"canonicalProduct": "enterprise_linux_server", "canonicalVendor": "redhat", "cpe": "cpe:2.3:o:redhat:enterprise_linux_server:7.0:*:*:*:*:*:*:*", "ecosystem": null, "packageName": null, "product": "enterprise_linux_server", "purl": null, "vendor": "redhat", "version": "7.0"}, {"canonicalProduct": "enterprise_linux_workstation", "canonicalVendor": "redhat", "cpe": "cpe:2.3:o:redhat:enterprise_linux_workstation:6.0:*:*:*:*:*:*:*", "ecosystem": null, "packageName": null, "product": "enterprise_linux_workstation", "purl": null, "vendor": "redhat", "version": "6.0"}, {"canonicalProduct": "enterprise_linux_workstation", "canonicalVendor": "redhat", "cpe": "cpe:2.3:o:redhat:enterprise_linux_workstation:7.0:*:*:*:*:*:*:*", "ecosystem": null, "packageName": null, "product": "enterprise_linux_workstation", "purl": null, "vendor": "redhat", "version": "7.0"}], "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2018-10902/", "cvss_score": 7.8, "cvss_severity": "HIGH", "data_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2018-10902.json", "defensive_priority": "Continuous monitoring candidate", "epss_percentile": 0.40562, "epss_score": 0.00523, "exposure_hint": "local exposure", "human_consequence": "A local user may cross a privilege boundary and gain more access than intended.", "human_impact_label": "privilege escalation risk · local exposure", "human_risk_summary": "CVE-2018-10902 for debian / debian_linux: A local user may cross a privilege boundary and gain more access than intended.", "id": "CVE-2018-10902", "impact_tags": ["privilege boundary review", "local exposure relevant"], "kev": false, "observed_at": "2026-07-08T03:39:09.814067+00:00", "product": "debian_linux", "public_human_impact": "Source describes privilege escalation risk · local exposure. Possible impact: A local user may cross a privilege boundary and gain more access than intended.", "public_human_summary": "NVD: It was found that the raw midi kernel driver does not protect against concurrent access which leads to a double realloc (double free) in snd_rawmidi_input_params() and snd_rawmidi_output_status() which are part of snd_rawmidi_ioctl() handler in rawmidi.c file. NVD: A malicious local attacker could possibly use this for privilege escalation. OSV: It was found that the raw midi kernel driver does not protect against concurrent access which leads to a double realloc (double free) in snd_rawmidi_input_params() and snd_rawmidi_output_status() which are part of snd_rawmidi_ioctl() handler in rawmidi.c file.", "public_human_what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "public_human_why_it_matters": "Source describes privilege escalation risk · local exposure. Possible impact: A local user may cross a privilege boundary and gain more access than intended.; CVSS 7.8 (HIGH); EPSS percentile 41; not listed in KEV; Remediation reference present; patch status requires confirmation in the linked advisory; sources: NVD, OSV, Vendor Advisory.", "public_safe_summary": "NVD: It was found that the raw midi kernel driver does not protect against concurrent access which leads to a double realloc (double free) in snd_rawmidi_input_params() and snd_rawmidi_output_status() which are part of snd_rawmidi_ioctl() handler in rawmidi.c file. NVD: A malicious local attacker could possibly use this for privilege escalation. OSV: It was found that the raw midi kernel driver does not protect against concurrent access which leads to a double realloc (double free) in snd_rawmidi_input_params() and snd_rawmidi_output_status() which are part of snd_rawmidi_ioctl() handler in rawmidi.c file.", "public_status": "public_safe", "published_at": null, "redaction_notes": ["source-published defensive context retained", "vulnerability class, impact, affected context, and remediation references remain displayable"], "remediation_handoff": {"auto_remediation_allowed": false, "codex_prompt_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2018-10902-codex-prompt.md", "external_execution_allowed": false, "human_approval_required": true, "json_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2018-10902.json", "markdown_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2018-10902.md", "scan_allowed": false}, "remediation_urls": ["http://www.securityfocus.com/bid/105119", "http://www.securitytracker.com/id/1041529", "https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-10902", "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=39675f7a7c7e7702f7d5341f1e0d01db746543a0", "https://www.debian.org/security/2018/dsa-4308"], "sort_priority": 78.40562, "source_copy_policy": {"allowed": "source-published defensive facts, vulnerability class, impact, affected context, version and remediation facts", "excluded": "exploit procedures, exploit strings, shell commands, scanner instructions, procedural bypass detail, and reproduction material", "summary": "Official or semi-official source descriptions may be summarized for defensive triage; exploit-enabling procedure is removed."}, "source_derived_note": "Summary derived from NVD / OSV / Vendor Advisory description; unsafe procedural detail is not shown.", "source_label": "NVD, OSV, Vendor Advisory", "source_published_affected": "vendor/product: debian / debian_linux; affected version context: -, 12.04, 14.04, 16.04, 18.04", "source_published_description": "NVD: It was found that the raw midi kernel driver does not protect against concurrent access which leads to a double realloc (double free) in snd_rawmidi_input_params() and snd_rawmidi_output_status() which are part of snd_rawmidi_ioctl() handler in rawmidi.c file. NVD: A malicious local attacker could possibly use this for privilege escalation. OSV: It was found that the raw midi kernel driver does not protect against concurrent access which leads to a double realloc (double free) in snd_rawmidi_input_params() and snd_rawmidi_output_status() which are part of snd_rawmidi_ioctl() handler in rawmidi.c file.", "source_published_evidence_refs": [{"source": "NVD", "type": "source_description", "url": null}, {"source": "OSV", "type": "source_description", "url": null}, {"source": "Vendor Advisory", "type": "source_description", "url": null}, {"source": "Reference", "type": "reference", "url": "http://www.securityfocus.com/bid/105119"}, {"source": "Vendor Advisory", "type": "reference", "url": "http://www.securitytracker.com/id/1041529"}, {"source": "Reference", "type": "reference", "url": "https://access.redhat.com/errata/RHSA-2018:3083"}, {"source": "Reference", "type": "reference", "url": "https://access.redhat.com/errata/RHSA-2018:3096"}, {"source": "Reference", "type": "reference", "url": "https://access.redhat.com/errata/RHSA-2019:0415"}, {"source": "Reference", "type": "reference", "url": "https://access.redhat.com/errata/RHSA-2019:0641"}, {"source": "Reference", "type": "reference", "url": "https://access.redhat.com/errata/RHSA-2019:3217"}], "source_published_impact": "Source describes privilege escalation risk · local exposure. Possible impact: A local user may cross a privilege boundary and gain more access than intended.", "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.", "source_published_summary": "NVD: It was found that the raw midi kernel driver does not protect against concurrent access which leads to a double realloc (double free) in snd_rawmidi_input_params() and snd_rawmidi_output_status() which are part of snd_rawmidi_ioctl() handler in rawmidi.c file. NVD: A malicious local attacker could possibly use this for privilege escalation. OSV: It was found that the raw midi kernel driver does not protect against concurrent access which leads to a double realloc (double free) in snd_rawmidi_input_params() and snd_rawmidi_output_status() which are part of snd_rawmidi_ioctl() handler in rawmidi.c file.", "sources": ["NVD", "OSV", "Vendor Advisory"], "summary": "CVE-2018-10902 is a defensive prioritization candidate. NVD lists CVSS severity as HIGH. CVSS score is 7.8. EPSS score is 0.0052 with percentile 0.4056. Known exploited catalog status is not listed in NVD for this record. Use official advisories and vendor remediation references for defensive review.", "summary_ja": null, "title": "CVE-2018-10902 defensive priority signal", "title_ja": null, "translation": null, "updated_at": null, "urgency_reasons": ["CVSS HIGH", "affected product present", "vendor advisory present", "recent update", "remediation reference present"], "vendor": "debian", "what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "why_it_matters": "A local user may cross a privilege boundary and gain more access than intended; CVSS 7.8 (HIGH); EPSS percentile 41; affected product context: debian / debian_linux; sources: NVD, OSV, Vendor Advisory."}, {"affected_label": "snap7_project / snap7", "affected_products": [{"canonicalProduct": "snap7", "canonicalVendor": "snap7_project", "cpe": "cpe:2.3:a:snap7_project:snap7:1.4.1:*:*:*:*:*:*:*", "ecosystem": null, "packageName": null, "product": "snap7", "purl": null, "vendor": "snap7_project", "version": "1.4.1"}], "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2020-22552/", "cvss_score": 7.5, "cvss_severity": "HIGH", "data_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2020-22552.json", "defensive_priority": "Continuous monitoring candidate", "epss_percentile": 0.78525, "epss_score": 0.02011, "exposure_hint": "exposure unknown", "human_consequence": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.", "human_impact_label": "high severity review", "human_risk_summary": "CVE-2020-22552 for snap7_project / snap7: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.", "id": "CVE-2020-22552", "impact_tags": [], "kev": false, "observed_at": "2026-07-08T03:39:09.814067+00:00", "product": "snap7", "public_human_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.", "public_human_summary": "NVD: The Snap7 server component in version 1.4.1, when an attacker sends a crafted packet with COTP protocol the last-data-unit flag set to No and S7 writes a var function, the Snap7 server will be crashed.", "public_human_what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "public_human_why_it_matters": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.; CVSS 7.5 (HIGH); EPSS percentile 79; not listed in KEV; Remediation reference present; patch status requires confirmation in the linked advisory; sources: NVD.", "public_safe_summary": "NVD: The Snap7 server component in version 1.4.1, when an attacker sends a crafted packet with COTP protocol the last-data-unit flag set to No and S7 writes a var function, the Snap7 server will be crashed.", "public_status": "public_safe", "published_at": null, "redaction_notes": ["source-published defensive context retained", "vulnerability class, impact, affected context, and remediation references remain displayable"], "remediation_handoff": {"auto_remediation_allowed": false, "codex_prompt_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-22552-codex-prompt.md", "external_execution_allowed": false, "human_approval_required": true, "json_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-22552.json", "markdown_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-22552.md", "scan_allowed": false}, "remediation_urls": ["https://nvd.nist.gov/vuln/detail/CVE-2020-22552"], "sort_priority": 75.78525, "source_copy_policy": {"allowed": "source-published defensive facts, vulnerability class, impact, affected context, version and remediation facts", "excluded": "exploit procedures, exploit strings, shell commands, scanner instructions, procedural bypass detail, and reproduction material", "summary": "Official or semi-official source descriptions may be summarized for defensive triage; exploit-enabling procedure is removed."}, "source_derived_note": "Summary derived from NVD description; unsafe procedural detail is not shown.", "source_label": "NVD, Vendor Advisory", "source_published_affected": "vendor/product: snap7_project / snap7; affected version context: 1.4.1", "source_published_description": "NVD: The Snap7 server component in version 1.4.1, when an attacker sends a crafted packet with COTP protocol the last-data-unit flag set to No and S7 writes a var function, the Snap7 server will be crashed.", "source_published_evidence_refs": [{"source": "NVD", "type": "source_description", "url": null}, {"source": "Reference", "type": "reference", "url": "https://sourceforge.net/p/snap7/discussion/bugfix/thread/456d76fdde/"}, {"source": "Reference", "type": "reference", "url": "https://sourceforge.net/projects/snap7/"}, {"source": "Reference", "type": "reference", "url": "http://snap7.com"}, {"source": "Reference", "type": "reference", "url": "https://sourceforge.net/p/snap7/discussion/bugfix/thread/456d76fdde/"}, {"source": "Reference", "type": "reference", "url": "https://sourceforge.net/projects/snap7/"}, {"source": "Official Reference", "type": "reference", "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-22552"}], "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.", "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.", "source_published_summary": "NVD: The Snap7 server component in version 1.4.1, when an attacker sends a crafted packet with COTP protocol the last-data-unit flag set to No and S7 writes a var function, the Snap7 server will be crashed.", "sources": ["NVD", "Vendor Advisory"], "summary": "CVE-2020-22552 is a defensive prioritization candidate. NVD lists CVSS severity as HIGH. CVSS score is 7.5. EPSS score is 0.0201 with percentile 0.7853. Known exploited catalog status is not listed in NVD for this record. Use official advisories and vendor remediation references for defensive review.", "summary_ja": null, "title": "CVE-2020-22552 defensive priority signal", "title_ja": null, "translation": null, "updated_at": null, "urgency_reasons": ["CVSS HIGH", "affected product present", "vendor advisory present", "recent update"], "vendor": "snap7_project", "what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "why_it_matters": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review; CVSS 7.5 (HIGH); EPSS percentile 79; affected product context: snap7_project / snap7; sources: NVD."}, {"affected_label": "sagemcom / f\\@st_3686_firmware", "affected_products": [{"canonicalProduct": "f\\@st_3686_firmware", "canonicalVendor": "sagemcom", "cpe": "cpe:2.3:o:sagemcom:f\\@st_3686_firmware:1.0_hun_3.97.0:*:*:*:*:*:*:*", "ecosystem": null, "packageName": null, "product": "f\\@st_3686_firmware", "purl": null, "vendor": "sagemcom", "version": "1.0_hun_3.97.0"}, {"canonicalProduct": "f\\@st_3686", "canonicalVendor": "sagemcom", "cpe": "cpe:2.3:h:sagemcom:f\\@st_3686:-:*:*:*:*:*:*:*", "ecosystem": null, "packageName": null, "product": "f\\@st_3686", "purl": null, "vendor": "sagemcom", "version": "-"}], "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2020-21733/", "cvss_score": 6.1, "cvss_severity": "MEDIUM", "data_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2020-21733.json", "defensive_priority": "Continuous monitoring candidate", "epss_percentile": 0.58423, "epss_score": 0.00995, "exposure_hint": "exposure unknown", "human_consequence": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk.", "human_impact_label": "XSS risk", "human_risk_summary": "CVE-2020-21733 for sagemcom / f\\@st_3686_firmware: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk.", "id": "CVE-2020-21733", "impact_tags": ["XSS risk"], "kev": false, "observed_at": "2026-07-08T03:39:09.814067+00:00", "product": "f\\@st_3686_firmware", "public_human_impact": "Source describes XSS risk. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk.", "public_human_summary": "NVD: Sagemcom F@ST3686 v1.0 HUN 3.97.0 has XSS via RgDiagnostics.asp, RgDdns.asp, RgFirewallEL.asp, RgVpnL2tpPptp.asp.", "public_human_what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "public_human_why_it_matters": "Source describes XSS risk. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk.; CVSS 6.1 (MEDIUM); EPSS percentile 58; not listed in KEV; Remediation reference present; patch status requires confirmation in the linked advisory; sources: NVD, Vendor Advisory.", "public_safe_summary": "NVD: Sagemcom F@ST3686 v1.0 HUN 3.97.0 has XSS via RgDiagnostics.asp, RgDdns.asp, RgFirewallEL.asp, RgVpnL2tpPptp.asp.", "public_status": "public_safe", "published_at": null, "redaction_notes": ["source-published defensive context retained", "vulnerability class, impact, affected context, and remediation references remain displayable"], "remediation_handoff": {"auto_remediation_allowed": false, "codex_prompt_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-21733-codex-prompt.md", "external_execution_allowed": false, "human_approval_required": true, "json_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-21733.json", "markdown_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-21733.md", "scan_allowed": false}, "remediation_urls": ["http://sagemcom.com"], "sort_priority": 61.58423, "source_copy_policy": {"allowed": "source-published defensive facts, vulnerability class, impact, affected context, version and remediation facts", "excluded": "exploit procedures, exploit strings, shell commands, scanner instructions, procedural bypass detail, and reproduction material", "summary": "Official or semi-official source descriptions may be summarized for defensive triage; exploit-enabling procedure is removed."}, "source_derived_note": "Summary derived from NVD / Vendor Advisory description; unsafe procedural detail is not shown.", "source_label": "NVD, Vendor Advisory", "source_published_affected": "vendor/product: sagemcom / f\\@st_3686_firmware; affected version context: -, 1.0_hun_3.97.0", "source_published_description": "NVD: Sagemcom F@ST3686 v1.0 HUN 3.97.0 has XSS via RgDiagnostics.asp, RgDdns.asp, RgFirewallEL.asp, RgVpnL2tpPptp.asp.", "source_published_evidence_refs": [{"source": "NVD", "type": "source_description", "url": null}, {"source": "Vendor Advisory", "type": "source_description", "url": null}, {"source": "Reference", "type": "reference", "url": "https://github.com/Gr3gPr1est/BugReport/blob/master/CVE-2020-21733"}, {"source": "Reference", "type": "reference", "url": "https://github.com/Gr3gPr1est/BugReport/blob/master/SAGEM_F%40ST3686_v1.0_HUN_3.97.0_XSS_Vuln..pdf"}, {"source": "Vendor Advisory", "type": "reference", "url": "http://sagemcom.com"}, {"source": "Reference", "type": "reference", "url": "http://sagemcomfst3686v10hun3970.com"}, {"source": "Reference", "type": "reference", "url": "https://github.com/Gr3gPr1est/BugReport/blob/master/CVE-2020-21733"}, {"source": "Reference", "type": "reference", "url": "https://github.com/Gr3gPr1est/BugReport/blob/master/SAGEM_F%40ST3686_v1.0_HUN_3.97.0_XSS_Vuln..pdf"}, {"source": "Official Reference", "type": "reference", "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-21733"}], "source_published_impact": "Source describes XSS risk. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk.", "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.", "source_published_summary": "NVD: Sagemcom F@ST3686 v1.0 HUN 3.97.0 has XSS via RgDiagnostics.asp, RgDdns.asp, RgFirewallEL.asp, RgVpnL2tpPptp.asp.", "sources": ["NVD", "Vendor Advisory"], "summary": "CVE-2020-21733 is a defensive prioritization candidate. NVD lists CVSS severity as MEDIUM. CVSS score is 6.1. EPSS score is 0.0100 with percentile 0.5842. Known exploited catalog status is not listed in NVD for this record. Use official advisories and vendor remediation references for defensive review.", "summary_ja": null, "title": "CVE-2020-21733 defensive priority signal", "title_ja": null, "translation": null, "updated_at": null, "urgency_reasons": ["affected product present", "vendor advisory present", "recent update", "remediation reference present"], "vendor": "sagemcom", "what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "why_it_matters": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk; CVSS 6.1 (MEDIUM); EPSS percentile 58; affected product context: sagemcom / f\\@st_3686_firmware; sources: NVD, Vendor Advisory."}, {"affected_label": "gazie_project / gazie", "affected_products": [{"canonicalProduct": "gazie", "canonicalVendor": "gazie_project", "cpe": "cpe:2.3:a:gazie_project:gazie:7.29:*:*:*:*:*:*:*", "ecosystem": null, "packageName": null, "product": "gazie", "purl": null, "vendor": "gazie_project", "version": "7.29"}], "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2020-21731/", "cvss_score": 6.1, "cvss_severity": "MEDIUM", "data_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2020-21731.json", "defensive_priority": "Continuous monitoring candidate", "epss_percentile": 0.54231, "epss_score": 0.00864, "exposure_hint": "exposure unknown", "human_consequence": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.", "human_impact_label": "defensive exposure review", "human_risk_summary": "CVE-2020-21731 for gazie_project / gazie: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.", "id": "CVE-2020-21731", "impact_tags": [], "kev": false, "observed_at": "2026-07-08T03:39:09.814067+00:00", "product": "gazie", "public_human_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.", "public_human_summary": "NVD: Gazie 7.29 is affected by: Cross Site Scripting (XSS) via An attacker can inject JavaScript code, and the webapplication stores the injected code.", "public_human_what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "public_human_why_it_matters": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.; CVSS 6.1 (MEDIUM); EPSS percentile 54; not listed in KEV; Remediation reference present; patch status requires confirmation in the linked advisory; sources: NVD, Vendor Advisory.", "public_safe_summary": "NVD: Gazie 7.29 is affected by: Cross Site Scripting (XSS) via An attacker can inject JavaScript code, and the webapplication stores the injected code.", "public_status": "public_safe", "published_at": null, "redaction_notes": ["source-published defensive context retained", "vulnerability class, impact, affected context, and remediation references remain displayable"], "remediation_handoff": {"auto_remediation_allowed": false, "codex_prompt_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-21731-codex-prompt.md", "external_execution_allowed": false, "human_approval_required": true, "json_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-21731.json", "markdown_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-21731.md", "scan_allowed": false}, "remediation_urls": ["http://gazie.devincentiis.it/"], "sort_priority": 61.54231, "source_copy_policy": {"allowed": "source-published defensive facts, vulnerability class, impact, affected context, version and remediation facts", "excluded": "exploit procedures, exploit strings, shell commands, scanner instructions, procedural bypass detail, and reproduction material", "summary": "Official or semi-official source descriptions may be summarized for defensive triage; exploit-enabling procedure is removed."}, "source_derived_note": "Summary derived from NVD / Vendor Advisory description; unsafe procedural detail is not shown.", "source_label": "NVD, Vendor Advisory", "source_published_affected": "vendor/product: gazie_project / gazie; affected version context: 7.29", "source_published_description": "NVD: Gazie 7.29 is affected by: Cross Site Scripting (XSS) via An attacker can inject JavaScript code, and the webapplication stores the injected code.", "source_published_evidence_refs": [{"source": "NVD", "type": "source_description", "url": null}, {"source": "Vendor Advisory", "type": "source_description", "url": null}, {"source": "Vendor Advisory", "type": "reference", "url": "http://gazie.devincentiis.it/"}, {"source": "Reference", "type": "reference", "url": "https://github.com/Gr3gPr1est/BugReport/blob/master/CVE-2020-21731"}, {"source": "Reference", "type": "reference", "url": "http://gazie.com"}, {"source": "Vendor Advisory", "type": "reference", "url": "http://gazie.devincentiis.it/"}, {"source": "Reference", "type": "reference", "url": "https://github.com/Gr3gPr1est/BugReport/blob/master/CVE-2020-21731"}, {"source": "Official Reference", "type": "reference", "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-21731"}], "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.", "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.", "source_published_summary": "NVD: Gazie 7.29 is affected by: Cross Site Scripting (XSS) via An attacker can inject JavaScript code, and the webapplication stores the injected code.", "sources": ["NVD", "Vendor Advisory"], "summary": "CVE-2020-21731 is a defensive prioritization candidate. NVD lists CVSS severity as MEDIUM. CVSS score is 6.1. EPSS score is 0.0086 with percentile 0.5423. Known exploited catalog status is not listed in NVD for this record. Use official advisories and vendor remediation references for defensive review.", "summary_ja": null, "title": "CVE-2020-21731 defensive priority signal", "title_ja": null, "translation": null, "updated_at": null, "urgency_reasons": ["affected product present", "vendor advisory present", "recent update", "remediation reference present"], "vendor": "gazie_project", "what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "why_it_matters": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review; CVSS 6.1 (MEDIUM); EPSS percentile 54; affected product context: gazie_project / gazie; sources: NVD, Vendor Advisory."}, {"affected_label": "rukovoditel / rukovoditel", "affected_products": [{"canonicalProduct": "rukovoditel", "canonicalVendor": "rukovoditel", "cpe": "cpe:2.3:a:rukovoditel:rukovoditel:2.6:*:*:*:*:*:*:*", "ecosystem": null, "packageName": null, "product": "rukovoditel", "purl": null, "vendor": "rukovoditel", "version": "2.6"}], "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2020-21732/", "cvss_score": 6.1, "cvss_severity": "MEDIUM", "data_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2020-21732.json", "defensive_priority": "Continuous monitoring candidate", "epss_percentile": 0.54231, "epss_score": 0.00864, "exposure_hint": "exposure unknown", "human_consequence": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk.", "human_impact_label": "XSS risk", "human_risk_summary": "CVE-2020-21732 for rukovoditel / rukovoditel: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk.", "id": "CVE-2020-21732", "impact_tags": ["XSS risk"], "kev": false, "observed_at": "2026-07-08T03:39:09.814067+00:00", "product": "rukovoditel", "public_human_impact": "Source describes XSS risk. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk.", "public_human_summary": "NVD: Rukovoditel Project Management app 2.6 is affected by: Cross Site Scripting (XSS). NVD: An attacker can add JavaScript code to the filename.", "public_human_what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "public_human_why_it_matters": "Source describes XSS risk. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk.; CVSS 6.1 (MEDIUM); EPSS percentile 54; not listed in KEV; Remediation reference present; patch status requires confirmation in the linked advisory; sources: NVD, Vendor Advisory.", "public_safe_summary": "NVD: Rukovoditel Project Management app 2.6 is affected by: Cross Site Scripting (XSS). NVD: An attacker can add JavaScript code to the filename.", "public_status": "public_safe", "published_at": null, "redaction_notes": ["source-published defensive context retained", "vulnerability class, impact, affected context, and remediation references remain displayable"], "remediation_handoff": {"auto_remediation_allowed": false, "codex_prompt_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-21732-codex-prompt.md", "external_execution_allowed": false, "human_approval_required": true, "json_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-21732.json", "markdown_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-21732.md", "scan_allowed": false}, "remediation_urls": ["https://www.rukovoditel.net"], "sort_priority": 61.54231, "source_copy_policy": {"allowed": "source-published defensive facts, vulnerability class, impact, affected context, version and remediation facts", "excluded": "exploit procedures, exploit strings, shell commands, scanner instructions, procedural bypass detail, and reproduction material", "summary": "Official or semi-official source descriptions may be summarized for defensive triage; exploit-enabling procedure is removed."}, "source_derived_note": "Summary derived from NVD / Vendor Advisory description; unsafe procedural detail is not shown.", "source_label": "NVD, Vendor Advisory", "source_published_affected": "vendor/product: rukovoditel / rukovoditel; affected version context: 2.6", "source_published_description": "NVD: Rukovoditel Project Management app 2.6 is affected by: Cross Site Scripting (XSS). NVD: An attacker can add JavaScript code to the filename.", "source_published_evidence_refs": [{"source": "NVD", "type": "source_description", "url": null}, {"source": "Vendor Advisory", "type": "source_description", "url": null}, {"source": "Reference", "type": "reference", "url": "https://github.com/Gr3gPr1est/BugReport/blob/master/CVE-2020-21732"}, {"source": "Vendor Advisory", "type": "reference", "url": "https://www.rukovoditel.net"}, {"source": "Reference", "type": "reference", "url": "http://rukovoditel.com"}, {"source": "Reference", "type": "reference", "url": "https://github.com/Gr3gPr1est/BugReport/blob/master/CVE-2020-21732"}, {"source": "Vendor Advisory", "type": "reference", "url": "https://www.rukovoditel.net"}, {"source": "Official Reference", "type": "reference", "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-21732"}], "source_published_impact": "Source describes XSS risk. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk.", "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.", "source_published_summary": "NVD: Rukovoditel Project Management app 2.6 is affected by: Cross Site Scripting (XSS). NVD: An attacker can add JavaScript code to the filename.", "sources": ["NVD", "Vendor Advisory"], "summary": "CVE-2020-21732 is a defensive prioritization candidate. NVD lists CVSS severity as MEDIUM. CVSS score is 6.1. EPSS score is 0.0086 with percentile 0.5423. Known exploited catalog status is not listed in NVD for this record. Use official advisories and vendor remediation references for defensive review.", "summary_ja": null, "title": "CVE-2020-21732 defensive priority signal", "title_ja": null, "translation": null, "updated_at": null, "urgency_reasons": ["affected product present", "vendor advisory present", "recent update", "remediation reference present"], "vendor": "rukovoditel", "what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "why_it_matters": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk; CVSS 6.1 (MEDIUM); EPSS percentile 54; affected product context: rukovoditel / rukovoditel; sources: NVD, Vendor Advisory."}, {"affected_label": "daily_tracker_system_project / daily_tracker_system", "affected_products": [{"canonicalProduct": "daily_tracker_system", "canonicalVendor": "daily_tracker_system_project", "cpe": "cpe:2.3:a:daily_tracker_system_project:daily_tracker_system:1.0:*:*:*:*:*:*:*", "ecosystem": null, "packageName": null, "product": "daily_tracker_system", "purl": null, "vendor": "daily_tracker_system_project", "version": "1.0"}], "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2020-24194/", "cvss_score": 6.1, "cvss_severity": "MEDIUM", "data_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2020-24194.json", "defensive_priority": "Continuous monitoring candidate", "epss_percentile": 0.53283, "epss_score": 0.00835, "exposure_hint": "remote exposure", "human_consequence": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk · remote exposure.", "human_impact_label": "XSS risk · remote exposure", "human_risk_summary": "CVE-2020-24194 for daily_tracker_system_project / daily_tracker_system: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk · remote exposure.", "id": "CVE-2020-24194", "impact_tags": ["XSS risk", "remote exposure relevant"], "kev": false, "observed_at": "2026-07-08T03:39:09.814067+00:00", "product": "daily_tracker_system", "public_human_impact": "Source describes XSS risk · remote exposure. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk · remote exposure.", "public_human_summary": "NVD: A Cross-site scripting (XSS) vulnerability in 'user-profile.php' in SourceCodester Daily Tracker System v1.0 allows remote attackers to inject arbitrary web script or HTML via the 'fullname' parameter.", "public_human_what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "public_human_why_it_matters": "Source describes XSS risk · remote exposure. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk · remote exposure.; CVSS 6.1 (MEDIUM); EPSS percentile 53; not listed in KEV; Remediation reference present; patch status requires confirmation in the linked advisory; sources: NVD.", "public_safe_summary": "NVD: A Cross-site scripting (XSS) vulnerability in 'user-profile.php' in SourceCodester Daily Tracker System v1.0 allows remote attackers to inject arbitrary web script or HTML via the 'fullname' parameter.", "public_status": "public_safe", "published_at": null, "redaction_notes": ["source-published defensive context retained", "vulnerability class, impact, affected context, and remediation references remain displayable"], "remediation_handoff": {"auto_remediation_allowed": false, "codex_prompt_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-24194-codex-prompt.md", "external_execution_allowed": false, "human_approval_required": true, "json_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-24194.json", "markdown_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-24194.md", "scan_allowed": false}, "remediation_urls": ["https://cxsecurity.com/issue/WLB-2020090030"], "sort_priority": 61.53283, "source_copy_policy": {"allowed": "source-published defensive facts, vulnerability class, impact, affected context, version and remediation facts", "excluded": "exploit procedures, exploit strings, shell commands, scanner instructions, procedural bypass detail, and reproduction material", "summary": "Official or semi-official source descriptions may be summarized for defensive triage; exploit-enabling procedure is removed."}, "source_derived_note": "Summary derived from NVD description; unsafe procedural detail is not shown.", "source_label": "NVD, Vendor Advisory", "source_published_affected": "vendor/product: daily_tracker_system_project / daily_tracker_system; affected version context: 1.0", "source_published_description": "NVD: A Cross-site scripting (XSS) vulnerability in 'user-profile.php' in SourceCodester Daily Tracker System v1.0 allows remote attackers to inject arbitrary web script or HTML via the 'fullname' parameter.", "source_published_evidence_refs": [{"source": "NVD", "type": "source_description", "url": null}, {"source": "Reference", "type": "reference", "url": "https://cxsecurity.com/issue/WLB-2020090030"}, {"source": "Reference", "type": "reference", "url": "http://sourcecodetester.com"}, {"source": "Reference", "type": "reference", "url": "https://cxsecurity.com/issue/WLB-2020090030"}, {"source": "Official Reference", "type": "reference", "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-24194"}], "source_published_impact": "Source describes XSS risk · remote exposure. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk · remote exposure.", "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.", "source_published_summary": "NVD: A Cross-site scripting (XSS) vulnerability in 'user-profile.php' in SourceCodester Daily Tracker System v1.0 allows remote attackers to inject arbitrary web script or HTML via the 'fullname' parameter.", "sources": ["NVD", "Vendor Advisory"], "summary": "CVE-2020-24194 is a defensive prioritization candidate. NVD lists CVSS severity as MEDIUM. CVSS score is 6.1. EPSS score is 0.0083 with percentile 0.5328. Known exploited catalog status is not listed in NVD for this record. Use official advisories and vendor remediation references for defensive review.", "summary_ja": null, "title": "CVE-2020-24194 defensive priority signal", "title_ja": null, "translation": null, "updated_at": null, "urgency_reasons": ["affected product present", "vendor advisory present", "recent update", "remediation reference present"], "vendor": "daily_tracker_system_project", "what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "why_it_matters": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk · remote exposure; CVSS 6.1 (MEDIUM); EPSS percentile 53; affected product context: daily_tracker_system_project / daily_tracker_system..."}, {"affected_label": "microweber / microweber", "affected_products": [{"canonicalProduct": "microweber", "canonicalVendor": "microweber", "cpe": "cpe:2.3:a:microweber:microweber:1.1.18:*:*:*:*:*:*:*", "ecosystem": null, "packageName": null, "product": "microweber", "purl": null, "vendor": "microweber", "version": "1.1.18"}], "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2020-23136/", "cvss_score": 5.5, "cvss_severity": "MEDIUM", "data_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2020-23136.json", "defensive_priority": "Routine monitoring candidate", "epss_percentile": 0.24698, "epss_score": 0.00328, "exposure_hint": "exposure unknown", "human_consequence": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.", "human_impact_label": "defensive exposure review", "human_risk_summary": "CVE-2020-23136 for microweber / microweber: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.", "id": "CVE-2020-23136", "impact_tags": [], "kev": false, "observed_at": "2026-07-08T03:39:09.814067+00:00", "product": "microweber", "public_human_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.", "public_human_summary": "NVD: Microweber v1.1.18 is affected by no session expiry after log-out.", "public_human_what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "public_human_why_it_matters": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.; CVSS 5.5 (MEDIUM); EPSS percentile 25; not listed in KEV; Remediation reference present; patch status requires confirmation in the linked advisory; sources: NVD.", "public_safe_summary": "NVD: Microweber v1.1.18 is affected by no session expiry after log-out.", "public_status": "public_safe", "published_at": null, "redaction_notes": ["source-published defensive context retained", "vulnerability class, impact, affected context, and remediation references remain displayable"], "remediation_handoff": {"auto_remediation_allowed": false, "codex_prompt_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-23136-codex-prompt.md", "external_execution_allowed": false, "human_approval_required": true, "json_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-23136.json", "markdown_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-23136.md", "scan_allowed": false}, "remediation_urls": ["https://nvd.nist.gov/vuln/detail/CVE-2020-23136"], "sort_priority": 55.24698, "source_copy_policy": {"allowed": "source-published defensive facts, vulnerability class, impact, affected context, version and remediation facts", "excluded": "exploit procedures, exploit strings, shell commands, scanner instructions, procedural bypass detail, and reproduction material", "summary": "Official or semi-official source descriptions may be summarized for defensive triage; exploit-enabling procedure is removed."}, "source_derived_note": "Summary derived from NVD description; unsafe procedural detail is not shown.", "source_label": "NVD, Vendor Advisory", "source_published_affected": "vendor/product: microweber / microweber; affected version context: 1.1.18", "source_published_description": "NVD: Microweber v1.1.18 is affected by no session expiry after log-out.", "source_published_evidence_refs": [{"source": "NVD", "type": "source_description", "url": null}, {"source": "Reference", "type": "reference", "url": "https://gist.github.com/virendratiwari03/0b0d161e1141fdd74122abbb02fefe17"}, {"source": "Reference", "type": "reference", "url": "http://microweber.com"}, {"source": "Reference", "type": "reference", "url": "https://gist.github.com/virendratiwari03/0b0d161e1141fdd74122abbb02fefe17"}, {"source": "Official Reference", "type": "reference", "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-23136"}], "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.", "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.", "source_published_summary": "NVD: Microweber v1.1.18 is affected by no session expiry after log-out.", "sources": ["NVD", "Vendor Advisory"], "summary": "CVE-2020-23136 is a defensive prioritization candidate. NVD lists CVSS severity as MEDIUM. CVSS score is 5.5. EPSS score is 0.0033 with percentile 0.2470. Known exploited catalog status is not listed in NVD for this record. Use official advisories and vendor remediation references for defensive review.", "summary_ja": null, "title": "CVE-2020-23136 defensive priority signal", "title_ja": null, "translation": null, "updated_at": null, "urgency_reasons": ["affected product present", "vendor advisory present", "recent update"], "vendor": "microweber", "what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "why_it_matters": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review; CVSS 5.5 (MEDIUM); EPSS percentile 25; affected product context: microweber / microweber; sources: NVD."}, {"affected_label": "spiceworks / spiceworks", "affected_products": [{"canonicalProduct": "spiceworks", "canonicalVendor": "spiceworks", "cpe": "cpe:2.3:a:spiceworks:spiceworks:*:*:*:*:*:*:*:*", "ecosystem": null, "packageName": null, "product": "spiceworks", "purl": null, "vendor": "spiceworks", "version": null}], "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2020-23450/", "cvss_score": 5.4, "cvss_severity": "MEDIUM", "data_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2020-23450.json", "defensive_priority": "Continuous monitoring candidate", "epss_percentile": 0.5158, "epss_score": 0.00783, "exposure_hint": "exposure unknown", "human_consequence": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.", "human_impact_label": "defensive exposure review", "human_risk_summary": "CVE-2020-23450 for spiceworks / spiceworks: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.", "id": "CVE-2020-23450", "impact_tags": [], "kev": false, "observed_at": "2026-07-08T03:39:09.814067+00:00", "product": "spiceworks", "public_human_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.", "public_human_summary": "NVD: Spiceworks Version <= 7.5.00107 is affected by XSS. NVD: Any name typed on Custom Groups function is vulnerable to stored XSS as they displayed on without output sanitization.", "public_human_what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "public_human_why_it_matters": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.; CVSS 5.4 (MEDIUM); EPSS percentile 52; not listed in KEV; Remediation reference present; patch status requires confirmation in the linked advisory; sources: NVD, Vendor Advisory.", "public_safe_summary": "NVD: Spiceworks Version <= 7.5.00107 is affected by XSS. NVD: Any name typed on Custom Groups function is vulnerable to stored XSS as they displayed on without output sanitization.", "public_status": "public_safe", "published_at": null, "redaction_notes": ["source-published defensive context retained", "vulnerability class, impact, affected context, and remediation references remain displayable"], "remediation_handoff": {"auto_remediation_allowed": false, "codex_prompt_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-23450-codex-prompt.md", "external_execution_allowed": false, "human_approval_required": true, "json_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-23450.json", "markdown_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-23450.md", "scan_allowed": false}, "remediation_urls": ["http://spiceworks.com"], "sort_priority": 54.5158, "source_copy_policy": {"allowed": "source-published defensive facts, vulnerability class, impact, affected context, version and remediation facts", "excluded": "exploit procedures, exploit strings, shell commands, scanner instructions, procedural bypass detail, and reproduction material", "summary": "Official or semi-official source descriptions may be summarized for defensive triage; exploit-enabling procedure is removed."}, "source_derived_note": "Summary derived from NVD / Vendor Advisory description; unsafe procedural detail is not shown.", "source_label": "NVD, Vendor Advisory", "source_published_affected": "vendor/product: spiceworks / spiceworks", "source_published_description": "NVD: Spiceworks Version <= 7.5.00107 is affected by XSS. NVD: Any name typed on Custom Groups function is vulnerable to stored XSS as they displayed on without output sanitization.", "source_published_evidence_refs": [{"source": "NVD", "type": "source_description", "url": null}, {"source": "Vendor Advisory", "type": "source_description", "url": null}, {"source": "Reference", "type": "reference", "url": "https://abuyv.com"}, {"source": "Reference", "type": "reference", "url": "https://abuyv.com/cve/spiceworks-stored-xss"}, {"source": "Vendor Advisory", "type": "reference", "url": "http://spiceworks.com"}, {"source": "Reference", "type": "reference", "url": "https://abuyv.com"}, {"source": "Reference", "type": "reference", "url": "https://abuyv.com/cve/spiceworks-stored-xss"}, {"source": "Official Reference", "type": "reference", "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-23450"}], "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.", "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.", "source_published_summary": "NVD: Spiceworks Version <= 7.5.00107 is affected by XSS. NVD: Any name typed on Custom Groups function is vulnerable to stored XSS as they displayed on without output sanitization.", "sources": ["NVD", "Vendor Advisory"], "summary": "CVE-2020-23450 is a defensive prioritization candidate. NVD lists CVSS severity as MEDIUM. CVSS score is 5.4. EPSS score is 0.0078 with percentile 0.5158. Known exploited catalog status is not listed in NVD for this record. Use official advisories and vendor remediation references for defensive review.", "summary_ja": null, "title": "CVE-2020-23450 defensive priority signal", "title_ja": null, "translation": null, "updated_at": null, "urgency_reasons": ["affected product present", "vendor advisory present", "recent update", "remediation reference present"], "vendor": "spiceworks", "what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "why_it_matters": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review; CVSS 5.4 (MEDIUM); EPSS percentile 52; affected product context: spiceworks / spiceworks; sources: NVD, Vendor Advisory."}, {"affected_label": "yourls / yourls", "affected_products": [{"canonicalProduct": "yourls", "canonicalVendor": "yourls", "cpe": "cpe:2.3:a:yourls:yourls:*:*:*:*:*:*:*:*", "ecosystem": null, "packageName": null, "product": "yourls", "purl": null, "vendor": "yourls", "version": null}], "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2020-27388/", "cvss_score": 5.4, "cvss_severity": "MEDIUM", "data_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2020-27388.json", "defensive_priority": "Continuous monitoring candidate", "epss_percentile": 0.50603, "epss_score": 0.00754, "exposure_hint": "exposure unknown", "human_consequence": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.", "human_impact_label": "defensive exposure review", "human_risk_summary": "CVE-2020-27388 for yourls / yourls: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.", "id": "CVE-2020-27388", "impact_tags": [], "kev": false, "observed_at": "2026-07-08T03:39:09.814067+00:00", "product": "yourls", "public_human_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.", "public_human_summary": "NVD: Multiple Stored Cross Site Scripting (XSS) vulnerabilities exist in the YOURLS Admin Panel, Versions 1.5 - 1.7.10.", "public_human_what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "public_human_why_it_matters": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.; CVSS 5.4 (MEDIUM); EPSS percentile 51; not listed in KEV; Remediation reference present; patch status requires confirmation in the linked advisory; sources: NVD.", "public_safe_summary": "NVD: Multiple Stored Cross Site Scripting (XSS) vulnerabilities exist in the YOURLS Admin Panel, Versions 1.5 - 1.7.10.", "public_status": "public_safe", "published_at": null, "redaction_notes": ["source-published defensive context retained", "exploit string, command, scanner, or code-like detail removed", "vulnerability class, impact, affected context, and remediation references remain displayable"], "remediation_handoff": {"auto_remediation_allowed": false, "codex_prompt_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-27388-codex-prompt.md", "external_execution_allowed": false, "human_approval_required": true, "json_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-27388.json", "markdown_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-27388.md", "scan_allowed": false}, "remediation_urls": ["https://nvd.nist.gov/vuln/detail/CVE-2020-27388"], "sort_priority": 54.50603, "source_copy_policy": {"allowed": "source-published defensive facts, vulnerability class, impact, affected context, version and remediation facts", "excluded": "exploit procedures, exploit strings, shell commands, scanner instructions, procedural bypass detail, and reproduction material", "summary": "Official or semi-official source descriptions may be summarized for defensive triage; exploit-enabling procedure is removed."}, "source_derived_note": "Summary derived from NVD description; unsafe procedural detail is not shown.", "source_label": "NVD, Vendor Advisory", "source_published_affected": "vendor/product: yourls / yourls", "source_published_description": "NVD: Multiple Stored Cross Site Scripting (XSS) vulnerabilities exist in the YOURLS Admin Panel, Versions 1.5 - 1.7.10.", "source_published_evidence_refs": [{"source": "NVD", "type": "source_description", "url": null}, {"source": "Reference", "type": "reference", "url": "https://github.com/YOURLS/YOURLS/pull/2761"}, {"source": "Reference", "type": "reference", "url": "https://johnjhacking.com/blog/cve-2020-27388/"}, {"source": "Reference", "type": "reference", "url": "http://yourls.com"}, {"source": "Reference", "type": "reference", "url": "https://github.com/YOURLS/YOURLS/pull/2761"}, {"source": "Reference", "type": "reference", "url": "https://johnjhacking.com/blog/cve-2020-27388/"}, {"source": "Official Reference", "type": "reference", "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-27388"}], "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.", "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.", "source_published_summary": "NVD: Multiple Stored Cross Site Scripting (XSS) vulnerabilities exist in the YOURLS Admin Panel, Versions 1.5 - 1.7.10.", "sources": ["NVD", "Vendor Advisory"], "summary": "CVE-2020-27388 is a defensive prioritization candidate. NVD lists CVSS severity as MEDIUM. CVSS score is 5.4. EPSS score is 0.0075 with percentile 0.5060. Known exploited catalog status is not listed in NVD for this record. Use official advisories and vendor remediation references for defensive review.", "summary_ja": null, "title": "CVE-2020-27388 defensive priority signal", "title_ja": null, "translation": null, "updated_at": null, "urgency_reasons": ["affected product present", "vendor advisory present", "recent update"], "vendor": "yourls", "what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "why_it_matters": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review; CVSS 5.4 (MEDIUM); EPSS percentile 51; affected product context: yourls / yourls; sources: NVD."}, {"affected_label": "verint / workforce_optimization", "affected_products": [{"canonicalProduct": "workforce_optimization", "canonicalVendor": "verint", "cpe": "cpe:2.3:a:verint:workforce_optimization:15.1.0.37634:*:*:*:*:*:*:*", "ecosystem": null, "packageName": null, "product": "workforce_optimization", "purl": null, "vendor": "verint", "version": "15.1.0.37634"}], "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2020-23446/", "cvss_score": 5.3, "cvss_severity": "MEDIUM", "data_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2020-23446.json", "defensive_priority": "Continuous monitoring candidate", "epss_percentile": 0.70416, "epss_score": 0.0146, "exposure_hint": "exposure unknown", "human_consequence": "An attacker may be able to access information that should not be exposed.", "human_impact_label": "information exposure review", "human_risk_summary": "CVE-2020-23446 for verint / workforce_optimization: An attacker may be able to access information that should not be exposed.", "id": "CVE-2020-23446", "impact_tags": ["information exposure review"], "kev": false, "observed_at": "2026-07-08T03:39:09.814067+00:00", "product": "workforce_optimization", "public_human_impact": "Source describes information exposure review. Possible impact: An attacker may be able to access information that should not be exposed.", "public_human_summary": "NVD: Verint Workforce Optimization suite 15.1 (15.1.0.37634) has Unauthenticated Information Disclosure via API", "public_human_what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "public_human_why_it_matters": "Source describes information exposure review. Possible impact: An attacker may be able to access information that should not be exposed.; CVSS 5.3 (MEDIUM); EPSS percentile 70; not listed in KEV; Remediation reference present; patch status requires confirmation in the linked advisory; sources: NVD, Vendor Advisory.", "public_safe_summary": "NVD: Verint Workforce Optimization suite 15.1 (15.1.0.37634) has Unauthenticated Information Disclosure via API", "public_status": "public_safe", "published_at": null, "redaction_notes": ["source-published defensive context retained", "vulnerability class, impact, affected context, and remediation references remain displayable"], "remediation_handoff": {"auto_remediation_allowed": false, "codex_prompt_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-23446-codex-prompt.md", "external_execution_allowed": false, "human_approval_required": true, "json_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-23446.json", "markdown_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-23446.md", "scan_allowed": false}, "remediation_urls": ["http://verint.com"], "sort_priority": 53.70416, "source_copy_policy": {"allowed": "source-published defensive facts, vulnerability class, impact, affected context, version and remediation facts", "excluded": "exploit procedures, exploit strings, shell commands, scanner instructions, procedural bypass detail, and reproduction material", "summary": "Official or semi-official source descriptions may be summarized for defensive triage; exploit-enabling procedure is removed."}, "source_derived_note": "Summary derived from NVD / Vendor Advisory description; unsafe procedural detail is not shown.", "source_label": "NVD, Vendor Advisory", "source_published_affected": "vendor/product: verint / workforce_optimization; affected version context: 15.1.0.37634", "source_published_description": "NVD: Verint Workforce Optimization suite 15.1 (15.1.0.37634) has Unauthenticated Information Disclosure via API", "source_published_evidence_refs": [{"source": "NVD", "type": "source_description", "url": null}, {"source": "Vendor Advisory", "type": "source_description", "url": null}, {"source": "Reference", "type": "reference", "url": "http://cvewalkthrough.com/variant-unauthenticated-information-disclosure-via-api/"}, {"source": "Reference", "type": "reference", "url": "https://tejaspingulkar.blogspot.com/2020/09/cve-2020-23446-verint-workforce.html"}, {"source": "Reference", "type": "reference", "url": "http://cvewalkthrough.com/variant-unauthenticated-information-disclosure-via-api/"}, {"source": "Vendor Advisory", "type": "reference", "url": "http://verint.com"}, {"source": "Reference", "type": "reference", "url": "https://tejaspingulkar.blogspot.com/2020/09/cve-2020-23446-verint-workforce.html"}, {"source": "Official Reference", "type": "reference", "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-23446"}], "source_published_impact": "Source describes information exposure review. Possible impact: An attacker may be able to access information that should not be exposed.", "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.", "source_published_summary": "NVD: Verint Workforce Optimization suite 15.1 (15.1.0.37634) has Unauthenticated Information Disclosure via API", "sources": ["NVD", "Vendor Advisory"], "summary": "CVE-2020-23446 is a defensive prioritization candidate. NVD lists CVSS severity as MEDIUM. CVSS score is 5.3. EPSS score is 0.0146 with percentile 0.7042. Known exploited catalog status is not listed in NVD for this record. Use official advisories and vendor remediation references for defensive review.", "summary_ja": null, "title": "CVE-2020-23446 defensive priority signal", "title_ja": null, "translation": null, "updated_at": null, "urgency_reasons": ["affected product present", "vendor advisory present", "recent update", "remediation reference present"], "vendor": "verint", "what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "why_it_matters": "An attacker may be able to access information that should not be exposed; CVSS 5.3 (MEDIUM); EPSS percentile 70; affected product context: verint / workforce_optimization; sources: NVD, Vendor Advisory."}], "footerStats": {"dataSources": 3, "itemCount": 20}, "generatedAt": "2026-07-08T03:43:17.030146+00:00", "observedBuckets": {"2026-07-08": 20}, "reportPreview": {"count": 20, "defensive_checklist": ["Confirm affected products", "Review official source references", "Prioritize KEV, critical CVSS, and high EPSS percentile items", "Record human confirmation"], "mode": "read_only_public_beta_dashboard", "safety": {"procedural_detail": false, "public_launch": true, "scanner_execution": false}, "severity_distribution": {"CRITICAL": 4, "HIGH": 8, "LOW": 0, "MEDIUM": 8, "NONE": 0, "UNKNOWN": 0}, "top_risk": "CVE-2005-4459"}, "severityDistribution": {"CRITICAL": 4, "HIGH": 8, "LOW": 0, "MEDIUM": 8, "NONE": 0, "UNKNOWN": 0}, "sourceDistribution": {"NVD": 20, "OSV": 2, "Vendor Advisory": 20}, "sourceHealth": {"deploy_mode": "fresh_fetch", "errors": [], "generated_at": "2026-07-08T03:39:09.827335+00:00", "normalized_count": 20, "note": "Latest public surface was generated from a successful safety-gated source fetch.", "public_safe_count": 20, "source_counts": {"epss": 20, "nvd": 20, "osv": 2}, "source_error_count": 0, "status": "healthy", "summary_available": true}, "sourceStatus": [{"count": 20, "errorType": null, "lastObserved": "2026-07-08", "name": "NVD", "status": "healthy"}, {"count": 20, "errorType": null, "lastObserved": "2026-07-08", "name": "EPSS", "status": "healthy"}, {"count": 2, "errorType": null, "lastObserved": "2026-07-08", "name": "OSV", "status": "healthy"}, {"count": 0, "errorType": null, "lastObserved": "2026-07-08", "name": "CISA KEV", "status": "not observed"}, {"count": 20, "errorType": null, "lastObserved": "2026-07-08", "name": "Vendor Advisory", "status": "observed"}], "topRisks": [{"affected_label": "vmware / ace", "affected_products": [{"canonicalProduct": "ace", "canonicalVendor": "vmware", "cpe": "cpe:2.3:a:vmware:ace:1.0.1:*:*:*:*:*:*:*", "ecosystem": null, "packageName": null, "product": "ace", "purl": null, "vendor": "vmware", "version": "1.0.1"}, {"canonicalProduct": "gsx_server", "canonicalVendor": "vmware", "cpe": "cpe:2.3:a:vmware:gsx_server:2.0:*:*:*:*:*:*:*", "ecosystem": null, "packageName": null, "product": "gsx_server", "purl": null, "vendor": "vmware", "version": "2.0"}, {"canonicalProduct": "gsx_server", "canonicalVendor": "vmware", "cpe": "cpe:2.3:a:vmware:gsx_server:2.0.1_build_2129:*:*:*:*:*:*:*", "ecosystem": null, "packageName": null, "product": "gsx_server", "purl": null, "vendor": "vmware", "version": "2.0.1_build_2129"}, {"canonicalProduct": "gsx_server", "canonicalVendor": "vmware", "cpe": "cpe:2.3:a:vmware:gsx_server:2.5.1:*:*:*:*:*:*:*", "ecosystem": null, "packageName": null, "product": "gsx_server", "purl": null, "vendor": "vmware", "version": "2.5.1"}, {"canonicalProduct": "gsx_server", "canonicalVendor": "vmware", "cpe": "cpe:2.3:a:vmware:gsx_server:2.5.1_build_5336:*:*:*:*:*:*:*", "ecosystem": null, "packageName": null, "product": "gsx_server", "purl": null, "vendor": "vmware", "version": "2.5.1_build_5336"}, {"canonicalProduct": "gsx_server", "canonicalVendor": "vmware", "cpe": "cpe:2.3:a:vmware:gsx_server:2.5.2:*:*:*:*:*:*:*", "ecosystem": null, "packageName": null, "product": "gsx_server", "purl": null, "vendor": "vmware", "version": "2.5.2"}, {"canonicalProduct": "gsx_server", "canonicalVendor": "vmware", "cpe": "cpe:2.3:a:vmware:gsx_server:3.0:*:*:*:*:*:*:*", "ecosystem": null, "packageName": null, "product": "gsx_server", "purl": null, "vendor": "vmware", "version": "3.0"}, {"canonicalProduct": "gsx_server", "canonicalVendor": "vmware", "cpe": "cpe:2.3:a:vmware:gsx_server:3.0_build_7592:*:*:*:*:*:*:*", "ecosystem": null, "packageName": null, "product": "gsx_server", "purl": null, "vendor": "vmware", "version": "3.0_build_7592"}, {"canonicalProduct": "gsx_server", "canonicalVendor": "vmware", "cpe": "cpe:2.3:a:vmware:gsx_server:3.1:*:*:*:*:*:*:*", "ecosystem": null, "packageName": null, "product": "gsx_server", "purl": null, "vendor": "vmware", "version": "3.1"}, {"canonicalProduct": "gsx_server", "canonicalVendor": "vmware", "cpe": "cpe:2.3:a:vmware:gsx_server:3.2:*:*:*:*:*:*:*", "ecosystem": null, "packageName": null, "product": "gsx_server", "purl": null, "vendor": "vmware", "version": "3.2"}, {"canonicalProduct": "player", "canonicalVendor": "vmware", "cpe": "cpe:2.3:a:vmware:player:1.0.0:*:*:*:*:*:*:*", "ecosystem": null, "packageName": null, "product": "player", "purl": null, "vendor": "vmware", "version": "1.0.0"}, {"canonicalProduct": "workstation", "canonicalVendor": "vmware", "cpe": "cpe:2.3:a:vmware:workstation:3.2.1:patch1:*:*:*:*:*:*", "ecosystem": null, "packageName": null, "product": "workstation", "purl": null, "vendor": "vmware", "version": "3.2.1"}, {"canonicalProduct": "workstation", "canonicalVendor": "vmware", "cpe": "cpe:2.3:a:vmware:workstation:3.4:*:*:*:*:*:*:*", "ecosystem": null, "packageName": null, "product": "workstation", "purl": null, "vendor": "vmware", "version": "3.4"}, {"canonicalProduct": "workstation", "canonicalVendor": "vmware", "cpe": "cpe:2.3:a:vmware:workstation:4.0:*:*:*:*:*:*:*", "ecosystem": null, "packageName": null, "product": "workstation", "purl": null, "vendor": "vmware", "version": "4.0"}, {"canonicalProduct": "workstation", "canonicalVendor": "vmware", "cpe": "cpe:2.3:a:vmware:workstation:4.0.1:*:*:*:*:*:*:*", "ecosystem": null, "packageName": null, "product": "workstation", "purl": null, "vendor": "vmware", "version": "4.0.1"}, {"canonicalProduct": "workstation", "canonicalVendor": "vmware", "cpe": "cpe:2.3:a:vmware:workstation:4.0.2:*:*:*:*:*:*:*", "ecosystem": null, "packageName": null, "product": "workstation", "purl": null, "vendor": "vmware", "version": "4.0.2"}, {"canonicalProduct": "workstation", "canonicalVendor": "vmware", "cpe": "cpe:2.3:a:vmware:workstation:4.5.2:*:*:*:*:*:*:*", "ecosystem": null, "packageName": null, "product": "workstation", "purl": null, "vendor": "vmware", "version": "4.5.2"}, {"canonicalProduct": "workstation", "canonicalVendor": "vmware", "cpe": "cpe:2.3:a:vmware:workstation:4.5.2_build_8848:r4:*:*:*:*:*:*", "ecosystem": null, "packageName": null, "product": "workstation", "purl": null, "vendor": "vmware", "version": "4.5.2_build_8848"}, {"canonicalProduct": "workstation", "canonicalVendor": "vmware", "cpe": "cpe:2.3:a:vmware:workstation:5.0.0_build_13124:*:*:*:*:*:*:*", "ecosystem": null, "packageName": null, "product": "workstation", "purl": null, "vendor": "vmware", "version": "5.0.0_build_13124"}, {"canonicalProduct": "workstation", "canonicalVendor": "vmware", "cpe": "cpe:2.3:a:vmware:workstation:5.5:*:*:*:*:*:*:*", "ecosystem": null, "packageName": null, "product": "workstation", "purl": null, "vendor": "vmware", "version": "5.5"}], "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2005-4459/", "cvss_score": 10.0, "cvss_severity": "CRITICAL", "data_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2005-4459.json", "defensive_priority": "Priority review candidate", "epss_percentile": 0.96028, "epss_score": 0.13661, "exposure_hint": "authenticated boundary", "human_consequence": "An attacker may be able to run code or commands on affected systems.", "human_impact_label": "code execution review · memory safety review · authenticated boundary", "human_risk_summary": "CVE-2005-4459 for vmware / ace: An attacker may be able to run code or commands on affected systems.", "id": "CVE-2005-4459", "impact_tags": ["code execution review", "memory safety review", "authenticated boundary review"], "kev": false, "observed_at": "2026-07-08T03:39:09.814067+00:00", "product": "ace", "public_human_impact": "Source describes code execution review · memory safety review · authenticated boundary. Possible impact: An attacker may be able to run code or commands on affected systems.", "public_human_summary": "NVD: Heap-based buffer overflow in the NAT networking components vmnat.exe and vmnet-natd in VMWare Workstation 5.5, GSX Server 3.2, ACE 1.0.1, and Player 1.0 allows remote authenticated attackers, including guests, to execute arbitrary code via crafted (1) EPRT...", "public_human_what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "public_human_why_it_matters": "Source describes code execution review · memory safety review · authenticated boundary. Possible impact: An attacker may be able to run code or commands on affected systems.; CVSS 10.0 (CRITICAL); EPSS percentile 96; not listed in KEV; Remediation reference present; patch status requires confirmation in the linked advisory; sources: NVD, Vendor Advisory.", "public_safe_summary": "NVD: Heap-based buffer overflow in the NAT networking components vmnat.exe and vmnet-natd in VMWare Workstation 5.5, GSX Server 3.2, ACE 1.0.1, and Player 1.0 allows remote authenticated attackers, including guests, to execute arbitrary code via crafted (1) EPRT...", "public_status": "public_safe", "published_at": null, "redaction_notes": ["source-published defensive context retained", "vulnerability class, impact, affected context, and remediation references remain displayable"], "remediation_handoff": {"auto_remediation_allowed": false, "codex_prompt_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2005-4459-codex-prompt.md", "external_execution_allowed": false, "human_approval_required": true, "json_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2005-4459.json", "markdown_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2005-4459.md", "scan_allowed": false}, "remediation_urls": ["http://secunia.com/advisories/18162", "http://secunia.com/advisories/18344", "http://securityreason.com/securityalert/282", "http://securityreason.com/securityalert/289", "http://securitytracker.com/id?1015401", "http://www.gentoo.org/security/en/glsa/glsa-200601-04.xml", "http://www.securityfocus.com/archive/1/419997/100/0/threaded", "http://www.securityfocus.com/archive/1/420017/100/0/threaded", "http://www.securityfocus.com/bid/15998", "http://www.vmware.com/support/kb/enduser/std_adp.php?p_faqid=2000"], "sort_priority": 100.96028, "source_copy_policy": {"allowed": "source-published defensive facts, vulnerability class, impact, affected context, version and remediation facts", "excluded": "exploit procedures, exploit strings, shell commands, scanner instructions, procedural bypass detail, and reproduction material", "summary": "Official or semi-official source descriptions may be summarized for defensive triage; exploit-enabling procedure is removed."}, "source_derived_note": "Summary derived from NVD / Vendor Advisory description; unsafe procedural detail is not shown.", "source_label": "NVD, Vendor Advisory", "source_published_affected": "vendor/product: vmware / ace; affected version context: 1.0.0, 1.0.1, 2.0, 2.0.1_build_2129, 2.5.1", "source_published_description": "NVD: Heap-based buffer overflow in the NAT networking components vmnat.exe and vmnet-natd in VMWare Workstation 5.5, GSX Server 3.2, ACE 1.0.1, and Player 1.0 allows remote authenticated attackers, including guests, to execute arbitrary code via crafted (1) EPRT...", "source_published_evidence_refs": [{"source": "NVD", "type": "source_description", "url": null}, {"source": "Vendor Advisory", "type": "source_description", "url": null}, {"source": "Reference", "type": "reference", "url": "http://lists.grok.org.uk/pipermail/full-disclosure/2005-December/040442.html"}, {"source": "Vendor Advisory", "type": "reference", "url": "http://secunia.com/advisories/18162"}, {"source": "Vendor Advisory", "type": "reference", "url": "http://secunia.com/advisories/18344"}, {"source": "Reference", "type": "reference", "url": "http://securityreason.com/securityalert/282"}, {"source": "Reference", "type": "reference", "url": "http://securityreason.com/securityalert/289"}, {"source": "Reference", "type": "reference", "url": "http://securitytracker.com/id?1015401"}, {"source": "Reference", "type": "reference", "url": "http://www.gentoo.org/security/en/glsa/glsa-200601-04.xml"}, {"source": "Reference", "type": "reference", "url": "http://www.kb.cert.org/vuls/id/856689"}], "source_published_impact": "Source describes code execution review · memory safety review · authenticated boundary. Possible impact: An attacker may be able to run code or commands on affected systems.", "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.", "source_published_summary": "NVD: Heap-based buffer overflow in the NAT networking components vmnat.exe and vmnet-natd in VMWare Workstation 5.5, GSX Server 3.2, ACE 1.0.1, and Player 1.0 allows remote authenticated attackers, including guests, to execute arbitrary code via crafted (1) EPRT...", "sources": ["NVD", "Vendor Advisory"], "summary": "CVE-2005-4459 is a defensive prioritization candidate. NVD lists CVSS severity as HIGH. CVSS score is 10.0. EPSS score is 0.1366 with percentile 0.9603. Known exploited catalog status is not listed in NVD for this record. Use official advisories and vendor remediation references for defensive review.", "summary_ja": null, "title": "CVE-2005-4459 defensive priority signal", "title_ja": null, "translation": null, "updated_at": null, "urgency_reasons": ["CVSS CRITICAL", "EPSS percentile high", "affected product present", "vendor advisory present", "recent update", "remediation reference present"], "vendor": "vmware", "what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "why_it_matters": "An attacker may be able to run code or commands on affected systems; CVSS 10.0 (CRITICAL); EPSS percentile 96; affected product context: vmware / ace; sources: NVD, Vendor Advisory."}, {"affected_label": "zohocorp / manageengine_adselfservice_plus", "affected_products": [{"canonicalProduct": "manageengine_adselfservice_plus", "canonicalVendor": "zohocorp", "cpe": "cpe:2.3:a:zohocorp:manageengine_adselfservice_plus:*:*:*:*:*:*:*:*", "ecosystem": null, "packageName": null, "product": "manageengine_adselfservice_plus", "purl": null, "vendor": "zohocorp", "version": null}, {"canonicalProduct": "manageengine_adselfservice_plus", "canonicalVendor": "zohocorp", "cpe": "cpe:2.3:a:zohocorp:manageengine_adselfservice_plus:5.5:-:*:*:*:*:*:*", "ecosystem": null, "packageName": null, "product": "manageengine_adselfservice_plus", "purl": null, "vendor": "zohocorp", "version": "5.5"}], "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2018-5353/", "cvss_score": 9.8, "cvss_severity": "CRITICAL", "data_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2018-5353.json", "defensive_priority": "Priority review candidate", "epss_percentile": 0.94138, "epss_score": 0.08103, "exposure_hint": "remote exposure", "human_consequence": "This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary.", "human_impact_label": "remote exposure · authenticated boundary", "human_risk_summary": "CVE-2018-5353 for zohocorp / manageengine_adselfservice_plus: This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary.", "id": "CVE-2018-5353", "impact_tags": ["remote exposure relevant", "authenticated boundary review"], "kev": false, "observed_at": "2026-07-08T03:39:09.814067+00:00", "product": "manageengine_adselfservice_plus", "public_human_impact": "Source describes remote exposure · authenticated boundary. Possible impact: This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary.", "public_human_summary": "NVD: The custom GINA/CP module in Zoho ManageEngine ADSelfService Plus before 5.5 build 5517 allows remote attackers to execute code and escalate privileges via spoofing. NVD: It does not authenticate the intended server before opening a browser window. NVD: An unauthenticated attacker capable of conducting a spoofing attack can redirect the browser to gain execution in the context of the WinLogon.exe process.", "public_human_what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "public_human_why_it_matters": "Source describes remote exposure · authenticated boundary. Possible impact: This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary.; CVSS 9.8 (CRITICAL); EPSS percentile 94; not listed in KEV; Remediation reference present; patch status requires confirmation in the linked advisory; sources: NVD, Vendor Advisory.", "public_safe_summary": "NVD: The custom GINA/CP module in Zoho ManageEngine ADSelfService Plus before 5.5 build 5517 allows remote attackers to execute code and escalate privileges via spoofing. NVD: It does not authenticate the intended server before opening a browser window. NVD: An unauthenticated attacker capable of conducting a spoofing attack can redirect the browser to gain execution in the context of the WinLogon.exe process.", "public_status": "public_safe", "published_at": null, "redaction_notes": ["source-published defensive context retained", "vulnerability class, impact, affected context, and remediation references remain displayable"], "remediation_handoff": {"auto_remediation_allowed": false, "codex_prompt_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2018-5353-codex-prompt.md", "external_execution_allowed": false, "human_approval_required": true, "json_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2018-5353.json", "markdown_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2018-5353.md", "scan_allowed": false}, "remediation_urls": ["http://zoho.com", "https://www.manageengine.com/products/self-service-password/release-notes.html"], "sort_priority": 98.94138, "source_copy_policy": {"allowed": "source-published defensive facts, vulnerability class, impact, affected context, version and remediation facts", "excluded": "exploit procedures, exploit strings, shell commands, scanner instructions, procedural bypass detail, and reproduction material", "summary": "Official or semi-official source descriptions may be summarized for defensive triage; exploit-enabling procedure is removed."}, "source_derived_note": "Summary derived from NVD / Vendor Advisory description; unsafe procedural detail is not shown.", "source_label": "NVD, Vendor Advisory", "source_published_affected": "vendor/product: zohocorp / manageengine_adselfservice_plus; affected version context: 5.5", "source_published_description": "NVD: The custom GINA/CP module in Zoho ManageEngine ADSelfService Plus before 5.5 build 5517 allows remote attackers to execute code and escalate privileges via spoofing. NVD: It does not authenticate the intended server before opening a browser window. NVD: An unauthenticated attacker capable of conducting a spoofing attack can redirect the browser to gain execution in the context of the WinLogon.exe process.", "source_published_evidence_refs": [{"source": "NVD", "type": "source_description", "url": null}, {"source": "Vendor Advisory", "type": "source_description", "url": null}, {"source": "Reference", "type": "reference", "url": "https://github.com/missing0x00/CVE-2018-5353"}, {"source": "Vendor Advisory", "type": "reference", "url": "https://www.manageengine.com/products/self-service-password/release-notes.html"}, {"source": "Vendor Advisory", "type": "reference", "url": "http://zoho.com"}, {"source": "Reference", "type": "reference", "url": "https://github.com/missing0x00/CVE-2018-5353"}, {"source": "Vendor Advisory", "type": "reference", "url": "https://www.manageengine.com/products/self-service-password/release-notes.html"}, {"source": "Official Reference", "type": "reference", "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-5353"}], "source_published_impact": "Source describes remote exposure · authenticated boundary. Possible impact: This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary.", "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.", "source_published_summary": "NVD: The custom GINA/CP module in Zoho ManageEngine ADSelfService Plus before 5.5 build 5517 allows remote attackers to execute code and escalate privileges via spoofing. NVD: It does not authenticate the intended server before opening a browser window. NVD: An unauthenticated attacker capable of conducting a spoofing attack can redirect the browser to gain execution in the context of the WinLogon.exe process.", "sources": ["NVD", "Vendor Advisory"], "summary": "CVE-2018-5353 is a defensive prioritization candidate. NVD lists CVSS severity as CRITICAL. CVSS score is 9.8. EPSS score is 0.0810 with percentile 0.9414. Known exploited catalog status is not listed in NVD for this record. Use official advisories and vendor remediation references for defensive review.", "summary_ja": null, "title": "CVE-2018-5353 defensive priority signal", "title_ja": null, "translation": null, "updated_at": null, "urgency_reasons": ["CVSS CRITICAL", "EPSS percentile high", "affected product present", "vendor advisory present", "recent update", "remediation reference present"], "vendor": "zohocorp", "what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "why_it_matters": "This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary; CVSS 9.8 (CRITICAL); EPSS percentile 94; affected product context: zohocorp /..."}, {"affected_label": "crmeb / crmeb", "affected_products": [{"canonicalProduct": "crmeb", "canonicalVendor": "crmeb", "cpe": "cpe:2.3:a:crmeb:crmeb:3.0:*:*:*:*:*:*:*", "ecosystem": null, "packageName": null, "product": "crmeb", "purl": null, "vendor": "crmeb", "version": "3.0"}], "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2020-25466/", "cvss_score": 9.8, "cvss_severity": "CRITICAL", "data_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2020-25466.json", "defensive_priority": "Priority review candidate", "epss_percentile": 0.85894, "epss_score": 0.03033, "exposure_hint": "exposure unknown", "human_consequence": "An attacker may be able to run code or commands on affected systems.", "human_impact_label": "code execution review", "human_risk_summary": "CVE-2020-25466 for crmeb / crmeb: An attacker may be able to run code or commands on affected systems.", "id": "CVE-2020-25466", "impact_tags": ["code execution review"], "kev": false, "observed_at": "2026-07-08T03:39:09.814067+00:00", "product": "crmeb", "public_human_impact": "Source describes code execution review. Possible impact: An attacker may be able to run code or commands on affected systems.", "public_human_summary": "NVD: A SSRF vulnerability exists in the downloadimage interface of CRMEB 3.0, which can remotely download arbitrary files on the server and remotely execute arbitrary code. OSV: A SSRF vulnerability exists in the downloadimage interface of CRMEB 3.0, which can remotely download arbitrary files on the server and remotely execute arbitrary code.", "public_human_what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "public_human_why_it_matters": "Source describes code execution review. Possible impact: An attacker may be able to run code or commands on affected systems.; CVSS 9.8 (CRITICAL); EPSS percentile 86; not listed in KEV; Remediation reference present; patch status requires confirmation in the linked advisory; sources: NVD, OSV, Vendor Advisory.", "public_safe_summary": "NVD: A SSRF vulnerability exists in the downloadimage interface of CRMEB 3.0, which can remotely download arbitrary files on the server and remotely execute arbitrary code. OSV: A SSRF vulnerability exists in the downloadimage interface of CRMEB 3.0, which can remotely download arbitrary files on the server and remotely execute arbitrary code.", "public_status": "public_safe", "published_at": null, "redaction_notes": ["source-published defensive context retained", "vulnerability class, impact, affected context, and remediation references remain displayable"], "remediation_handoff": {"auto_remediation_allowed": false, "codex_prompt_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-25466-codex-prompt.md", "external_execution_allowed": false, "human_approval_required": true, "json_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-25466.json", "markdown_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-25466.md", "scan_allowed": false}, "remediation_urls": ["http://crmeb.com"], "sort_priority": 98.85894, "source_copy_policy": {"allowed": "source-published defensive facts, vulnerability class, impact, affected context, version and remediation facts", "excluded": "exploit procedures, exploit strings, shell commands, scanner instructions, procedural bypass detail, and reproduction material", "summary": "Official or semi-official source descriptions may be summarized for defensive triage; exploit-enabling procedure is removed."}, "source_derived_note": "Summary derived from NVD / OSV / Vendor Advisory description; unsafe procedural detail is not shown.", "source_label": "NVD, OSV, Vendor Advisory", "source_published_affected": "vendor/product: crmeb / crmeb; affected version context: 3.0", "source_published_description": "NVD: A SSRF vulnerability exists in the downloadimage interface of CRMEB 3.0, which can remotely download arbitrary files on the server and remotely execute arbitrary code. OSV: A SSRF vulnerability exists in the downloadimage interface of CRMEB 3.0, which can remotely download arbitrary files on the server and remotely execute arbitrary code.", "source_published_evidence_refs": [{"source": "NVD", "type": "source_description", "url": null}, {"source": "OSV", "type": "source_description", "url": null}, {"source": "Vendor Advisory", "type": "source_description", "url": null}, {"source": "Reference", "type": "reference", "url": "https://github.com/crmeb/CRMEB"}, {"source": "Reference", "type": "reference", "url": "https://github.com/crmeb/CRMEB/issues/22"}, {"source": "Vendor Advisory", "type": "reference", "url": "http://crmeb.com"}, {"source": "Reference", "type": "reference", "url": "https://github.com/crmeb/CRMEB"}, {"source": "Reference", "type": "reference", "url": "https://github.com/crmeb/CRMEB/issues/22"}, {"source": "Official Reference", "type": "reference", "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-25466"}, {"source": "Official Reference", "type": "reference", "url": "https://osv.dev/vulnerability/CVE-2020-25466"}], "source_published_impact": "Source describes code execution review. Possible impact: An attacker may be able to run code or commands on affected systems.", "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.", "source_published_summary": "NVD: A SSRF vulnerability exists in the downloadimage interface of CRMEB 3.0, which can remotely download arbitrary files on the server and remotely execute arbitrary code. OSV: A SSRF vulnerability exists in the downloadimage interface of CRMEB 3.0, which can remotely download arbitrary files on the server and remotely execute arbitrary code.", "sources": ["NVD", "OSV", "Vendor Advisory"], "summary": "CVE-2020-25466 is a defensive prioritization candidate. NVD lists CVSS severity as CRITICAL. CVSS score is 9.8. EPSS score is 0.0303 with percentile 0.8589. Known exploited catalog status is not listed in NVD for this record. Use official advisories and vendor remediation references for defensive review.", "summary_ja": null, "title": "CVE-2020-25466 defensive priority signal", "title_ja": null, "translation": null, "updated_at": null, "urgency_reasons": ["CVSS CRITICAL", "affected product present", "vendor advisory present", "recent update", "remediation reference present"], "vendor": "crmeb", "what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "why_it_matters": "An attacker may be able to run code or commands on affected systems; CVSS 9.8 (CRITICAL); EPSS percentile 86; affected product context: crmeb / crmeb; sources: NVD, OSV, Vendor Advisory."}, {"affected_label": "daily_tracker_system_project / daily_tracker_system", "affected_products": [{"canonicalProduct": "daily_tracker_system", "canonicalVendor": "daily_tracker_system_project", "cpe": "cpe:2.3:a:daily_tracker_system_project:daily_tracker_system:1.0:*:*:*:*:*:*:*", "ecosystem": null, "packageName": null, "product": "daily_tracker_system", "purl": null, "vendor": "daily_tracker_system_project", "version": "1.0"}], "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2020-24193/", "cvss_score": 9.8, "cvss_severity": "CRITICAL", "data_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2020-24193.json", "defensive_priority": "Priority review candidate", "epss_percentile": 0.84557, "epss_score": 0.0277, "exposure_hint": "authenticated boundary", "human_consequence": "An attacker may be able to read or change database-backed application data.", "human_impact_label": "authentication boundary review · SQL injection risk · authenticated boundary", "human_risk_summary": "CVE-2020-24193 for daily_tracker_system_project / daily_tracker_system: An attacker may be able to read or change database-backed application data.", "id": "CVE-2020-24193", "impact_tags": ["authentication boundary review", "SQL injection risk", "authenticated boundary review"], "kev": false, "observed_at": "2026-07-08T03:39:09.814067+00:00", "product": "daily_tracker_system", "public_human_impact": "Source describes authentication boundary review · SQL injection risk · authenticated boundary. Possible impact: An attacker may be able to read or change database-backed application data.", "public_human_summary": "NVD: A SQL injection vulnerability in login in Sourcecodetester Daily Tracker System 1.0 allows unauthenticated user to execute authentication bypass with SQL injection via the email parameter.", "public_human_what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "public_human_why_it_matters": "Source describes authentication boundary review · SQL injection risk · authenticated boundary. Possible impact: An attacker may be able to read or change database-backed application data.; CVSS 9.8 (CRITICAL); EPSS percentile 85; not listed in KEV; Remediation reference present; patch status requires confirmation in the linked advisory; sources: NVD.", "public_safe_summary": "NVD: A SQL injection vulnerability in login in Sourcecodetester Daily Tracker System 1.0 allows unauthenticated user to execute authentication bypass with SQL injection via the email parameter.", "public_status": "public_safe", "published_at": null, "redaction_notes": ["source-published defensive context retained", "vulnerability class, impact, affected context, and remediation references remain displayable"], "remediation_handoff": {"auto_remediation_allowed": false, "codex_prompt_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-24193-codex-prompt.md", "external_execution_allowed": false, "human_approval_required": true, "json_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-24193.json", "markdown_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-24193.md", "scan_allowed": false}, "remediation_urls": ["https://nvd.nist.gov/vuln/detail/CVE-2020-24193"], "sort_priority": 98.84557, "source_copy_policy": {"allowed": "source-published defensive facts, vulnerability class, impact, affected context, version and remediation facts", "excluded": "exploit procedures, exploit strings, shell commands, scanner instructions, procedural bypass detail, and reproduction material", "summary": "Official or semi-official source descriptions may be summarized for defensive triage; exploit-enabling procedure is removed."}, "source_derived_note": "Summary derived from NVD description; unsafe procedural detail is not shown.", "source_label": "NVD, Vendor Advisory", "source_published_affected": "vendor/product: daily_tracker_system_project / daily_tracker_system; affected version context: 1.0", "source_published_description": "NVD: A SQL injection vulnerability in login in Sourcecodetester Daily Tracker System 1.0 allows unauthenticated user to execute authentication bypass with SQL injection via the email parameter.", "source_published_evidence_refs": [{"source": "NVD", "type": "source_description", "url": null}, {"source": "Reference", "type": "reference", "url": "https://www.exploit-db.com/exploits/48787"}, {"source": "Reference", "type": "reference", "url": "http://sourcecodetester.com"}, {"source": "Reference", "type": "reference", "url": "https://www.exploit-db.com/exploits/48787"}, {"source": "Official Reference", "type": "reference", "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-24193"}], "source_published_impact": "Source describes authentication boundary review · SQL injection risk · authenticated boundary. Possible impact: An attacker may be able to read or change database-backed application data.", "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.", "source_published_summary": "NVD: A SQL injection vulnerability in login in Sourcecodetester Daily Tracker System 1.0 allows unauthenticated user to execute authentication bypass with SQL injection via the email parameter.", "sources": ["NVD", "Vendor Advisory"], "summary": "CVE-2020-24193 is a defensive prioritization candidate. NVD lists CVSS severity as CRITICAL. CVSS score is 9.8. EPSS score is 0.0277 with percentile 0.8456. Known exploited catalog status is not listed in NVD for this record. Use official advisories and vendor remediation references for defensive review.", "summary_ja": null, "title": "CVE-2020-24193 defensive priority signal", "title_ja": null, "translation": null, "updated_at": null, "urgency_reasons": ["CVSS CRITICAL", "affected product present", "vendor advisory present", "recent update"], "vendor": "daily_tracker_system_project", "what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "why_it_matters": "An attacker may be able to read or change database-backed application data; CVSS 9.8 (CRITICAL); EPSS percentile 85; affected product context: daily_tracker_system_project / daily_tracker_system; sources: NVD."}, {"affected_label": "anixis / password_reset_client", "affected_products": [{"canonicalProduct": "password_reset_client", "canonicalVendor": "anixis", "cpe": "cpe:2.3:a:anixis:password_reset_client:*:*:*:*:*:*:*:*", "ecosystem": null, "packageName": null, "product": "password_reset_client", "purl": null, "vendor": "anixis", "version": null}], "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2018-5354/", "cvss_score": 8.8, "cvss_severity": "HIGH", "data_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2018-5354.json", "defensive_priority": "Continuous monitoring candidate", "epss_percentile": 0.83994, "epss_score": 0.02678, "exposure_hint": "remote exposure", "human_consequence": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary.", "human_impact_label": "remote exposure · authenticated boundary", "human_risk_summary": "CVE-2018-5354 for anixis / password_reset_client: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary.", "id": "CVE-2018-5354", "impact_tags": ["remote exposure relevant", "authenticated boundary review"], "kev": false, "observed_at": "2026-07-08T03:39:09.814067+00:00", "product": "password_reset_client", "public_human_impact": "Source describes remote exposure · authenticated boundary. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary.", "public_human_summary": "NVD: The custom GINA/CP module in ANIXIS Password Reset Client before version 3.22 allows remote attackers to execute code and escalate privileges via spoofing. NVD: When the client is configured to use HTTP, it does not authenticate the intended server before opening a browser window. NVD: An unauthenticated attacker capable of conducting a spoofing attack can redirect the browser to gain execution in the context of the WinLogon.exe process.", "public_human_what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "public_human_why_it_matters": "Source describes remote exposure · authenticated boundary. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary.; CVSS 8.8 (HIGH); EPSS percentile 84; not listed in KEV; Remediation reference present; patch status requires confirmation in the linked advisory; sources: NVD, Vendor Advisory.", "public_safe_summary": "NVD: The custom GINA/CP module in ANIXIS Password Reset Client before version 3.22 allows remote attackers to execute code and escalate privileges via spoofing. NVD: When the client is configured to use HTTP, it does not authenticate the intended server before opening a browser window. NVD: An unauthenticated attacker capable of conducting a spoofing attack can redirect the browser to gain execution in the context of the WinLogon.exe process.", "public_status": "public_safe", "published_at": null, "redaction_notes": ["source-published defensive context retained", "vulnerability class, impact, affected context, and remediation references remain displayable"], "remediation_handoff": {"auto_remediation_allowed": false, "codex_prompt_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2018-5354-codex-prompt.md", "external_execution_allowed": false, "human_approval_required": true, "json_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2018-5354.json", "markdown_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2018-5354.md", "scan_allowed": false}, "remediation_urls": ["http://anixis.com"], "sort_priority": 88.83994, "source_copy_policy": {"allowed": "source-published defensive facts, vulnerability class, impact, affected context, version and remediation facts", "excluded": "exploit procedures, exploit strings, shell commands, scanner instructions, procedural bypass detail, and reproduction material", "summary": "Official or semi-official source descriptions may be summarized for defensive triage; exploit-enabling procedure is removed."}, "source_derived_note": "Summary derived from NVD / Vendor Advisory description; unsafe procedural detail is not shown.", "source_label": "NVD, Vendor Advisory", "source_published_affected": "vendor/product: anixis / password_reset_client", "source_published_description": "NVD: The custom GINA/CP module in ANIXIS Password Reset Client before version 3.22 allows remote attackers to execute code and escalate privileges via spoofing. NVD: When the client is configured to use HTTP, it does not authenticate the intended server before opening a browser window. NVD: An unauthenticated attacker capable of conducting a spoofing attack can redirect the browser to gain execution in the context of the WinLogon.exe process.", "source_published_evidence_refs": [{"source": "NVD", "type": "source_description", "url": null}, {"source": "Vendor Advisory", "type": "source_description", "url": null}, {"source": "Reference", "type": "reference", "url": "https://github.com/missing0x00/CVE-2018-5354"}, {"source": "Vendor Advisory", "type": "reference", "url": "http://anixis.com"}, {"source": "Reference", "type": "reference", "url": "https://github.com/missing0x00/CVE-2018-5354"}, {"source": "Official Reference", "type": "reference", "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-5354"}], "source_published_impact": "Source describes remote exposure · authenticated boundary. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary.", "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.", "source_published_summary": "NVD: The custom GINA/CP module in ANIXIS Password Reset Client before version 3.22 allows remote attackers to execute code and escalate privileges via spoofing. NVD: When the client is configured to use HTTP, it does not authenticate the intended server before opening a browser window. NVD: An unauthenticated attacker capable of conducting a spoofing attack can redirect the browser to gain execution in the context of the WinLogon.exe process.", "sources": ["NVD", "Vendor Advisory"], "summary": "CVE-2018-5354 is a defensive prioritization candidate. NVD lists CVSS severity as HIGH. CVSS score is 8.8. EPSS score is 0.0268 with percentile 0.8399. Known exploited catalog status is not listed in NVD for this record. Use official advisories and vendor remediation references for defensive review.", "summary_ja": null, "title": "CVE-2018-5354 defensive priority signal", "title_ja": null, "translation": null, "updated_at": null, "urgency_reasons": ["CVSS HIGH", "affected product present", "vendor advisory present", "recent update", "remediation reference present"], "vendor": "anixis", "what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.", "why_it_matters": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary; CVSS 8.8 (HIGH); EPSS percentile 84; affected product context: anixis / password_reset_client; sources: NVD..."}], "vendorDistribution": {"anixis": 1, "crmeb": 1, "daily_tracker_system_project": 2, "debian": 1, "gazie_project": 1, "ilex": 1, "microweber": 1, "phpgurukul": 1, "rukovoditel": 1, "sagemcom": 1, "simple_library_management_system_project": 2, "snap7_project": 1, "spiceworks": 2, "verint": 1, "vmware": 1, "yourls": 1, "zohocorp": 1}}, "wellKnown": {"archive_index_url": "https://vuln.signal-radar.com/data/vuln/archive/index.json", "archive_latest_url": "https://vuln.signal-radar.com/data/vuln/archive/latest.json", "auto_remediation_allowed": false, "data_index_url": "https://vuln.signal-radar.com/data/vuln/index.json", "external_execution_allowed": false, "generated_at": "2026-07-08T03:43:17.030146+00:00", "github_issue_creation_allowed": false, "indexing_allowed": true, "machine_readable_surface": {"knowledge_graph_jsonld": {"content_type": "application/ld+json", "description": "JSON-LD graph of radar signals, source links, affected products, and trust metadata for agent-side provenance checks.", "enabled": true, "expected_shape": "@context plus @graph containing radar-specific vulnerability signal nodes", "primary_endpoint": "https://vuln.signal-radar.com/data/v1/graph/latest.jsonld", "well_known_endpoint": "https://vuln.signal-radar.com/.well-known/signal-graph.jsonld"}, "local_first_personal_data_vault": {"capabilities": ["import", "export", "clear", "shape validation"], "contains_public_signal_source_data": false, "description": "Browser-local vault for personal review context such as vendors, products, packages, CPE prefixes, saved signals, muted signals, and preferences.", "enabled": true, "network_behavior": "no fetch, XMLHttpRequest, sendBeacon, WebSocket, or EventSource", "server_sync": false, "storage": "localStorage"}, "purpose": "Expose public-safe vulnerability signals in formats that humans can inspect and AI agents can consume without mutation or external execution.", "rirastafab_trust_layer": {"attestation_ledger": "https://vuln.signal-radar.com/data/v1/attestations/vuln-signal-ledger.json", "canonical_envelope_index": "https://vuln.signal-radar.com/data/v1/proof/canonical-envelope-index.json", "description": "Read-only proof surface with hash-only integrity metadata, canonical envelopes, signed-JSON readiness, EAS preflight metadata, and attestation ledger endpoints.", "enabled": true, "external_submission_performed": false, "proof_latest": "https://vuln.signal-radar.com/data/v1/proof/latest.json", "proof_level": "hash-only", "trust_manifest": "https://vuln.signal-radar.com/.well-known/rirastafab-trust.json"}, "safety_boundary": {"auto_remediation_allowed": false, "external_execution_allowed": false, "github_issue_creation_allowed": false, "patch_allowed": false, "read_only": true, "runtime_server_endpoints": [], "scan_allowed": false}}, "mcp_http_endpoint": null, "pages_functions_enabled": false, "public_launch_allowed": true, "radar": "vuln", "read_only_static_data": true, "remediation_handoff": {"base_path": "/data/v1/remediation-handoff", "index_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/index.json", "item_count": 20, "packs": [{"auto_remediation_allowed": false, "codex_prompt_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2005-4459-codex-prompt.md", "cve_id": "CVE-2005-4459", "epss_percentile": 0.96028, "external_execution_allowed": false, "human_approval_required": true, "json_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2005-4459.json", "kev_status": "not_listed", "markdown_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2005-4459.md", "product": "ace", "recommended_route": "vendor_patch_or_mitigation", "scan_allowed": false, "severity": "CRITICAL", "vendor": "vmware"}, {"auto_remediation_allowed": false, "codex_prompt_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2018-5353-codex-prompt.md", "cve_id": "CVE-2018-5353", "epss_percentile": 0.94138, "external_execution_allowed": false, "human_approval_required": true, "json_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2018-5353.json", "kev_status": "not_listed", "markdown_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2018-5353.md", "product": "manageengine_adselfservice_plus", "recommended_route": "vendor_patch_or_mitigation", "scan_allowed": false, "severity": "CRITICAL", "vendor": "zohocorp"}, {"auto_remediation_allowed": false, "codex_prompt_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-25466-codex-prompt.md", "cve_id": "CVE-2020-25466", "epss_percentile": 0.85894, "external_execution_allowed": false, "human_approval_required": true, "json_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-25466.json", "kev_status": "not_listed", "markdown_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-25466.md", "product": "crmeb", "recommended_route": "vendor_patch_or_mitigation", "scan_allowed": false, "severity": "CRITICAL", "vendor": "crmeb"}, {"auto_remediation_allowed": false, "codex_prompt_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-24193-codex-prompt.md", "cve_id": "CVE-2020-24193", "epss_percentile": 0.84557, "external_execution_allowed": false, "human_approval_required": true, "json_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-24193.json", "kev_status": "not_listed", "markdown_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-24193.md", "product": "daily_tracker_system", "recommended_route": "vendor_patch_or_mitigation", "scan_allowed": false, "severity": "CRITICAL", "vendor": "daily_tracker_system_project"}, {"auto_remediation_allowed": false, "codex_prompt_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2018-5354-codex-prompt.md", "cve_id": "CVE-2018-5354", "epss_percentile": 0.83994, "external_execution_allowed": false, "human_approval_required": true, "json_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2018-5354.json", "kev_status": "not_listed", "markdown_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2018-5354.md", "product": "password_reset_client", "recommended_route": "vendor_patch_or_mitigation", "scan_allowed": false, "severity": "HIGH", "vendor": "anixis"}, {"auto_remediation_allowed": false, "codex_prompt_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-23451-codex-prompt.md", "cve_id": "CVE-2020-23451", "epss_percentile": 0.44482, "external_execution_allowed": false, "human_approval_required": true, "json_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-23451.json", "kev_status": "not_listed", "markdown_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-23451.md", "product": "spiceworks", "recommended_route": "vendor_patch_or_mitigation", "scan_allowed": false, "severity": "HIGH", "vendor": "spiceworks"}, {"auto_remediation_allowed": false, "codex_prompt_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-25514-codex-prompt.md", "cve_id": "CVE-2020-25514", "epss_percentile": 0.45772, "external_execution_allowed": false, "human_approval_required": true, "json_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-25514.json", "kev_status": "not_listed", "markdown_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-25514.md", "product": "simple_library_management_system", "recommended_route": "vendor_patch_or_mitigation", "scan_allowed": false, "severity": "HIGH", "vendor": "simple_library_management_system_project"}, {"auto_remediation_allowed": false, "codex_prompt_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-23968-codex-prompt.md", "cve_id": "CVE-2020-23968", "epss_percentile": 0.55043, "external_execution_allowed": false, "human_approval_required": true, "json_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-23968.json", "kev_status": "not_listed", "markdown_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-23968.md", "product": "international_sign\\&go", "recommended_route": "vendor_patch_or_mitigation", "scan_allowed": false, "severity": "HIGH", "vendor": "ilex"}, {"auto_remediation_allowed": false, "codex_prompt_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-25487-codex-prompt.md", "cve_id": "CVE-2020-25487", "epss_percentile": 0.42196, "external_execution_allowed": false, "human_approval_required": true, "json_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-25487.json", "kev_status": "not_listed", "markdown_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-25487.md", "product": "zoo_management_system", "recommended_route": "vendor_patch_or_mitigation", "scan_allowed": false, "severity": "HIGH", "vendor": "phpgurukul"}, {"auto_remediation_allowed": false, "codex_prompt_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-25515-codex-prompt.md", "cve_id": "CVE-2020-25515", "epss_percentile": 0.41554, "external_execution_allowed": false, "human_approval_required": true, "json_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-25515.json", "kev_status": "not_listed", "markdown_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-25515.md", "product": "simple_library_management_system", "recommended_route": "vendor_patch_or_mitigation", "scan_allowed": false, "severity": "HIGH", "vendor": "simple_library_management_system_project"}, {"auto_remediation_allowed": false, "codex_prompt_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2018-10902-codex-prompt.md", "cve_id": "CVE-2018-10902", "epss_percentile": 0.40562, "external_execution_allowed": false, "human_approval_required": true, "json_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2018-10902.json", "kev_status": "not_listed", "markdown_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2018-10902.md", "product": "debian_linux", "recommended_route": "vendor_patch_or_mitigation", "scan_allowed": false, "severity": "HIGH", "vendor": "debian"}, {"auto_remediation_allowed": false, "codex_prompt_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-22552-codex-prompt.md", "cve_id": "CVE-2020-22552", "epss_percentile": 0.78525, "external_execution_allowed": false, "human_approval_required": true, "json_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-22552.json", "kev_status": "not_listed", "markdown_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-22552.md", "product": "snap7", "recommended_route": "vendor_patch_or_mitigation", "scan_allowed": false, "severity": "HIGH", "vendor": "snap7_project"}, {"auto_remediation_allowed": false, "codex_prompt_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-21733-codex-prompt.md", "cve_id": "CVE-2020-21733", "epss_percentile": 0.58423, "external_execution_allowed": false, "human_approval_required": true, "json_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-21733.json", "kev_status": "not_listed", "markdown_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-21733.md", "product": "f\\@st_3686_firmware", "recommended_route": "vendor_patch_or_mitigation", "scan_allowed": false, "severity": "MEDIUM", "vendor": "sagemcom"}, {"auto_remediation_allowed": false, "codex_prompt_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-21731-codex-prompt.md", "cve_id": "CVE-2020-21731", "epss_percentile": 0.54231, "external_execution_allowed": false, "human_approval_required": true, "json_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-21731.json", "kev_status": "not_listed", "markdown_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-21731.md", "product": "gazie", "recommended_route": "vendor_patch_or_mitigation", "scan_allowed": false, "severity": "MEDIUM", "vendor": "gazie_project"}, {"auto_remediation_allowed": false, "codex_prompt_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-21732-codex-prompt.md", "cve_id": "CVE-2020-21732", "epss_percentile": 0.54231, "external_execution_allowed": false, "human_approval_required": true, "json_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-21732.json", "kev_status": "not_listed", "markdown_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-21732.md", "product": "rukovoditel", "recommended_route": "vendor_patch_or_mitigation", "scan_allowed": false, "severity": "MEDIUM", "vendor": "rukovoditel"}, {"auto_remediation_allowed": false, "codex_prompt_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-24194-codex-prompt.md", "cve_id": "CVE-2020-24194", "epss_percentile": 0.53283, "external_execution_allowed": false, "human_approval_required": true, "json_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-24194.json", "kev_status": "not_listed", "markdown_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-24194.md", "product": "daily_tracker_system", "recommended_route": "vendor_patch_or_mitigation", "scan_allowed": false, "severity": "MEDIUM", "vendor": "daily_tracker_system_project"}, {"auto_remediation_allowed": false, "codex_prompt_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-23136-codex-prompt.md", "cve_id": "CVE-2020-23136", "epss_percentile": 0.24698, "external_execution_allowed": false, "human_approval_required": true, "json_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-23136.json", "kev_status": "not_listed", "markdown_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-23136.md", "product": "microweber", "recommended_route": "vendor_patch_or_mitigation", "scan_allowed": false, "severity": "MEDIUM", "vendor": "microweber"}, {"auto_remediation_allowed": false, "codex_prompt_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-23450-codex-prompt.md", "cve_id": "CVE-2020-23450", "epss_percentile": 0.5158, "external_execution_allowed": false, "human_approval_required": true, "json_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-23450.json", "kev_status": "not_listed", "markdown_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-23450.md", "product": "spiceworks", "recommended_route": "vendor_patch_or_mitigation", "scan_allowed": false, "severity": "MEDIUM", "vendor": "spiceworks"}, {"auto_remediation_allowed": false, "codex_prompt_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-27388-codex-prompt.md", "cve_id": "CVE-2020-27388", "epss_percentile": 0.50603, "external_execution_allowed": false, "human_approval_required": true, "json_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-27388.json", "kev_status": "not_listed", "markdown_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-27388.md", "product": "yourls", "recommended_route": "vendor_patch_or_mitigation", "scan_allowed": false, "severity": "MEDIUM", "vendor": "yourls"}, {"auto_remediation_allowed": false, "codex_prompt_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-23446-codex-prompt.md", "cve_id": "CVE-2020-23446", "epss_percentile": 0.70416, "external_execution_allowed": false, "human_approval_required": true, "json_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-23446.json", "kev_status": "not_listed", "markdown_url": "https://vuln.signal-radar.com/data/v1/remediation-handoff/CVE-2020-23446.md", "product": "workforce_optimization", "recommended_route": "vendor_patch_or_mitigation", "scan_allowed": false, "severity": "MEDIUM", "vendor": "verint"}], "runtime_endpoint": false}, "runtime_endpoints": [], "schema_url": "https://vuln.signal-radar.com/data/vuln/schema.json", "schema_version": "v0.1", "search_console_registered": true, "signal_radar_integration_allowed": false, "source_health": {"deploy_mode": "fresh_fetch", "errors": [], "generated_at": "2026-07-08T03:39:09.827335+00:00", "normalized_count": 20, "note": "Latest public surface was generated from a successful safety-gated source fetch.", "public_safe_count": 20, "source_counts": {"epss": 20, "nvd": 20, "osv": 2}, "source_error_count": 0, "status": "healthy", "summary_available": true}, "trust_layer": {"attestation_ledger_envelope_url": "https://vuln.signal-radar.com/data/v1/proof/envelopes/attestation-ledger.json", "attestation_ledger_url": "https://vuln.signal-radar.com/data/v1/attestations/vuln-signal-ledger.json", "canonical_envelope_index_url": "https://vuln.signal-radar.com/data/v1/proof/canonical-envelope-index.json", "canonical_envelope_url": "https://vuln.signal-radar.com/data/v1/proof/canonical-envelope.json", "canonical_policy_url": "https://vuln.signal-radar.com/data/v1/proof/canonical-policy.json", "canonicalization_profile": "json-sort-keys-no-whitespace-v0", "eas_candidate_url": "https://vuln.signal-radar.com/data/v1/proof/eas-candidate.json", "eas_dry_run_status": "local_only", "eas_encoder_dry_run_url": "https://vuln.signal-radar.com/data/v1/proof/eas-encoder-dry-run.json", "eas_encoder_mode": "local_shape_check", "eas_mode": "reserved_offchain", "eas_preflight_url": "https://vuln.signal-radar.com/data/v1/proof/eas-preflight.json", "eas_rc_status": "frozen", "eas_rc_status_url": "https://vuln.signal-radar.com/data/v1/proof/eas-rc-status.json", "eas_schema_mapping_url": "https://vuln.signal-radar.com/data/v1/proof/eas-schema-mapping.json", "eas_schema_registration_status": "not_registered", "eas_sdk_adapter_contract_url": "https://vuln.signal-radar.com/data/v1/proof/eas-sdk-adapter-contract.json", "eas_sdk_encode_dry_run_url": "https://vuln.signal-radar.com/data/v1/proof/eas-sdk-encode-dry-run.json", "eas_sdk_execution_status": "not_available", "eas_status": "not_enabled", "eas_submission_status": "not_submitted", "eas_typed_payload_url": "https://vuln.signal-radar.com/data/v1/proof/eas-typed-payload.json", "external_call_performed": false, "manifest_url": "https://vuln.signal-radar.com/.well-known/rirastafab-trust.json", "proof_archive_index_url": "https://vuln.signal-radar.com/data/v1/proof/archive-index.json", "proof_latest_envelope_url": "https://vuln.signal-radar.com/data/v1/proof/envelopes/proof-latest.json", "proof_latest_url": "https://vuln.signal-radar.com/data/v1/proof/latest.json", "proof_level": "hash-only", "public_key_status": "not_available_until_signature_enabled", "public_key_url": "https://vuln.signal-radar.com/data/v1/proof/public-key.json", "remediation_proof_status": "not_enabled", "signal_graph_url": "https://vuln.signal-radar.com/data/v1/graph/latest.jsonld", "signature_algorithm": "Ed25519", "signature_status": "not_enabled", "signature_target_url": "https://vuln.signal-radar.com/data/v1/proof/canonical-envelope-index.json", "signed_json_ready": true, "signed_json_status_url": "https://vuln.signal-radar.com/data/v1/proof/signed-json-status.json", "signing_target_status": "preflight_frozen", "source_health_url": "https://vuln.signal-radar.com/data/v1/source-health.json", "status": "public_indexable", "trust_layer_eas_version": "0.3-rc", "trust_layer_version": "0.1", "trust_manifest_envelope_url": "https://vuln.signal-radar.com/data/v1/proof/envelopes/trust-manifest.json", "well_known_signal_graph_url": "https://vuln.signal-radar.com/.well-known/signal-graph.jsonld"}, "webmcp_runtime": {"annotations": {"readOnlyHint": true, "untrustedContentHint": true}, "api": "document.modelContext", "auto_remediation_allowed": false, "cross_origin_exposure_allowed": false, "deploy_allowed": false, "enabled": true, "endpoint": null, "exposed_to": [], "external_execution_allowed": false, "fallback_api": "navigator.modelContext", "fetch_allowed": false, "github_issue_creation_allowed": false, "mode": "browser_imperative_progressive_enhancement", "mutation_allowed": false, "planned": false, "scan_allowed": false, "tool_output_max_items": 10, "tool_output_target_max_chars": 1500, "tools": ["vuln_signal_search", "vuln_signal_get_item", "vuln_signal_list_priority"]}, "worker_enabled": false}}</template>
<script src="/assets/vuln/dashboard.js?v=20260708-vendor-wrap-1" defer></script>
</body></html>