{
  "append_only": true,
  "archive_index_url": "https://vuln.signal-radar.com/data/vuln/archive/index.json",
  "archive_version": "v0.1",
  "generated_at": "2026-08-10T16:21:56.094648+00:00",
  "immutable_run": true,
  "item_count": 20,
  "items": [
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15430/",
      "current_public_safe_latest": true,
      "cvss_score": 6.2,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.01293,
      "epss_score": 0.00107,
      "first_observed_at": "2026-08-10T16:12:24.021737+00:00",
      "id": "CVE-2026-15430",
      "impact_tags": [
        "privilege boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-10T16:12:24.021737+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-15430.json",
      "product": null,
      "public_safe_summary": "NVD: Improper access control in the IRP_MJ_WRITE command interface in Wellbia XIGNCODE3 xhunter2.sys, version 2026.6.1.192, allows a local, unprivileged attacker to achieve local privilege escalation to NT AUTHORITY\\SYSTEM, extract credentials from PPL-protected...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260810T162156Z/items/CVE-2026-15430.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes privilege escalation risk. Possible impact: An attacker may cross a privilege boundary and gain more access than intended.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Improper access control in the IRP_MJ_WRITE command interface in Wellbia XIGNCODE3 xhunter2.sys, version 2026.6.1.192, allows a local, unprivileged attacker to achieve local privilege escalation to NT AUTHORITY\\SYSTEM, extract credentials from PPL-protected...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15430/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-18248/",
      "current_public_safe_latest": true,
      "cvss_score": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.12234,
      "epss_score": 0.00218,
      "first_observed_at": "2026-08-10T16:12:24.021737+00:00",
      "id": "CVE-2026-18248",
      "impact_tags": [
        "privilege boundary review",
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-10T16:12:24.021737+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-18248.json",
      "product": null,
      "public_safe_summary": "NVD: @fastify/aws-lambda version 6.4.0 decorates each Fastify request with request.awsLambda.event and request.awsLambda.context, values that applications are documented to use for authorization decisions such as reading API Gateway authorizer claims. NVD: In the default configuration, the getter that populates this decoration reads the client-controlled x-apigateway-event and x-apigateway-context HTTP headers before falling back to the trusted internal request token, and those reserved headers are not stripped... NVD: An unauthenticated attacker who can set a single HTTP header can therefore forge the entire Lambda proxy event, including the authorizer context, and override the genuine one.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260810T162156Z/items/CVE-2026-18248.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes privilege escalation risk · remote exposure · authenticated boundary. Possible impact: A remote attacker may cross a privilege boundary and gain more access than intended.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: @fastify/aws-lambda version 6.4.0 decorates each Fastify request with request.awsLambda.event and request.awsLambda.context, values that applications are documented to use for authorization decisions such as reading API Gateway authorizer claims. NVD: In the default configuration, the getter that populates this decoration reads the client-controlled x-apigateway-event and x-apigateway-context HTTP headers before falling back to the trusted internal request token, and those reserved headers are not stripped... NVD: An unauthenticated attacker who can set a single HTTP header can therefore forge the entire Lambda proxy event, including the authorizer context, and override the genuine one.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-18248/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-18508/",
      "current_public_safe_latest": true,
      "cvss_score": 4.4,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.03565,
      "epss_score": 0.00137,
      "first_observed_at": "2026-08-10T16:12:24.021737+00:00",
      "id": "CVE-2026-18508",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-10T16:12:24.021737+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-18508.json",
      "product": null,
      "public_safe_summary": "NVD: A flaw was found in GNU tar. NVD: When extracting an archive with the --one-top-level option, hardlink targets are not confined to the designated top-level directory and may resolve relative to the extraction working directory. NVD: A crafted archive can create hardlinks that escape the intended boundary and, when combined with a preexisting symbolic link under the working directory, may allow writing outside that boundary during a single extraction.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260810T162156Z/items/CVE-2026-18508.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A flaw was found in GNU tar. NVD: When extracting an archive with the --one-top-level option, hardlink targets are not confined to the designated top-level directory and may resolve relative to the extraction working directory. NVD: A crafted archive can create hardlinks that escape the intended boundary and, when combined with a preexisting symbolic link under the working directory, may allow writing outside that boundary during a single extraction.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-18508/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "xml\\ / \\",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-18568/",
      "current_public_safe_latest": true,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.08907,
      "epss_score": 0.00191,
      "first_observed_at": "2026-08-10T16:12:24.021737+00:00",
      "id": "CVE-2026-18568",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-10T16:12:24.021737+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-18568.json",
      "product": "\\",
      "public_safe_summary": "NVD: XML::Sig versions from 0.29 before 0.72 for Perl allow signature verification bypass because verify returns true when every signature was skipped before any cryptographic check. NVD: verify in lib/XML/Sig.pm counts the //dsig:Signature elements into $numsigs and iterates over them, but two paths reach next before any digest or key check runs: a SignedInfo/Reference/@URI that resolves to no element while $numsigs is greater than 1, and... NVD: The loop records nothing about what it checked, so when every signature takes one of those paths control reaches the unconditional return 1 that ends verify.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260810T162156Z/items/CVE-2026-18568.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: xml\\ / \\; affected version context: sig_project",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: XML::Sig versions from 0.29 before 0.72 for Perl allow signature verification bypass because verify returns true when every signature was skipped before any cryptographic check. NVD: verify in lib/XML/Sig.pm counts the //dsig:Signature elements into $numsigs and iterates over them, but two paths reach next before any digest or key check runs: a SignedInfo/Reference/@URI that resolves to no element while $numsigs is greater than 1, and... NVD: The loop records nothing about what it checked, so when every signature takes one of those paths control reaches the unconditional return 1 that ends verify.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-18568/timeline.json",
      "vendor": "xml\\"
    },
    {
      "affected_label": "redhat / directory_server",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-18651/",
      "current_public_safe_latest": true,
      "cvss_score": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.06287,
      "epss_score": 0.00167,
      "first_observed_at": "2026-08-10T16:12:24.021737+00:00",
      "id": "CVE-2026-18651",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-10T16:12:24.021737+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-18651.json",
      "product": "directory_server",
      "public_safe_summary": "NVD: A flaw was found in 389 Directory Server. NVD: During SASL PLAIN authentication, the server installs connection-level bind credentials before performing the account-lock check. NVD: If the account is subsequently found to be locked, the bind is reported as failed to the client, but the already-installed authenticated state on the connection is not reverted.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260810T162156Z/items/CVE-2026-18651.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: redhat / directory_server; affected version context: -, 10.0, 11.0, 12.0, 13.0",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A flaw was found in 389 Directory Server. NVD: During SASL PLAIN authentication, the server installs connection-level bind credentials before performing the account-lock check. NVD: If the account is subsequently found to be locked, the bind is reported as failed to the client, but the already-installed authenticated state on the connection is not reverted.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-18651/timeline.json",
      "vendor": "redhat"
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-18243/",
      "current_public_safe_latest": true,
      "cvss_score": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.07977,
      "epss_score": 0.00182,
      "first_observed_at": "2026-08-10T16:12:24.021737+00:00",
      "id": "CVE-2026-18243",
      "impact_tags": [
        "XSS risk"
      ],
      "kev": false,
      "last_observed_at": "2026-08-10T16:12:24.021737+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-18243.json",
      "product": null,
      "public_safe_summary": "NVD: Certain HP DesignJet products may be potentially vulnerable to cross-site scripting (XSS), which may allow unauthenticated HTTP requests to view print job previews.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260810T162156Z/items/CVE-2026-18243.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes XSS risk. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Certain HP DesignJet products may be potentially vulnerable to cross-site scripting (XSS), which may allow unauthenticated HTTP requests to view print job previews.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-18243/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-18477/",
      "current_public_safe_latest": true,
      "cvss_score": 4.4,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.01227,
      "epss_score": 0.00105,
      "first_observed_at": "2026-08-10T16:12:24.021737+00:00",
      "id": "CVE-2026-18477",
      "impact_tags": [
        "privilege boundary review",
        "local exposure relevant"
      ],
      "kev": false,
      "last_observed_at": "2026-08-10T16:12:24.021737+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-18477.json",
      "product": null,
      "public_safe_summary": "NVD: A TOCTOU (Time-of-Check Time-of-Use) vulnerability in GNU tar's incremental dumpdir 'X' rename handling allows a local attacker with write access to a directory being backed up to influence the restore process if the attacker has access to the system where... NVD: During restoration, files or directories may be created, renamed or overwritten outside the intended extraction directory. NVD: This could lead to unauthorized file modification or, in some cases, privilege escalation.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260810T162156Z/items/CVE-2026-18477.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes privilege escalation risk · local exposure. Possible impact: A local user may cross a privilege boundary and gain more access than intended.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A TOCTOU (Time-of-Check Time-of-Use) vulnerability in GNU tar's incremental dumpdir 'X' rename handling allows a local attacker with write access to a directory being backed up to influence the restore process if the attacker has access to the system where... NVD: During restoration, files or directories may be created, renamed or overwritten outside the intended extraction directory. NVD: This could lead to unauthorized file modification or, in some cases, privilege escalation.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-18477/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-18602/",
      "current_public_safe_latest": true,
      "cvss_score": 8.9,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.78725,
      "epss_score": 0.01989,
      "first_observed_at": "2026-08-10T16:12:24.021737+00:00",
      "id": "CVE-2026-18602",
      "impact_tags": [
        "command injection risk"
      ],
      "kev": false,
      "last_observed_at": "2026-08-10T16:12:24.021737+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-18602.json",
      "product": null,
      "public_safe_summary": "NVD: A vulnerability was determined in GL.iNet GL-MT3000 up to 4.4.5. NVD: Affected is the function ovpn-client.get_recommend_config of the file /cgi-bin/glc of the component ovpn-client.so Native Plugin. NVD: Executing a manipulation of the argument Hostname can lead to command injection.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260810T162156Z/items/CVE-2026-18602.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes command injection risk. Possible impact: An attacker may be able to run unintended system commands through the affected component.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability was determined in GL.iNet GL-MT3000 up to 4.4.5. NVD: Affected is the function ovpn-client.get_recommend_config of the file /cgi-bin/glc of the component ovpn-client.so Native Plugin. NVD: Executing a manipulation of the argument Hostname can lead to command injection.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-18602/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-18604/",
      "current_public_safe_latest": true,
      "cvss_score": 1.9,
      "cvss_severity": "LOW",
      "epss_percentile": 0.01108,
      "epss_score": 0.00103,
      "first_observed_at": "2026-08-10T16:12:24.021737+00:00",
      "id": "CVE-2026-18604",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-10T16:12:24.021737+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-18604.json",
      "product": null,
      "public_safe_summary": "NVD: A vulnerability was identified in textPlus Text Message and Call App up to 8.3.5 on Android. NVD: This impacts the function DialerActivity of the component com.gogii.textplus. NVD: Such manipulation leads to improper export of android application components.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260810T162156Z/items/CVE-2026-18604.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability was identified in textPlus Text Message and Call App up to 8.3.5 on Android. NVD: This impacts the function DialerActivity of the component com.gogii.textplus. NVD: Such manipulation leads to improper export of android application components.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-18604/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-18605/",
      "current_public_safe_latest": true,
      "cvss_score": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.01889,
      "epss_score": 0.00116,
      "first_observed_at": "2026-08-10T16:12:24.021737+00:00",
      "id": "CVE-2026-18605",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-10T16:12:24.021737+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-18605.json",
      "product": null,
      "public_safe_summary": "NVD: A security flaw has been discovered in CheckMAL AppCheck Pro 3.1.43.10. NVD: Affected is an unknown function in the library AppCheckD.sys of the component Kernel Mini-Filter Driver. NVD: Performing a manipulation results in uncontrolled search path.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260810T162156Z/items/CVE-2026-18605.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A security flaw has been discovered in CheckMAL AppCheck Pro 3.1.43.10. NVD: Affected is an unknown function in the library AppCheckD.sys of the component Kernel Mini-Filter Driver. NVD: Performing a manipulation results in uncontrolled search path.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-18605/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-18606/",
      "current_public_safe_latest": true,
      "cvss_score": 7.1,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.01509,
      "epss_score": 0.00111,
      "first_observed_at": "2026-08-10T16:12:24.021737+00:00",
      "id": "CVE-2026-18606",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-10T16:12:24.021737+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-18606.json",
      "product": null,
      "public_safe_summary": "NVD: A weakness has been identified in Razer RzUpdateService 1.10.14.0. NVD: Affected by this vulnerability is an unknown functionality of the file C:\\Program Files (x86)\\Razer\\RzUpdateEngineService\\RzUpdateService.exe of the component Named Pipe Handler. NVD: Executing a manipulation of the argument lpThreadParameter can lead to improper privilege management.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260810T162156Z/items/CVE-2026-18606.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A weakness has been identified in Razer RzUpdateService 1.10.14.0. NVD: Affected by this vulnerability is an unknown functionality of the file C:\\Program Files (x86)\\Razer\\RzUpdateEngineService\\RzUpdateService.exe of the component Named Pipe Handler. NVD: Executing a manipulation of the argument lpThreadParameter can lead to improper privilege management.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-18606/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-18607/",
      "current_public_safe_latest": true,
      "cvss_score": 7.4,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.36042,
      "epss_score": 0.00438,
      "first_observed_at": "2026-08-10T16:12:24.021737+00:00",
      "id": "CVE-2026-18607",
      "impact_tags": [
        "memory safety review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-10T16:12:24.021737+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-18607.json",
      "product": null,
      "public_safe_summary": "NVD: A security vulnerability has been detected in Wavlink WN572, WN570H, WN573, WN529, WN530, WN531, WN535, etc. NVD: WN529, WN530, WN531, WN535, WN536, WN551, WN557 and NU516 up to 20260609. NVD: Affected by this issue is the function strcpy of the file upload.cgi of the component lighttpd.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260810T162156Z/items/CVE-2026-18607.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes memory safety review. Possible impact: The affected component has memory-safety risk that may lead to crash, privilege, or code-execution impact depending on exposure.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A security vulnerability has been detected in Wavlink WN572, WN570H, WN573, WN529, WN530, WN531, WN535, etc. NVD: WN529, WN530, WN531, WN535, WN536, WN551, WN557 and NU516 up to 20260609. NVD: Affected by this issue is the function strcpy of the file upload.cgi of the component lighttpd.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-18607/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-18610/",
      "current_public_safe_latest": true,
      "cvss_score": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.32478,
      "epss_score": 0.00397,
      "first_observed_at": "2026-08-10T16:12:24.021737+00:00",
      "id": "CVE-2026-18610",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-10T16:12:24.021737+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-18610.json",
      "product": null,
      "public_safe_summary": "NVD: A vulnerability was detected in NewType WebEIP up to 3.0. NVD: This affects an unknown part of the file /EIP_Com_FileList.aspx. NVD: The manipulation results in improper authentication.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260810T162156Z/items/CVE-2026-18610.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability was detected in NewType WebEIP up to 3.0. NVD: This affects an unknown part of the file /EIP_Com_FileList.aspx. NVD: The manipulation results in improper authentication.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-18610/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-18718/",
      "current_public_safe_latest": true,
      "cvss_score": 7.1,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.10763,
      "epss_score": 0.00206,
      "first_observed_at": "2026-08-10T16:12:24.021737+00:00",
      "id": "CVE-2026-18718",
      "impact_tags": [
        "code execution review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-10T16:12:24.021737+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-18718.json",
      "product": null,
      "public_safe_summary": "NVD: Ghidra contains an arbitrary code execution vulnerability in the Swift demangler analyzer that allows an attacker to execute arbitrary binaries by supplying a malicious Ghidra project with a crafted Swift tool directory path. NVD: When a victim opens the attacker-supplied project, SwiftDemanglerAnalyzer restores the persisted Swift binary directory from project state and SwiftNativeDemangler executes the resolved binary without integrity or signature verification, causing... OSV: Ghidra Swift Demangler Analyzer Arbitrary Code Execution via Project State",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260810T162156Z/items/CVE-2026-18718.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes code execution review. Possible impact: An attacker may be able to run code or commands on affected systems.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Ghidra contains an arbitrary code execution vulnerability in the Swift demangler analyzer that allows an attacker to execute arbitrary binaries by supplying a malicious Ghidra project with a crafted Swift tool directory path. NVD: When a victim opens the attacker-supplied project, SwiftDemanglerAnalyzer restores the persisted Swift binary directory from project state and SwiftNativeDemangler executes the resolved binary without integrity or signature verification, causing... OSV: Ghidra Swift Demangler Analyzer Arbitrary Code Execution via Project State",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-18718/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-39931/",
      "current_public_safe_latest": true,
      "cvss_score": 8.6,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.25212,
      "epss_score": 0.00327,
      "first_observed_at": "2026-08-10T16:12:24.021737+00:00",
      "id": "CVE-2026-39931",
      "impact_tags": [
        "SQL injection risk"
      ],
      "kev": false,
      "last_observed_at": "2026-08-10T16:12:24.021737+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-39931.json",
      "product": null,
      "public_safe_summary": "NVD: OpenEMR through 8.2.0 contains an authenticated SQL injection vulnerability in the backup configuration import feature that allows administrators with admin or super ACL privileges to execute arbitrary DDL and DML statements against the application database... NVD: Attackers can exploit the unfiltered shell_exec invocation of the mysql command-line client to extract credential hashes, modify access control tables, inject backdoor accounts, create persistent triggers or stored procedures, and write arbitrary files to the... OSV: OpenEMR Authenticated SQL Injection via backup.php Import Feature",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260810T162156Z/items/CVE-2026-39931.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes SQL injection risk. Possible impact: An attacker may be able to read or change database-backed application data.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: OpenEMR through 8.2.0 contains an authenticated SQL injection vulnerability in the backup configuration import feature that allows administrators with admin or super ACL privileges to execute arbitrary DDL and DML statements against the application database... NVD: Attackers can exploit the unfiltered shell_exec invocation of the mysql command-line client to extract credential hashes, modify access control tables, inject backdoor accounts, create persistent triggers or stored procedures, and write arbitrary files to the... OSV: OpenEMR Authenticated SQL Injection via backup.php Import Feature",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-39931/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-39932/",
      "current_public_safe_latest": true,
      "cvss_score": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.52313,
      "epss_score": 0.00773,
      "first_observed_at": "2026-08-10T16:12:24.021737+00:00",
      "id": "CVE-2026-39932",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-10T16:12:24.021737+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-39932.json",
      "product": null,
      "public_safe_summary": "NVD: OpenEMR through 8.2.0 contains a remote code execution vulnerability in the document category tree component (library/classes/Tree.class.php) that allows authenticated administrators to execute arbitrary operating system commands by injecting PHP payloads... OSV: OpenEMR 8.2.0 Remote Code Execution via CategoryTree eval() Injection OSV: OpenEMR through 8.2.0 contains a remote code execution vulnerability in the document category tree component (library/classes/Tree.class.php) that allows authenticated administrators to execute arbitrary operating system commands by injecting PHP payloads...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260810T162156Z/items/CVE-2026-39932.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: OpenEMR through 8.2.0 contains a remote code execution vulnerability in the document category tree component (library/classes/Tree.class.php) that allows authenticated administrators to execute arbitrary operating system commands by injecting PHP payloads... OSV: OpenEMR 8.2.0 Remote Code Execution via CategoryTree eval() Injection OSV: OpenEMR through 8.2.0 contains a remote code execution vulnerability in the document category tree component (library/classes/Tree.class.php) that allows authenticated administrators to execute arbitrary operating system commands by injecting PHP payloads...",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-39932/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-41452/",
      "current_public_safe_latest": true,
      "cvss_score": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.48116,
      "epss_score": 0.00658,
      "first_observed_at": "2026-08-10T16:12:24.021737+00:00",
      "id": "CVE-2026-41452",
      "impact_tags": [
        "remote exposure relevant"
      ],
      "kev": false,
      "last_observed_at": "2026-08-10T16:12:24.021737+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-41452.json",
      "product": null,
      "public_safe_summary": "NVD: Krayin CRM 2.2.4 contains a missing authentication vulnerability in the installer middleware that allows unauthenticated remote attackers to overwrite the primary administrator account by sending a crafted HTTP POST request with the X-Requested-With... NVD: Attackers can supply arbitrary name, email, and password values to the admin-config-setup endpoint, which performs an unauthenticated updateOrInsert targeting the hardcoded administrator user ID, enabling full administrative access to all CRM data. OSV: Krayin CRM 2.2.4 Missing Authentication via install/api/admin-config-setup",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260810T162156Z/items/CVE-2026-41452.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes remote exposure. Possible impact: This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Krayin CRM 2.2.4 contains a missing authentication vulnerability in the installer middleware that allows unauthenticated remote attackers to overwrite the primary administrator account by sending a crafted HTTP POST request with the X-Requested-With... NVD: Attackers can supply arbitrary name, email, and password values to the admin-config-setup endpoint, which performs an unauthenticated updateOrInsert targeting the hardcoded administrator user ID, enabling full administrative access to all CRM data. OSV: Krayin CRM 2.2.4 Missing Authentication via install/api/admin-config-setup",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-41452/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-41453/",
      "current_public_safe_latest": true,
      "cvss_score": 8.7,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.27699,
      "epss_score": 0.0035,
      "first_observed_at": "2026-08-10T16:12:24.021737+00:00",
      "id": "CVE-2026-41453",
      "impact_tags": [
        "SQL injection risk",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-10T16:12:24.021737+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-41453.json",
      "product": null,
      "public_safe_summary": "NVD: Krayin CRM before 2.2.4 contains a blind SQL injection vulnerability in the leads DataGrid that allows authenticated users with leads access to inject arbitrary SQL into a HAVING clause by manipulating the rotten_lead[in] query parameter, which is... NVD: Attackers can exploit this flaw using time-based and boolean-based blind injection techniques to extract the entire database contents, including user credential hashes, CRM records, and application configuration data. OSV: Krayin CRM < 2.2.4 Blind SQL Injection via LeadDataGrid.php rotten_lead Parameter",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260810T162156Z/items/CVE-2026-41453.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes SQL injection risk · authenticated boundary. Possible impact: An attacker may be able to read or change database-backed application data.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Krayin CRM before 2.2.4 contains a blind SQL injection vulnerability in the leads DataGrid that allows authenticated users with leads access to inject arbitrary SQL into a HAVING clause by manipulating the rotten_lead[in] query parameter, which is... NVD: Attackers can exploit this flaw using time-based and boolean-based blind injection techniques to extract the entire database contents, including user credential hashes, CRM records, and application configuration data. OSV: Krayin CRM < 2.2.4 Blind SQL Injection via LeadDataGrid.php rotten_lead Parameter",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-41453/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "apache / jena_fuseki",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-61372/",
      "current_public_safe_latest": true,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.43954,
      "epss_score": 0.00568,
      "first_observed_at": "2026-08-10T16:12:24.021737+00:00",
      "id": "CVE-2026-61372",
      "impact_tags": [
        "path traversal review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-10T16:12:24.021737+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-61372.json",
      "product": "jena_fuseki",
      "public_safe_summary": "NVD: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache Jena Fuseki. NVD: This issue affects Apache Jena Fuseki: through 6.1.0. NVD: Users are recommended to upgrade to version 6.2.0, which fixes the issue.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260810T162156Z/items/CVE-2026-61372.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: apache / jena_fuseki",
      "source_published_impact": "Source describes path traversal review. Possible impact: An attacker may be able to reach files outside the intended application path.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache Jena Fuseki. NVD: This issue affects Apache Jena Fuseki: through 6.1.0. NVD: Users are recommended to upgrade to version 6.2.0, which fixes the issue.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-61372/timeline.json",
      "vendor": "apache"
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-67610/",
      "current_public_safe_latest": true,
      "cvss_score": 8.6,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.25103,
      "epss_score": 0.00326,
      "first_observed_at": "2026-08-10T16:12:24.021737+00:00",
      "id": "CVE-2026-67610",
      "impact_tags": [
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-10T16:12:24.021737+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-67610.json",
      "product": null,
      "public_safe_summary": "NVD: OpenEMR through 8.2.0 contains an improper authentication vulnerability in the OAuth2 dynamic client registration endpoint that allows unauthenticated attackers to register a malicious client with system-level FHIR scopes by supplying a self-generated RSA... NVD: Once an administrator approves the registered client, attackers can use the client_credentials grant with a self-signed JWT assertion to obtain access tokens granting read access to all FHIR resources across all patients in the system. OSV: OpenEMR 8.2.0 OAuth2 Dynamic Client Registration Unauthorized FHIR Access",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260810T162156Z/items/CVE-2026-67610.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes remote exposure · authenticated boundary. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: OpenEMR through 8.2.0 contains an improper authentication vulnerability in the OAuth2 dynamic client registration endpoint that allows unauthenticated attackers to register a malicious client with system-level FHIR scopes by supplying a self-generated RSA... NVD: Once an administrator approves the registered client, attackers can use the client_credentials grant with a self-signed JWT assertion to obtain access tokens granting read access to all FHIR resources across all patients in the system. OSV: OpenEMR 8.2.0 OAuth2 Dynamic Client Registration Unauthorized FHIR Access",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-67610/timeline.json",
      "vendor": null
    }
  ],
  "public_safe_only": true,
  "radar": "vuln",
  "run_id": "20260810T162156Z",
  "run_index_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260810T162156Z/index.json",
  "safety": {
    "auto_remediation_allowed": false,
    "exploit_detail_allowed": false,
    "external_execution_allowed": false,
    "github_issue_creation_allowed": false,
    "indexing_allowed": true,
    "noindex_removal_allowed": true,
    "noindex_required": false,
    "patch_allowed": false,
    "public_launch_allowed": true,
    "public_safe_only": true,
    "raw_source_included": false,
    "read_only": true,
    "scan_allowed": false,
    "search_console_registered": true,
    "signal_radar_integration_allowed": false
  },
  "schema_version": "v0.1"
}