{
  "append_only": true,
  "archive_index_url": "https://vuln.signal-radar.com/data/vuln/archive/index.json",
  "archive_version": "v0.1",
  "generated_at": "2026-08-12T05:14:28.122778+00:00",
  "immutable_run": true,
  "item_count": 20,
  "items": [
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-18900/",
      "current_public_safe_latest": true,
      "cvss_score": 7.3,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.8235,
      "epss_score": 0.02384,
      "first_observed_at": "2026-08-12T05:08:50.991993+00:00",
      "id": "CVE-2026-18900",
      "impact_tags": [
        "command injection risk"
      ],
      "kev": false,
      "last_observed_at": "2026-08-12T05:08:50.991993+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-18900.json",
      "product": null,
      "public_safe_summary": "NVD: A weakness has been identified in H3C NX15 V100R017. NVD: This impacts the function file.exec of the file /api/esps of the component Backend RPC. NVD: This manipulation of the argument File causes os command injection.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260812T051428Z/items/CVE-2026-18900.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes command injection risk. Possible impact: An attacker may be able to run unintended system commands through the affected component.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A weakness has been identified in H3C NX15 V100R017. NVD: This impacts the function file.exec of the file /api/esps of the component Backend RPC. NVD: This manipulation of the argument File causes os command injection.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-18900/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-18901/",
      "current_public_safe_latest": true,
      "cvss_score": 7.3,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.37337,
      "epss_score": 0.00454,
      "first_observed_at": "2026-08-12T05:08:50.991993+00:00",
      "id": "CVE-2026-18901",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-12T05:08:50.991993+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-18901.json",
      "product": null,
      "public_safe_summary": "NVD: A security vulnerability has been detected in H3C NX15 V100R017. NVD: Affected is the function service.add of the file /api/esps of the component Web API. NVD: Such manipulation leads to exposed dangerous routine.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260812T051428Z/items/CVE-2026-18901.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A security vulnerability has been detected in H3C NX15 V100R017. NVD: Affected is the function service.add of the file /api/esps of the component Web API. NVD: Such manipulation leads to exposed dangerous routine.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-18901/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-11421/",
      "current_public_safe_latest": true,
      "cvss_score": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.25421,
      "epss_score": 0.00328,
      "first_observed_at": "2026-08-12T05:08:50.991993+00:00",
      "id": "CVE-2026-11421",
      "impact_tags": [
        "information exposure review",
        "SQL injection risk",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-12T05:08:50.991993+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-11421.json",
      "product": null,
      "public_safe_summary": "NVD: The ERP: Complete HR, Accounting & CRM Suite with WooCommerce CRM Support plugin for WordPress is vulnerable to SQL Injection via the 'erpadvancefilter' parameter in all versions up to, and including, 1.17.4 due to insufficient escaping on the user supplied... NVD: The handler runs the value through sanitize_text_field, which preserves single quotes, and the downstream erp_crm_contact_advance_filter() function interpolates it directly into a single-quoted SQL WHERE clause before execution via $wpdb->get_results(). NVD: This makes it possible for authenticated attackers, with the plugin-supplied CRM Agent role (or higher CRM Manager / WordPress admin) and the erp_crm_list_contact capability, to append additional SQL queries into already existing queries that can be used to...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260812T051428Z/items/CVE-2026-11421.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes information exposure review · SQL injection risk · authenticated boundary. Possible impact: An attacker may be able to read or change database-backed application data.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The ERP: Complete HR, Accounting & CRM Suite with WooCommerce CRM Support plugin for WordPress is vulnerable to SQL Injection via the 'erpadvancefilter' parameter in all versions up to, and including, 1.17.4 due to insufficient escaping on the user supplied... NVD: The handler runs the value through sanitize_text_field, which preserves single quotes, and the downstream erp_crm_contact_advance_filter() function interpolates it directly into a single-quoted SQL WHERE clause before execution via $wpdb->get_results(). NVD: This makes it possible for authenticated attackers, with the plugin-supplied CRM Agent role (or higher CRM Manager / WordPress admin) and the erp_crm_list_contact capability, to append additional SQL queries into already existing queries that can be used to...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-11421/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15918/",
      "current_public_safe_latest": true,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.31699,
      "epss_score": 0.00388,
      "first_observed_at": "2026-08-12T05:08:50.991993+00:00",
      "id": "CVE-2026-15918",
      "impact_tags": [
        "information exposure review",
        "SQL injection risk"
      ],
      "kev": false,
      "last_observed_at": "2026-08-12T05:08:50.991993+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-15918.json",
      "product": null,
      "public_safe_summary": "NVD: VikAppointments Service Booking Calendar wordpress plugin is vulnerable to unauthenticated SQL injection due to one of the parameters that controls how the public reviews list is sorted is taken from the incoming request and used to build a database query... NVD: Because this value is placed directly into the query, an attacker who is not logged in can inject arbitrary SQL through a normal booking page and read data from the site's database — including sensitive information such as WordPress user credentials. NVD: No authentication or special privileges are required",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260812T051428Z/items/CVE-2026-15918.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes information exposure review · SQL injection risk. Possible impact: An attacker may be able to read or change database-backed application data.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: VikAppointments Service Booking Calendar wordpress plugin is vulnerable to unauthenticated SQL injection due to one of the parameters that controls how the public reviews list is sorted is taken from the incoming request and used to build a database query... NVD: Because this value is placed directly into the query, an attacker who is not logged in can inject arbitrary SQL through a normal booking page and read data from the site's database — including sensitive information such as WordPress user credentials. NVD: No authentication or special privileges are required",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15918/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15941/",
      "current_public_safe_latest": true,
      "cvss_score": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.16307,
      "epss_score": 0.00249,
      "first_observed_at": "2026-08-12T05:08:50.991993+00:00",
      "id": "CVE-2026-15941",
      "impact_tags": [
        "SQL injection risk"
      ],
      "kev": false,
      "last_observed_at": "2026-08-12T05:08:50.991993+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-15941.json",
      "product": null,
      "public_safe_summary": "NVD: The plugin provides an Admin Search page that allows users with the edit_posts capability to run Relevanssi searches from the WordPress dashboard. NVD: The AJAX handler accepts a URL-encoded args parameter, parses it into a WP_Query, and then passes user-controlled taxonomy query data into Relevanssi's taxonomy restriction builder. NVD: The taxonomy value is sanitized as text but is not parameterized for SQL before being interpolated into a term taxonomy lookup query.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260812T051428Z/items/CVE-2026-15941.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes SQL injection risk. Possible impact: An attacker may be able to read or change database-backed application data.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The plugin provides an Admin Search page that allows users with the edit_posts capability to run Relevanssi searches from the WordPress dashboard. NVD: The AJAX handler accepts a URL-encoded args parameter, parses it into a WP_Query, and then passes user-controlled taxonomy query data into Relevanssi's taxonomy restriction builder. NVD: The taxonomy value is sanitized as text but is not parameterized for SQL before being interpolated into a term taxonomy lookup query.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15941/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-16143/",
      "current_public_safe_latest": true,
      "cvss_score": 7.2,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.14719,
      "epss_score": 0.00236,
      "first_observed_at": "2026-08-12T05:08:50.991993+00:00",
      "id": "CVE-2026-16143",
      "impact_tags": [
        "XSS risk",
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-12T05:08:50.991993+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-16143.json",
      "product": null,
      "public_safe_summary": "NVD: The VikRentItems – Flexible Rental Management System plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the customer email field of the booking checkout form in versions up to, and including, 1.2.1. NVD: This is due to insufficient input sanitization and output escaping in the saveorder() function, which stores the raw email value via VikRequest::getString() (applying only sanitize_text_field(), which does not neutralize HTML attribute-breaking characters... NVD: This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260812T051428Z/items/CVE-2026-16143.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes XSS risk · remote exposure · authenticated boundary. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk · remote exposure · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The VikRentItems – Flexible Rental Management System plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the customer email field of the booking checkout form in versions up to, and including, 1.2.1. NVD: This is due to insufficient input sanitization and output escaping in the saveorder() function, which stores the raw email value via VikRequest::getString() (applying only sanitize_text_field(), which does not neutralize HTML attribute-breaking characters... NVD: This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-16143/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-18322/",
      "current_public_safe_latest": true,
      "cvss_score": 8.8,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.23888,
      "epss_score": 0.00314,
      "first_observed_at": "2026-08-12T05:08:50.991993+00:00",
      "id": "CVE-2026-18322",
      "impact_tags": [
        "privilege boundary review",
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-12T05:08:50.991993+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-18322.json",
      "product": null,
      "public_safe_summary": "NVD: The Smart Popup by Supsystic plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.12.0. NVD: This is due to a permission map collision in the havePermissions() function in classes/frame.php, where array_merge() overwrites the popup module's administrator-restricted method list with the base controller's value, silently removing save from protected... NVD: This makes it possible for unauthenticated attackers to submit a crafted POST request to admin-ajax.php using a nonce obtained from a public subscription confirmation email, setting params[tpl][sub_wp_create_user_role] to administrator via the exposed...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260812T051428Z/items/CVE-2026-18322.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes privilege escalation risk · remote exposure · authenticated boundary. Possible impact: A remote attacker may cross a privilege boundary and gain more access than intended.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Smart Popup by Supsystic plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.12.0. NVD: This is due to a permission map collision in the havePermissions() function in classes/frame.php, where array_merge() overwrites the popup module's administrator-restricted method list with the base controller's value, silently removing save from protected... NVD: This makes it possible for unauthenticated attackers to submit a crafted POST request to admin-ajax.php using a nonce obtained from a public subscription confirmation email, setting params[tpl][sub_wp_create_user_role] to administrator via the exposed...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-18322/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-18902/",
      "current_public_safe_latest": true,
      "cvss_score": 7.3,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.8235,
      "epss_score": 0.02384,
      "first_observed_at": "2026-08-12T05:08:50.991993+00:00",
      "id": "CVE-2026-18902",
      "impact_tags": [
        "command injection risk"
      ],
      "kev": false,
      "last_observed_at": "2026-08-12T05:08:50.991993+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-18902.json",
      "product": null,
      "public_safe_summary": "NVD: A vulnerability was detected in H3C NX15 V100R017. NVD: Affected by this vulnerability is the function esps.wan.repeater.set/repeaterproc of the file /api/esps. NVD: Performing a manipulation of the argument my2P4key results in command injection.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260812T051428Z/items/CVE-2026-18902.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes command injection risk. Possible impact: An attacker may be able to run unintended system commands through the affected component.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability was detected in H3C NX15 V100R017. NVD: Affected by this vulnerability is the function esps.wan.repeater.set/repeaterproc of the file /api/esps. NVD: Performing a manipulation of the argument my2P4key results in command injection.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-18902/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-18903/",
      "current_public_safe_latest": true,
      "cvss_score": 2.1,
      "cvss_severity": "LOW",
      "epss_percentile": 0.28568,
      "epss_score": 0.00357,
      "first_observed_at": "2026-08-12T05:08:50.991993+00:00",
      "id": "CVE-2026-18903",
      "impact_tags": [
        "path traversal review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-12T05:08:50.991993+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-18903.json",
      "product": null,
      "public_safe_summary": "NVD: A vulnerability was determined in yeqifu warehouse up to aaf29962ba407d22d991781de28796ee7b4670e4. NVD: This issue affects some unknown processing of the file src/main/java/com/yeqifu/sys/controller/FileController.java. NVD: This manipulation of the argument path causes path traversal.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260812T051428Z/items/CVE-2026-18903.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes path traversal review. Possible impact: An attacker may be able to reach files outside the intended application path.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability was determined in yeqifu warehouse up to aaf29962ba407d22d991781de28796ee7b4670e4. NVD: This issue affects some unknown processing of the file src/main/java/com/yeqifu/sys/controller/FileController.java. NVD: This manipulation of the argument path causes path traversal.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-18903/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-55707/",
      "current_public_safe_latest": true,
      "cvss_score": 7.1,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.39474,
      "epss_score": 0.00487,
      "first_observed_at": "2026-08-12T05:08:50.991993+00:00",
      "id": "CVE-2026-55707",
      "impact_tags": [
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-12T05:08:50.991993+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-55707.json",
      "product": null,
      "public_safe_summary": "NVD: In OpenStack Neutron before 28.0.2, the subnetpool onboarding API does not verify ownership of the target subnets. NVD: An authenticated user can onboard subnets from another project's shared network into their own subnetpool, mutating the victim's subnet state and altering L3 routing and address scope behavior for victim routers.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260812T051428Z/items/CVE-2026-55707.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes authenticated boundary. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: In OpenStack Neutron before 28.0.2, the subnetpool onboarding API does not verify ownership of the target subnets. NVD: An authenticated user can onboard subnets from another project's shared network into their own subnetpool, mutating the victim's subnet state and altering L3 routing and address scope behavior for victim routers.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-55707/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-5062/",
      "current_public_safe_latest": true,
      "cvss_score": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.1866,
      "epss_score": 0.00266,
      "first_observed_at": "2026-08-12T05:08:50.991993+00:00",
      "id": "CVE-2026-5062",
      "impact_tags": [
        "information exposure review",
        "SQL injection risk",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-12T05:08:50.991993+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-5062.json",
      "product": null,
      "public_safe_summary": "NVD: The PrettyLinks – Affiliate Links, Link Branding, Link Tracking, Marketing and Stripe Payments Plugin plugin for WordPress is vulnerable to SQL Injection via the 's' (search) parameter on the Pretty Links listing page in all versions up to, and including... NVD: This is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query in the search_links_table() function. NVD: This makes it possible for authenticated attackers, with Administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260812T051428Z/items/CVE-2026-5062.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes information exposure review · SQL injection risk · authenticated boundary. Possible impact: An attacker may be able to read or change database-backed application data.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The PrettyLinks – Affiliate Links, Link Branding, Link Tracking, Marketing and Stripe Payments Plugin plugin for WordPress is vulnerable to SQL Injection via the 's' (search) parameter on the Pretty Links listing page in all versions up to, and including... NVD: This is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query in the search_links_table() function. NVD: This makes it possible for authenticated attackers, with Administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-5062/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "apache / qpid_proton-j",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-66257/",
      "current_public_safe_latest": true,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.35249,
      "epss_score": 0.00426,
      "first_observed_at": "2026-08-12T05:08:50.991993+00:00",
      "id": "CVE-2026-66257",
      "impact_tags": [
        "service availability review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-12T05:08:50.991993+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-66257.json",
      "product": "qpid_proton-j",
      "public_safe_summary": "NVD: A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service. NVD: This issue affects Apache Qpid Proton-J: through 0.34.1. NVD: Users are recommended to upgrade to version 0.35.0, which fixes the issue.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260812T051428Z/items/CVE-2026-66257.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: apache / qpid_proton-j",
      "source_published_impact": "Source describes service availability risk. Possible impact: The affected service may become unavailable or unreliable.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service. NVD: This issue affects Apache Qpid Proton-J: through 0.34.1. NVD: Users are recommended to upgrade to version 0.35.0, which fixes the issue.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-66257/timeline.json",
      "vendor": "apache"
    },
    {
      "affected_label": "apache / qpid_proton-j",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-66273/",
      "current_public_safe_latest": true,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.35249,
      "epss_score": 0.00426,
      "first_observed_at": "2026-08-12T05:08:50.991993+00:00",
      "id": "CVE-2026-66273",
      "impact_tags": [
        "service availability review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-12T05:08:50.991993+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-66273.json",
      "product": "qpid_proton-j",
      "public_safe_summary": "NVD: A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service. NVD: This issue affects Apache Qpid Proton-J: through 0.34.1. NVD: Users are recommended to upgrade to version 0.35.0, which fixes the issue.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260812T051428Z/items/CVE-2026-66273.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: apache / qpid_proton-j",
      "source_published_impact": "Source describes service availability risk. Possible impact: The affected service may become unavailable or unreliable.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service. NVD: This issue affects Apache Qpid Proton-J: through 0.34.1. NVD: Users are recommended to upgrade to version 0.35.0, which fixes the issue.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-66273/timeline.json",
      "vendor": "apache"
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-66344/",
      "current_public_safe_latest": true,
      "cvss_score": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.01883,
      "epss_score": 0.00116,
      "first_observed_at": "2026-08-12T05:08:50.991993+00:00",
      "id": "CVE-2026-66344",
      "impact_tags": [
        "code execution review",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-12T05:08:50.991993+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-66344.json",
      "product": null,
      "public_safe_summary": "NVD: NetKids iMark, provided by Integrated Systems Technologies, Inc., contains an Uncontrolled Search Path Element vulnerability (CWE-427). NVD: An authenticated attacker may exploit this vulnerability to execute arbitrary code with SYSTEM privileges.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260812T051428Z/items/CVE-2026-66344.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes code execution review · authenticated boundary. Possible impact: An attacker may be able to run code or commands on affected systems.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: NetKids iMark, provided by Integrated Systems Technologies, Inc., contains an Uncontrolled Search Path Element vulnerability (CWE-427). NVD: An authenticated attacker may exploit this vulnerability to execute arbitrary code with SYSTEM privileges.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-66344/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-66839/",
      "current_public_safe_latest": true,
      "cvss_score": 8.4,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.034,
      "epss_score": 0.00135,
      "first_observed_at": "2026-08-12T05:08:50.991993+00:00",
      "id": "CVE-2026-66839",
      "impact_tags": [
        "code execution review",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-12T05:08:50.991993+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-66839.json",
      "product": null,
      "public_safe_summary": "NVD: NetKids iMark, provided by Integrated Systems Technologies, Inc., contains an Unquoted Search Path or Element vulnerability (CWE-428). NVD: An authenticated attacker may exploit this vulnerability to execute arbitrary code with SYSTEM privileges.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260812T051428Z/items/CVE-2026-66839.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes code execution review · authenticated boundary. Possible impact: An attacker may be able to run code or commands on affected systems.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: NetKids iMark, provided by Integrated Systems Technologies, Inc., contains an Unquoted Search Path or Element vulnerability (CWE-428). NVD: An authenticated attacker may exploit this vulnerability to execute arbitrary code with SYSTEM privileges.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-66839/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "apache / qpid_proton-dotnet",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-67465/",
      "current_public_safe_latest": true,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.39834,
      "epss_score": 0.00493,
      "first_observed_at": "2026-08-12T05:08:50.991993+00:00",
      "id": "CVE-2026-67465",
      "impact_tags": [
        "service availability review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-12T05:08:50.991993+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-67465.json",
      "product": "qpid_proton-dotnet",
      "public_safe_summary": "NVD: A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service. NVD: This issue affects Apache Qpid Proton-Dotnet: through 1.0.0. NVD: Users are recommended to upgrade to version 1.1.0, which fixes the issue.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260812T051428Z/items/CVE-2026-67465.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: apache / qpid_proton-dotnet",
      "source_published_impact": "Source describes service availability risk. Possible impact: The affected service may become unavailable or unreliable.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service. NVD: This issue affects Apache Qpid Proton-Dotnet: through 1.0.0. NVD: Users are recommended to upgrade to version 1.1.0, which fixes the issue.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-67465/timeline.json",
      "vendor": "apache"
    },
    {
      "affected_label": "apache / qpid_proton-dotnet",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-67551/",
      "current_public_safe_latest": true,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.39835,
      "epss_score": 0.00493,
      "first_observed_at": "2026-08-12T05:08:50.991993+00:00",
      "id": "CVE-2026-67551",
      "impact_tags": [
        "service availability review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-12T05:08:50.991993+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-67551.json",
      "product": "qpid_proton-dotnet",
      "public_safe_summary": "NVD: pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service. NVD: This issue affects Apache Qpid Proton-Dotnet: through 1.0.0. NVD: Users are recommended to upgrade to version 1.1.0, which fixes the issue.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260812T051428Z/items/CVE-2026-67551.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: apache / qpid_proton-dotnet",
      "source_published_impact": "Source describes service availability risk. Possible impact: The affected service may become unavailable or unreliable.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service. NVD: This issue affects Apache Qpid Proton-Dotnet: through 1.0.0. NVD: Users are recommended to upgrade to version 1.1.0, which fixes the issue.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-67551/timeline.json",
      "vendor": "apache"
    },
    {
      "affected_label": "apache / qpid_protonj2",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-67588/",
      "current_public_safe_latest": true,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.39222,
      "epss_score": 0.00483,
      "first_observed_at": "2026-08-12T05:08:50.991993+00:00",
      "id": "CVE-2026-67588",
      "impact_tags": [
        "service availability review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-12T05:08:50.991993+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-67588.json",
      "product": "qpid_protonj2",
      "public_safe_summary": "NVD: A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service. NVD: This issue affects Apache Qpid ProtonJ2: through 1.1.0. NVD: Users are recommended to upgrade to version 1.2.0, which fixes the issue.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260812T051428Z/items/CVE-2026-67588.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: apache / qpid_protonj2",
      "source_published_impact": "Source describes service availability risk. Possible impact: The affected service may become unavailable or unreliable.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service. NVD: This issue affects Apache Qpid ProtonJ2: through 1.1.0. NVD: Users are recommended to upgrade to version 1.2.0, which fixes the issue.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-67588/timeline.json",
      "vendor": "apache"
    },
    {
      "affected_label": "apache / qpid_protonj2",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-67589/",
      "current_public_safe_latest": true,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.39836,
      "epss_score": 0.00493,
      "first_observed_at": "2026-08-12T05:08:50.991993+00:00",
      "id": "CVE-2026-67589",
      "impact_tags": [
        "service availability review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-12T05:08:50.991993+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-67589.json",
      "product": "qpid_protonj2",
      "public_safe_summary": "NVD: A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service. NVD: This issue affects Apache Qpid ProtonJ2: through 1.1.0. NVD: Users are recommended to upgrade to version 1.2.0, which fixes the issue.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260812T051428Z/items/CVE-2026-67589.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: apache / qpid_protonj2",
      "source_published_impact": "Source describes service availability risk. Possible impact: The affected service may become unavailable or unreliable.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service. NVD: This issue affects Apache Qpid ProtonJ2: through 1.1.0. NVD: Users are recommended to upgrade to version 1.2.0, which fixes the issue.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-67589/timeline.json",
      "vendor": "apache"
    },
    {
      "affected_label": "apache / qpid_broker-j",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-68060/",
      "current_public_safe_latest": true,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.39222,
      "epss_score": 0.00483,
      "first_observed_at": "2026-08-12T05:08:50.991993+00:00",
      "id": "CVE-2026-68060",
      "impact_tags": [
        "service availability review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-12T05:08:50.991993+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-68060.json",
      "product": "qpid_broker-j",
      "public_safe_summary": "NVD: A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service. NVD: This issue affects Apache Qpid Broker-J: through 10.0.1. NVD: Users are recommended to upgrade to version 10.1.0, which fixes the issue.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260812T051428Z/items/CVE-2026-68060.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: apache / qpid_broker-j",
      "source_published_impact": "Source describes service availability risk. Possible impact: The affected service may become unavailable or unreliable.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: version.",
      "source_published_summary": "NVD: A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service. NVD: This issue affects Apache Qpid Broker-J: through 10.0.1. NVD: Users are recommended to upgrade to version 10.1.0, which fixes the issue.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-68060/timeline.json",
      "vendor": "apache"
    }
  ],
  "public_safe_only": true,
  "radar": "vuln",
  "run_id": "20260812T051428Z",
  "run_index_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260812T051428Z/index.json",
  "safety": {
    "auto_remediation_allowed": false,
    "exploit_detail_allowed": false,
    "external_execution_allowed": false,
    "github_issue_creation_allowed": false,
    "indexing_allowed": true,
    "noindex_removal_allowed": true,
    "noindex_required": false,
    "patch_allowed": false,
    "public_launch_allowed": true,
    "public_safe_only": true,
    "raw_source_included": false,
    "read_only": true,
    "scan_allowed": false,
    "search_console_registered": true,
    "signal_radar_integration_allowed": false
  },
  "schema_version": "v0.1"
}