{
  "append_only": true,
  "archive_index_url": "https://vuln.signal-radar.com/data/vuln/archive/index.json",
  "archive_version": "v0.1",
  "generated_at": "2026-10-10T15:29:14.334220+00:00",
  "immutable_run": true,
  "item_count": 20,
  "items": [
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-96451/",
      "current_public_safe_latest": true,
      "cvss_score": 8.8,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.21274,
      "epss_score": 0.00304,
      "first_observed_at": "2026-10-10T09:55:06.507578+00:00",
      "id": "CVE-2026-96451",
      "impact_tags": [
        "privilege boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-10-10T15:28:36.400018+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-96451.json",
      "product": null,
      "public_safe_summary": "NVD: Authorization Bypass Through User-Controlled Key vulnerability in Ultimate Member Ultimate Member ultimate-member allows Privilege Escalation.This issue affects Ultimate Member: from n/a through 2.13.1.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20261010T152914Z/items/CVE-2026-96451.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes privilege escalation risk. Possible impact: An attacker may cross a privilege boundary and gain more access than intended.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Authorization Bypass Through User-Controlled Key vulnerability in Ultimate Member Ultimate Member ultimate-member allows Privilege Escalation.This issue affects Ultimate Member: from n/a through 2.13.1.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-96451/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-105123/",
      "current_public_safe_latest": true,
      "cvss_score": 8.7,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.42142,
      "epss_score": 0.00516,
      "first_observed_at": "2026-10-10T09:55:06.507578+00:00",
      "id": "CVE-2026-105123",
      "impact_tags": [
        "code execution review"
      ],
      "kev": false,
      "last_observed_at": "2026-10-10T15:28:36.400018+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-105123.json",
      "product": null,
      "public_safe_summary": "NVD: W (vincent-peugnet/wcms) through 3.18.0 contains a remote code execution vulnerability that allows authenticated editors to write arbitrary files by abusing the unvalidated path in POST /api/v0/media/upload/[*:path]. NVD: Attackers can upload .php files executed by the web server, use encoded ../ sequences to write outside the media directory, and delete arbitrary files via DELETE /api/v0/media/[*:path]. OSV: W (wcms) through 3.18.0 RCE and Arbitrary File Write via Media Upload API",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20261010T152914Z/items/CVE-2026-105123.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes code execution review. Possible impact: An attacker may be able to run code or commands on affected systems.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: W (vincent-peugnet/wcms) through 3.18.0 contains a remote code execution vulnerability that allows authenticated editors to write arbitrary files by abusing the unvalidated path in POST /api/v0/media/upload/[*:path]. NVD: Attackers can upload .php files executed by the web server, use encoded ../ sequences to write outside the media directory, and delete arbitrary files via DELETE /api/v0/media/[*:path]. OSV: W (wcms) through 3.18.0 RCE and Arbitrary File Write via Media Upload API",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-105123/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-105124/",
      "current_public_safe_latest": true,
      "cvss_score": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.10976,
      "epss_score": 0.00215,
      "first_observed_at": "2026-10-10T09:55:06.507578+00:00",
      "id": "CVE-2026-105124",
      "impact_tags": [
        "XSS risk",
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-10-10T15:28:36.400018+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-105124.json",
      "product": null,
      "public_safe_summary": "NVD: W (vincent-peugnet/wcms) through 3.18.0 contains a stored cross-site scripting vulnerability that allows unauthenticated attackers to inject scripts via the login user field and visitor comment website field. NVD: Attackers can submit failed logins rendered unescaped in the adminlog.php log viewer, or comment URLs echoed into href attributes in editrightbar.php, executing script with administrator or editor privileges. OSV: W (wcms) through 3.18.0 Unauthenticated Stored XSS via Login Username and Comments",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20261010T152914Z/items/CVE-2026-105124.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes XSS risk · remote exposure · authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk · remote exposure · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: W (vincent-peugnet/wcms) through 3.18.0 contains a stored cross-site scripting vulnerability that allows unauthenticated attackers to inject scripts via the login user field and visitor comment website field. NVD: Attackers can submit failed logins rendered unescaped in the adminlog.php log viewer, or comment URLs echoed into href attributes in editrightbar.php, executing script with administrator or editor privileges. OSV: W (wcms) through 3.18.0 Unauthenticated Stored XSS via Login Username and Comments",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-105124/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-105125/",
      "current_public_safe_latest": true,
      "cvss_score": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.21969,
      "epss_score": 0.0031,
      "first_observed_at": "2026-10-10T09:55:06.507578+00:00",
      "id": "CVE-2026-105125",
      "impact_tags": [
        "path traversal review",
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-10-10T15:28:36.400018+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-105125.json",
      "product": null,
      "public_safe_summary": "NVD: LaraDashboard before 1.4.8 contains a path traversal vulnerability that allows unauthenticated attackers to read JSON files by manipulating the {lang} route segment. NVD: On Windows hosts, attackers can send URL-encoded backslash sequences like ..%5C to escape resources/lang and read composer.json or other application JSON files. OSV: LaraDashboard before 1.4.8 Path Traversal via /api/translations/{lang} Endpoint",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20261010T152914Z/items/CVE-2026-105125.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes path traversal review · remote exposure · authenticated boundary. Possible impact: A remote attacker may be able to reach files outside the intended application path.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: LaraDashboard before 1.4.8 contains a path traversal vulnerability that allows unauthenticated attackers to read JSON files by manipulating the {lang} route segment. NVD: On Windows hosts, attackers can send URL-encoded backslash sequences like ..%5C to escape resources/lang and read composer.json or other application JSON files. OSV: LaraDashboard before 1.4.8 Path Traversal via /api/translations/{lang} Endpoint",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-105125/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-105126/",
      "current_public_safe_latest": true,
      "cvss_score": 8.6,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.40457,
      "epss_score": 0.00493,
      "first_observed_at": "2026-10-10T09:55:06.507578+00:00",
      "id": "CVE-2026-105126",
      "impact_tags": [
        "privilege boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-10-10T15:28:36.400018+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-105126.json",
      "product": null,
      "public_safe_summary": "NVD: LaraDashboard before 1.4.8 contains an improper privilege management vulnerability that allows authenticated Admin users to escalate to Superadmin by editing or renaming roles. NVD: Attackers with role.edit can rename their role to Superadmin or grant user.login_as permissions to take over accounts and reach core upgrade and module installation functions for code execution. OSV: LaraDashboard before 1.4.8 Privilege Escalation via Superadmin Role Tampering",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20261010T152914Z/items/CVE-2026-105126.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 2,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes privilege escalation risk. Possible impact: An attacker may cross a privilege boundary and gain more access than intended.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: LaraDashboard before 1.4.8 contains an improper privilege management vulnerability that allows authenticated Admin users to escalate to Superadmin by editing or renaming roles. NVD: Attackers with role.edit can rename their role to Superadmin or grant user.login_as permissions to take over accounts and reach core upgrade and module installation functions for code execution. OSV: LaraDashboard before 1.4.8 Privilege Escalation via Superadmin Role Tampering",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-105126/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-105127/",
      "current_public_safe_latest": true,
      "cvss_score": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.32887,
      "epss_score": 0.00406,
      "first_observed_at": "2026-10-10T15:28:36.400018+00:00",
      "id": "CVE-2026-105127",
      "impact_tags": [
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-10-10T15:28:36.400018+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-105127.json",
      "product": null,
      "public_safe_summary": "NVD: LaraDashboard 1.4.2 before 1.4.8 applies advanced email validation to unauthenticated forgot-password and reset-password requests, triggering DNS lookups and paid AbstractAPI verification calls. NVD: Unauthenticated attackers can submit arbitrary addresses to exhaust the verification quota, making validation fail open for all public forms, and probe domain resolution. OSV: LaraDashboard 1.4.2 before 1.4.8 Resource Exhaustion via Password Recovery Endpoints",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20261010T152914Z/items/CVE-2026-105127.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes remote exposure · authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: LaraDashboard 1.4.2 before 1.4.8 applies advanced email validation to unauthenticated forgot-password and reset-password requests, triggering DNS lookups and paid AbstractAPI verification calls. NVD: Unauthenticated attackers can submit arbitrary addresses to exhaust the verification quota, making validation fail open for all public forms, and probe domain resolution. OSV: LaraDashboard 1.4.2 before 1.4.8 Resource Exhaustion via Password Recovery Endpoints",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-105127/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-105128/",
      "current_public_safe_latest": true,
      "cvss_score": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.16271,
      "epss_score": 0.0026,
      "first_observed_at": "2026-10-10T15:28:36.400018+00:00",
      "id": "CVE-2026-105128",
      "impact_tags": [
        "remote exposure relevant"
      ],
      "kev": false,
      "last_observed_at": "2026-10-10T15:28:36.400018+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-105128.json",
      "product": null,
      "public_safe_summary": "NVD: LaraDashboard before 1.4.8 contains an open redirect vulnerability that allows remote attackers to redirect users by supplying an unvalidated redirect_url parameter to EmailTemplateController builder and builderEdit. NVD: Attackers can send crafted builder links to logged-in users with email template permissions so saving a template navigates them to attacker-controlled phishing sites. OSV: LaraDashboard before 1.4.8 Open Redirect via Email Template Builder redirect_url",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20261010T152914Z/items/CVE-2026-105128.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes remote exposure. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: LaraDashboard before 1.4.8 contains an open redirect vulnerability that allows remote attackers to redirect users by supplying an unvalidated redirect_url parameter to EmailTemplateController builder and builderEdit. NVD: Attackers can send crafted builder links to logged-in users with email template permissions so saving a template navigates them to attacker-controlled phishing sites. OSV: LaraDashboard before 1.4.8 Open Redirect via Email Template Builder redirect_url",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-105128/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-105129/",
      "current_public_safe_latest": true,
      "cvss_score": 7.1,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.21559,
      "epss_score": 0.00306,
      "first_observed_at": "2026-10-10T15:28:36.400018+00:00",
      "id": "CVE-2026-105129",
      "impact_tags": [
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-10-10T15:28:36.400018+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-105129.json",
      "product": null,
      "public_safe_summary": "NVD: LaraDashboard before 1.4.8 contains an incorrect authorization vulnerability that allows authenticated users with only settings.view permission to read stored secrets through the settings API. NVD: Attackers can query GET /api/settings or /api/settings/{option_name} to retrieve plaintext AI provider API keys, mail credentials, passwords and tokens. OSV: LaraDashboard before 1.4.8 Incorrect Authorization Exposes Secrets via Settings API",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20261010T152914Z/items/CVE-2026-105129.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes authenticated boundary. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: LaraDashboard before 1.4.8 contains an incorrect authorization vulnerability that allows authenticated users with only settings.view permission to read stored secrets through the settings API. NVD: Attackers can query GET /api/settings or /api/settings/{option_name} to retrieve plaintext AI provider API keys, mail credentials, passwords and tokens. OSV: LaraDashboard before 1.4.8 Incorrect Authorization Exposes Secrets via Settings API",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-105129/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-105130/",
      "current_public_safe_latest": true,
      "cvss_score": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.11923,
      "epss_score": 0.00223,
      "first_observed_at": "2026-10-10T15:28:36.400018+00:00",
      "id": "CVE-2026-105130",
      "impact_tags": [
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-10-10T15:28:36.400018+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-105130.json",
      "product": null,
      "public_safe_summary": "NVD: LaraDashboard from 1.4.0 before 1.4.8 contains a race condition vulnerability in RegisterController::register that allows unauthenticated attackers to bypass the per-IP daily registration limit. NVD: Attackers can send many concurrent registration requests from one IP so all pass RegistrationGuardService::hasExceededIpLimit before recordRegistration runs, creating accounts in bulk and defeating anti-automation controls. OSV: LaraDashboard 1.4.0 before 1.4.8 Race Condition Bypasses Per-IP Registration Limit",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20261010T152914Z/items/CVE-2026-105130.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes remote exposure · authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: LaraDashboard from 1.4.0 before 1.4.8 contains a race condition vulnerability in RegisterController::register that allows unauthenticated attackers to bypass the per-IP daily registration limit. NVD: Attackers can send many concurrent registration requests from one IP so all pass RegistrationGuardService::hasExceededIpLimit before recordRegistration runs, creating accounts in bulk and defeating anti-automation controls. OSV: LaraDashboard 1.4.0 before 1.4.8 Race Condition Bypasses Per-IP Registration Limit",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-105130/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-105096/",
      "current_public_safe_latest": true,
      "cvss_score": 2.1,
      "cvss_severity": "LOW",
      "epss_percentile": 0.19313,
      "epss_score": 0.00285,
      "first_observed_at": "2026-10-10T15:28:36.400018+00:00",
      "id": "CVE-2026-105096",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-10-10T15:28:36.400018+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-105096.json",
      "product": null,
      "public_safe_summary": "NVD: A vulnerability was determined in Omega Solution CoinEx Crypto 2025. NVD: This affects an unknown function of the file /customer/ of the component Customer Profile API. NVD: Executing a manipulation of the argument ID can lead to authorization bypass.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20261010T152914Z/items/CVE-2026-105096.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability was determined in Omega Solution CoinEx Crypto 2025. NVD: This affects an unknown function of the file /customer/ of the component Customer Profile API. NVD: Executing a manipulation of the argument ID can lead to authorization bypass.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-105096/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-105131/",
      "current_public_safe_latest": true,
      "cvss_score": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.08825,
      "epss_score": 0.00198,
      "first_observed_at": "2026-10-10T15:28:36.400018+00:00",
      "id": "CVE-2026-105131",
      "impact_tags": [
        "privilege boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-10-10T15:28:36.400018+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-105131.json",
      "product": null,
      "public_safe_summary": "NVD: ezBookkeeping 1.2.0 before 2.0.1 contains a privilege escalation vulnerability that allows attackers holding an API token to obtain a full session token via /api/v1/tokens/refresh.json. NVD: Because TokenRefreshHandler never checks token type, attackers can exchange short-lived or IP-restricted API tokens for 30-day normal session tokens that bypass API token expiry and allowlists. OSV: mayswind ezBookkeeping 1.2.0 before 2.0.1 Privilege Escalation via Token Refresh Endpoint",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20261010T152914Z/items/CVE-2026-105131.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes privilege escalation risk. Possible impact: An attacker may cross a privilege boundary and gain more access than intended.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: ezBookkeeping 1.2.0 before 2.0.1 contains a privilege escalation vulnerability that allows attackers holding an API token to obtain a full session token via /api/v1/tokens/refresh.json. NVD: Because TokenRefreshHandler never checks token type, attackers can exchange short-lived or IP-restricted API tokens for 30-day normal session tokens that bypass API token expiry and allowlists. OSV: mayswind ezBookkeeping 1.2.0 before 2.0.1 Privilege Escalation via Token Refresh Endpoint",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-105131/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-105097/",
      "current_public_safe_latest": true,
      "cvss_score": 2.1,
      "cvss_severity": "LOW",
      "epss_percentile": 0.2021,
      "epss_score": 0.00294,
      "first_observed_at": "2026-10-10T15:28:36.400018+00:00",
      "id": "CVE-2026-105097",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-10-10T15:28:36.400018+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-105097.json",
      "product": null,
      "public_safe_summary": "NVD: A vulnerability was identified in Omega Solution CoinEx Crypto 2025. NVD: This impacts an unknown function of the file /customer-currency/ of the component Customer Information API. NVD: The manipulation of the argument ID leads to authorization bypass.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20261010T152914Z/items/CVE-2026-105097.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability was identified in Omega Solution CoinEx Crypto 2025. NVD: This impacts an unknown function of the file /customer-currency/ of the component Customer Information API. NVD: The manipulation of the argument ID leads to authorization bypass.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-105097/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-105098/",
      "current_public_safe_latest": true,
      "cvss_score": 2.1,
      "cvss_severity": "LOW",
      "epss_percentile": 0.18759,
      "epss_score": 0.00279,
      "first_observed_at": "2026-10-10T15:28:36.400018+00:00",
      "id": "CVE-2026-105098",
      "impact_tags": [
        "information exposure review"
      ],
      "kev": false,
      "last_observed_at": "2026-10-10T15:28:36.400018+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-105098.json",
      "product": null,
      "public_safe_summary": "NVD: A security flaw has been discovered in Omega Solution CoinEx Crypto 2025. NVD: Affected is an unknown function of the file /ticket/customer of the component Support Ticket API. NVD: The manipulation of the argument status/page/count results in information disclosure.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20261010T152914Z/items/CVE-2026-105098.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes information exposure review. Possible impact: An attacker may be able to access information that should not be exposed.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A security flaw has been discovered in Omega Solution CoinEx Crypto 2025. NVD: Affected is an unknown function of the file /ticket/customer of the component Support Ticket API. NVD: The manipulation of the argument status/page/count results in information disclosure.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-105098/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "citrix / netscaler_application_delivery_controller",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-88779/",
      "current_public_safe_latest": true,
      "cvss_score": 8.7,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.4671,
      "epss_score": 0.00592,
      "first_observed_at": "2026-10-10T15:28:36.400018+00:00",
      "id": "CVE-2026-88779",
      "impact_tags": [],
      "kev": true,
      "last_observed_at": "2026-10-10T15:28:36.400018+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-88779.json",
      "product": "netscaler_application_delivery_controller",
      "public_safe_summary": "NVD: Vulnerability in NetScaler ADC and NetScaler Gateway. NVD: This issue affects ADC: before 14.1-73.41, before 13.1-64.28, before 14.1-73.41 FIPS, and before 13.1-37.282; Gateway: before 14.1-73.41 and before 13.1-64.28. NVD: Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20261010T152914Z/items/CVE-2026-88779.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: citrix / netscaler_application_delivery_controller",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for known exploited catalog listed.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Vulnerability in NetScaler ADC and NetScaler Gateway. NVD: This issue affects ADC: before 14.1-73.41, before 13.1-64.28, before 14.1-73.41 FIPS, and before 13.1-37.282; Gateway: before 14.1-73.41 and before 13.1-64.28. NVD: Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-88779/timeline.json",
      "vendor": "citrix"
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-105099/",
      "current_public_safe_latest": true,
      "cvss_score": 2.0,
      "cvss_severity": "LOW",
      "epss_percentile": 0.0805,
      "epss_score": 0.00191,
      "first_observed_at": "2026-10-10T15:28:36.400018+00:00",
      "id": "CVE-2026-105099",
      "impact_tags": [
        "XSS risk"
      ],
      "kev": false,
      "last_observed_at": "2026-10-10T15:28:36.400018+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-105099.json",
      "product": null,
      "public_safe_summary": "NVD: A weakness has been identified in Omega Solution CoinEx Crypto 2025. NVD: Affected by this vulnerability is an unknown functionality of the file /user/ticket of the component Ticket Attachment Upload. NVD: This manipulation causes cross site scripting.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20261010T152914Z/items/CVE-2026-105099.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes XSS risk. Possible impact: This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A weakness has been identified in Omega Solution CoinEx Crypto 2025. NVD: Affected by this vulnerability is an unknown functionality of the file /user/ticket of the component Ticket Attachment Upload. NVD: This manipulation causes cross site scripting.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-105099/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-104118/",
      "current_public_safe_latest": true,
      "cvss_score": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.07124,
      "epss_score": 0.00182,
      "first_observed_at": "2026-10-10T15:28:36.400018+00:00",
      "id": "CVE-2026-104118",
      "impact_tags": [
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-10-10T15:28:36.400018+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-104118.json",
      "product": null,
      "public_safe_summary": "NVD: The Razorpay for WooCommerce WordPress plugin before 4.8.8 does not perform ownership or authorization checks on a REST API route used during checkout, allowing unauthenticated attackers to modify the shipping information stored on arbitrary orders.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20261010T152914Z/items/CVE-2026-104118.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes remote exposure · authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Razorpay for WooCommerce WordPress plugin before 4.8.8 does not perform ownership or authorization checks on a REST API route used during checkout, allowing unauthenticated attackers to modify the shipping information stored on arbitrary orders.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-104118/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-104119/",
      "current_public_safe_latest": true,
      "cvss_score": 3.5,
      "cvss_severity": "LOW",
      "epss_percentile": 0.03082,
      "epss_score": 0.00142,
      "first_observed_at": "2026-10-10T15:28:36.400018+00:00",
      "id": "CVE-2026-104119",
      "impact_tags": [
        "XSS risk"
      ],
      "kev": false,
      "last_observed_at": "2026-10-10T15:28:36.400018+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-104119.json",
      "product": null,
      "public_safe_summary": "NVD: The Simple Shopping Cart WordPress plugin before 5.2.6 does not escape some of its settings field values before outputting them on an admin settings page, allowing high-privilege users such as administrators to perform Stored Cross-Site Scripting attacks...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20261010T152914Z/items/CVE-2026-104119.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes XSS risk. Possible impact: This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Simple Shopping Cart WordPress plugin before 5.2.6 does not escape some of its settings field values before outputting them on an admin settings page, allowing high-privilege users such as administrators to perform Stored Cross-Site Scripting attacks...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-104119/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-105133/",
      "current_public_safe_latest": true,
      "cvss_score": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.30343,
      "epss_score": 0.00383,
      "first_observed_at": "2026-10-10T15:28:36.400018+00:00",
      "id": "CVE-2026-105133",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-10-10T15:28:36.400018+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-105133.json",
      "product": null,
      "public_safe_summary": "NVD: A vulnerability was detected in Ahsay AhsayCBS up to 10.3.2. NVD: This affects the function checkSysPwd of the file com/ahsay/obs/api/ApiStructsAction.java of the component API. NVD: Performing a manipulation of the argument random results in improper authentication.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20261010T152914Z/items/CVE-2026-105133.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability was detected in Ahsay AhsayCBS up to 10.3.2. NVD: This affects the function checkSysPwd of the file com/ahsay/obs/api/ApiStructsAction.java of the component API. NVD: Performing a manipulation of the argument random results in improper authentication.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-105133/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-105134/",
      "current_public_safe_latest": true,
      "cvss_score": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.78416,
      "epss_score": 0.01843,
      "first_observed_at": "2026-10-10T15:28:36.400018+00:00",
      "id": "CVE-2026-105134",
      "impact_tags": [
        "command injection risk"
      ],
      "kev": false,
      "last_observed_at": "2026-10-10T15:28:36.400018+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-105134.json",
      "product": null,
      "public_safe_summary": "NVD: A flaw has been found in Ahsay AhsayCBS up to 10.3.2. NVD: This vulnerability affects unknown code of the file /rps/api/json/UpdateReceivers.do of the component Replication Receiver. NVD: Executing a manipulation of the argument random can lead to os command injection.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20261010T152914Z/items/CVE-2026-105134.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes command injection risk. Possible impact: An attacker may be able to run unintended system commands through the affected component.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A flaw has been found in Ahsay AhsayCBS up to 10.3.2. NVD: This vulnerability affects unknown code of the file /rps/api/json/UpdateReceivers.do of the component Replication Receiver. NVD: Executing a manipulation of the argument random can lead to os command injection.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-105134/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-105135/",
      "current_public_safe_latest": true,
      "cvss_score": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.54322,
      "epss_score": 0.0077,
      "first_observed_at": "2026-10-10T15:28:36.400018+00:00",
      "id": "CVE-2026-105135",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-10-10T15:28:36.400018+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-105135.json",
      "product": null,
      "public_safe_summary": "NVD: A vulnerability has been found in InternLM MindSearch 0.1.0. NVD: This issue affects the function ExecutionAction.run of the file mindsearch/agent/graph.py of the component Planner Agent. NVD: The manipulation of the argument inputs leads to code injection.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20261010T152914Z/items/CVE-2026-105135.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability has been found in InternLM MindSearch 0.1.0. NVD: This issue affects the function ExecutionAction.run of the file mindsearch/agent/graph.py of the component Planner Agent. NVD: The manipulation of the argument inputs leads to code injection.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-105135/timeline.json",
      "vendor": null
    }
  ],
  "public_safe_only": true,
  "radar": "vuln",
  "run_id": "20261010T152914Z",
  "run_index_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20261010T152914Z/index.json",
  "safety": {
    "auto_remediation_allowed": false,
    "exploit_detail_allowed": false,
    "external_execution_allowed": false,
    "github_issue_creation_allowed": false,
    "indexing_allowed": true,
    "noindex_removal_allowed": true,
    "noindex_required": false,
    "patch_allowed": false,
    "public_launch_allowed": true,
    "public_safe_only": true,
    "raw_source_included": false,
    "read_only": true,
    "scan_allowed": false,
    "search_console_registered": true,
    "signal_radar_integration_allowed": false
  },
  "schema_version": "v0.1"
}