Shortened for this page: items: 3 of 5 shown; [].enrichment.cwe[].capec_id: first 10 items
[
{
"id": "CVE-2026-96891",
"source_identifier": "user@vuldb.com",
"published": "2026-09-24T03:16:58Z",
"last_modified": "2026-09-24T03:16:58Z",
"status": "Received",
"evaluator_comment": null,
"evaluator_solution": null,
"evaluator_impact": null,
"cisa_exploit_add": null,
"cisa_action_due": null,
"cisa_required_action": null,
"cisa_vulnerability_name": null,
"descriptions": [
{
"lang": "en",
"value": "A vulnerability was identified in D-Link DIR-825 3.00b32. Affected is the function tunnel_set_params of the file tunnel.c of the component rp-l2tp. The manipulation of the argument peer_hostname leads to out-of-bounds write. The attack may be initiated remotely."
}
],
"references": [
{
"url": "https://tzh00203.notion.site/D-Link-DIR-825-L2TP-Host-Name-AVP-Out-of-Bounds-Write-33cb5c52018a80458ffec58b62096940",
"source": "user@vuldb.com",
"tags": null
},
{
"url": "https://vuldb.com/cve/CVE-2026-96891",
"source": "user@vuldb.com",
"tags": null
},
{
"url": "https://vuldb.com/submit/906301",
"source": "user@vuldb.com",
"tags": null
},
{
"url": "https://vuldb.com/vuln/409134",
"source": "user@vuldb.com",
"tags": null
},
{
"url": "https://vuldb.com/vuln/409134/cti",
"source": "user@vuldb.com",
"tags": null
},
{
"url": "https://www.dlink.com/",
"source": "user@vuldb.com",
"tags": null
}
],
"metrics": {
"cvss_metric_v40": [
{
"source": "user@vuldb.com",
"type": "Secondary",
"cvss_data": {
"version": "4.0",
"vector_string": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
"attack_vector": "NETWORK",
"attack_complexity": "LOW",
"attack_requirements": "NONE",
"privileges_required": "NONE",
"user_interaction": "NONE",
"vulnerable_system_confidentiality": null,
"vulnerable_system_integrity": null,
"vulnerable_system_availability": null,
"subsequent_system_confidentiality": null,
"subsequent_system_integrity": null,
"subsequent_system_availability": null,
"exploit_maturity": "NOT_DEFINED",
"confidentiality_requirements": null,
"integrity_requirements": null,
"availability_requirements": null,
"modified_attack_vector": "NOT_DEFINED",
"modified_attack_complexity": "NOT_DEFINED",
"modified_attack_requirements": "NOT_DEFINED",
"modified_privileges_required": "NOT_DEFINED",
"modified_user_interaction": "NOT_DEFINED",
"modified_vulnerable_system_confidentiality": null,
"modified_vulnerable_system_integrity": null,
"modified_vulnerable_system_availability": null,
"modified_subsequent_system_confidentiality": null,
"modified_subsequent_system_integrity": null,
"modified_subsequent_system_availability": null,
"safety": null,
"automatable": null,
"recovery": null,
"value_density": "NOT_DEFINED",
"vulnerability_response_effort": "NOT_DEFINED",
"provider_urgency": "NOT_DEFINED",
"base_score": 9.3,
"base_severity": "CRITICAL"
}
}
],
"cvss_metric_v31": [
{
"source": "user@vuldb.com",
"type": "Primary",
"cvss_data": {
"version": "3.1",
"vector_string": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"attack_vector": "NETWORK",
"attack_complexity": "LOW",
"privileges_required": "NONE",
"user_interaction": "NONE",
"scope": "UNCHANGED",
"confidentiality_impact": "HIGH",
"integrity_impact": "HIGH",
"availability_impact": "HIGH",
"base_score": 9.8,
"base_severity": "CRITICAL",
"exploit_code_maturity": null,
"remediation_level": null,
"report_confidence": null,
"temporal_score": null,
"temporal_severity": null,
"confidentiality_requirement": null,
"integrity_requirement": null,
"availability_requirement": null,
"modified_attack_vector": null,
"modified_attack_complexity": null,
"modified_privileges_required": null,
"modified_user_interaction": null,
"modified_scope": null,
"modified_confidentiality_impact": null,
"modified_integrity_impact": null,
"modified_availability_impact": null,
"environmental_score": null,
"environmental_severity": null
},
"exploitability_score": 3.9,
"impact_score": 5.9
}
],
"cvss_metric_v30": null,
"cvss_metric_v2": [
{
"source": "user@vuldb.com",
"type": "Secondary",
"cvss_data": {
"version": "2.0",
"vector_string": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
"access_vector": "NETWORK",
"access_complexity": "LOW",
"authentication": "NONE",
"confidentiality_impact": "COMPLETE",
"integrity_impact": "COMPLETE",
"availability_impact": "COMPLETE",
"base_score": 10.0,
"exploitability": null,
"remediation_level": null,
"report_confidence": null,
"temporal_score": null,
"collateral_damage_potential": null,
"target_distribution": null,
"confidentiality_requirement": null,
"integrity_requirement": null,
"availability_requirement": null,
"environmental_score": null
},
"base_severity": "HIGH",
"exploitability_score": 10.0,
"impact_score": 10.0,
"ac_insuf_info": false,
"obtain_all_privilege": false,
"obtain_user_privilege": false,
"obtain_other_privilege": false,
"user_interaction_required": false
}
]
},
"weaknesses": [
{
"source": "user@vuldb.com",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-119"
},
{
"lang": "en",
"value": "CWE-787"
}
]
}
],
"configurations": null,
"vendor_comments": null,
"enrichment": {
"cpe": null,
"cwe": [
{
"id": 787,
"owasptop10_2021": null,
"name": "Out-of-bounds Write",
"description": "The product writes data past the end, or before the beginning, of the intended buffer.",
"capec_id": null,
"scope": [
"Availability",
"Integrity",
"Other"
],
"impact": [
"DoS: Crash, Exit, or Restart",
"Execute Unauthorized Code or Commands",
"Modify Memory",
"Unexpected State"
],
"detection_method": [
"Automated Dynamic Analysis",
"Automated Static Analysis"
]
},
{
"id": 119,
"owasptop10_2021": null,
"name": "Improper Restriction of Operations within the Bounds of a Memory Buffer",
"description": "The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.",
"capec_id": [
8,
9,
10,
14,
24,
42,
44,
45,
46,
47
],
"scope": [
"Availability",
"Confidentiality",
"Integrity"
],
"impact": [
"DoS: Crash, Exit, or Restart",
"DoS: Resource Consumption (CPU)",
"DoS: Resource Consumption (Memory)",
"Execute Unauthorized Code or Commands",
"Modify Memory",
"Read Memory"
],
"detection_method": [
"Architecture or Design Review",
"Automated Dynamic Analysis",
"Automated Static Analysis",
"Automated Static Analysis - Binary or Bytecode",
"Automated Static Analysis - Source Code",
"Dynamic Analysis with Automated Results Interpretation",
"Dynamic Analysis with Manual Results Interpretation",
"Manual Static Analysis - Binary or Bytecode",
"Manual Static Analysis - Source Code"
]
}
],
"epss_score": null,
"cisa_kev": null,
"vdeep_metric": {
"available_versions": [
"4.0",
"3.1",
"2.0"
],
"source": "user@vuldb.com",
"type": "Secondary",
"cvss_data": {
"version": "4.0",
"vector_string": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
"attack_vector": "NETWORK",
"attack_complexity": "LOW",
"attack_requirements": "NONE",
"privileges_required": "NONE",
"user_interaction": "NONE",
"vulnerable_system_confidentiality": null,
"vulnerable_system_integrity": null,
"vulnerable_system_availability": null,
"subsequent_system_confidentiality": null,
"subsequent_system_integrity": null,
"subsequent_system_availability": null,
"exploit_maturity": "NOT_DEFINED",
"confidentiality_requirements": null,
"integrity_requirements": null,
"availability_requirements": null,
"modified_attack_vector": "NOT_DEFINED",
"modified_attack_complexity": "NOT_DEFINED",
"modified_attack_requirements": "NOT_DEFINED",
"modified_privileges_required": "NOT_DEFINED",
"modified_user_interaction": "NOT_DEFINED",
"modified_vulnerable_system_confidentiality": null,
"modified_vulnerable_system_integrity": null,
"modified_vulnerable_system_availability": null,
"modified_subsequent_system_confidentiality": null,
"modified_subsequent_system_integrity": null,
"modified_subsequent_system_availability": null,
"safety": null,
"automatable": null,
"recovery": null,
"value_density": "NOT_DEFINED",
"vulnerability_response_effort": "NOT_DEFINED",
"provider_urgency": "NOT_DEFINED",
"base_score": 9.3,
"base_severity": "CRITICAL"
}
}
}
},
{
"id": "CVE-2026-18467",
"source_identifier": "user@wordfence.com",
"published": "2026-09-24T02:16:52Z",
"last_modified": "2026-09-24T02:16:52Z",
"status": "Received",
"evaluator_comment": null,
"evaluator_solution": null,
"evaluator_impact": null,
"cisa_exploit_add": null,
"cisa_action_due": null,
"cisa_required_action": null,
"cisa_vulnerability_name": null,
"descriptions": [
{
"lang": "en",
"value": "The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 5.0.3. The 5.0.3 patch introduced a wp_hash()/hash_equals() signature gate on the pt-paytium-user-data field, but left a second filter — pt_cf_checkout_meta(), registered on the pt_meta_values hook after the signed builder — that copies every $_POST['pt_form_field'][*] key verbatim into the payment meta array without any signature verification; this allows the pt-user-role value it copies to overwrite the signed path's output, after which paytium_user_data_processing() reads the persisted _pt-user-role post meta and passes it directly as the role argument to wp_insert_user(). This makes it possible for unauthenticated attackers to register a new WordPress account with the administrator role and fully take over the site. Exploitation requires submitting a payment through a publicly-exposed [paytium] shortcode form and completing the resulting payment flow, after which the attacker can seize the new administrator account via the standard lost-password flow on their supplied email address."
}
],
"references": [
{
"url": "https://plugins.trac.wordpress.org/browser/paytium/tags/5.0.3/includes/payment-functions.php#L113",
"source": "user@wordfence.com",
"tags": null
},
{
"url": "https://plugins.trac.wordpress.org/browser/paytium/tags/5.0.3/includes/process-payment-functions.php#L1103",
"source": "user@wordfence.com",
"tags": null
},
{
"url": "https://plugins.trac.wordpress.org/browser/paytium/tags/5.0.3/includes/process-payment-functions.php#L21",
"source": "user@wordfence.com",
"tags": null
},
{
"url": "https://plugins.trac.wordpress.org/browser/paytium/tags/5.0.3/includes/process-payment-functions.php#L696",
"source": "user@wordfence.com",
"tags": null
},
{
"url": "https://plugins.trac.wordpress.org/browser/paytium/tags/5.0.3/includes/user-data-functions.php#L214",
"source": "user@wordfence.com",
"tags": null
},
{
"url": "https://plugins.trac.wordpress.org/changeset/3678569/paytium",
"source": "user@wordfence.com",
"tags": null
},
{
"url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/caa1a42a-6bb2-42c8-aae7-fb1c895573a8?source=cve",
"source": "user@wordfence.com",
"tags": null
}
],
"metrics": {
"cvss_metric_v40": null,
"cvss_metric_v31": [
{
"source": "user@wordfence.com",
"type": "Primary",
"cvss_data": {
"version": "3.1",
"vector_string": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"attack_vector": "NETWORK",
"attack_complexity": "LOW",
"privileges_required": "NONE",
"user_interaction": "NONE",
"scope": "UNCHANGED",
"confidentiality_impact": "HIGH",
"integrity_impact": "HIGH",
"availability_impact": "HIGH",
"base_score": 9.8,
"base_severity": "CRITICAL",
"exploit_code_maturity": null,
"remediation_level": null,
"report_confidence": null,
"temporal_score": null,
"temporal_severity": null,
"confidentiality_requirement": null,
"integrity_requirement": null,
"availability_requirement": null,
"modified_attack_vector": null,
"modified_attack_complexity": null,
"modified_privileges_required": null,
"modified_user_interaction": null,
"modified_scope": null,
"modified_confidentiality_impact": null,
"modified_integrity_impact": null,
"modified_availability_impact": null,
"environmental_score": null,
"environmental_severity": null
},
"exploitability_score": 3.9,
"impact_score": 5.9
}
],
"cvss_metric_v30": null,
"cvss_metric_v2": null
},
"weaknesses": [
{
"source": "user@wordfence.com",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-269"
}
]
}
],
"configurations": null,
"vendor_comments": null,
"enrichment": {
"cpe": null,
"cwe": [
{
"id": 269,
"owasptop10_2021": "A04 Insecure Design",
"name": "Improper Privilege Management",
"description": "The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.",
"capec_id": [
58,
122,
233
],
"scope": [
"Access Control"
],
"impact": [
"Gain Privileges or Assume Identity"
],
"detection_method": [
"Automated Static Analysis"
]
}
],
"epss_score": null,
"cisa_kev": null,
"vdeep_metric": {
"available_versions": [
"3.1"
],
"source": "user@wordfence.com",
"type": "Primary",
"cvss_data": {
"version": "3.1",
"vector_string": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"attack_vector": "NETWORK",
"attack_complexity": "LOW",
"attack_requirements": null,
"privileges_required": "NONE",
"user_interaction": "NONE",
"vulnerable_system_confidentiality": "HIGH",
"vulnerable_system_integrity": "HIGH",
"vulnerable_system_availability": "HIGH",
"subsequent_system_confidentiality": null,
"subsequent_system_integrity": null,
"subsequent_system_availability": null,
"exploit_maturity": null,
"confidentiality_requirements": null,
"integrity_requirements": null,
"availability_requirements": null,
"modified_attack_vector": null,
"modified_attack_complexity": null,
"modified_attack_requirements": null,
"modified_privileges_required": null,
"modified_user_interaction": null,
"modified_vulnerable_system_confidentiality": null,
"modified_vulnerable_system_integrity": null,
"modified_vulnerable_system_availability": null,
"modified_subsequent_system_confidentiality": null,
"modified_subsequent_system_integrity": null,
"modified_subsequent_system_availability": null,
"safety": null,
"automatable": null,
"recovery": null,
"value_density": null,
"vulnerability_response_effort": null,
"provider_urgency": null,
"base_score": 9.8,
"base_severity": "CRITICAL"
}
}
}
},
{
"id": "CVE-2026-93577",
"source_identifier": "user@gitlab.com",
"published": "2026-09-24T00:17:22Z",
"last_modified": "2026-09-24T00:17:22Z",
"status": "Received",
"evaluator_comment": null,
"evaluator_solution": null,
"evaluator_impact": null,
"cisa_exploit_add": null,
"cisa_action_due": null,
"cisa_required_action": null,
"cisa_vulnerability_name": null,
"descriptions": [
{
"lang": "en",
"value": "GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.2 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under certain conditions could have allowed an authenticated user to execute arbitrary code on the GitLab server due to an integer overflow issue when compiling a specially crafted regular expression in a CI/CD configuration."
}
],
"references": [
{
"url": "https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-4-1-released/",
"source": "user@gitlab.com",
"tags": null
},
{
"url": "https://gitlab.com/gitlab-org/gitlab/-/work_items/629758",
"source": "user@gitlab.com",
"tags": null
},
{
"url": "https://hackerone.com/reports/3995696",
"source": "user@gitlab.com",
"tags": null
}
],
"metrics": {
"cvss_metric_v40": null,
"cvss_metric_v31": [
{
"source": "user@gitlab.com",
"type": "Secondary",
"cvss_data": {
"version": "3.1",
"vector_string": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
"attack_vector": "NETWORK",
"attack_complexity": "LOW",
"privileges_required": "LOW",
"user_interaction": "NONE",
"scope": "CHANGED",
"confidentiality_impact": "HIGH",
"integrity_impact": "HIGH",
"availability_impact": "HIGH",
"base_score": 9.9,
"base_severity": "CRITICAL",
"exploit_code_maturity": null,
"remediation_level": null,
"report_confidence": null,
"temporal_score": null,
"temporal_severity": null,
"confidentiality_requirement": null,
"integrity_requirement": null,
"availability_requirement": null,
"modified_attack_vector": null,
"modified_attack_complexity": null,
"modified_privileges_required": null,
"modified_user_interaction": null,
"modified_scope": null,
"modified_confidentiality_impact": null,
"modified_integrity_impact": null,
"modified_availability_impact": null,
"environmental_score": null,
"environmental_severity": null
},
"exploitability_score": 3.1,
"impact_score": 6.0
}
],
"cvss_metric_v30": null,
"cvss_metric_v2": null
},
"weaknesses": [
{
"source": "user@gitlab.com",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-190"
}
]
}
],
"configurations": null,
"vendor_comments": null,
"enrichment": {
"cpe": null,
"cwe": [
{
"id": 190,
"owasptop10_2021": null,
"name": "Integer Overflow or Wraparound",
"description": "The product performs a calculation that can\n produce an integer overflow or wraparound when the logic\n assumes that the resulting value will always be larger than\n the original value. This occurs when an integer value is\n incremented to a value that is too large to store in the\n associated representation. When this occurs, the value may\n become a very small or negative number.",
"capec_id": [
92
],
"scope": [
"Access Control",
"Availability",
"Confidentiality",
"Integrity",
"Other"
],
"impact": [
"Alter Execution Logic",
"Bypass Protection Mechanism",
"DoS: Crash, Exit, or Restart",
"DoS: Instability",
"DoS: Resource Consumption (CPU)",
"DoS: Resource Consumption (Memory)",
"Execute Unauthorized Code or Commands",
"Modify Memory"
],
"detection_method": [
"Architecture or Design Review",
"Automated Static Analysis",
"Automated Static Analysis - Binary or Bytecode",
"Automated Static Analysis - Source Code",
"Black Box",
"Dynamic Analysis with Manual Results Interpretation",
"Manual Analysis",
"Manual Static Analysis - Source Code"
]
}
],
"epss_score": null,
"cisa_kev": null,
"vdeep_metric": {
"available_versions": [
"3.1"
],
"source": "user@gitlab.com",
"type": "Secondary",
"cvss_data": {
"version": "3.1",
"vector_string": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
"attack_vector": "NETWORK",
"attack_complexity": "LOW",
"attack_requirements": null,
"privileges_required": "LOW",
"user_interaction": "NONE",
"vulnerable_system_confidentiality": "HIGH",
"vulnerable_system_integrity": "HIGH",
"vulnerable_system_availability": "HIGH",
"subsequent_system_confidentiality": null,
"subsequent_system_integrity": null,
"subsequent_system_availability": null,
"exploit_maturity": null,
"confidentiality_requirements": null,
"integrity_requirements": null,
"availability_requirements": null,
"modified_attack_vector": null,
"modified_attack_complexity": null,
"modified_attack_requirements": null,
"modified_privileges_required": null,
"modified_user_interaction": null,
"modified_vulnerable_system_confidentiality": null,
"modified_vulnerable_system_integrity": null,
"modified_vulnerable_system_availability": null,
"modified_subsequent_system_confidentiality": null,
"modified_subsequent_system_integrity": null,
"modified_subsequent_system_availability": null,
"safety": null,
"automatable": null,
"recovery": null,
"value_density": null,
"vulnerability_response_effort": null,
"provider_urgency": null,
"base_score": 9.9,
"base_severity": "CRITICAL"
}
}
}
}
]