<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9">
  <url><loc>https://junglewise.ai/threats/cve-2026-57179-python-social-auth-social-auth-core-session-fixation-in-partial</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-57178-python-social-auth-social-core-vk-app-backend-auth-bypass</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-57177-python-social-auth-social-core-login-csrf-in-loginradius-backend</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-57176-python-social-auth-social-core-account-takeover-in-vend-backend</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-57175-python-social-auth-social-auth-core-saml-authentication-bypass</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-57171-compliance-trestle-author-generate-path-traversal-file-write</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-61815-zbateson-mail-mime-parser-crlf-header-injection-in-attachment</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-61816-zbateson-mail-mime-parser-uncontrolled-resource-consumption-in</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-59980-hpack-unbounded-variable-integer-decoding-denial-of-service</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-61782-rsdoctor-rspack-plugin-unauthenticated-information-disclosure</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-61788-bytebase-dbhub-read-only-mode-bypass-via-function-calls</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-61742-dbhub-http-transport-dns-rebinding-allows-unauthenticated-sql</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-61741-http4s-scala-xml-xxe-vulnerability-in-entitydecoder</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-61784-xhtml-purifier-attribute-injection-sanitizer-bypass-leading-to</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-56744-bsv-wallet-toolbox-storage-output-validation-bypass</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-56738-phpmyfaq-sql-injection-in-stopwords-add</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-56737-phpmyfaq-two-factor-authentication-password-bypass</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-56736-phpmyfaq-stored-xss-in-admin-faq-editor-via-html-entity-bypass</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/langchain-nvidia-local-file-disclosure-through-vlm-image-inputs-2ea392d6</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-61604-ixo-blockchain-x-bonds-did-resolved-payer-authorization-bypass</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-61732-decepticon-role-boundary-forgery-via-chatml-special-token</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-96883-aws-pgcollection-type-confusion-remote-code-execution</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/virustotal-yara-x-unvalidated-deserialization-in-rules-deserialize-d5769253</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-63498-snipe-it-stored-xss-via-inline-xml-rendering-in-uploaded-files</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-85056-zitadel-login-v2-mfa-bypass-via-session-reuse</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-85057-zitadel-actions-v1-sandbox-escape-via-require-filesystem-read</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-62368-snipe-it-stored-xss-in-custom-field-names</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-62286-dozzle-label-filter-bypass-in-events-stream</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-63493-snipe-it-2fa-bypass-via-api-token-flow</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-19730-podman-quadlet-install-incomplete-file-truncation</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-59167-suneditor-xss-vulnerability-in-sanitizer-with-namespaced-tags</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-62998-redaxo-rex-list-unwhitelisted-order-by-column-injection</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-93289-eufy-omni-c20-and-x10-pro-os-command-injection-and-certificate</loc><lastmod>2026-09-24</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-84399-botslab-g980h-dashcam-multiple-authentication-and-authorization</loc><lastmod>2026-09-24</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-5430-wso2-api-control-plane-path-traversal-vulnerability</loc><lastmod>2026-09-24</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-71362-adobe-commerce-and-magento-incorrect-authorization</loc><lastmod>2026-09-24</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-61685-reactpress-sql-injection-via-dynamic-column-names-in-typeorm</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/plone-plone-app-contenttypes-denial-of-service-via-excessive-filename-c46fb307</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-57576-plone-plone-app-dexterity-denial-of-service-via-excessive-field</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-77394-openc3-cosmos-stored-cross-user-xss-in-button-widget</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-82407-klever-go-bls-public-key-validation-bypass-in-validator</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-82409-klever-go-elasticsearch-injection-via-account-name</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-82406-klever-go-marketplace-buy-missing-isclaimed-guard</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-76089-verbb-formie-missing-authorization-on-sent-notification-resend</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-61814-typelevel-jawn-asyncparser-quadratic-parsing-effort-denial-of</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-59990-jawn-json-parser-denial-of-service-via-uncontrolled-nesting-depth</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-82405-klever-go-account-takeover-via-authorization-bypass-in</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-86065-klever-go-unauthenticated-websocket-subscribe-remote-dos</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-86064-klever-go-log-endpoint-unauthenticated-logging-configuration</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-93421-google-mesop-unauthenticated-ansi-escape-sequence-injection-in</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-77602-openc3-cosmos-authenticated-remote-code-execution-via-config</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-77601-openc3-cosmos-authenticated-os-command-injection-via-pypi-url</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-61695-square-wire-swift-runtime-negative-length-in-skipgroup-denial-of</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-76087-verbb-formie-unauthenticated-submission-hijacking-via-submit</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-76086-craft-formie-integration-form-settings-ssrf-and-credential</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-92692-sulu-jcr-sql2-injection-in-category-filter</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-77421-jline-nano-editor-redos-in-regex-search-mode</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-77422-jline-redos-in-built-in-grep-command</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-77420-jline-history-ignore-redos-via-unescaped-regex-metacharacters</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-85724-moquette-mqtt-broker-pattern-acl-wildcard-injection-and</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-73858-solspace-freeform-twig-template-injection-via-form-field-values</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-88974-wpgraphql-authorization-bypass-in-updatepost-mutation</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-63000-redaxo-missing-csrf-protection-on-package-update</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-63002-redaxo-stored-xss-in-mediapool-sync-page-via-unescaped-filenames</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-63001-redaxo-media-manager-stored-xss-in-type-name</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-61541-zapros-unbounded-content-encoding-decompression-denial-of-service</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-61652-zapros-decompression-bomb-in-streaming-decoder</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-57149-plone-plone-app-portlets-tales-injection-remote-code-execution</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/third-party-ics-integrators-supply-chain-risk-to-critical-90b78f9a</loc><lastmod>2026-09-24</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-91130-home-assistant-statistics-graph-card-xss-via-entity-names</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-91129-home-assistant-server-side-request-forgery-in-mdns-ipp</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-88010-traefik-basicauth-singleflight-username-enumeration-via-timing</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-88978-hatchet-durabletask-workerstatus-grpc-authorization-bypass-via</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-84298-hatchet-cross-tenant-durable-callback-payload-disclosure</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-79913-cloudreve-ssrf-guard-bypass-via-ipv6-transition-wrappers</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-79767-gardener-authorization-bypass-via-group-subject-injection</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-77637-cloudreve-privilege-scope-bypass-in-admin-api-endpoints</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-77633-cloudreve-toctou-race-in-storage-quota-check-and-charge</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-94462-spree-store-api-broken-access-control-in-cart-association</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-86062-lightrag-webui-stored-xss-in-chat-answer-renderer</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-85740-lightrag-ssrf-via-ipv6-transition-address-bypass-in-markdown</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-85734-lightrag-hku-login-endpoint-missing-rate-limiting-enables-brute</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-85725-lightrag-plaintext-password-timing-attack-vulnerability</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-85709-lightrag-api-sensitive-information-exposure-in-error-responses</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-83805-nautobot-authorization-bypass-in-approval-workflow-rest-api</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-83801-nautobot-stored-cross-site-scripting-in-form-help-text</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-77528-autobahn-python-permessage-deflate-decompression-bypass-in</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-76805-nuclei-environment-variable-disclosure-in-dast-fuzz-mode</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-76804-projectdiscovery-nuclei-security-gate-bypass-via-workflow-file</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-76803-projectdiscovery-nuclei-local-file-read-via-mysql-sandbox-bypass</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-76802-projectdiscovery-nuclei-arbitrary-command-execution-in-dast</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-76819-projectdiscovery-nuclei-arbitrary-code-execution-via-goja</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-77561-tinyauth-denial-of-service-via-login-attempt-map-saturation</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-77560-tinyauth-forward-auth-authorization-bypass-via-case-sensitive-acl</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-77582-tinyauth-user-enumeration-via-timing-oracle</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-62371-kubeedge-command-injection-in-nodeupgradejob-via-v1alpha2-api</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-62370-kubeedge-cloudhub-unbounded-buffer-allocation-in-viaduct-packer</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-62369-kubeedge-keadm-path-traversal-in-decompresstargz</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-63131-openbao-authorization-bypass-in-policy-enforcement-for-list</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-63132-openbao-recovery-mode-timing-attack-token-leakage</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-71543-openbao-templated-policies-privilege-escalation-via-wildcard</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-77285-openbao-agent-information-disclosure-via-stdout-in-exec-rendering</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-62182-kubeedge-configupdatejob-command-injection-in-updatefields</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-77426-unleash-admin-api-missing-await-on-permission-check-and-cross</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-77425-unleash-authorization-bypass-in-strategy-reordering</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-77250-mcp-atlassian-oauth-fallback-token-storage-plaintext-exposure</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-77249-atlassian-mcp-jira-user-permission-lookup-ssrf-via-unvalidated</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-77247-sooperset-mcp-atlassian-arbitrary-file-upload-to-jira-confluence</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-77244-mcp-atlassian-authentication-bypass-in-http-transport</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-77274-atlassian-mcp-ssrf-protection-bypass-via-url-parser-mismatch</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-77271-atlassian-mcp-path-traversal-bypass-leading-to-rce</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-77267-mcp-atlassian-incomplete-ssrf-remediation-in-url-header</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-77272-atlassian-mcp-reflected-xss-in-oauth-setup-callback-handler</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-77262-sooperset-mcp-atlassian-path-traversal-in-confluence-upload</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-77268-atlassian-mcp-insecure-oauth-token-file-permissions</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-77259-mcp-atlassian-arbitrary-file-read-via-confluence-upload</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-77261-mcp-atlassian-ssrf-protection-bypass-in-basic-auth-and-oauth</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-77270-atlassian-mcp-arbitrary-file-read-via-upload-attachment-tools</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-77265-atlassian-mcp-server-ssrf-via-dns-rebinding-in-header</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-77266-mcp-atlassian-path-traversal-in-upload-attachment</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-77269-atlassian-mcp-path-traversal-in-upload-attachment-allows</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-77260-atlassian-mcp-server-arbitrary-file-read-via-unconstrained-upload</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-77257-sooperset-mcp-atlassian-arbitrary-local-file-read-in-http-upload</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-77243-mcp-atlassian-tool-authorization-bypass-in-tools-call</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-77255-atlassian-mcp-arbitrary-file-read-via-path-traversal-in-update</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-77253-mcp-atlassian-arbitrary-file-read-in-attachment-upload</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-77251-mcp-atlassian-jql-cql-filter-bypass-in-jira-and-confluence-search</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-77246-mcp-atlassian-http-server-local-file-exfiltration-via-unvalidated</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-77248-atlassian-mcp-unauthenticated-arbitrary-file-read-in-upload</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-76910-unleash-feature-toggle-authorization-bypass-in-clone-endpoint</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-76909-unleash-change-request-approval-email-html-injection</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-75510-novu-stored-xss-in-in-app-inbox-via-javascript-scheme-in-redirect</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-69190-graylog-privilege-escalation-in-saved-searches-and-dashboards-api</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-77322-sipgo-dos-via-unvalidated-websocket-frame-length</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-65829-mpxj-path-traversal-in-primavera-p3-prx-and-suretrak-stx-readers</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-61570-mpxj-xxe-vulnerability-in-merlinreader</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-62987-fabio-incomplete-fix-for-hop-by-hop-header-stripping-in-trust</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-63628-mppx-gas-draining-via-eip-2930-access-list</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-63627-mppx-gas-draining-via-calldata-padding</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-63342-hatchet-authorization-bypass-in-durable-task-event-log-endpoint</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-61681-hatchet-ssrf-in-sns-unsubscribeconfirmation-handler</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-62364-weblate-wlc-api-token-disclosure-in-project-configuration</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-58268-sipgo-dos-via-unvalidated-content-length-in-stream-parser</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-63116-deepstream-patch-multi-permission-bypass-in-valve-access-control</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-62985-request-filtering-agent-unhandled-synchronous-exception-in</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-62866-dasel-selector-lexer-panic-on-trailing-whitespace</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-59168-dasel-unbounded-recursion-in-json-and-xml-readers-causes-stack</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-62282-opencve-server-side-request-forgery-in-notifications</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-59991-psd-tools-uncontrolled-memory-allocation-in-composite-numpy</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-61670-microsandbox-information-disclosure-in-process-arguments</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-94384-amazon-connect-salesforce-lambda-authorization-bypass-in</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-56682-9router-login-brute-force-lockout-bypass-via-spoofable-header</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-56681-9router-authentication-bypass-in-public-llm-api-via-spoofable-x</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-61612-aborruso-ckan-mcp-server-ssrf-via-dns-name-resolution</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-58272-sync-in-server-username-enumeration-via-timing-side-channel-in</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-58270-sync-in-server-redos-via-unsanitized-regex-in-pathfilters</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-58269-sync-in-server-two-factor-authentication-bypass-in-token-endpoint</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-58271-sync-in-server-totp-brute-force-in-sync-registration</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-61647-roomi-fields-notebooklm-mcp-path-traversal-in-vault-batch-tool</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-89207-siemens-wtv676-and-wtv776-denial-of-service-via-input-validation</loc><lastmod>2026-09-24</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-50093-siemens-siveillance-control-arbitrary-file-upload-in-ois-web</loc><lastmod>2026-09-24</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-67367-siemens-simove-fleetmanager-and-siplant-path-traversal</loc><lastmod>2026-09-24</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-87121-lwip-tcp-ip-stack-mqtt-client-application-out-of-bounds-write</loc><lastmod>2026-09-24</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-34223-siemens-desigo-cc-code-injection-in-graphics-documents</loc><lastmod>2026-09-24</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-88020-openplc-runtime-v3-cross-site-scripting-in-web-interface</loc><lastmod>2026-09-24</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-91018-lwip-double-free-vulnerability</loc><lastmod>2026-09-24</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-94127-f5-big-ip-apm-heap-based-buffer-overflow</loc><lastmod>2026-09-24</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-93952-arista-velocloud-orchestrator-improper-input-validation</loc><lastmod>2026-09-24</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-93616-check-point-multiple-products-path-traversal-vulnerability</loc><lastmod>2026-09-24</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-85102-check-point-security-gateway-and-spark-firewall-improper</loc><lastmod>2026-09-24</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-61628-nginx-ignition-unauthenticated-admin-account-creation-via</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-61629-nginx-ignition-i18n-middleware-cpu-amplification-via-accept</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-61630-nginx-ignition-totp-reuse-during-validity-window</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/falco-k8saudit-detection-bypass-for-privileged-init-and-ephemeral-7788502d</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-61687-hatchet-oauth-state-csrf-via-empty-state-collision</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/obot-server-side-request-forgery-via-remote-mcp-server-url-8f4d0bee</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/obot-mcp-registry-api-authentication-bypass-7d5ec1f3</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/obot-oauth-dynamic-client-registration-token-theft-via-audience-62f98039</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-71537-paymenter-credit-refund-double-spend-race-condition-in-service</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-85058-moquette-mqtt-broker-authorization-bypass-in-will-message</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-59163-mnemosyne-jwt-signature-verification-bypass-in-sync-server</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-63445-perses-filesystem-path-traversal-via-unvalidated-project</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-63199-perses-missing-authorization-in-datasource-proxy</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-63458-perses-project-query-parameter-authorization-bypass</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-91127-file-viewer-dom-xss-via-unsafe-hyperlink-schemes-in-legacy-doc</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-77301-adm-zip-uncontrolled-memory-allocation-via-uncompressed-size</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-77339-f1bonacc1-process-compose-dns-rebinding-in-mcp-sse-transport</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-81505-convoy-cross-tenant-source-idor-leaks-broker-credentials</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-84992-md-editor-v3-cross-site-scripting-in-code-fence-rendering</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-63406-anycable-hardcoded-telemetry-auth-token-and-credential-leak</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-63349-anyio-run-process-open-process-privilege-dropping-bug-with-extra</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-63374-anyio-tlsstream-idna-2003-host-name-encoding-certificate-spoofing</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-64847-anyio-process-pool-workers-indefinite-blocking-on-undrained</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-63405-anycable-pusher-rest-api-request-body-md5-verification-bypass</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-58197-toolhive-containerized-mcp-servers-host-service-access-via-host</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-61682-kcp-front-proxy-header-injection-and-privilege-escalation</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-61833-zot-registry-bearer-authentication-delete-authorization-bypass</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-61795-capsule-hostnameregexhandler-parameter-order-bypass-in-webhook</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-61672-capsule-forbidden-namespace-service-node-label-and-annotation</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-61794-capsule-tenant-forbiddenannotations-regex-validation-bypass</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/lmdeploy-ssrf-bypass-in-url-validation-f10a8d23</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-33625-lmdeploy-arbitrary-code-execution-via-eval-of-untrusted-quant</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2025-66455-lmdeploy-remote-code-execution-via-pickle-deserialization-in</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/semantic-mediawiki-missing-authorization-in-smwtask-api-module-37615b77</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/semantic-mediawiki-special-facetedsearch-reflected-xss-via-cstate-15c1ff89</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-77616-semantic-mediawiki-reflected-xss-in-special-ask-cursor-parameter</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-77610-semantic-mediawiki-query-debug-output-xss-in-debugformatter</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-77609-semantic-mediawiki-open-redirect-in-special-uriresolver</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-77607-semantic-mediawiki-reflected-xss-in-special-ask-separator</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-77608-semantic-mediawiki-reflected-xss-in-searchbyproperty</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-77606-semantic-mediawiki-reflected-xss-in-special-ask-plain-table</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2025-61682-semantic-mediawiki-stored-xss-through-wikitext-data-attributes</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2025-53837-xwiki-xwiki-rendering-xml-eval-injection-via-html-macro-escaping</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-77615-opencast-paella-player-stored-xss-in-webvtt-dfxp-caption-cues</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-72819-grav-cms-remote-code-execution-via-zip-file-upload</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-75837-grav-missing-admin-super-guard-in-group-blueprint-access-field</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-75834-grav-stored-xss-via-invalid-utf-8-byte-in-security-detectxss</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-75827-grav-blueprint-bare-function-arbitrary-file-write-via-error-log</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-75828-grav-stored-xss-in-xss-detector-via-unpaired-quote-bypass</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-74907-grav-path-traversal-in-static-asset-server</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-72695-grav-path-traversal-in-mediauploadtrait-deletefile</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-86003-coredns-rfc-2136-update-bypass-in-doh-doq-grpc</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-86000-soup-sieve-redos-in-identifier-and-value-selector-patterns</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-85999-soup-sieve-polynomial-time-redos-in-whitespace-trimming-regex</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-88976-plate-html-deserialization-xss-via-browser-parsing-behavior</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-84997-reactphp-http-denial-of-service-in-chunked-decoder</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-82399-coredns-unauthenticated-memory-exhaustion-in-doh-doq-and-doh3</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-81876-hapi-fhir-shcparser-deflate-infinite-loop-denial-of-service</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-81875-hapi-fhir-shcparser-unbounded-deflate-decompression-denial-of</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/djust-template-xss-via-inherited-context-safety-grant-eaaae5cf</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/djust-six-template-auto-escaping-bypass-xss-fc506972</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-81871-opentelemetry-go-otlp-log-grpc-exporter-tls-certificate</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-81870-opentelemetry-go-endpoint-url-logging-in-tracerprovider</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-81868-steeltoe-certificate-authorization-header-spoofing-via-missing</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-81516-steeltoe-discovery-consul-malformed-secure-metadata-dos</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-81515-steeltoe-eureka-discovery-client-denial-of-service-via-malformed</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-86049-jupyter-server-token-leakage-in-5xx-error-logs</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-81176-svelte-devalue-dos-via-malformed-input</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-79752-cakephp-functionsbuilder-sql-injection-in-multiple-methods</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-72697-grav-cms-media-directory-path-traversal-and-file-disclosure</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-76839-grav-user-interface-credential-leak-via-twig-sandbox-offsetget</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-76846-grav-sandbox-config-denial-paths-incomplete-exposing-system</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-72698-grav-cms-twig-sandbox-bypass-via-system-site-theme-arrays</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-72701-grav-cms-non-constant-time-nonce-comparison-in-csrf-protection</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-72702-grav-cms-origin-validation-bypass-in-referrer-origin-check</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-45140-chamilo-lms-cstudio-upload-flow-unauthenticated-remote-code</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-92943-aws-iot-device-sdk-for-python-certificate-host-mismatch</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-68537-fulgur-non-painting-replaced-elements-denial-of-service</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-68523-fulgur-unbounded-page-slicing-denial-of-service</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-86039-libp2p-peerstore-peer-id-spoofing-in-signed-records</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-75523-steeltoe-management-endpoint-httpexchanges-query-string-secret</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-75831-grav-stored-xss-via-markdown-audio-video-source-url</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-86038-libp2p-gossipsub-message-authentication-bypass-in-rsa-peer-ids</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-72832-grav-stored-xss-via-quoted-attribute-bypass-in-detectxss</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-85717-asynchttpclient-credential-leak-on-cross-origin-redirect</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-85720-asynchttpclient-credentials-exposure-in-plaintext-connect-proxy</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-85721-asynchttpclient-unbounded-http-1-1-response-decompression-denial</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-85716-asynchttpclient-scram-and-digest-mutual-authentication</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-85756-ssh-net-scpclient-remote-code-execution-via-unquoted-scp-paths</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-69147-vllm-request-selected-pynvvideocodec-gpu-decode-bypasses-vram</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-69089-grav-cms-path-traversal-in-imagemedium-watermark</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-69088-grav-cms-incomplete-callable-validation-in-blueprint-dynamic</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-85732-oras-go-blind-ssrf-via-unvalidated-link-header-in-pagination</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-85731-oras-go-arbitrary-file-write-via-symlink-chain-bypass-in-tar</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-86043-skipper-opa-body-authz-bypass-in-chunked-http-2-requests</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-77412-rabbitmq-amqp091-go-denial-of-service-via-malicious-field-length</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-77411-rabbitmq-amqp091-go-protocol-desynchronization-via-integer</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-77410-rabbitmq-amqp091-go-resource-exhaustion-via-unbounded-buffer</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-77408-rabbitmq-amqp091-go-silent-data-truncation-via-shortstr-integer</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-77407-rabbitmq-amqp091-go-plaintext-credential-exposure-in-plain-auth</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-77406-rabbitmq-amqp091-go-resource-exhaustion-via-signed-to-unsigned</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-77405-rabbitmq-amqp091-go-missing-tls-minimum-version-configuration</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-77404-rabbitmq-amqp091-go-connection-configuration-injection-via-tls</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-77403-rabbitmq-amqp091-go-denial-of-service-in-frame-size-negotiation</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-86071-junrar-localfolderextractor-path-traversal-via-intermediate</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-77401-zope-accesscontrol-information-disclosure-via-string-format</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-76825-restrictedpython-sandbox-escape-via-string-formatter-field</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-85715-exifreader-denial-of-service-via-crafted-heic-avif-iloc-box</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-61700-mariadb-connector-j-allowlocalinfile-bypass-in-local-infile</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-69197-umbraco-delivery-api-authorization-bypass-in-content-reference</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-85078-sanic-http-chunked-trailer-request-smuggling</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-63506-tinacms-auth-broken-access-control-in-isauthorized</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-63225-redocly-cli-path-traversal-in-split-command</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-82410-pocketbase-unhandled-panic-in-worker-goroutines</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-62949-asyncssh-event-loop-infinite-loop-via-zero-maximum-packet-size</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-63126-wire-protobuf-decoder-integer-overflow-denial-of-service</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-77360-orpc-vary-header-injection-in-cors-plugin</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-75516-rabbitmq-java-client-frame-level-oom-via-math-min-with-unlimited</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-75513-marten-linq-provider-sql-injection-via-unescaped-string-literals</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-59823-litellm-proxy-server-side-request-forgery-in-user-config</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-71538-cyclonedx-cyclonedx-npm-shell-injection-in-workspace-argument-on</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-63472-vendure-account-takeover-in-external-authentication</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-63461-vendure-shop-api-authorization-bypass-via-filteroperator</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-63460-vendure-unauthenticated-redos-in-regex-filter-on-sqlite</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-63459-vendure-dashboard-stored-xss-in-richtextdescriptioncell</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-61793-nuxt-og-image-unauthenticated-ssrf-in-font-url-validation</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-64684-model-context-protocol-rust-sdk-custom-header-leak-on-cross</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-13348-schneider-electric-powerchute-serial-shutdown-improper</loc><lastmod>2026-09-24</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2025-6625-schneider-electric-modicon-m340-improper-input-validation-in-ftp</loc><lastmod>2026-09-24</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-15688-mitsubishi-electric-gx-works3-authentication-bypass-in-block</loc><lastmod>2026-09-24</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-86520-bransys-eld-hardcoded-credentials-and-cleartext-transmission</loc><lastmod>2026-09-24</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2024-4872-hitachi-energy-facts-control-platform-multiple-vulnerabilities-in</loc><lastmod>2026-09-24</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-13336-schneider-electric-netbotz-5-750-755-os-command-injection-and-sql</loc><lastmod>2026-09-24</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-61709-openfga-listusers-incorrect-authorization-in-intersection</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-63671-nuxtjs-mdc-url-sanitizer-bypass-via-svg-xlink-href-and-data</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-63128-rmcp-streamable-http-server-unauthenticated-session-table-memory</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-63127-rmcp-missing-resource-field-validation-in-oauth-metadata</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-57173-vllm-unauthenticated-audio-decompression-bomb-dos</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-61599-djust-unauthenticated-arbitrary-module-import-in-websocket-sse</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-61589-djust-host-header-omission-in-websocket-tenant-resolution</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-61596-djust-broken-object-level-access-control-idor</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-61588-djust-django-model-serialization-sensitive-data-exposure</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-61594-djust-authorization-bypass-on-websocket-sse-mount-path</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-61591-djust-state-snapshot-state-injection-vulnerability</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-61592-djust-sse-session-hijacking-via-client-chosen-session-id</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-61597-djust-stored-reflected-xss-via-javascript-urls-in-component-tags</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-86831-amazon-eks-aws-network-policy-agent-cross-namespace-networkpolicy</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-68904-node-opcua-tcp-socket-leak-in-keepalive-reconnection</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-61593-djust-server-sent-events-cross-site-request-forgery</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2025-59953-lmdeploy-remote-code-execution-via-pickle-deserialization-in-zmq</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-61595-djust-multi-tenant-isolation-bypass-on-websocket-sse</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-61598-djust-mass-assignment-of-arbitrary-view-attributes-in-update</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-81192-opentelemetry-resources-host-path-hijacking-privilege-escalation</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-61590-djust-observability-endpoints-authentication-bypass</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-61560-zereight-mcp-gitlab-unauthenticated-arbitrary-file-read-via</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cisa-cyber-decoys-guidance-for-detection-and-response-4396c45f</loc><lastmod>2026-09-24</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-58704-google-pixel-improper-authorization-in-cellular-modem</loc><lastmod>2026-09-24</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-76460-cisco-identity-services-engine-incorrect-privileged-api-use</loc><lastmod>2026-09-24</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-87886-acronis-backup-privilege-escalation-in-cpanel-whm-and-plesk</loc><lastmod>2026-09-24</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-15587-google-security-operations-soar-privilege-escalation-via</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-61559-zereight-mcp-gitlab-server-side-request-forgery-in-dynamic-api</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-61568-zereight-mcp-gitlab-dns-rebinding-in-streamable-http-transport</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/zereight-mcp-gitlab-multiple-safety-control-bypasses-fcdfc95d</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/zereight-mcp-gitlab-multiple-safety-control-bypasses-6b1d97f3</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-61554-emp3r0r-http-polling-unauthenticated-dos</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-88975-http4s-ember-http-2-frame-buffering-denial-of-service</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-61544-libp2p-quic-remote-panic-in-quic-handshake-certificate-validation</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-69201-http4s-resourceservice-and-webjarservice-path-traversal-via</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-69218-http4s-ember-http-2-unbounded-continuation-frame-accumulation</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-69216-http4s-ember-chunk-parser-lenience-in-http-request-smuggling</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-69215-http4s-cookiejar-middleware-cookie-leakage-via-substring-matching</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-69214-http4s-cookiejar-middleware-accepts-arbitrary-set-cookie-domain</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-69213-http4s-ember-http-2-unbounded-outbound-frame-queue-denial-of</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-69208-http4s-digestauth-memory-exhaustion-via-unbounded-nonce-cache</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-69206-http4s-digestauth-replay-attack-in-authorization-header</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-69205-http4s-ember-http-request-smuggling-via-transfer-encoding-parsing</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-69204-http4s-ember-http-request-smuggling-via-transfer-encoding-and</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-69203-http4s-ember-http-2-stream-limit-enforcement-bypass</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-69202-http4s-ember-http-2-unbounded-inbound-body-buffering</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/nezha-oauth2-redirect-uri-host-header-injection-regression-331e924a</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-32599-netmaker-boolean-based-sql-injection-in-dns-deletion</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-81861-schneider-electric-scadapack-x70-insufficiently-protected</loc><lastmod>2026-09-24</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-76081-zitadel-improper-role-revocation-on-granted-projects</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-59178-esphome-device-builder-authentication-bypass-via-silent-env-var</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-86830-aws-team-privilege-escalation-in-iam-identity-center</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/october-cms-incomplete-url-scheme-validation-in-image-resizer-f7555212</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-49400-october-cms-php-object-injection-in-widget-session-storage</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-46696-october-cms-twig-sandbox-bypass-in-safe-mode</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-76461-cisco-secure-email-gateway-sql-injection</loc><lastmod>2026-09-24</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-61534-yayson-prototype-pollution-in-store-legacystore-deserialization</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-59973-frontmcp-and-mcp-from-openapi-ssrf-bypass-in-openapi-ref</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-56825-shopper-collectionproducts-missing-authorization-on-product</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-56830-shopper-media-component-missing-authorization-in-store</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-56829-shopper-variantstock-missing-authorization-and-unlocked-property</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-56828-shopper-privilege-escalation-via-improper-livewire-authorization</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-56826-shopper-framework-missing-authorization-in-settings-components</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-56831-shopper-framework-negative-discount-validation-bypass</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-56827-shopper-authorization-bypass-in-filament-bulk-actions</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-59971-mysql-mcp-server-missing-authentication-and-dns-rebinding</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-89332-kiro-ide-sensitive-workspace-data-exfiltration-via-agent-written</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-89090-aws-sdk-for-go-v2-denial-of-service-in-eventstream-header-decoder</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-18061-aws-advanced-jdbc-wrapper-xxe-in-remotequerycacheplugin</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-89065-projen-path-traversal-in-file-manifest-cleanup</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-84869-connectwise-screenconnect-unauthorized-file-transfer-and</loc><lastmod>2026-09-24</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-42018-jfrog-artifactory-improper-authentication-vulnerability</loc><lastmod>2026-09-24</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-85706-gitlab-community-and-enterprise-edition-path-traversal-in-commits</loc><lastmod>2026-09-24</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-65107-slurm-sbcast-shared-library-validation-bypass</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-88006-open-webui-oauth-token-exchange-authorization-bypass</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-88008-traefik-http-request-smuggling-via-unrestricted-protocol-upgrade</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-88004-traefik-entrypoint-header-sanitization-bypass-via-request</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-88007-traefik-http-3-backend-ntlm-connection-reuse</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-88009-traefik-rootless-http-1-request-target-routing-bypass</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-88014-rclone-archive-zip-zip-slip-path-traversal</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-88013-rclone-http-backend-header-forwarding-on-redirect</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-88016-rclone-directory-metadata-escape-through-symlink-in-links-mode</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-88015-rclone-local-symlink-range-header-dos</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-88018-rclone-serve-s3-sigv4-signature-bypass-with-auth-proxy</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-88044-rclone-per-server-auth-proxy-bypass-in-ftp-and-s3</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-88017-rclone-ftp-cross-session-auth-proxy-backend-confusion</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-88046-rclone-path-traversal-via-object-name-escaping-on-upload</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-88045-rclone-serve-s3-multipart-declared-length-memory-exhaustion</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-87011-open-webui-oidc-back-channel-logout-denial-of-service</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-87012-open-webui-calendar-alert-suppression-via-non-numeric-meta-value</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-87013-open-webui-infinite-loop-via-folder-parent-cycle</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-87014-open-webui-session-privilege-escalation-through-sso-role-sync</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-59965-jhb-software-payload-alt-text-plugin-authorization-bypass-in</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-59960-argos-ci-core-os-command-injection-in-git-branch-handling</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/mistral-rs-unbounded-media-fetch-and-video-frame-extraction-dos-9ec59bbb</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/mistral-rs-media-loader-ssrf-and-arbitrary-file-read-via-image-url-669bc2df</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-87015-open-webui-session-cookie-disclosure-in-tool-servers</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-87016-open-webui-wildcard-injection-in-oauth-oidc-identity-matching-on</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-88062-omniroute-acp-custom-agent-remote-code-execution</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-86073-n8n-oauth-consent-bypass-via-unbound-refresh-token</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-86074-n8n-instance-ai-credential-setup-ssrf-via-unvalidated-probe-url</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-86995-n8n-git-node-config-bypass-enables-local-repository-read</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-86085-n8n-missing-authorization-in-role-assignment-endpoints</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-86993-n8n-log-streaming-credentials-unauthorized-access</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-86084-n8n-authentication-bypass-via-disabled-oidc-sso-endpoints</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-86080-n8n-github-trigger-cryptographic-signature-verification-fail-open</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-86079-n8n-path-injection-in-elasticsearch-and-elasticsecurity-nodes</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-86078-n8n-prototype-pollution-in-workflow-summary</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-86994-n8n-missing-authorization-in-active-workflows-endpoint</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-86083-n8n-expression-sandbox-escape-in-legacy-engine-via-json-stringify</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-86077-n8n-approval-gate-bypass-via-reused-resumetoken-in-chat-websocket</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-88011-traefik-forwardauth-identity-spoofing-via-header-alias</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-88012-traefik-readtimeout-not-enforced-on-http-3-connections</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-88060-angular-platform-server-ssr-xss-via-unescaped-template-in</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-88056-angular-platform-server-ssrf-via-url-resolution-discrepancy</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-88059-angular-information-leak-in-httptransfercache-with-hierarchical</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-88057-angular-sanitization-bypass-in-directive-host-bindings</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-55416-pimcore-sql-injection-in-custom-reports-via-configuration</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-89049-aws-systems-manager-agent-ssrf-in-session-manager-port-forwarding</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-85228-aws-deep-java-library-integer-overflow-in-tensor-buffer</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-86082-n8n-openai-chat-model-domain-restriction-bypass-in-model-search</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-86081-n8n-regular-expression-denial-of-service-in-git-node-file-pattern</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-86075-n8n-unauthenticated-storage-exhaustion-via-oauth-registration</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-86076-n8n-expression-sandbox-escape-via-class-field-sanitizer-rebinding</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-87017-open-webui-knowledge-tool-authorization-bypass</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-87994-open-webui-message-authorship-bypass-in-channel-completions</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-87995-open-webui-account-takeover-via-port-preview-iframe-sandbox</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-87996-open-webui-ssrf-via-dns-rebinding-in-playwright-web-loader</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-87997-open-webui-missing-folder-write-access-check-in-chat-completions</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-87998-open-webui-privilege-escalation-in-external-knowledge-connection</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-87999-open-webui-server-side-request-forgery-in-url-fetching</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-88005-open-webui-oauth-token-exchange-authorization-bypass</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/eigenpal-docx-editor-css-injection-and-print-time-xss-via-font-family-24c5738e</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/eigenpal-docx-editor-react-css-injection-and-xss-via-font-family-name-722ac5b4</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-84939-apache-freemarker-path-traversal-in-template-loading</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-86060-mikrotik-routeros-argument-delimiter-neutralization-privilege</loc><lastmod>2026-09-24</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-67277-mikrotik-routeros-missing-authentication-in-btest-service</loc><lastmod>2026-09-24</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-88000-open-webui-denial-of-service-via-cyclic-chat-tree-message</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-88001-open-webui-server-side-request-forgery-via-unvalidated-http</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-88002-open-webui-infinite-loop-denial-of-service-in-chat-history</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-59185-identrail-cross-tenant-idor-via-unverified-github-app</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-59179-openhop-server-path-traversal-in-flow-id-file-operations</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-59177-esphome-device-builder-auth-bypass-via-unrestricted-ingress</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-59176-functype-mcp-server-set-functype-version-package-alias-rce</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-59172-joker-linter-arbitrary-code-execution-in-project-local-config</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/komari-management-interface-csrf-b9b45191</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-59160-yeger-turbo-graph-unauthenticated-task-execution-via-api-run</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-59158-nuxt-ollama-credentials-exposure-in-public-runtime-config</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-59157-webhookd-unrestricted-http-header-to-shell-variable-injection</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-55864-geonetwork-unauthenticated-server-side-request-forgery-in-sld</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-19642-aws-sdk-for-c-memory-safety-issues-in-base64-decoder</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-18954-amazon-aws-labs-documentdb-mcp-server-authorization-bypass-in</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-19111-aws-strands-agents-tools-insecure-direct-object-reference-in</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-18952-opensearch-security-analytics-plugin-missing-input-validation</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-19311-opensearch-alerting-plugin-missing-authorization</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-18953-aws-transform-mcp-server-improper-pathname-validation</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-85781-amazon-efs-csi-driver-insufficient-access-point-ownership</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-81838-awsdac-zip-slip-path-traversal-vulnerability</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-78379-amazon-strands-agents-tools-python-repl-consent-bypass</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-83497-opensearch-sql-plugin-unrestricted-java-deserialization-in-cursor</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-75897-opensearch-dashboards-uncontrolled-resource-consumption-in</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-84942-opensearch-dashboards-stored-xss-via-vega-expression-function</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-85786-amazon-ion-java-memory-amplification-denial-of-service</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-85012-amazon-codecatalyst-blueprints-sdk-os-command-injection</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-77234-aws-freertos-kernel-memory-safety-issues</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-85654-amazon-awslabs-dynamodb-mcp-server-code-injection-in-cdk</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-75910-aws-athena-clickhouse-connector-privilege-escalation-in-secrets</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-87912-aws-security-agent-missing-s3-bucket-ownership-verification</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-18428-opensearch-sql-plugin-async-query-validation-bypass</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-85788-aws-labs-mysql-mcp-server-read-only-enforcement-bypass-via-sql</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-81849-amazon-ssm-agent-path-traversal-in-aws-downloadcontent-plugin</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-85787-amazon-postgres-mcp-server-sql-validation-bypass</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-75935-amazon-ion-java-memory-amplification-denial-of-service</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-85028-aws-fpga-development-kit-arbitrary-code-execution-via-insecure</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-77811-opensearch-dashboards-stored-cross-site-scripting-in-integration</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-83551-amazon-sagemaker-python-sdk-cleartext-hmac-key-storage</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-84851-amazon-ion-c-uncontrolled-recursion-in-reader</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-77810-aws-athena-federated-query-neptune-connector-credential-exposure</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-85730-smol-toml-infinite-loop-in-parser-via-malformed-toml</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-55073-weasyprint-server-side-request-forgery-and-local-file-read-via</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-54529-sqladmin-unvalidated-sortby-parameter-in-modelview-bypasses</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-53495-containerd-cri-execsync-goroutine-leak-denial-of-service</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-50024-githacker-path-traversal-in-ref-parsing-enables-file-existence</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-44282-decidim-decidim-elections-stored-xss-in-question-titles</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2025-58363-lf-edge-ekuiper-path-traversal-in-plugin-installation</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2025-24979-lf-edge-ekuiper-ssrf-in-external-service-registration</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2025-24978-lf-edge-ekuiper-stored-xss-in-external-service-creation</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2025-24890-gitoxidelabs-gix-sec-safe-directory-bypass-in-elevated</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-69304-microsoft-asp-net-core-iis-middleware-denial-of-service-in</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-69522-microsoft-diasymreader-native-heap-buffer-overflow-in-pdb</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-69439-microsoft-diasymreader-native-heap-overflow-in-pdb-parsing</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-71328-microsoft-diasymreader-native-heap-buffer-overflow</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-19490-citrix-netscaler-authentication-bypass-via-alternate-path</loc><lastmod>2026-09-24</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-87491-google-chromium-v8-out-of-bounds-write-in-javascript-engine</loc><lastmod>2026-09-24</lastmod></url>
  <url><loc>https://junglewise.ai/threats/containerd-cri-security-context-bypass-in-checkpoint-restore-d7cf36e0</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-86996-n8n-agent-workflow-tool-bypasses-sub-workflow-caller-policy</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/nodemailer-idn-domain-allow-list-bypass-in-address-normalization-234ce721</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-92598-nodemailer-idn-punycode-domain-allow-list-bypass</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-92596-nodemailer-quadratic-time-complexity-in-address-parser-denial-of</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/nodemailer-quadratic-time-complexity-in-address-parser-f6132e7e</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/nodemailer-email-address-validation-bypass-in-rfc-5322-comment-parsing-c1300f22</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-92597-nodemailer-recipient-domain-validation-bypass-via-rfc-5322</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/typespec-openapi3-path-traversal-in-version-placeholder-4368a6df</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/microsoft-typespec-openapi3-path-traversal-in-version-value-2fdcfbf7</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-77078-multer-denial-of-service-via-crafted-multipart-field-names</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-77037-express-multer-file-descriptor-leak-on-aborted-uploads</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-77063-multer-file-size-limit-bypass-via-async-filefilter-race-condition</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-82333-multer-denial-of-service-via-oversized-array-index-in-field-names</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-15603-express-js-morgan-log-forging-via-unicode-line-separators</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-84452-microsoft-winml-cli-cors-misconfiguration-enables-localhost-rce</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-81525-mongodb-php-library-namespace-injection-in-database-and</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/astro-remote-code-execution-via-avif-image-processing-6b99ffe8</loc><lastmod>2026-09-24</lastmod></url>
  <url><loc>https://junglewise.ai/threats/astro-remote-code-execution-through-avif-image-optimization-79155f65</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-84376-astro-authorization-bypass-in-base-path-stripping</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-84361-composer-arbitrary-command-execution-via-malicious-perforce</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/sharp-heap-based-buffer-overflow-via-libheif-image-parsing-6451a83e</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/sharp-remote-code-execution-via-malformed-heif-image-32a48ae6</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-84375-js-yaml-denial-of-service-via-empty-merge-sources</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-84308-phpseclib-x25519-non-constant-time-scalar-multiplication-private</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/tiptap-redos-in-markdown-attribute-parsing-9e6d9287</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/tiptap-quadratic-redos-in-markdown-attribute-parsing-7c4b0aab</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-84365-hono-tossg-path-traversal-with-consecutive-parent-directory</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-84364-hono-parsebody-memory-exhaustion-with-unbounded-dot-notation</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-84363-hono-query-parser-fragment-interpretation-differential</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-84445-grpc-go-xds-server-denial-of-service-via-missing-headers</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/next-js-image-optimization-heap-buffer-overflow-via-avif-9ce530ed</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/next-js-heap-buffer-overflow-in-image-optimization-via-malicious-avif-90b951e0</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-84370-svgo-removescripts-xss-bypass-via-namespace-and-control-character</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-84369-svgo-removescripts-incomplete-html-sanitization-in-foreignobject</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/nodemailer-resolvecontent-sandbox-bypass-in-legacy-signature-09738384</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-92595-nodemailer-resolvecontent-legacy-signature-security-sandbox</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-83616-xmldom-processing-instruction-target-injection-in-serialization</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-83617-xmldom-xmlserializer-requirewellformed-bypass-via-line-terminator</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-83608-xmldom-doctype-name-injection-bypasses-requirewellformed</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-83609-xmldom-name-qname-validation-bypass-via-embedded-line-terminator</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-83618-xmldom-requirewellformed-doctype-validation-bypass-via-line</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-83611-xmldom-parser-silently-accepts-malformed-xml-end-tags</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-83613-xmldom-quadratic-time-attribute-deduplication</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-83619-xmldom-end-tag-whitespace-trim-redos</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-83615-xmldom-quadratic-memory-consumption-in-namespace-parsing</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-83614-xmldom-quadratic-time-parsing-denial-of-service</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-83612-xmldom-html-raw-text-closing-tag-case-mismatch-causes-output</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-84372-predis-redis-command-injection-in-pipelined-cluster-connections</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-77635-cakephp-functionsbuilder-jsonvalue-sql-injection-with</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-77634-cakephp-smtptransport-crlf-header-injection</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-84368-joi-prototype-pollution-via-proto-in-custom-messages</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-85062-colord-regular-expression-denial-of-service-in-color-parsing</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-75604-next-js-unauthenticated-remote-code-execution-on-windows</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-84367-hapi-joi-object-rename-prototype-pollution-via-template-target</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-85061-maplibre-gl-js-xss-sanitizer-bypass-in-dom-sanitize</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-84303-grpc-go-xds-rbac-http-filter-bypass-via-case-sensitive-header</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-84382-pydantic-httpx2-decompression-memory-amplification</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-84373-vitest-vitest-mocker-path-traversal-in-redirect-mock</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-84380-pydantic-httpx2-http-request-smuggling-via-conflicting-headers</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-84379-httpx2-multipart-header-injection-via-unvalidated-content-type</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-84378-httpx2-quadratic-sse-line-buffering-denial-of-service</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-84381-httpx2-secure-websocket-plaintext-transmission-via-socks-proxy</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-73560-vllm-ssrf-and-arbitrary-file-read-in</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-84374-laravel-excel-arbitrary-file-overwrite-via-path-traversal</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-83606-xmldom-pi-grammar-regex-redos-in-unterminated-processing</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-83607-xmldom-element-name-injection-via-createelement</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-83605-xmldom-setattribute-attribute-name-injection</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-81725-nltk-pl196xcorpusreader-quadratic-redos-on-malformed-tei-blocks</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-80206-nltk-tgrep-regular-expression-denial-of-service</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-80205-nltk-redos-in-text-findall-via-unvalidated-regex</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-62815-microsoft-quic-use-after-free-in-path-migration</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-62900-microsoft-net-information-disclosure-in-git-and-sourcelink</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-73558-vllm-integer-overflow-in-kernel-causing-cross-user-data-leak</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-78679-gitpython-tagreference-create-argument-injection-bypasses-file</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-78677-gitpython-clone-from-omits-separate-git-dir-from-denylist</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-78678-gitpython-arbitrary-file-read-in-repo-blame-via-incomplete-option</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-78676-gitpython-config-parser-multi-line-value-injection-in-write</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-78675-gitpython-arbitrary-local-file-content-disclosure-via-gitmodules</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/microsoft-visual-studio-heap-buffer-overflow-in-diasymreader-b617ae69</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/microsoft-visual-studio-heap-buffer-overflow-in-diasymreader-20fcd9b2</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/microsoft-net-and-visual-studio-heap-buffer-overflow-elevation-of-02f3702a</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/microsoft-asp-net-core-iis-integration-denial-of-service-via-data-69730a19</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-75595-netty-sni-routing-bypass-via-fragmented-tls-clienthello</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-75596-netty-quadratic-pre-handshake-clienthello-reassembly-in-sni</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-71494-infracost-terraform-cloud-token-disclosure-via-unvalidated</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-71493-infracost-path-traversal-via-symlink-following-in-config-template</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-73087-dozzle-webhook-ssrf-guard-bypass-via-ipv6-transition-addresses</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-69222-liquidjs-uncontrolled-resource-consumption-in-join-filter</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-73262-prowler-stored-xss-in-html-reports-through-unescaped-resource</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-85063-csv-parse-prototype-pollution-via-columns-configuration</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-72925-swc-html-minifier-script-injection-via-json-escaping</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-60004-gitea-code-injection-in-diffpatch-api</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-72789-siyuan-publish-access-gate-treats-encrypted-notebooks-as-public</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-72790-siyuan-getnotebookinfo-unauthorized-disclosure-in-api</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/siyuan-getattributeviewfieldviews-missing-authorization-cb8fd4f6</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-79674-nltk-corpus-reader-sandbox-bypass</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-79676-nltk-corpus-readers-symlink-boundary-bypass</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-79657-nltk-remote-code-execution-via-unsafe-pickle-deserialization</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-78681-nltk-entity-expansion-denial-of-service-via-elementtree-parsing</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-78682-nltk-pathsec-ssrf-bypass-with-http-proxy</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-78683-nltk-unsafe-pickle-deserialization-in-transitionparser</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-62383-nltk-ipipancorpusreader-symlink-based-arbitrary-file-read</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-62384-nltk-framenetcorpusreader-symlink-sandbox-bypass</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-62385-nltk-framenet-and-nkjp-readers-path-traversal-via-corpus</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-12259-nltk-missing-post-download-integrity-verification</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-63312-nltk-streambackedcorpusview-pathsec-enforce-bypass</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-65915-nltk-filesystempathpointer-sandbox-bypass-arbitrary-file-read</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-70626-nltk-symlink-escape-in-corpusreader-local-file-read</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-76969-sap-cds-mtxs-credential-disclosure-in-multitenant-cap</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-81963-microsoft-windows-privilege-escalation-via-link-following-in</loc><lastmod>2026-09-24</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-86218-n-able-n-central-static-code-injection-vulnerability</loc><lastmod>2026-09-24</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-85880-microsoft-windows-heap-based-buffer-overflow-in-advanced-local</loc><lastmod>2026-09-24</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-75650-adobe-commerce-and-magento-improper-neutralization-in-template</loc><lastmod>2026-09-24</lastmod></url>
  <url><loc>https://junglewise.ai/threats/typespec-spector-unauthenticated-remote-shutdown-via-post-admin-stop-da8e8fd5</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/typespec-spector-unauthenticated-remote-shutdown-547234f5</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-73557-vllm-concurrent-prompt-embedding-guard-bypass</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-73556-vllm-redos-in-lm-format-enforcer-backend-regex-parsing</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-73555-vllm-information-disclosure-via-validation-error-messages</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-71486-vllm-derender-endpoints-unbounded-token-decoding-dos</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-72792-siyuan-tag-api-information-disclosure-via-password-bypass</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-72793-siyuan-getconf-information-disclosure-of-session-key-and-secrets</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-72795-siyuan-embedded-block-content-leak-via-missing-publish-access</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-72794-siyuan-session-cookie-signing-key-disclosure-in-api-system</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-72796-siyuan-static-routes-access-control-bypass</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-72797-siyuan-getencryptednotebookstatus-information-disclosure</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-72798-siyuan-renderattributeview-missing-authorization-in-related</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-72799-siyuan-missing-publish-access-filter-on-path-resolution-endpoints</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-75911-codewhale-project-config-allow-shell-override-enables-arbitrary</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-75858-codewhale-rlm-eval-approval-bypass-code-execution</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-75912-codewhale-git-blame-argument-injection-allows-arbitrary-file-read</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-75856-codewhale-ssrf-bypass-via-toctou-in-dns-pinning</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-75915-codewhale-js-execution-environment-variable-disclosure</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-75913-codewhale-argument-injection-in-git-show-tool</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-75857-codewhale-exec-shell-interact-privilege-escalation-via-llm-input</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-75859-codewhale-project-config-instructions-arbitrary-file-read</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-75914-codewhale-image-analyze-symlink-path-traversal-in-vision-tool</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/simplewebauthn-certificate-chain-validation-bypass-ee3041ed</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/simplewebauthn-attestation-certificate-chain-validation-bypass-cd1a87f7</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-85046-google-chromium-v8-type-confusion-vulnerability</loc><lastmod>2026-09-24</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-4644-google-cloud-integration-connectors-http-missing-authorization</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-72800-siyuan-missing-authorization-filters-on-api-endpoints-leaks</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-72801-siyuan-encrypted-notebook-key-material-and-wrapped-keys</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-72802-siyuan-resolveassetpath-information-disclosure</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-72803-siyuan-missing-publish-access-filter-on-getblockattrs-and</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-72804-siyuan-graph-endpoints-bypass-publish-password-protection</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-72805-siyuan-missing-authorization-in-block-api-endpoints</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-72806-siyuan-attribute-view-database-password-bypass-in-publish-mode</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-72807-siyuan-second-order-sql-injection-via-queryblocks-template</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-72808-siyuan-missing-authorization-on-getfileannotation-endpoint</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-72809-siyuan-kernel-localhost-trust-admin-bypass-on-auth-gated</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-72810-siyuan-publish-boundary-bypass-via-websocket-broadcast</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-72811-siyuan-backlink-search-sql-injection-via-unescaped-metadata</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-72812-siyuan-missing-authorization-in-refreshbacklink-endpoint</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-68584-siyuan-password-protected-document-bypass-via-content-api</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-68585-siyuan-missing-authorization-in-getblockinfo-metadata-endpoint</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-68586-siyuan-getbacklinkdoc-getbackmentiondoc-authorization-bypass-in</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-68587-siyuan-getheading-transaction-authorization-bypass-in-publish</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-69083-siyuan-fulltextsearchassetcontent-sql-injection-and-regexp</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-77465-toml-node-uncontrolled-recursion-in-parser</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-63376-npm-toml-prototype-pollution-via-proto-desynchronization</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-69086-siyuan-path-traversal-in-attribute-view-read-endpoints</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-71429-stream-json-path-filters-algorithmic-complexity-denial-of-service</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-69084-siyuan-arbitrary-sql-execution-via-searchembedblock</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-79921-rabbitmq-amqp091-go-memory-exhaustion-in-frame-parsing</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-63670-sanitize-html-xss-bypass-via-textarea-solidus-close-tag</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-63669-apostrophecms-page-move-authorization-bypass</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-73295-material-for-mkdocs-dom-xss-in-search-suggestions</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-82404-toon-format-prototype-pollution-in-decoder</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-62681-orval-code-injection-via-openapi-path-template-literal</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-62682-orval-code-injection-via-unescaped-server-url-in-template-literal</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-72717-orval-zod-schema-code-injection-via-unescaped-default-value</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-71869-orval-code-injection-in-zod-schema-generation-via-template</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-71871-orval-code-injection-in-zod-schema-generation</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-71867-orval-rce-via-schema-property-name-computed-property-key</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-71868-orval-template-literal-injection-in-zod-schema-defaults</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-71865-orval-zod-code-injection-via-unescaped-query-parameter-name</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-71864-orval-zod-client-import-time-rce-via-header-parameter-name</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-73232-ffuf-denial-of-service-via-http-response-decompression-bomb</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-61625-victoriametrics-vmrestore-path-traversal-in-backup-restore</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-61556-liquidjs-infinite-loop-in-strip-html-filter</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-75602-openlist-simplehttp-offline-download-path-traversal-arbitrary</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/openclaw-feishu-permission-tools-authorization-bypass-4a298b98</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/openclaw-feishu-tools-authorization-bypass-75a656d3</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-71428-unstructured-partition-server-side-request-forgery</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/siyuan-path-traversal-in-export-temp-branch-6fc4f947</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/siyuan-svg-sanitizer-bypass-leading-to-stored-and-reflected-xss-6a7a1f5f</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-67445-mailpit-smtp-command-parser-unbounded-buffering-denial-of-service</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-72921-seaweedfs-filer-jwt-authorization-bypass-in-allowed-prefixes</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-71485-centrifugo-header-spoofing-via-client-controlled-emulation</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-67446-mailpit-thumbnail-generation-unbounded-image-dimension-decode</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-84366-scrapy-s3downloadhandler-cleartext-transmission-of-aws</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-68921-dicebear-svg-injection-via-unescaped-numeric-options</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-62676-omnigent-shell-command-parser-policy-bypass-in-shell-py</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-65842-plate-docx-export-ssrf-with-response-disclosure</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-63490-handlebars-java-springtemplateloader-arbitrary-file-read-via-url</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-63481-hurl-cookie-leak-on-cross-host-redirects</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-63435-mail-email-address-spoofing-via-malformed-rfc-2047-encoded-words</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-62669-grav-2fa-bypass-via-unauthorized-secret-regeneration</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-62677-omnigent-path-traversal-in-agent-bundle-os-env-cwd</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-62674-omnigent-shared-agent-bundle-overwrite-leading-to-authenticated</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-62675-omnigent-authenticated-remote-code-execution-via-python-callable</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-61842-grav-twig-sandbox-config-exfiltration-via-offsetget-and-dump</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-61690-grav-ziparchiver-decompression-bomb-via-missing-extraction-limits</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-61704-link-preview-js-dns-rebinding-ssrf-bypass</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-75931-fastify-fast-uri-host-confusion-via-skipped-idn-canonicalization</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-75975-fast-uri-server-side-request-forgery-via-malformed-ipv6</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-75899-fast-uri-server-side-request-forgery-via-double-percent-decoding</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-76172-fast-uri-host-confusion-via-percent-encoded-scheme-normalization</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-62388-nltk-pathsec-insecure-default-configuration</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-63311-nltk-ssrf-fail-open-in-validate-network-url-via-dns-resolution</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-83610-xmldom-xml-fragment-injection-in-entityreference-serialization</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-76098-mistune-uncontrolled-recursion-in-html-rendering</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-16732-fastify-x-forwarded-header-spoofing-in-trustproxy-numeric-mode</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-18504-fastify-schema-validation-bypass-via-root-primitive-coercion</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-71553-apostrophecms-prototype-pollution-in-patch-endpoint</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-82396-sulu-stored-xss-via-media-download-inline-disposition-override</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-82394-sulu-authorization-bypass-in-preview-link-generation</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-82395-sulu-media-move-authorization-bypass-idor</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-63667-apostrophecms-import-export-path-traversal-arbitrary-file-read</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-75592-kirby-path-traversal-in-media-handling-via-sibling-directory</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-62680-orval-ssrf-and-file-inclusion-via-unrestricted-ref-resolution</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-72716-orval-code-generation-rce-via-unescaped-template-literals-in-zod</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-71866-orval-zod-client-import-time-rce-via-property-name-injection</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-72920-seaweedfs-unauthenticated-filer-iam-grpc-service-authentication</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-64850-grav-remote-code-execution-via-unrestricted-callable-in-blueprint</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-62672-grav-authenticated-redos-in-regex-replace-twig-filter</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-82562-npm-qs-array-limit-bypass-in-bracket-key-comma-parsing</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-82417-qs-stringify-denial-of-service-via-unchecked-isbuffer-call</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/tiptap-mergeattributes-prototype-pollution-leading-to-xss-32e26b93</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/tiptap-mergeattributes-prototype-pollution-enabling-xss-94f4a025</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-81892-easycorp-easyadminbundle-authorization-bypass-in-custom-action</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-81887-livewire-dom-based-cross-site-scripting-in-client-side-state</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-82397-tornado-urlencoded-body-parsing-dos-via-unbounded-fields</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-71492-banks-directorypromptregistry-path-traversal-in-set</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-82398-pypdf-inefficient-handling-of-non-whitespace-inputs-in-read-until</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-81891-elfinder-zip-extraction-mime-filter-bypass-allowing-php-upload</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-81890-elfinder-csrf-in-netmount-allows-forced-ftp-mounts</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-82392-pnpm-virtual-store-linker-path-traversal-via-unvalidated-deppath</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-82393-pnpm-tarball-dependency-manifest-name-path-traversal-arbitrary</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-81722-nltk-porterstemmer-quadratic-time-dos-via-long-runs-of-y</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-81727-nltk-downloader-hardlink-traversal-in-file-extraction</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-81726-nltk-model-artifact-apis-sandbox-bypass-via-path-traversal</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-81723-nltk-xmlcorpusview-quadratic-cpu-exhaustion</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-12876-nltk-recursivedescentparser-uncontrolled-recursion-denial-of</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-81724-nltk-featstructreader-uncontrolled-recursion-denial-of-service</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/imagemagick-memory-leak-in-cli-invalid-options-dc8e6305</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/humanfs-symlink-dereference-directory-traversal-b5fdd713</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/humanfs-symlink-dereference-allows-arbitrary-file-disclosure-4a851f9d</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-73231-faker-helpers-fake-arbitrary-code-execution</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-82329-jfrog-artifactory-improper-authentication-vulnerability</loc><lastmod>2026-09-24</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-83548-sonicwall-sma1000-server-side-request-forgery</loc><lastmod>2026-09-24</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-83549-sonicwall-sma1000-os-command-injection</loc><lastmod>2026-09-24</lastmod></url>
  <url><loc>https://junglewise.ai/threats/google-gke-multi-cloud-authorization-bypass-in-cluster-registration-af138b69</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-84304-grpc-go-heap-memory-exhaustion-via-http-2-data-frame</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-84306-filament-app-based-multi-factor-authentication-bypass-via-reused</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-84307-filament-password-validity-disclosure-in-login-mfa</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-77567-filament-multi-factor-authentication-bypass-in-app-based-mfa</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-84310-pypdf-denial-of-service-via-malicious-pdf-outlines</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-84311-pypdf-denial-of-service-via-crafted-xform-objects</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-84309-pypdf-infinite-loop-in-treeobject-insert-child</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-84305-sqlparse-quadratic-cpu-consumption-in-reindent-filter</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-84371-sanitize-html-stored-xss-via-svg-smil-uri-list-scheme-bypass</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-79675-nltk-jvm-argument-injection-bypass-in-stanford-wrappers</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/league-commonmark-denial-of-service-in-attributes-extension-932b44b3</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-78680-nltk-arbitrary-code-execution-via-uncontrolled-graphviz-dot</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/league-commonmark-denial-of-service-in-smartpunct-and-attributes-252cde7d</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/league-commonmark-xss-via-form-feed-in-attributesextension-d61618f5</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/league-commonmark-denial-of-service-via-parsing-algorithms-d1480161</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/tornado-multipart-form-data-memory-amplification-dos-in-httputil-py-5d8eb9f2</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/tornado-cookie-attribute-injection-via-case-insensitive-kwargs-c42b886c</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-73229-django-rest-framework-adminrenderer-permission-bypass-information</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-73086-nanoid-integer-overflow-in-csprng-pool</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/pnpm-environment-variable-exfiltration-via-proxy-settings-5cfe8952</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/pnpm-environment-secret-exfiltration-via-proxy-settings-in-workspace-f6626cca</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/pnpm-pacquet-path-traversal-in-lockfile-dependency-symlinks-dc3f81d1</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/pnpm-pacquet-path-traversal-in-lockfile-install-2f692861</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/mlflow-statsmodels-flavor-security-control-bypass-in-pickle-c4a0165d</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/mysql2-auth-plugin-downgrade-to-mysql-clear-password-leaks-credentials-620917f5</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/mysql2-auth-plugin-downgrade-to-mysql-clear-password-leaks-plaintext-4f504449</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-62993-smarty-ssrf-via-redirect-bypass-in-fetch</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-69127-kirby-rest-api-information-disclosure-via-error-messages</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/mysql2-unbounded-zlib-inflate-decompression-bomb-6d425342</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/mysql2-unbounded-zlib-inflate-decompression-bomb-dos-1b8791b1</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-71415-kirby-authorization-bypass-in-rest-api-file-uploads</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-75594-kirby-path-traversal-in-media-handler-via-encoded-slashes</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/nltk-tgrep-regular-expression-denial-of-service-02fca1b2</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-81888-hono-oauth-providers-oauth-state-validation-bypass-in-social</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-81889-elfinder-ssrf-protection-bypass-via-dns-rebinding</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/nodemailer-raw-message-option-bypasses-disablefileaccess-fb6da12e</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/nodemailer-message-level-raw-option-ssrf-and-file-read-af1f28b4</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-82078-papercut-ng-mf-unsafe-reflection-vulnerability</loc><lastmod>2026-09-24</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-81578-papercut-ng-mf-missing-authentication-for-critical-function</loc><lastmod>2026-09-24</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-55855-mariadb-connector-node-js-sql-injection-in-buffer-parameter</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-55860-mariadb-r2dbc-cleartext-password-disclosure-to-mitm</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-55859-mariadb-r2dbc-charset-confusion-leading-to-sql-injection</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-55858-mariadb-java-client-charset-confusion-encoding-mismatch</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-55857-mariadb-connector-j-cleartext-password-transmission-in-pam</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-55856-mariadb-connector-j-cleartext-password-disclosure-in-mitm</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-55848-mapfish-print-xxe-in-gml-layer-processing</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-55785-free5gc-ausf-non-constant-time-authentication-comparison-and</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-55784-free5gc-ausf-authentication-context-race-condition</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-55779-silverstripe-versioned-xss-in-archive-admin-restore</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-55867-graylog-token-revocation-endpoint-idor</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-55841-graylog-syslog-parser-field-injection-in-key-value-message</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-55764-klever-go-sft-add-quantity-int64-overflow-bypasses-maxsupply</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-55854-mariadb-connector-node-js-cleartext-password-transmission-in-pam</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-55678-arc-enterprise-authentication-bypass-in-cluster-node-admission</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-55763-klever-klever-go-percentage-transfer-royalty-zero-debit-in</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-55891-privatebin-reflected-json-injection-in-jsonld-endpoints</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-55696-privatebin-stored-xss-in-attachment-download-link</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/aiir-verification-and-policy-gates-fail-open-ab3a8d0c</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-55484-alos-http-unauthenticated-dos-in-sanitizerequestpath</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-55634-pimcore-dataobject-class-definition-field-name-remote-code</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-55220-pimcore-hotspotimage-unrestricted-php-object-deserialization</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-55215-mariadb-connector-node-js-cleartext-password-disclosure-to-mitm</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-55247-plone-plone-app-event-denial-of-service-in-icalendar-import</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-55622-incus-project-restriction-bypass-in-instance-copy</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-55621-incus-authorization-bypass-in-custom-volume-copy</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-55228-weblate-idor-in-groupviewset-authorization-bypass</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-55227-weblate-observable-object-existence-disclosure-via-http-status</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-55520-protego-redos-in-robots-txt-wildcard-matching</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-55248-plone-plone-app-portlets-denial-of-service-via-rss-feed-portlet</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-55673-powsybl-core-os-command-injection-in-localcommandexecutor</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-55584-phpsysinfo-ip-allowlist-bypass-via-header-spoofing</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-55245-bifrost-ssrf-bypass-in-ispublicip-ip-classification</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-55588-oras-cli-uncontrolled-recursion-in-referrer-graph-traversal</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-55485-piccolo-admin-privilege-escalation-via-session-token-disclosure</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-55509-wsgidav-mysqlbrowserprovider-blind-sql-injection</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-55425-graylog-server-information-disclosure-in-system-catalog-api</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-55566-yamcs-dom-xss-in-extension-routing</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-55565-yamcs-remote-code-execution-via-unescaped-streamsql-like-pattern</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-55559-yamcs-remote-code-execution-via-yaml-injection-in-instance</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-55552-yamcs-unauthenticated-directory-traversal</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-55549-yamcs-reflected-xss-in-authorize-endpoint</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-55547-yamcs-missing-authorization-on-role-and-privilege-enumeration</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-55545-yamcs-websocket-subscription-handlers-missing-authorization</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-55521-yamcs-core-api-missing-authorization-in-multiple-endpoints</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-55511-yamcs-authenticated-rce-via-streamsql-column-name-injection</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-55068-free5gc-nrf-input-validation-bypass-in-nf-profile-registration</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-55067-vikunja-kanban-bucket-cross-tenant-relocation-via-mass-assignment</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-55065-vikunja-authorization-bypass-in-project-view-deletion</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-55064-vikunja-incomplete-privilege-escalation-fix-via-parent-project-id</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-54766-vikunja-project-duplication-authorization-bypass</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-54788-datadog-dd-trace-rs-unbounded-w3c-tracestate-parsing-dos</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-55834-pocket-id-open-redirect-in-oidc-authorize-page-with-prompt-none</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-55569-aqua-archive-extraction-path-traversal-via-symlink</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-54755-klever-integer-overflow-in-split-royalty-validation-enables</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-54754-klever-marketplace-settlement-mints-klv-when-referral-and-royalty</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-55108-kubevela-terraform-remote-loader-dos-via-unbounded-file-read</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/gix-packetline-integer-underflow-in-side-band-packet-parsing-50c9592d</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-54746-hatchet-cross-tenant-authorization-bypass-in-dispatcher-grpc</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-55558-aiosmtplib-starttls-response-injection</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-54770-webob-open-redirect-via-leading-control-characters-in-location</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-37004-berriai-litellm-server-side-template-injection-in-prompts</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/nltk-downloader-hardlink-filesystem-containment-bypass-522cb97d</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/nltk-uncontrolled-recursion-in-featstructreader-denial-of-service-e246abcc</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/nltk-path-traversal-in-model-artifact-apis-via-pathsec-bypass-a4651c73</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/nltk-pl196xcorpusreader-quadratic-redos-on-malformed-tei-blocks-8473e6ef</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/nltk-quadratic-cpu-exhaustion-in-xmlcorpusview-read-xml-fragment-439bc4da</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/nltk-porterstemmer-quadratic-time-dos-via-long-runs-of-y-b1fab99a</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/crossplane-package-manager-signature-bypass-via-toctou-in-tag-c3cd8716</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-54732-libreoffice-convert-path-traversal-in-filename-handling</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-54718-silverstripe-advanced-workflow-rce-in-email-template</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-54687-n8n-nodes-sqlite3-path-traversal-via-user-controlled-database</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-54713-cakephp-queue-incomplete-comparison-in-getuniqueid</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-54721-silverstripe-userforms-remote-code-execution-in-email-subject</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2023-49105-owncloud-improper-authentication-vulnerability</loc><lastmod>2026-09-24</lastmod></url>
  <url><loc>https://junglewise.ai/threats/nltk-redos-in-text-findall-via-unvalidated-regex-70befad1</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-44701-openstamanager-html-injection-in-group-name</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/librenms-stored-xss-via-snmp-syslog-data-in-legacy-templates-a27e8a90</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-54614-cakephp-debugkit-mailpreview-unsafe-reflection</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-54569-senaite-core-unauthenticated-rce-via-eval-injection-and-missing</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-54606-suneditor-embed-plugin-dom-xss-via-external-script-element</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/openwisp-ipam-missing-authorization-in-subnet-export-55f60554</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/pantheon-agents-trojanized-pypi-packages-deliver-credential-stealer-56064d97</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-54511-logtape-syslog-log-injection-via-unescaped-control-characters</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-54550-izpack-path-traversal-in-unpackerbase</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-54523-kyverno-namespacedmutatingpolicy-generator-apply-namespace</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-54548-siemens-kas-ssh-host-key-checking-configuration-weakness</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-54553-starlette-admin-unvalidated-order-by-parameter-information</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-54556-http4s-http-2-denial-of-service-in-hpack-header-compression</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-54356-budibase-s3-signed-upload-url-issuance-via-attachments-endpoint</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-65182-apache-tomcat-security-constraint-bypass</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-65905-apache-tomcat-digest-authenticator-authentication-bypass</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-68525-apache-tomcat-form-authentication-authorization-bypass</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-73513-envoy-proxy-multiple-vulnerabilities</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-12717-google-bigquery-data-transfer-service-jdbc-driver-input</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2021-23758-ajax-net-professional-unsafe-deserialization-of-untrusted-data</loc><lastmod>2026-09-24</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2015-3246-red-hat-libuser-race-condition-in-passwd-file-handling</loc><lastmod>2026-09-24</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2015-5287-red-hat-abrt-privilege-escalation-via-symlink-attack</loc><lastmod>2026-09-24</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2022-0995-linux-kernel-out-of-bounds-write-vulnerability</loc><lastmod>2026-09-24</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2019-1068-microsoft-sql-server-remote-code-execution</loc><lastmod>2026-09-24</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-54338-jupyterhub-unauthenticated-denial-of-service-in-login-form</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-55099-icalendar-algorithmic-complexity-in-equality-comparison</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-45019-chainlit-server-side-request-forgery-via-mcp-transports</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-45018-chainlit-command-injection-in-mcp-stdio-transport</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-55609-sublinear-time-solver-mcp-arbitrary-file-write</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/nokogiri-unchecked-return-value-in-canonicalize-method-3863de91</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/nltk-jvm-argument-injection-in-stanford-wrappers-via-per-call-options-628f3938</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/nokogiri-xslt-transform-memory-leak-0441ddf7</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/nokogiri-css-selector-tokenizer-redos-d52ae203</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/nltk-corpus-reader-sandbox-bypass-6e33487f</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/nltk-corpus-readers-symlink-path-traversal-bypass-edf52a38</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-55620-eml-parser-denial-of-service-via-nested-parentheses-in-received</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-55619-eml-parser-denial-of-service-via-deeply-nested-email-header</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-55618-govcert-lu-eml-parser-url-extraction-bypass-via-html-entities</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-55663-mediasoup-sctp-state-cookie-authentication-bypass</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-55637-genieacs-mcp-dns-rebinding-in-streamable-http-transport</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-55419-pollen-robotics-reachy-mini-unrestricted-file-upload-in-media-api</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/phpmyfaq-privilege-escalation-in-groupcontroller-updatepermissions-3da5d4fe</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/phpmyfaq-public-api-information-disclosure-in-faq-endpoints-8f0c6c40</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/phpmyfaq-path-traversal-in-pdf-export-5f62d0df</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-55557-browse-mcp-arbitrary-file-write-via-path-traversal</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-55585-qwed-authenticated-remote-code-execution-in-parse-expr</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-55553-urllib-cross-origin-redirect-credential-leakage</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-55571-djust-authentication-bypass-in-liveview-websocket-mount</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-55640-nextcloud-mcp-server-webhook-auth-bypass-in-vector-sync</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/pickem-terminal-escape-sequence-injection-via-unsanitized-item-text-d94d9a83</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/pickem-terminal-escape-sequence-injection-in-item-text-b54eb4a3</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/utcp-http-oauth2-tokenurl-trust-boundary-bypass-in-openapi-conversion-c10cfda8</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/utcp-http-http-tool-invocation-ssrf-via-unvalidated-redirects-681a2cb0</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-55580-mcp-shell-security-disabled-by-default-and-shell-interpreter</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-55581-sonirico-mcp-shell-allowlist-bypass-via-bash-c-flag</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-55582-mcp-shell-secure-mode-allowlist-bypass-via-git-shell-alias</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-55546-qwed-ai-qwed-mcp-unsafe-sympy-parse-expr-remote-code-execution</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-55536-praisonai-browser-server-websocket-origin-validation-bypass</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-55532-praisonai-origin-validation-bypass-enabling-csrf</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-55533-praisonai-recipe-server-authentication-bypass-with-missing</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-55539-praisonai-async-jobs-api-authentication-bypass</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-55527-praisonaiagents-filememory-path-traversal-arbitrary-file-write</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-55541-praisonai-authentication-bypass-in-serve-command</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-55535-praisonai-server-side-request-forgery-in-webhook-url-validation</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-55537-praisonai-webhook-ssrf-via-dns-fail-open-and-toctou</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-55538-praisonai-agent-invocation-auth-bypass-via-missing-api-key</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-55540-praisonai-path-traversal-via-symlinks-and-unvalidated-working</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-55530-praisonai-ast-grep-rewrite-missing-authorization-in-file</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-55524-praisonai-agents-ssrf-in-web-crawl-tool-via-redirect-and-dns</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-55534-praisonai-serve-agents-authentication-bypass</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-55526-praisonai-ssrf-protection-bypass-in-spider-tools-via-dns</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-55531-praisonai-mcp-http-server-memory-exhaustion-via-unbounded-session</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-55528-praisonai-agentserver-authentication-bypass-on-all-routes</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-55529-praisonai-mcp-http-stream-origin-validation-bypass</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-55523-praisonai-web-crawl-ssrf-protection-bypass-via-unchecked</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-55522-praisonai-workflow-include-remote-code-execution-in-tools-py</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-55525-praisonai-web-crawl-ssrf-via-redirect-following</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/nltk-unsafe-pickle-deserialization-in-allowlisted-loaders-eeef7a48</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/nltk-untrusted-search-path-in-graphviz-dot-invocation-a4934721</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/nltk-entity-expansion-denial-of-service-via-elementtree-xml-parsing-e2038a9e</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/nltk-pathsec-ssrf-protection-bypass-with-proxy-configured-e731f278</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/nltk-unsafe-pickle-deserialization-in-transitionparser-672e8ed3</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/gitpython-incomplete-denylist-argument-injection-in-repo-blame-0f5a1996</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/gitpython-tagreference-create-arbitrary-file-read-via-positional-4b3f134a</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/gitpython-config-injection-via-unsafe-re-serialization-of-multi-line-a7bdddba</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/gitpython-local-file-disclosure-via-gitmodules-include-directive-e93466b0</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/gitpython-path-traversal-in-clone-from-and-clone-via-separate-git-dir-76bb0c2e</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/grav-userinterface-offsetget-offsetexists-twig-sandbox-bypass-f709468e</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/grav-incomplete-twig-sandbox-denylist-information-disclosure-e903bd3b</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/grav-cms-twig-sandbox-bypass-in-configuration-variables-342f3ed2</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/grav-cms-origin-validation-bypass-in-referrer-header-0f775642</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/grav-cms-path-traversal-in-media-directory-twig-function-a2c5a56f</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/grav-path-traversal-in-mediauploadtrait-deletefile-e695e1dc</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/grav-cms-timing-attack-on-nonce-verification-in-csrf-protection-640c32bc</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/next-js-and-libheif-rce-in-heif-avif-image-processing-eebb5345</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/vibeio-http-dos-in-http-1-x-chunked-encoding-parser-d87e84a0</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cloudreve-path-traversal-in-remote-download-28748249</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cloudreve-broken-access-control-in-file-share-caching-13df24a4</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/gorilla-websocket-weak-prng-for-mask-key-generation-0861bf09</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/netfoil-improper-output-neutralization-for-logs-in-doh-response-c6a8161c</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-54625-django-cms-page-cache-ignores-plugin-vary-headers</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-54623-django-cms-plugin-move-endpoint-denial-of-service-via-cyclic</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/tokio-postgres-out-of-bounds-read-on-mismatched-datarow-fields-51e13d2d</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/postgres-protocol-panic-on-malformed-hstore-value-98d63cdf</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/postgres-protocol-unbounded-scram-iteration-count-dos-d8dcba22</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-54050-sakai-profile-image-deletion-authorization-bypass</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-54049-sakai-conversations-stored-cross-site-scripting-in-messages</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-53710-ibm-mcp-contextforge-gateway-restrictedpython-sandbox-bypass-via</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-78329-apache-camel-undertow-header-filter-bypass-in-endpoint-routes</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-71300-apache-camel-atmosphere-websocket-header-injection-in-producer</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-63621-apache-camel-knative-header-injection-in-structured-content-mode</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-66906-apache-camel-azure-storage-blob-path-traversal-in</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-66907-apache-camel-google-storage-relative-path-traversal-in-download</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-59230-apache-camel-mail-header-injection-via-headersinline</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-60093-apache-camel-azure-storage-datalake-path-traversal-in</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-66908-apache-camel-platform-http-main-jwt-authentication-bypass</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-76845-adm-zip-symlink-following-in-archive-extraction</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/justhtml-uncontrolled-recursion-dos-via-deeply-nested-html-26591bb6</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/nltk-symlink-escape-in-corpusreader-allows-arbitrary-local-file-read-f12c334c</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/nltk-ipipancorpusreader-symlink-based-arbitrary-file-read-50fafa81</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/nltk-filesystempathpointer-arbitrary-file-read-via-file-protocol-065a2b57</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/nltk-streambackedcorpusview-pathsec-bypass-arbitrary-file-read-dc56e3c3</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/nltk-framenetcorpusreader-symlink-sandbox-bypass-9890e9b3</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/nltk-ssrf-fail-open-in-validate-network-url-via-dns-resolution-failure-e27dfd99</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-71513-nltk-allowlistunpickler-dotted-name-validation-bypass</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/nltk-insecure-default-configuration-in-pathsec-f4930423</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-71514-nltk-crubadancorpusreader-path-traversal-in-corpus-reader</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/nltk-unbounded-recursion-in-jsontaggeddecoder-decode-obj-e977609c</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/nltk-framenet-and-nkjp-readers-path-traversal-106fc925</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-63310-nltk-missing-post-download-integrity-verification-in-downloader</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-77415-jsonata-arbitrary-code-execution-via-crafted-expressions</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-77414-jsonata-arbitrary-code-execution-in-expression-evaluation</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-68508-hydra-hydra-utils-instantiate-code-injection-with-untrusted</loc><lastmod>2026-09-25</lastmod></url>
  <url><loc>https://junglewise.ai/threats/cve-2026-63135-yourls-stored-xss-in-referrer-statistics-via-crafted-referer</loc><lastmod>2026-09-25</lastmod></url>
</urlset>
