{
  "day": "2026-05-21",
  "boundary": "UTC calendar day",
  "published_count": 187,
  "by_severity": {
    "CRITICAL": 15,
    "HIGH": 74,
    "MEDIUM": 69,
    "LOW": 28
  },
  "kev_count": 2,
  "exploit_reference_count": 7,
  "awaiting_enrichment_count": 1,
  "ranking": "Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.",
  "results": [
    {
      "rank": 1,
      "cve_id": "CVE-2025-34291",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.83844,
      "epss_percentile": 0.99669,
      "kev": true,
      "kev_due_at": "2026-06-04",
      "vendor": "Langflow",
      "product": "Langflow",
      "cwe": null,
      "title": "Langflow Langflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-34291"
    },
    {
      "rank": 2,
      "cve_id": "CVE-2026-34926",
      "cvss_base": 6.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.12682,
      "epss_percentile": 0.95936,
      "kev": true,
      "kev_due_at": "2026-06-04",
      "vendor": "Trend Micro, Inc.",
      "product": "TrendAI Apex One",
      "cwe": "CWE-23",
      "title": "Trend Micro Apex One",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34926"
    },
    {
      "rank": 3,
      "cve_id": "CVE-2025-71210",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.03811,
      "epss_percentile": 0.89179,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Trend Micro, Inc.",
      "product": "TrendAI Apex One",
      "cwe": "CWE-22",
      "title": "A vulnerability in the Trend Micro Apex One management console could allow a remote attacker to upload malicious code and execute commands on affected installations. Please note: although this vulnerability carries a technical critical CVSS rating, this was reported via responsible disclosure via a researcher through the Zero Day Initiative. The SaaS versions of the product have already been mitigated and no customer action required. For this particular vulnerability, an attacker must have access to the Trend Micro Apex One Management Console, so customers that have their console�s IP address exposed externally should consider mitigating factors such as source restrictions if not already applied.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-71210"
    },
    {
      "rank": 4,
      "cve_id": "CVE-2025-71211",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.03754,
      "epss_percentile": 0.89004,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Trend Micro, Inc.",
      "product": "TrendAI Apex One",
      "cwe": "CWE-22",
      "title": "A vulnerability in the Trend Micro Apex One management console could allow a remote attacker to upload malicious code and execute commands on affected installations. This vulnerability is similar in scope to CVE-2025-71210 but affects a different executable. Please note: although this vulnerability carries a technical critical CVSS rating, this was reported via responsible disclosure via a researcher through the Zero Day Initiative. The SaaS versions of the product have already been mitigated and no customer action required. For this particular vulnerability, an attacker must have access to the Trend Micro Apex One Management Console, so customers that have their console�s IP address exposed externally should consider mitigating factors such as source restrictions if not already applied.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-71211"
    },
    {
      "rank": 5,
      "cve_id": "CVE-2026-6279",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.02163,
      "epss_percentile": 0.80771,
      "kev": false,
      "kev_due_at": null,
      "vendor": "themefusion",
      "product": "Avada (Fusion) Builder",
      "cwe": "CWE-74",
      "title": "Avada (Fusion) Builder <= 3.15.2 - Unauthenticated Remote Code Execution via PHP Function Injection via 'render_logics' Shortcode Attribute via Widget AJAX Handler",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6279"
    },
    {
      "rank": 6,
      "cve_id": "CVE-2026-2740",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.01702,
      "epss_percentile": 0.75387,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Zohocorp",
      "product": "ManageEngine ADSelfService Plus",
      "cwe": "CWE-77",
      "title": "Remote Code Execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-2740"
    },
    {
      "rank": 7,
      "cve_id": "CVE-2026-5433",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00971,
      "epss_percentile": 0.59172,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Honeywell International Inc.",
      "product": "Control Network Module (CNM)",
      "cwe": "CWE-77",
      "title": "Improper sanitization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-5433"
    },
    {
      "rank": 8,
      "cve_id": "CVE-2026-8134",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00739,
      "epss_percentile": 0.51767,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Concrete CMS",
      "product": "Concrete CMS",
      "cwe": "CWE-23",
      "title": "Concrete CMS 9.5.0 and below is vulnerable to Authenticated RCE via Composer customTemplate Path Traversal leading to PHP File Inclusion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8134"
    },
    {
      "rank": 9,
      "cve_id": "CVE-2026-47101",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00739,
      "epss_percentile": 0.51772,
      "kev": false,
      "kev_due_at": null,
      "vendor": "BerriAI",
      "product": "litellm",
      "cwe": "CWE-863",
      "title": "LiteLLM < 1.83.14 Privilege Escalation via API Key Generation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47101"
    },
    {
      "rank": 10,
      "cve_id": "CVE-2026-43499",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00725,
      "epss_percentile": 0.51247,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-416",
      "title": "rtmutex: Use waiter::task instead of current in remove_waiter()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43499"
    },
    {
      "rank": 11,
      "cve_id": "CVE-2026-47114",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00702,
      "epss_percentile": 0.50413,
      "kev": false,
      "kev_due_at": null,
      "vendor": "iina",
      "product": "iina",
      "cwe": "CWE-88",
      "title": "IINA < 1.4.3 Command Execution via iina://open URL Scheme",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47114"
    },
    {
      "rank": 12,
      "cve_id": "CVE-2026-6960",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00672,
      "epss_percentile": 0.49264,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Repute Infosystems",
      "product": "BookingPress Appointment Booking Pro",
      "cwe": "CWE-434",
      "title": "BookingPress Pro <= 5.6 - Unauthenticated Arbitrary File Upload via Signature Custom Field",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6960"
    },
    {
      "rank": 13,
      "cve_id": "CVE-2026-47102",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00654,
      "epss_percentile": 0.48557,
      "kev": false,
      "kev_due_at": null,
      "vendor": "BerriAI",
      "product": "litellm",
      "cwe": "CWE-863",
      "title": "LiteLLM < 1.83.10 Privilege Escalation via User Update",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47102"
    },
    {
      "rank": 14,
      "cve_id": "CVE-2026-43501",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00595,
      "epss_percentile": 0.45828,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-787",
      "title": "ipv6: rpl: reserve mac_len headroom when recompressed SRH grows",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43501"
    },
    {
      "rank": 15,
      "cve_id": "CVE-2026-48207",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00574,
      "epss_percentile": 0.44885,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Fory",
      "cwe": "CWE-502",
      "title": "Apache Fory: PyFory ReduceSerializer Incomplete Policy Enforcement",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48207"
    },
    {
      "rank": 16,
      "cve_id": "CVE-2026-6826",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00562,
      "epss_percentile": 0.44272,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Concrete CMS",
      "product": "Concrete CMS",
      "cwe": "CWE-200",
      "title": "Concrete 9.5.0 and below has file usage disclosure via missing permission check in Usage controller",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6826"
    },
    {
      "rank": 17,
      "cve_id": "CVE-2025-71212",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00544,
      "epss_percentile": 0.43352,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Trend Micro, Inc.",
      "product": "TrendAI Apex One",
      "cwe": "CWE-59",
      "title": "A link following vulnerability in the Trend Micro Apex One scan engine could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-71212"
    },
    {
      "rank": 18,
      "cve_id": "CVE-2026-44058",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00532,
      "epss_percentile": 0.4267,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Netatalk",
      "product": "Netatalk",
      "cwe": "CWE-287",
      "title": "Authentication bypass via admin auth user",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44058"
    },
    {
      "rank": 19,
      "cve_id": "CVE-2026-44049",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00516,
      "epss_percentile": 0.41755,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Netatalk",
      "product": "Netatalk",
      "cwe": "CWE-787",
      "title": "Out-of-bounds write in convert_charset() null termination",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44049"
    },
    {
      "rank": 20,
      "cve_id": "CVE-2026-5118",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00487,
      "epss_percentile": 0.39997,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Divi Engine",
      "product": "Divi Form Builder",
      "cwe": "CWE-269",
      "title": "Divi Form Builder <= 5.1.2 - Unauthenticated Privilege Escalation via 'role'",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-5118"
    },
    {
      "rank": 21,
      "cve_id": "CVE-2026-44051",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00477,
      "epss_percentile": 0.39332,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Netatalk",
      "product": "Netatalk",
      "cwe": "CWE-59",
      "title": "Arbitrary file read via attacker-controlled symlink creation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44051"
    },
    {
      "rank": 22,
      "cve_id": "CVE-2026-8135",
      "cvss_base": 8.9,
      "cvss_severity": "HIGH",
      "epss_score": 0.0047,
      "epss_percentile": 0.38883,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Concrete CMS",
      "product": "Concrete CMS",
      "cwe": "CWE-502",
      "title": "Concrete CMS 9.5.0 and below is vulnerable to RCE due to insecure deserialization occurring in the ExpressEntryList block controller.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8135"
    },
    {
      "rank": 23,
      "cve_id": "CVE-2026-2734",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00441,
      "epss_percentile": 0.3691,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mlflow",
      "product": "mlflow/mlflow",
      "cwe": "CWE-284",
      "title": "Authorization Bypass in SearchModelVersions in mlflow/mlflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-2734"
    },
    {
      "rank": 24,
      "cve_id": "CVE-2026-44050",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00418,
      "epss_percentile": 0.35088,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Netatalk",
      "product": "Netatalk",
      "cwe": "CWE-122",
      "title": "Heap buffer overflow in CNID daemon comm_rcv()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44050"
    },
    {
      "rank": 25,
      "cve_id": "CVE-2026-44048",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00418,
      "epss_percentile": 0.35088,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Netatalk",
      "product": "Netatalk",
      "cwe": "CWE-121",
      "title": "Stack buffer overflow via UCS-2 type confusion in convert_charset()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44048"
    },
    {
      "rank": 26,
      "cve_id": "CVE-2026-46473",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00416,
      "epss_percentile": 0.34901,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TCHATZI",
      "product": "Authen::TOTP",
      "cwe": "CWE-331",
      "title": "Authen::TOTP versions before 0.1.1 for Perl generate secrets using rand",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46473"
    },
    {
      "rank": 27,
      "cve_id": "CVE-2026-45250",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00409,
      "epss_percentile": 0.34275,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FreeBSD",
      "product": "FreeBSD",
      "cwe": "CWE-121",
      "title": "Stack buffer overflow via setcred(2)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45250"
    },
    {
      "rank": 28,
      "cve_id": "CVE-2026-44061",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00389,
      "epss_percentile": 0.32201,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Netatalk",
      "product": "Netatalk",
      "cwe": "CWE-208",
      "title": "DES-ECB auth with timing side channel",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44061"
    },
    {
      "rank": 29,
      "cve_id": "CVE-2026-44047",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00371,
      "epss_percentile": 0.30401,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Netatalk",
      "product": "Netatalk",
      "cwe": "CWE-89",
      "title": "SQL injection in MySQL CNID backend",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44047"
    },
    {
      "rank": 30,
      "cve_id": "CVE-2026-42001",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00365,
      "epss_percentile": 0.29768,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PowerDNS",
      "product": "Authoritative",
      "cwe": "CWE-400",
      "title": "Insufficient Validation of Autoprimary SOA Queries",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42001"
    },
    {
      "rank": 31,
      "cve_id": "CVE-2026-44055",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0036,
      "epss_percentile": 0.29278,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Netatalk",
      "product": "Netatalk",
      "cwe": "CWE-78",
      "title": "Bitwise OR logic bug enables shell injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44055"
    },
    {
      "rank": 32,
      "cve_id": "CVE-2025-71214",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00357,
      "epss_percentile": 0.28969,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Trend Micro, Inc.",
      "product": "TrendAI Apex One (Mac)",
      "cwe": "CWE-346",
      "title": "An origin validation error vulnerability in the Trend Micro Apex One (mac) agent iCore service could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The following information is provided as informational only for CVE references, as these were addressed already via ActiveUpdate/SaaS updates in mid to late 2025 (SaaS 2507 & 2005 Yearly Release).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-71214"
    },
    {
      "rank": 33,
      "cve_id": "CVE-2026-44062",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00357,
      "epss_percentile": 0.28891,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Netatalk",
      "product": "Netatalk",
      "cwe": "CWE-787",
      "title": "Missing o_len bounds check in pull_charset_flags()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44062"
    },
    {
      "rank": 34,
      "cve_id": "CVE-2026-42396",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00353,
      "epss_percentile": 0.28539,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PowerDNS",
      "product": "Authoritative",
      "cwe": "CWE-94",
      "title": "Insufficient Validation of Member Zone Data May Cause Catalog Zone Transfer to Fail",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42396"
    },
    {
      "rank": 35,
      "cve_id": "CVE-2026-9152",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00339,
      "epss_percentile": 0.26992,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Altium",
      "product": "Altium 365",
      "cwe": "CWE-306",
      "title": "Unauthenticated SOAP Endpoint in Altium 365 SearchService Allows Cross-Tenant Data Exfiltration and Index Destruction",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9152"
    },
    {
      "rank": 36,
      "cve_id": "CVE-2025-71213",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00337,
      "epss_percentile": 0.26794,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Trend Micro, Inc.",
      "product": "TrendAI Apex One",
      "cwe": "CWE-346",
      "title": "An origin validation error vulnerability in Trend Micro Apex One could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-71213"
    },
    {
      "rank": 37,
      "cve_id": "CVE-2026-1543",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00337,
      "epss_percentile": 0.26703,
      "kev": false,
      "kev_due_at": null,
      "vendor": "themefusion",
      "product": "Avada (Fusion) Builder",
      "cwe": "CWE-79",
      "title": "Avada (Fusion) Builder <= 3.15.2 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Multiple Shortcodes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-1543"
    },
    {
      "rank": 38,
      "cve_id": "CVE-2026-44071",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00335,
      "epss_percentile": 0.26495,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Netatalk",
      "product": "Netatalk",
      "cwe": "CWE-693",
      "title": "FORTIFY_SOURCE disabled",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44071"
    },
    {
      "rank": 39,
      "cve_id": "CVE-2026-44074",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00329,
      "epss_percentile": 0.25944,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Netatalk",
      "product": "Netatalk",
      "cwe": "CWE-682",
      "title": "Bitwise OR of errno values",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44074"
    },
    {
      "rank": 40,
      "cve_id": "CVE-2026-44075",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00329,
      "epss_percentile": 0.25944,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Netatalk",
      "product": "Netatalk",
      "cwe": "CWE-484",
      "title": "Missing break in DSI OpenSession",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44075"
    },
    {
      "rank": 41,
      "cve_id": "CVE-2026-44060",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00328,
      "epss_percentile": 0.25741,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Netatalk",
      "product": "Netatalk",
      "cwe": "CWE-191",
      "title": "Integer underflow in dsi_writeinit() leads to denial of service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44060"
    },
    {
      "rank": 42,
      "cve_id": "CVE-2026-4858",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00327,
      "epss_percentile": 0.25716,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mattermost",
      "product": "Mattermost",
      "cwe": "CWE-22",
      "title": "Path traversal in integration action URL leading to arbitrary API execution via system admin’s auth token.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-4858"
    },
    {
      "rank": 43,
      "cve_id": "CVE-2026-45760",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00325,
      "epss_percentile": 0.25513,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Camel K",
      "cwe": "CWE-610",
      "title": "Apache Camel K: Camel K Cross-Namespace Build Deputy Attack",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45760"
    },
    {
      "rank": 44,
      "cve_id": "CVE-2025-71216",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00323,
      "epss_percentile": 0.25241,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Trend Micro, Inc.",
      "product": "TrendAI Apex One (Mac)",
      "cwe": "CWE-367",
      "title": "A time-of-check time-of-use vulnerability in the Trend Micro Apex One (mac) agent cache mechanism could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The following information is provided as informational only for CVE references, as these were addressed already via ActiveUpdate/SaaS updates in mid to late 2025 (SaaS 2507 & 2005 Yearly Release).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-71216"
    },
    {
      "rank": 45,
      "cve_id": "CVE-2026-44068",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00322,
      "epss_percentile": 0.25051,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Netatalk",
      "product": "Netatalk",
      "cwe": "CWE-22",
      "title": "EA path traversal via incomplete sanitization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44068"
    },
    {
      "rank": 46,
      "cve_id": "CVE-2026-7835",
      "cvss_base": 3.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00318,
      "epss_percentile": 0.24686,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Netatalk",
      "product": "Netatalk",
      "cwe": "CWE-134",
      "title": "Format string argument mismatch",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7835"
    },
    {
      "rank": 47,
      "cve_id": "CVE-2026-44070",
      "cvss_base": 3.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00318,
      "epss_percentile": 0.24686,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Netatalk",
      "product": "Netatalk",
      "cwe": "CWE-770",
      "title": "Unbounded realloc in charset conversion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44070"
    },
    {
      "rank": 48,
      "cve_id": "CVE-2026-9089",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00311,
      "epss_percentile": 0.23857,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ConnectWise",
      "product": "Automate",
      "cwe": "CWE-494",
      "title": "The ConnectWise Automate™ Agent does not fully verify the authenticity of components obtained during plugin loading and self-update operations. This issue is addressed in Automate 2026.5.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9089"
    },
    {
      "rank": 49,
      "cve_id": "CVE-2026-4811",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00311,
      "epss_percentile": 0.23905,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wpbean",
      "product": "WPB Floating Menu or Categories – Sticky Floating Side Menu & Categories with Icons",
      "cwe": "CWE-79",
      "title": "WPB Floating Menu or Categories – Sticky Floating Side Menu & Categories with Icons <= 1.0.8 - Authenticated (Editor+) Stored Cross-Site Scripting via 'Icon CSS Class' Category Field",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-4811"
    },
    {
      "rank": 50,
      "cve_id": "CVE-2026-39593",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00307,
      "epss_percentile": 0.23404,
      "kev": false,
      "kev_due_at": null,
      "vendor": "VillaTheme",
      "product": "HAPPY",
      "cwe": "CWE-862",
      "title": "WordPress HAPPY plugin <= 1.0.10 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39593"
    },
    {
      "rank": 51,
      "cve_id": "CVE-2026-48241",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00305,
      "epss_percentile": 0.2319,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Open ISES",
      "product": "Tickets",
      "cwe": "CWE-798",
      "title": "Open ISES Tickets < 3.44.2 Hardcoded MySQL Database Credentials in loader.php",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48241"
    },
    {
      "rank": 52,
      "cve_id": "CVE-2026-45255",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00305,
      "epss_percentile": 0.23155,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FreeBSD",
      "product": "FreeBSD",
      "cwe": "CWE-78",
      "title": "Remote code execution via installer Wi-Fi access point scans",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45255"
    },
    {
      "rank": 53,
      "cve_id": "CVE-2026-8350",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00301,
      "epss_percentile": 0.22739,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Concrete CMS",
      "product": "Concrete CMS",
      "cwe": "CWE-863",
      "title": "Concrete CMS 9.5.0 and below is vulnerable to missing authorization in the bulk_user_assignment.php which can lead to privilege escalation to Administrative Group",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8350"
    },
    {
      "rank": 54,
      "cve_id": "CVE-2026-44053",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00301,
      "epss_percentile": 0.22761,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Netatalk",
      "product": "Netatalk",
      "cwe": "CWE-327",
      "title": "Weak cryptography in DHCAST128 UAM",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44053"
    },
    {
      "rank": 55,
      "cve_id": "CVE-2025-71215",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00301,
      "epss_percentile": 0.22768,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Trend Micro, Inc.",
      "product": "TrendAI Apex One (Mac)",
      "cwe": "CWE-367",
      "title": "A time-of-check time-of-use vulnerability in the Trend Micro Apex One (mac) agent iCore service signature verification could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The following information is provided as informational only for CVE references, as these were addressed already via ActiveUpdate/SaaS updates in mid to late 2025 (SaaS 2507 & 2005 Yearly Release).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-71215"
    },
    {
      "rank": 56,
      "cve_id": "CVE-2026-45208",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.003,
      "epss_percentile": 0.22636,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Trend Micro, Inc.",
      "product": "TrendAI Apex One",
      "cwe": "CWE-367",
      "title": "A time-of-check time-of-use vulnerability in the Apex One/SEP agent could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45208"
    },
    {
      "rank": 57,
      "cve_id": "CVE-2026-43494",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00299,
      "epss_percentile": 0.22519,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-1341",
      "title": "net/rds: reset op_nents when zerocopy page pin fails",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43494"
    },
    {
      "rank": 58,
      "cve_id": "CVE-2026-48242",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00297,
      "epss_percentile": 0.22307,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Open ISES",
      "product": "Tickets",
      "cwe": "CWE-798",
      "title": "Open ISES Tickets < 3.44.2 Hardcoded MySQL Database Credentials in import_mdb.php",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48242"
    },
    {
      "rank": 59,
      "cve_id": "CVE-2025-71217",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00295,
      "epss_percentile": 0.2219,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Trend Micro, Inc.",
      "product": "TrendAI Apex One (Mac)",
      "cwe": "CWE-346",
      "title": "An origin validation error vulnerability in the Trend Micro Apex One (mac) agent self-protection mechanism could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The following information is provided as informational only for CVE references, as these were addressed already via ActiveUpdate/SaaS updates in mid to late 2025 (SaaS 2507 & 2005 Yearly Release).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-71217"
    },
    {
      "rank": 60,
      "cve_id": "CVE-2026-44067",
      "cvss_base": 4.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00292,
      "epss_percentile": 0.21824,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Netatalk",
      "product": "Netatalk",
      "cwe": "CWE-125",
      "title": "EA header parsing heap over-read",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44067"
    },
    {
      "rank": 61,
      "cve_id": "CVE-2026-44066",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0029,
      "epss_percentile": 0.21623,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Netatalk",
      "product": "Netatalk",
      "cwe": "CWE-125",
      "title": "Heap out-of-bounds reads in Spotlight RPC unmarshalling",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44066"
    },
    {
      "rank": 62,
      "cve_id": "CVE-2026-7886",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00288,
      "epss_percentile": 0.21368,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Concrete CMS",
      "product": "Concrete CMS",
      "cwe": "CWE-639",
      "title": "Concrete CMS 9.5.0 and below is vulnerable to IDOR in AddMessage/UpdateMessage via attachments[] parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7886"
    },
    {
      "rank": 63,
      "cve_id": "CVE-2026-45252",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00284,
      "epss_percentile": 0.20976,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FreeBSD",
      "product": "FreeBSD",
      "cwe": "CWE-122",
      "title": "Heap overflow in FUSE_LISTXATTR",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45252"
    },
    {
      "rank": 64,
      "cve_id": "CVE-2026-44054",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0028,
      "epss_percentile": 0.20562,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Netatalk",
      "product": "Netatalk",
      "cwe": "CWE-330",
      "title": "Predictable afpd session token",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44054"
    },
    {
      "rank": 65,
      "cve_id": "CVE-2026-44073",
      "cvss_base": 5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00277,
      "epss_percentile": 0.20247,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Netatalk",
      "product": "Netatalk",
      "cwe": "CWE-273",
      "title": "seteuid failure ignored in auth modules",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44073"
    },
    {
      "rank": 66,
      "cve_id": "CVE-2026-42002",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00264,
      "epss_percentile": 0.18407,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PowerDNS",
      "product": "Authoritative",
      "cwe": "CWE-364",
      "title": "Concurrency and locking defects in GSS-TSIG",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42002"
    },
    {
      "rank": 67,
      "cve_id": "CVE-2026-43495",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00261,
      "epss_percentile": 0.1809,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-125",
      "title": "net: wwan: t7xx: validate port_count against message length in t7xx_port_enum_msg_handler",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43495"
    },
    {
      "rank": 68,
      "cve_id": "CVE-2026-48218",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00259,
      "epss_percentile": 0.17839,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Open ISES",
      "product": "Tickets",
      "cwe": "CWE-79",
      "title": "Open ISES Tickets < 3.44.2 Reflected XSS via icons/buttons/landb.php frm_name and frm_id Parameters",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48218"
    },
    {
      "rank": 69,
      "cve_id": "CVE-2026-48224",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00259,
      "epss_percentile": 0.17839,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Open ISES",
      "product": "Tickets",
      "cwe": "CWE-79",
      "title": "Open ISES Tickets < 3.44.2 Reflected XSS via ics214.php frm_add_str Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48224"
    },
    {
      "rank": 70,
      "cve_id": "CVE-2026-7836",
      "cvss_base": 3.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00257,
      "epss_percentile": 0.17572,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Netatalk",
      "product": "Netatalk",
      "cwe": "CWE-682",
      "title": "hextoint macro uppercase bug",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7836"
    },
    {
      "rank": 71,
      "cve_id": "CVE-2026-44056",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00253,
      "epss_percentile": 0.1704,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Netatalk",
      "product": "Netatalk",
      "cwe": "CWE-121",
      "title": "Stack buffer overflow in desktop.c",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44056"
    },
    {
      "rank": 72,
      "cve_id": "CVE-2025-13479",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00251,
      "epss_percentile": 0.16744,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PosCube Hardware Software and Consulting Ltd.",
      "product": "QR Menu",
      "cwe": "CWE-639",
      "title": "IDOR in PosCube's QR Menu",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-13479"
    },
    {
      "rank": 73,
      "cve_id": "CVE-2026-34927",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00246,
      "epss_percentile": 0.16123,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Trend Micro, Inc.",
      "product": "TrendAI Apex One",
      "cwe": "CWE-346",
      "title": "An origin validation vulnerability in the Apex One/SEP agent could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34927"
    },
    {
      "rank": 74,
      "cve_id": "CVE-2026-34929",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00246,
      "epss_percentile": 0.16124,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Trend Micro, Inc.",
      "product": "TrendAI Apex One",
      "cwe": "CWE-346",
      "title": "An origin validation vulnerability in the Apex One/SEP agent could allow a local attacker to escalate privileges on affected installations. This is similar to CVE-2026-34927 but exists in a different inter-process communication mechanism. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34929"
    },
    {
      "rank": 75,
      "cve_id": "CVE-2026-44052",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00245,
      "epss_percentile": 0.16066,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Netatalk",
      "product": "Netatalk",
      "cwe": "CWE-532",
      "title": "LDAP simple-bind password exposure in log output",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44052"
    },
    {
      "rank": 76,
      "cve_id": "CVE-2026-0393",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00244,
      "epss_percentile": 0.15864,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CODESYS",
      "product": "Visualization",
      "cwe": "CWE-522",
      "title": "CODESYS Visualization - Insufficiently Protected Credentials",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-0393"
    },
    {
      "rank": 77,
      "cve_id": "CVE-2026-39531",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00243,
      "epss_percentile": 0.15715,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Wp Directory Kit",
      "product": "WP Directory Kit",
      "cwe": "CWE-89",
      "title": "WordPress WP Directory Kit plugin <= 1.5.0 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39531"
    },
    {
      "rank": 78,
      "cve_id": "CVE-2026-42000",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00242,
      "epss_percentile": 0.15601,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PowerDNS",
      "product": "Authoritative",
      "cwe": "CWE-77",
      "title": "Insufficient Validation of Names During AXFR",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42000"
    },
    {
      "rank": 79,
      "cve_id": "CVE-2026-48235",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0024,
      "epss_percentile": 0.1543,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Open ISES",
      "product": "Tickets",
      "cwe": "CWE-89",
      "title": "Open ISES Tickets < 3.44.2 SQL Injection in incs/remotes.inc.php via External GPS Tracker Data",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48235"
    },
    {
      "rank": 80,
      "cve_id": "CVE-2026-7837",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00236,
      "epss_percentile": 0.1481,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Netatalk",
      "product": "Netatalk",
      "cwe": "CWE-367",
      "title": "TOCTOU with root privilege in ad_flush",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7837"
    },
    {
      "rank": 81,
      "cve_id": "CVE-2026-6841",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00235,
      "epss_percentile": 0.14658,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Best Practical",
      "product": "Request Tracker",
      "cwe": "CWE-79",
      "title": "Reflected XSS in Request Tracker",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6841"
    },
    {
      "rank": 82,
      "cve_id": "CVE-2025-13477",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00224,
      "epss_percentile": 0.1333,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Digital Operations Services Inc.",
      "product": "WifiBurada",
      "cwe": "CWE-359",
      "title": "OTP Bypass in Digital Operation Services' WifiBurada",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-13477"
    },
    {
      "rank": 83,
      "cve_id": "CVE-2026-48243",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00224,
      "epss_percentile": 0.13297,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Open ISES",
      "product": "Tickets",
      "cwe": "CWE-798",
      "title": "Open ISES Tickets < 3.44.2 Hardcoded WhitePages API Key in wp1.php",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48243"
    },
    {
      "rank": 84,
      "cve_id": "CVE-2026-48244",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00224,
      "epss_percentile": 0.13297,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Open ISES",
      "product": "Tickets",
      "cwe": "CWE-798",
      "title": "Open ISES Tickets < 3.44.2 Hardcoded Google Maps API Key in settings.inc.php",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48244"
    },
    {
      "rank": 85,
      "cve_id": "CVE-2026-48245",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00224,
      "epss_percentile": 0.13297,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Open ISES",
      "product": "Tickets",
      "cwe": "CWE-798",
      "title": "Open ISES Tickets < 3.44.2 Hardcoded Google Maps API Key in tables.php",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48245"
    },
    {
      "rank": 86,
      "cve_id": "CVE-2026-7879",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00224,
      "epss_percentile": 0.13356,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Concrete CMS",
      "product": "Concrete CMS",
      "cwe": "CWE-862",
      "title": "Concrete CMS 9.5.0 and below is vulnerable to File Download Authorization Bypass in submit_password()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7879"
    },
    {
      "rank": 87,
      "cve_id": "CVE-2026-22678",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00221,
      "epss_percentile": 0.12971,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Webmin",
      "product": "Webmin",
      "cwe": "CWE-79",
      "title": "Webmin < 2.641 Stored XSS via System and Server Status",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-22678"
    },
    {
      "rank": 88,
      "cve_id": "CVE-2026-1881",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00219,
      "epss_percentile": 0.12688,
      "kev": false,
      "kev_due_at": null,
      "vendor": "broadstreetads",
      "product": "Broadstreet",
      "cwe": "CWE-639",
      "title": "Broadstreet <= 1.52.2 - Authenticated (Subscriber+) Private Post Meta Disclosure via get_sponsored_meta",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-1881"
    },
    {
      "rank": 89,
      "cve_id": "CVE-2026-48240",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00218,
      "epss_percentile": 0.12589,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Open ISES",
      "product": "Tickets",
      "cwe": "CWE-89",
      "title": "Open ISES Tickets < 3.44.2 SQL Injection via ajax/statistics.php tick_id and f_tick_id Parameters",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48240"
    },
    {
      "rank": 90,
      "cve_id": "CVE-2026-48231",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00214,
      "epss_percentile": 0.1201,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Open ISES",
      "product": "Tickets",
      "cwe": "CWE-89",
      "title": "Open ISES Tickets < 3.44.2 SQL Injection via tables.php Multiple Parameters",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48231"
    },
    {
      "rank": 91,
      "cve_id": "CVE-2026-48232",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00214,
      "epss_percentile": 0.1201,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Open ISES",
      "product": "Tickets",
      "cwe": "CWE-89",
      "title": "Open ISES Tickets < 3.44.2 SQL Injection via ajax/fullsit_incidents.php offset Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48232"
    },
    {
      "rank": 92,
      "cve_id": "CVE-2026-48233",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00214,
      "epss_percentile": 0.12012,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Open ISES",
      "product": "Tickets",
      "cwe": "CWE-89",
      "title": "Open ISES Tickets < 3.44.2 SQL Injection via ajax/sit_incidents.php offset Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48233"
    },
    {
      "rank": 93,
      "cve_id": "CVE-2026-48234",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00214,
      "epss_percentile": 0.12012,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Open ISES",
      "product": "Tickets",
      "cwe": "CWE-89",
      "title": "Open ISES Tickets < 3.44.2 SQL Injection via portal/ajax/list_requests.php sort and dir Parameters",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48234"
    },
    {
      "rank": 94,
      "cve_id": "CVE-2026-48236",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00214,
      "epss_percentile": 0.12012,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Open ISES",
      "product": "Tickets",
      "cwe": "CWE-89",
      "title": "Open ISES Tickets < 3.44.2 SQL Injection via db_loader.php Multiple Parameters",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48236"
    },
    {
      "rank": 95,
      "cve_id": "CVE-2026-48237",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00214,
      "epss_percentile": 0.12009,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Open ISES",
      "product": "Tickets",
      "cwe": "CWE-89",
      "title": "Open ISES Tickets < 3.44.2 SQL Injection via message.php frm_ticket_id and frm_resp_id Parameters",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48237"
    },
    {
      "rank": 96,
      "cve_id": "CVE-2026-48238",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00214,
      "epss_percentile": 0.1201,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Open ISES",
      "product": "Tickets",
      "cwe": "CWE-89",
      "title": "Open ISES Tickets < 3.44.2 SQL Injection via ajax/mobile_main.php id Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48238"
    },
    {
      "rank": 97,
      "cve_id": "CVE-2026-48239",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00214,
      "epss_percentile": 0.12011,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Open ISES",
      "product": "Tickets",
      "cwe": "CWE-89",
      "title": "Open ISES Tickets < 3.44.2 SQL Injection via ajax/reports.php tick_id Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48239"
    },
    {
      "rank": 98,
      "cve_id": "CVE-2026-34928",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00213,
      "epss_percentile": 0.11943,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Trend Micro, Inc.",
      "product": "TrendAI Apex One",
      "cwe": "CWE-346",
      "title": "An origin validation vulnerability in the Apex One/SEP agent could allow a local attacker to escalate privileges on affected installations. This is similar to CVE-2026-34927 but exists in a different named pipe communication mechanism. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34928"
    },
    {
      "rank": 99,
      "cve_id": "CVE-2026-34930",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00213,
      "epss_percentile": 0.11944,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Trend Micro, Inc.",
      "product": "TrendAI Apex One",
      "cwe": "CWE-346",
      "title": "An origin validation vulnerability in the Apex One/SEP agent could allow a local attacker to escalate privileges on affected installations. This is similar to CVE-2026-34927 but exists in a different process protection mechanism. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34930"
    },
    {
      "rank": 100,
      "cve_id": "CVE-2026-45206",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00213,
      "epss_percentile": 0.11944,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Trend Micro, Inc.",
      "product": "TrendAI Apex One",
      "cwe": "CWE-346",
      "title": "An origin validation vulnerability in the Apex One/SEP agent could allow a local attacker to escalate privileges on affected installations. This is similar to CVE-2026-45207 but exists in a different process protection communication mechanism. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45206"
    },
    {
      "rank": 101,
      "cve_id": "CVE-2026-45207",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00213,
      "epss_percentile": 0.11943,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Trend Micro, Inc.",
      "product": "TrendAI Apex One",
      "cwe": "CWE-346",
      "title": "An origin validation vulnerability in the Apex One/SEP agent could allow a local attacker to escalate privileges on affected installations. This is similar to CVE-2026-45206 but exists in a different process protection communication mechanism. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45207"
    },
    {
      "rank": 102,
      "cve_id": "CVE-2026-44063",
      "cvss_base": 4.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00213,
      "epss_percentile": 0.11941,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Netatalk",
      "product": "Netatalk",
      "cwe": "CWE-90",
      "title": "LDAP filter injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44063"
    },
    {
      "rank": 103,
      "cve_id": "CVE-2026-48214",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00212,
      "epss_percentile": 0.11847,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Open ISES",
      "product": "Tickets",
      "cwe": "CWE-79",
      "title": "Open ISES Tickets < 3.44.2 Reflected XSS via add_nm.php ticket_id Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48214"
    },
    {
      "rank": 104,
      "cve_id": "CVE-2026-48215",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00212,
      "epss_percentile": 0.11849,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Open ISES",
      "product": "Tickets",
      "cwe": "CWE-79",
      "title": "Open ISES Tickets < 3.44.2 Reflected XSS via circle.php frm_id Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48215"
    },
    {
      "rank": 105,
      "cve_id": "CVE-2026-48216",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00212,
      "epss_percentile": 0.11849,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Open ISES",
      "product": "Tickets",
      "cwe": "CWE-79",
      "title": "Open ISES Tickets < 3.44.2 Reflected XSS via db_loader.php Multiple POST Parameters",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48216"
    },
    {
      "rank": 106,
      "cve_id": "CVE-2026-48217",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00212,
      "epss_percentile": 0.11848,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Open ISES",
      "product": "Tickets",
      "cwe": "CWE-79",
      "title": "Open ISES Tickets < 3.44.2 Reflected XSS via delete_module.php Multiple POST Parameters",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48217"
    },
    {
      "rank": 107,
      "cve_id": "CVE-2026-48219",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00212,
      "epss_percentile": 0.11848,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Open ISES",
      "product": "Tickets",
      "cwe": "CWE-79",
      "title": "Open ISES Tickets < 3.44.2 Reflected XSS via ics202.php frm_add_str Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48219"
    },
    {
      "rank": 108,
      "cve_id": "CVE-2026-48220",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00212,
      "epss_percentile": 0.11847,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Open ISES",
      "product": "Tickets",
      "cwe": "CWE-79",
      "title": "Open ISES Tickets < 3.44.2 Reflected XSS via ics205.php frm_add_str Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48220"
    },
    {
      "rank": 109,
      "cve_id": "CVE-2026-48221",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00212,
      "epss_percentile": 0.11848,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Open ISES",
      "product": "Tickets",
      "cwe": "CWE-79",
      "title": "Open ISES Tickets < 3.44.2 Reflected XSS via ics205a.php frm_add_str Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48221"
    },
    {
      "rank": 110,
      "cve_id": "CVE-2026-48222",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00212,
      "epss_percentile": 0.11848,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Open ISES",
      "product": "Tickets",
      "cwe": "CWE-79",
      "title": "Open ISES Tickets < 3.44.2 Reflected XSS via ics213.php frm_add_str Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48222"
    },
    {
      "rank": 111,
      "cve_id": "CVE-2026-48223",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00212,
      "epss_percentile": 0.11847,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Open ISES",
      "product": "Tickets",
      "cwe": "CWE-79",
      "title": "Open ISES Tickets < 3.44.2 Reflected XSS via ics213rr.php frm_add_str Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48223"
    },
    {
      "rank": 112,
      "cve_id": "CVE-2026-48225",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00212,
      "epss_percentile": 0.1175,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Open ISES",
      "product": "Tickets",
      "cwe": "CWE-79",
      "title": "Open ISES Tickets < 3.44.2 Reflected XSS via landb.php _type Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48225"
    },
    {
      "rank": 113,
      "cve_id": "CVE-2026-48230",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00212,
      "epss_percentile": 0.11749,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Open ISES",
      "product": "Tickets",
      "cwe": "CWE-79",
      "title": "Open ISES Tickets < 3.44.2 Reflected XSS via ticketsmdb_import.php Multiple POST Parameters",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48230"
    },
    {
      "rank": 114,
      "cve_id": "CVE-2026-8204",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00211,
      "epss_percentile": 0.11729,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Concrete CMS",
      "product": "Concrete CMS",
      "cwe": "CWE-639",
      "title": "Concrete CMS 9.5.0 and below is vulnerable to Authorization Bypass in the Calendar Event Frontend Dialog",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8204"
    },
    {
      "rank": 115,
      "cve_id": "CVE-2026-8205",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00211,
      "epss_percentile": 0.11729,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Concrete CMS",
      "product": "Concrete CMS",
      "cwe": "CWE-425",
      "title": "Concrete CMS 9.5.0 and below is vulnerable to authorization bypass in Calendar Block since action_get_events does not check canView on the calendar",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8205"
    },
    {
      "rank": 116,
      "cve_id": "CVE-2026-5434",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00208,
      "epss_percentile": 0.11221,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Honeywell International Inc.",
      "product": "Control Network Module (CNM)",
      "cwe": "CWE-538",
      "title": "Improper storage of sensitive information",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-5434"
    },
    {
      "rank": 117,
      "cve_id": "CVE-2026-48248",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00205,
      "epss_percentile": 0.10836,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Open ISES",
      "product": "Tickets",
      "cwe": "CWE-295",
      "title": "Open ISES Tickets < 3.44.2 Disabled TLS Certificate Verification in incs/login.inc.php",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48248"
    },
    {
      "rank": 118,
      "cve_id": "CVE-2026-7881",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00205,
      "epss_percentile": 0.10798,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Concrete CMS",
      "product": "Concrete CMS",
      "cwe": "CWE-639",
      "title": "Concrete CMS 9.5.0 and below is vulnerable to IDOR in the Express Entry Detail block",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7881"
    },
    {
      "rank": 119,
      "cve_id": "CVE-2026-4929",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00205,
      "epss_percentile": 0.10808,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Drupal",
      "product": "Simple Hierarchical Select (shs)",
      "cwe": "CWE-79",
      "title": "Simple Hierarchical Select (Drupal 7) XSS in term-derived output",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-4929"
    },
    {
      "rank": 120,
      "cve_id": "CVE-2026-28764",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00203,
      "epss_percentile": 0.10648,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MediaArea",
      "product": "MediaInfoLib",
      "cwe": "CWE-823",
      "title": "MediaArea MediaInfoLib LXF element parsing heap-based buffer overflow vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28764"
    },
    {
      "rank": 121,
      "cve_id": "CVE-2026-8236",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00202,
      "epss_percentile": 0.10503,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Concrete CMS",
      "product": "Concrete CMS",
      "cwe": "CWE-862",
      "title": "Concrete CMS 9.5.0 and below is vulnerable to IDOR combined with a missing authentication gate for endpoint /ccm/system/dialogs/file/usage/{fID}",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8236"
    },
    {
      "rank": 122,
      "cve_id": "CVE-2026-8237",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00201,
      "epss_percentile": 0.10361,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Concrete CMS",
      "product": "Concrete CMS",
      "cwe": "CWE-862",
      "title": "Concrete CMS 9.5.0 and below is vulnerable to IDOR in the`/ccm/frontend/conversations/message_detail` endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8237"
    },
    {
      "rank": 123,
      "cve_id": "CVE-2026-8238",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00201,
      "epss_percentile": 0.10361,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Concrete CMS",
      "product": "Concrete CMS",
      "cwe": "CWE-862",
      "title": "Concrete CMS 9.5.0 and below is vulnerable to IDOR in '/ccm/frontend/conversations/message_page' allowing unauthenticated read of any conversation message",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8238"
    },
    {
      "rank": 124,
      "cve_id": "CVE-2026-45253",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00196,
      "epss_percentile": 0.09736,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FreeBSD",
      "product": "FreeBSD",
      "cwe": "CWE-787",
      "title": "Missing validation in ptrace(PT_SC_REMOTE)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45253"
    },
    {
      "rank": 125,
      "cve_id": "CVE-2026-5091",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00196,
      "epss_percentile": 0.09653,
      "kev": false,
      "kev_due_at": null,
      "vendor": "JJNAPIORK",
      "product": "Catalyst::Plugin::Authentication",
      "cwe": "CWE-208",
      "title": "Catalyst::Plugin::Authentication versions through 0.10024 for Perl is susceptible to timing attacks",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-5091"
    },
    {
      "rank": 126,
      "cve_id": "CVE-2026-8239",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00195,
      "epss_percentile": 0.09558,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Concrete CMS",
      "product": "Concrete CMS",
      "cwe": "CWE-862",
      "title": "Concrete CMS 9.5.0 and below is vulnerable to IDOR in '/ccm/frontend/conversations/get_rating'",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8239"
    },
    {
      "rank": 127,
      "cve_id": "CVE-2026-8240",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00195,
      "epss_percentile": 0.09557,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Concrete CMS",
      "product": "Concrete CMS",
      "cwe": "CWE-284",
      "title": "Concrete CMS 9.5.0 and below is vulnerable to unauthenticated page metadata disclosure in Backend\\SummaryTemplate",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8240"
    },
    {
      "rank": 128,
      "cve_id": "CVE-2026-45254",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00194,
      "epss_percentile": 0.09487,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FreeBSD",
      "product": "FreeBSD",
      "cwe": "CWE-269",
      "title": "Incorrect libcap_net limitation list manipulation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45254"
    },
    {
      "rank": 129,
      "cve_id": "CVE-2026-8337",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00194,
      "epss_percentile": 0.09489,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Concrete CMS",
      "product": "Concrete CMS",
      "cwe": "CWE-565",
      "title": "Concrete CMS 9.5.0 and below is vulnerable to IDOR in surveys when sites are running concurrent public surveys and private surveys",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8337"
    },
    {
      "rank": 130,
      "cve_id": "CVE-2026-4843",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00192,
      "epss_percentile": 0.09248,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mrdollar4444",
      "product": "GSheet For Woo Importer",
      "cwe": "CWE-862",
      "title": "GSheet For Woo Importer <= 2.3.1 - Missing Authorization to Authenticated (Subscriber+) Plugin Settings Reset",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-4843"
    },
    {
      "rank": 131,
      "cve_id": "CVE-2026-44057",
      "cvss_base": 3.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00186,
      "epss_percentile": 0.08552,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Netatalk",
      "product": "Netatalk",
      "cwe": "CWE-561",
      "title": "Dead bounds check in Spotlight RPC unmarshaller",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44057"
    },
    {
      "rank": 132,
      "cve_id": "CVE-2026-1816",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00184,
      "epss_percentile": 0.08298,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Turkiye Electricity Transmission Corporation (TEİAŞ)",
      "product": "Mobile Application",
      "cwe": "CWE-307",
      "title": "OTP Bypass in TEİAŞ's Mobile Application",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-1816"
    },
    {
      "rank": 133,
      "cve_id": "CVE-2026-8197",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00182,
      "epss_percentile": 0.08058,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Concrete CMS",
      "product": "Concrete CMS",
      "cwe": "CWE-79",
      "title": "Concrete CMS 9.5.0 and below is vulnerable to Stored XSS via OAuth integration name",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8197"
    },
    {
      "rank": 134,
      "cve_id": "CVE-2026-8327",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00182,
      "epss_percentile": 0.08152,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Concrete CMS",
      "product": "Concrete CMS",
      "cwe": "CWE-269",
      "title": "Concrete CMS below 9.5.0 and below is vulnerable to password change without reauthorization and session-hardening bypass.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8327"
    },
    {
      "rank": 135,
      "cve_id": "CVE-2026-1815",
      "cvss_base": 5.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00178,
      "epss_percentile": 0.07605,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Turkiye Electricity Transmission Corporation (TEİAŞ)",
      "product": "Mobile Application",
      "cwe": "CWE-613",
      "title": "Session Hijacking in TEİAŞ's Mobile Application",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-1815"
    },
    {
      "rank": 136,
      "cve_id": "CVE-2026-48247",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00173,
      "epss_percentile": 0.0702,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Open ISES",
      "product": "Tickets",
      "cwe": "CWE-295",
      "title": "Open ISES Tickets < 3.44.2 Disabled TLS Certificate Verification in incs/functions.inc.php",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48247"
    },
    {
      "rank": 137,
      "cve_id": "CVE-2026-48249",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00173,
      "epss_percentile": 0.0702,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Open ISES",
      "product": "Tickets",
      "cwe": "CWE-295",
      "title": "Open ISES Tickets < 3.44.2 Disabled TLS Certificate Verification in rm/incs/mobile_login.inc.php",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48249"
    },
    {
      "rank": 138,
      "cve_id": "CVE-2026-39461",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00172,
      "epss_percentile": 0.06994,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FreeBSD",
      "product": "FreeBSD",
      "cwe": "CWE-121",
      "title": "select(2) file descriptor set overflow causes stack overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39461"
    },
    {
      "rank": 139,
      "cve_id": "CVE-2026-4093",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00172,
      "epss_percentile": 0.06916,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Drupal",
      "product": "Term Reference Tree",
      "cwe": "CWE-79",
      "title": "Stored XSS in Drupal 7 Term Reference Tree module (token display templates and term labels)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-4093"
    },
    {
      "rank": 140,
      "cve_id": "CVE-2026-48213",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00172,
      "epss_percentile": 0.07013,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Open ISES",
      "product": "Tickets",
      "cwe": "CWE-79",
      "title": "Open ISES Tickets < 3.44.2 Reflected XSS via add.php ticket_id Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48213"
    },
    {
      "rank": 141,
      "cve_id": "CVE-2026-7887",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00172,
      "epss_percentile": 0.07001,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Concrete CMS",
      "product": "Concrete CMS",
      "cwe": "CWE-1287",
      "title": "For Concrete CMS 9.5.0 and below, OAuth 2.0 Authorization-Code Handler Bypasses Account Status",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7887"
    },
    {
      "rank": 142,
      "cve_id": "CVE-2026-8421",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00171,
      "epss_percentile": 0.0684,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Concrete CMS",
      "product": "Concrete CMS",
      "cwe": "CWE-352",
      "title": "Concrete CMS 9.5.0 and below is vulnerable to CSRF on install_package() with conditional token bypass leading to RCE",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8421"
    },
    {
      "rank": 143,
      "cve_id": "CVE-2026-8426",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00171,
      "epss_percentile": 0.0684,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Concrete CMS",
      "product": "Concrete CMS",
      "cwe": "CWE-352",
      "title": "Concrete CMS 9.5.0 and below is vulnerable to CSRF on prepare_remote_upgrade() leading to one-request RCE via package overwrite",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8426"
    },
    {
      "rank": 144,
      "cve_id": "CVE-2026-44064",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00171,
      "epss_percentile": 0.06822,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Netatalk",
      "product": "Netatalk",
      "cwe": "CWE-125",
      "title": "ASP session ID out-of-bounds access",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44064"
    },
    {
      "rank": 145,
      "cve_id": "CVE-2026-27393",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00171,
      "epss_percentile": 0.06851,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tobias",
      "product": "CF7 WOW Styler",
      "cwe": "CWE-862",
      "title": "WordPress CF7 WOW Styler plugin <= 1.7.6 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-27393"
    },
    {
      "rank": 146,
      "cve_id": "CVE-2026-27349",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00171,
      "epss_percentile": 0.06884,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WPFunnels Team",
      "product": "Mail Mint",
      "cwe": "CWE-497",
      "title": "WordPress Mail Mint plugin <= 1.19.5 - Sensitive Data Exposure vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-27349"
    },
    {
      "rank": 147,
      "cve_id": "CVE-2026-45251",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0017,
      "epss_percentile": 0.06816,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FreeBSD",
      "product": "FreeBSD",
      "cwe": "CWE-416",
      "title": "Kernel use-after-free via file descriptor syscalls",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45251"
    },
    {
      "rank": 148,
      "cve_id": "CVE-2026-48246",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00169,
      "epss_percentile": 0.06683,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Open ISES",
      "product": "Tickets",
      "cwe": "CWE-295",
      "title": "Open ISES Tickets < 3.44.2 Disabled TLS Certificate Verification in ajax/reports.php",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48246"
    },
    {
      "rank": 149,
      "cve_id": "CVE-2026-48226",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00169,
      "epss_percentile": 0.06668,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Open ISES",
      "product": "Tickets",
      "cwe": "CWE-79",
      "title": "Open ISES Tickets < 3.44.2 Reflected XSS via os_watch.php ref and mode_orig Parameters",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48226"
    },
    {
      "rank": 150,
      "cve_id": "CVE-2026-48227",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00169,
      "epss_percentile": 0.06669,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Open ISES",
      "product": "Tickets",
      "cwe": "CWE-79",
      "title": "Open ISES Tickets < 3.44.2 Reflected XSS via patient.php id and ticket_id Parameters",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48227"
    },
    {
      "rank": 151,
      "cve_id": "CVE-2026-48228",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00169,
      "epss_percentile": 0.0667,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Open ISES",
      "product": "Tickets",
      "cwe": "CWE-79",
      "title": "Open ISES Tickets < 3.44.2 Reflected XSS via patient_w.php id and ticket_id Parameters",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48228"
    },
    {
      "rank": 152,
      "cve_id": "CVE-2026-48229",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00169,
      "epss_percentile": 0.06669,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Open ISES",
      "product": "Tickets",
      "cwe": "CWE-79",
      "title": "Open ISES Tickets < 3.44.2 Reflected XSS via routes_i.php ticket_id Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48229"
    },
    {
      "rank": 153,
      "cve_id": "CVE-2026-4055",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00152,
      "epss_percentile": 0.04906,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mattermost",
      "product": "Mattermost",
      "cwe": "CWE-863",
      "title": "Insufficient permission validation on cross-team playbook run creation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-4055"
    },
    {
      "rank": 154,
      "cve_id": "CVE-2026-7890",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00152,
      "epss_percentile": 0.04936,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Concrete CMS",
      "product": "Concrete CMS",
      "cwe": "CWE-918",
      "title": "Concrete CMS 9.5.0 is vulnerable to SSRF via RSS Displayer Block",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7890"
    },
    {
      "rank": 155,
      "cve_id": "CVE-2026-8139",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": 0.0015,
      "epss_percentile": 0.04748,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Concrete CMS",
      "product": "Concrete CMS",
      "cwe": "CWE-79",
      "title": "Concrete CMS 9.5.0 and below is vulnerable to Stored XSS via external-link page cvName",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8139"
    },
    {
      "rank": 156,
      "cve_id": "CVE-2026-41999",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00142,
      "epss_percentile": 0.04018,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PowerDNS",
      "product": "Authoritative",
      "cwe": "CWE-284",
      "title": "Incorrect Behaviour of Views with TCP PROXY Requests",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41999"
    },
    {
      "rank": 157,
      "cve_id": "CVE-2026-8409",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00142,
      "epss_percentile": 0.04025,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Concrete CMS",
      "product": "Concrete CMS",
      "cwe": "CWE-352",
      "title": "Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/logs/delete",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8409"
    },
    {
      "rank": 158,
      "cve_id": "CVE-2026-8410",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00142,
      "epss_percentile": 0.04025,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Concrete CMS",
      "product": "Concrete CMS",
      "cwe": "CWE-352",
      "title": "Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/logs/bulk/delete",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8410"
    },
    {
      "rank": 159,
      "cve_id": "CVE-2026-8245",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00139,
      "epss_percentile": 0.03759,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Concrete CMS",
      "product": "Concrete CMS",
      "cwe": "CWE-83",
      "title": "Concrete CMS 9.5.0 and below is vulnerable to Reflected XSS in Legacy Pagination via HTML attribute injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8245"
    },
    {
      "rank": 160,
      "cve_id": "CVE-2026-36189",
      "cvss_base": 6.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00134,
      "epss_percentile": 0.03337,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-120",
      "title": "Buffer Overflow vulnerability in Uncrustify Project Affected v.Uncrustify_d-0.82.0-132-bcc41cbdc and Fixed in commit 68e67b9a1435a1bb173b106fedb4a4f510972bdc allows a local attacker to cause a denial of service via the check_template.cpp, check_template function, tokenize_cleanup function, uncrustify executable components",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-36189"
    },
    {
      "rank": 161,
      "cve_id": "CVE-2026-8428",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00132,
      "epss_percentile": 0.03215,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Concrete CMS",
      "product": "Concrete CMS",
      "cwe": "CWE-352",
      "title": "CSRF token is not validated in the core CMS update controller for Concrete CMS 9.5.0 and below",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8428"
    },
    {
      "rank": 162,
      "cve_id": "CVE-2026-44076",
      "cvss_base": 6.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0013,
      "epss_percentile": 0.03066,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Netatalk",
      "product": "Netatalk",
      "cwe": "CWE-78",
      "title": "Shell injection via volume path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44076"
    },
    {
      "rank": 163,
      "cve_id": "CVE-2026-44065",
      "cvss_base": 4.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0013,
      "epss_percentile": 0.03091,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Netatalk",
      "product": "Netatalk",
      "cwe": "CWE-193",
      "title": "Off-by-two in papd lp_write()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44065"
    },
    {
      "rank": 164,
      "cve_id": "CVE-2026-8411",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": 0.0013,
      "epss_percentile": 0.03081,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Concrete CMS",
      "product": "Concrete CMS",
      "cwe": "CWE-352",
      "title": "Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/page/bulk/delete",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8411"
    },
    {
      "rank": 165,
      "cve_id": "CVE-2026-8412",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": 0.0013,
      "epss_percentile": 0.03082,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Concrete CMS",
      "product": "Concrete CMS",
      "cwe": "CWE-352",
      "title": "Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/page/bulk/cache",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8412"
    },
    {
      "rank": 166,
      "cve_id": "CVE-2026-8413",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": 0.0013,
      "epss_percentile": 0.03084,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Concrete CMS",
      "product": "Concrete CMS",
      "cwe": "CWE-352",
      "title": "Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/page/bulk/design",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8413"
    },
    {
      "rank": 167,
      "cve_id": "CVE-2026-8414",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": 0.0013,
      "epss_percentile": 0.03082,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Concrete CMS",
      "product": "Concrete CMS",
      "cwe": "CWE-352",
      "title": "Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/event/duplicate",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8414"
    },
    {
      "rank": 168,
      "cve_id": "CVE-2026-8415",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": 0.0013,
      "epss_percentile": 0.03083,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Concrete CMS",
      "product": "Concrete CMS",
      "cwe": "CWE-352",
      "title": "Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/express/association/reorder",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8415"
    },
    {
      "rank": 169,
      "cve_id": "CVE-2026-8416",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": 0.0013,
      "epss_percentile": 0.03081,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Concrete CMS",
      "product": "Concrete CMS",
      "cwe": "CWE-352",
      "title": "Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file addFavoriteFolder($id)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8416"
    },
    {
      "rank": 170,
      "cve_id": "CVE-2026-8427",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": 0.0013,
      "epss_percentile": 0.03083,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Concrete CMS",
      "product": "Concrete CMS",
      "cwe": "CWE-352",
      "title": "Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file removeFavoriteFolder($id)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8427"
    },
    {
      "rank": 171,
      "cve_id": "CVE-2026-8432",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": 0.0013,
      "epss_percentile": 0.03082,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Concrete CMS",
      "product": "Concrete CMS",
      "cwe": "CWE-352",
      "title": "Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file star()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8432"
    },
    {
      "rank": 172,
      "cve_id": "CVE-2026-8433",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": 0.0013,
      "epss_percentile": 0.03083,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Concrete CMS",
      "product": "Concrete CMS",
      "cwe": "CWE-352",
      "title": "Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file rescan()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8433"
    },
    {
      "rank": 173,
      "cve_id": "CVE-2026-8434",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": 0.0013,
      "epss_percentile": 0.03083,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Concrete CMS",
      "product": "Concrete CMS",
      "cwe": "CWE-352",
      "title": "Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file rescanMultiple()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8434"
    },
    {
      "rank": 174,
      "cve_id": "CVE-2026-43502",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00123,
      "epss_percentile": 0.02485,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net/rds: handle zerocopy send cleanup before the message is queued",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43502"
    },
    {
      "rank": 175,
      "cve_id": "CVE-2026-8417",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00122,
      "epss_percentile": 0.02332,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Concrete CMS",
      "product": "Concrete CMS",
      "cwe": "CWE-352",
      "title": "Concrete CMS 9.5.0 and below is vulnerable to CSRF in do_update() in the package update controller",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8417"
    },
    {
      "rank": 176,
      "cve_id": "CVE-2026-8203",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00122,
      "epss_percentile": 0.0233,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Concrete CMS",
      "product": "Concrete CMS",
      "cwe": "CWE-79",
      "title": "Concrete CMS 9.5.0 and below has Stored XSS on the height parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8203"
    },
    {
      "rank": 177,
      "cve_id": "CVE-2026-9157",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.0012,
      "epss_percentile": 0.02139,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Gmission",
      "product": "Web Fax",
      "cwe": "CWE-20",
      "title": "Remote Code Execution in Gmission Web FAX",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9157"
    },
    {
      "rank": 178,
      "cve_id": "CVE-2026-8140",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00118,
      "epss_percentile": 0.02027,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Concrete CMS",
      "product": "Concrete CMS",
      "cwe": "CWE-352",
      "title": "Concrete CMS 9.5.0 and below is vulnerable to CSRF on download() in the package install controller",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8140"
    },
    {
      "rank": 179,
      "cve_id": "CVE-2026-43496",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00118,
      "epss_percentile": 0.02036,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-476",
      "title": "net/sched: sch_red: Replace direct dequeue call with peek and qdisc_dequeue_peeked",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43496"
    },
    {
      "rank": 180,
      "cve_id": "CVE-2026-22880",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00117,
      "epss_percentile": 0.01978,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mattermost",
      "product": "Mattermost",
      "cwe": "CWE-352",
      "title": "Mobile SSO authentication flow allows credential theft via malicious server",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-22880"
    },
    {
      "rank": 181,
      "cve_id": "CVE-2026-7882",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00116,
      "epss_percentile": 0.01872,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Concrete CMS",
      "product": "Concrete CMS",
      "cwe": "CWE-352",
      "title": "Concrete CMS 9.5.0 and below is vulnerable to CSRF via the DeleteFile controller",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7882"
    },
    {
      "rank": 182,
      "cve_id": "CVE-2026-8435",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00115,
      "epss_percentile": 0.01803,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Concrete CMS",
      "product": "Concrete CMS",
      "cwe": "CWE-352",
      "title": "Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file approveVersion()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8435"
    },
    {
      "rank": 183,
      "cve_id": "CVE-2026-43498",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00113,
      "epss_percentile": 0.01625,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-787",
      "title": "accel/ivpu: Disallow re-exporting imported GEM objects",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43498"
    },
    {
      "rank": 184,
      "cve_id": "CVE-2026-43497",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00113,
      "epss_percentile": 0.01684,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-416",
      "title": "fbdev: udlfb: add vm_ops to dlfb_ops_mmap to prevent use-after-free",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43497"
    },
    {
      "rank": 185,
      "cve_id": "CVE-2026-44069",
      "cvss_base": 3.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00094,
      "epss_percentile": 0.00682,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Netatalk",
      "product": "Netatalk",
      "cwe": "CWE-191",
      "title": "Integer underflow in volxlate",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44069"
    },
    {
      "rank": 186,
      "cve_id": "CVE-2026-44072",
      "cvss_base": 3,
      "cvss_severity": "LOW",
      "epss_score": 0.00091,
      "epss_percentile": 0.00554,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Netatalk",
      "product": "Netatalk",
      "cwe": "CWE-78",
      "title": "system() after failed chdir()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44072"
    },
    {
      "rank": 187,
      "cve_id": "CVE-2026-44059",
      "cvss_base": 4.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00065,
      "epss_percentile": 0.00021,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Netatalk",
      "product": "Netatalk",
      "cwe": "CWE-362",
      "title": "Non-reentrant privilege toggle",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44059"
    }
  ],
  "transactions": [
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-2734",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-2734 (mlflow/mlflow). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-28764",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-28764 (MediaArea MediaInfoLib). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-4093",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-4093 (Drupal Term Reference Tree). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-43494",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-43494 (Linux). Public exploit reference added."
    }
  ],
  "attribution": "CVE Program, NVD (NIST), CISA KEV, FIRST EPSS, OSV. See /security/methodology/."
}
