{
  "day": "2026-05-22",
  "boundary": "UTC calendar day",
  "published_count": 148,
  "by_severity": {
    "CRITICAL": 25,
    "HIGH": 52,
    "MEDIUM": 61,
    "LOW": 10
  },
  "kev_count": 1,
  "exploit_reference_count": 5,
  "awaiting_enrichment_count": 0,
  "ranking": "Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.",
  "results": [
    {
      "rank": 1,
      "cve_id": "CVE-2026-9082",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.88319,
      "epss_percentile": 0.99757,
      "kev": true,
      "kev_due_at": "2026-05-27",
      "vendor": "Drupal",
      "product": "Drupal core",
      "cwe": "CWE-89",
      "title": "Drupal core - Highly critical - SQL injection - SA-CORE-2026-004",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9082"
    },
    {
      "rank": 2,
      "cve_id": "CVE-2026-9256",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.09963,
      "epss_percentile": 0.95209,
      "kev": false,
      "kev_due_at": null,
      "vendor": "F5",
      "product": "NGINX Plus",
      "cwe": "CWE-122",
      "title": "NGINX ngx_http_rewrite_module vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9256"
    },
    {
      "rank": 3,
      "cve_id": "CVE-2026-8679",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.01566,
      "epss_percentile": 0.73324,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cssigniterteam",
      "product": "AudioIgniter Music Player",
      "cwe": "CWE-639",
      "title": "AudioIgniter Music Player <= 2.0.2 - Unauthenticated Insecure Direct Object Reference to 'audioigniter_playlist_id' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8679"
    },
    {
      "rank": 4,
      "cve_id": "CVE-2026-33000",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.01248,
      "epss_percentile": 0.66963,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ubiquiti Inc",
      "product": "UniFi OS Server",
      "cwe": "CWE-20",
      "title": "A malicious actor with access to the network and high privileges could exploit an Improper Input Validation vulnerability found in UniFi OS devices to execute a Command Injection.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-33000"
    },
    {
      "rank": 5,
      "cve_id": "CVE-2026-41104",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00922,
      "epss_percentile": 0.57531,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft Planetary Computer Pro (GeoCatalog)",
      "cwe": "CWE-502",
      "title": "Microsoft Planetary Computer Pro Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41104"
    },
    {
      "rank": 6,
      "cve_id": "CVE-2026-36227",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00866,
      "epss_percentile": 0.55863,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-22",
      "title": "Directory Traversal vulnerability in Easy Chat Server 3.1 allows a remote attacker to obtain sensitive information and execute arbitrary code via the UserName parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-36227"
    },
    {
      "rank": 7,
      "cve_id": "CVE-2026-9277",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00848,
      "epss_percentile": 0.5525,
      "kev": false,
      "kev_due_at": null,
      "vendor": null,
      "product": "shell-quote",
      "cwe": "CWE-78",
      "title": "shell-quote `quote()` does not validate object-token shapes, allowing command injection via line terminators in `.op`",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9277"
    },
    {
      "rank": 8,
      "cve_id": "CVE-2025-45145",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00715,
      "epss_percentile": 0.50909,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-22",
      "title": "Directory traversal in Follett Software's Destiny Library Manager 22_0_2_rc1 and fixed in v.22.5 AU1 allows remote attackers to read arbitrary system and application files via the image parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-45145"
    },
    {
      "rank": 9,
      "cve_id": "CVE-2026-7798",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00695,
      "epss_percentile": 0.50172,
      "kev": false,
      "kev_due_at": null,
      "vendor": "techjewel",
      "product": "FluentCRM – Email Newsletter, Automation, Email Marketing, Email Campaigns, Optins, Leads, and CRM Solution",
      "cwe": "CWE-918",
      "title": "FluentCRM <= 2.9.87 - Unauthenticated Blind Server-Side Request Forgery via 'SubscribeURL' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7798"
    },
    {
      "rank": 10,
      "cve_id": "CVE-2026-44930",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00694,
      "epss_percentile": 0.50137,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache CXF",
      "cwe": "CWE-90",
      "title": "Apache CXF: LDAP Injection vulnerability in XKMS LDAP Repository",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44930"
    },
    {
      "rank": 11,
      "cve_id": "CVE-2026-34911",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.0068,
      "epss_percentile": 0.49609,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ubiquiti Inc",
      "product": "UniFi OS Server",
      "cwe": "CWE-22",
      "title": "A malicious actor with access to the network and low privileges could exploit a Path Traversal vulnerability found in UniFi OS devices to access files on the underlying system that could be manipulated to obtain sensitive information.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34911"
    },
    {
      "rank": 12,
      "cve_id": "CVE-2026-39821",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00655,
      "epss_percentile": 0.48619,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Go standard library",
      "product": "net/http",
      "cwe": "CWE-1289",
      "title": "Invoking failure to reject ASCII-only Punycode-encoded labels in golang.org/x/net/idna",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39821"
    },
    {
      "rank": 13,
      "cve_id": "CVE-2026-44417",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0064,
      "epss_percentile": 0.47914,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache CXF",
      "cwe": "CWE-20",
      "title": "Apache CXF: Incomplete fix for CVE-2025-48913 (Untrusted JMS configuration can lead to RCE)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44417"
    },
    {
      "rank": 14,
      "cve_id": "CVE-2026-39830",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00621,
      "epss_percentile": 0.47109,
      "kev": false,
      "kev_due_at": null,
      "vendor": "golang.org/x/crypto",
      "product": "golang.org/x/crypto/ssh",
      "cwe": "CWE-772",
      "title": "Invoking client can cause server deadlock on unexpected responses in golang.org/x/crypto/ssh",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39830"
    },
    {
      "rank": 15,
      "cve_id": "CVE-2026-39832",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.006,
      "epss_percentile": 0.46112,
      "kev": false,
      "kev_due_at": null,
      "vendor": "golang.org/x/crypto",
      "product": "golang.org/x/crypto/ssh/agent",
      "cwe": "CWE-502",
      "title": "Invoking agent constraints dropped when forwarding keys in golang.org/x/crypto/ssh/agent",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39832"
    },
    {
      "rank": 16,
      "cve_id": "CVE-2026-26147",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00579,
      "epss_percentile": 0.45116,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Azure Stack HCI",
      "cwe": "CWE-20",
      "title": "Azure Stack HCI Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-26147"
    },
    {
      "rank": 17,
      "cve_id": "CVE-2026-23652",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00577,
      "epss_percentile": 0.45011,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft Power Pages",
      "cwe": "CWE-77",
      "title": "Microsoft Power Pages Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-23652"
    },
    {
      "rank": 18,
      "cve_id": "CVE-2026-42508",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00568,
      "epss_percentile": 0.44597,
      "kev": false,
      "kev_due_at": null,
      "vendor": "golang.org/x/crypto",
      "product": "golang.org/x/crypto/ssh/knownhosts",
      "cwe": "CWE-295",
      "title": "Invoking auth bypass via unenforced @revoked status in golang.org/x/crypto/ssh/knownhosts",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42508"
    },
    {
      "rank": 19,
      "cve_id": "CVE-2026-8992",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00564,
      "epss_percentile": 0.44403,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ivanti",
      "product": "Secure Access Client",
      "cwe": "CWE-295",
      "title": "An improper certificate validation vulnerability in Ivanti Secure Access Client before 22.8R6 allows a remote unauthenticated attacker to execute arbitrary code.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8992"
    },
    {
      "rank": 20,
      "cve_id": "CVE-2026-23663",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00551,
      "epss_percentile": 0.43725,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft Global Secure Access (GSA)",
      "cwe": "CWE-269",
      "title": "Microsoft Global Secure Access (GSA) Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-23663"
    },
    {
      "rank": 21,
      "cve_id": "CVE-2026-9018",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00541,
      "epss_percentile": 0.43188,
      "kev": false,
      "kev_due_at": null,
      "vendor": "themewant",
      "product": "Easy Elements for Elementor – Addons & Website Templates",
      "cwe": "CWE-269",
      "title": "Easy Elements for Elementor – Addons & Website Templates <= 1.4.5 - Unauthenticated Privilege Escalation via 'custom_meta' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9018"
    },
    {
      "rank": 22,
      "cve_id": "CVE-2026-40172",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00535,
      "epss_percentile": 0.42848,
      "kev": false,
      "kev_due_at": null,
      "vendor": "goauthentik",
      "product": "authentik",
      "cwe": "CWE-269",
      "title": "authentik: Privilege Escalation via User PATCH: Superuser Group Assignment Bypasses enable_group_superuser",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40172"
    },
    {
      "rank": 23,
      "cve_id": "CVE-2026-40412",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00534,
      "epss_percentile": 0.4279,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Azure Orbital Spatio",
      "cwe": "CWE-434",
      "title": "Azure Orbital Spatio Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40412"
    },
    {
      "rank": 24,
      "cve_id": "CVE-2026-39834",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00525,
      "epss_percentile": 0.42299,
      "kev": false,
      "kev_due_at": null,
      "vendor": "golang.org/x/crypto",
      "product": "golang.org/x/crypto/ssh",
      "cwe": "CWE-190",
      "title": "Invoking infinite loop on large channel writes in golang.org/x/crypto/ssh",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39834"
    },
    {
      "rank": 25,
      "cve_id": "CVE-2026-40411",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00525,
      "epss_percentile": 0.42303,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Azure Virtual Network Gateway",
      "cwe": "CWE-20",
      "title": "Azure Virtual Network Gateway Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40411"
    },
    {
      "rank": 26,
      "cve_id": "CVE-2026-39835",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00504,
      "epss_percentile": 0.40986,
      "kev": false,
      "kev_due_at": null,
      "vendor": "golang.org/x/crypto",
      "product": "golang.org/x/crypto/ssh",
      "cwe": "CWE-476",
      "title": "Invoking server panic during CheckHostKey/Authenticate in golang.org/x/crypto/ssh",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39835"
    },
    {
      "rank": 27,
      "cve_id": "CVE-2026-46595",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00503,
      "epss_percentile": 0.40975,
      "kev": false,
      "kev_due_at": null,
      "vendor": "golang.org/x/crypto",
      "product": "golang.org/x/crypto/ssh",
      "cwe": "CWE-863",
      "title": "Invoking VerifiedPublicKeyCallback permissions skip enforcement in golang.org/x/crypto/ssh",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46595"
    },
    {
      "rank": 28,
      "cve_id": "CVE-2026-42827",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00503,
      "epss_percentile": 0.40948,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Copilot",
      "cwe": "CWE-77",
      "title": "M365 Copilot Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42827"
    },
    {
      "rank": 29,
      "cve_id": "CVE-2026-40597",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00498,
      "epss_percentile": 0.40672,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mantisbt",
      "product": "mantisbt",
      "cwe": "CWE-79",
      "title": "MantisBT has a Content Security Policy bypass via attachments",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40597"
    },
    {
      "rank": 30,
      "cve_id": "CVE-2026-47280",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00494,
      "epss_percentile": 0.40394,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Azure Resource Manager",
      "cwe": "CWE-287",
      "title": "Azure Resource Manager Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47280"
    },
    {
      "rank": 31,
      "cve_id": "CVE-2026-46727",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00478,
      "epss_percentile": 0.39385,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ruby-lang",
      "product": "Ruby",
      "cwe": "CWE-362",
      "title": "An issue was discovered in Ruby 4 before 4.0.5. A race condition leading to a use-after-free in the pthread-based getaddrinfo timeout handler (rb_getaddrinfo in ext/socket/raddrinfo.c) allows a remote attacker who can delay DNS responses near the user-specified timeout to crash a Ruby process that calls Addrinfo.getaddrinfo(..., timeout:) or Socket.tcp(..., resolv_timeout:). Memory-corruption-based exploitation is theoretically possible. The attack could, for example, be carried out through a crafted authoritative DNS server or recursive resolver.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46727"
    },
    {
      "rank": 32,
      "cve_id": "CVE-2026-33843",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00473,
      "epss_percentile": 0.39115,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft Entra",
      "cwe": "CWE-288",
      "title": "Microsoft Azure Active Directory B2C Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-33843"
    },
    {
      "rank": 33,
      "cve_id": "CVE-2026-46597",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00473,
      "epss_percentile": 0.39068,
      "kev": false,
      "kev_due_at": null,
      "vendor": "golang.org/x/crypto",
      "product": "golang.org/x/crypto/ssh",
      "cwe": "CWE-704",
      "title": "Invoking byte arithmetic causes underflow and panic in golang.org/x/crypto/ssh",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46597"
    },
    {
      "rank": 34,
      "cve_id": "CVE-2026-39829",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00467,
      "epss_percentile": 0.38671,
      "kev": false,
      "kev_due_at": null,
      "vendor": "golang.org/x/crypto",
      "product": "golang.org/x/crypto/ssh",
      "cwe": "CWE-1284",
      "title": "Invoking pathological RSA/DSA parameters may cause DoS in golang.org/x/crypto/ssh",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39829"
    },
    {
      "rank": 35,
      "cve_id": "CVE-2026-9011",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00464,
      "epss_percentile": 0.38478,
      "kev": false,
      "kev_due_at": null,
      "vendor": "metaphorcreations",
      "product": "Ditty – Responsive News Tickers, Sliders, and Lists",
      "cwe": "CWE-862",
      "title": "Ditty <= 3.1.65 - Missing Authorization to Unauthenticated Sensitive Information Disclosure via ditty_init AJAX Action",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9011"
    },
    {
      "rank": 36,
      "cve_id": "CVE-2026-40166",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0046,
      "epss_percentile": 0.38263,
      "kev": false,
      "kev_due_at": null,
      "vendor": "goauthentik",
      "product": "authentik",
      "cwe": "CWE-200",
      "title": "authentik: Non-admin user can retrieve confidential OAuth client_secret via /api/v3/oauth2/access_tokens/",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40166"
    },
    {
      "rank": 37,
      "cve_id": "CVE-2026-40598",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00447,
      "epss_percentile": 0.37403,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mantisbt",
      "product": "mantisbt",
      "cwe": "CWE-79",
      "title": "MantisBT has Potential Referer-Based Reflected HTML Injection / XSS in Tag Update Page",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40598"
    },
    {
      "rank": 38,
      "cve_id": "CVE-2026-35430",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00426,
      "epss_percentile": 0.35732,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Azure Privileged Identity Management (PIM)",
      "cwe": "CWE-639",
      "title": "Azure Privileged Identity Management (PIM) Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-35430"
    },
    {
      "rank": 39,
      "cve_id": "CVE-2026-36228",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00425,
      "epss_percentile": 0.35623,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-120",
      "title": "Buffer Overflow vulnerability in Easy Chat Server 3.1 allows a remote attacker to obtain sensitive information and execute arbitrary code via the chat message functionality",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-36228"
    },
    {
      "rank": 40,
      "cve_id": "CVE-2026-40596",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00424,
      "epss_percentile": 0.35571,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mantisbt",
      "product": "mantisbt",
      "cwe": "CWE-79",
      "title": "MantisBT is vulnerable to XSS and potential account takeover via user font family preference update",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40596"
    },
    {
      "rank": 41,
      "cve_id": "CVE-2026-41090",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0042,
      "epss_percentile": 0.35237,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Copilot for iOS",
      "cwe": "CWE-77",
      "title": "Microsoft Copilot Tampering Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41090"
    },
    {
      "rank": 42,
      "cve_id": "CVE-2026-39831",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0042,
      "epss_percentile": 0.35242,
      "kev": false,
      "kev_due_at": null,
      "vendor": "golang.org/x/crypto",
      "product": "golang.org/x/crypto/ssh",
      "cwe": "CWE-862",
      "title": "Invoking bypass of FIDO/U2F security keys physical interaction in golang.org/x/crypto/ssh",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39831"
    },
    {
      "rank": 43,
      "cve_id": "CVE-2026-40607",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00419,
      "epss_percentile": 0.35096,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mantisbt",
      "product": "mantisbt",
      "cwe": "CWE-79",
      "title": "MantisBT is Vulnerable to Stored XSS Through its Saved-Filter Owner Column",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40607"
    },
    {
      "rank": 44,
      "cve_id": "CVE-2026-39833",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00412,
      "epss_percentile": 0.34542,
      "kev": false,
      "kev_due_at": null,
      "vendor": "golang.org/x/crypto",
      "product": "golang.org/x/crypto/ssh/agent",
      "cwe": "CWE-862",
      "title": "Invoking key constraints not enforced in golang.org/x/crypto/ssh/agent",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39833"
    },
    {
      "rank": 45,
      "cve_id": "CVE-2026-46598",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00412,
      "epss_percentile": 0.34554,
      "kev": false,
      "kev_due_at": null,
      "vendor": "golang.org/x/crypto",
      "product": "golang.org/x/crypto/ssh/agent",
      "cwe": "CWE-129",
      "title": "Invoking pathological inputs can lead to client panic in golang.org/x/crypto/ssh/agent",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46598"
    },
    {
      "rank": 46,
      "cve_id": "CVE-2026-41149",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00401,
      "epss_percentile": 0.33448,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mermaid-js",
      "product": "mermaid",
      "cwe": "CWE-94",
      "title": "Mermaid: Improper sanitization of `classDef` in state diagrams leads to HTML injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41149"
    },
    {
      "rank": 47,
      "cve_id": "CVE-2026-3294",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00398,
      "epss_percentile": 0.33131,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TP-Link Systems Inc.",
      "product": "Archer RE650 v1",
      "cwe": "CWE-862",
      "title": "Authentication Logic Vulnerability on Multiple TP-Link Range Extenders",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-3294"
    },
    {
      "rank": 48,
      "cve_id": "CVE-2026-41076",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00392,
      "epss_percentile": 0.32484,
      "kev": false,
      "kev_due_at": null,
      "vendor": "bestpractical",
      "product": "rt",
      "cwe": "CWE-287",
      "title": "RT: LDAP authentication bypass via empty password",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41076"
    },
    {
      "rank": 49,
      "cve_id": "CVE-2026-9291",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0038,
      "epss_percentile": 0.31346,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AWS",
      "product": "Amazon Braket Python SDK",
      "cwe": "CWE-502",
      "title": "Insecure Deserialization in Amazon Braket SDK Job Results Processing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9291"
    },
    {
      "rank": 50,
      "cve_id": "CVE-2026-39828",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00369,
      "epss_percentile": 0.30113,
      "kev": false,
      "kev_due_at": null,
      "vendor": "golang.org/x/crypto",
      "product": "golang.org/x/crypto/ssh",
      "cwe": "CWE-281",
      "title": "Invoking bypass of certificate restrictions in golang.org/x/crypto/ssh",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39828"
    },
    {
      "rank": 51,
      "cve_id": "CVE-2026-41147",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00349,
      "epss_percentile": 0.28116,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nukeviet",
      "product": "nukeviet",
      "cwe": "CWE-79",
      "title": "NukeViet CMS: Stored Cross-Site Scripting (XSS) via insufficient server-side input sanitization in Request class",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41147"
    },
    {
      "rank": 52,
      "cve_id": "CVE-2026-33712",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00347,
      "epss_percentile": 0.27837,
      "kev": false,
      "kev_due_at": null,
      "vendor": "baptisteArno",
      "product": "typebot.io",
      "cwe": "CWE-862",
      "title": "TypeBot: Unauthenticated SSRF via isolated-vm fetch in preview chat endpoint bypasses SSRF controls",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-33712"
    },
    {
      "rank": 53,
      "cve_id": "CVE-2022-31231",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00346,
      "epss_percentile": 0.27746,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "ECS",
      "cwe": "CWE-284",
      "title": "Dell ECS, versions 3.5 and 3.6, contain an Improper Access Control in the Identity and Access Management (IAM) module. A remote unauthenticated attacker may potentially exploit this vulnerability, leading to gaining read access to unauthorized data.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2022-31231"
    },
    {
      "rank": 54,
      "cve_id": "CVE-2026-41075",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00344,
      "epss_percentile": 0.27563,
      "kev": false,
      "kev_due_at": null,
      "vendor": "bestpractical",
      "product": "rt",
      "cwe": "CWE-89",
      "title": "RT: SQL injection via entry_aggregator parameter in JSON search",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41075"
    },
    {
      "rank": 55,
      "cve_id": "CVE-2026-5740",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0034,
      "epss_percentile": 0.27138,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mattermost",
      "product": "Mattermost",
      "cwe": "CWE-789",
      "title": "Unauthenticated WebSocket binary frame causes denial of service in Mattermost Server",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-5740"
    },
    {
      "rank": 56,
      "cve_id": "CVE-2026-41148",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00338,
      "epss_percentile": 0.26843,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mermaid-js",
      "product": "mermaid",
      "cwe": "CWE-94",
      "title": "Mermaid: Improper sanitization of `classDefs` in diagrams leads to CSS injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41148"
    },
    {
      "rank": 57,
      "cve_id": "CVE-2026-25680",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00326,
      "epss_percentile": 0.25609,
      "kev": false,
      "kev_due_at": null,
      "vendor": "golang.org/x/net",
      "product": "golang.org/x/net/html",
      "cwe": "CWE-400",
      "title": "Invoking denial of service when parsing arbitrary HTML in golang.org/x/net/html",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-25680"
    },
    {
      "rank": 58,
      "cve_id": "CVE-2026-37470",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00324,
      "epss_percentile": 0.25283,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-1021",
      "title": "An issue in ClipBucket v5 v.5.5.2 allows an attacker to execute arbitrary code via the Authentication interface, login page endpoint and HTTP response security headers components",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-37470"
    },
    {
      "rank": 59,
      "cve_id": "CVE-2026-9047",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00319,
      "epss_percentile": 0.24719,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Devolutions",
      "product": "Server",
      "cwe": "CWE-305",
      "title": "Improper handling of factor key state in the multi-factor authentication management feature in Devolutions Server allows an attacker with knowledge of a user's password to bypass the user's multi-factor authentication after the user reconfigures their factors. This issue affects : * Devolutions Server 2026.1.6.0 through 2026.1.16.0",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9047"
    },
    {
      "rank": 60,
      "cve_id": "CVE-2026-28444",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00316,
      "epss_percentile": 0.24479,
      "kev": false,
      "kev_due_at": null,
      "vendor": "baptisteArno",
      "product": "typebot.io",
      "cwe": "CWE-639",
      "title": "Typebot: IDOR in Result Logs Endpoint Allows Cross-Workspace Data Disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28444"
    },
    {
      "rank": 61,
      "cve_id": "CVE-2026-44618",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00303,
      "epss_percentile": 0.23004,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache CXF",
      "cwe": "CWE-611",
      "title": "Apache CXF: XXE vulnerability in WS-Transfer functionality",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44618"
    },
    {
      "rank": 62,
      "cve_id": "CVE-2026-41071",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00302,
      "epss_percentile": 0.22812,
      "kev": false,
      "kev_due_at": null,
      "vendor": "strukturag",
      "product": "libheif",
      "cwe": "CWE-125",
      "title": "libheif: Heap buffer over-read in SampleAuxInfoReader via crafted HEIF sequence file with mismatched saiz sample count",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41071"
    },
    {
      "rank": 63,
      "cve_id": "CVE-2026-42901",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00301,
      "epss_percentile": 0.2274,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft Entra",
      "cwe": "CWE-346",
      "title": "Microsoft Entra ID Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42901"
    },
    {
      "rank": 64,
      "cve_id": "CVE-2026-5072",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.003,
      "epss_percentile": 0.22683,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zephyrproject-rtos",
      "product": "Zephyr",
      "cwe": "CWE-1335",
      "title": "ptp: Potential Denial of Service via PTP Interval Shift",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-5072"
    },
    {
      "rank": 65,
      "cve_id": "CVE-2026-32253",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00291,
      "epss_percentile": 0.21688,
      "kev": false,
      "kev_due_at": null,
      "vendor": "LizardByte",
      "product": "Sunshine",
      "cwe": "CWE-287",
      "title": "Sunshine: Authentication bypass via improper client certificate validation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-32253"
    },
    {
      "rank": 66,
      "cve_id": "CVE-2026-9054",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00291,
      "epss_percentile": 0.21731,
      "kev": false,
      "kev_due_at": null,
      "vendor": "9front",
      "product": "9front",
      "cwe": "CWE-130",
      "title": "Invalid IP packets cause a kernel panic",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9054"
    },
    {
      "rank": 67,
      "cve_id": "CVE-2026-40610",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00284,
      "epss_percentile": 0.20981,
      "kev": false,
      "kev_due_at": null,
      "vendor": "bentoml",
      "product": "BentoML",
      "cwe": "CWE-59",
      "title": "BentoML has Information Disclosure in `bentoml build` via symlink traversal in the build context",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40610"
    },
    {
      "rank": 68,
      "cve_id": "CVE-2026-39827",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00279,
      "epss_percentile": 0.20499,
      "kev": false,
      "kev_due_at": null,
      "vendor": "golang.org/x/crypto",
      "product": "golang.org/x/crypto/ssh",
      "cwe": "CWE-924",
      "title": "Invoking memory leak when rejecting channels can lead to DoS in golang.org/x/crypto/ssh",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39827"
    },
    {
      "rank": 69,
      "cve_id": "CVE-2026-8684",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00278,
      "epss_percentile": 0.2038,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jetmonsters",
      "product": "MotoPress Hotel Booking",
      "cwe": "CWE-862",
      "title": "MotoPress Hotel Booking <= 6.0.1 - Missing Authorization to Unauthenticated Arbitrary Booking Notes Modification via mphb_update_booking_notes AJAX Action",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8684"
    },
    {
      "rank": 70,
      "cve_id": "CVE-2026-39970",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00276,
      "epss_percentile": 0.20137,
      "kev": false,
      "kev_due_at": null,
      "vendor": "baptisteArno",
      "product": "typebot.io",
      "cwe": "CWE-79",
      "title": "TypeBot: Stored Cross-Site Scripting (XSS) via SVG File Upload On Profile Picture Form",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39970"
    },
    {
      "rank": 71,
      "cve_id": "CVE-2026-9053",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00276,
      "epss_percentile": 0.20124,
      "kev": false,
      "kev_due_at": null,
      "vendor": "9front",
      "product": "9front",
      "cwe": "CWE-434",
      "title": "Mothra would respect a default value given by a website for HTML file upload forms. An attacker could craft a website with a malicious default file path, and then conceal this form element.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9053"
    },
    {
      "rank": 72,
      "cve_id": "CVE-2026-4834",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00273,
      "epss_percentile": 0.19724,
      "kev": false,
      "kev_due_at": null,
      "vendor": "weDevs",
      "product": "WP ERP Pro",
      "cwe": "CWE-89",
      "title": "WP ERP Pro <= 1.5.1 - Unauthenticated SQL Injection via 'search_key' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-4834"
    },
    {
      "rank": 73,
      "cve_id": "CVE-2026-39968",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00271,
      "epss_percentile": 0.19385,
      "kev": false,
      "kev_due_at": null,
      "vendor": "baptisteArno",
      "product": "typebot.io",
      "cwe": "CWE-284",
      "title": "TypeBot: Cross-Workspace Credential Theft via Bot-Engine Preview Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39968"
    },
    {
      "rank": 74,
      "cve_id": "CVE-2026-6864",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00264,
      "epss_percentile": 0.18431,
      "kev": false,
      "kev_due_at": null,
      "vendor": "manchumahara",
      "product": "CBX 5 Star Rating & Review",
      "cwe": "CWE-79",
      "title": "CBX 5 Star Rating & Review <= 1.0.7 - Reflected Cross-Site Scripting via 'page' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6864"
    },
    {
      "rank": 75,
      "cve_id": "CVE-2026-28445",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00257,
      "epss_percentile": 0.17512,
      "kev": false,
      "kev_due_at": null,
      "vendor": "baptisteArno",
      "product": "typebot.io",
      "cwe": "CWE-79",
      "title": "Typebot: Stored XSS via Rating Block Custom Icon Bypasses isUnsafe Sandbox in Builder Preview",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28445"
    },
    {
      "rank": 76,
      "cve_id": "CVE-2026-39966",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00256,
      "epss_percentile": 0.17435,
      "kev": false,
      "kev_due_at": null,
      "vendor": "baptisteArno",
      "product": "typebot.io",
      "cwe": "CWE-863",
      "title": "TypeBot: Async filter() bypasses authorization, allowing IDOR in getLinkedTypebots and leaking cross-workspace bot definitions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39966"
    },
    {
      "rank": 77,
      "cve_id": "CVE-2026-36226",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00256,
      "epss_percentile": 0.17363,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-79",
      "title": "Cross Site Scripting vulnerability in Advantech WebAccess/SCADA 8.0-2015.08.16 allows a remote attacker to obtain sensitive information via the decryption field in the Create New Project User component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-36226"
    },
    {
      "rank": 78,
      "cve_id": "CVE-2026-5308",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00254,
      "epss_percentile": 0.1718,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mattermost",
      "product": "Mattermost",
      "cwe": "CWE-400",
      "title": "Missing request body size limits on Zoom plugin HTTP endpoints",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-5308"
    },
    {
      "rank": 79,
      "cve_id": "CVE-2026-41069",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00253,
      "epss_percentile": 0.16996,
      "kev": false,
      "kev_due_at": null,
      "vendor": "strukturag",
      "product": "libheif",
      "cwe": "CWE-125",
      "title": "libheif allows Out-of-bounds vector access leading to invalid dereference (DoS)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41069"
    },
    {
      "rank": 80,
      "cve_id": "CVE-2026-4646",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0025,
      "epss_percentile": 0.16681,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mattermost",
      "product": "Mattermost",
      "cwe": "CWE-1287",
      "title": "Insufficient input validation in GitHub plugin API causes denial of service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-4646"
    },
    {
      "rank": 81,
      "cve_id": "CVE-2026-7509",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00249,
      "epss_percentile": 0.16606,
      "kev": false,
      "kev_due_at": null,
      "vendor": "helgatheviking",
      "product": "KIA Subtitle",
      "cwe": "CWE-79",
      "title": "KIA Subtitle <= 4.0.1 - [Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')]",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7509"
    },
    {
      "rank": 82,
      "cve_id": "CVE-2026-3481",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00249,
      "epss_percentile": 0.16542,
      "kev": false,
      "kev_due_at": null,
      "vendor": "burlingtonbytes",
      "product": "WP Blockade – Visual Page Builder",
      "cwe": "CWE-79",
      "title": "WP Blockade <= 0.9.14 - Reflected Cross-Site Scripting via 'shortcode' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-3481"
    },
    {
      "rank": 83,
      "cve_id": "CVE-2026-8477",
      "cvss_base": 2.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00249,
      "epss_percentile": 0.16496,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Devolutions",
      "product": "Server",
      "cwe": "CWE-841",
      "title": "Improper enforcement of the sealed-entry workflow in the entry sensitive-data retrieval feature in Devolutions Server allows an authenticated user with access to a sealed entry to retrieve its sensitive data without triggering the unseal audit notification via a crafted API request. This issue affects : * Devolutions Server 2026.1.6.0 through 2026.1.16.0 * Devolutions Server 2025.3.20.0 and earlier",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8477"
    },
    {
      "rank": 84,
      "cve_id": "CVE-2026-7249",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00248,
      "epss_percentile": 0.16378,
      "kev": false,
      "kev_due_at": null,
      "vendor": "shapedplugin",
      "product": "Location Weather – WordPress Weather Forecast, AQI, Temperature and Weather Widget",
      "cwe": "CWE-862",
      "title": "Location Weather <= 3.0.2 - Missing Authorization to Authenticated (Contributor+) Block Settings Modification and Cache Purging",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7249"
    },
    {
      "rank": 85,
      "cve_id": "CVE-2022-34363",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00247,
      "epss_percentile": 0.16336,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "Unisphere for PowerMax",
      "cwe": "CWE-285",
      "title": "Dell Unisphere for PowerMax vApp version prior to 10.0.0.2, contains an authorization bypass vulnerability in the Unisphere for VMAX application running in vApp",
      "url": "https://www.cve.org/CVERecord?id=CVE-2022-34363"
    },
    {
      "rank": 86,
      "cve_id": "CVE-2026-7325",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00247,
      "epss_percentile": 0.16282,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Devolutions",
      "product": "Server",
      "cwe": "CWE-918",
      "title": "Improper authorization in the Active Directory browsing feature in Devolutions Server allows a low-privileged authenticated user to obtain authentication material associated with a stored PAM provider service account via authentication relay to an attacker-controlled server. This issue affects : * Devolutions Server 2026.1.6.0 through 2026.1.16.0 * Devolutions Server 2025.3.20.0 and earlier",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7325"
    },
    {
      "rank": 87,
      "cve_id": "CVE-2026-5755",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00245,
      "epss_percentile": 0.16065,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mattermost",
      "product": "Mattermost",
      "cwe": "CWE-400",
      "title": "Denial of service via crafted TIFF file upload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-5755"
    },
    {
      "rank": 88,
      "cve_id": "CVE-2026-40295",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00241,
      "epss_percentile": 0.15512,
      "kev": false,
      "kev_due_at": null,
      "vendor": "heartcombo",
      "product": "devise",
      "cwe": "CWE-601",
      "title": "Devise: Open Redirect via Unvalidated `request.referrer` in Timeoutable Session Timeout Handler",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40295"
    },
    {
      "rank": 89,
      "cve_id": "CVE-2026-39964",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00241,
      "epss_percentile": 0.15532,
      "kev": false,
      "kev_due_at": null,
      "vendor": "baptisteArno",
      "product": "typebot.io",
      "cwe": "CWE-79",
      "title": "TypeBot: Stored XSS via javascript: URI in text bubble links — bot author executes JS on visitors' browsers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39964"
    },
    {
      "rank": 90,
      "cve_id": "CVE-2026-39965",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00239,
      "epss_percentile": 0.15226,
      "kev": false,
      "kev_due_at": null,
      "vendor": "baptisteArno",
      "product": "typebot.io",
      "cwe": "CWE-918",
      "title": "TypeBot: SSRF via Open Redirect Bypass in HTTP Request and Code Blocks",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39965"
    },
    {
      "rank": 91,
      "cve_id": "CVE-2026-34207",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00239,
      "epss_percentile": 0.15194,
      "kev": false,
      "kev_due_at": null,
      "vendor": "baptisteArno",
      "product": "typebot.io",
      "cwe": "CWE-20",
      "title": "TypeBot: SSRF Protection Bypass via DNS-Resolved Hostnames in Webhook / HTTP Request Validation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34207"
    },
    {
      "rank": 92,
      "cve_id": "CVE-2026-7636",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00236,
      "epss_percentile": 0.14864,
      "kev": false,
      "kev_due_at": null,
      "vendor": "smub",
      "product": "Slider by Soliloquy – Responsive Image Slider for WordPress",
      "cwe": "CWE-200",
      "title": "Slider by Soliloquy <= 2.8.1 - Authenticated (Subscriber+) Information Disclosure via REST API Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7636"
    },
    {
      "rank": 93,
      "cve_id": "CVE-2026-42506",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00235,
      "epss_percentile": 0.14785,
      "kev": false,
      "kev_due_at": null,
      "vendor": "golang.org/x/net",
      "product": "golang.org/x/net/html",
      "cwe": "CWE-79",
      "title": "Invoking incorrect handling of namespaced elements in foreign content in golang.org/x/net/html",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42506"
    },
    {
      "rank": 94,
      "cve_id": "CVE-2026-5171",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00234,
      "epss_percentile": 0.14586,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Devolutions",
      "product": "Server",
      "cwe": "CWE-284",
      "title": "Improper access control in the entry activity log feature in Devolutions Server allows an authenticated user with access to an entry but without the required permission to retrieve that entry's activity logs via a crafted API request. This issue affects : * Devolutions Server 2026.1.6.0 through 2026.1.16.0 * Devolutions Server 2025.3.20.0 and earlier",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-5171"
    },
    {
      "rank": 95,
      "cve_id": "CVE-2026-9264",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00231,
      "epss_percentile": 0.14261,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Trimble",
      "product": "SketchUp",
      "cwe": "CWE-94",
      "title": "Cross-Site Scripting in SketchUp Dynamic Components",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9264"
    },
    {
      "rank": 96,
      "cve_id": "CVE-2026-9245",
      "cvss_base": 5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0023,
      "epss_percentile": 0.14073,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Devolutions",
      "product": "Server",
      "cwe": "CWE-601",
      "title": "Improper input validation in the external authentication provider flow in Devolutions Server allows an unauthenticated remote attacker to redirect victims to an attacker-controlled domain via a crafted login link. This issue affects : * Devolutions Server 2026.1.6.0 through 2026.1.16.0 * Devolutions Server 2025.3.20.0 and earlier",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9245"
    },
    {
      "rank": 97,
      "cve_id": "CVE-2026-2518",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0023,
      "epss_percentile": 0.14139,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wpxpo",
      "product": "FastX",
      "cwe": "CWE-862",
      "title": "FastX <= 1.0.2 - Missing Authorization to Authenticated (Subscriber+) Limited Plugin Installation and Activation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-2518"
    },
    {
      "rank": 98,
      "cve_id": "CVE-2026-25606",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00225,
      "epss_percentile": 0.13372,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Centralny Instytut Ochrony Pracy - Państwowy Instytut Badawczy",
      "product": "STER",
      "cwe": "CWE-89",
      "title": "SQL Injection in STER",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-25606"
    },
    {
      "rank": 99,
      "cve_id": "CVE-2026-8692",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00225,
      "epss_percentile": 0.13508,
      "kev": false,
      "kev_due_at": null,
      "vendor": "registrationformbuilder",
      "product": "Vedrixa Forms – User Registration Form, Signup Form & Drag & Drop Form Builder",
      "cwe": "CWE-862",
      "title": "Vedrixa Forms <= 1.1.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Form Structure Modification via wefb_save_form_structure AJAX Action",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8692"
    },
    {
      "rank": 100,
      "cve_id": "CVE-2026-5817",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00224,
      "epss_percentile": 0.13363,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Docker",
      "product": "Docker Desktop",
      "cwe": "CWE-829",
      "title": "Docker Model Runner container-to-host code execution via unsandboxed trust_remote_code in Python inference backends",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-5817"
    },
    {
      "rank": 101,
      "cve_id": "CVE-2026-5843",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00224,
      "epss_percentile": 0.13363,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Docker",
      "product": "Docker Desktop",
      "cwe": "CWE-829",
      "title": "Docker Model Runner container-to-host code execution via MLX-LM model_file importlib loading",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-5843"
    },
    {
      "rank": 102,
      "cve_id": "CVE-2026-25681",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00223,
      "epss_percentile": 0.13207,
      "kev": false,
      "kev_due_at": null,
      "vendor": "golang.org/x/net",
      "product": "golang.org/x/net/html",
      "cwe": "CWE-1021",
      "title": "Invoking incorrect handling of character references in DOCTYPE nodes in golang.org/x/net/html",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-25681"
    },
    {
      "rank": 103,
      "cve_id": "CVE-2026-27136",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00223,
      "epss_percentile": 0.13206,
      "kev": false,
      "kev_due_at": null,
      "vendor": "golang.org/x/net",
      "product": "golang.org/x/net/html",
      "cwe": "CWE-1021",
      "title": "Invoking duplicate attributes can cause XSS in golang.org/x/net/html",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-27136"
    },
    {
      "rank": 104,
      "cve_id": "CVE-2026-42502",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00223,
      "epss_percentile": 0.13207,
      "kev": false,
      "kev_due_at": null,
      "vendor": "golang.org/x/net",
      "product": "golang.org/x/net/html",
      "cwe": "CWE-1021",
      "title": "Invoking incorrect handling of HTML elements in foreign content in golang.org/x/net/html",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42502"
    },
    {
      "rank": 105,
      "cve_id": "CVE-2026-9104",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0022,
      "epss_percentile": 0.12778,
      "kev": false,
      "kev_due_at": null,
      "vendor": "dartiss",
      "product": "Draft List",
      "cwe": "CWE-79",
      "title": "Draft List <= 2.6.3 - Authenticated (Author+) Stored Cross-Site Scripting via Draft Post Title",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9104"
    },
    {
      "rank": 106,
      "cve_id": "CVE-2026-9247",
      "cvss_base": 2.4,
      "cvss_severity": "LOW",
      "epss_score": 0.00219,
      "epss_percentile": 0.12663,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Devolutions",
      "product": "Server",
      "cwe": "CWE-778",
      "title": "Insufficient logging in the entry export feature in Devolutions Server allows an authenticated user with export permissions to export a sealed entry without triggering the unseal notification to administrators via a crafted export request. This issue affects : * Devolutions Server 2026.1.6.0 through 2026.1.16.0 * Devolutions Server 2025.3.20.0 and earlier",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9247"
    },
    {
      "rank": 107,
      "cve_id": "CVE-2026-8670",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00216,
      "epss_percentile": 0.12328,
      "kev": false,
      "kev_due_at": null,
      "vendor": "syslink software AG",
      "product": "Avantra",
      "cwe": "CWE-613",
      "title": "Insecure session handling on metrics web server",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8670"
    },
    {
      "rank": 108,
      "cve_id": "CVE-2026-8671",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00216,
      "epss_percentile": 0.12324,
      "kev": false,
      "kev_due_at": null,
      "vendor": "syslink software AG",
      "product": "Avantra",
      "cwe": "CWE-532",
      "title": "Log Files contain encrypted secrets",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8671"
    },
    {
      "rank": 109,
      "cve_id": "CVE-2026-44409",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00216,
      "epss_percentile": 0.12316,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ZTE",
      "product": "MU5250",
      "cwe": "CWE-862",
      "title": "Information disclosure vulnerability in ZTE MU5250",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44409"
    },
    {
      "rank": 110,
      "cve_id": "CVE-2026-9223",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00213,
      "epss_percentile": 0.11924,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Devolutions",
      "product": "Server",
      "cwe": "CWE-284",
      "title": "Missing authorization in the vault import feature in Devolutions Server 2026.1.16.0 and earlier allows a low-privileged authenticated user to create new vaults via a crafted import request.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9223"
    },
    {
      "rank": 111,
      "cve_id": "CVE-2026-9224",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00213,
      "epss_percentile": 0.11895,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Devolutions",
      "product": "Server",
      "cwe": "CWE-862",
      "title": "Missing authorization in the user profile update feature in Devolutions Server allows an authenticated Active Directory user to modify their own profile attributes via a crafted API request. This issue affects : * Devolutions Server 2026.1.6.0 through 2026.1.16.0 * Devolutions Server 2025.3.20.0 and earlier",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9224"
    },
    {
      "rank": 112,
      "cve_id": "CVE-2026-9246",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00213,
      "epss_percentile": 0.11896,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Devolutions",
      "product": "Server",
      "cwe": "CWE-862",
      "title": "Improper access control in the entry documentation and attachment features in Devolutions Server allows an authenticated user with vault read access to retrieve the documentation and attachments of sealed entries via a crafted API request. This issue affects : * Devolutions Server 2026.1.6.0 through 2026.1.16.0 * Devolutions Server 2025.3.20.0 and earlier",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9246"
    },
    {
      "rank": 113,
      "cve_id": "CVE-2026-6406",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00211,
      "epss_percentile": 0.11608,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Docker",
      "product": "Docker Desktop",
      "cwe": "CWE-863",
      "title": "Docker Desktop Enhanced Container Isolation bypass via --use-api-socket CLI flag",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6406"
    },
    {
      "rank": 114,
      "cve_id": "CVE-2026-25608",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00208,
      "epss_percentile": 0.11265,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Centralny Instytut Ochrony Pracy - Państwowy Instytut Badawczy",
      "product": "STER",
      "cwe": "CWE-319",
      "title": "Lack of traffic encryption in STER",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-25608"
    },
    {
      "rank": 115,
      "cve_id": "CVE-2026-9251",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00194,
      "epss_percentile": 0.09439,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Devolutions",
      "product": "Server",
      "cwe": "CWE-862",
      "title": "Missing authorization in the entry status management feature in Devolutions Server allows a non-administrator authenticated user to bypass the administrator-enforced Pending Approval flow and gain access to an entry's data via a crafted status change request. This issue affects : * Devolutions Server 2026.1.6.0 through 2026.1.16.0 * Devolutions Server 2025.3.20.0 and earlier",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9251"
    },
    {
      "rank": 116,
      "cve_id": "CVE-2026-8673",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00192,
      "epss_percentile": 0.09193,
      "kev": false,
      "kev_due_at": null,
      "vendor": "syslink software AG",
      "product": "Avantra",
      "cwe": "CWE-523",
      "title": "Password re-initialization mechanism sends passwords in plain text",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8673"
    },
    {
      "rank": 117,
      "cve_id": "CVE-2026-9249",
      "cvss_base": 3.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00186,
      "epss_percentile": 0.08552,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Devolutions",
      "product": "Server",
      "cwe": "CWE-620",
      "title": "Unverified password change in Devolutions Server allows an attacker to change a user's password without providing the previous one via a crafted password change request. This issue affects : * Devolutions Server 2026.1.6.0 through 2026.1.16.0 * Devolutions Server 2025.3.20.0 and earlier",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9249"
    },
    {
      "rank": 118,
      "cve_id": "CVE-2026-39967",
      "cvss_base": 3.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00186,
      "epss_percentile": 0.08506,
      "kev": false,
      "kev_due_at": null,
      "vendor": "baptisteArno",
      "product": "typebot.io",
      "cwe": "CWE-639",
      "title": "TypeBot: Cross-Typebot Result Data Access via Missing typebotId Filter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39967"
    },
    {
      "rank": 119,
      "cve_id": "CVE-2026-9248",
      "cvss_base": 2.6,
      "cvss_severity": "LOW",
      "epss_score": 0.00186,
      "epss_percentile": 0.0854,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Devolutions",
      "product": "Server",
      "cwe": "CWE-639",
      "title": "Authorization bypass in the entry duplication feature in Devolutions Server allows an authenticated user with write access to any vault to copy documentation and attachments from an entry in a vault they cannot access via a crafted save request. This issue affects : * Devolutions Server 2026.1.6.0 through 2026.1.16.0 * Devolutions Server 2025.3.20.0 and earlier",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9248"
    },
    {
      "rank": 120,
      "cve_id": "CVE-2026-3636",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00184,
      "epss_percentile": 0.08341,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mattermost",
      "product": "Mattermost",
      "cwe": "CWE-200",
      "title": "Sanitize team member data returned by API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-3636"
    },
    {
      "rank": 121,
      "cve_id": "CVE-2026-8347",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00175,
      "epss_percentile": 0.07301,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Concrete CMS",
      "product": "Concrete CMS",
      "cwe": "CWE-639",
      "title": "Concrete CMS 9.5.0 and below is vulnerable to IDOR + wrong-authorization-level in Express association Reorder dialog",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8347"
    },
    {
      "rank": 122,
      "cve_id": "CVE-2025-26483",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00173,
      "epss_percentile": 0.07029,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "PowerFlex Manager (Appliance)",
      "cwe": "CWE-601",
      "title": "Dell PowerFlex Manager, versions 4.6.2 and prior, contains an Open Redirect Vulnerability. An unauthenticated attacker could potentially exploit this vulnerability, leading to a targeted application user being redirected to arbitrary web URLs. The vulnerability could be leveraged by attackers to conduct phishing attacks that cause users to divulge sensitive information.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-26483"
    },
    {
      "rank": 123,
      "cve_id": "CVE-2026-4635",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00172,
      "epss_percentile": 0.06982,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mattermost",
      "product": "Mattermost",
      "cwe": "CWE-362",
      "title": "Persistent notification timing attack causing server denial of service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-4635"
    },
    {
      "rank": 124,
      "cve_id": "CVE-2026-7615",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00168,
      "epss_percentile": 0.06618,
      "kev": false,
      "kev_due_at": null,
      "vendor": "kasparsd",
      "product": "Widget Context",
      "cwe": "CWE-352",
      "title": "Widget Context <= 1.3.3 - Cross-Site Request Forgery to Settings Update via 'wl' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7615"
    },
    {
      "rank": 125,
      "cve_id": "CVE-2026-41073",
      "cvss_base": 4.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00166,
      "epss_percentile": 0.06291,
      "kev": false,
      "kev_due_at": null,
      "vendor": "bestpractical",
      "product": "rt",
      "cwe": "CWE-1236",
      "title": "RT: Spreadsheet downloads vulnerable to CSV/formula injection in Microsoft Excel and similar apps",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41073"
    },
    {
      "rank": 126,
      "cve_id": "CVE-2026-4070",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00164,
      "epss_percentile": 0.0607,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pftool",
      "product": "Alfie – Feed Plugin",
      "cwe": "CWE-352",
      "title": "Alfie <= 1.2.1 - Cross-Site Request Forgery to Feed Deletion via 'delete' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-4070"
    },
    {
      "rank": 127,
      "cve_id": "CVE-2026-42626",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0016,
      "epss_percentile": 0.0568,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-400",
      "title": "HP ENVY 5000 series printers VERBASPP1N003.2237A.00 do not properly manage concurrent TCP connections to port 9100 (JetDirect/RAW printing). An unauthenticated remote attacker on the same network can establish a persistent connection to port 9100 and send keep-alive packets, causing the printer's session threads to remain locked in a waiting state. The firmware lacks connection timeouts and concurrent session limits, resulting in a persistent Denial of Service (DoS) that renders the printer unresponsive to all user commands and print jobs. Physical intervention (manual restart) is required to restore functionality, and the attack can be immediately re-initiated.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42626"
    },
    {
      "rank": 128,
      "cve_id": "CVE-2026-40864",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00159,
      "epss_percentile": 0.05563,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jupyterhub",
      "product": "jupyterhub",
      "cwe": "CWE-352",
      "title": "JupyterHub: Cross-origin form POSTs bypass XSRF",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40864"
    },
    {
      "rank": 129,
      "cve_id": "CVE-2026-3473",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00149,
      "epss_percentile": 0.04657,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mattermost",
      "product": "Mattermost",
      "cwe": "CWE-639",
      "title": "Improper file ownership validation in the Boards API allows unauthorised file access",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-3473"
    },
    {
      "rank": 130,
      "cve_id": "CVE-2026-8353",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00149,
      "epss_percentile": 0.04655,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Concrete CMS",
      "product": "Concrete CMS",
      "cwe": "CWE-79",
      "title": "Concrete CMS version 9.0 to 9.5.0 is vulnerable to Stored XSS via page name in atomik theme",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8353"
    },
    {
      "rank": 131,
      "cve_id": "CVE-2026-8381",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00141,
      "epss_percentile": 0.03898,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TeamViewer",
      "product": "DEX (On-premises)",
      "cwe": "CWE-862",
      "title": "Broken Access Control in TeamViewer DEX Platform (On Premises)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8381"
    },
    {
      "rank": 132,
      "cve_id": "CVE-2026-39969",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0014,
      "epss_percentile": 0.03889,
      "kev": false,
      "kev_due_at": null,
      "vendor": "baptisteArno",
      "product": "typebot.io",
      "cwe": "CWE-287",
      "title": "TypeBot: WhatsApp Webhook Endpoint Missing Signature Verification",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39969"
    },
    {
      "rank": 133,
      "cve_id": "CVE-2026-8997",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0014,
      "epss_percentile": 0.03887,
      "kev": false,
      "kev_due_at": null,
      "vendor": "vifm",
      "product": "vifm",
      "cwe": "CWE-122",
      "title": "Heap Buffer Overflow in vifm",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8997"
    },
    {
      "rank": 134,
      "cve_id": "CVE-2026-28735",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00138,
      "epss_percentile": 0.03652,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mattermost",
      "product": "Mattermost",
      "cwe": "CWE-863",
      "title": "GitHub OAuth Scope Validation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28735"
    },
    {
      "rank": 135,
      "cve_id": "CVE-2026-42627",
      "cvss_base": 6.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00132,
      "epss_percentile": 0.0321,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-190",
      "title": "In Arm ArmNN through 2026-03-27, an integer overflow in TensorShape::GetNumElements() in armnn/Tensor.cpp allows a crafted TFLite model file to bypass buffer size validation and trigger a heap-based buffer over-read during model optimization. The overflow occurs when multiplying tensor dimensions using 32-bit unsigned arithmetic without overflow detection, causing GetNumBytes() to return an understated allocation size. During Optimize()->InferOutputShapes(), the BatchToSpaceNdLayer reads beyond the allocated buffer.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42627"
    },
    {
      "rank": 136,
      "cve_id": "CVE-2025-32749",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00127,
      "epss_percentile": 0.02837,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "PowerFlex Manager (Appliance)",
      "cwe": "CWE-276",
      "title": "Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Exposure of Information Through Directory Listing vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information exposure.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-32749"
    },
    {
      "rank": 137,
      "cve_id": "CVE-2026-9255",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00119,
      "epss_percentile": 0.02097,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AWS",
      "product": "Kiro CLI",
      "cwe": "CWE-862",
      "title": "Tool Execution Without Authorization via Piped Stdin in Kiro CLI",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9255"
    },
    {
      "rank": 138,
      "cve_id": "CVE-2026-41074",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00117,
      "epss_percentile": 0.01927,
      "kev": false,
      "kev_due_at": null,
      "vendor": "bestpractical",
      "product": "rt",
      "cwe": "CWE-352",
      "title": "RT has broken CSRF protection for authenticated users",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41074"
    },
    {
      "rank": 139,
      "cve_id": "CVE-2021-21508",
      "cvss_base": 6.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00117,
      "epss_percentile": 0.01918,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "VxRail",
      "cwe": "CWE-532",
      "title": "Dell VxRail versions before 7.0.200 contain a Plain-text Password Storage Vulnerability in VxRail Manager. A sys-admin user may exploit this vulnerability, leading to the disclosure of certain user credentials. The attacker may be able to use the exposed credentials to access the vulnerable application with privileges of the compromised account.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2021-21508"
    },
    {
      "rank": 140,
      "cve_id": "CVE-2026-39824",
      "cvss_base": 3.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00114,
      "epss_percentile": 0.01725,
      "kev": false,
      "kev_due_at": null,
      "vendor": "golang.org/x/sys",
      "product": "golang.org/x/sys/windows",
      "cwe": "CWE-190",
      "title": "Invoking integer overflow in NewNTUnicodeString in golang.org/x/sys/windows",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39824"
    },
    {
      "rank": 141,
      "cve_id": "CVE-2026-8672",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00105,
      "epss_percentile": 0.01206,
      "kev": false,
      "kev_due_at": null,
      "vendor": "syslink software AG",
      "product": "Avantra",
      "cwe": "CWE-1393",
      "title": "Default credentials for internal DB",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8672"
    },
    {
      "rank": 142,
      "cve_id": "CVE-2025-32746",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00103,
      "epss_percentile": 0.01139,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "PowerFlex Manager (Appliance)",
      "cwe": "CWE-922",
      "title": "Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Insecure Storage of Sensitive Information vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability, leading to unauthorized access to sensitive information.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-32746"
    },
    {
      "rank": 143,
      "cve_id": "CVE-2026-8340",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00103,
      "epss_percentile": 0.01109,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Concrete CMS",
      "product": "Concrete CMS",
      "cwe": "CWE-352",
      "title": "Concrete CMS 9.5.0 and below is vulnerable to CSRF via Backend\\File::approveVersion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8340"
    },
    {
      "rank": 144,
      "cve_id": "CVE-2025-32751",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00102,
      "epss_percentile": 0.0108,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "PowerFlex Manager (Appliance)",
      "cwe": "CWE-922",
      "title": "Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Insecure Storage of Sensitive Information vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to unauthorized access to sensitive information.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-32751"
    },
    {
      "rank": 145,
      "cve_id": "CVE-2026-25607",
      "cvss_base": 5.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00096,
      "epss_percentile": 0.00805,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Centralny Instytut Ochrony Pracy - Państwowy Instytut Badawczy",
      "product": "STER",
      "cwe": "CWE-261",
      "title": "Weak password encoding in STER",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-25607"
    },
    {
      "rank": 146,
      "cve_id": "CVE-2025-32747",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0009,
      "epss_percentile": 0.00532,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "PowerFlex Manager (Appliance)",
      "cwe": "CWE-266",
      "title": "Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Incorrect Privilege Assignment vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-32747"
    },
    {
      "rank": 147,
      "cve_id": "CVE-2025-32745",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00083,
      "epss_percentile": 0.00301,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "PowerFlex Manager (Appliance)",
      "cwe": "CWE-295",
      "title": "Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Improper Certificate Validation vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Information tampering.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-32745"
    },
    {
      "rank": 148,
      "cve_id": "CVE-2025-46371",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00067,
      "epss_percentile": 0.00028,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "PowerFlex Manager (Appliance)",
      "cwe": "CWE-327",
      "title": "Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) a Use of a Broken or Risky Cryptographic Algorithm vulnerability in the ssh. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Protection mechanism bypass.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-46371"
    }
  ],
  "transactions": [
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-32253",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-32253 (LizardByte Sunshine). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-40610",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-40610 (BentoML). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-41069",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-41069 (strukturag libheif). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-41071",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-41071 (strukturag libheif). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-5072",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-5072 (zephyrproject-rtos Zephyr). Public exploit reference added."
    }
  ],
  "attribution": "CVE Program, NVD (NIST), CISA KEV, FIRST EPSS, OSV. See /security/methodology/."
}
