{
  "day": "2026-05-23",
  "boundary": "UTC calendar day",
  "published_count": 41,
  "by_severity": {
    "CRITICAL": 2,
    "HIGH": 23,
    "MEDIUM": 3,
    "LOW": 13
  },
  "kev_count": 0,
  "exploit_reference_count": 1,
  "awaiting_enrichment_count": 0,
  "ranking": "Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.",
  "results": [
    {
      "rank": 1,
      "cve_id": "CVE-2026-46300",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.07006,
      "epss_percentile": 0.93633,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-787",
      "title": "net: skbuff: preserve shared-frag marker during coalescing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46300"
    },
    {
      "rank": 2,
      "cve_id": "CVE-2018-25357",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.01701,
      "epss_percentile": 0.75363,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dolibarr",
      "product": "Dolibarr ERP CRM",
      "cwe": "CWE-94",
      "title": "Dolibarr ERP CRM 7.0.3 Remote Code Execution via install/step1.php",
      "url": "https://www.cve.org/CVERecord?id=CVE-2018-25357"
    },
    {
      "rank": 3,
      "cve_id": "CVE-2026-9343",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.01519,
      "epss_percentile": 0.72532,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Edimax",
      "product": "EW-7438RPn",
      "cwe": "CWE-77",
      "title": "Edimax EW-7438RPn webs formWpsStart os command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9343"
    },
    {
      "rank": 4,
      "cve_id": "CVE-2026-9297",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.01398,
      "epss_percentile": 0.70262,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Edimax",
      "product": "BR-6428NS",
      "cwe": "CWE-74",
      "title": "Edimax BR-6428NS POST Request formWlbasic command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9297"
    },
    {
      "rank": 5,
      "cve_id": "CVE-2026-9296",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.01158,
      "epss_percentile": 0.64551,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Edimax",
      "product": "BR-6428NS",
      "cwe": "CWE-74",
      "title": "Edimax BR-6428NS POST Request formWlanM system command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9296"
    },
    {
      "rank": 6,
      "cve_id": "CVE-2018-25358",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00585,
      "epss_percentile": 0.45419,
      "kev": false,
      "kev_due_at": null,
      "vendor": "D-Link",
      "product": "DIR-601",
      "cwe": "CWE-497",
      "title": "D-Link DIR601 2.02NA Credential Disclosure via my_cgi.cgi",
      "url": "https://www.cve.org/CVERecord?id=CVE-2018-25358"
    },
    {
      "rank": 7,
      "cve_id": "CVE-2026-9294",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00542,
      "epss_percentile": 0.43241,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Edimax",
      "product": "BR-6428NS",
      "cwe": "CWE-119",
      "title": "Edimax BR-6428NS POST Request formWanTcpipSetup buffer overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9294"
    },
    {
      "rank": 8,
      "cve_id": "CVE-2026-9295",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00542,
      "epss_percentile": 0.4324,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Edimax",
      "product": "BR-6428NS",
      "cwe": "CWE-119",
      "title": "Edimax BR-6428NS POST Request formWirelessTbl buffer overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9295"
    },
    {
      "rank": 9,
      "cve_id": "CVE-2018-25353",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00452,
      "epss_percentile": 0.37726,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Redaxo",
      "product": "Redaxo CMS Mediapool",
      "cwe": "CWE-863",
      "title": "Redaxo CMS Mediapool Addon 5.5.1 Arbitrary File Upload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2018-25353"
    },
    {
      "rank": 10,
      "cve_id": "CVE-2018-25350",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00433,
      "epss_percentile": 0.36257,
      "kev": false,
      "kev_due_at": null,
      "vendor": "UserSpice",
      "product": "userSpice",
      "cwe": "CWE-204",
      "title": "userSpice 4.3.24 Username Enumeration via existingUsernameCheck.php",
      "url": "https://www.cve.org/CVERecord?id=CVE-2018-25350"
    },
    {
      "rank": 11,
      "cve_id": "CVE-2026-9284",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00401,
      "epss_percentile": 0.33451,
      "kev": false,
      "kev_due_at": null,
      "vendor": "woocommerce",
      "product": "WooCommerce PayPal Payments",
      "cwe": "CWE-862",
      "title": "WooCommerce PayPal Payments <= 4.0.1 - Missing Authorization to Unauthenticated Order Manipulation and Information Disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9284"
    },
    {
      "rank": 12,
      "cve_id": "CVE-2018-25348",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00358,
      "epss_percentile": 0.29076,
      "kev": false,
      "kev_due_at": null,
      "vendor": "harmistechnology",
      "product": "Ek Rishta",
      "cwe": "CWE-89",
      "title": "Joomla! Component Ek Rishta 2.10 SQL Injection via user_detail",
      "url": "https://www.cve.org/CVERecord?id=CVE-2018-25348"
    },
    {
      "rank": 13,
      "cve_id": "CVE-2018-25351",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00358,
      "epss_percentile": 0.29076,
      "kev": false,
      "kev_due_at": null,
      "vendor": "harmistechnology",
      "product": "EkRishta",
      "cwe": "CWE-89",
      "title": "Joomla! Component EkRishta 2.10 SQL Injection via username",
      "url": "https://www.cve.org/CVERecord?id=CVE-2018-25351"
    },
    {
      "rank": 14,
      "cve_id": "CVE-2026-43503",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00337,
      "epss_percentile": 0.26746,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-664",
      "title": "net: skbuff: propagate shared-frag marker through frag-transfer helpers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43503"
    },
    {
      "rank": 15,
      "cve_id": "CVE-2018-25340",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00334,
      "epss_percentile": 0.2642,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Behance",
      "product": "Smartshop",
      "cwe": "CWE-89",
      "title": "Smartshop 1 SQL Injection via category.php",
      "url": "https://www.cve.org/CVERecord?id=CVE-2018-25340"
    },
    {
      "rank": 16,
      "cve_id": "CVE-2018-25341",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00334,
      "epss_percentile": 0.2642,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Behance",
      "product": "Smartshop",
      "cwe": "CWE-89",
      "title": "Smartshop 1 SQL Injection via product.php id Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2018-25341"
    },
    {
      "rank": 17,
      "cve_id": "CVE-2018-25342",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00334,
      "epss_percentile": 0.2642,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Behance",
      "product": "Smartshop",
      "cwe": "CWE-89",
      "title": "Smartshop 1 SQL Injection via search.php",
      "url": "https://www.cve.org/CVERecord?id=CVE-2018-25342"
    },
    {
      "rank": 18,
      "cve_id": "CVE-2026-9306",
      "cvss_base": 2.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00291,
      "epss_percentile": 0.21735,
      "kev": false,
      "kev_due_at": null,
      "vendor": "QuantumNous",
      "product": "new-api",
      "cwe": "CWE-285",
      "title": "QuantumNous new-api Midjourney Image Relay Endpoint relay-router.go GetByOnlyMJId authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9306"
    },
    {
      "rank": 19,
      "cve_id": "CVE-2026-6419",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00258,
      "epss_percentile": 0.17636,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Wishlist Member",
      "product": "Wishlist Member",
      "cwe": "CWE-269",
      "title": "Wishlist Member <= 3.30.1 - Missing Authorization to Authenticated (Subscriber+) API Secret Key Disclosure and Privilege Escalation via 'wlm3_get_screen' AJAX action",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6419"
    },
    {
      "rank": 20,
      "cve_id": "CVE-2026-6895",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00248,
      "epss_percentile": 0.16403,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Wishlist Member",
      "product": "Wishlist Member",
      "cwe": "CWE-269",
      "title": "Wishlist Member <= 3.30.1 - Missing Authorization to Authenticated (Subscriber+) API Secret Key Disclosure and Privilege Escalation via 'wlm3_export_settings' AJAX Action",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6895"
    },
    {
      "rank": 21,
      "cve_id": "CVE-2026-6897",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00244,
      "epss_percentile": 0.15858,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Wishlist Member",
      "product": "Wishlist Member",
      "cwe": "CWE-269",
      "title": "Wishlist Member <= 3.30.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Plugin Options Update via 'wishlistmember_team_accounts_save_settings' AJAX action",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6897"
    },
    {
      "rank": 22,
      "cve_id": "CVE-2026-6898",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00244,
      "epss_percentile": 0.15857,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Wishlist Member",
      "product": "Wishlist Member",
      "cwe": "CWE-269",
      "title": "WishList Member <= 3.30.1 - Missing Authorization to Authenticated (Subscriber+) Generate API Secret Key via 'wlm3_generate_api_key' AJAX action",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6898"
    },
    {
      "rank": 23,
      "cve_id": "CVE-2026-9302",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00237,
      "epss_percentile": 0.14954,
      "kev": false,
      "kev_due_at": null,
      "vendor": "546669204",
      "product": "vps-inventory-monitoring",
      "cwe": "CWE-74",
      "title": "546669204 vps-inventory-monitoring VpsTest Console VpsTest.php eval code injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9302"
    },
    {
      "rank": 24,
      "cve_id": "CVE-2026-9299",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00229,
      "epss_percentile": 0.13909,
      "kev": false,
      "kev_due_at": null,
      "vendor": "omec-project",
      "product": "amf",
      "cwe": "CWE-119",
      "title": "omec-project amf handler.go PDUSessionResourceModifyIndication memory corruption",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9299"
    },
    {
      "rank": 25,
      "cve_id": "CVE-2026-9300",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00229,
      "epss_percentile": 0.13909,
      "kev": false,
      "kev_due_at": null,
      "vendor": "omec-project",
      "product": "amf",
      "cwe": "CWE-119",
      "title": "omec-project amf NGSetupRequest memory corruption",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9300"
    },
    {
      "rank": 26,
      "cve_id": "CVE-2026-9301",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00229,
      "epss_percentile": 0.13909,
      "kev": false,
      "kev_due_at": null,
      "vendor": "omec-project",
      "product": "amf",
      "cwe": "CWE-119",
      "title": "omec-project amf NGReset Message memory corruption",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9301"
    },
    {
      "rank": 27,
      "cve_id": "CVE-2026-9298",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00228,
      "epss_percentile": 0.13881,
      "kev": false,
      "kev_due_at": null,
      "vendor": "omec-project",
      "product": "amf",
      "cwe": "CWE-119",
      "title": "omec-project amf PathSwitchRequest memory corruption",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9298"
    },
    {
      "rank": 28,
      "cve_id": "CVE-2018-25347",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00214,
      "epss_percentile": 0.12011,
      "kev": false,
      "kev_due_at": null,
      "vendor": "web-dorado",
      "product": "Contact Form Maker",
      "cwe": "CWE-89",
      "title": "WordPress Contact Form Maker Plugin 1.12.20 SQL Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2018-25347"
    },
    {
      "rank": 29,
      "cve_id": "CVE-2018-25352",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00214,
      "epss_percentile": 0.12012,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ultimate-form-builder-lite",
      "product": "Ultimate Form Builder Lite",
      "cwe": "CWE-89",
      "title": "WordPress Ultimate Form Builder Lite 1.3.7 SQL Injection via entry_id",
      "url": "https://www.cve.org/CVERecord?id=CVE-2018-25352"
    },
    {
      "rank": 30,
      "cve_id": "CVE-2026-9304",
      "cvss_base": 1.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00199,
      "epss_percentile": 0.10039,
      "kev": false,
      "kev_due_at": null,
      "vendor": "calcom",
      "product": "cal.diy",
      "cwe": "CWE-918",
      "title": "calcom cal.diy Logo API route.ts validateUrlForSSRF server-side request forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9304"
    },
    {
      "rank": 31,
      "cve_id": "CVE-2018-25346",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00197,
      "epss_percentile": 0.09804,
      "kev": false,
      "kev_due_at": null,
      "vendor": "10Web",
      "product": "Form Maker",
      "cwe": "CWE-89",
      "title": "WordPress Form Maker Plugin 1.12.24 SQL Injection via admin-ajax.php",
      "url": "https://www.cve.org/CVERecord?id=CVE-2018-25346"
    },
    {
      "rank": 32,
      "cve_id": "CVE-2026-9303",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00194,
      "epss_percentile": 0.09429,
      "kev": false,
      "kev_due_at": null,
      "vendor": "calcom",
      "product": "cal.diy",
      "cwe": "CWE-352",
      "title": "calcom cal.diy cross-site request forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9303"
    },
    {
      "rank": 33,
      "cve_id": "CVE-2026-9305",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00192,
      "epss_percentile": 0.09275,
      "kev": false,
      "kev_due_at": null,
      "vendor": "QuantumNous",
      "product": "new-api",
      "cwe": "CWE-74",
      "title": "QuantumNous new-api self Endpoint topup.go SearchAllTopUps sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9305"
    },
    {
      "rank": 34,
      "cve_id": "CVE-2026-9342",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00192,
      "epss_percentile": 0.09269,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "Hospitals Patient Records Management System",
      "cwe": "CWE-74",
      "title": "SourceCodester Hospitals Patient Records Management System view_history.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9342"
    },
    {
      "rank": 35,
      "cve_id": "CVE-2018-25345",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00166,
      "epss_percentile": 0.06334,
      "kev": false,
      "kev_due_at": null,
      "vendor": "10-Strike",
      "product": "Network Scanner",
      "cwe": "CWE-120",
      "title": "10-Strike Network Scanner 3.0 Local Buffer Overflow SEH",
      "url": "https://www.cve.org/CVERecord?id=CVE-2018-25345"
    },
    {
      "rank": 36,
      "cve_id": "CVE-2018-25344",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00162,
      "epss_percentile": 0.05931,
      "kev": false,
      "kev_due_at": null,
      "vendor": "10-Strike",
      "product": "Network Inventory Explorer",
      "cwe": "CWE-121",
      "title": "10-Strike Network Inventory Explorer 8.54 Buffer Overflow SEH",
      "url": "https://www.cve.org/CVERecord?id=CVE-2018-25344"
    },
    {
      "rank": 37,
      "cve_id": "CVE-2018-25355",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00162,
      "epss_percentile": 0.05931,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Audiograbber",
      "product": "Audiograbber",
      "cwe": "CWE-120",
      "title": "Audiograbber 1.83 Local Buffer Overflow via SEH",
      "url": "https://www.cve.org/CVERecord?id=CVE-2018-25355"
    },
    {
      "rank": 38,
      "cve_id": "CVE-2018-25356",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00162,
      "epss_percentile": 0.05914,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Sipp",
      "product": "SIPp",
      "cwe": "CWE-120",
      "title": "SIPp 3.6 Local Buffer Overflow via Command-line Arguments",
      "url": "https://www.cve.org/CVERecord?id=CVE-2018-25356"
    },
    {
      "rank": 39,
      "cve_id": "CVE-2018-25349",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00155,
      "epss_percentile": 0.05143,
      "kev": false,
      "kev_due_at": null,
      "vendor": "UserSpice",
      "product": "userSpice",
      "cwe": "CWE-79",
      "title": "userSpice 4.3.24 Cross-Site Scripting via X-Forwarded-For Header",
      "url": "https://www.cve.org/CVERecord?id=CVE-2018-25349"
    },
    {
      "rank": 40,
      "cve_id": "CVE-2018-25343",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00132,
      "epss_percentile": 0.03217,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Behance",
      "product": "Smartshop",
      "cwe": "CWE-352",
      "title": "Smartshop 1 Cross-Site Request Forgery via editprofile.php",
      "url": "https://www.cve.org/CVERecord?id=CVE-2018-25343"
    },
    {
      "rank": 41,
      "cve_id": "CVE-2018-25354",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00132,
      "epss_percentile": 0.03217,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jomres",
      "product": "Jomres",
      "cwe": "CWE-352",
      "title": "Joomla Component jomres 9.11.2 Cross-Site Request Forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2018-25354"
    }
  ],
  "transactions": [],
  "attribution": "CVE Program, NVD (NIST), CISA KEV, FIRST EPSS, OSV. See /security/methodology/."
}
