{
  "day": "2026-05-25",
  "boundary": "UTC calendar day",
  "published_count": 187,
  "by_severity": {
    "CRITICAL": 5,
    "HIGH": 72,
    "MEDIUM": 56,
    "LOW": 53
  },
  "kev_count": 0,
  "exploit_reference_count": 11,
  "awaiting_enrichment_count": 1,
  "ranking": "Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.",
  "results": [
    {
      "rank": 1,
      "cve_id": "CVE-2026-9514",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.10811,
      "epss_percentile": 0.95486,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Totolink",
      "product": "CA750-PoE",
      "cwe": "CWE-77",
      "title": "Totolink CA750-PoE Setting cstecgi.cgi setNetworkDiag os command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9514"
    },
    {
      "rank": 2,
      "cve_id": "CVE-2026-9515",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.10811,
      "epss_percentile": 0.95485,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Totolink",
      "product": "CA750-PoE",
      "cwe": "CWE-77",
      "title": "Totolink CA750-PoE Setting cstecgi.cgi setUnloadUserData os command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9515"
    },
    {
      "rank": 3,
      "cve_id": "CVE-2026-9457",
      "cvss_base": 8.9,
      "cvss_severity": "HIGH",
      "epss_score": 0.02094,
      "epss_percentile": 0.80152,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Totolink",
      "product": "A8000RU",
      "cwe": "CWE-77",
      "title": "Totolink A8000RU Web Management cstecgi.cgi UploadFirmwareFile os command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9457"
    },
    {
      "rank": 4,
      "cve_id": "CVE-2026-9458",
      "cvss_base": 8.9,
      "cvss_severity": "HIGH",
      "epss_score": 0.02094,
      "epss_percentile": 0.80153,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Totolink",
      "product": "A8000RU",
      "cwe": "CWE-77",
      "title": "Totolink A8000RU Web Management cstecgi.cgi setWanCfg os command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9458"
    },
    {
      "rank": 5,
      "cve_id": "CVE-2026-9423",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": 0.02077,
      "epss_percentile": 0.79967,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Edimax",
      "product": "BR-6675nD",
      "cwe": "CWE-74",
      "title": "Edimax BR-6675nD POST Request mp command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9423"
    },
    {
      "rank": 6,
      "cve_id": "CVE-2026-9436",
      "cvss_base": 8.9,
      "cvss_severity": "HIGH",
      "epss_score": 0.02005,
      "epss_percentile": 0.79235,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Totolink",
      "product": "A8000RU",
      "cwe": "CWE-77",
      "title": "Totolink A8000RU Web Management cstecgi.cgi setL2tpServerCfg os command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9436"
    },
    {
      "rank": 7,
      "cve_id": "CVE-2026-9435",
      "cvss_base": 8.9,
      "cvss_severity": "HIGH",
      "epss_score": 0.01909,
      "epss_percentile": 0.78131,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Totolink",
      "product": "A8000RU",
      "cwe": "CWE-77",
      "title": "Totolink A8000RU Web Management cstecgi.cgi setQosCfg os command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9435"
    },
    {
      "rank": 8,
      "cve_id": "CVE-2026-9454",
      "cvss_base": 8.9,
      "cvss_severity": "HIGH",
      "epss_score": 0.01909,
      "epss_percentile": 0.7813,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Totolink",
      "product": "A8000RU",
      "cwe": "CWE-77",
      "title": "Totolink A8000RU Web Management cstecgi.cgi setOpenVpnCertGenerationCfg os command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9454"
    },
    {
      "rank": 9,
      "cve_id": "CVE-2026-9455",
      "cvss_base": 8.9,
      "cvss_severity": "HIGH",
      "epss_score": 0.01909,
      "epss_percentile": 0.7813,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Totolink",
      "product": "A8000RU",
      "cwe": "CWE-77",
      "title": "Totolink A8000RU Web Management cstecgi.cgi UploadOpenVpnCert os command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9455"
    },
    {
      "rank": 10,
      "cve_id": "CVE-2026-9456",
      "cvss_base": 8.9,
      "cvss_severity": "HIGH",
      "epss_score": 0.01909,
      "epss_percentile": 0.7813,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Totolink",
      "product": "A8000RU",
      "cwe": "CWE-77",
      "title": "Totolink A8000RU Web Management cstecgi.cgi setOpenVpnCfg os command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9456"
    },
    {
      "rank": 11,
      "cve_id": "CVE-2026-9475",
      "cvss_base": 8.9,
      "cvss_severity": "HIGH",
      "epss_score": 0.01909,
      "epss_percentile": 0.78131,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Totolink",
      "product": "A8000RU",
      "cwe": "CWE-77",
      "title": "Totolink A8000RU Web Management cstecgi.cgi setIpQosRules os command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9475"
    },
    {
      "rank": 12,
      "cve_id": "CVE-2026-9476",
      "cvss_base": 8.9,
      "cvss_severity": "HIGH",
      "epss_score": 0.01909,
      "epss_percentile": 0.78131,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Totolink",
      "product": "A8000RU",
      "cwe": "CWE-77",
      "title": "Totolink A8000RU Web Management cstecgi.cgi setPasswordCfg os command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9476"
    },
    {
      "rank": 13,
      "cve_id": "CVE-2026-9477",
      "cvss_base": 8.9,
      "cvss_severity": "HIGH",
      "epss_score": 0.01909,
      "epss_percentile": 0.7813,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Totolink",
      "product": "A8000RU",
      "cwe": "CWE-77",
      "title": "Totolink A8000RU Web Management cstecgi.cgi setAccessDeviceCfg os command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9477"
    },
    {
      "rank": 14,
      "cve_id": "CVE-2026-9478",
      "cvss_base": 8.9,
      "cvss_severity": "HIGH",
      "epss_score": 0.01909,
      "epss_percentile": 0.78129,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Totolink",
      "product": "A8000RU",
      "cwe": "CWE-77",
      "title": "Totolink A8000RU Web Management cstecgi.cgi setParentalRules os command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9478"
    },
    {
      "rank": 15,
      "cve_id": "CVE-2026-9408",
      "cvss_base": 8.9,
      "cvss_severity": "HIGH",
      "epss_score": 0.01732,
      "epss_percentile": 0.75788,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Totolink",
      "product": "A8000RU",
      "cwe": "CWE-77",
      "title": "Totolink A8000RU Web Management cstecgi.cgi setStaticDhcpRules os command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9408"
    },
    {
      "rank": 16,
      "cve_id": "CVE-2026-9432",
      "cvss_base": 8.9,
      "cvss_severity": "HIGH",
      "epss_score": 0.01732,
      "epss_percentile": 0.75787,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Totolink",
      "product": "A8000RU",
      "cwe": "CWE-77",
      "title": "Totolink A8000RU Web Management cstecgi.cgi setWiFiAdvancedCfg os command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9432"
    },
    {
      "rank": 17,
      "cve_id": "CVE-2026-9433",
      "cvss_base": 8.9,
      "cvss_severity": "HIGH",
      "epss_score": 0.01732,
      "epss_percentile": 0.75787,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Totolink",
      "product": "A8000RU",
      "cwe": "CWE-77",
      "title": "Totolink A8000RU Web Management cstecgi.cgi setMacFilterRules os command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9433"
    },
    {
      "rank": 18,
      "cve_id": "CVE-2026-9434",
      "cvss_base": 8.9,
      "cvss_severity": "HIGH",
      "epss_score": 0.01732,
      "epss_percentile": 0.75787,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Totolink",
      "product": "A8000RU",
      "cwe": "CWE-77",
      "title": "Totolink A8000RU Web Management cstecgi.cgi setWiFiWpsCfg os command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9434"
    },
    {
      "rank": 19,
      "cve_id": "CVE-2026-9452",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.01385,
      "epss_percentile": 0.70013,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FoundDream",
      "product": "miniclawd",
      "cwe": "CWE-77",
      "title": "FoundDream miniclawd exec.ts ExecTool.execute os command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9452"
    },
    {
      "rank": 20,
      "cve_id": "CVE-2026-9453",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.01385,
      "epss_percentile": 0.70013,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FoundDream",
      "product": "miniclawd",
      "cwe": "CWE-74",
      "title": "FoundDream miniclawd SkillsLoader skills-loader.ts which command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9453"
    },
    {
      "rank": 21,
      "cve_id": "CVE-2026-9437",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.01364,
      "epss_percentile": 0.69583,
      "kev": false,
      "kev_due_at": null,
      "vendor": "DTStack",
      "product": "Taier",
      "cwe": "CWE-77",
      "title": "DTStack Taier REST API Runtime.exec os command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9437"
    },
    {
      "rank": 22,
      "cve_id": "CVE-2026-9440",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.01364,
      "epss_percentile": 0.69582,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Edimax",
      "product": "BR-6478AC",
      "cwe": "CWE-74",
      "title": "Edimax BR-6478AC POST Request formAccept command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9440"
    },
    {
      "rank": 23,
      "cve_id": "CVE-2026-9441",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.0135,
      "epss_percentile": 0.6927,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Edimax",
      "product": "BR-6478AC",
      "cwe": "CWE-74",
      "title": "Edimax BR-6478AC POST Request formiNICbasic command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9441"
    },
    {
      "rank": 24,
      "cve_id": "CVE-2026-9424",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.01158,
      "epss_percentile": 0.6455,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Edimax",
      "product": "EW-7438RPn",
      "cwe": "CWE-77",
      "title": "Edimax EW-7438RPn Content-Type formWlanMP os command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9424"
    },
    {
      "rank": 25,
      "cve_id": "CVE-2026-9439",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.01158,
      "epss_percentile": 0.64553,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Edimax",
      "product": "BR-6675nD",
      "cwe": "CWE-74",
      "title": "Edimax BR-6675nD stainfo command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9439"
    },
    {
      "rank": 26,
      "cve_id": "CVE-2026-9511",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.01057,
      "epss_percentile": 0.61797,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Totolink",
      "product": "CA750-PoE",
      "cwe": "CWE-77",
      "title": "Totolink CA750-PoE Setting cstecgi.cgi setWebWlanIdx os command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9511"
    },
    {
      "rank": 27,
      "cve_id": "CVE-2026-9512",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.01057,
      "epss_percentile": 0.61797,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Totolink",
      "product": "CA750-PoE",
      "cwe": "CWE-77",
      "title": "Totolink CA750-PoE Setting cstecgi.cgi setPasswordCfg os command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9512"
    },
    {
      "rank": 28,
      "cve_id": "CVE-2026-9513",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.01057,
      "epss_percentile": 0.61796,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Totolink",
      "product": "CA750-PoE",
      "cwe": "CWE-77",
      "title": "Totolink CA750-PoE Setting cstecgi.cgi NTPSyncWithHost os command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9513"
    },
    {
      "rank": 29,
      "cve_id": "CVE-2026-47073",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00853,
      "epss_percentile": 0.55444,
      "kev": false,
      "kev_due_at": null,
      "vendor": "benoitc",
      "product": "hackney",
      "cwe": "CWE-400",
      "title": "Unbounded memory consumption in WebSocket client in hackney",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47073"
    },
    {
      "rank": 30,
      "cve_id": "CVE-2018-25365",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00785,
      "epss_percentile": 0.53254,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PCViewer",
      "product": "PCViewer",
      "cwe": "CWE-22",
      "title": "PCViewer vt1000 Directory Traversal via GET Request",
      "url": "https://www.cve.org/CVERecord?id=CVE-2018-25365"
    },
    {
      "rank": 31,
      "cve_id": "CVE-2018-25374",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00785,
      "epss_percentile": 0.53254,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Softneta",
      "product": "MedDream PACS Server Premium",
      "cwe": "CWE-22",
      "title": "Softneta MedDream PACS Server Premium 6.7.1.1 Directory Traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2018-25374"
    },
    {
      "rank": 32,
      "cve_id": "CVE-2026-48842",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00764,
      "epss_percentile": 0.52603,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Roundcube",
      "product": "Webmail",
      "cwe": "CWE-89",
      "title": "Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has Pre-authentication SQL injection in the virtuser_query plugin via a preg_replace() backslash escape bypass.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48842"
    },
    {
      "rank": 33,
      "cve_id": "CVE-2026-47066",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00753,
      "epss_percentile": 0.52232,
      "kev": false,
      "kev_due_at": null,
      "vendor": "benoitc",
      "product": "hackney",
      "cwe": "CWE-835",
      "title": "Infinite loop in Alt-Svc header parser in hackney",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47066"
    },
    {
      "rank": 34,
      "cve_id": "CVE-2026-47067",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00753,
      "epss_percentile": 0.52231,
      "kev": false,
      "kev_due_at": null,
      "vendor": "benoitc",
      "product": "hackney",
      "cwe": "CWE-770",
      "title": "Atom table exhaustion via unrecognized URL schemes in hackney",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47067"
    },
    {
      "rank": 35,
      "cve_id": "CVE-2026-47071",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00753,
      "epss_percentile": 0.52231,
      "kev": false,
      "kev_due_at": null,
      "vendor": "benoitc",
      "product": "hackney",
      "cwe": "CWE-400",
      "title": "SOCKS5 TLS upgrade ignores caller timeout in hackney",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47071"
    },
    {
      "rank": 36,
      "cve_id": "CVE-2026-9459",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00751,
      "epss_percentile": 0.52151,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Edimax",
      "product": "EW-7438RPn",
      "cwe": "CWE-119",
      "title": "Edimax EW-7438RPn formConnectionSetting stack-based overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9459"
    },
    {
      "rank": 37,
      "cve_id": "CVE-2026-9460",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00751,
      "epss_percentile": 0.5215,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Edimax",
      "product": "EW-7438RPn",
      "cwe": "CWE-119",
      "title": "Edimax EW-7438RPn formAccept stack-based overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9460"
    },
    {
      "rank": 38,
      "cve_id": "CVE-2026-9461",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00751,
      "epss_percentile": 0.52151,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Edimax",
      "product": "EW-7438RPn",
      "cwe": "CWE-119",
      "title": "Edimax EW-7438RPn formRadius stack-based overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9461"
    },
    {
      "rank": 39,
      "cve_id": "CVE-2026-45249",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00749,
      "epss_percentile": 0.52084,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache ECharts",
      "cwe": "CWE-79",
      "title": "Apache ECharts: XSS in Lines series tooltip rendering",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45249"
    },
    {
      "rank": 40,
      "cve_id": "CVE-2026-8652",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00722,
      "epss_percentile": 0.51125,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NEC Platforms, Ltd.",
      "product": "Aterm MR51FN",
      "cwe": "CWE-78",
      "title": "An OS Command Injection vulnerability exists in Aterm. If a malicious third person gains administrator access to the product’s web console, they may be able to execute arbitrary OS commands via adjacent network.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8652"
    },
    {
      "rank": 41,
      "cve_id": "CVE-2026-47077",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00703,
      "epss_percentile": 0.50481,
      "kev": false,
      "kev_due_at": null,
      "vendor": "benoitc",
      "product": "hackney",
      "cwe": "CWE-400",
      "title": "Unbounded body accumulation in HTTP/3 response loop in hackney",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47077"
    },
    {
      "rank": 42,
      "cve_id": "CVE-2026-42782",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00653,
      "epss_percentile": 0.48504,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Syncope",
      "cwe": "CWE-653",
      "title": "Apache Syncope: Post-auth RCE via Groovy static",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42782"
    },
    {
      "rank": 43,
      "cve_id": "CVE-2026-9480",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00647,
      "epss_percentile": 0.48248,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Edimax",
      "product": "EW-7438RPn",
      "cwe": "CWE-119",
      "title": "Edimax EW-7438RPn formrefresh stack-based overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9480"
    },
    {
      "rank": 44,
      "cve_id": "CVE-2026-45361",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0059,
      "epss_percentile": 0.45632,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Airflow Google provider",
      "cwe": "CWE-322",
      "title": "Apache Airflow Google provider: SSH host key verification disabled in ComputeEngineSSHHook (paramiko AutoAddPolicy default)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45361"
    },
    {
      "rank": 45,
      "cve_id": "CVE-2026-9442",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00589,
      "epss_percentile": 0.45598,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Edimax",
      "product": "BR-6478AC",
      "cwe": "CWE-119",
      "title": "Edimax BR-6478AC POST Request formiNICSiteSurvey buffer overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9442"
    },
    {
      "rank": 46,
      "cve_id": "CVE-2026-9443",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00589,
      "epss_percentile": 0.45596,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Edimax",
      "product": "BR-6478AC",
      "cwe": "CWE-119",
      "title": "Edimax BR-6478AC POST Request formL2TPSetup buffer overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9443"
    },
    {
      "rank": 47,
      "cve_id": "CVE-2026-9462",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00589,
      "epss_percentile": 0.45598,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Edimax",
      "product": "EW-7438RPn",
      "cwe": "CWE-119",
      "title": "Edimax EW-7438RPn formWpsProxyEnable stack-based overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9462"
    },
    {
      "rank": 48,
      "cve_id": "CVE-2026-9463",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00589,
      "epss_percentile": 0.45598,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Edimax",
      "product": "EW-7438RPn",
      "cwe": "CWE-119",
      "title": "Edimax EW-7438RPn formLicence stack-based overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9463"
    },
    {
      "rank": 49,
      "cve_id": "CVE-2026-9479",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00589,
      "epss_percentile": 0.45597,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Edimax",
      "product": "EW-7438RPn",
      "cwe": "CWE-119",
      "title": "Edimax EW-7438RPn formLogout stack-based overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9479"
    },
    {
      "rank": 50,
      "cve_id": "CVE-2026-9481",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00589,
      "epss_percentile": 0.45597,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Edimax",
      "product": "EW-7438RPn",
      "cwe": "CWE-119",
      "title": "Edimax EW-7438RPn formStats stack-based overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9481"
    },
    {
      "rank": 51,
      "cve_id": "CVE-2026-9482",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00589,
      "epss_percentile": 0.45597,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Edimax",
      "product": "EW-7438RPn",
      "cwe": "CWE-119",
      "title": "Edimax EW-7438RPn formSDHCP stack-based overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9482"
    },
    {
      "rank": 52,
      "cve_id": "CVE-2026-9428",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00579,
      "epss_percentile": 0.45119,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tenda",
      "product": "F1202",
      "cwe": "CWE-119",
      "title": "Tenda F1202 PPTPUserSetting fromPPTPUserSetting stack-based overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9428"
    },
    {
      "rank": 53,
      "cve_id": "CVE-2026-9429",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00579,
      "epss_percentile": 0.45119,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tenda",
      "product": "F1202",
      "cwe": "CWE-119",
      "title": "Tenda F1202 WrlExtraSet formWrlExtraSet stack-based overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9429"
    },
    {
      "rank": 54,
      "cve_id": "CVE-2026-46745",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00575,
      "epss_percentile": 0.44919,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Airflow FAB provider",
      "cwe": "CWE-90",
      "title": "Apache Airflow FAB provider: LDAP Filter Injection in FAB Auth Manager _search_ldap reachable via /auth/token",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46745"
    },
    {
      "rank": 55,
      "cve_id": "CVE-2026-47072",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00542,
      "epss_percentile": 0.43227,
      "kev": false,
      "kev_due_at": null,
      "vendor": "benoitc",
      "product": "hackney",
      "cwe": "CWE-93",
      "title": "CRLF injection in WebSocket upgrade request in hackney",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47072"
    },
    {
      "rank": 56,
      "cve_id": "CVE-2026-47075",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00479,
      "epss_percentile": 0.39474,
      "kev": false,
      "kev_due_at": null,
      "vendor": "benoitc",
      "product": "hackney",
      "cwe": "CWE-93",
      "title": "CR/LF injection in query parameter in hackney",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47075"
    },
    {
      "rank": 57,
      "cve_id": "CVE-2026-5222",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00478,
      "epss_percentile": 0.39386,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Rust",
      "product": "Cargo",
      "cwe": "CWE-647",
      "title": "Cargo can be coerced to share credentials between registries",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-5222"
    },
    {
      "rank": 58,
      "cve_id": "CVE-2026-9425",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00445,
      "epss_percentile": 0.37223,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Edimax",
      "product": "EW-7438RPn",
      "cwe": "CWE-119",
      "title": "Edimax EW-7438RPn formWlanMP stack-based overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9425"
    },
    {
      "rank": 59,
      "cve_id": "CVE-2026-9426",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00445,
      "epss_percentile": 0.37224,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Edimax",
      "product": "EW-7438RPn",
      "cwe": "CWE-119",
      "title": "Edimax EW-7438RPn formHwSet stack-based overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9426"
    },
    {
      "rank": 60,
      "cve_id": "CVE-2026-9427",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00445,
      "epss_percentile": 0.37222,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Edimax",
      "product": "EW-7438RPn",
      "cwe": "CWE-119",
      "title": "Edimax EW-7438RPn webs formWlSiteSurvey stack-based overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9427"
    },
    {
      "rank": 61,
      "cve_id": "CVE-2026-8376",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00443,
      "epss_percentile": 0.37034,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SHAY",
      "product": "perl",
      "cwe": "CWE-680",
      "title": "Perl versions through 5.43.10 have a heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8376"
    },
    {
      "rank": 62,
      "cve_id": "CVE-2026-9430",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00438,
      "epss_percentile": 0.36639,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tenda",
      "product": "F1202",
      "cwe": "CWE-119",
      "title": "Tenda F1202 GstDhcpSetSerof formGstDhcpSetSer stack-based overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9430"
    },
    {
      "rank": 63,
      "cve_id": "CVE-2026-9431",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00438,
      "epss_percentile": 0.36639,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tenda",
      "product": "F1202",
      "cwe": "CWE-119",
      "title": "Tenda F1202 PptpUserAdd fromPptpUserAdd stack-based overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9431"
    },
    {
      "rank": 64,
      "cve_id": "CVE-2026-9467",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00438,
      "epss_percentile": 0.36637,
      "kev": false,
      "kev_due_at": null,
      "vendor": "debugmcp",
      "product": "mcp-debugger",
      "cwe": "CWE-22",
      "title": "debugmcp mcp-debugger server.ts handleGetSourceContext path traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9467"
    },
    {
      "rank": 65,
      "cve_id": "CVE-2026-42797",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00437,
      "epss_percentile": 0.36572,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Syncope",
      "cwe": "CWE-202",
      "title": "Apache Syncope: JexlContextBuilder Information Disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42797"
    },
    {
      "rank": 66,
      "cve_id": "CVE-2026-48847",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00433,
      "epss_percentile": 0.36287,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Roundcube",
      "product": "Webmail",
      "cwe": "CWE-669",
      "title": "Roundcube Webmail 1.6.x before 1.6.16, and 1.7.x before 1.7.1 allows pre-authentication arbitrary file deletion via redis/memcache session poisoning bypass.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48847"
    },
    {
      "rank": 67,
      "cve_id": "CVE-2026-47069",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00425,
      "epss_percentile": 0.35681,
      "kev": false,
      "kev_due_at": null,
      "vendor": "benoitc",
      "product": "hackney",
      "cwe": "CWE-93",
      "title": "CRLF injection in cookie domain/path options in hackney",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47069"
    },
    {
      "rank": 68,
      "cve_id": "CVE-2026-48844",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00414,
      "epss_percentile": 0.34679,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Roundcube",
      "product": "Webmail",
      "cwe": "CWE-670",
      "title": "Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has insecure code evaluation logic in LDAP the autovalues option that could lead to code injection. (Support for code evaluation has been removed in 1.6.16 and 1.7.1.)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48844"
    },
    {
      "rank": 69,
      "cve_id": "CVE-2026-43827",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00412,
      "epss_percentile": 0.34556,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Shiro",
      "cwe": "CWE-384",
      "title": "Apache Shiro: Session fixation: new session is not created after login by default",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43827"
    },
    {
      "rank": 70,
      "cve_id": "CVE-2026-24937",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00408,
      "epss_percentile": 0.34181,
      "kev": false,
      "kev_due_at": null,
      "vendor": "VideoWhisper.com",
      "product": "Broadcast Live Video",
      "cwe": "CWE-94",
      "title": "WordPress Broadcast Live Video plugin < 7.1.3 - Remote Code Execution (RCE) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-24937"
    },
    {
      "rank": 71,
      "cve_id": "CVE-2026-48846",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00405,
      "epss_percentile": 0.33917,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Roundcube",
      "product": "Webmail",
      "cwe": "CWE-669",
      "title": "In Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1, the remote image blocking feature can be bypassed via a crafted CSS var() value in an e-mail message, which may lead to information disclosure or access-control bypass.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48846"
    },
    {
      "rank": 72,
      "cve_id": "CVE-2026-41863",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00398,
      "epss_percentile": 0.33173,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Spring",
      "product": "Spring AI",
      "cwe": "CWE-22",
      "title": "LLM-influenced filename used unsanitized in Path.resolve before file write in Spring AI support for Anthropic Skills API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41863"
    },
    {
      "rank": 73,
      "cve_id": "CVE-2018-25379",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0039,
      "epss_percentile": 0.32309,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ourenergy",
      "product": "Collectric CMU",
      "cwe": "CWE-89",
      "title": "Collectric CMU 1.0 SQL Injection via lang Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2018-25379"
    },
    {
      "rank": 74,
      "cve_id": "CVE-2026-45216",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00389,
      "epss_percentile": 0.32228,
      "kev": false,
      "kev_due_at": null,
      "vendor": "StoreApps",
      "product": "Smart Manager",
      "cwe": "CWE-266",
      "title": "WordPress Smart Manager plugin <= 8.85.0 - Privilege Escalation vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45216"
    },
    {
      "rank": 75,
      "cve_id": "CVE-2026-48848",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00388,
      "epss_percentile": 0.32125,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Roundcube",
      "product": "Webmail",
      "cwe": "CWE-79",
      "title": "Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7 has insufficient HTML sanitization that could lead to Cascading Style Sheets (CSS) injection via an SVG document that has an animate element with the attributeName attribute.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48848"
    },
    {
      "rank": 76,
      "cve_id": "CVE-2018-25368",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00386,
      "epss_percentile": 0.3189,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Nordvpn",
      "product": "NordVPN",
      "cwe": "CWE-789",
      "title": "Nord VPN 6.14.31 Denial of Service via Password Field",
      "url": "https://www.cve.org/CVERecord?id=CVE-2018-25368"
    },
    {
      "rank": 77,
      "cve_id": "CVE-2026-48845",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00377,
      "epss_percentile": 0.31022,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Roundcube",
      "product": "Webmail",
      "cwe": "CWE-669",
      "title": "In Roundcube Webmail 1.6.x between 1.6.14 and 1.6.16 and 1.7.x before 1.7.1, remote image blocking was not honored for URLs pointing to local/private destinations, which may lead to information disclosure or privilege escalation via a text/html email message.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48845"
    },
    {
      "rank": 78,
      "cve_id": "CVE-2026-48837",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00373,
      "epss_percentile": 0.30579,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unlimited Elements",
      "product": "Unlimited Elements For Elementor",
      "cwe": "CWE-89",
      "title": "WordPress Unlimited Elements For Elementor plugin <= 2.0.8 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48837"
    },
    {
      "rank": 79,
      "cve_id": "CVE-2026-42773",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00372,
      "epss_percentile": 0.30492,
      "kev": false,
      "kev_due_at": null,
      "vendor": "eMagicOne",
      "product": "eMagicOne Store Manager",
      "cwe": "CWE-89",
      "title": "WordPress eMagicOne Store Manager plugin <= 1.3.2 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42773"
    },
    {
      "rank": 80,
      "cve_id": "CVE-2026-42774",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00372,
      "epss_percentile": 0.30491,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Crocoblock",
      "product": "JetEngine",
      "cwe": "CWE-89",
      "title": "WordPress JetEngine plugin <= 3.8.8.1 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42774"
    },
    {
      "rank": 81,
      "cve_id": "CVE-2026-47070",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00372,
      "epss_percentile": 0.30505,
      "kev": false,
      "kev_due_at": null,
      "vendor": "benoitc",
      "product": "hackney",
      "cwe": "CWE-601",
      "title": "HTTP/3 redirect handler leaks Authorization and Cookie headers to cross-origin redirect target in hackney",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47070"
    },
    {
      "rank": 82,
      "cve_id": "CVE-2026-44598",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00367,
      "epss_percentile": 0.29958,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Shiro Jakarta EE module",
      "cwe": "CWE-601",
      "title": "Apache Shiro Jakarta EE module: Open redirect and SSRF (requires valid credentials)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44598"
    },
    {
      "rank": 83,
      "cve_id": "CVE-2026-9464",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": 0.0036,
      "epss_percentile": 0.29276,
      "kev": false,
      "kev_due_at": null,
      "vendor": "YunaiV",
      "product": "yudao-cloud",
      "cwe": "CWE-918",
      "title": "YunaiV yudao-cloud Admin API Endpoint create IotDataSinkHttpConfig server-side request forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9464"
    },
    {
      "rank": 84,
      "cve_id": "CVE-2026-45217",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00352,
      "epss_percentile": 0.28442,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ThemeHigh",
      "product": "Stripe Payment Gateway for WooCommerce",
      "cwe": "CWE-288",
      "title": "WordPress Stripe Payment Gateway for WooCommerce plugin <= 5.0.7 - Broken Authentication vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45217"
    },
    {
      "rank": 85,
      "cve_id": "CVE-2026-9466",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00352,
      "epss_percentile": 0.28361,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tiandy",
      "product": "Easy7 Integrated Management Platform",
      "cwe": "CWE-640",
      "title": "Tiandy Easy7 Integrated Management Platform API Endpoint updateUserPassword password recovery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9466"
    },
    {
      "rank": 86,
      "cve_id": "CVE-2026-48589",
      "cvss_base": 0,
      "cvss_severity": "NONE",
      "epss_score": 0.00352,
      "epss_percentile": 0.28404,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Shiro",
      "cwe": "CWE-601",
      "title": "Apache Shiro: Jakarta EE open redirect via untrusted Referer in post-login redirect flow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48589"
    },
    {
      "rank": 87,
      "cve_id": "CVE-2026-40127",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00351,
      "epss_percentile": 0.28259,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OutSystems",
      "product": "Lifetime",
      "cwe": "CWE-639",
      "title": "Authorization Bypass Through User-Controlled Key in OutSystems Lifetime",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40127"
    },
    {
      "rank": 88,
      "cve_id": "CVE-2018-25371",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00348,
      "epss_percentile": 0.27966,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Moosocial",
      "product": "mooSocial Store Plugin",
      "cwe": "CWE-89",
      "title": "mooSocial Store Plugin 2.6 SQL Injection via product parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2018-25371"
    },
    {
      "rank": 89,
      "cve_id": "CVE-2026-2651",
      "cvss_base": 9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00345,
      "epss_percentile": 0.27656,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mlflow",
      "product": "mlflow/mlflow",
      "cwe": "CWE-862",
      "title": "Missing Authorization Validation in mlflow/mlflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-2651"
    },
    {
      "rank": 90,
      "cve_id": "CVE-2026-27768",
      "cvss_base": 6.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0034,
      "epss_percentile": 0.27096,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Genetec Inc.",
      "product": "Genetec Security Center",
      "cwe": "CWE-89",
      "title": "SQL Injection affecting the Access Manager role.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-27768"
    },
    {
      "rank": 91,
      "cve_id": "CVE-2026-9497",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00338,
      "epss_percentile": 0.26822,
      "kev": false,
      "kev_due_at": null,
      "vendor": "changmingxie",
      "product": "tcc-transaction",
      "cwe": "CWE-20",
      "title": "changmingxie tcc-transaction Fastjson AutoType REST API Fastjson.parseObject deserialization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9497"
    },
    {
      "rank": 92,
      "cve_id": "CVE-2018-25364",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00337,
      "epss_percentile": 0.26683,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Fyffe",
      "product": "PHP-Twitter-Clone",
      "cwe": "CWE-89",
      "title": "Twitter-Clone 1 SQL Injection via search.php",
      "url": "https://www.cve.org/CVERecord?id=CVE-2018-25364"
    },
    {
      "rank": 93,
      "cve_id": "CVE-2026-9468",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00337,
      "epss_percentile": 0.2673,
      "kev": false,
      "kev_due_at": null,
      "vendor": "dazeb",
      "product": "cline-mcp-memory-bank",
      "cwe": "CWE-22",
      "title": "dazeb cline-mcp-memory-bank index.ts handleInitializeMemoryBank path traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9468"
    },
    {
      "rank": 94,
      "cve_id": "CVE-2026-9472",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00337,
      "epss_percentile": 0.2673,
      "kev": false,
      "kev_due_at": null,
      "vendor": "dazeb",
      "product": "markdown-downloader",
      "cwe": "CWE-22",
      "title": "dazeb markdown-downloader index.ts create_subdirectory path traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9472"
    },
    {
      "rank": 95,
      "cve_id": "CVE-2026-9473",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00337,
      "epss_percentile": 0.2673,
      "kev": false,
      "kev_due_at": null,
      "vendor": "c-rick",
      "product": "jimeng-mcp",
      "cwe": "CWE-22",
      "title": "c-rick jimeng-mcp api.ts generateVideo path traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9473"
    },
    {
      "rank": 96,
      "cve_id": "CVE-2026-9448",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00336,
      "epss_percentile": 0.2663,
      "kev": false,
      "kev_due_at": null,
      "vendor": "code-projects",
      "product": "Employee Management System",
      "cwe": "CWE-79",
      "title": "code-projects Employee Management System applyleave.php cross site scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9448"
    },
    {
      "rank": 97,
      "cve_id": "CVE-2026-9438",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00324,
      "epss_percentile": 0.25292,
      "kev": false,
      "kev_due_at": null,
      "vendor": "yashpokharna2555",
      "product": "StudentManagementSystem",
      "cwe": "CWE-99",
      "title": "yashpokharna2555 StudentManagementSystem courseDel.php resource injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9438"
    },
    {
      "rank": 98,
      "cve_id": "CVE-2026-48850",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0032,
      "epss_percentile": 0.2489,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PuTTY",
      "product": "PuTTY",
      "cwe": "CWE-415",
      "title": "PuTTY 0.72 before 0.84 has a double free in RSA KEX.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48850"
    },
    {
      "rank": 99,
      "cve_id": "CVE-2026-9447",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00319,
      "epss_percentile": 0.24776,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "Simple POS and Inventory System",
      "cwe": "CWE-74",
      "title": "SourceCodester Simple POS and Inventory System search.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9447"
    },
    {
      "rank": 100,
      "cve_id": "CVE-2026-9465",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00319,
      "epss_percentile": 0.24777,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tiandy",
      "product": "Easy7 Integrated Management Platform",
      "cwe": "CWE-74",
      "title": "Tiandy Easy7 Integrated Management Platform GetDBDataEx.jsp sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9465"
    },
    {
      "rank": 101,
      "cve_id": "CVE-2026-9469",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00319,
      "epss_percentile": 0.24776,
      "kev": false,
      "kev_due_at": null,
      "vendor": "yashpokharna2555",
      "product": "StudentManagementSystem",
      "cwe": "CWE-74",
      "title": "yashpokharna2555 StudentManagementSystem success.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9469"
    },
    {
      "rank": 102,
      "cve_id": "CVE-2026-9470",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00319,
      "epss_percentile": 0.24777,
      "kev": false,
      "kev_due_at": null,
      "vendor": "yashpokharna2555",
      "product": "StudentManagementSystem",
      "cwe": "CWE-74",
      "title": "yashpokharna2555 StudentManagementSystem student_trans.php confirm_logged_in sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9470"
    },
    {
      "rank": 103,
      "cve_id": "CVE-2026-9474",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00319,
      "epss_percentile": 0.24778,
      "kev": false,
      "kev_due_at": null,
      "vendor": "yashpokharna2555",
      "product": "StudentManagementSystem",
      "cwe": "CWE-74",
      "title": "yashpokharna2555 StudentManagementSystem studentdel.php confirm_logged_in sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9474"
    },
    {
      "rank": 104,
      "cve_id": "CVE-2026-9058",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0031,
      "epss_percentile": 0.23713,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Krajowa Izba Rozliczeniowa",
      "product": "Szafir SDK",
      "cwe": "CWE-295",
      "title": "Improper Certificate Verification in Szafir SDK",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9058"
    },
    {
      "rank": 105,
      "cve_id": "CVE-2018-25362",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00309,
      "epss_percentile": 0.23642,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Fyffe",
      "product": "PHP-Twitter-Clone",
      "cwe": "CWE-89",
      "title": "Twitter-Clone 1 SQL Injection via follow.php",
      "url": "https://www.cve.org/CVERecord?id=CVE-2018-25362"
    },
    {
      "rank": 106,
      "cve_id": "CVE-2018-25372",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00305,
      "epss_percentile": 0.23236,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MedDream",
      "product": "PACS Server Premium",
      "cwe": "CWE-89",
      "title": "MedDream PACS Server Premium 6.7.1.1 SQL Injection via email",
      "url": "https://www.cve.org/CVERecord?id=CVE-2018-25372"
    },
    {
      "rank": 107,
      "cve_id": "CVE-2026-45209",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00305,
      "epss_percentile": 0.23223,
      "kev": false,
      "kev_due_at": null,
      "vendor": "edward_plainview",
      "product": "MyCryptoCheckout",
      "cwe": "CWE-862",
      "title": "WordPress MyCryptoCheckout plugin <= 2.161 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45209"
    },
    {
      "rank": 108,
      "cve_id": "CVE-2026-9422",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00304,
      "epss_percentile": 0.23134,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "KLiK SocialMediaWebsite",
      "cwe": "CWE-74",
      "title": "KLiK SocialMediaWebsite HTTP POST Request Parameter injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9422"
    },
    {
      "rank": 109,
      "cve_id": "CVE-2026-24546",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00295,
      "epss_percentile": 0.22108,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ruben Garcia",
      "product": "GamiPress",
      "cwe": "CWE-862",
      "title": "WordPress GamiPress plugin <= 7.6.3 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-24546"
    },
    {
      "rank": 110,
      "cve_id": "CVE-2026-9498",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00295,
      "epss_percentile": 0.22149,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dromara",
      "product": "lamp-cloud",
      "cwe": "CWE-791",
      "title": "Dromara lamp-cloud Message Template GroovyClassLoader.parseClass special elements used in a template engine",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9498"
    },
    {
      "rank": 111,
      "cve_id": "CVE-2026-5223",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00294,
      "epss_percentile": 0.22063,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Rust Project",
      "product": "Cargo",
      "cwe": "CWE-61",
      "title": "Crates in third party registries can override the cached source of other crates",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-5223"
    },
    {
      "rank": 112,
      "cve_id": "CVE-2026-9421",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00293,
      "epss_percentile": 0.21861,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "KLiK SocialMediaWebsite",
      "cwe": "CWE-284",
      "title": "KLiK SocialMediaWebsite File upload.inc.php uniqid unrestricted upload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9421"
    },
    {
      "rank": 113,
      "cve_id": "CVE-2026-45438",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00289,
      "epss_percentile": 0.2144,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WebToffee",
      "product": "Smart Coupons for WooCommerce",
      "cwe": "CWE-862",
      "title": "WordPress Smart Coupons for WooCommerce plugin < 2.3.0 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45438"
    },
    {
      "rank": 114,
      "cve_id": "CVE-2018-25380",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00284,
      "epss_percentile": 0.21017,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Extro",
      "product": "eXtroForms",
      "cwe": "CWE-89",
      "title": "Joomla Component eXtroForms 2.1.5 SQL Injection via filter parameters",
      "url": "https://www.cve.org/CVERecord?id=CVE-2018-25380"
    },
    {
      "rank": 115,
      "cve_id": "CVE-2018-25381",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00284,
      "epss_percentile": 0.21017,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Extro",
      "product": "Responsive Portfolio",
      "cwe": "CWE-89",
      "title": "Joomla Responsive Portfolio 1.6.1 SQL Injection via filter parameters",
      "url": "https://www.cve.org/CVERecord?id=CVE-2018-25381"
    },
    {
      "rank": 116,
      "cve_id": "CVE-2026-4915",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00277,
      "epss_percentile": 0.20238,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mattermost",
      "product": "Mattermost",
      "cwe": "CWE-754",
      "title": "Server panic via outgoing webhook responses",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-4915"
    },
    {
      "rank": 117,
      "cve_id": "CVE-2026-48852",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00274,
      "epss_percentile": 0.19889,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PuTTY",
      "product": "PuTTY",
      "cwe": "CWE-617",
      "title": "PuTTY 0.71 before 0.84 has an assertion failure in ECDSA signature verification.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48852"
    },
    {
      "rank": 118,
      "cve_id": "CVE-2026-43828",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00272,
      "epss_percentile": 0.19656,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Shiro",
      "cwe": "CWE-614",
      "title": "Apache Shiro: Shiro's native session and rememberMe cookies do not have secure flag set by default",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43828"
    },
    {
      "rank": 119,
      "cve_id": "CVE-2026-9484",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00272,
      "epss_percentile": 0.1961,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "Student Grades Management System",
      "cwe": "CWE-266",
      "title": "SourceCodester Student Grades Management System classroom.php removeStudentFromClassroom improper authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9484"
    },
    {
      "rank": 120,
      "cve_id": "CVE-2026-48843",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00268,
      "epss_percentile": 0.19046,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Roundcube",
      "product": "Webmail",
      "cwe": "CWE-918",
      "title": "Roundcube Webmail 1.6.x between 1.6.14 and 1.6.16,and 1.7.x before 1.7.1 has Insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to SSRF or Information Disclosure, e.g., if stylesheet links point to local network hosts. The issue stems from an insufficient fix for CVE-2026-35540.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48843"
    },
    {
      "rank": 121,
      "cve_id": "CVE-2026-42763",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00264,
      "epss_percentile": 0.18417,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SePay team",
      "product": "SePay Gateway",
      "cwe": "CWE-862",
      "title": "WordPress SePay Gateway plugin <= 1.1.20 - Sensitive Data Exposure vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42763"
    },
    {
      "rank": 122,
      "cve_id": "CVE-2026-9413",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00263,
      "epss_percentile": 0.18345,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "Indian Invoicing System",
      "cwe": "CWE-79",
      "title": "SourceCodester Indian Invoicing System category.php cross site scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9413"
    },
    {
      "rank": 123,
      "cve_id": "CVE-2026-9415",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00263,
      "epss_percentile": 0.18342,
      "kev": false,
      "kev_due_at": null,
      "vendor": "code-projects",
      "product": "Employee Management System",
      "cwe": "CWE-79",
      "title": "code-projects Employee Management System eloginwel.php cross site scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9415"
    },
    {
      "rank": 124,
      "cve_id": "CVE-2026-9416",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00263,
      "epss_percentile": 0.18341,
      "kev": false,
      "kev_due_at": null,
      "vendor": "code-projects",
      "product": "Employee Management System",
      "cwe": "CWE-79",
      "title": "code-projects Employee Management System myprofile.php cross site scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9416"
    },
    {
      "rank": 125,
      "cve_id": "CVE-2026-9417",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00263,
      "epss_percentile": 0.18344,
      "kev": false,
      "kev_due_at": null,
      "vendor": "code-projects",
      "product": "Employee Management System",
      "cwe": "CWE-79",
      "title": "code-projects Employee Management System myprofileup.php cross site scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9417"
    },
    {
      "rank": 126,
      "cve_id": "CVE-2026-9418",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00263,
      "epss_percentile": 0.18344,
      "kev": false,
      "kev_due_at": null,
      "vendor": "code-projects",
      "product": "Employee Management System",
      "cwe": "CWE-79",
      "title": "code-projects Employee Management System changepassemp.php cross site scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9418"
    },
    {
      "rank": 127,
      "cve_id": "CVE-2026-9419",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00263,
      "epss_percentile": 0.18343,
      "kev": false,
      "kev_due_at": null,
      "vendor": "code-projects",
      "product": "Employee Management System",
      "cwe": "CWE-79",
      "title": "code-projects Employee Management System empproject.php cross site scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9419"
    },
    {
      "rank": 128,
      "cve_id": "CVE-2026-9445",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00261,
      "epss_percentile": 0.18053,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "Simple POS and Inventory System",
      "cwe": "CWE-284",
      "title": "SourceCodester Simple POS and Inventory System File Extension addproduct.php unrestricted upload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9445"
    },
    {
      "rank": 129,
      "cve_id": "CVE-2026-9483",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00261,
      "epss_percentile": 0.18053,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "Student Grades Management System",
      "cwe": "CWE-266",
      "title": "SourceCodester Student Grades Management System grades.php improper authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9483"
    },
    {
      "rank": 130,
      "cve_id": "CVE-2026-7766",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00258,
      "epss_percentile": 0.17664,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Kenik",
      "product": "KG-5230TAS-IL-3",
      "cwe": "CWE-22",
      "title": "Path Traversal in Kenik cameras",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7766"
    },
    {
      "rank": 131,
      "cve_id": "CVE-2026-9444",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": 0.00258,
      "epss_percentile": 0.17636,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "Simple POS and Inventory System",
      "cwe": "CWE-74",
      "title": "SourceCodester Simple POS and Inventory System GET Parameter deleteproduct.php delete sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9444"
    },
    {
      "rank": 132,
      "cve_id": "CVE-2026-9446",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": 0.00258,
      "epss_percentile": 0.17636,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "Simple POS and Inventory System",
      "cwe": "CWE-74",
      "title": "SourceCodester Simple POS and Inventory System edit_customer.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9446"
    },
    {
      "rank": 133,
      "cve_id": "CVE-2026-24586",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00255,
      "epss_percentile": 0.17236,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Themeansar",
      "product": "Newses",
      "cwe": "CWE-862",
      "title": "WordPress Newses theme <= 2.0.0.77 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-24586"
    },
    {
      "rank": 134,
      "cve_id": "CVE-2026-27346",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00254,
      "epss_percentile": 0.17129,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Kings Plugins",
      "product": "B2BKing",
      "cwe": "CWE-862",
      "title": "WordPress B2BKing plugin < 5.2.10 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-27346"
    },
    {
      "rank": 135,
      "cve_id": "CVE-2026-9471",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": 0.00248,
      "epss_percentile": 0.1636,
      "kev": false,
      "kev_due_at": null,
      "vendor": "yashpokharna2555",
      "product": "StudentManagementSystem",
      "cwe": "CWE-79",
      "title": "yashpokharna2555 StudentManagementSystem student.php cross site scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9471"
    },
    {
      "rank": 136,
      "cve_id": "CVE-2026-9485",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": 0.00248,
      "epss_percentile": 0.16359,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "Student Grades Management System",
      "cwe": "CWE-79",
      "title": "SourceCodester Student Grades Management System students.php cross site scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9485"
    },
    {
      "rank": 137,
      "cve_id": "CVE-2026-9449",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00246,
      "epss_percentile": 0.16125,
      "kev": false,
      "kev_due_at": null,
      "vendor": "code-projects",
      "product": "Employee Management System",
      "cwe": "CWE-74",
      "title": "code-projects Employee Management System changepassemp.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9449"
    },
    {
      "rank": 138,
      "cve_id": "CVE-2026-9450",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00246,
      "epss_percentile": 0.16124,
      "kev": false,
      "kev_due_at": null,
      "vendor": "code-projects",
      "product": "Employee Management System",
      "cwe": "CWE-74",
      "title": "code-projects Employee Management System psubmit.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9450"
    },
    {
      "rank": 139,
      "cve_id": "CVE-2026-9451",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00246,
      "epss_percentile": 0.16124,
      "kev": false,
      "kev_due_at": null,
      "vendor": "code-projects",
      "product": "Employee Management System",
      "cwe": "CWE-74",
      "title": "code-projects Employee Management System applyleaveprocess.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9451"
    },
    {
      "rank": 140,
      "cve_id": "CVE-2026-9420",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00242,
      "epss_percentile": 0.15658,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "KLiK SocialMediaWebsite",
      "cwe": "CWE-74",
      "title": "KLiK SocialMediaWebsite HTTP GET Request Parameter injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9420"
    },
    {
      "rank": 141,
      "cve_id": "CVE-2026-48849",
      "cvss_base": 4.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00239,
      "epss_percentile": 0.1519,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Roundcube",
      "product": "Webmail",
      "cwe": "CWE-79",
      "title": "In Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1, an unsanitized subject field in the draft restored value could lead to stored XSS/HTML/CSS injection on shared mailboxes.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48849"
    },
    {
      "rank": 142,
      "cve_id": "CVE-2026-24592",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00231,
      "epss_percentile": 0.1425,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Lucian Apostol",
      "product": "Auto Affiliate Links",
      "cwe": "CWE-862",
      "title": "WordPress Auto Affiliate Links plugin <= 6.8.8.3 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-24592"
    },
    {
      "rank": 143,
      "cve_id": "CVE-2026-27357",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00231,
      "epss_percentile": 0.14251,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cornel Raiu",
      "product": "WP Search Analytics",
      "cwe": "CWE-862",
      "title": "WordPress WP Search Analytics plugin < 1.5.0 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-27357"
    },
    {
      "rank": 144,
      "cve_id": "CVE-2026-27398",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00231,
      "epss_percentile": 0.1425,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WP Chill",
      "product": "RSVP and Event Management",
      "cwe": "CWE-862",
      "title": "WordPress RSVP and Event Management plugin <= 2.7.16 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-27398"
    },
    {
      "rank": 145,
      "cve_id": "CVE-2026-47076",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00229,
      "epss_percentile": 0.1395,
      "kev": false,
      "kev_due_at": null,
      "vendor": "benoitc",
      "product": "hackney",
      "cwe": "CWE-436",
      "title": "SSRF allowlist bypass via percent-encoded host in hackney",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47076"
    },
    {
      "rank": 146,
      "cve_id": "CVE-2026-48851",
      "cvss_base": 3.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00224,
      "epss_percentile": 0.1326,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PuTTY",
      "product": "PuTTY",
      "cwe": "CWE-451",
      "title": "PuTTY 0.77 before 0.84 uses a copy of the PuTTY icon as a trust indication for TELNET data but the trust status is not cleared between proxy authentication and the main session.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48851"
    },
    {
      "rank": 147,
      "cve_id": "CVE-2026-32389",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00223,
      "epss_percentile": 0.13202,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linethemes",
      "product": "NanoCare",
      "cwe": "CWE-862",
      "title": "WordPress NanoCare theme < 1.2.2 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-32389"
    },
    {
      "rank": 148,
      "cve_id": "CVE-2026-42776",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00202,
      "epss_percentile": 0.10483,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WP Sunshine",
      "product": "Sunshine Photo Cart",
      "cwe": "CWE-862",
      "title": "WordPress Sunshine Photo Cart plugin <= 3.6.7 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42776"
    },
    {
      "rank": 149,
      "cve_id": "CVE-2026-9412",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00201,
      "epss_percentile": 0.10394,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "Indian Invoicing System",
      "cwe": "CWE-266",
      "title": "SourceCodester Indian Invoicing System Backend Endpoint access control",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9412"
    },
    {
      "rank": 150,
      "cve_id": "CVE-2026-24527",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.002,
      "epss_percentile": 0.10209,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Patterns in the cloud",
      "product": "Autoship Cloud for WooCommerce Subscription Products",
      "cwe": "CWE-862",
      "title": "WordPress Autoship Cloud for WooCommerce Subscription Products plugin <= 2.14.0 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-24527"
    },
    {
      "rank": 151,
      "cve_id": "CVE-2026-24545",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.002,
      "epss_percentile": 0.10209,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Nikki Blight",
      "product": "QR Redirector",
      "cwe": "CWE-862",
      "title": "WordPress QR Redirector plugin <= 2.0.3 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-24545"
    },
    {
      "rank": 152,
      "cve_id": "CVE-2026-24582",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.002,
      "epss_percentile": 0.10209,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WPPOOL",
      "product": "FlexTable",
      "cwe": "CWE-862",
      "title": "WordPress FlexTable plugin <= 3.24.0 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-24582"
    },
    {
      "rank": 153,
      "cve_id": "CVE-2026-9078",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00199,
      "epss_percentile": 0.10139,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox for iOS",
      "cwe": "CWE-451",
      "title": "Firefox iOS RTL Domain Rendering Issue in Link Preview",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9078"
    },
    {
      "rank": 154,
      "cve_id": "CVE-2018-25363",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00199,
      "epss_percentile": 0.10038,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Fyffe",
      "product": "PHP-Twitter-Clone",
      "cwe": "CWE-352",
      "title": "Twitter-Clone 1 Cross-Site Request Forgery via tweetdel.php",
      "url": "https://www.cve.org/CVERecord?id=CVE-2018-25363"
    },
    {
      "rank": 155,
      "cve_id": "CVE-2026-9409",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00198,
      "epss_percentile": 0.09966,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Sushmi-pal",
      "product": "Invoice-System",
      "cwe": "CWE-266",
      "title": "Sushmi-pal Invoice-System User Management user improper authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9409"
    },
    {
      "rank": 156,
      "cve_id": "CVE-2026-9410",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00198,
      "epss_percentile": 0.09967,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Sushmi-pal",
      "product": "Invoice-System",
      "cwe": "CWE-266",
      "title": "Sushmi-pal Invoice-System Profile Workflow profile improper authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9410"
    },
    {
      "rank": 157,
      "cve_id": "CVE-2026-45435",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00197,
      "epss_percentile": 0.09805,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Melapress",
      "product": "WP Activity Log",
      "cwe": "CWE-79",
      "title": "WordPress WP Activity Log plugin <= 5.6.3 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45435"
    },
    {
      "rank": 158,
      "cve_id": "CVE-2018-25370",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00192,
      "epss_percentile": 0.09203,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Admidio",
      "product": "Admidio",
      "cwe": "CWE-352",
      "title": "Admidio 3.3.5 Cross-Site Request Forgery via roles_function.php",
      "url": "https://www.cve.org/CVERecord?id=CVE-2018-25370"
    },
    {
      "rank": 159,
      "cve_id": "CVE-2026-9411",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00192,
      "epss_percentile": 0.09266,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "Indian Invoicing System",
      "cwe": "CWE-74",
      "title": "SourceCodester Indian Invoicing System Invoice Generation IGST_Invoice.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9411"
    },
    {
      "rank": 160,
      "cve_id": "CVE-2026-9414",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": 0.00191,
      "epss_percentile": 0.09115,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "Indian Invoicing System",
      "cwe": "CWE-79",
      "title": "SourceCodester Indian Invoicing System Invoice Template Render Database-Backed add_order.php cross site scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9414"
    },
    {
      "rank": 161,
      "cve_id": "CVE-2018-25360",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00189,
      "epss_percentile": 0.08845,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Agatasoft",
      "product": "Auto PingMaster",
      "cwe": "CWE-121",
      "title": "AgataSoft Auto PingMaster 1.5 Buffer Overflow SEH",
      "url": "https://www.cve.org/CVERecord?id=CVE-2018-25360"
    },
    {
      "rank": 162,
      "cve_id": "CVE-2026-9486",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00187,
      "epss_percentile": 0.08666,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "Student Grades Management System",
      "cwe": "CWE-352",
      "title": "SourceCodester Student Grades Management System cross-site request forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9486"
    },
    {
      "rank": 163,
      "cve_id": "CVE-2018-25366",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00183,
      "epss_percentile": 0.08164,
      "kev": false,
      "kev_due_at": null,
      "vendor": "globalscape",
      "product": "CuteFTP",
      "cwe": "CWE-120",
      "title": "CuteFTP 5.0 XP Buffer Overflow via Site Manager Label Field",
      "url": "https://www.cve.org/CVERecord?id=CVE-2018-25366"
    },
    {
      "rank": 164,
      "cve_id": "CVE-2018-25376",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00183,
      "epss_percentile": 0.08164,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SocuSoft",
      "product": "3GP Photo Slideshow",
      "cwe": "CWE-120",
      "title": "Socusoft 3GP Photo Slideshow 8.05 Buffer Overflow SEH",
      "url": "https://www.cve.org/CVERecord?id=CVE-2018-25376"
    },
    {
      "rank": 165,
      "cve_id": "CVE-2018-25373",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00182,
      "epss_percentile": 0.08094,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SocuSoft",
      "product": "DVD Photo Slideshow Professional",
      "cwe": "CWE-121",
      "title": "DVD Photo Slideshow Professional 8.07 Buffer Overflow SEH",
      "url": "https://www.cve.org/CVERecord?id=CVE-2018-25373"
    },
    {
      "rank": 166,
      "cve_id": "CVE-2018-25375",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00182,
      "epss_percentile": 0.08094,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SocuSoft",
      "product": "iPod Photo Slideshow",
      "cwe": "CWE-121",
      "title": "SocuSoft iPod Photo Slideshow 8.05 Buffer Overflow SEH",
      "url": "https://www.cve.org/CVERecord?id=CVE-2018-25375"
    },
    {
      "rank": 167,
      "cve_id": "CVE-2018-25377",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00182,
      "epss_percentile": 0.08095,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SocuSoft",
      "product": "Flash Slideshow Maker Professional",
      "cwe": "CWE-120",
      "title": "Flash Slideshow Maker Professional 5.20 Buffer Overflow SEH",
      "url": "https://www.cve.org/CVERecord?id=CVE-2018-25377"
    },
    {
      "rank": 168,
      "cve_id": "CVE-2026-6059",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00179,
      "epss_percentile": 0.07729,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NEC Platforms, Ltd.",
      "product": "Aterm WX1800HP",
      "cwe": "CWE-79",
      "title": "A cross-site scripting vulnerability exists in Aterm. Arbitrary scripts may be executed in the web browser of a user accessing the web management interface via adjacent network.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6059"
    },
    {
      "rank": 169,
      "cve_id": "CVE-2026-9504",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00176,
      "epss_percentile": 0.07486,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GNU",
      "product": "LibreDWG",
      "cwe": "CWE-119",
      "title": "GNU LibreDWG Dwggrep Utility dwggrep.c bit_convert_TU out-of-bounds",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9504"
    },
    {
      "rank": 170,
      "cve_id": "CVE-2026-9490",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00173,
      "epss_percentile": 0.07033,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Acer",
      "product": "Care Center",
      "cwe": "CWE-269",
      "title": "Acer Care Center creates a Named Pipe with a weak Security Descriptor",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9490"
    },
    {
      "rank": 171,
      "cve_id": "CVE-2025-62745",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00171,
      "epss_percentile": 0.06902,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PickPlugins",
      "product": "Team Showcase",
      "cwe": "CWE-79",
      "title": "WordPress Team Showcase plugin <= 1.22.28 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-62745"
    },
    {
      "rank": 172,
      "cve_id": "CVE-2018-25369",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0017,
      "epss_percentile": 0.0679,
      "kev": false,
      "kev_due_at": null,
      "vendor": "scanwith",
      "product": "Visual Ping",
      "cwe": "CWE-120",
      "title": "Visual Ping 0.8.0.0 Buffer Overflow Denial of Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2018-25369"
    },
    {
      "rank": 173,
      "cve_id": "CVE-2018-25367",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00168,
      "epss_percentile": 0.06617,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NASA",
      "product": "openVSP",
      "cwe": "CWE-120",
      "title": "NASA openVSP 3.16.1 Denial of Service via Buffer Overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2018-25367"
    },
    {
      "rank": 174,
      "cve_id": "CVE-2018-25359",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00159,
      "epss_percentile": 0.05604,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Splinterware",
      "product": "Splinterware System Scheduler Pro",
      "cwe": "CWE-276",
      "title": "Splinterware System Scheduler Pro 5.12 Privilege Escalation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2018-25359"
    },
    {
      "rank": 175,
      "cve_id": "CVE-2026-9502",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00154,
      "epss_percentile": 0.05063,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GNU",
      "product": "LibreDWG",
      "cwe": "CWE-119",
      "title": "GNU LibreDWG Dwgread Utility decode.c decompress_R2004_section heap-based overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9502"
    },
    {
      "rank": 176,
      "cve_id": "CVE-2026-9501",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00144,
      "epss_percentile": 0.04186,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GNU",
      "product": "LibreDWG",
      "cwe": "CWE-617",
      "title": "GNU LibreDWG Dwgread Utility decode.c decompress_R2004_section assertion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9501"
    },
    {
      "rank": 177,
      "cve_id": "CVE-2026-24574",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0014,
      "epss_percentile": 0.03837,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Recorp",
      "product": "Export WP Page to Static HTML/CSS",
      "cwe": "CWE-352",
      "title": "WordPress Export WP Page to Static HTML/CSS plugin <= 6.0.0 - Cross Site Request Forgery (CSRF) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-24574"
    },
    {
      "rank": 178,
      "cve_id": "CVE-2026-25193",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00136,
      "epss_percentile": 0.03522,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Gallagher",
      "product": "Command Centre Server",
      "cwe": "CWE-532",
      "title": "Insertion of Sensitive Information into Log File (CWE-532) in some Command Centre Service installers could lead to Service Account credentials exposure. Mitigating Factor: Only sites that install Command Centre Services with a custom Service Account (not the default Network Service account) are potentially impacted. Mitigation: For sites concerned about exposure, the recommended action is to change the Service Account password. They can also delete any installer log files, usually found in %programdata%\\Gallagher\\Command Centre.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-25193"
    },
    {
      "rank": 179,
      "cve_id": "CVE-2018-25378",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00136,
      "epss_percentile": 0.03541,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Stokedonit",
      "product": "Notebook Pro",
      "cwe": "CWE-789",
      "title": "Notebook Pro 2.0 Denial of Service via Notebook Name Field",
      "url": "https://www.cve.org/CVERecord?id=CVE-2018-25378"
    },
    {
      "rank": 180,
      "cve_id": "CVE-2026-39436",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00131,
      "epss_percentile": 0.03116,
      "kev": false,
      "kev_due_at": null,
      "vendor": "bgermann",
      "product": "CformsII",
      "cwe": "CWE-352",
      "title": "WordPress CformsII plugin <= 15.1.3 - Cross Site Request Forgery (CSRF) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39436"
    },
    {
      "rank": 181,
      "cve_id": "CVE-2026-9274",
      "cvss_base": 5.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00125,
      "epss_percentile": 0.02636,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CP Plus",
      "product": "Wi-Fi Camera CP-E38Q, CP-E48Q, CP-E25Q, CP-E35Q, CP-E45Q, CP-E28Q, CP-E21Q, CP-E31Q, CP-E41Q, CP-E24Q, CP-Z43Q, CP-E34Q, CP-E44Q, CP-T31Q, CP-V48Q, CP-V41Q, CP-Z45Q",
      "cwe": "CWE-312",
      "title": "Information Exposure Vulnerability in CP-Plus Wi-Fi Camera",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9274"
    },
    {
      "rank": 182,
      "cve_id": "CVE-2026-9500",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00124,
      "epss_percentile": 0.0255,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GNU",
      "product": "LibreDWG",
      "cwe": "CWE-119",
      "title": "GNU LibreDWG Dwgread Utility decode.c read_2004_compressed_section heap-based overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9500"
    },
    {
      "rank": 183,
      "cve_id": "CVE-2018-25361",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00122,
      "epss_percentile": 0.02326,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Soroush",
      "product": "Soroush IM Desktop App",
      "cwe": "CWE-290",
      "title": "Soroush IM Desktop App 0.17.0 Authentication Bypass via Database Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2018-25361"
    },
    {
      "rank": 184,
      "cve_id": "CVE-2026-24554",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00122,
      "epss_percentile": 0.02343,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Convers Lab",
      "product": "WPSubscription",
      "cwe": "CWE-352",
      "title": "WordPress WPSubscription plugin <= 1.9.1 - Cross Site Request Forgery (CSRF) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-24554"
    },
    {
      "rank": 185,
      "cve_id": "CVE-2026-24597",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00122,
      "epss_percentile": 0.02343,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WpDevArt",
      "product": "Organization chart",
      "cwe": "CWE-352",
      "title": "WordPress Organization chart plugin <= 1.7.5 - Cross Site Request Forgery (CSRF) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-24597"
    },
    {
      "rank": 186,
      "cve_id": "CVE-2026-9489",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0012,
      "epss_percentile": 0.02198,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Acer",
      "product": "NitrorSense V3",
      "cwe": "CWE-22",
      "title": "NitroSense V3: Local Privilege Escalation (LPE) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9489"
    },
    {
      "rank": 187,
      "cve_id": "CVE-2026-9503",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00113,
      "epss_percentile": 0.01638,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GNU",
      "product": "LibreDWG",
      "cwe": "CWE-404",
      "title": "GNU LibreDWG DWG File decode.c dwg_next_entity null pointer dereference",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9503"
    }
  ],
  "transactions": [
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-2651",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-2651 (mlflow/mlflow). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-47066",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-47066 (benoitc hackney). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-47067",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-47067 (benoitc hackney). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-47069",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-47069 (benoitc hackney). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-47070",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-47070 (benoitc hackney). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-47071",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-47071 (benoitc hackney). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-47072",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-47072 (benoitc hackney). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-47073",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-47073 (benoitc hackney). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-47075",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-47075 (benoitc hackney). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-47076",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-47076 (benoitc hackney). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-47077",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-47077 (benoitc hackney). Public exploit reference added."
    }
  ],
  "attribution": "CVE Program, NVD (NIST), CISA KEV, FIRST EPSS, OSV. See /security/methodology/."
}
