{
  "day": "2026-05-26",
  "boundary": "UTC calendar day",
  "published_count": 275,
  "by_severity": {
    "CRITICAL": 30,
    "HIGH": 94,
    "MEDIUM": 119,
    "LOW": 32
  },
  "kev_count": 1,
  "exploit_reference_count": 21,
  "awaiting_enrichment_count": 0,
  "ranking": "Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.",
  "results": [
    {
      "rank": 1,
      "cve_id": "CVE-2026-48172",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.18914,
      "epss_percentile": 0.97064,
      "kev": true,
      "kev_due_at": "2026-05-29",
      "vendor": "LiteSpeed Technologies",
      "product": "cPanel Plugin",
      "cwe": "CWE-266",
      "title": "LiteSpeed cPanel Plugin",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48172"
    },
    {
      "rank": 2,
      "cve_id": "CVE-2026-4480",
      "cvss_base": 9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.1393,
      "epss_percentile": 0.9624,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-78",
      "title": "Samba: samba: remote code execution in printing subsystem via unescaped job description",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-4480"
    },
    {
      "rank": 3,
      "cve_id": "CVE-2026-9531",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.10811,
      "epss_percentile": 0.95485,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Totolink",
      "product": "CA750-PoE",
      "cwe": "CWE-77",
      "title": "Totolink CA750-PoE Setting cstecgi.cgi setUpgradeUboot os command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9531"
    },
    {
      "rank": 4,
      "cve_id": "CVE-2026-9532",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.10811,
      "epss_percentile": 0.95484,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Totolink",
      "product": "CA750-PoE",
      "cwe": "CWE-77",
      "title": "Totolink CA750-PoE Setting cstecgi.cgi setUploadUserData os command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9532"
    },
    {
      "rank": 5,
      "cve_id": "CVE-2026-9533",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.10811,
      "epss_percentile": 0.95485,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Totolink",
      "product": "CA750-PoE",
      "cwe": "CWE-77",
      "title": "Totolink CA750-PoE Setting cstecgi.cgi recvUpgradeNewFw os command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9533"
    },
    {
      "rank": 6,
      "cve_id": "CVE-2026-9534",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.10811,
      "epss_percentile": 0.95485,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Totolink",
      "product": "CA750-PoE",
      "cwe": "CWE-77",
      "title": "Totolink CA750-PoE Setting cstecgi.cgi setWiFiWpsConfig os command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9534"
    },
    {
      "rank": 7,
      "cve_id": "CVE-2026-46368",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.06582,
      "epss_percentile": 0.93276,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mossdef-org",
      "product": "luci-app-https-dns-proxy",
      "cwe": "CWE-77",
      "title": "luci-app-https-dns-proxy Authenticated Command Injection via setInitAction",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46368"
    },
    {
      "rank": 8,
      "cve_id": "CVE-2026-48133",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0475,
      "epss_percentile": 0.91154,
      "kev": false,
      "kev_due_at": null,
      "vendor": "checkpoint",
      "product": "Quantum Security Gateway",
      "cwe": "CWE-98",
      "title": "Identity Awareness Captive Portal - Unauthenticated Local File Inclusion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48133"
    },
    {
      "rank": 9,
      "cve_id": "CVE-2026-48134",
      "cvss_base": 5.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.04356,
      "epss_percentile": 0.90454,
      "kev": false,
      "kev_due_at": null,
      "vendor": "checkpoint",
      "product": "Quantum Security Gateway",
      "cwe": "CWE-89",
      "title": "SQL injection issue in UserCheck Portal when DLP Software Blade is active",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48134"
    },
    {
      "rank": 10,
      "cve_id": "CVE-2026-48136",
      "cvss_base": 4.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.04102,
      "epss_percentile": 0.8993,
      "kev": false,
      "kev_due_at": null,
      "vendor": "checkpoint",
      "product": "Quantum Security Management",
      "cwe": "CWE-89",
      "title": "Authenticated Administrator Role-Based Access Control Bypass in Compliance",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48136"
    },
    {
      "rank": 11,
      "cve_id": "CVE-2026-48131",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.02658,
      "epss_percentile": 0.84473,
      "kev": false,
      "kev_due_at": null,
      "vendor": "checkpoint",
      "product": "Quantum Security Gateway",
      "cwe": "CWE-122",
      "title": "VPND IKE Fragment Reassembly - Heap Out-of-Bounds Write via Sequence Number Zero",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48131"
    },
    {
      "rank": 12,
      "cve_id": "CVE-2026-48135",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.02607,
      "epss_percentile": 0.84151,
      "kev": false,
      "kev_due_at": null,
      "vendor": "checkpoint",
      "product": "Quantum Security Gateway",
      "cwe": "CWE-122",
      "title": "HTTP service can incorrectly process malformed HTTP requests",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48135"
    },
    {
      "rank": 13,
      "cve_id": "CVE-2026-48132",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.02139,
      "epss_percentile": 0.80563,
      "kev": false,
      "kev_due_at": null,
      "vendor": "checkpoint",
      "product": "Quantum Security Gateway",
      "cwe": "CWE-125",
      "title": "VPN service may restart unexpectedly when processing IKE traffic over NAT-T 4500/UDP",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48132"
    },
    {
      "rank": 14,
      "cve_id": "CVE-2026-9543",
      "cvss_base": 8.9,
      "cvss_severity": "HIGH",
      "epss_score": 0.02133,
      "epss_percentile": 0.80517,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Totolink",
      "product": "N300RH",
      "cwe": "CWE-77",
      "title": "Totolink N300RH Web Management cstecgi.cgi setPasswordCfg os command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9543"
    },
    {
      "rank": 15,
      "cve_id": "CVE-2026-48710",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.01839,
      "epss_percentile": 0.7725,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Kludex",
      "product": "starlette",
      "cwe": "CWE-444",
      "title": "Starlette has missing Host header validation that poisons request.url.path, bypassing path-based security checks",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48710"
    },
    {
      "rank": 16,
      "cve_id": "CVE-2026-48687",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.01645,
      "epss_percentile": 0.74531,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-78",
      "title": "FastNetMon Community Edition through 1.2.9 contains an OS command injection vulnerability in the Juniper router integration plugin. The _log() function in src/juniper_plugin/fastnetmon_juniper.php (lines 117-118) constructs shell commands by concatenating the $msg parameter directly into exec() calls: exec(\"echo `date` \\\"- {FASTNETMON] - \" . $msg . \" \\\" >> \" . $FILE_LOG_TMP). The $msg variable contains unsanitized data derived from command-line arguments argv[1] through argv[3], which represent the attack IP address, direction, and power. While FastNetMon's C++ core currently passes IP addresses via inet_ntoa() (which only produces safe dotted-decimal notation), the PHP script performs no input validation or shell escaping. If the script is invoked directly, by another orchestration system, or if future code changes pass string-sourced IPs, arbitrary commands can be injected. The correct fix is to replace exec() with file_put_contents() or use escapeshellarg() on all parameters.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48687"
    },
    {
      "rank": 17,
      "cve_id": "CVE-2026-45298",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.01491,
      "epss_percentile": 0.72036,
      "kev": false,
      "kev_due_at": null,
      "vendor": "amir20",
      "product": "dozzle",
      "cwe": "CWE-918",
      "title": "Dozzle: Pre-auth SSRF with response-body reflection via POST /api/notifications/test-webhook (default no-auth deploy)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45298"
    },
    {
      "rank": 18,
      "cve_id": "CVE-2026-44680",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.0145,
      "epss_percentile": 0.71263,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mikro-orm",
      "product": "mikro-orm",
      "cwe": "CWE-89",
      "title": "MikroORM: SQL injection via runtime-controlled identifiers and JSON-path keys",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44680"
    },
    {
      "rank": 19,
      "cve_id": "CVE-2026-48695",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0107,
      "epss_percentile": 0.62184,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-78",
      "title": "FastNetMon Community Edition through 1.2.9 contains an OS command injection vulnerability in the MikroTik router integration plugin. The _log() function in src/mikrotik_plugin/fastnetmon_mikrotik.php (lines 107-108) constructs shell commands by concatenating the $msg parameter directly into exec() calls: exec(\"echo `date` \\\"- {FASTNETMON] - \" . $msg . \" \\\" >> \" . $FILE_LOG_TMP). This is identical in pattern to the Juniper plugin vulnerability. The $msg variable contains unsanitized attack data from command-line arguments. An attacker who can influence argv[] values can inject arbitrary shell commands. The fix is to replace exec() with file_put_contents() or use escapeshellarg().",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48695"
    },
    {
      "rank": 20,
      "cve_id": "CVE-2026-9565",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.0105,
      "epss_percentile": 0.61587,
      "kev": false,
      "kev_due_at": null,
      "vendor": "haojing8312",
      "product": "WorkClaw",
      "cwe": "CWE-77",
      "title": "haojing8312 WorkClaw Blacklist bash.rs is_dangerous os command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9565"
    },
    {
      "rank": 21,
      "cve_id": "CVE-2026-40033",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.01037,
      "epss_percentile": 0.61222,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FreeRDP",
      "product": "FreeRDP",
      "cwe": "CWE-122",
      "title": "FreeRDP - Heap-buffer-overflow in gdi_CacheToSurface via rectangle validation bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40033"
    },
    {
      "rank": 22,
      "cve_id": "CVE-2026-8633",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00848,
      "epss_percentile": 0.55262,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Web Server Plug-ins for WebSphere Application Server and WebSphere Liberty",
      "cwe": "CWE-94",
      "title": "IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by multiple vulnerabilities when using when using Web Server Plug-ins",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8633"
    },
    {
      "rank": 23,
      "cve_id": "CVE-2026-5260",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00727,
      "epss_percentile": 0.51336,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-126",
      "title": "Gnutls: gnutls: information disclosure via heap overread in rsa key exchange",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-5260"
    },
    {
      "rank": 24,
      "cve_id": "CVE-2026-42015",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00727,
      "epss_percentile": 0.51332,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-193",
      "title": "Gnutls: gnutls: memory corruption due to off-by-one error in pkcs#12 bag handling",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42015"
    },
    {
      "rank": 25,
      "cve_id": "CVE-2026-42785",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00679,
      "epss_percentile": 0.49578,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Openkm",
      "product": "OpenKM Community Edition",
      "cwe": "CWE-94",
      "title": "OpenKM 6.3.12 Remote Code Execution via Administrative Scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42785"
    },
    {
      "rank": 26,
      "cve_id": "CVE-2026-48689",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00677,
      "epss_percentile": 0.49466,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-787",
      "title": "FastNetMon Community Edition through 1.2.9 contains an off-by-one heap-based buffer overflow in the dynamic_binary_buffer_t class (src/dynamic_binary_buffer.hpp). Five methods (append_dynamic_buffer, append_data_as_pointer, append_data_as_object_ptr, memcpy_from_ptr, memcpy_from_object_ptr) use an incorrect bounds check of the form 'if (offset + length > maximum_internal_storage_size + 1)' instead of the correct 'if (offset + length > maximum_internal_storage_size)'. This allows writing exactly one byte past the end of the heap-allocated buffer. The class is used pervasively in BGP message encoding/decoding, NetFlow template processing, and Flow Spec NLRI construction. An attacker who can send network traffic (NetFlow, sFlow, IPFIX, or BGP) to a FastNetMon instance can trigger this overflow, potentially achieving arbitrary code execution by corrupting heap metadata. Notably, the append_byte() method uses the correct bounds check, confirming the inconsistency.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48689"
    },
    {
      "rank": 27,
      "cve_id": "CVE-2026-24212",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00655,
      "epss_percentile": 0.48584,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "Isaac Launchable",
      "cwe": "CWE-319",
      "title": "NVIDIA Isaac Launchable for Linux contains a vulnerability where sensitive information is transmitted in clear text. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure, and data tampering.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-24212"
    },
    {
      "rank": 28,
      "cve_id": "CVE-2026-42425",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00641,
      "epss_percentile": 0.47956,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Openkm",
      "product": "OpenKM Community Edition",
      "cwe": "CWE-89",
      "title": "OpenKM 6.3.12 Unrestricted SQL Execution via DatabaseQuery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42425"
    },
    {
      "rank": 29,
      "cve_id": "CVE-2026-7374",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00596,
      "epss_percentile": 0.45861,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Container Native Virtualization 4.12",
      "cwe": "CWE-59",
      "title": "Kubevirt: kubevirt virt-handler: privilege escalation and node compromise via symlink following vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7374"
    },
    {
      "rank": 30,
      "cve_id": "CVE-2026-3660",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0058,
      "epss_percentile": 0.45139,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Engineering Lifecycle Management",
      "cwe": "CWE-863",
      "title": "IBM Engineering Lifecycle Management - Jazz Foundation is vulnerable to Authentication Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-3660"
    },
    {
      "rank": 31,
      "cve_id": "CVE-2026-9560",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00574,
      "epss_percentile": 0.44862,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenVPN Inc",
      "product": "OpenVPN Connect",
      "cwe": "CWE-78",
      "title": "Privilege escalation via background service of OpenVPN Connect 3.5.1 through 3.8.1 on macOS allows attackers to execute arbitrary commands with elevated privileges via local IPC channel",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9560"
    },
    {
      "rank": 32,
      "cve_id": "CVE-2026-48686",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00565,
      "epss_percentile": 0.44451,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-120",
      "title": "FastNetMon Community Edition through 1.2.9 contains a stack-based buffer overflow in the BGP NLRI (Network Layer Reachability Information) decoder. The function decode_bgp_subnet_encoding_ipv4_raw() in src/bgp_protocol.cpp reads prefix_bit_length directly from the BGP packet (line 99) without validating it is <= 32 for IPv4 prefixes. This value is passed to how_much_bytes_we_need_for_storing_certain_subnet_mask() which computes ceil(prefix_bit_length / 8), returning up to 32 bytes for a prefix_bit_length of 255. The result is used as the length argument to memcpy() (line 106), which copies into a 4-byte uint32_t stack variable (prefix_ipv4). This causes a stack buffer overflow of up to 28 bytes, which can be exploited for arbitrary code execution. Additionally, the unvalidated prefix_bit_length is passed to convert_cidr_to_binary_netmask_local_function_copy() (line 111), where a shift of (32 - cidr) with cidr > 32 causes undefined behavior.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48686"
    },
    {
      "rank": 33,
      "cve_id": "CVE-2026-44209",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00539,
      "epss_percentile": 0.43069,
      "kev": false,
      "kev_due_at": null,
      "vendor": "masci",
      "product": "banks",
      "cwe": "CWE-1336",
      "title": "Banks: Critical Remote Code Execution (RCE) via Jinja2 SSTI",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44209"
    },
    {
      "rank": 34,
      "cve_id": "CVE-2026-41401",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00519,
      "epss_percentile": 0.41943,
      "kev": false,
      "kev_due_at": null,
      "vendor": "libyang",
      "product": "libyang",
      "cwe": "CWE-416",
      "title": "libyang - Heap Use-After-Free Write in XML Metadata Parsing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41401"
    },
    {
      "rank": 35,
      "cve_id": "CVE-2026-9550",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00519,
      "epss_percentile": 0.41905,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Acrel Electrical",
      "product": "EEMS Enterprise Power Operation and Maintenance Cloud Platform",
      "cwe": "CWE-22",
      "title": "Acrel Electrical EEMS Enterprise Power Operation and Maintenance Cloud Platform upfile path traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9550"
    },
    {
      "rank": 36,
      "cve_id": "CVE-2026-44966",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00505,
      "epss_percentile": 0.41095,
      "kev": false,
      "kev_due_at": null,
      "vendor": "shepherdwind",
      "product": "velocity.js",
      "cwe": "CWE-1321",
      "title": "Velocity.js: Prototype Pollution in #set path assignment",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44966"
    },
    {
      "rank": 37,
      "cve_id": "CVE-2026-40383",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.005,
      "epss_percentile": 0.40776,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Joomla! Project",
      "product": "Joomla! CMS",
      "cwe": "CWE-22",
      "title": "Joomla! Core - [20260509] - LFI in HTMLView layout parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40383"
    },
    {
      "rank": 38,
      "cve_id": "CVE-2026-48592",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.005,
      "epss_percentile": 0.40792,
      "kev": false,
      "kev_due_at": null,
      "vendor": "oban-bg",
      "product": "oban_web",
      "cwe": "CWE-862",
      "title": "Missing authorization check on save-job event handler in oban_web",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48592"
    },
    {
      "rank": 39,
      "cve_id": "CVE-2026-7251",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00498,
      "epss_percentile": 0.4067,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Eppendorf",
      "product": "BioFlo 320",
      "cwe": "CWE-259",
      "title": "Eppendorf BioFlo 320 Use of hard-coded password",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7251"
    },
    {
      "rank": 40,
      "cve_id": "CVE-2026-8890",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0049,
      "epss_percentile": 0.40181,
      "kev": false,
      "kev_due_at": null,
      "vendor": "code100x",
      "product": "code100x",
      "cwe": "CWE-639",
      "title": "code100x Mobile API Authentication Bypass via Header Spoofing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8890"
    },
    {
      "rank": 41,
      "cve_id": "CVE-2026-40564",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0049,
      "epss_percentile": 0.40201,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Flink Kubernetes Operator",
      "cwe": "CWE-552",
      "title": "Apache Flink Kubernetes Operator: Server-Side Request Forgery and local file access in Kubernetes Operator",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40564"
    },
    {
      "rank": 42,
      "cve_id": "CVE-2026-9170",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00488,
      "epss_percentile": 0.40061,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "HTTP Server",
      "cwe": "CWE-94",
      "title": "IBM HTTP Server is affected by multiple vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9170"
    },
    {
      "rank": 43,
      "cve_id": "CVE-2026-46624",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00483,
      "epss_percentile": 0.3971,
      "kev": false,
      "kev_due_at": null,
      "vendor": "twentyhq",
      "product": "twenty",
      "cwe": "CWE-78",
      "title": "Twenty: SQL Injection via the timeZone field",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46624"
    },
    {
      "rank": 44,
      "cve_id": "CVE-2026-44723",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00469,
      "epss_percentile": 0.38813,
      "kev": false,
      "kev_due_at": null,
      "vendor": "VowpalWabbit",
      "product": "vowpal_wabbit",
      "cwe": "CWE-78",
      "title": "Vowpal Wabbit: Shell injection via crafted PR title in python_checks.yml allows arbitrary command execution on CI runner",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44723"
    },
    {
      "rank": 45,
      "cve_id": "CVE-2026-8855",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00456,
      "epss_percentile": 0.38011,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "HTTP Server",
      "cwe": "CWE-94",
      "title": "IBM HTTP Server is affected by multiple vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8855"
    },
    {
      "rank": 46,
      "cve_id": "CVE-2026-44449",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00451,
      "epss_percentile": 0.37657,
      "kev": false,
      "kev_due_at": null,
      "vendor": "prolix-oc",
      "product": "Lumiverse",
      "cwe": "CWE-88",
      "title": "Lumiverse: SMB `exists()` basename injection via smbclient `!cmd` escape",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44449"
    },
    {
      "rank": 47,
      "cve_id": "CVE-2026-9538",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00448,
      "epss_percentile": 0.37473,
      "kev": false,
      "kev_due_at": null,
      "vendor": "BINGOS",
      "product": "Archive::Tar",
      "cwe": "CWE-789",
      "title": "Archive::Tar versions before 3.10 for Perl allow memory exhaustion via attacker controlled entry size field in tar header",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9538"
    },
    {
      "rank": 48,
      "cve_id": "CVE-2026-8047",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00445,
      "epss_percentile": 0.37218,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CODESYS",
      "product": "CODESYS Control RTE (SL)",
      "cwe": "CWE-1284",
      "title": "Out-of-bounds Write in CODESYS Control",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8047"
    },
    {
      "rank": 49,
      "cve_id": "CVE-2026-40384",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00445,
      "epss_percentile": 0.37174,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Joomla! Project",
      "product": "Joomla! CMS",
      "cwe": "CWE-22",
      "title": "Joomla! Core - [20260510] - Path traversal in com_media webservice endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40384"
    },
    {
      "rank": 50,
      "cve_id": "CVE-2026-45721",
      "cvss_base": 9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00437,
      "epss_percentile": 0.36563,
      "kev": false,
      "kev_due_at": null,
      "vendor": "xyproto",
      "product": "algernon",
      "cwe": "CWE-20",
      "title": "Algernon: handler.lua discovery walks parent directories above the server root",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45721"
    },
    {
      "rank": 51,
      "cve_id": "CVE-2026-42496",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0043,
      "epss_percentile": 0.36031,
      "kev": false,
      "kev_due_at": null,
      "vendor": "BINGOS",
      "product": "Archive::Tar",
      "cwe": "CWE-59",
      "title": "Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directory",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42496"
    },
    {
      "rank": 52,
      "cve_id": "CVE-2026-9540",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00427,
      "epss_percentile": 0.35816,
      "kev": false,
      "kev_due_at": null,
      "vendor": "vllm-project",
      "product": "vllm",
      "cwe": "CWE-404",
      "title": "vllm-project vllm OpenAI-compatible Serving Path denial of service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9540"
    },
    {
      "rank": 53,
      "cve_id": "CVE-2026-42013",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00423,
      "epss_percentile": 0.35461,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-295",
      "title": "Gnutls: gnutls: certificate validation bypass due to oversized subject alternative name",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42013"
    },
    {
      "rank": 54,
      "cve_id": "CVE-2026-39661",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00418,
      "epss_percentile": 0.35027,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Magentech",
      "product": "SW Core",
      "cwe": "CWE-98",
      "title": "WordPress SW Core plugin <= 1.7.18 - Local File Inclusion vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39661"
    },
    {
      "rank": 55,
      "cve_id": "CVE-2026-42497",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00417,
      "epss_percentile": 0.34953,
      "kev": false,
      "kev_due_at": null,
      "vendor": "BINGOS",
      "product": "Archive::Tar",
      "cwe": "CWE-59",
      "title": "Archive::Tar versions before 3.08 for Perl extract hardlinks to attacker controlled paths outside the extraction directory",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42497"
    },
    {
      "rank": 56,
      "cve_id": "CVE-2026-48593",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00417,
      "epss_percentile": 0.34956,
      "kev": false,
      "kev_due_at": null,
      "vendor": "oban-bg",
      "product": "oban_web",
      "cwe": "CWE-400",
      "title": "Unbounded range expansion in cron describe causes memory exhaustion in oban_web",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48593"
    },
    {
      "rank": 57,
      "cve_id": "CVE-2026-24162",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00416,
      "epss_percentile": 0.34873,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "Merlin Transformers4Rec",
      "cwe": "CWE-502",
      "title": "NVIDIA Transformers4Rec for Linux contains a vulnerability where an attacker could cause improper deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-24162"
    },
    {
      "rank": 58,
      "cve_id": "CVE-2026-44837",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00412,
      "epss_percentile": 0.34516,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ViewComponent",
      "product": "view_component",
      "cwe": "CWE-187",
      "title": "view_component: System Test Entry Point Path Check Allows Sibling Directory Escape",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44837"
    },
    {
      "rank": 59,
      "cve_id": "CVE-2026-44843",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00406,
      "epss_percentile": 0.34001,
      "kev": false,
      "kev_due_at": null,
      "vendor": "langchain-ai",
      "product": "langchain",
      "cwe": "CWE-502",
      "title": "LangChain: Unsafe deserialization of attacker-controlled LangChain objects through overly broad `load()` allowlists",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44843"
    },
    {
      "rank": 60,
      "cve_id": "CVE-2026-9521",
      "cvss_base": 2.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00401,
      "epss_percentile": 0.33463,
      "kev": false,
      "kev_due_at": null,
      "vendor": "fraillt",
      "product": "bitsery",
      "cwe": "CWE-20",
      "title": "fraillt bitsery std_smart_ptr.h loadFromSharedState improper validation of specified type of input",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9521"
    },
    {
      "rank": 61,
      "cve_id": "CVE-2026-44844",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00396,
      "epss_percentile": 0.32954,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GOVCERT-LU",
      "product": "eml_parser",
      "cwe": "CWE-674",
      "title": "eml_parser: Recursion DoS via nested message/rfc822 attachments",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44844"
    },
    {
      "rank": 62,
      "cve_id": "CVE-2026-44895",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00392,
      "epss_percentile": 0.32546,
      "kev": false,
      "kev_due_at": null,
      "vendor": "yoda-digital",
      "product": "mcp-gitlab-server",
      "cwe": "CWE-306",
      "title": "GitLab MCP Server: SSE transport has no authentication and wildcard CORS, exposing all GitLab tools",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44895"
    },
    {
      "rank": 63,
      "cve_id": "CVE-2026-9517",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0039,
      "epss_percentile": 0.32288,
      "kev": false,
      "kev_due_at": null,
      "vendor": "hemant6488",
      "product": "CodeIgniter-StudentManagementSystem",
      "cwe": "CWE-266",
      "title": "hemant6488 CodeIgniter-StudentManagementSystem Student Management addStudentView access control",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9517"
    },
    {
      "rank": 64,
      "cve_id": "CVE-2026-41917",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00387,
      "epss_percentile": 0.32028,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Openkm",
      "product": "OpenKM Community Edition",
      "cwe": "CWE-22",
      "title": "OpenKM 6.3.12 Local File Inclusion via Admin Scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41917"
    },
    {
      "rank": 65,
      "cve_id": "CVE-2026-8606",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00386,
      "epss_percentile": 0.31942,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GitHub",
      "product": "Enterprise Server",
      "cwe": "CWE-918",
      "title": "Server-Side Request Forgery in GitHub Enterprise Server via Advisory Package URL Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8606"
    },
    {
      "rank": 66,
      "cve_id": "CVE-2026-8850",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0038,
      "epss_percentile": 0.31292,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "HTTP Server",
      "cwe": "CWE-476",
      "title": "IBM HTTP Server is affected by multiple vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8850"
    },
    {
      "rank": 67,
      "cve_id": "CVE-2026-44450",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00377,
      "epss_percentile": 0.30951,
      "kev": false,
      "kev_due_at": null,
      "vendor": "prolix-oc",
      "product": "Lumiverse",
      "cwe": "CWE-88",
      "title": "Lumiverse: RCE via MCP stdio argument injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44450"
    },
    {
      "rank": 68,
      "cve_id": "CVE-2026-8174",
      "cvss_base": 5.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00371,
      "epss_percentile": 0.30361,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Zohocorp",
      "product": "Zoho Mail wordpress plugin",
      "cwe": "CWE-352",
      "title": "Cross-site Request Forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8174"
    },
    {
      "rank": 69,
      "cve_id": "CVE-2026-44444",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0037,
      "epss_percentile": 0.30231,
      "kev": false,
      "kev_due_at": null,
      "vendor": "prolix-oc",
      "product": "Lumiverse",
      "cwe": "CWE-78",
      "title": "Lumiverse: Spindle extension install runs untrusted lifecycle scripts before security scan",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44444"
    },
    {
      "rank": 70,
      "cve_id": "CVE-2026-4051",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00369,
      "epss_percentile": 0.30086,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Engineering Lifecycle Management",
      "cwe": "CWE-749",
      "title": "IBM Engineering Lifecycle Management - Jazz Foundation is vulnerable to Server Post-Auth Remote Code Execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-4051"
    },
    {
      "rank": 71,
      "cve_id": "CVE-2026-44668",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00364,
      "epss_percentile": 0.2966,
      "kev": false,
      "kev_due_at": null,
      "vendor": "factionsecurity",
      "product": "faction",
      "cwe": "CWE-306",
      "title": "Faction: Unauthenticated Read, Modify, and Delete of Boilerplate Templates",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44668"
    },
    {
      "rank": 72,
      "cve_id": "CVE-2026-2264",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0036,
      "epss_percentile": 0.292,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google Cloud",
      "product": "Apigee-X",
      "cwe": "CWE-918",
      "title": "Server-Side Request Forgery and Credential Exfiltration in Google Cloud Apigee via SetIntegrationRequest Policy.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-2264"
    },
    {
      "rank": 73,
      "cve_id": "CVE-2026-9495",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0036,
      "epss_percentile": 0.29241,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "@koa/router",
      "cwe": "CWE-284",
      "title": "Versions of the package @koa/router from 14.0.0 and before 15.0.0 are vulnerable to Access Control Bypass due to the middleware being silently dropped from the execution chain when the router prefix contains path parameters. Depending on what the skipped middleware was supposed to protect, an attacker could bypass authentication and authorization, evade rate limiting or bypass input sanitization.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9495"
    },
    {
      "rank": 74,
      "cve_id": "CVE-2026-8854",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00359,
      "epss_percentile": 0.29174,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "HTTP Server",
      "cwe": "CWE-825",
      "title": "IBM HTTP Server is affected by multiple vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8854"
    },
    {
      "rank": 75,
      "cve_id": "CVE-2026-3603",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00354,
      "epss_percentile": 0.28697,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Engineering Lifecycle Management",
      "cwe": "CWE-611",
      "title": "IBM Engineering Lifecycle Management - Jazz Foundation is vulnerable to XML external entity injection (XXE) attack",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-3603"
    },
    {
      "rank": 76,
      "cve_id": "CVE-2026-42012",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00354,
      "epss_percentile": 0.28598,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-295",
      "title": "Gnutls: gnutls: certificate validation bypass due to improper handling of uri and srv sans",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42012"
    },
    {
      "rank": 77,
      "cve_id": "CVE-2026-40034",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00351,
      "epss_percentile": 0.28294,
      "kev": false,
      "kev_due_at": null,
      "vendor": "gitoxide",
      "product": "gitoxide",
      "cwe": "CWE-77",
      "title": "gitoxide - Command Injection via Partial .gitmodules Override in gix-submodule",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40034"
    },
    {
      "rank": 78,
      "cve_id": "CVE-2026-35223",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00348,
      "epss_percentile": 0.27946,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Joomla! Project",
      "product": "Joomla! CMS",
      "cwe": "CWE-284",
      "title": "Joomla! Core - [20260508] - Improper access check in com_config webservice endpoints",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-35223"
    },
    {
      "rank": 79,
      "cve_id": "CVE-2026-8046",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00348,
      "epss_percentile": 0.27962,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CODESYS",
      "product": "CODESYS Control RTE (SL)",
      "cwe": "CWE-863",
      "title": "Incorrect Authorization in CODESYS Control",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8046"
    },
    {
      "rank": 80,
      "cve_id": "CVE-2026-9496",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00346,
      "epss_percentile": 0.27743,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "pacote",
      "cwe": "CWE-1333",
      "title": "Versions of the package pacote from 11.2.7 and before 21.5.1 are vulnerable to Denial of Service (DoS) via the addGitSha function. An attacker can exploit this vulnerability by supplying a specially crafted spec.rawSpec value that triggers the function’s regex replacement and string-manipulation logic, causing excessive CPU consumption and potentially stalling or crashing the process.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9496"
    },
    {
      "rank": 81,
      "cve_id": "CVE-2026-43982",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00344,
      "epss_percentile": 0.2757,
      "kev": false,
      "kev_due_at": null,
      "vendor": "xyproto",
      "product": "algernon",
      "cwe": "CWE-22",
      "title": "Algernon: Path traversal file write via savein()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43982"
    },
    {
      "rank": 82,
      "cve_id": "CVE-2026-44707",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00344,
      "epss_percentile": 0.27534,
      "kev": false,
      "kev_due_at": null,
      "vendor": "chatwoot",
      "product": "chatwoot",
      "cwe": "CWE-283",
      "title": "Chatwoot: Pre-Account Takeover via OAuth on Unconfirmed Accounts",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44707"
    },
    {
      "rank": 83,
      "cve_id": "CVE-2026-44836",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00343,
      "epss_percentile": 0.27462,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ViewComponent",
      "product": "view_component",
      "cwe": "CWE-749",
      "title": "view_component: Preview Route Can Dispatch Inherited Helper Methods",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44836"
    },
    {
      "rank": 84,
      "cve_id": "CVE-2026-9605",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00339,
      "epss_percentile": 0.27006,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GNU",
      "product": "libredwg",
      "cwe": "CWE-119",
      "title": "GNU libredwg Dwgbmp Utility bits.c bit_read_RC heap-based overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9605"
    },
    {
      "rank": 85,
      "cve_id": "CVE-2026-9518",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00336,
      "epss_percentile": 0.2663,
      "kev": false,
      "kev_due_at": null,
      "vendor": "hemant6488",
      "product": "CodeIgniter-StudentManagementSystem",
      "cwe": "CWE-79",
      "title": "hemant6488 CodeIgniter-StudentManagementSystem Students Controller view_students.php addStudent cross site scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9518"
    },
    {
      "rank": 86,
      "cve_id": "CVE-2026-9519",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00336,
      "epss_percentile": 0.26629,
      "kev": false,
      "kev_due_at": null,
      "vendor": "stonith404",
      "product": "pingvin-share",
      "cwe": "CWE-79",
      "title": "stonith404 pingvin-share Sign-in Auto-Redirect signIn.tsx getServerSideProps cross site scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9519"
    },
    {
      "rank": 87,
      "cve_id": "CVE-2026-9520",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00336,
      "epss_percentile": 0.26629,
      "kev": false,
      "kev_due_at": null,
      "vendor": "blitz-js",
      "product": "blitz",
      "cwe": "CWE-79",
      "title": "blitz-js blitz Sign-in LoginForm.tsx cross site scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9520"
    },
    {
      "rank": 88,
      "cve_id": "CVE-2026-9527",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00336,
      "epss_percentile": 0.2663,
      "kev": false,
      "kev_due_at": null,
      "vendor": "itsourcecode",
      "product": "Electronic Judging System",
      "cwe": "CWE-79",
      "title": "itsourcecode Electronic Judging System judges.php cross site scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9527"
    },
    {
      "rank": 89,
      "cve_id": "CVE-2026-48126",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00335,
      "epss_percentile": 0.26535,
      "kev": false,
      "kev_due_at": null,
      "vendor": "xyproto",
      "product": "algernon",
      "cwe": "CWE-22",
      "title": "Algernon: Host header path traversal in --domain mode reads files and runs Lua from parent dir",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48126"
    },
    {
      "rank": 90,
      "cve_id": "CVE-2026-48683",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00331,
      "epss_percentile": 0.26126,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-125",
      "title": "FastNetMon Community Edition through 1.2.9 contains an out-of-bounds read vulnerability in the NetFlow v9 data flowset processor. In src/netflow_plugin/netflow_v9_collector.cpp, the Data template branch (lines 1695-1702) iterates over flow records without performing a per-iteration bounds check against the packet end pointer. In contrast, the Options template branch (lines 1709-1719) correctly checks 'if (pkt + offset + field_template->total_length > packet_end)' before each iteration. The Data branch omits this check entirely. Since template definitions are sent by the network peer (and are unauthenticated UDP), an attacker can craft templates that cause the parser to read arbitrary memory past the packet buffer. This can leak sensitive memory contents or cause a crash.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48683"
    },
    {
      "rank": 91,
      "cve_id": "CVE-2026-9523",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0033,
      "epss_percentile": 0.25961,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Acrel Electrical",
      "product": "EEMS Enterprise Power Operation and Maintenance Cloud Platform",
      "cwe": "CWE-74",
      "title": "Acrel Electrical EEMS Enterprise Power Operation and Maintenance Cloud Platform getCalcmeterDetailDayListTree sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9523"
    },
    {
      "rank": 92,
      "cve_id": "CVE-2026-46740",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00326,
      "epss_percentile": 0.25526,
      "kev": false,
      "kev_due_at": null,
      "vendor": "RRWO",
      "product": "Mojolicious::Plugin::Statsd",
      "cwe": "CWE-93",
      "title": "Mojolicious::Plugin::Statsd versions through 0.04 for Perl allowed metric injections",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46740"
    },
    {
      "rank": 93,
      "cve_id": "CVE-2026-9603",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00325,
      "epss_percentile": 0.25466,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "eDoc Doctor Appointment System",
      "cwe": "CWE-862",
      "title": "SourceCodester eDoc Doctor Appointment System delete-session.php authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9603"
    },
    {
      "rank": 94,
      "cve_id": "CVE-2025-11482",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00322,
      "epss_percentile": 0.25052,
      "kev": false,
      "kev_due_at": null,
      "vendor": "B&R Industrial Automation GmbH",
      "product": "PPT30 Operating System",
      "cwe": "CWE-770",
      "title": "Allocation of Resources Without Limits or Throttling in the OPC-UA Server",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-11482"
    },
    {
      "rank": 95,
      "cve_id": "CVE-2026-35221",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00322,
      "epss_percentile": 0.25091,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Joomla! Project",
      "product": "Joomla! CMS",
      "cwe": "CWE-89",
      "title": "Joomla! Core - [20260506] - Authenticated blind SQLi in com_finder",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-35221"
    },
    {
      "rank": 96,
      "cve_id": "CVE-2026-9525",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00319,
      "epss_percentile": 0.24776,
      "kev": false,
      "kev_due_at": null,
      "vendor": "itsourcecode",
      "product": "Electronic Judging System",
      "cwe": "CWE-74",
      "title": "itsourcecode Electronic Judging System edit_judge.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9525"
    },
    {
      "rank": 97,
      "cve_id": "CVE-2026-9526",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00319,
      "epss_percentile": 0.24777,
      "kev": false,
      "kev_due_at": null,
      "vendor": "itsourcecode",
      "product": "Electronic Judging System",
      "cwe": "CWE-74",
      "title": "itsourcecode Electronic Judging System edit_team.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9526"
    },
    {
      "rank": 98,
      "cve_id": "CVE-2026-9528",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00319,
      "epss_percentile": 0.24776,
      "kev": false,
      "kev_due_at": null,
      "vendor": "itsourcecode",
      "product": "Electronic Judging System",
      "cwe": "CWE-74",
      "title": "itsourcecode Electronic Judging System delete_judge.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9528"
    },
    {
      "rank": 99,
      "cve_id": "CVE-2026-9551",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00318,
      "epss_percentile": 0.24663,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Das",
      "product": "Parking Management System 停车场管理系统",
      "cwe": "CWE-74",
      "title": "Das Parking Management System 停车场管理系统 API Endpoint ExportParkingRecords xp_cmdshell sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9551"
    },
    {
      "rank": 100,
      "cve_id": "CVE-2026-9552",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00318,
      "epss_percentile": 0.24664,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Das",
      "product": "Parking Management System 停车场管理系统",
      "cwe": "CWE-74",
      "title": "Das Parking Management System 停车场管理系统 Search API Endpoint sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9552"
    },
    {
      "rank": 101,
      "cve_id": "CVE-2026-44730",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00316,
      "epss_percentile": 0.24483,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenCTI-Platform",
      "product": "opencti",
      "cwe": "CWE-284",
      "title": "OpenCTI: Privilege escalation via graphQL API abusable by organization admins, due to incorrect ACL on userEdit relationAdd",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44730"
    },
    {
      "rank": 102,
      "cve_id": "CVE-2026-44832",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00315,
      "epss_percentile": 0.24286,
      "kev": false,
      "kev_due_at": null,
      "vendor": "grokability",
      "product": "snipe-it",
      "cwe": "CWE-281",
      "title": "Snipe-IT: Privilege Escalation via API Permissions Assignment",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44832"
    },
    {
      "rank": 103,
      "cve_id": "CVE-2026-44788",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00313,
      "epss_percentile": 0.24119,
      "kev": false,
      "kev_due_at": null,
      "vendor": "adamhathcock",
      "product": "sharpcompress",
      "cwe": "CWE-22",
      "title": "SharpCompress: Directory traversal via directory entries in WriteToDirectory (zip slip variant)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44788"
    },
    {
      "rank": 104,
      "cve_id": "CVE-2025-36220",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0031,
      "epss_percentile": 0.23745,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Cloud Pak for Data System - Cyclops",
      "cwe": "CWE-89",
      "title": "Vulnerabilities exists in IBM Cloud Pak for Data System (CPDS 1.0) - Cyclops.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-36220"
    },
    {
      "rank": 105,
      "cve_id": "CVE-2026-35222",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0031,
      "epss_percentile": 0.23747,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Joomla! Project",
      "product": "Joomla! CMS",
      "cwe": "CWE-89",
      "title": "Joomla! Core - [20260507] - Authenticated blind SQLi in com_tags",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-35222"
    },
    {
      "rank": 106,
      "cve_id": "CVE-2026-48691",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00308,
      "epss_percentile": 0.2353,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-190",
      "title": "FastNetMon Community Edition through 1.2.9 contains an integer overflow in the BGP AS_PATH attribute encoder. In src/bgp_protocol.hpp, the IPv4UnicastAnnounce::get_attributes() function computes attribute_length as 'sizeof(bgp_as_path_segment_element_t) + this->as_path_asns.size() * sizeof(uint32_t)' and stores it in a uint8_t field (line 600-605). Since uint8_t can only hold values 0-255, an AS_PATH containing more than 63 ASNs (2 + 64*4 = 258 > 255) causes silent truncation. The truncated length is used for buffer sizing, while the actual data written is the full untruncated amount, resulting in a heap buffer overflow. Similarly, the path_segment_length field at line 621 is also uint8_t, truncating with more than 255 ASNs.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48691"
    },
    {
      "rank": 107,
      "cve_id": "CVE-2026-45728",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00303,
      "epss_percentile": 0.22932,
      "kev": false,
      "kev_due_at": null,
      "vendor": "xyproto",
      "product": "algernon",
      "cwe": "CWE-209",
      "title": "Algernon: Single-file mode unconditionally enables debug mode",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45728"
    },
    {
      "rank": 108,
      "cve_id": "CVE-2026-45082",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.003,
      "epss_percentile": 0.22684,
      "kev": false,
      "kev_due_at": null,
      "vendor": "karakeep-app",
      "product": "karakeep",
      "cwe": "CWE-918",
      "title": "Karakeep has a SSRF Protection Bypass via Redirect Handling",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45082"
    },
    {
      "rank": 109,
      "cve_id": "CVE-2026-48896",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00297,
      "epss_percentile": 0.22307,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Joomla! Project",
      "product": "Joomla! CMS",
      "cwe": "CWE-287",
      "title": "Joomla! Core - [20260511] - MFA Authentication Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48896"
    },
    {
      "rank": 110,
      "cve_id": "CVE-2026-43935",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00297,
      "epss_percentile": 0.22337,
      "kev": false,
      "kev_due_at": null,
      "vendor": "e107inc",
      "product": "e107",
      "cwe": "CWE-20",
      "title": "e107: Host Header Injection in e107 password reset enables phishing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43935"
    },
    {
      "rank": 111,
      "cve_id": "CVE-2026-48685",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00295,
      "epss_percentile": 0.2217,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-130",
      "title": "FastNetMon Community Edition through 1.2.9 has out-of-bounds memory access because it incorrectly parses BGP path attributes with the extended length flag set. In src/bgp_protocol.hpp, the parse_raw_bgp_attribute() function correctly identifies when extended_length_bit is set and sets length_of_length_field to 2, but then reads only a single byte for the attribute value length (attribute_value_length = value[2] at line 173). Per RFC 4271 Section 4.3, when the Extended Length bit is set, the Attribute Length field is two octets and the value should be read as a 16-bit big-endian integer from value[2] and value[3]. As a result, any attribute longer than 255 bytes has its length silently truncated to the low byte (e.g., 300 bytes = 0x012C is read as 0x2C = 44 bytes). The remaining 256 bytes are then misinterpreted as subsequent attributes, causing cascading parse failures and potential out-of-bounds memory access.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48685"
    },
    {
      "rank": 112,
      "cve_id": "CVE-2026-48904",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00292,
      "epss_percentile": 0.21787,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Joomla! Project",
      "product": "Joomla! CMS",
      "cwe": "CWE-284",
      "title": "Joomla! Core - [20260514] - Privilege escalation through com_users webservice endpoints",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48904"
    },
    {
      "rank": 113,
      "cve_id": "CVE-2026-9580",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00291,
      "epss_percentile": 0.21666,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "JeecgBoot",
      "cwe": "CWE-266",
      "title": "JeecgBoot selectDepart LoginController.selectDepart access control",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9580"
    },
    {
      "rank": 114,
      "cve_id": "CVE-2026-9562",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00288,
      "epss_percentile": 0.21385,
      "kev": false,
      "kev_due_at": null,
      "vendor": "sambitraj",
      "product": "STUDENT-MANAGEMENT-SYSTEM",
      "cwe": "CWE-266",
      "title": "sambitraj STUDENT-MANAGEMENT-SYSTEM Dashboard access control",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9562"
    },
    {
      "rank": 115,
      "cve_id": "CVE-2026-44502",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00286,
      "epss_percentile": 0.2121,
      "kev": false,
      "kev_due_at": null,
      "vendor": "bugsink",
      "product": "bugsink",
      "cwe": "CWE-918",
      "title": "Bugsink: SSRF bypass in `validate_webhook_url`",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44502"
    },
    {
      "rank": 116,
      "cve_id": "CVE-2026-48688",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00283,
      "epss_percentile": 0.20844,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-125",
      "title": "FastNetMon Community Edition through 1.2.9 contains multiple out-of-bounds reads in the BGP MP_REACH_NLRI IPv6 attribute decoder. The function decode_mp_reach_ipv6() in src/bgp_protocol.cpp contains a TODO comment at line 156 explicitly acknowledging 'we should add sanity checks to avoid reads after attribute memory block.' The function casts raw pointers to structure types without verifying sufficient data exists (line 158), uses the attacker-controlled length_of_next_hop field to determine memcpy size (line 181), and computes prefix_length by dereferencing a pointer calculated from multiple attacker-controlled offsets without bounds validation (line 189). The prefix_length is then used to calculate number_of_bytes_required_for_prefix which becomes a memcpy length (line 202) with no check against remaining buffer size.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48688"
    },
    {
      "rank": 117,
      "cve_id": "CVE-2026-9566",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00282,
      "epss_percentile": 0.20731,
      "kev": false,
      "kev_due_at": null,
      "vendor": "teableio",
      "product": "teable",
      "cwe": "CWE-79",
      "title": "teableio teable Sign-up LoginPage.tsx cross site scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9566"
    },
    {
      "rank": 118,
      "cve_id": "CVE-2026-44775",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00281,
      "epss_percentile": 0.20621,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Kareadita",
      "product": "Kavita",
      "cwe": "CWE-306",
      "title": "Kavita: No authentication at /api/Reader/image",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44775"
    },
    {
      "rank": 119,
      "cve_id": "CVE-2026-8620",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00279,
      "epss_percentile": 0.20497,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Web Server Plug-ins for WebSphere Application Server and WebSphere Liberty",
      "cwe": "CWE-444",
      "title": "IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by multiple vulnerabilities when using when using Web Server Plug-ins",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8620"
    },
    {
      "rank": 120,
      "cve_id": "CVE-2026-44214",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00277,
      "epss_percentile": 0.20196,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rexxars",
      "product": "eventsource-encoder",
      "cwe": "CWE-93",
      "title": "eventsource-encoder: SSE event injection via unsanitized event and id fields",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44214"
    },
    {
      "rank": 121,
      "cve_id": "CVE-2026-44847",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00271,
      "epss_percentile": 0.19398,
      "kev": false,
      "kev_due_at": null,
      "vendor": "1Panel-dev",
      "product": "MaxKB",
      "cwe": "CWE-287",
      "title": "MaxKB: Webhook Trigger Authentication Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44847"
    },
    {
      "rank": 122,
      "cve_id": "CVE-2025-36221",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00269,
      "epss_percentile": 0.1911,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Cloud Pak for Data System - Cyclops",
      "cwe": "CWE-1392",
      "title": "Vulnerabilities exists in IBM Cloud Pak for Data System (CPDS 1.0) - Cyclops.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-36221"
    },
    {
      "rank": 123,
      "cve_id": "CVE-2026-48898",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00268,
      "epss_percentile": 0.19084,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Joomla! Project",
      "product": "Joomla! CMS",
      "cwe": "CWE-284",
      "title": "Joomla! Core - [20260513] - Privilege escalation through com_users batch task",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48898"
    },
    {
      "rank": 124,
      "cve_id": "CVE-2026-48684",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00264,
      "epss_percentile": 0.18418,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-125",
      "title": "FastNetMon Community Edition through 1.2.9 contains an out-of-bounds read in the NetFlow v9 options template parser. In process_netflow_v9_options_template() (src/netflow_plugin/netflow_v9_collector.cpp), the scope parsing loop (lines 224-229) iterates until scopes_offset reaches the attacker-controlled option_scope_length value, reading netflow9_template_flowset_record_t structures at each step. No bounds check validates that (zone_address + scopes_offset + sizeof(record)) stays within the flowset. The same issue affects the options field loop (lines 241-257) with option_length. Furthermore, option_scope_length is not validated to be a multiple of sizeof(netflow9_template_flowset_record_t), potentially causing misaligned reads. An attacker can trigger reads past the end of the UDP packet buffer.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48684"
    },
    {
      "rank": 125,
      "cve_id": "CVE-2025-71310",
      "cvss_base": 1.8,
      "cvss_severity": "LOW",
      "epss_score": 0.00264,
      "epss_percentile": 0.18452,
      "kev": false,
      "kev_due_at": null,
      "vendor": "BackdropCMS",
      "product": "GDPR cookies module for Backdrop CMS",
      "cwe": "CWE-80",
      "title": "The GDPR cookies module for Backdrop CMS (before 1.x-1.3.5) doesn't sufficiently protect visitors from Cross Site Scripting (XSS) if a malicious value has been provided for the optional 'Info content' field for the YouTube service. This is mitigated by the fact that an attacker must have a role with the permission \"Create a GDPR Cookies Service\" or \"Edit any GDPR Cookies Service\" and a site must have added a YouTube service as configuration.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-71310"
    },
    {
      "rank": 126,
      "cve_id": "CVE-2026-8834",
      "cvss_base": 8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0026,
      "epss_percentile": 0.1787,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "HTTP Server",
      "cwe": "CWE-122",
      "title": "IBM HTTP Server is affected by multiple vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8834"
    },
    {
      "rank": 127,
      "cve_id": "CVE-2026-9544",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00259,
      "epss_percentile": 0.17809,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Shenzhen Sixun Software",
      "product": "Sixun Shanghui Group Business Management System",
      "cwe": "CWE-74",
      "title": "Shenzhen Sixun Software Sixun Shanghui Group Business Management System PayConfig sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9544"
    },
    {
      "rank": 128,
      "cve_id": "CVE-2026-9573",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00259,
      "epss_percentile": 0.17818,
      "kev": false,
      "kev_due_at": null,
      "vendor": "itsourcecode",
      "product": "Student Transcript Processing System",
      "cwe": "CWE-74",
      "title": "itsourcecode Student Transcript Processing System index.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9573"
    },
    {
      "rank": 129,
      "cve_id": "CVE-2026-9574",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00259,
      "epss_percentile": 0.17819,
      "kev": false,
      "kev_due_at": null,
      "vendor": "itsourcecode",
      "product": "Student Transcript Processing System",
      "cwe": "CWE-74",
      "title": "itsourcecode Student Transcript Processing System trans.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9574"
    },
    {
      "rank": 130,
      "cve_id": "CVE-2026-9575",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00259,
      "epss_percentile": 0.17813,
      "kev": false,
      "kev_due_at": null,
      "vendor": "itsourcecode",
      "product": "Student Transcript Processing System",
      "cwe": "CWE-74",
      "title": "itsourcecode Student Transcript Processing System index.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9575"
    },
    {
      "rank": 131,
      "cve_id": "CVE-2026-44729",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00258,
      "epss_percentile": 0.17661,
      "kev": false,
      "kev_due_at": null,
      "vendor": "twentyhq",
      "product": "twenty",
      "cwe": "CWE-79",
      "title": "Twenty: Stored Cross-Site Scripting via Unsanitized File Serving (Missing Content-Type/Content-Disposition Headers)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44729"
    },
    {
      "rank": 132,
      "cve_id": "CVE-2026-44749",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00258,
      "epss_percentile": 0.17668,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SAP_SE",
      "product": "SAP Gateway",
      "cwe": "CWE-497",
      "title": "Information Disclosure vulnerability in SAP Gateway",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44749"
    },
    {
      "rank": 133,
      "cve_id": "CVE-2026-39642",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00255,
      "epss_percentile": 0.17318,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SpabRice",
      "product": "Nyla",
      "cwe": "CWE-80",
      "title": "WordPress Nyla theme <= 1.7 - Arbitrary Shortcode Execution vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39642"
    },
    {
      "rank": 134,
      "cve_id": "CVE-2026-9584",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00254,
      "epss_percentile": 0.17157,
      "kev": false,
      "kev_due_at": null,
      "vendor": "code-projects",
      "product": "Project Management System",
      "cwe": "CWE-74",
      "title": "code-projects Project Management System Login chk.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9584"
    },
    {
      "rank": 135,
      "cve_id": "CVE-2026-9606",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00254,
      "epss_percentile": 0.17157,
      "kev": false,
      "kev_due_at": null,
      "vendor": "itsourcecode",
      "product": "Courier Management System",
      "cwe": "CWE-74",
      "title": "itsourcecode Courier Management System manage_user.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9606"
    },
    {
      "rank": 136,
      "cve_id": "CVE-2026-48902",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00252,
      "epss_percentile": 0.16849,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Joomla! Project",
      "product": "Joomla! CMS",
      "cwe": "CWE-319",
      "title": "Joomla! Core - [20260518] - Transport encryption downgrade for password and username reset links",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48902"
    },
    {
      "rank": 137,
      "cve_id": "CVE-2026-8835",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00252,
      "epss_percentile": 0.16913,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "HTTP Server",
      "cwe": "CWE-822",
      "title": "IBM HTTP Server is affected by multiple vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8835"
    },
    {
      "rank": 138,
      "cve_id": "CVE-2026-44776",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0025,
      "epss_percentile": 0.16711,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Kareadita",
      "product": "Kavita",
      "cwe": "CWE-639",
      "title": "Kavita: IDOR in /api/Download/*",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44776"
    },
    {
      "rank": 139,
      "cve_id": "CVE-2025-14361",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00248,
      "epss_percentile": 0.164,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AA-Team",
      "product": "Woocommerce Envato Affiliates",
      "cwe": "CWE-862",
      "title": "WordPress Woocommerce Envato Affiliates plugin <= 1.2.1 - Settings Change vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-14361"
    },
    {
      "rank": 140,
      "cve_id": "CVE-2026-36239",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00247,
      "epss_percentile": 0.16319,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-79",
      "title": "PbootCMS v.3.2.11 contains a code injection vulnerability in its site configuration functionality",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-36239"
    },
    {
      "rank": 141,
      "cve_id": "CVE-2026-9524",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00246,
      "epss_percentile": 0.16125,
      "kev": false,
      "kev_due_at": null,
      "vendor": "xianrendzw",
      "product": "EasyReport",
      "cwe": "CWE-74",
      "title": "xianrendzw EasyReport REST Endpoint execute sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9524"
    },
    {
      "rank": 142,
      "cve_id": "CVE-2026-24590",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00246,
      "epss_percentile": 0.16153,
      "kev": false,
      "kev_due_at": null,
      "vendor": "VideoWhisper.com",
      "product": "Paid Videochat Turnkey Site",
      "cwe": "CWE-862",
      "title": "WordPress Paid Videochat Turnkey Site plugin <= 7.3.23 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-24590"
    },
    {
      "rank": 143,
      "cve_id": "CVE-2026-48901",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00245,
      "epss_percentile": 0.16023,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Joomla! Project",
      "product": "Joomla! CMS",
      "cwe": "CWE-524",
      "title": "Joomla! Core - [20260517] - Incorrect Cache Key Construction for InputFilter objects",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48901"
    },
    {
      "rank": 144,
      "cve_id": "CVE-2026-9583",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00242,
      "epss_percentile": 0.15632,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "CET Automated Grading System with AI Predictive Analytics",
      "cwe": "CWE-200",
      "title": "SourceCodester CET Automated Grading System with AI Predictive Analytics SQL index.php information exposure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9583"
    },
    {
      "rank": 145,
      "cve_id": "CVE-2026-48694",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00234,
      "epss_percentile": 0.14563,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-77",
      "title": "FastNetMon Community Edition through 1.2.9 contains a configuration injection vulnerability in the Juniper router integration plugin. In src/juniper_plugin/fastnetmon_juniper.php, the $IP_ATTACK variable (received from argv[1]) is directly interpolated into Juniper NETCONF set-configuration commands at lines 69 and 90 without any validation or sanitization. Line 69: $conn->load_set_configuration(\"set routing-options static route {$IP_ATTACK} community 65535:666 discard\"). Line 90: $conn->load_set_configuration(\"delete routing-options static route {$IP_ATTACK}/32\"). An attacker who can control the IP address string can inject additional Juniper CLI configuration commands by embedding newline characters followed by arbitrary set/delete commands. This could modify the router's routing table, firewall filters, user accounts, or any other configuration element accessible via NETCONF. The impact is full router compromise.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48694"
    },
    {
      "rank": 146,
      "cve_id": "CVE-2026-4795",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00234,
      "epss_percentile": 0.1452,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Zyxel",
      "product": "GS1200-5v3 firmware",
      "cwe": "CWE-862",
      "title": "A missing authorization vulnerability in Zyxel GS1200-5v3 firmware versions through 1.00(ACPS.2)C0, GS1200-8v3 firmware versions through 1.00(ACPT.2)C0, GS1200-5HPv3 firmware versions through 1.00(ACPU.2)C0, GS1200-8HPv3 firmware versions through 1.00(ACPV.2)C0, and GS1200-10v3 firmware versions through 1.00(ACPW.2)C0 could allow a LAN-based, unauthenticated attacker to read the system configuration from a log file via a crafted HTTP request.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-4795"
    },
    {
      "rank": 147,
      "cve_id": "CVE-2026-48899",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00234,
      "epss_percentile": 0.14608,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Joomla! Project",
      "product": "Joomla! CMS",
      "cwe": "CWE-284",
      "title": "Joomla! Core - [20260515] - Incorrect Access Control in sample data plugins",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48899"
    },
    {
      "rank": 148,
      "cve_id": "CVE-2026-48692",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00233,
      "epss_percentile": 0.14438,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-306",
      "title": "FastNetMon Community Edition through 1.2.9 exposes a gRPC API server on port 50052 with no authentication mechanism. The server is initialized with grpc::InsecureServerCredentials() (src/fastnetmon.cpp line 477) and a source code comment explicitly acknowledges 'Listen on the given address without any authentication mechanism.' None of the RPC methods in src/api.cpp (ExecuteBan, ExecuteUnBan, GetBanlist, GetTotalTrafficCounters, etc.) perform any credential verification. The ExecuteBan and ExecuteUnBan methods trigger security-critical actions: BGP route announcements that can blackhole network traffic, and execution of external notification scripts via popen(). An attacker with local network access can ban arbitrary IP addresses (causing denial of service to legitimate traffic), unban active attacks (disabling DDoS mitigation), and trigger script execution. There is also no role-based access control separating read-only monitoring from destructive administrative operations.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48692"
    },
    {
      "rank": 149,
      "cve_id": "CVE-2026-42335",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00232,
      "epss_percentile": 0.14368,
      "kev": false,
      "kev_due_at": null,
      "vendor": "1Panel-dev",
      "product": "MaxKB",
      "cwe": "CWE-918",
      "title": "MaxKB: SSRF Bypass in MaxKB OSS URL Fetch due to URL Parsing Discrepancy",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42335"
    },
    {
      "rank": 150,
      "cve_id": "CVE-2026-39655",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00231,
      "epss_percentile": 0.14251,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TeconceTheme",
      "product": "Mayosis Core",
      "cwe": "CWE-862",
      "title": "WordPress Mayosis Core plugin <= 5.4.7 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39655"
    },
    {
      "rank": 151,
      "cve_id": "CVE-2026-44451",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0023,
      "epss_percentile": 0.1409,
      "kev": false,
      "kev_due_at": null,
      "vendor": "prolix-oc",
      "product": "Lumiverse",
      "cwe": "CWE-693",
      "title": "Lumiverse: TSX component sandbox escape via DOM ref and string-split identifier bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44451"
    },
    {
      "rank": 152,
      "cve_id": "CVE-2026-44708",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00228,
      "epss_percentile": 0.13837,
      "kev": false,
      "kev_due_at": null,
      "vendor": "lepture",
      "product": "mistune",
      "cwe": "CWE-79",
      "title": "Mistune Math Plugin XSS Escape Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44708"
    },
    {
      "rank": 153,
      "cve_id": "CVE-2026-44897",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00228,
      "epss_percentile": 0.13839,
      "kev": false,
      "kev_due_at": null,
      "vendor": "lepture",
      "product": "mistune",
      "cwe": "CWE-79",
      "title": "Mistune Heading ID Attribute Injection XSS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44897"
    },
    {
      "rank": 154,
      "cve_id": "CVE-2026-44898",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00228,
      "epss_percentile": 0.13838,
      "kev": false,
      "kev_due_at": null,
      "vendor": "lepture",
      "product": "mistune",
      "cwe": "CWE-79",
      "title": "Mistune TOC Anchor Injection XSS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44898"
    },
    {
      "rank": 155,
      "cve_id": "CVE-2026-44899",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00228,
      "epss_percentile": 0.13838,
      "kev": false,
      "kev_due_at": null,
      "vendor": "lepture",
      "product": "mistune",
      "cwe": "CWE-79",
      "title": "Mistune Image Directive CSS Injection Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44899"
    },
    {
      "rank": 156,
      "cve_id": "CVE-2026-44706",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00227,
      "epss_percentile": 0.13648,
      "kev": false,
      "kev_due_at": null,
      "vendor": "chatwoot",
      "product": "chatwoot",
      "cwe": "CWE-89",
      "title": "Chatwoot: SQL Injection in Conversation/Contact Filter API via Custom Attribute Values",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44706"
    },
    {
      "rank": 157,
      "cve_id": "CVE-2026-48864",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00227,
      "epss_percentile": 0.13654,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-787",
      "title": "Libsolv: heap buffer overflow in libsolv repopagestore via unchecked decompression of malicious .solv page data",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48864"
    },
    {
      "rank": 158,
      "cve_id": "CVE-2026-8647",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00222,
      "epss_percentile": 0.1307,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MIK",
      "product": "Crypt::ScryptKDF",
      "cwe": "CWE-338",
      "title": "Crypt::ScryptKDF versions through 0.010 for Perl uses insecure random number source when no CSPRNG module is available",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8647"
    },
    {
      "rank": 159,
      "cve_id": "CVE-2026-9604",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00222,
      "epss_percentile": 0.13042,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "JeecgBoot",
      "cwe": "CWE-266",
      "title": "JeecgBoot AiragModelController access control",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9604"
    },
    {
      "rank": 160,
      "cve_id": "CVE-2026-24190",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00221,
      "epss_percentile": 0.12917,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "GeForce",
      "cwe": "CWE-862",
      "title": "NVIDIA Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where a user could cause improper access to GPU resources. A successful exploit of this vulnerability might lead to denial of service, escalation of privileges, information disclosure, data tampering, and code execution.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-24190"
    },
    {
      "rank": 161,
      "cve_id": "CVE-2026-38587",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00221,
      "epss_percentile": 0.12938,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-639",
      "title": "An Insecure Direct Object Reference (IDOR) vulnerability was discovered in ONLYOFFICE DocSpace before 3.2.1. The flaw exists in multiple REST API endpoints. This allows authenticated users with low-level permissions (User or Guest) to retrieve sensitive information, such as the Owner's unique identifier (ID) and profile information, which should only be accessible to administrators.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-38587"
    },
    {
      "rank": 162,
      "cve_id": "CVE-2026-46431",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00219,
      "epss_percentile": 0.12678,
      "kev": false,
      "kev_due_at": null,
      "vendor": "xyproto",
      "product": "algernon",
      "cwe": "CWE-942",
      "title": "Algernon: Auto-refresh SSE event server sets Access-Control-Allow-Origin: *",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46431"
    },
    {
      "rank": 163,
      "cve_id": "CVE-2026-9568",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00219,
      "epss_percentile": 0.12662,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "ThingsBoard",
      "cwe": "CWE-74",
      "title": "ThingsBoard YAML provision getGatewayDockerComposeFile code injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9568"
    },
    {
      "rank": 164,
      "cve_id": "CVE-2026-44831",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00218,
      "epss_percentile": 0.12544,
      "kev": false,
      "kev_due_at": null,
      "vendor": "grokability",
      "product": "snipe-it",
      "cwe": "CWE-79",
      "title": "Snipe-IT: XSS vulnerability in component notes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44831"
    },
    {
      "rank": 165,
      "cve_id": "CVE-2026-24638",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00217,
      "epss_percentile": 0.12486,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Webful Creations",
      "product": "RepairBuddy",
      "cwe": "CWE-862",
      "title": "WordPress RepairBuddy plugin <= 4.1121 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-24638"
    },
    {
      "rank": 166,
      "cve_id": "CVE-2026-44667",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00211,
      "epss_percentile": 0.11687,
      "kev": false,
      "kev_due_at": null,
      "vendor": "factionsecurity",
      "product": "faction",
      "cwe": "CWE-79",
      "title": "Faction: Stored XSS in Remediation Verification Attachment Filename Preview Rendering",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44667"
    },
    {
      "rank": 167,
      "cve_id": "CVE-2026-44669",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00211,
      "epss_percentile": 0.11687,
      "kev": false,
      "kev_due_at": null,
      "vendor": "factionsecurity",
      "product": "faction",
      "cwe": "CWE-79",
      "title": "Faction: Stored XSS in Assessment Attachment Filename Preview Rendering",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44669"
    },
    {
      "rank": 168,
      "cve_id": "CVE-2026-48897",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00211,
      "epss_percentile": 0.11721,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Joomla! Project",
      "product": "Joomla! CMS",
      "cwe": "CWE-287",
      "title": "Joomla! Core - [20260512] - MFA Authentication Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48897"
    },
    {
      "rank": 169,
      "cve_id": "CVE-2026-9579",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00209,
      "epss_percentile": 0.11437,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "JeecgBoot",
      "cwe": "CWE-266",
      "title": "JeecgBoot SysUser userEdit user.getUsername access control",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9579"
    },
    {
      "rank": 170,
      "cve_id": "CVE-2026-9581",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00209,
      "epss_percentile": 0.11439,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "JeecgBoot",
      "cwe": "CWE-266",
      "title": "JeecgBoot add access control",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9581"
    },
    {
      "rank": 171,
      "cve_id": "CVE-2026-25104",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00207,
      "epss_percentile": 0.1107,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MediaArea",
      "product": "MediaInfoLib",
      "cwe": "CWE-191",
      "title": "MediaArea MediaInfoLib LXF parsing heap-based buffer overflow vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-25104"
    },
    {
      "rank": 172,
      "cve_id": "CVE-2026-25713",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00207,
      "epss_percentile": 0.11069,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MediaArea",
      "product": "MediaInfoLib",
      "cwe": "CWE-122",
      "title": "MediaArea MediaInfoLib ID3v2 parsing heap buffer overflow vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-25713"
    },
    {
      "rank": 173,
      "cve_id": "CVE-2026-44213",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00207,
      "epss_percentile": 0.11118,
      "kev": false,
      "kev_due_at": null,
      "vendor": "open-telemetry",
      "product": "opentelemetry-dotnet-contrib",
      "cwe": "CWE-295",
      "title": "OpenTelemetry.Exporter.Instana bypasses TLS certificate validation when a proxy is configured",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44213"
    },
    {
      "rank": 174,
      "cve_id": "CVE-2026-45412",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00207,
      "epss_percentile": 0.11119,
      "kev": false,
      "kev_due_at": null,
      "vendor": "1Panel-dev",
      "product": "MaxKB",
      "cwe": "CWE-918",
      "title": "MaxKB: Unauthenticated SSRF via Workflow Template Import",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45412"
    },
    {
      "rank": 175,
      "cve_id": "CVE-2026-42337",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00207,
      "epss_percentile": 0.11124,
      "kev": false,
      "kev_due_at": null,
      "vendor": "1Panel-dev",
      "product": "MaxKB",
      "cwe": "CWE-862",
      "title": "MaxKB: Broken Access Control in MaxKB OSS URL Fetch API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42337"
    },
    {
      "rank": 176,
      "cve_id": "CVE-2026-24192",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00206,
      "epss_percentile": 0.10936,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "GeForce",
      "cwe": "CWE-681",
      "title": "NVIDIA Display Driver for Linux contains a vulnerability where an attacker could cause an incorrect conversion between numeric types, leading to a heap buffer overflow. A successful exploit of this vulnerability might lead to denial of service, escalation of privileges, information disclosure, data tampering, and code execution.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-24192"
    },
    {
      "rank": 177,
      "cve_id": "CVE-2026-8676",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00202,
      "epss_percentile": 0.10536,
      "kev": false,
      "kev_due_at": null,
      "vendor": "silabs.com",
      "product": "Simplicity SDK",
      "cwe": "CWE-290",
      "title": "An attacker is able to downgrade the security of a Bluetooth LE connection by deleting an existing bond, spoofing the bonded device and creating a new bond.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8676"
    },
    {
      "rank": 178,
      "cve_id": "CVE-2026-44905",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00202,
      "epss_percentile": 0.10509,
      "kev": false,
      "kev_due_at": null,
      "vendor": "riebl",
      "product": "vanetza",
      "cwe": "CWE-248",
      "title": "Vanetza: Remote Denial of Service via Uncaught OER Encoding Exception in Cryptographic Verification",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44905"
    },
    {
      "rank": 179,
      "cve_id": "CVE-2026-9564",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00202,
      "epss_percentile": 0.10465,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "Hospitals Patient Records Management System",
      "cwe": "CWE-79",
      "title": "SourceCodester/oretnom23 Hospitals Patient Records Management System view_patient cross site scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9564"
    },
    {
      "rank": 180,
      "cve_id": "CVE-2026-44896",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00198,
      "epss_percentile": 0.09993,
      "kev": false,
      "kev_due_at": null,
      "vendor": "lepture",
      "product": "mistune",
      "cwe": "CWE-79",
      "title": "Mistune: XSS via unescaped figclass/figwidth in Figure directive",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44896"
    },
    {
      "rank": 181,
      "cve_id": "CVE-2026-8856",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00197,
      "epss_percentile": 0.09789,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "HTTP Server",
      "cwe": "CWE-400",
      "title": "IBM HTTP Server is affected by multiple vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8856"
    },
    {
      "rank": 182,
      "cve_id": "CVE-2026-24193",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00197,
      "epss_percentile": 0.09895,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "GeForce",
      "cwe": "CWE-787",
      "title": "NVIDIA Display Driver for Windows and Linux contains a vulnerability where an attacker could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to denial of service, escalation of privileges, information disclosure, data tampering, and code execution.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-24193"
    },
    {
      "rank": 183,
      "cve_id": "CVE-2026-8852",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00197,
      "epss_percentile": 0.0979,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "HTTP Server",
      "cwe": "CWE-617",
      "title": "IBM HTTP Server is affected by multiple vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8852"
    },
    {
      "rank": 184,
      "cve_id": "CVE-2026-46430",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00197,
      "epss_percentile": 0.09832,
      "kev": false,
      "kev_due_at": null,
      "vendor": "xyproto",
      "product": "algernon",
      "cwe": "CWE-668",
      "title": "Algernon: Auto-refresh SSE event server binds to all interfaces by default on Linux/macOS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46430"
    },
    {
      "rank": 185,
      "cve_id": "CVE-2026-42448",
      "cvss_base": 3.5,
      "cvss_severity": "LOW",
      "epss_score": 0.00197,
      "epss_percentile": 0.09757,
      "kev": false,
      "kev_due_at": null,
      "vendor": "magic-wormhole",
      "product": "magic-wormhole",
      "cwe": "CWE-22",
      "title": "wormhole receive, with --output pointing at an existing directory can be path-traversed",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42448"
    },
    {
      "rank": 186,
      "cve_id": "CVE-2026-9542",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00196,
      "epss_percentile": 0.09745,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CodeAstro",
      "product": "Leave Management System",
      "cwe": "CWE-74",
      "title": "CodeAstro Leave Management System add_staff.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9542"
    },
    {
      "rank": 187,
      "cve_id": "CVE-2026-44985",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00195,
      "epss_percentile": 0.0962,
      "kev": false,
      "kev_due_at": null,
      "vendor": "amir20",
      "product": "dozzle",
      "cwe": "CWE-346",
      "title": "Dozzle: Cross-Site WebSocket Hijacking (CSWSH) on exec/attach endpoints bypasses authentication",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44985"
    },
    {
      "rank": 188,
      "cve_id": "CVE-2025-36148",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00193,
      "epss_percentile": 0.09354,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Financial Transaction Manager for SWIFT Services for Multiplatforms",
      "cwe": "CWE-79",
      "title": "IBM Financial Transaction Manager for SWIFT Services for Multiplatforms is vulnerable to cross-site scripting.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-36148"
    },
    {
      "rank": 189,
      "cve_id": "CVE-2026-43936",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00193,
      "epss_percentile": 0.09332,
      "kev": false,
      "kev_due_at": null,
      "vendor": "e107inc",
      "product": "e107",
      "cwe": "CWE-918",
      "title": "e107: Server-Side Request Forgery (SSRF) in the remote file fetcher",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43936"
    },
    {
      "rank": 190,
      "cve_id": "CVE-2026-25426",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00191,
      "epss_percentile": 0.09122,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Magepeople inc.",
      "product": "Taxi Booking Manager for WooCommerce",
      "cwe": "CWE-862",
      "title": "WordPress Taxi Booking Manager for WooCommerce plugin <= 2.0.1 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-25426"
    },
    {
      "rank": 191,
      "cve_id": "CVE-2025-68708",
      "cvss_base": 2.4,
      "cvss_severity": "LOW",
      "epss_score": 0.0019,
      "epss_percentile": 0.08967,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-288",
      "title": "SailingLab AppLock (aka com.alpha.applock) 4.3.8 for Android allows a local attacker with physical access to bypass the PIN lock. The lock is implemented as an overlay rather than by using Android's secure authentication APIs. By navigating cascading interface flows - insecure navigation through exposed routes facilitates app control evasion {I.N.T.E.R.F.A.C.E] via advertisement or browser intents - an attacker can evade lockscreen verification and access protected apps (e.g., Chrome). This results in information disclosure and privilege escalation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-68708"
    },
    {
      "rank": 192,
      "cve_id": "CVE-2026-24187",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00188,
      "epss_percentile": 0.08759,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "GeForce",
      "cwe": "CWE-416",
      "title": "NVIDIA Display Driver for Linux contains a vulnerability where an attacker could cause a use-after-free. A successful exploit of this vulnerability might lead to denial of service, escalation of privileges, information disclosure, data tampering, and code execution.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-24187"
    },
    {
      "rank": 193,
      "cve_id": "CVE-2026-42336",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00187,
      "epss_percentile": 0.0862,
      "kev": false,
      "kev_due_at": null,
      "vendor": "1Panel-dev",
      "product": "MaxKB",
      "cwe": "CWE-367",
      "title": "MaxKB: SSRF Bypass via DNS Rebinding in MaxKB OSS URL Fetch",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42336"
    },
    {
      "rank": 194,
      "cve_id": "CVE-2025-68711",
      "cvss_base": 2.4,
      "cvss_severity": "LOW",
      "epss_score": 0.00186,
      "epss_percentile": 0.08505,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-288",
      "title": "AppLockZ App Lock and Fingerprint Lock (applock.passwordfingerprint.applockz) 4.2.11 for Android allows a local attacker with physical access to bypass the PIN lock. The lock is implemented as an overlay rather than by using Android's secure authentication APIs. By navigating cascading interface flows - insecure navigation through exposed routes facilitates app control evasion {I.N.T.E.R.F.A.C.E] via advertisement or browser intents, an attacker can evade lockscreen verification and access protected apps (e.g., Chrome). This results in information disclosure and privilege escalation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-68711"
    },
    {
      "rank": 195,
      "cve_id": "CVE-2025-36126",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00185,
      "epss_percentile": 0.08372,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Cognos Analytics",
      "cwe": "CWE-79",
      "title": "IBM Cognos Analytics is affected by Cross-site scripting.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-36126"
    },
    {
      "rank": 196,
      "cve_id": "CVE-2026-44314",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00185,
      "epss_percentile": 0.08427,
      "kev": false,
      "kev_due_at": null,
      "vendor": "traccar",
      "product": "traccar",
      "cwe": "CWE-863",
      "title": "Traccar: Missing edit authorization on device image upload allows read-only users to write files",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44314"
    },
    {
      "rank": 197,
      "cve_id": "CVE-2026-43988",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00184,
      "epss_percentile": 0.08274,
      "kev": false,
      "kev_due_at": null,
      "vendor": "riebl",
      "product": "vanetza",
      "cwe": "CWE-248",
      "title": "Vanetza: Remote Denial of Service via Uncaught Exception in ASN.1/OER Parsing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43988"
    },
    {
      "rank": 198,
      "cve_id": "CVE-2026-43981",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00182,
      "epss_percentile": 0.08143,
      "kev": false,
      "kev_due_at": null,
      "vendor": "xyproto",
      "product": "algernon",
      "cwe": "CWE-362",
      "title": "Algernon: Race Condition in handle() shared LState",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43981"
    },
    {
      "rank": 199,
      "cve_id": "CVE-2026-25900",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00182,
      "epss_percentile": 0.0807,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Joomla! Project",
      "product": "Joomla! CMS",
      "cwe": "CWE-79",
      "title": "Joomla! Core - [20260501] - XSS in feed modules",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-25900"
    },
    {
      "rank": 200,
      "cve_id": "CVE-2026-30894",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00182,
      "epss_percentile": 0.08071,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Joomla! Project",
      "product": "Joomla! CMS",
      "cwe": "CWE-79",
      "title": "Joomla! Core - [20260503] - XSS in com_contenthistory",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-30894"
    },
    {
      "rank": 201,
      "cve_id": "CVE-2025-14290",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00182,
      "epss_percentile": 0.08134,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "webMethods Integration (on prem) -Integration Server",
      "cwe": "CWE-918",
      "title": "IBM webMethods Integration Sever is vulnerable to server-side request forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-14290"
    },
    {
      "rank": 202,
      "cve_id": "CVE-2026-44903",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00182,
      "epss_percentile": 0.0813,
      "kev": false,
      "kev_due_at": null,
      "vendor": "prometheus",
      "product": "prometheus",
      "cwe": "CWE-79",
      "title": "Prometheus: Stored XSS via crafted histogram bucket label values in the heatmap display of the old Prometheus web UI",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44903"
    },
    {
      "rank": 203,
      "cve_id": "CVE-2026-43934",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00181,
      "epss_percentile": 0.08017,
      "kev": false,
      "kev_due_at": null,
      "vendor": "e107inc",
      "product": "e107",
      "cwe": "CWE-284",
      "title": "e107: Broken Access Control in e107 comment edit allows cross-user comment modification",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43934"
    },
    {
      "rank": 204,
      "cve_id": "CVE-2025-68710",
      "cvss_base": 2.4,
      "cvss_severity": "LOW",
      "epss_score": 0.00179,
      "epss_percentile": 0.07767,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-288",
      "title": "Easyelife App lock (aka Fingerprint,Applock or locker.app.safe.applocker) 1.9.2 for Android allows a local attacker with physical access to bypass the PIN lock. The lock is implemented as an overlay rather than by using Android's secure authentication APIs. By navigating cascading interface flows - insecure navigation through exposed routes facilitates app control evasion {I.N.T.E.R.F.A.C.E] via advertisement or browser intents - an attacker can evade lockscreen verification and access protected apps (e.g., Chrome), resulting in information disclosure and privilege escalation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-68710"
    },
    {
      "rank": 205,
      "cve_id": "CVE-2026-47728",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00178,
      "epss_percentile": 0.07609,
      "kev": false,
      "kev_due_at": null,
      "vendor": "bugsink",
      "product": "bugsink",
      "cwe": "CWE-862",
      "title": "Bugsink: Project scoping missing in sourcemap and debug-file lookup",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47728"
    },
    {
      "rank": 206,
      "cve_id": "CVE-2025-68709",
      "cvss_base": 5.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00177,
      "epss_percentile": 0.07508,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-79",
      "title": "SailingLab AppLock (aka com.alpha.applock) 4.3.8 for Android allows a local attacker to trigger arbitrary JavaScript execution via BrowserMainActivity, which accepts VIEW intents with javascript: URIs. This unsafe navigation path results in script execution and may allow UI spoofing or privilege escalation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-68709"
    },
    {
      "rank": 207,
      "cve_id": "CVE-2026-25901",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00175,
      "epss_percentile": 0.07314,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Joomla! Project",
      "product": "Joomla! CMS",
      "cwe": "CWE-79",
      "title": "Joomla! Core - [20260502] - XSS in com_associations",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-25901"
    },
    {
      "rank": 208,
      "cve_id": "CVE-2026-30895",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00175,
      "epss_percentile": 0.07315,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Joomla! Project",
      "product": "Joomla! CMS",
      "cwe": "CWE-79",
      "title": "Joomla! Core - [20260504] - XSS in readmore links",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-30895"
    },
    {
      "rank": 209,
      "cve_id": "CVE-2025-33221",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00175,
      "epss_percentile": 0.07307,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "GeForce",
      "cwe": "CWE-20",
      "title": "NVIDIA Display Driver for Windows and Linux contains a vulnerability in the kernel driver, where a user could cause an incorrect permission assignment for a critical resource. A successful exploit of this vulnerability might lead to data tampering and denial of service.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-33221"
    },
    {
      "rank": 210,
      "cve_id": "CVE-2026-3314",
      "cvss_base": 4.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00175,
      "epss_percentile": 0.07347,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hitachi",
      "product": "Hitachi Ops Center Analyzer",
      "cwe": "CWE-549",
      "title": "Missing Password Masking in Hitachi Infrastructure Analytics Advisor, Hitachi Ops Center Analyzer and Hitachi Ops Center Analyzer viewpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-3314"
    },
    {
      "rank": 211,
      "cve_id": "CVE-2026-47202",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00171,
      "epss_percentile": 0.06874,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Kareadita",
      "product": "Kavita",
      "cwe": "CWE-287",
      "title": "Kavita: Pre-Auth Account Takeover",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47202"
    },
    {
      "rank": 212,
      "cve_id": "CVE-2026-27427",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00171,
      "epss_percentile": 0.06901,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dylan Kuhn",
      "product": "Geo Mashup",
      "cwe": "CWE-79",
      "title": "WordPress Geo Mashup plugin <= 1.13.18 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-27427"
    },
    {
      "rank": 213,
      "cve_id": "CVE-2026-8479",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0017,
      "epss_percentile": 0.06771,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hitachi Energy",
      "product": "RTU500 series CMU firmware",
      "cwe": "CWE-476",
      "title": "IEC 60870-5-104 used in bidirectional mode in RTU500 is vulnerable for a NULL pointer dereferencing, if a specially crafted sequence of messages is sent for a certain time, causing Denial of Service impact. Product is only affected if IEC 60870-5-104 functionality in bidirectional mode (BCI) is configured.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8479"
    },
    {
      "rank": 214,
      "cve_id": "CVE-2026-9541",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": 0.0017,
      "epss_percentile": 0.06728,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "Squirrel",
      "cwe": "CWE-119",
      "title": "Squirrel Cnut File sqobject.cpp ReadObject heap-based overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9541"
    },
    {
      "rank": 215,
      "cve_id": "CVE-2026-24200",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00167,
      "epss_percentile": 0.06482,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "Virtual GPU Manager",
      "cwe": "CWE-416",
      "title": "NVIDIA vGPU software contains a vulnerability in the virtual GPU manager, where an attacker could cause a use-after-free for stack memory. A successful exploit of this vulnerability might lead to denial of service, escalation of privileges, information disclosure, data tampering, and code execution.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-24200"
    },
    {
      "rank": 216,
      "cve_id": "CVE-2026-7451",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00166,
      "epss_percentile": 0.06344,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Autodesk",
      "product": "3ds Max",
      "cwe": "CWE-787",
      "title": "TIF File Parsing Out-of-Bounds Write in Autodesk 3ds Max",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7451"
    },
    {
      "rank": 217,
      "cve_id": "CVE-2026-7452",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00166,
      "epss_percentile": 0.06343,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Autodesk",
      "product": "3ds Max",
      "cwe": "CWE-120",
      "title": "WRL File Parsing Memory Corruption in Autodesk 3ds Max",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7452"
    },
    {
      "rank": 218,
      "cve_id": "CVE-2026-24196",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00166,
      "epss_percentile": 0.06382,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "GeForce",
      "cwe": "CWE-125",
      "title": "NVIDIA Display Driver for Linux contains a vulnerability where a user could cause an out-of-bounds read. A successful exploit of this vulnerability might lead to denial of service and information disclosure.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-24196"
    },
    {
      "rank": 219,
      "cve_id": "CVE-2025-36145",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00166,
      "epss_percentile": 0.06369,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "watsonx.data",
      "cwe": "CWE-923",
      "title": "Multiple Vulnerabilities in watsonx.data",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-36145"
    },
    {
      "rank": 220,
      "cve_id": "CVE-2026-48697",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00164,
      "epss_percentile": 0.06071,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-295",
      "title": "FastNetMon Community Edition through 1.2.9 does not verify TLS certificates on outbound HTTPS connections. The execute_web_request_secure() function in src/fast_library.cpp creates a boost::asio::ssl::context with tls_client mode and calls set_default_verify_paths() to load CA certificates, but never calls set_verify_mode(boost::asio::ssl::verify_peer). Without this call, OpenSSL performs the TLS handshake without validating the server's certificate chain, making all HTTPS connections vulnerable to man-in-the-middle attacks. This function is used for telemetry reporting to community-stats.fastnetmon.com, which sends system information including CPU model, kernel version, traffic statistics, and software configuration. An attacker can intercept and modify this data or redirect it to a malicious server.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48697"
    },
    {
      "rank": 221,
      "cve_id": "CVE-2026-44833",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00163,
      "epss_percentile": 0.05985,
      "kev": false,
      "kev_due_at": null,
      "vendor": "grokability",
      "product": "snipe-it",
      "cwe": "CWE-601",
      "title": "Snipe-IT: Open redirect vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44833"
    },
    {
      "rank": 222,
      "cve_id": "CVE-2026-47672",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00162,
      "epss_percentile": 0.05887,
      "kev": false,
      "kev_due_at": null,
      "vendor": "oviva-ag",
      "product": "epa4all-client",
      "cwe": "CWE-306",
      "title": "epa4all-client: Unauthenticated REST API for Patient Record Writes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47672"
    },
    {
      "rank": 223,
      "cve_id": "CVE-2026-24195",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00162,
      "epss_percentile": 0.05956,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "Guest driver",
      "cwe": "CWE-20",
      "title": "NVIDIA Display Driver for Linux contains a vulnerability in UVM, where a user could cause improper input validation. A successful exploit of this vulnerability might lead to denial of service.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-24195"
    },
    {
      "rank": 224,
      "cve_id": "CVE-2026-9572",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00161,
      "epss_percentile": 0.05843,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "GPAC",
      "cwe": "CWE-401",
      "title": "GPAC MP4Box media.c Media_GetSample memory leak",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9572"
    },
    {
      "rank": 225,
      "cve_id": "CVE-2026-24197",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0016,
      "epss_percentile": 0.05656,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "GeForce",
      "cwe": "CWE-1188",
      "title": "NVIDIA Display Driver for Linux contains a vulnerability in the Multi-Instance GPU (MIG) partition management, where an insecure default initialization of memory subsystem routing resources could lead to data corruption or a hang during partition reconfiguration. A successful exploit of this vulnerability might lead to denial of service.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-24197"
    },
    {
      "rank": 226,
      "cve_id": "CVE-2026-48900",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0016,
      "epss_percentile": 0.05726,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Joomla! Project",
      "product": "Joomla! CMS",
      "cwe": "CWE-284",
      "title": "Joomla! Core - [20260516] - Incorrect Access Control in com_scheduler",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48900"
    },
    {
      "rank": 227,
      "cve_id": "CVE-2026-9582",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00159,
      "epss_percentile": 0.05543,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "CET Automated Grading System with AI Predictive Analytics",
      "cwe": "CWE-352",
      "title": "SourceCodester CET Automated Grading System with AI Predictive Analytics cross-site request forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9582"
    },
    {
      "rank": 228,
      "cve_id": "CVE-2026-27331",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00157,
      "epss_percentile": 0.05382,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Magepeople inc.",
      "product": "WpTravelly",
      "cwe": "CWE-862",
      "title": "WordPress WpTravelly plugin <= 2.1.5 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-27331"
    },
    {
      "rank": 229,
      "cve_id": "CVE-2026-24198",
      "cvss_base": 5.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00155,
      "epss_percentile": 0.05239,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "GeForce",
      "cwe": "CWE-200",
      "title": "NVIDIA GPU Display Driver for Linux contains a vulnerability where an advanced attacker could use a race condition to leak sensitive memory, which might cause limited exposure of sensitive information to an unauthorized actor. A successful exploit of this vulnerability might lead to denial of service, data tampering, and information disclosure.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-24198"
    },
    {
      "rank": 230,
      "cve_id": "CVE-2026-7450",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00155,
      "epss_percentile": 0.05155,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Autodesk",
      "product": "3ds Max",
      "cwe": "CWE-476",
      "title": "PAR File Parsing NULL Pointer Dereference in Autodesk 3ds Max",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7450"
    },
    {
      "rank": 231,
      "cve_id": "CVE-2026-7453",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00155,
      "epss_percentile": 0.05155,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Autodesk",
      "product": "3ds Max",
      "cwe": "CWE-674",
      "title": "WRL File Parsing Memory Exhaustion in Autodesk 3ds Max",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7453"
    },
    {
      "rank": 232,
      "cve_id": "CVE-2026-24520",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00155,
      "epss_percentile": 0.05205,
      "kev": false,
      "kev_due_at": null,
      "vendor": "bPlugins",
      "product": "Tiktok Feed",
      "cwe": "CWE-862",
      "title": "WordPress Tiktok Feed plugin <= 1.0.24 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-24520"
    },
    {
      "rank": 233,
      "cve_id": "CVE-2026-25444",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00155,
      "epss_percentile": 0.05205,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Magepeople inc.",
      "product": "WpBookingly",
      "cwe": "CWE-862",
      "title": "WordPress WpBookingly plugin <= 1.2.9 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-25444"
    },
    {
      "rank": 234,
      "cve_id": "CVE-2026-47715",
      "cvss_base": 3.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00154,
      "epss_percentile": 0.0512,
      "kev": false,
      "kev_due_at": null,
      "vendor": "bugsink",
      "product": "bugsink",
      "cwe": "CWE-639",
      "title": "Bugsink: Issue event views can show an event from another project if its UUID is known",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47715"
    },
    {
      "rank": 235,
      "cve_id": "CVE-2026-24194",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00152,
      "epss_percentile": 0.04892,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "GeForce",
      "cwe": "CWE-281",
      "title": "NVIDIA Display Driver for Linux contains a vulnerability in a kernel mode layer handler, where a user could cause improper permission handling. A successful exploit of this vulnerability might lead to denial of service, escalation of privileges, information disclosure, data tampering, and code execution.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-24194"
    },
    {
      "rank": 236,
      "cve_id": "CVE-2026-44983",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00151,
      "epss_percentile": 0.04826,
      "kev": false,
      "kev_due_at": null,
      "vendor": "servo",
      "product": "smallbitvec",
      "cwe": "CWE-122",
      "title": "smallbitvec: Safe API Triggered Heap Buffer Overflow via Integer Overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44983"
    },
    {
      "rank": 237,
      "cve_id": "CVE-2025-46307",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0015,
      "epss_percentile": 0.04706,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": "CWE-284",
      "title": "A logic issue was addressed with improved restrictions. This issue is fixed in macOS Tahoe 26. An app may be able to access sensitive user data.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-46307"
    },
    {
      "rank": 238,
      "cve_id": "CVE-2026-48903",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00149,
      "epss_percentile": 0.04659,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Joomla! Project",
      "product": "Joomla! Framework Filter package",
      "cwe": "CWE-79",
      "title": "Joomla! Framework - [20260519] - Inadequate content filtering within the checkAttribute filter code.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48903"
    },
    {
      "rank": 239,
      "cve_id": "CVE-2026-48905",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00149,
      "epss_percentile": 0.04658,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Joomla! Project",
      "product": "Joomla! Framework Filter package",
      "cwe": "CWE-79",
      "title": "Joomla! Framework - [20260520] - Inadequate content filtering within the cleanAttributes filter code.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48905"
    },
    {
      "rank": 240,
      "cve_id": "CVE-2026-47716",
      "cvss_base": 3.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00147,
      "epss_percentile": 0.04428,
      "kev": false,
      "kev_due_at": null,
      "vendor": "bugsink",
      "product": "bugsink",
      "cwe": "CWE-639",
      "title": "Bugsink: Issue bulk actions can affect another project’s issue if its UUID is known",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47716"
    },
    {
      "rank": 241,
      "cve_id": "CVE-2026-25112",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00145,
      "epss_percentile": 0.04331,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Genetec Inc.",
      "product": "Genetec RabbitMQ",
      "cwe": "CWE-732",
      "title": "A high-severity vulnerability in the deployment of Genetec RabbitMQ that allows a privilege escalation attack.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-25112"
    },
    {
      "rank": 242,
      "cve_id": "CVE-2026-24201",
      "cvss_base": 5.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00143,
      "epss_percentile": 0.04063,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "Virtual GPU Manager",
      "cwe": "CWE-787",
      "title": "NVIDIA vGPU software contains a vulnerability in the virtual GPU manager, where an attacker could cause an out-of-bound access. A successful exploit of this vulnerability might lead to data tampering, denial of service, or information disclosure.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-24201"
    },
    {
      "rank": 243,
      "cve_id": "CVE-2026-9529",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00143,
      "epss_percentile": 0.04067,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GNU",
      "product": "LibreDWG",
      "cwe": "CWE-404",
      "title": "GNU LibreDWG Dwggrep Utility dwggrep.c match_BLOCK_HEADER null pointer dereference",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9529"
    },
    {
      "rank": 244,
      "cve_id": "CVE-2026-9530",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00143,
      "epss_percentile": 0.04117,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GNU",
      "product": "LibreDWG",
      "cwe": "CWE-119",
      "title": "GNU LibreDWG Dwgbmp Utility decode.c read_2004_compressed_section out-of-bounds",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9530"
    },
    {
      "rank": 245,
      "cve_id": "CVE-2025-43289",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00139,
      "epss_percentile": 0.03735,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": "CWE-285",
      "title": "A logic issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.7, macOS Sonoma 14.8, macOS Tahoe 26. A malicious app may be able to access sensitive user data.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-43289"
    },
    {
      "rank": 246,
      "cve_id": "CVE-2026-45574",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00138,
      "epss_percentile": 0.03694,
      "kev": false,
      "kev_due_at": null,
      "vendor": "oviva-ag",
      "product": "epa4all-client",
      "cwe": "CWE-295",
      "title": "epa4all-client: TLS Certificate Validation Disabled in Production",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45574"
    },
    {
      "rank": 247,
      "cve_id": "CVE-2026-24191",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00138,
      "epss_percentile": 0.03644,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "GeForce",
      "cwe": "CWE-367",
      "title": "NVIDIA Display Driver for Windows contains a vulnerability where an attacker could cause a time-of-check time-of-use issue. A successful exploit of this vulnerability might lead to denial of service, escalation of privileges, information disclosure, data tampering, and code execution.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-24191"
    },
    {
      "rank": 248,
      "cve_id": "CVE-2025-46280",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00136,
      "epss_percentile": 0.03534,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": "CWE-125",
      "title": "An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Tahoe 26. An app may be able to cause unexpected system termination.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-46280"
    },
    {
      "rank": 249,
      "cve_id": "CVE-2025-43306",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00135,
      "epss_percentile": 0.03425,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": "CWE-269",
      "title": "A logic issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7, macOS Sonoma 14.8, macOS Tahoe 26. A malicious app may be able to gain root privileges.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-43306"
    },
    {
      "rank": 250,
      "cve_id": "CVE-2025-43451",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00135,
      "epss_percentile": 0.03432,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": "CWE-284",
      "title": "A permissions issue was addressed by removing the vulnerable code. This issue is fixed in macOS Tahoe 26. An app may be able to access sensitive user data.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-43451"
    },
    {
      "rank": 251,
      "cve_id": "CVE-2026-46620",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00133,
      "epss_percentile": 0.03256,
      "kev": false,
      "kev_due_at": null,
      "vendor": "e107inc",
      "product": "e107",
      "cwe": "CWE-285",
      "title": "e107: CSRF in comment.php moderation endpoints via token-optional validation in session_handler::check()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46620"
    },
    {
      "rank": 252,
      "cve_id": "CVE-2026-7454",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00132,
      "epss_percentile": 0.03208,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Autodesk",
      "product": "3ds Max",
      "cwe": "CWE-120",
      "title": "WRL File Parsing Memory Corruption in Autodesk 3ds Max",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7454"
    },
    {
      "rank": 253,
      "cve_id": "CVE-2026-44410",
      "cvss_base": 3.8,
      "cvss_severity": "LOW",
      "epss_score": 0.00131,
      "epss_percentile": 0.03179,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ZTE",
      "product": "ZXUniPOS NDS-LTE",
      "cwe": "CWE-1240",
      "title": "Function Abusement Vulnerability in ZTE ZXUniPOS NDS-LTE",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44410"
    },
    {
      "rank": 254,
      "cve_id": "CVE-2025-43290",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00129,
      "epss_percentile": 0.0297,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": "CWE-732",
      "title": "A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7, macOS Sonoma 14.8, macOS Tahoe 26. An app may be able to modify protected parts of the file system.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-43290"
    },
    {
      "rank": 255,
      "cve_id": "CVE-2026-48693",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00127,
      "epss_percentile": 0.02755,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-59",
      "title": "FastNetMon Community Edition through 1.2.9 is vulnerable to a local symlink attack via predictable file paths in /tmp. The statistics file path defaults to '/tmp/fastnetmon.dat' (src/fastnetmon.cpp line 159). The print_screen_contents_into_file() function (src/fastnetmon_logic.cpp line 2186) opens this path with std::ios::trunc without checking for symlinks or using O_NOFOLLOW. Additionally, the chmod() call on line 2190 always operates on cli_stats_file_path regardless of which file_path parameter was passed (a bug that applies wrong permissions), and the umask is set to 0 during daemonization (src/fastnetmon.cpp line 1821), making all created files world-writable. A local attacker can exploit this to overwrite arbitrary files as the FastNetMon process user (typically root).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48693"
    },
    {
      "rank": 256,
      "cve_id": "CVE-2026-44728",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00125,
      "epss_percentile": 0.02633,
      "kev": false,
      "kev_due_at": null,
      "vendor": "babel",
      "product": "babel",
      "cwe": "CWE-94",
      "title": "Improper Control of Generation of Code when compiling specifically crafted malicious code with @babel/plugin-transform-modules-systemjs",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44728"
    },
    {
      "rank": 257,
      "cve_id": "CVE-2026-24182",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00125,
      "epss_percentile": 0.02655,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "GeForce",
      "cwe": "CWE-667",
      "title": "NVIDIA Display Driver for Windows and Linux contains a vulnerability where an attacker could leak held driver locks. A successful exploit of this vulnerability might lead to denial of service.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-24182"
    },
    {
      "rank": 258,
      "cve_id": "CVE-2026-48696",
      "cvss_base": 6.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00124,
      "epss_percentile": 0.0256,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-120",
      "title": "FastNetMon Community Edition through 1.2.9 has a buffer overflow, a different vulnerability than CVE-2026-48686 and CVE-2026-48689.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48696"
    },
    {
      "rank": 259,
      "cve_id": "CVE-2026-44468",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00123,
      "epss_percentile": 0.025,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CODESYS",
      "product": "CODESYS Development System",
      "cwe": "CWE-276",
      "title": "Incorrect Default Permissions in CODESYS Development System",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44468"
    },
    {
      "rank": 260,
      "cve_id": "CVE-2026-45834",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00123,
      "epss_percentile": 0.02443,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-476",
      "title": "Bluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_state_change_cb()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45834"
    },
    {
      "rank": 261,
      "cve_id": "CVE-2026-45835",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00123,
      "epss_percentile": 0.02443,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-476",
      "title": "Bluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_new_connection_cb()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45835"
    },
    {
      "rank": 262,
      "cve_id": "CVE-2026-45836",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00123,
      "epss_percentile": 0.02443,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-476",
      "title": "Bluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_get_sndtimeo_cb()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45836"
    },
    {
      "rank": 263,
      "cve_id": "CVE-2026-44900",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00121,
      "epss_percentile": 0.02228,
      "kev": false,
      "kev_due_at": null,
      "vendor": "oviva-ag",
      "product": "epa4all-client",
      "cwe": "CWE-295",
      "title": "epa4all-client: VAU Signature bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44900"
    },
    {
      "rank": 264,
      "cve_id": "CVE-2026-45575",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00118,
      "epss_percentile": 0.01997,
      "kev": false,
      "kev_due_at": null,
      "vendor": "oviva-ag",
      "product": "epa4all-client",
      "cwe": "CWE-347",
      "title": "epa4all-client: Improper Verification of Cryptographic Signature",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45575"
    },
    {
      "rank": 265,
      "cve_id": "CVE-2026-44443",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00118,
      "epss_percentile": 0.01988,
      "kev": false,
      "kev_due_at": null,
      "vendor": "prolix-oc",
      "product": "Lumiverse",
      "cwe": "CWE-362",
      "title": "Lumiverse: Sign-up nonce race condition allows unauthorized account registration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44443"
    },
    {
      "rank": 266,
      "cve_id": "CVE-2026-48690",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00116,
      "epss_percentile": 0.0191,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-122",
      "title": "FastNetMon Community Edition through 1.2.9 contains an integer overflow vulnerability in the packet capture buffer allocation. In src/packet_storage.hpp, the allocate_buffer() function computes memory_size_in_bytes as 'buffer_size_in_packets * (max_captured_packet_size + sizeof(fastnetmon_pcap_pkthdr_t)) + sizeof(fastnetmon_pcap_file_header_t)' using unsigned int (32-bit) arithmetic. With max_captured_packet_size=1500 and sizeof(fastnetmon_pcap_pkthdr_t)=16, each packet requires approximately 1516 bytes. If buffer_size_in_packets exceeds approximately 2,832,542, the multiplication overflows, resulting in a much smaller allocation than expected. Subsequent write_packet() calls then write past the allocated buffer, causing heap corruption. The buffer_size_in_packets value is derived from the ban_details_records_count configuration parameter, which is parsed using atoi() with no overflow checking.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48690"
    },
    {
      "rank": 267,
      "cve_id": "CVE-2026-9567",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00115,
      "epss_percentile": 0.01821,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "GPAC",
      "cwe": "CWE-404",
      "title": "GPAC MP4Box isom_intern.c MergeFragment null pointer dereference",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9567"
    },
    {
      "rank": 268,
      "cve_id": "CVE-2025-13755",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00108,
      "epss_percentile": 0.01351,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Db2",
      "cwe": "CWE-532",
      "title": "IBM® Db2® is vulnerable to credential exposure in db2diag when executing specific testcase buckets",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-13755"
    },
    {
      "rank": 269,
      "cve_id": "CVE-2026-35220",
      "cvss_base": 4.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00108,
      "epss_percentile": 0.01352,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Joomla! Project",
      "product": "Joomla! CMS",
      "cwe": "CWE-352",
      "title": "Joomla! Core - [20260505] - CSRF in user activation endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-35220"
    },
    {
      "rank": 270,
      "cve_id": "CVE-2026-44469",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00105,
      "epss_percentile": 0.01226,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CODESYS",
      "product": "CODESYS Development System",
      "cwe": "CWE-276",
      "title": "Incorrect Default Permissions in CODESYS Development System",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44469"
    },
    {
      "rank": 271,
      "cve_id": "CVE-2025-46284",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00103,
      "epss_percentile": 0.01099,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": "CWE-362",
      "title": "A race condition was addressed with additional validation. This issue is fixed in macOS Sequoia 15.7, macOS Tahoe 26. An app may be able to gain root privileges.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-46284"
    },
    {
      "rank": 272,
      "cve_id": "CVE-2026-7310",
      "cvss_base": 4.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00103,
      "epss_percentile": 0.01137,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hitachi Energy",
      "product": "MACH HiDraw",
      "cwe": "CWE-122",
      "title": "A heap-based buffer overflow vulnerability exists in XML parser functionality in the HiDraw. An authenticated malicious user with local access can exploit this vulnerability using a specially crafted XML file which may lead to memory corruption and potential arbitrary code execution. Successful exploitation could result in application crashes (denial of service) and compromise the confidentiality and integrity of the affected system.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7310"
    },
    {
      "rank": 273,
      "cve_id": "CVE-2026-24199",
      "cvss_base": 4.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00092,
      "epss_percentile": 0.00617,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "GeForce",
      "cwe": "CWE-362",
      "title": "NVIDIA Display Driver for Linux contains a vulnerability in a kernel module, where a user could cause a race condition by reordering compiler or processor memory instructions. A successful exploit of this vulnerability might lead to denial of service.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-24199"
    },
    {
      "rank": 274,
      "cve_id": "CVE-2026-45413",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00083,
      "epss_percentile": 0.00282,
      "kev": false,
      "kev_due_at": null,
      "vendor": "1Panel-dev",
      "product": "MaxKB",
      "cwe": "CWE-328",
      "title": "MaxKB: Unsalted MD5 Password Hashing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45413"
    },
    {
      "rank": 275,
      "cve_id": "CVE-2026-41164",
      "cvss_base": 4.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00076,
      "epss_percentile": 0.00125,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nuts-foundation",
      "product": "nuts-node",
      "cwe": "CWE-345",
      "title": "nuts-node: JWT type confusion in v1 access token introspection allows VP replay as access token",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41164"
    }
  ],
  "transactions": [
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-25104",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-25104 (MediaArea MediaInfoLib). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-25713",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-25713 (MediaArea MediaInfoLib). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-40033",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-40033 (FreeRDP). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-44214",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-44214 (rexxars eventsource-encoder). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-44708",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-44708 (lepture mistune). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-44723",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-44723 (VowpalWabbit vowpal_wabbit). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-44729",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-44729 (twentyhq twenty). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-44788",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-44788 (adamhathcock sharpcompress). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-44837",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-44837 (ViewComponent view_component). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-44897",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-44897 (lepture mistune). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-44898",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-44898 (lepture mistune). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-44899",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-44899 (lepture mistune). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-44966",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-44966 (shepherdwind velocity.js). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-44985",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-44985 (amir20 dozzle). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-45298",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-45298 (amir20 dozzle). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-46624",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-46624 (twentyhq twenty). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-48687",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-48687. Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-48689",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-48689. Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-48710",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-48710 (Kludex starlette). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-48864",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-48864 (Red Hat Enterprise Linux 10). Public exploit reference added."
    }
  ],
  "attribution": "CVE Program, NVD (NIST), CISA KEV, FIRST EPSS, OSV. See /security/methodology/."
}
