{
  "day": "2026-05-27",
  "boundary": "UTC calendar day",
  "published_count": 715,
  "by_severity": {
    "CRITICAL": 49,
    "HIGH": 296,
    "MEDIUM": 357,
    "LOW": 12
  },
  "kev_count": 3,
  "exploit_reference_count": 30,
  "awaiting_enrichment_count": 1,
  "ranking": "Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.",
  "results": [
    {
      "rank": 1,
      "cve_id": "CVE-2026-45321",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.02342,
      "epss_percentile": 0.82277,
      "kev": true,
      "kev_due_at": "2026-06-10",
      "vendor": "@tanstack",
      "product": "arktype-adapter",
      "cwe": "CWE-506",
      "title": "Malware in 42 @tanstack/* packages exfiltrates cloud credentials, GitHub tokens, and SSH keys",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45321"
    },
    {
      "rank": 2,
      "cve_id": "CVE-2026-48027",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0185,
      "epss_percentile": 0.77399,
      "kev": true,
      "kev_due_at": "2026-06-10",
      "vendor": "nrwl",
      "product": "nx-console",
      "cwe": "CWE-506",
      "title": "Compromised Nx Console version 18.95.0",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48027"
    },
    {
      "rank": 3,
      "cve_id": "CVE-2026-8398",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.01456,
      "epss_percentile": 0.71389,
      "kev": true,
      "kev_due_at": "2026-05-30",
      "vendor": "Daemon",
      "product": "Daemon Tools Lite",
      "cwe": null,
      "title": "Daemon Daemon Tools Lite",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8398"
    },
    {
      "rank": 4,
      "cve_id": "CVE-2026-9312",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.06552,
      "epss_percentile": 0.93248,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GitHub",
      "product": "Enterprise Server",
      "cwe": "CWE-918",
      "title": "Server-Side Request Forgery vulnerability in GitHub Enterprise Server allowed access to internal services via path traversal in upload endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9312"
    },
    {
      "rank": 5,
      "cve_id": "CVE-2025-12686",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.02762,
      "epss_percentile": 0.85103,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Synology",
      "product": "BeeStation OS",
      "cwe": "CWE-120",
      "title": "Buffer copy without checking size of input ('Classic Buffer Overflow') vulnerability in AdminCenter in Synology BeeStation OS before 1.3.2-65648 allows remote attackers to execute arbitrary code via unspecified vectors.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-12686"
    },
    {
      "rank": 6,
      "cve_id": "CVE-2026-5509",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.02458,
      "epss_percentile": 0.83136,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TP-Link Systems Inc.",
      "product": "Archer BE7200 V1",
      "cwe": "CWE-77",
      "title": "Arbitrary Command Injection via Browser Developer Console in TP-Link Archer BE450 and BE7200",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-5509"
    },
    {
      "rank": 7,
      "cve_id": "CVE-2026-8832",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.01862,
      "epss_percentile": 0.77565,
      "kev": false,
      "kev_due_at": null,
      "vendor": "smub",
      "product": "WPCode – Insert Headers and Footers + Custom Code Snippets – WordPress Code Manager",
      "cwe": "CWE-94",
      "title": "WPCode <= 2.3.5 - Authenticated (Author+) Remote Code Execution via CPT Capability Bypass via XML-RPC wp.newPost",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8832"
    },
    {
      "rank": 8,
      "cve_id": "CVE-2026-45322",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.01722,
      "epss_percentile": 0.75653,
      "kev": false,
      "kev_due_at": null,
      "vendor": "microsoft",
      "product": "UFO",
      "cwe": "CWE-78",
      "title": "OS Command Injection in Microsoft UFO Shell Action Replay via Stored Session JSON",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45322"
    },
    {
      "rank": 9,
      "cve_id": "CVE-2026-8054",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.01584,
      "epss_percentile": 0.73582,
      "kev": false,
      "kev_due_at": null,
      "vendor": "dotCMS",
      "product": "dotCMS Core",
      "cwe": "CWE-89",
      "title": "Unauthenticated SQL Injection in dotCMS Publish Audit API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8054"
    },
    {
      "rank": 10,
      "cve_id": "CVE-2026-45087",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.01471,
      "epss_percentile": 0.71683,
      "kev": false,
      "kev_due_at": null,
      "vendor": "hahwul",
      "product": "dalfox",
      "cwe": "CWE-15",
      "title": "Dalfox: Unauthenticated Remote Code Execution via `found-action` in Dalfox Server Mode",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45087"
    },
    {
      "rank": 11,
      "cve_id": "CVE-2026-8450",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.01398,
      "epss_percentile": 0.70272,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OALDERS",
      "product": "HTTP::Daemon",
      "cwe": "CWE-73",
      "title": "HTTP::Daemon versions before 6.17 for Perl allow OS command injection via send_file()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8450"
    },
    {
      "rank": 12,
      "cve_id": "CVE-2026-36540",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.0132,
      "epss_percentile": 0.68562,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-77",
      "title": "Netis AC1200 Router NC21 V4.0.1.4296 is vulnerable to unauthenticated command injection via the /cgi-bin/skk_set.cgi endpoint. The password and new_pwd_confirm POST parameters are passed directly to the underlying OS shell without sanitization. An attacker can inject arbitrary shell commands by wrapping them in backticks (`) and encoding them in base64. Because the endpoint requires no authentication, any device on the LAN can achieve full Remote Code Execution on the router's operating system with a single HTTP POST request.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-36540"
    },
    {
      "rank": 13,
      "cve_id": "CVE-2026-36045",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.01314,
      "epss_percentile": 0.68439,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-78",
      "title": "picoclaw <=v0.1.2 and earlier is vulnerable to OS command injection via the ExecTool component (pkg/tools/shell.go). The guardCommand() function attempts to restrict shell command execution using a denylist of 8 regular expressions, but the denylist is incomplete.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-36045"
    },
    {
      "rank": 14,
      "cve_id": "CVE-2026-44590",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.01141,
      "epss_percentile": 0.64096,
      "kev": false,
      "kev_due_at": null,
      "vendor": "sherlock-project",
      "product": "sherlock",
      "cwe": "CWE-78",
      "title": "Sherlock: Command Injection via pull_request_target in validate_modified_targets.yml",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44590"
    },
    {
      "rank": 15,
      "cve_id": "CVE-2026-2340",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00939,
      "epss_percentile": 0.58148,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-280",
      "title": "Samba: vfs_worm does not block directory modification",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-2340"
    },
    {
      "rank": 16,
      "cve_id": "CVE-2026-1933",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00862,
      "epss_percentile": 0.55735,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-284",
      "title": "Samba: missing access check on reparse point operations",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-1933"
    },
    {
      "rank": 17,
      "cve_id": "CVE-2025-69600",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00826,
      "epss_percentile": 0.54587,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-77",
      "title": "Command injection in Raynet rvia RayVentory Scan Engine 12.6 Update 8 and previous versions allows adversaries to execute commands via getconfig, upload, inventory, and oracle options.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-69600"
    },
    {
      "rank": 18,
      "cve_id": "CVE-2026-38422",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00813,
      "epss_percentile": 0.54167,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-121",
      "title": "Buffer Overflow vulnerability in arendst Tasmota v.15.3.0.3 and before allows a remote attacker to execute arbitrary code via the tasmota/tasmota_xdrv_driver/xdrv_10_scripter.ino, fetch_jpg() function.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-38422"
    },
    {
      "rank": 19,
      "cve_id": "CVE-2026-38945",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00799,
      "epss_percentile": 0.53701,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-77",
      "title": "Command injection in Raynet rvia version 12.6 Update 8 and previous versions allows adversaries to execute arbitrary code via a crafted path that matches the improperly terminated search criteria of rvia's Java search using the find command.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-38945"
    },
    {
      "rank": 20,
      "cve_id": "CVE-2026-7524",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00787,
      "epss_percentile": 0.53311,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Langflow OSS",
      "cwe": "CWE-22",
      "title": "Path Traversal Vulnerability in File Processing Components Allows Unauthorized File System Access and Potential Remote Code Execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7524"
    },
    {
      "rank": 21,
      "cve_id": "CVE-2026-45152",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00715,
      "epss_percentile": 0.50908,
      "kev": false,
      "kev_due_at": null,
      "vendor": "uniget-org",
      "product": "cli",
      "cwe": "CWE-78",
      "title": "uniget: Command Injection in tool.Check Leading to Arbitrary Code Execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45152"
    },
    {
      "rank": 22,
      "cve_id": "CVE-2026-45860",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00686,
      "epss_percentile": 0.49842,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "netfilter: nf_conncount: increase the connection clean up limit to 64",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45860"
    },
    {
      "rank": 23,
      "cve_id": "CVE-2026-46402",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00674,
      "epss_percentile": 0.49349,
      "kev": false,
      "kev_due_at": null,
      "vendor": "microsoft",
      "product": "UFO",
      "cwe": "CWE-22",
      "title": "Microsoft UFO uses untrusted task_name in log paths, allowing authenticated path traversal and log file creation outside the logs directory",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46402"
    },
    {
      "rank": 24,
      "cve_id": "CVE-2026-35087",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00662,
      "epss_percentile": 0.48892,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Slican",
      "product": "IPx",
      "cwe": "CWE-288",
      "title": "Authentication Bypass in Slican telephone exchanges",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-35087"
    },
    {
      "rank": 25,
      "cve_id": "CVE-2026-35090",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00625,
      "epss_percentile": 0.4729,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Slican",
      "product": "CCT-1668",
      "cwe": "CWE-288",
      "title": "Authentication Bypass in Slican telephone exchanges",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-35090"
    },
    {
      "rank": 26,
      "cve_id": "CVE-2026-44724",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0062,
      "epss_percentile": 0.47001,
      "kev": false,
      "kev_due_at": null,
      "vendor": "sebhildebrandt",
      "product": "systeminformation",
      "cwe": "CWE-78",
      "title": "systeminformation: Linux command injection in networkInterfaces() via unsanitized NetworkManager connection profile name",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44724"
    },
    {
      "rank": 27,
      "cve_id": "CVE-2026-8760",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00618,
      "epss_percentile": 0.46922,
      "kev": false,
      "kev_due_at": null,
      "vendor": "india-web-developer",
      "product": "Login with OTP",
      "cwe": "CWE-307",
      "title": "Login with OTP <= 1.6 - Unauthenticated Authentication Bypass via OTP Brute Force",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8760"
    },
    {
      "rank": 28,
      "cve_id": "CVE-2026-38426",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00614,
      "epss_percentile": 0.46759,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-120",
      "title": "Buffer Overflow vulnerability in arendst Tasmota v.15.3.0.3 and before allows a remote attacker to execute arbitrary code via the xdrv_10_scripter.ino, fetch_jpg(), jpg_task.boundary[40], strcpy() function.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-38426"
    },
    {
      "rank": 29,
      "cve_id": "CVE-2026-45859",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00612,
      "epss_percentile": 0.46618,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "netfilter: nfnetlink_queue: do shared-unconfirmed check before segmentation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45859"
    },
    {
      "rank": 30,
      "cve_id": "CVE-2026-6169",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00603,
      "epss_percentile": 0.46227,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cservit",
      "product": "affiliate-toolkit – Multi-Network Affiliate & Amazon Product Display",
      "cwe": "CWE-94",
      "title": "affiliate-toolkit <= 3.8.5 - Authenticated (Editor+) Remote Code Execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6169"
    },
    {
      "rank": 31,
      "cve_id": "CVE-2026-3366",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00596,
      "epss_percentile": 0.45897,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "InfoSphere Optim Test Data Fabrication",
      "cwe": "CWE-22",
      "title": "InfoSphere Optim Test Data Fabrication is affected by Arbitrary File Read",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-3366"
    },
    {
      "rank": 32,
      "cve_id": "CVE-2026-35089",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00589,
      "epss_percentile": 0.45584,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Slican",
      "product": "IPx",
      "cwe": "CWE-1391",
      "title": "Use of Weak Credentials in Slican telephone exchanges",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-35089"
    },
    {
      "rank": 33,
      "cve_id": "CVE-2026-8175",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0058,
      "epss_percentile": 0.45165,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Aspera High-Speed Transfer Endpoint",
      "cwe": "CWE-122",
      "title": "Multiple vulnerabilities in Aspera applications.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8175"
    },
    {
      "rank": 34,
      "cve_id": "CVE-2026-44887",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00545,
      "epss_percentile": 0.4338,
      "kev": false,
      "kev_due_at": null,
      "vendor": "leiweibau",
      "product": "Pi.Alert",
      "cwe": "CWE-94",
      "title": "Unauthenticated RCE via Python Config File Injection in SaveConfigFile() (Path)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44887"
    },
    {
      "rank": 35,
      "cve_id": "CVE-2025-13392",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00533,
      "epss_percentile": 0.42749,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Synology",
      "product": "DiskStation Manager (DSM)",
      "cwe": "CWE-754",
      "title": "Improper check for unusual or exceptional conditions vulnerability in SSO in Synology DiskStation Manager (DSM) before 7.2.2-72806-5 and 7.3.1-86003-1 (7.2.1-69057 is not affected) allows remote attackers to bypass authentication with prior knowledge of the distinguished name (DN).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-13392"
    },
    {
      "rank": 36,
      "cve_id": "CVE-2026-46414",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0053,
      "epss_percentile": 0.42585,
      "kev": false,
      "kev_due_at": null,
      "vendor": "microsoft",
      "product": "UFO",
      "cwe": "CWE-290",
      "title": "Microsoft UFO WebSocket role spoofing allows authenticated peer task hijacking",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46414"
    },
    {
      "rank": 37,
      "cve_id": "CVE-2026-49009",
      "cvss_base": 3.1,
      "cvss_severity": "LOW",
      "epss_score": 0.0052,
      "epss_percentile": 0.41998,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-22",
      "title": "Northern.tech Mender Server v4.1.0, v4.0.1 and below, and fixed in v4.1.1 and v4.0.2 allows Directory Traversal.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49009"
    },
    {
      "rank": 38,
      "cve_id": "CVE-2026-46043",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00514,
      "epss_percentile": 0.41638,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "RDMA/rxe: Validate pad and ICRC before payload_size() in rxe_rcv",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46043"
    },
    {
      "rank": 39,
      "cve_id": "CVE-2026-46027",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00501,
      "epss_percentile": 0.40834,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net/smc: avoid early lgr access in smc_clc_wait_msg",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46027"
    },
    {
      "rank": 40,
      "cve_id": "CVE-2026-46052",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00501,
      "epss_percentile": 0.40834,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ceph: only d_add() negative dentries when they are unhashed",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46052"
    },
    {
      "rank": 41,
      "cve_id": "CVE-2026-46102",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00501,
      "epss_percentile": 0.40833,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-401",
      "title": "net: strparser: fix skb_head leak in strp_abort_strp()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46102"
    },
    {
      "rank": 42,
      "cve_id": "CVE-2026-4410",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.005,
      "epss_percentile": 0.40781,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "WebSphere Application Server - Liberty",
      "cwe": "CWE-400",
      "title": "IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by a denial of service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-4410"
    },
    {
      "rank": 43,
      "cve_id": "CVE-2026-9627",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00497,
      "epss_percentile": 0.40577,
      "kev": false,
      "kev_due_at": null,
      "vendor": "UTT",
      "product": "HiPER 1200GW",
      "cwe": "CWE-119",
      "title": "UTT HiPER 1200GW Web Management setSysAdm strcpy buffer overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9627"
    },
    {
      "rank": 44,
      "cve_id": "CVE-2026-9200",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00495,
      "epss_percentile": 0.40471,
      "kev": false,
      "kev_due_at": null,
      "vendor": "shazdeh",
      "product": "Query Shortcode",
      "cwe": "CWE-98",
      "title": "Query Shortcode <= 0.2.1 - Authenticated (Contributor+) Local File Inclusion via 'lens' Shortcode Attribute",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9200"
    },
    {
      "rank": 45,
      "cve_id": "CVE-2026-46024",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0049,
      "epss_percentile": 0.40163,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-476",
      "title": "libceph: Prevent potential null-ptr-deref in ceph_handle_auth_reply()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46024"
    },
    {
      "rank": 46,
      "cve_id": "CVE-2026-47161",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00489,
      "epss_percentile": 0.40149,
      "kev": false,
      "kev_due_at": null,
      "vendor": "inducer",
      "product": "relate",
      "cwe": "CWE-502",
      "title": "RELATE Vulnerable to Remote Code Execution (RCE) via Insecure Celery Pickle Deserialization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47161"
    },
    {
      "rank": 47,
      "cve_id": "CVE-2025-14713",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00475,
      "epss_percentile": 0.39232,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Synology",
      "product": "C2 Identity Edge Server",
      "cwe": "CWE-749",
      "title": "An Exposed Dangerous Method or Function vulnerability in Synology C2 Identity Edge Server package in DSM before 1.76.0-0307 allows remote attackers to obtain user credentials from the edge server.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-14713"
    },
    {
      "rank": 48,
      "cve_id": "CVE-2026-9628",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00472,
      "epss_percentile": 0.39037,
      "kev": false,
      "kev_due_at": null,
      "vendor": "UTT",
      "product": "HiPER 1200GW",
      "cwe": "CWE-119",
      "title": "UTT HiPER 1200GW Web Management formPptpClientConfig stack-based overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9628"
    },
    {
      "rank": 49,
      "cve_id": "CVE-2026-1402",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00471,
      "epss_percentile": 0.38886,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GitLab",
      "product": "GitLab",
      "cwe": "CWE-770",
      "title": "Allocation of Resources Without Limits or Throttling in GitLab",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-1402"
    },
    {
      "rank": 50,
      "cve_id": "CVE-2026-45898",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00465,
      "epss_percentile": 0.38558,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-1341",
      "title": "RDMA/iwcm: Fix workqueue list corruption by removing work_list",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45898"
    },
    {
      "rank": 51,
      "cve_id": "CVE-2024-56462",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00463,
      "epss_percentile": 0.3846,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "QRadar",
      "cwe": "CWE-552",
      "title": "IBM QRadar SIEM is vulnerable to using components with known vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-56462"
    },
    {
      "rank": 52,
      "cve_id": "CVE-2026-9632",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00463,
      "epss_percentile": 0.38422,
      "kev": false,
      "kev_due_at": null,
      "vendor": "UTT",
      "product": "HiPER 1250GW",
      "cwe": "CWE-119",
      "title": "UTT HiPER 1250GW Web Management formGroupConfig strcpy stack-based overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9632"
    },
    {
      "rank": 53,
      "cve_id": "CVE-2026-38427",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00458,
      "epss_percentile": 0.38144,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-122",
      "title": "An issue in fetch_jpg() in xdrv_10_scripter.ino in Tasmota through 15.3.0.3 allows a remote attacker to cause heap buffer overflow. The Content-Length from a JPEG stream is stored in a uint16_t variable; values above 65535 wrap around, causing allocation of a smaller buffer than the data actually read.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-38427"
    },
    {
      "rank": 54,
      "cve_id": "CVE-2026-45988",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00457,
      "epss_percentile": 0.38063,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "rxrpc: Fix re-decryption of RESPONSE packets",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45988"
    },
    {
      "rank": 55,
      "cve_id": "CVE-2026-44902",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00455,
      "epss_percentile": 0.37896,
      "kev": false,
      "kev_due_at": null,
      "vendor": "open-telemetry",
      "product": "opentelemetry-js",
      "cwe": "CWE-755",
      "title": "opentelemetry-js: Prometheus exporter process crash via malformed HTTP request",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44902"
    },
    {
      "rank": 56,
      "cve_id": "CVE-2026-46039",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00442,
      "epss_percentile": 0.36979,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-190",
      "title": "rxgk: Fix potential integer overflow in length check",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46039"
    },
    {
      "rank": 57,
      "cve_id": "CVE-2026-45047",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00441,
      "epss_percentile": 0.36914,
      "kev": false,
      "kev_due_at": null,
      "vendor": "xddxdd",
      "product": "bird-lg-go",
      "cwe": "CWE-400",
      "title": "bird-lg-go: Fatal Out-of-Memory (OOM) Denial of Service via Unbounded JSON Decoding",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45047"
    },
    {
      "rank": 58,
      "cve_id": "CVE-2026-46085",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00441,
      "epss_percentile": 0.36848,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "rxrpc: Fix rxkad crypto unalignment handling",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46085"
    },
    {
      "rank": 59,
      "cve_id": "CVE-2026-9631",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00438,
      "epss_percentile": 0.36638,
      "kev": false,
      "kev_due_at": null,
      "vendor": "UTT",
      "product": "HiPER 1250GW",
      "cwe": "CWE-119",
      "title": "UTT HiPER 1250GW Web Management formConfigFastDirectionW strcpy stack-based overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9631"
    },
    {
      "rank": 60,
      "cve_id": "CVE-2026-46037",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00433,
      "epss_percentile": 0.3625,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ipv4: icmp: validate reply type before using icmp_pointers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46037"
    },
    {
      "rank": 61,
      "cve_id": "CVE-2026-46544",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00422,
      "epss_percentile": 0.35445,
      "kev": false,
      "kev_due_at": null,
      "vendor": "microsoft",
      "product": "UFO",
      "cwe": "CWE-639",
      "title": "Microsoft UFO reuses client-supplied WebSocket session IDs and replays stale task results to new authenticated requesters",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46544"
    },
    {
      "rank": 62,
      "cve_id": "CVE-2026-9208",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00421,
      "epss_percentile": 0.35286,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tanium",
      "product": "Connect",
      "cwe": "CWE-78",
      "title": "Tanium addressed an unauthorized code execution vulnerability in Connect.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9208"
    },
    {
      "rank": 63,
      "cve_id": "CVE-2026-44660",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00421,
      "epss_percentile": 0.35299,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ultrajson",
      "product": "ultrajson",
      "cwe": "CWE-401",
      "title": "UltraJSON: Memory Leak in ujson.dump() on Write Failure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44660"
    },
    {
      "rank": 64,
      "cve_id": "CVE-2026-4391",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0042,
      "epss_percentile": 0.35204,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "TeamSpeak 3 Server",
      "cwe": "CWE-119",
      "title": "TeamSpeak 3 Server ECC Key heap-based overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-4391"
    },
    {
      "rank": 65,
      "cve_id": "CVE-2026-44324",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0042,
      "epss_percentile": 0.35189,
      "kev": false,
      "kev_due_at": null,
      "vendor": "free5gc",
      "product": "free5gc",
      "cwe": "CWE-704",
      "title": "free5GC: UDR nudr-dr DELETE amf-subscriptions panics on missing UE state via nil interface type assertion (single authenticated request)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44324"
    },
    {
      "rank": 66,
      "cve_id": "CVE-2026-45083",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0041,
      "epss_percentile": 0.34303,
      "kev": false,
      "kev_due_at": null,
      "vendor": "intranda",
      "product": "goobi-viewer-core",
      "cwe": "CWE-306",
      "title": "Goobi viewer: Unauthenticated Solr Streaming Expression Proxy",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45083"
    },
    {
      "rank": 67,
      "cve_id": "CVE-2026-48544",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00409,
      "epss_percentile": 0.3423,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Avaiga",
      "product": "taipy",
      "cwe": "CWE-22",
      "title": "Taipy 4.1.1 Path Traversal via ElementLibrary.get_resource()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48544"
    },
    {
      "rank": 68,
      "cve_id": "CVE-2025-70116",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00407,
      "epss_percentile": 0.34131,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-476",
      "title": "A NULL pointer dereference in GPAC MP4Box: when parsing certain truncated MP4 files, an unknown/invalid stsd entry can result in missing descriptor fields (e.g., codec/mime/profile strings). gf_media_map_esd then calls strlen() on a NULL pointer, triggering a crash (ASan SEGV).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-70116"
    },
    {
      "rank": 69,
      "cve_id": "CVE-2026-44316",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00404,
      "epss_percentile": 0.33832,
      "kev": false,
      "kev_due_at": null,
      "vendor": "free5gc",
      "product": "free5gc",
      "cwe": "CWE-476",
      "title": "free5GC: PCF npcf-smpolicycontrol POST /sm-policies panics on downstream UDR/OpenAPI 404 via nil pointer dereference",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44316"
    },
    {
      "rank": 70,
      "cve_id": "CVE-2026-44319",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00404,
      "epss_percentile": 0.33832,
      "kev": false,
      "kev_due_at": null,
      "vendor": "free5gc",
      "product": "free5gc",
      "cwe": "CWE-20",
      "title": "free5GC: NEF crashes via logger.Fatal on PFD notification delivery failure (attacker-controlled notifyUri)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44319"
    },
    {
      "rank": 71,
      "cve_id": "CVE-2026-46010",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00403,
      "epss_percentile": 0.33776,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "rxrpc: Fix error handling in rxgk_extract_token()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46010"
    },
    {
      "rank": 72,
      "cve_id": "CVE-2026-4392",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00402,
      "epss_percentile": 0.33573,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "TeamSpeak 3 Server",
      "cwe": "CWE-617",
      "title": "TeamSpeak 3 Server clientek Handshake assertion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-4392"
    },
    {
      "rank": 73,
      "cve_id": "CVE-2026-3676",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00402,
      "epss_percentile": 0.33602,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Cloud APM, Base Private",
      "cwe": "CWE-1284",
      "title": "There are multiple vulnerabilities in IBM DB2 bundled with IBM Application Performance Management products.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-3676"
    },
    {
      "rank": 74,
      "cve_id": "CVE-2026-8179",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00401,
      "epss_percentile": 0.33527,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Aspera High-Speed Transfer Endpoint",
      "cwe": "CWE-121",
      "title": "Multiple vulnerabilities in Aspera applications.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8179"
    },
    {
      "rank": 75,
      "cve_id": "CVE-2026-49103",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00396,
      "epss_percentile": 0.33001,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Webmin",
      "product": "Webmin",
      "cwe": "CWE-24",
      "title": "Webmin before 2.640 does not safely construct a filename for saving of an attachment within the mailboxes component. This occurs in mailboxes/detachall.cgi.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49103"
    },
    {
      "rank": 76,
      "cve_id": "CVE-2026-40850",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00395,
      "epss_percentile": 0.32843,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MB connect line",
      "product": "mbCONNECT24",
      "cwe": "CWE-89",
      "title": "Unauthenticated SQLi in getAccountData function",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40850"
    },
    {
      "rank": 77,
      "cve_id": "CVE-2026-44325",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00394,
      "epss_percentile": 0.32704,
      "kev": false,
      "kev_due_at": null,
      "vendor": "free5gc",
      "product": "free5gc",
      "cwe": "CWE-20",
      "title": "free5GC: NRF POST /oauth2/token structured-form parser type-confusion panic family (Reflect.Set on incompatible types)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44325"
    },
    {
      "rank": 78,
      "cve_id": "CVE-2026-9207",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00391,
      "epss_percentile": 0.32457,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tanium",
      "product": "Connect",
      "cwe": "CWE-78",
      "title": "Tanium addressed an unauthorized code execution vulnerability in Connect.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9207"
    },
    {
      "rank": 79,
      "cve_id": "CVE-2026-8994",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0039,
      "epss_percentile": 0.32333,
      "kev": false,
      "kev_due_at": null,
      "vendor": "learnnearclub",
      "product": "Login with NEAR",
      "cwe": "CWE-287",
      "title": "Login with NEAR <= 0.3.3 - Authentication Bypass via 'account' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8994"
    },
    {
      "rank": 80,
      "cve_id": "CVE-2026-44322",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0039,
      "epss_percentile": 0.32347,
      "kev": false,
      "kev_due_at": null,
      "vendor": "free5gc",
      "product": "free5gc",
      "cwe": "CWE-476",
      "title": "free5GC: NEF 3gpp-pfd-management PATCH applications/{appId} panics on UDR access failure due to nil ProblemDetails dereference",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44322"
    },
    {
      "rank": 81,
      "cve_id": "CVE-2024-28765",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00385,
      "epss_percentile": 0.31798,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "SDI",
      "cwe": "CWE-209",
      "title": "Security vulnerability was found in IBM Security Directory Integrator",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-28765"
    },
    {
      "rank": 82,
      "cve_id": "CVE-2026-37711",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00384,
      "epss_percentile": 0.31723,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-94",
      "title": "An issue in Dolibarr ERP/CRM v.22.0.0 through v.22.0.4 and v.24.0.0-alpha allows a remote attacker to execute arbitrary code via the htdocs/core/actions_addupdatedelete.inc.php",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-37711"
    },
    {
      "rank": 83,
      "cve_id": "CVE-2026-37712",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00384,
      "epss_percentile": 0.31723,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-94",
      "title": "An issue in Dolibarr ERP/CRM v.22.0.0 through v.22.0.4 and v.24.0.0-alpha allows a remote attacker to execute arbitrary code via the htdocs/cron/class/cronjob.class.php, call_user_func_array() in function job type",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-37712"
    },
    {
      "rank": 84,
      "cve_id": "CVE-2026-37713",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00384,
      "epss_percentile": 0.31723,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-94",
      "title": "An issue in Dolibarr ERP/CRM v.22.0.0 through v.22.0.4 and v.24.0.0-alpha allows a remote attacker to execute arbitrary code via the htdocs/core/class/commonobject.class.php.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-37713"
    },
    {
      "rank": 85,
      "cve_id": "CVE-2026-3001",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00377,
      "epss_percentile": 0.31018,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jegstudio",
      "product": "Gutenverse – WordPress Blocks, Page Builder & Site Editor",
      "cwe": "CWE-79",
      "title": "Gutenverse <= 3.4.6 - Reflected Cross-Site Scripting via 's' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-3001"
    },
    {
      "rank": 86,
      "cve_id": "CVE-2026-47118",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00375,
      "epss_percentile": 0.30789,
      "kev": false,
      "kev_due_at": null,
      "vendor": "3clyp50",
      "product": "agent-zero",
      "cwe": "CWE-22",
      "title": "Agent Zero < 1.15 Path Traversal File Read via image_get API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47118"
    },
    {
      "rank": 87,
      "cve_id": "CVE-2026-48959",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00373,
      "epss_percentile": 0.30618,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PMQS",
      "product": "IO::Uncompress::Unzip",
      "cwe": "CWE-407",
      "title": "IO::Uncompress::Unzip versions before 2.220 for Perl allow CPU exhaustion via per-byte read loop in fastForward",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48959"
    },
    {
      "rank": 88,
      "cve_id": "CVE-2026-46031",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0037,
      "epss_percentile": 0.30218,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-667",
      "title": "net: ks8851: Reinstate disabling of BHs around IRQ handler",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46031"
    },
    {
      "rank": 89,
      "cve_id": "CVE-2026-40852",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.0037,
      "epss_percentile": 0.3023,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MB connect line",
      "product": "mbNET/mbNET.rokey",
      "cwe": "CWE-78",
      "title": "Command injection via malicious configuration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40852"
    },
    {
      "rank": 90,
      "cve_id": "CVE-2025-30028",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00368,
      "epss_percentile": 0.30059,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Synology",
      "product": "Active Backup for Business",
      "cwe": "CWE-89",
      "title": "A vulnerability in Active Backup for Business allows unauthorized remote attackers to read arbitrary files.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-30028"
    },
    {
      "rank": 91,
      "cve_id": "CVE-2025-70103",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00367,
      "epss_percentile": 0.29963,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-122",
      "title": "Heap buffer overflow vulnerability in libjxl 0.12.0 via crafted PBM images to the jxl::extras::DecodeImagePNM function in file lib/extras/dec/pnm.cc.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-70103"
    },
    {
      "rank": 92,
      "cve_id": "CVE-2026-45570",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00365,
      "epss_percentile": 0.29781,
      "kev": false,
      "kev_due_at": null,
      "vendor": "go-git",
      "product": "go-git",
      "cwe": "CWE-116",
      "title": "go-git: Improper single-quote escaping in go-git SSH transport",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45570"
    },
    {
      "rank": 93,
      "cve_id": "CVE-2026-44321",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00364,
      "epss_percentile": 0.2966,
      "kev": false,
      "kev_due_at": null,
      "vendor": "free5gc",
      "product": "free5gc",
      "cwe": "CWE-306",
      "title": "free5GC: SMF UPI POST /upi/v1/upNodesLinks exits the SMF process on overlapping UE pools (unauthenticated, reachable Fatalf)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44321"
    },
    {
      "rank": 94,
      "cve_id": "CVE-2026-1718",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00362,
      "epss_percentile": 0.29434,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Db2",
      "cwe": "CWE-770",
      "title": "IBM® Db2® is vulnerable to a denial of service with a specially crafted query when running an AUTONOMOUS procedure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-1718"
    },
    {
      "rank": 95,
      "cve_id": "CVE-2026-44635",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00362,
      "epss_percentile": 0.29472,
      "kev": false,
      "kev_due_at": null,
      "vendor": "kysely-org",
      "product": "kysely",
      "cwe": "CWE-22",
      "title": "Kysely: JSON-path traversal injection via unsanitized path-leg metacharacters in `JSONPathBuilder.key()` / `.at()`",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44635"
    },
    {
      "rank": 96,
      "cve_id": "CVE-2024-40684",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0036,
      "epss_percentile": 0.29192,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Operations Analytics - Log Analysis",
      "cwe": "CWE-521",
      "title": "IBM Operations Analytics - Log Analysis is affected by Weak Password Policy and Inadequate Account Lockout Mechanism",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-40684"
    },
    {
      "rank": 97,
      "cve_id": "CVE-2026-42757",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00359,
      "epss_percentile": 0.29111,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Saleswonder Team: Tobias",
      "product": "WebinarIgnition",
      "cwe": "CWE-22",
      "title": "WordPress WebinarIgnition plugin < 4.08.253 - Arbitrary File Deletion vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42757"
    },
    {
      "rank": 98,
      "cve_id": "CVE-2026-3375",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00359,
      "epss_percentile": 0.29097,
      "kev": false,
      "kev_due_at": null,
      "vendor": "litespeedtech",
      "product": "LiteSpeed Cache",
      "cwe": "CWE-79",
      "title": "LiteSpeed Cache <= 7.7 - Unauthenticated Stored Cross-Site Scripting via QUIC.cloud CCSS/UCSS REST API Endpoints",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-3375"
    },
    {
      "rank": 99,
      "cve_id": "CVE-2026-42737",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00358,
      "epss_percentile": 0.29017,
      "kev": false,
      "kev_due_at": null,
      "vendor": "e4jvikwp",
      "product": "VikBooking Hotel Booking Engine & PMS",
      "cwe": "CWE-22",
      "title": "WordPress VikBooking Hotel Booking Engine & PMS plugin <= 1.8.9 - Arbitrary File Deletion vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42737"
    },
    {
      "rank": 100,
      "cve_id": "CVE-2026-36539",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00358,
      "epss_percentile": 0.29066,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-200",
      "title": "Netis AC1200 Router NC21 V4.0.1.4296 exposes a CGI endpoint /cgi-bin/skk_get.cgi that returns the entire router configuration as a JSON response with no authentication required. Any attacker on the LAN can send a single HTTP GET request and instantly retrieve administrator credentials, WiFi passwords, PPPoE credentials, DDNS credentials, and a full map of all connected devices.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-36539"
    },
    {
      "rank": 101,
      "cve_id": "CVE-2026-45843",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00355,
      "epss_percentile": 0.28794,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "slip: bound decode() reads against the compressed packet length",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45843"
    },
    {
      "rank": 102,
      "cve_id": "CVE-2026-8361",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00351,
      "epss_percentile": 0.28273,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Gladinet",
      "product": "Triofox",
      "cwe": "CWE-23",
      "title": "Gladinet Triofox Path Traversal in WOSDefaultHttpModule.dll",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8361"
    },
    {
      "rank": 103,
      "cve_id": "CVE-2026-48545",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.0035,
      "epss_percentile": 0.28227,
      "kev": false,
      "kev_due_at": null,
      "vendor": "gradio-app",
      "product": "gradio",
      "cwe": "CWE-384",
      "title": "Gradio < 6.15.0 Cookie Injection via Shared Proxy Client",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48545"
    },
    {
      "rank": 104,
      "cve_id": "CVE-2026-48922",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0035,
      "epss_percentile": 0.28229,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jenkins Project",
      "product": "Jenkins Credentials Binding Plugin",
      "cwe": "CWE-20",
      "title": "Jenkins Credentials Binding Plugin 720.v3f6decef43ea_ and earlier does not properly sanitize file names for file and zip file credentials, allowing attackers able to provide credentials to a job to write files to arbitrary locations on the node filesystem, which can lead to remote code execution if Jenkins is configured to allow a low-privileged user to configure file or zip file credentials used for a job running on the built-in node.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48922"
    },
    {
      "rank": 105,
      "cve_id": "CVE-2026-44317",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0035,
      "epss_percentile": 0.28234,
      "kev": false,
      "kev_due_at": null,
      "vendor": "free5gc",
      "product": "free5gc",
      "cwe": "CWE-476",
      "title": "free5GC: PCF npcf-policyauthorization POST /app-sessions panics on suppFeat=1 with missing AfRoutReq via nil pointer dereference",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44317"
    },
    {
      "rank": 106,
      "cve_id": "CVE-2026-44323",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0035,
      "epss_percentile": 0.28234,
      "kev": false,
      "kev_due_at": null,
      "vendor": "free5gc",
      "product": "free5gc",
      "cwe": "CWE-476",
      "title": "free5GC: UDR nudr-dr DELETE amf-subscriptions panics on missing subsId when UE state exists (nil pointer dereference)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44323"
    },
    {
      "rank": 107,
      "cve_id": "CVE-2026-7493",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0035,
      "epss_percentile": 0.28223,
      "kev": false,
      "kev_due_at": null,
      "vendor": "croixhaug",
      "product": "Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin",
      "cwe": "CWE-400",
      "title": "Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin <= 1.6.11.5 - Unauthenticated Denial of Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7493"
    },
    {
      "rank": 108,
      "cve_id": "CVE-2026-44353",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00345,
      "epss_percentile": 0.27658,
      "kev": false,
      "kev_due_at": null,
      "vendor": "streamlink",
      "product": "streamlink",
      "cwe": "CWE-22",
      "title": "Streamlink: Arbitrary local file read via file:// URI in HLS and DASH",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44353"
    },
    {
      "rank": 109,
      "cve_id": "CVE-2026-48064",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00342,
      "epss_percentile": 0.27387,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mcdope",
      "product": "pam_usb",
      "cwe": "CWE-863",
      "title": "pam_usb: PAM_RHOST check skipped when deny_remote=false allows XDMCP authentication bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48064"
    },
    {
      "rank": 110,
      "cve_id": "CVE-2026-38807",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00341,
      "epss_percentile": 0.27237,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-639",
      "title": "Insecure Permissions vulnerability in kvf-admin v1.0.0 allows a remote attacker to escalate privileges via the UserController.java component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-38807"
    },
    {
      "rank": 111,
      "cve_id": "CVE-2026-4868",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00341,
      "epss_percentile": 0.27267,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GitLab",
      "product": "GitLab",
      "cwe": "CWE-639",
      "title": "Authorization Bypass Through User-Controlled Key in GitLab",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-4868"
    },
    {
      "rank": 112,
      "cve_id": "CVE-2024-47268",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0034,
      "epss_percentile": 0.27098,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Synology",
      "product": "Surveillance Station",
      "cwe": "CWE-862",
      "title": "Missing authorization vulnerability in AddOns functionality in Synology Surveillance Station before 9.2.2-11575 and 9.2.2-9575 allows remote authenticated users with administrator privileges to obtain sensitive information via unspecified vectors.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-47268"
    },
    {
      "rank": 113,
      "cve_id": "CVE-2024-47271",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0034,
      "epss_percentile": 0.27098,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Synology",
      "product": "Surveillance Station",
      "cwe": "CWE-522",
      "title": "Insufficiently protected credentials vulnerability in IPSpeaker component in Synology Surveillance Station before 9.2.2-11575 and 9.2.2-9575 allows remote authenticated users with administrator privileges to obtain sensitive information via unspecified vectors.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-47271"
    },
    {
      "rank": 114,
      "cve_id": "CVE-2026-42790",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00338,
      "epss_percentile": 0.26889,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Erlang",
      "product": "OTP",
      "cwe": "CWE-295",
      "title": "nameConstraints DNS bypass via subject CommonName fallback in public_key hostname verification",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42790"
    },
    {
      "rank": 115,
      "cve_id": "CVE-2026-42756",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00336,
      "epss_percentile": 0.26584,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ludwig You",
      "product": "QuickWebP &#8211; Compress / Optimize Images &amp; Convert WebP | SEO Friendly",
      "cwe": "CWE-22",
      "title": "WordPress QuickWebP – Compress / Optimize Images & Convert WebP | SEO Friendly plugin <= 3.2.7 - Arbitrary File Deletion vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42756"
    },
    {
      "rank": 116,
      "cve_id": "CVE-2026-8363",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00335,
      "epss_percentile": 0.26485,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Gladinet",
      "product": "Triofox",
      "cwe": "CWE-121",
      "title": "Gladinet Triofox Stack-based Buffer Overflow in WOSDeviceDropFolder.dll",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8363"
    },
    {
      "rank": 117,
      "cve_id": "CVE-2026-42731",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00333,
      "epss_percentile": 0.26363,
      "kev": false,
      "kev_due_at": null,
      "vendor": "miniOrange",
      "product": "miniorange otp verification",
      "cwe": "CWE-266",
      "title": "WordPress miniorange otp verification plugin <= 5.4.9 - Privilege Escalation vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42731"
    },
    {
      "rank": 118,
      "cve_id": "CVE-2026-45972",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00333,
      "epss_percentile": 0.26326,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-416",
      "title": "smb: client: fix potential UAF and double free in smb2_open_file()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45972"
    },
    {
      "rank": 119,
      "cve_id": "CVE-2026-44329",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00331,
      "epss_percentile": 0.2605,
      "kev": false,
      "kev_due_at": null,
      "vendor": "free5gc",
      "product": "free5gc",
      "cwe": "CWE-306",
      "title": "free5GC: SMF UPI management interface lacks auth middleware; unauthenticated topology read/write requests reach handlers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44329"
    },
    {
      "rank": 120,
      "cve_id": "CVE-2026-42789",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.0033,
      "epss_percentile": 0.26012,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Erlang",
      "product": "OTP",
      "cwe": "CWE-295",
      "title": "Non-CA certificate accepted as intermediate issuer in public_key path validation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42789"
    },
    {
      "rank": 121,
      "cve_id": "CVE-2026-48128",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00329,
      "epss_percentile": 0.25881,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Budibase",
      "product": "budibase",
      "cwe": "CWE-918",
      "title": "Budibase: SSRF via User-Controlled queryId in Automation Execute Query Step",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48128"
    },
    {
      "rank": 122,
      "cve_id": "CVE-2026-9035",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00325,
      "epss_percentile": 0.25429,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Aspera High-Speed Transfer Endpoint",
      "cwe": "CWE-22",
      "title": "Multiple vulnerabilities in Aspera applications.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9035"
    },
    {
      "rank": 123,
      "cve_id": "CVE-2024-47267",
      "cvss_base": 2.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00325,
      "epss_percentile": 0.25511,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Synology",
      "product": "Surveillance Station",
      "cwe": "CWE-22",
      "title": "Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in Archiving Pull functionality in Synology Surveillance Station before 9.2.2-11575 and 9.2.2-9575 allows remote authenticated users with administrator privileges to limited file write via unspecified vectors.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-47267"
    },
    {
      "rank": 124,
      "cve_id": "CVE-2026-44328",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00324,
      "epss_percentile": 0.25287,
      "kev": false,
      "kev_due_at": null,
      "vendor": "free5gc",
      "product": "free5gc",
      "cwe": "CWE-306",
      "title": "free5GC: SMF UPI DELETE /upi/v1/upNodesLinks/{ref} panics on AN-node deletion via nil UPF dereference; unauthenticated, state-mutating",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44328"
    },
    {
      "rank": 125,
      "cve_id": "CVE-2026-42459",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00324,
      "epss_percentile": 0.25365,
      "kev": false,
      "kev_due_at": null,
      "vendor": "free5gc",
      "product": "free5gc",
      "cwe": "CWE-20",
      "title": "free5GC: Improper Input Validation and Generation of Error Message Containing Sensitive Information in github.com/free5gc/udm",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42459"
    },
    {
      "rank": 126,
      "cve_id": "CVE-2026-40831",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00324,
      "epss_percentile": 0.25301,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MB connect line",
      "product": "mbCONNECT24",
      "cwe": "CWE-89",
      "title": "Authenticated SQLi in Easy View",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40831"
    },
    {
      "rank": 127,
      "cve_id": "CVE-2026-44378",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00324,
      "epss_percentile": 0.25367,
      "kev": false,
      "kev_due_at": null,
      "vendor": "randombit",
      "product": "botan",
      "cwe": "CWE-407",
      "title": "Botan: Quadratic complexity decoding BER indefinite length encodings",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44378"
    },
    {
      "rank": 128,
      "cve_id": "CVE-2026-42083",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00323,
      "epss_percentile": 0.25244,
      "kev": false,
      "kev_due_at": null,
      "vendor": "free5gc",
      "product": "free5gc",
      "cwe": "CWE-862",
      "title": "free5GC: PCF Npcf_SMPolicyControl missing authentication middleware allows unauthenticated access to SM policy handlers and disclosure of subscriber SUPI",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42083"
    },
    {
      "rank": 129,
      "cve_id": "CVE-2025-71311",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00323,
      "epss_percentile": 0.25268,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-908",
      "title": "fs/ntfs3: Initialize new folios before use",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-71311"
    },
    {
      "rank": 130,
      "cve_id": "CVE-2026-49017",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00322,
      "epss_percentile": 0.25072,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenStack",
      "product": "Swift",
      "cwe": "CWE-835",
      "title": "In OpenStack Swift before 2.36.2 and 2.37.2, s3api middleware enters an infinite loop when processing a truncated aws-chunked PUT request body. The StreamingInput class repeatedly appends an empty buffer and re-reads, causing the proxy-server worker handling the request to become permanently unresponsive with increasing CPU and memory consumption. An authenticated attacker can systematically exhaust all proxy-server workers, resulting in denial of service. The defect was introduced in Swift 2.36.0.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49017"
    },
    {
      "rank": 131,
      "cve_id": "CVE-2026-6713",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00322,
      "epss_percentile": 0.25079,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GitLab",
      "product": "GitLab",
      "cwe": "CWE-863",
      "title": "Incorrect Authorization in GitLab",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6713"
    },
    {
      "rank": 132,
      "cve_id": "CVE-2026-9689",
      "cvss_base": 4.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00322,
      "epss_percentile": 0.25073,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat build of Keycloak 26.4",
      "cwe": "CWE-1288",
      "title": "Keycloak: org.keycloak.protocol.oidc: http parameter pollution in oidc redirect uri allows response parameter duplication - #ghi-604",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9689"
    },
    {
      "rank": 133,
      "cve_id": "CVE-2026-44346",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00321,
      "epss_percentile": 0.24996,
      "kev": false,
      "kev_due_at": null,
      "vendor": "bentoml",
      "product": "BentoML",
      "cwe": "CWE-78",
      "title": "BentoML: Dockerfile command injection via envs[*].name in bentofile.yaml",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44346"
    },
    {
      "rank": 134,
      "cve_id": "CVE-2026-46099",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00321,
      "epss_percentile": 0.2499,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-911",
      "title": "net: ipv6: fix NOREF dst use in seg6 and rpl lwtunnels",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46099"
    },
    {
      "rank": 135,
      "cve_id": "CVE-2026-42758",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0032,
      "epss_percentile": 0.24914,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Saleswonder Team: Tobias",
      "product": "WebinarIgnition",
      "cwe": "CWE-266",
      "title": "WordPress WebinarIgnition plugin < 4.08.253 - Privilege Escalation vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42758"
    },
    {
      "rank": 136,
      "cve_id": "CVE-2026-9704",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0032,
      "epss_percentile": 0.24913,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat build of Keycloak 26.4",
      "cwe": "CWE-1284",
      "title": "Keycloak: keycloak: privilege escalation due to oversized subject_token jwt",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9704"
    },
    {
      "rank": 137,
      "cve_id": "CVE-2026-40810",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.0032,
      "epss_percentile": 0.24831,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MB connect line",
      "product": "mbCONNECT24",
      "cwe": "CWE-89",
      "title": "Unauthenticated SQLi in userinfo Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40810"
    },
    {
      "rank": 138,
      "cve_id": "CVE-2026-40811",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.0032,
      "epss_percentile": 0.24833,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MB connect line",
      "product": "mbCONNECT24",
      "cwe": "CWE-89",
      "title": "Unauthenticated SQLi in ssoabstractservice",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40811"
    },
    {
      "rank": 139,
      "cve_id": "CVE-2026-40812",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.0032,
      "epss_percentile": 0.24832,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MB connect line",
      "product": "mbCONNECT24",
      "cwe": "CWE-89",
      "title": "Unauthenticated SQLi in getLiveValues function",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40812"
    },
    {
      "rank": 140,
      "cve_id": "CVE-2026-40813",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.0032,
      "epss_percentile": 0.24833,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MB connect line",
      "product": "mbCONNECT24",
      "cwe": "CWE-89",
      "title": "Unauthenticated SQLi in getLiveValues",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40813"
    },
    {
      "rank": 141,
      "cve_id": "CVE-2026-40814",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.0032,
      "epss_percentile": 0.24831,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MB connect line",
      "product": "mbCONNECT24",
      "cwe": "CWE-89",
      "title": "Unauthenticated SQLi in _mb24confi_getTagAlarm function",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40814"
    },
    {
      "rank": 142,
      "cve_id": "CVE-2026-40815",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.0032,
      "epss_percentile": 0.24833,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MB connect line",
      "product": "mbCONNECT24",
      "cwe": "CWE-89",
      "title": "Unauthenticated SQLi in _mb24api_getUserAccount function",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40815"
    },
    {
      "rank": 143,
      "cve_id": "CVE-2026-40816",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.0032,
      "epss_percentile": 0.24833,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MB connect line",
      "product": "mbCONNECT24",
      "cwe": "CWE-89",
      "title": "Unauthenticated SQLi in _mb24confi_getTagAlarm function",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40816"
    },
    {
      "rank": 144,
      "cve_id": "CVE-2026-40817",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.0032,
      "epss_percentile": 0.24832,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MB connect line",
      "product": "mbCONNECT24",
      "cwe": "CWE-89",
      "title": "Unauthenticated SQLi in getAlarmProfiles function",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40817"
    },
    {
      "rank": 145,
      "cve_id": "CVE-2026-40818",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.0032,
      "epss_percentile": 0.24832,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MB connect line",
      "product": "mbCONNECT24",
      "cwe": "CWE-89",
      "title": "Unauthenticated SQLi in _mb24confi_getDevice function function",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40818"
    },
    {
      "rank": 146,
      "cve_id": "CVE-2026-40819",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.0032,
      "epss_percentile": 0.24832,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MB connect line",
      "product": "mbCONNECT24",
      "cwe": "CWE-89",
      "title": "Unauthenticated SQLi in sync_data24 task",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40819"
    },
    {
      "rank": 147,
      "cve_id": "CVE-2026-45104",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0032,
      "epss_percentile": 0.24928,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MapServer",
      "product": "MapServer",
      "cwe": "CWE-476",
      "title": "MapServer: NULL pointer dereference in SLD `<ElseFilter>` rule parsing reachable via WMS `SLD_BODY`",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45104"
    },
    {
      "rank": 148,
      "cve_id": "CVE-2026-8180",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00319,
      "epss_percentile": 0.2475,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Aspera High-Speed Transfer Endpoint",
      "cwe": "CWE-476",
      "title": "Multiple vulnerabilities in Aspera applications.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8180"
    },
    {
      "rank": 149,
      "cve_id": "CVE-2026-44345",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00317,
      "epss_percentile": 0.24496,
      "kev": false,
      "kev_due_at": null,
      "vendor": "bentoml",
      "product": "BentoML",
      "cwe": "CWE-78",
      "title": "BentoML: Dockerfile command injection via docker.base_image",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44345"
    },
    {
      "rank": 150,
      "cve_id": "CVE-2026-8362",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00316,
      "epss_percentile": 0.24482,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Gladinet",
      "product": "Triofox",
      "cwe": "CWE-121",
      "title": "Gladinet Triofox Stack-based Buffer Overflow in WOSDefaultHttpModule.dll",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8362"
    },
    {
      "rank": 151,
      "cve_id": "CVE-2026-42791",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00316,
      "epss_percentile": 0.24413,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Erlang",
      "product": "OTP",
      "cwe": "CWE-295",
      "title": "OCSP responder certificate validity period not checked in public_key",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42791"
    },
    {
      "rank": 152,
      "cve_id": "CVE-2026-44888",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00314,
      "epss_percentile": 0.24185,
      "kev": false,
      "kev_due_at": null,
      "vendor": "leiweibau",
      "product": "Pi.Alert",
      "cwe": "CWE-94",
      "title": "Unauthenticated RCE via Python Config File Injection in SaveConfigFile() (Interger)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44888"
    },
    {
      "rank": 153,
      "cve_id": "CVE-2026-44315",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00314,
      "epss_percentile": 0.24221,
      "kev": false,
      "kev_due_at": null,
      "vendor": "free5gc",
      "product": "free5gc",
      "cwe": "CWE-862",
      "title": "free5GC: NEF 3gpp-pfd-management API is unauthenticated; forged bearer tokens can create, read, and delete PFD transactions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44315"
    },
    {
      "rank": 154,
      "cve_id": "CVE-2026-7876",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00312,
      "epss_percentile": 0.23991,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Aspera HSTS for CP4I",
      "cwe": "CWE-287",
      "title": "Authentication bypass vulnerability found in Aspera High-Speed Transfer Server for Cloud Pak for Integration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7876"
    },
    {
      "rank": 155,
      "cve_id": "CVE-2026-42184",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00312,
      "epss_percentile": 0.2397,
      "kev": false,
      "kev_due_at": null,
      "vendor": "tauri-apps",
      "product": "tauri",
      "cwe": "CWE-918",
      "title": "Tauri: Origin Confusion Allows Remote Pages to Invoke Local-Only IPC Commands",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42184"
    },
    {
      "rank": 156,
      "cve_id": "CVE-2026-44327",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00311,
      "epss_percentile": 0.23888,
      "kev": false,
      "kev_due_at": null,
      "vendor": "free5gc",
      "product": "free5gc",
      "cwe": "CWE-306",
      "title": "free5GC: NEF nnef-oam route group is unauthenticated; no-token requests reach the OAM handler",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44327"
    },
    {
      "rank": 157,
      "cve_id": "CVE-2026-44326",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00311,
      "epss_percentile": 0.23889,
      "kev": false,
      "kev_due_at": null,
      "vendor": "free5gc",
      "product": "free5gc",
      "cwe": "CWE-862",
      "title": "free5GC: NEF 3gpp-traffic-influence API is unauthenticated; missing or forged bearer tokens can create, read, patch, and delete subscriptions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44326"
    },
    {
      "rank": 158,
      "cve_id": "CVE-2026-42197",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.0031,
      "epss_percentile": 0.23724,
      "kev": false,
      "kev_due_at": null,
      "vendor": "inducer",
      "product": "relate",
      "cwe": "CWE-79",
      "title": "RELATE Vulnerable to Stored XSS via Unprivileged User Profile",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42197"
    },
    {
      "rank": 159,
      "cve_id": "CVE-2025-3633",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.0031,
      "epss_percentile": 0.23808,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Cognos Analytics",
      "cwe": "CWE-79",
      "title": "IBM Cognos Analytics is affected by multiple security vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-3633"
    },
    {
      "rank": 160,
      "cve_id": "CVE-2026-48972",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00309,
      "epss_percentile": 0.23646,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SeedProd LLC",
      "product": "SeedProd Pro",
      "cwe": "CWE-98",
      "title": "WordPress SeedProd Pro plugin < 6.19.5 - Local File Inclusion vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48972"
    },
    {
      "rank": 161,
      "cve_id": "CVE-2026-47269",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00307,
      "epss_percentile": 0.23351,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mcdope",
      "product": "pam_usb",
      "cwe": "CWE-284",
      "title": "pam_usb: deny_remote feature incorrectly classifies IPv4-mapped IPv6 remote connections as local",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47269"
    },
    {
      "rank": 162,
      "cve_id": "CVE-2026-8364",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00305,
      "epss_percentile": 0.23174,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Gladinet",
      "product": "Triofox",
      "cwe": "CWE-306",
      "title": "Gladinet Triofox Missing Authentication for Critical Functions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8364"
    },
    {
      "rank": 163,
      "cve_id": "CVE-2026-49046",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00303,
      "epss_percentile": 0.2301,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Arjun Thakur",
      "product": "Duplicate Page and Post",
      "cwe": "CWE-89",
      "title": "WordPress Duplicate Page and Post plugin <= 2.9.5 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49046"
    },
    {
      "rank": 164,
      "cve_id": "CVE-2026-42553",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00302,
      "epss_percentile": 0.22859,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cinnyapp",
      "product": "cinny",
      "cwe": "CWE-20",
      "title": "Cinny: Access token disclosure via invalidated emoji pack avatar URL in service worker",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42553"
    },
    {
      "rank": 165,
      "cve_id": "CVE-2026-36538",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00301,
      "epss_percentile": 0.22739,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-798",
      "title": "Netis AC1200 Router NC21 V4.0.1.4296 contains a hard-coded root credential stored in /etc/shadow.sample. The password for the root account is set to the trivially weak value root, allowing an attacker with access to the device to authenticate as root and gain full control of the underlying operating system.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-36538"
    },
    {
      "rank": 166,
      "cve_id": "CVE-2026-48877",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00298,
      "epss_percentile": 0.22471,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tom",
      "product": "GenerateBlocks",
      "cwe": "CWE-201",
      "title": "WordPress GenerateBlocks plugin <= 2.1.0 - Sensitive Data Exposure vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48877"
    },
    {
      "rank": 167,
      "cve_id": "CVE-2026-45571",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00297,
      "epss_percentile": 0.22354,
      "kev": false,
      "kev_due_at": null,
      "vendor": "go-git",
      "product": "go-git",
      "cwe": "CWE-22",
      "title": "go-git: Crafted repositories may modify main and submodule .git directories",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45571"
    },
    {
      "rank": 168,
      "cve_id": "CVE-2026-6957",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00296,
      "epss_percentile": 0.22209,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mattermost",
      "product": "Mattermost",
      "cwe": "CWE-22",
      "title": "Path traversal in Mattermost Legal Hold plugin via unsanitized file name from federated peer allows arbitrary file write.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6957"
    },
    {
      "rank": 169,
      "cve_id": "CVE-2026-40827",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00295,
      "epss_percentile": 0.22184,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MB connect line",
      "product": "mbCONNECT24",
      "cwe": "CWE-89",
      "title": "Authenticated SQLi in _RemoveRequest function",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40827"
    },
    {
      "rank": 170,
      "cve_id": "CVE-2026-40828",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00295,
      "epss_percentile": 0.22185,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MB connect line",
      "product": "mbCONNECT24",
      "cwe": "CWE-89",
      "title": "Authenticated SQLi in DeleteSysLogEntry function",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40828"
    },
    {
      "rank": 171,
      "cve_id": "CVE-2026-40829",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00295,
      "epss_percentile": 0.22185,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MB connect line",
      "product": "mbCONNECT24",
      "cwe": "CWE-89",
      "title": "Authenticated SQLi in UpdateParam function",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40829"
    },
    {
      "rank": 172,
      "cve_id": "CVE-2026-40830",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00295,
      "epss_percentile": 0.22184,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MB connect line",
      "product": "mbCONNECT24",
      "cwe": "CWE-89",
      "title": "Authenticated SQLi in UpdateParam function",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40830"
    },
    {
      "rank": 173,
      "cve_id": "CVE-2026-42727",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00294,
      "epss_percentile": 0.21974,
      "kev": false,
      "kev_due_at": null,
      "vendor": "RealMag777",
      "product": "Active Products Tables for WooCommerce",
      "cwe": "CWE-89",
      "title": "WordPress Active Products Tables for WooCommerce plugin <= 1.0.8 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42727"
    },
    {
      "rank": 174,
      "cve_id": "CVE-2026-7618",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00294,
      "epss_percentile": 0.2205,
      "kev": false,
      "kev_due_at": null,
      "vendor": "dattateccom",
      "product": "EnvíaloSimple: Email Marketing y Newsletters",
      "cwe": "CWE-89",
      "title": "EnvíaloSimple: Email Marketing y Newsletters <= 2.4.5 - Authenticated (Administrator+) SQL Injection via 'orderby' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7618"
    },
    {
      "rank": 175,
      "cve_id": "CVE-2026-49002",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00293,
      "epss_percentile": 0.21868,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ZTE",
      "product": "ZXUniPOS NDS-LTE",
      "cwe": "CWE-284",
      "title": "Broken Access Control Vulnerabily in ZTE ZXUniPOS NDS-LTE product",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49002"
    },
    {
      "rank": 176,
      "cve_id": "CVE-2026-48150",
      "cvss_base": 9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00292,
      "epss_percentile": 0.21846,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Budibase",
      "product": "budibase",
      "cwe": "CWE-915",
      "title": "Budibase: Workspace-scoped builder escalates to global admin via /api/public/v1/roles/assign",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48150"
    },
    {
      "rank": 177,
      "cve_id": "CVE-2026-48962",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00292,
      "epss_percentile": 0.21754,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PMQS",
      "product": "IO::Compress",
      "cwe": "CWE-95",
      "title": "IO::Compress versions before 2.220 for Perl can execute arbitrary code in File::GlobMapper via an attacker-controlled output glob",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48962"
    },
    {
      "rank": 178,
      "cve_id": "CVE-2026-42760",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00291,
      "epss_percentile": 0.21634,
      "kev": false,
      "kev_due_at": null,
      "vendor": "revmakx",
      "product": "Backup and Staging by WP Time Capsule",
      "cwe": "CWE-288",
      "title": "WordPress Backup and Staging by WP Time Capsule plugin <= 1.22.25 - Broken Authentication vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42760"
    },
    {
      "rank": 179,
      "cve_id": "CVE-2026-48921",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00289,
      "epss_percentile": 0.21523,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jenkins Project",
      "product": "Jenkins Pipeline: Groovy Libraries Plugin",
      "cwe": "CWE-59",
      "title": "Jenkins Pipeline: Groovy Libraries Plugin 797.v90ea_a_9b_e45a_0 and earlier does not prohibit symbolic links in shared libraries, allowing attackers able to control the content of a library used by a Pipeline job to read arbitrary files on the Jenkins controller filesystem.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48921"
    },
    {
      "rank": 180,
      "cve_id": "CVE-2026-48920",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00288,
      "epss_percentile": 0.21355,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jenkins Project",
      "product": "Jenkins Email Extension Plugin",
      "cwe": "CWE-73",
      "title": "Jenkins Email Extension Plugin 1933.v45cec755423f and earlier allows inlining images as `base64` in email content by setting the `data-inline` attribute, without restrictions on the image URLs that can be inlined, allowing attackers able to control the email content to specify `file:` URLs for images to read arbitrary files from the Jenkins controller filesystem.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48920"
    },
    {
      "rank": 181,
      "cve_id": "CVE-2026-38808",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00288,
      "epss_percentile": 0.21356,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-89",
      "title": "SQL Injection vulnerability in uzy-ssm-mall v1.1.0 allows a remote attacker to obtain sensitive information via the ProductMapper.xml and /OrderUtil.java components",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-38808"
    },
    {
      "rank": 182,
      "cve_id": "CVE-2025-14481",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00288,
      "epss_percentile": 0.21337,
      "kev": false,
      "kev_due_at": null,
      "vendor": "yoast",
      "product": "Yoast SEO – Advanced SEO with real-time guidance and built-in AI",
      "cwe": "CWE-862",
      "title": "Yoast SEO <= 26.5 - Insecure Direct Object Reference to Authenticated (Contributor+) Sensitive Information Exposure via 'post_id' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-14481"
    },
    {
      "rank": 183,
      "cve_id": "CVE-2026-44330",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00287,
      "epss_percentile": 0.21271,
      "kev": false,
      "kev_due_at": null,
      "vendor": "free5gc",
      "product": "free5gc",
      "cwe": "CWE-863",
      "title": "free5GC: NEF nnef-pfdmanagement API is unauthenticated; forged bearer tokens can read PFD data and create/delete PFD subscriptions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44330"
    },
    {
      "rank": 184,
      "cve_id": "CVE-2026-46425",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00286,
      "epss_percentile": 0.21132,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Budibase",
      "product": "budibase",
      "cwe": "CWE-862",
      "title": "Budibase: SCIM endpoints lack role-based authorization, BASIC users CRUD tenant users",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46425"
    },
    {
      "rank": 185,
      "cve_id": "CVE-2026-8787",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00283,
      "epss_percentile": 0.20912,
      "kev": false,
      "kev_due_at": null,
      "vendor": "devsabbirahmed",
      "product": "Firebase Support & Chat Management",
      "cwe": "CWE-269",
      "title": "Firebase Support & Chat Management <= 3.1.1 - Missing Authorization to Authenticated (Subscriber+) Privilege Escalation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8787"
    },
    {
      "rank": 186,
      "cve_id": "CVE-2026-7528",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00283,
      "epss_percentile": 0.20911,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Langflow OSS",
      "cwe": "CWE-400",
      "title": "Unauthenticated File Upload Vulnerability Allows Disk Space Exhaustion and Path Disclosure in Langflow OSS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7528"
    },
    {
      "rank": 187,
      "cve_id": "CVE-2026-31266",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00283,
      "epss_percentile": 0.20843,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-862",
      "title": "Craft CMS 5.9.5 and earlier contains a Missing Authorization vulnerability in the migrate endpoint (/actions/app/migrate).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-31266"
    },
    {
      "rank": 188,
      "cve_id": "CVE-2026-40821",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00281,
      "epss_percentile": 0.20649,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MB connect line",
      "product": "mbCONNECT24",
      "cwe": "CWE-89",
      "title": "Authenticated SQLi in getAccountByID function",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40821"
    },
    {
      "rank": 189,
      "cve_id": "CVE-2026-40822",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00281,
      "epss_percentile": 0.20649,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MB connect line",
      "product": "mbCONNECT24",
      "cwe": "CWE-89",
      "title": "Authenticated SQLi in DevSerialReset function",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40822"
    },
    {
      "rank": 190,
      "cve_id": "CVE-2026-40826",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00281,
      "epss_percentile": 0.20649,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MB connect line",
      "product": "mbCONNECT24",
      "cwe": "CWE-89",
      "title": "Authenticated SQLi in dsgvo_contracts view",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40826"
    },
    {
      "rank": 191,
      "cve_id": "CVE-2025-0898",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00281,
      "epss_percentile": 0.20635,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WPXpro",
      "product": "Xpro Elementor Addons - Pro",
      "cwe": "CWE-73",
      "title": "Xpro Elementor Addons - Pro <= 1.4.7 - Authenticated (Contributor+) Arbitrary File Read via Draw SVG",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-0898"
    },
    {
      "rank": 192,
      "cve_id": "CVE-2026-9739",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00279,
      "epss_percentile": 0.20482,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "MCP Toolbox for Databases",
      "cwe": "CWE-942",
      "title": "Vulnerable to DNS rebinding attacks when using SSE (http://b/499408790). During the beta phase, we implemented `allowed-origins` and `allowed-hosts` flags to align with MCP security guidelines. However, the hardcoded `Access-Control-Allow-Origin: *` header in the SSE initialization handler was inadvertently retained. This vulnerability specifically impacts users connecting via Toolbox using SSE under specification v2024-11-05.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9739"
    },
    {
      "rank": 193,
      "cve_id": "CVE-2026-3279",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00277,
      "epss_percentile": 0.20229,
      "kev": false,
      "kev_due_at": null,
      "vendor": "clorith",
      "product": "Enable jQuery Migrate Helper",
      "cwe": "CWE-862",
      "title": "Enable jQuery Migrate Helper <= 1.4.1 - Missing Authorization to Authenticated (Subscriber+) jQuery Version Downgrade",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-3279"
    },
    {
      "rank": 194,
      "cve_id": "CVE-2026-42748",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00276,
      "epss_percentile": 0.20166,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WPify",
      "product": "WPify Woo Czech",
      "cwe": "CWE-434",
      "title": "WordPress WPify Woo Czech plugin <= 5.4.1 - Arbitrary File Upload vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42748"
    },
    {
      "rank": 195,
      "cve_id": "CVE-2026-46416",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00276,
      "epss_percentile": 0.20157,
      "kev": false,
      "kev_due_at": null,
      "vendor": "microsoft",
      "product": "UFO",
      "cwe": "CWE-284",
      "title": "Microsoft UFO shared WebSocket handler state causes cross-client response hijacking",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46416"
    },
    {
      "rank": 196,
      "cve_id": "CVE-2026-8359",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00275,
      "epss_percentile": 0.19938,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Gladinet",
      "product": "Triofox",
      "cwe": "CWE-476",
      "title": "Gladinet Triofox WOSHttpStatusModule.dll NULL Function Pointer Call DoS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8359"
    },
    {
      "rank": 197,
      "cve_id": "CVE-2026-8360",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00275,
      "epss_percentile": 0.19938,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Gladinet",
      "product": "Triofox",
      "cwe": "CWE-476",
      "title": "Gladinet Triofox Unchecked Return Value to NULL Pointer Dereference DOS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8360"
    },
    {
      "rank": 198,
      "cve_id": "CVE-2026-48916",
      "cvss_base": 6.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00275,
      "epss_percentile": 0.19919,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jenkins Project",
      "product": "Jenkins LDAP Plugin",
      "cwe": "CWE-918",
      "title": "Jenkins LDAP Plugin 807.v7d7de30930cf and earlier follows LDAP referrals.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48916"
    },
    {
      "rank": 199,
      "cve_id": "CVE-2026-4888",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00275,
      "epss_percentile": 0.19958,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wpeverest",
      "product": "Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder",
      "cwe": "CWE-862",
      "title": "Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder <= 3.4.7 - Missing Authorization to Authenticated (Subscriber+) Email Sending",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-4888"
    },
    {
      "rank": 200,
      "cve_id": "CVE-2026-42725",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00273,
      "epss_percentile": 0.1977,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WP Wham",
      "product": "Checkout Files Upload for WooCommerce",
      "cwe": "CWE-639",
      "title": "WordPress Checkout Files Upload for WooCommerce plugin <= 2.2.5 - Insecure Direct Object References (IDOR) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42725"
    },
    {
      "rank": 201,
      "cve_id": "CVE-2026-47273",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00273,
      "epss_percentile": 0.19711,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mcdope",
      "product": "pam_usb",
      "cwe": "CWE-91",
      "title": "pam_usb: XPath injection via PAM-supplied identifiers in pam_usb configuration queries",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47273"
    },
    {
      "rank": 202,
      "cve_id": "CVE-2026-44483",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00271,
      "epss_percentile": 0.19425,
      "kev": false,
      "kev_due_at": null,
      "vendor": "airjp73",
      "product": "rvf",
      "cwe": "CWE-1321",
      "title": "RVF: Prototype pollution in @rvf/set-get reachable via @rvf/core preprocessFormData (HTTP form data)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44483"
    },
    {
      "rank": 203,
      "cve_id": "CVE-2026-9014",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00268,
      "epss_percentile": 0.19036,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rahulbhangale",
      "product": "WP Promoter",
      "cwe": "CWE-862",
      "title": "WP Promoter <= 1.3 - Missing Authorization to Unauthenticated Statistics Reset via wpp-reset_stats AJAX Action",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9014"
    },
    {
      "rank": 204,
      "cve_id": "CVE-2026-44318",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00268,
      "epss_percentile": 0.19056,
      "kev": false,
      "kev_due_at": null,
      "vendor": "free5gc",
      "product": "free5gc",
      "cwe": "CWE-362",
      "title": "free5GC: BSF concurrent PUT /nbsf-management/v1/subscriptions/{subId} crashes the BSF process via concurrent map read/write on Subscriptions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44318"
    },
    {
      "rank": 205,
      "cve_id": "CVE-2026-48906",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00267,
      "epss_percentile": 0.18958,
      "kev": false,
      "kev_due_at": null,
      "vendor": "tassos.gr",
      "product": "Novarain/Tassos Framework (plg_system_nrframework)",
      "cwe": "CWE-284",
      "title": "Extension - tassos.gr - Arbitrary File Deletion in Novarain/Tassos Framework < 6.1.0 for Joomla",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48906"
    },
    {
      "rank": 206,
      "cve_id": "CVE-2026-45102",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00266,
      "epss_percentile": 0.18886,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OneUptime",
      "product": "oneuptime",
      "cwe": "CWE-693",
      "title": "OneUptime: RCE due to Node.js' vm module escape via error objects and infinite recursion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45102"
    },
    {
      "rank": 207,
      "cve_id": "CVE-2026-42081",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00266,
      "epss_percentile": 0.18885,
      "kev": false,
      "kev_due_at": null,
      "vendor": "free5gc",
      "product": "free5gc",
      "cwe": "CWE-358",
      "title": "free5GC: UE Security Capability bypass on NGAP PathSwitchRequest",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42081"
    },
    {
      "rank": 208,
      "cve_id": "CVE-2026-44460",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00265,
      "epss_percentile": 0.185,
      "kev": false,
      "kev_due_at": null,
      "vendor": "error311",
      "product": "FileRise",
      "cwe": "CWE-200",
      "title": "FileRise: TOTP Bypass via Setup Endpoint Disclosing Existing Secret",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44460"
    },
    {
      "rank": 209,
      "cve_id": "CVE-2025-10466",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00265,
      "epss_percentile": 0.18508,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Synology",
      "product": "Safe Access",
      "cwe": "CWE-79",
      "title": "Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in Safe Access in Synology Safe Access before 1.3.1-0329 allows remote authenticated users with administrator privileges to read or write specific files containing non-sensitive information or conduct limited denial-of-service in SRM.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-10466"
    },
    {
      "rank": 210,
      "cve_id": "CVE-2026-45061",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00263,
      "epss_percentile": 0.18285,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Budibase",
      "product": "budibase",
      "cwe": "CWE-918",
      "title": "Budibase: SSRF via trivial `.tar.gz` substring bypass in Plugin URL upload (`/api/plugin`)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45061"
    },
    {
      "rank": 211,
      "cve_id": "CVE-2026-45719",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00263,
      "epss_percentile": 0.18252,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Budibase",
      "product": "budibase",
      "cwe": "CWE-94",
      "title": "Budibase: CouchDB Reduce Injection via Unsanitized Calculation Parameter in V1 Views API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45719"
    },
    {
      "rank": 212,
      "cve_id": "CVE-2026-46056",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00262,
      "epss_percentile": 0.1819,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-416",
      "title": "Bluetooth: hci_event: fix potential UAF in SSP passkey handlers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46056"
    },
    {
      "rank": 213,
      "cve_id": "CVE-2026-42730",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00262,
      "epss_percentile": 0.18191,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Stylemix",
      "product": "MasterStudy LMS",
      "cwe": "CWE-89",
      "title": "WordPress MasterStudy LMS plugin <= 3.7.29 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42730"
    },
    {
      "rank": 214,
      "cve_id": "CVE-2026-48961",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00262,
      "epss_percentile": 0.18116,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PMQS",
      "product": "IO::Compress",
      "cwe": "CWE-755",
      "title": "IO::Compress versions from 2.207 before 2.220 for Perl ship a zipdetails CLI tool that crashes with undefined subroutine on Info-ZIP Unix Extra Field with 8-byte UID or GID",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48961"
    },
    {
      "rank": 215,
      "cve_id": "CVE-2026-40832",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00262,
      "epss_percentile": 0.18169,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MB connect line",
      "product": "mbCONNECT24",
      "cwe": "CWE-89",
      "title": "Authenticated SQLi in getDevicegroups function",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40832"
    },
    {
      "rank": 216,
      "cve_id": "CVE-2026-40835",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00262,
      "epss_percentile": 0.18171,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MB connect line",
      "product": "mbCONNECT24",
      "cwe": "CWE-89",
      "title": "Authenticated SQLi in saveObjectFromData function",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40835"
    },
    {
      "rank": 217,
      "cve_id": "CVE-2026-40837",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00262,
      "epss_percentile": 0.18169,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MB connect line",
      "product": "mbCONNECT24",
      "cwe": "CWE-89",
      "title": "Authenticated SQLi in getProjectScalings function",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40837"
    },
    {
      "rank": 218,
      "cve_id": "CVE-2026-40838",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00262,
      "epss_percentile": 0.18171,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MB connect line",
      "product": "mbCONNECT24",
      "cwe": "CWE-89",
      "title": "Authenticated SQLi in getDeviceScalings function",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40838"
    },
    {
      "rank": 219,
      "cve_id": "CVE-2026-40839",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00262,
      "epss_percentile": 0.18172,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MB connect line",
      "product": "mbCONNECT24",
      "cwe": "CWE-89",
      "title": "Authenticated SQLi in getComponentScalings function",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40839"
    },
    {
      "rank": 220,
      "cve_id": "CVE-2026-40840",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00262,
      "epss_percentile": 0.18171,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MB connect line",
      "product": "mbCONNECT24",
      "cwe": "CWE-89",
      "title": "Authenticated SQLi in VerifyCreateLicences function",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40840"
    },
    {
      "rank": 221,
      "cve_id": "CVE-2026-40841",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00262,
      "epss_percentile": 0.18171,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MB connect line",
      "product": "mbCONNECT24",
      "cwe": "CWE-89",
      "title": "Authenticated SQLi in getProjectTags function",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40841"
    },
    {
      "rank": 222,
      "cve_id": "CVE-2026-40842",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00262,
      "epss_percentile": 0.18172,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MB connect line",
      "product": "mbCONNECT24",
      "cwe": "CWE-89",
      "title": "Authenticated SQLi in getWidgetTags function",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40842"
    },
    {
      "rank": 223,
      "cve_id": "CVE-2026-40843",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00262,
      "epss_percentile": 0.18172,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MB connect line",
      "product": "mbCONNECT24",
      "cwe": "CWE-89",
      "title": "Authenticated SQLi in alarming view",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40843"
    },
    {
      "rank": 224,
      "cve_id": "CVE-2026-40844",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00262,
      "epss_percentile": 0.1817,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MB connect line",
      "product": "mbCONNECT24",
      "cwe": "CWE-89",
      "title": "Authenticated SQLi in dashboard view",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40844"
    },
    {
      "rank": 225,
      "cve_id": "CVE-2026-40845",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00262,
      "epss_percentile": 0.18172,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MB connect line",
      "product": "mbCONNECT24",
      "cwe": "CWE-89",
      "title": "Authenticated SQLi in devices_configuration view",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40845"
    },
    {
      "rank": 226,
      "cve_id": "CVE-2026-40846",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00262,
      "epss_percentile": 0.18169,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MB connect line",
      "product": "mbCONNECT24",
      "cwe": "CWE-89",
      "title": "Authenticated SQLi in system view",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40846"
    },
    {
      "rank": 227,
      "cve_id": "CVE-2026-40847",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00262,
      "epss_percentile": 0.18173,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MB connect line",
      "product": "mbCONNECT24",
      "cwe": "CWE-89",
      "title": "Authenticated SQLi in system_tag view",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40847"
    },
    {
      "rank": 228,
      "cve_id": "CVE-2026-40848",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00262,
      "epss_percentile": 0.1817,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MB connect line",
      "product": "mbCONNECT24",
      "cwe": "CWE-89",
      "title": "Authenticated SQLi in tag view",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40848"
    },
    {
      "rank": 229,
      "cve_id": "CVE-2026-40849",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00262,
      "epss_percentile": 0.1817,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MB connect line",
      "product": "mbCONNECT24",
      "cwe": "CWE-89",
      "title": "Authenticated SQLi in user_alarmprofile view",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40849"
    },
    {
      "rank": 230,
      "cve_id": "CVE-2026-45716",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00261,
      "epss_percentile": 0.18031,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Budibase",
      "product": "budibase",
      "cwe": "CWE-269",
      "title": "Budibase: Builder-to-Admin Privilege Escalation via onboardUsers Endpoint Without SMTP Configuration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45716"
    },
    {
      "rank": 231,
      "cve_id": "CVE-2026-3012",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00261,
      "epss_percentile": 0.18025,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-345",
      "title": "Samba: group policy certificate enrollment uses http:// without validation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-3012"
    },
    {
      "rank": 232,
      "cve_id": "CVE-2026-48917",
      "cvss_base": 6.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0026,
      "epss_percentile": 0.17917,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jenkins Project",
      "product": "Jenkins LDAP Plugin",
      "cwe": "CWE-502",
      "title": "Jenkins LDAP Plugin 807.v7d7de30930cf and earlier deserializes data from LDAP referrals without validation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48917"
    },
    {
      "rank": 233,
      "cve_id": "CVE-2026-48919",
      "cvss_base": 6.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0026,
      "epss_percentile": 0.17917,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jenkins Project",
      "product": "Jenkins Active Directory Plugin",
      "cwe": "CWE-502",
      "title": "Jenkins Active Directory Plugin 2.41 and earlier deserializes data from LDAP referrals without validation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48919"
    },
    {
      "rank": 234,
      "cve_id": "CVE-2026-4390",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0026,
      "epss_percentile": 0.1788,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "TeamSpeak 3 Server",
      "cwe": "CWE-119",
      "title": "TeamSpeak 3 Server Connection State Management process_resend_queue use after free",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-4390"
    },
    {
      "rank": 235,
      "cve_id": "CVE-2026-44886",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00258,
      "epss_percentile": 0.17634,
      "kev": false,
      "kev_due_at": null,
      "vendor": "leiweibau",
      "product": "Pi.Alert",
      "cwe": "CWE-89",
      "title": "Pi.Alert: Web Interface Vulnerable to Unauthenticated Blind SQL Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44886"
    },
    {
      "rank": 236,
      "cve_id": "CVE-2026-45548",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00258,
      "epss_percentile": 0.1762,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Budibase",
      "product": "budibase",
      "cwe": "CWE-918",
      "title": "Budibase: SSRF in AI Extract File Automation Step via Missing IP Blacklist Validation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45548"
    },
    {
      "rank": 237,
      "cve_id": "CVE-2026-45715",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00258,
      "epss_percentile": 0.17622,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Budibase",
      "product": "budibase",
      "cwe": "CWE-918",
      "title": "Budibase: SSRF Bypass via HTTP Redirect in REST Datasource Integration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45715"
    },
    {
      "rank": 238,
      "cve_id": "CVE-2026-48152",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00257,
      "epss_percentile": 0.17531,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Budibase",
      "product": "budibase",
      "cwe": "CWE-863",
      "title": "Budibase: Basic app users can exfiltrate stored REST datasource auth by rewriting datasource base URL",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48152"
    },
    {
      "rank": 239,
      "cve_id": "CVE-2026-42736",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00256,
      "epss_percentile": 0.17401,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wordplus",
      "product": "BP Better Messages",
      "cwe": "CWE-639",
      "title": "WordPress BP Better Messages plugin <= 2.14.16 - Insecure Direct Object References (IDOR) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42736"
    },
    {
      "rank": 240,
      "cve_id": "CVE-2026-3349",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00256,
      "epss_percentile": 0.17492,
      "kev": false,
      "kev_due_at": null,
      "vendor": "minhnhut",
      "product": "MinhNhut Link Gateway",
      "cwe": "CWE-79",
      "title": "MinhNhut Link Gateway <= 3.6.1 - Reflected Cross-Site Scripting via 'url' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-3349"
    },
    {
      "rank": 241,
      "cve_id": "CVE-2026-42735",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00255,
      "epss_percentile": 0.17273,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Iqonic Design",
      "product": "KiviCare",
      "cwe": "CWE-288",
      "title": "WordPress KiviCare plugin <= 4.3.0 - Broken Authentication vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42735"
    },
    {
      "rank": 242,
      "cve_id": "CVE-2025-13167",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00254,
      "epss_percentile": 0.17174,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Synology",
      "product": "Synology Contacts",
      "cwe": "CWE-79",
      "title": "Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in contact functionality in Synology Contacts before 1.0.10-20659 allows remote authenticated users to read or write specific files containing non-sensitive information via unspecified vectors.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-13167"
    },
    {
      "rank": 243,
      "cve_id": "CVE-2026-42749",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00252,
      "epss_percentile": 0.16957,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Themeisle",
      "product": "Disable Comments for Any Post Types (Remove comments)",
      "cwe": "CWE-288",
      "title": "WordPress Disable Comments for Any Post Types (Remove comments) plugin <= 1.3.0 - Broken Authentication vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42749"
    },
    {
      "rank": 244,
      "cve_id": "CVE-2026-45717",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00251,
      "epss_percentile": 0.16796,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Budibase",
      "product": "budibase",
      "cwe": "CWE-862",
      "title": "Budibase: `PUT /api/datasources/:datasourceId` is protected only by `TABLE/READ` permission instead of builder access, allowing any authenticated app user to overwrite datasource connection parameters including host, port, and URL.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45717"
    },
    {
      "rank": 245,
      "cve_id": "CVE-2026-45088",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00251,
      "epss_percentile": 0.16771,
      "kev": false,
      "kev_due_at": null,
      "vendor": "hahwul",
      "product": "dalfox",
      "cwe": "CWE-73",
      "title": "Dalfox: Unauthenticated Arbitrary File Read with Out-of-Band Exfiltration via `custom-payload-file` in Dalfox Server Mode",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45088"
    },
    {
      "rank": 246,
      "cve_id": "CVE-2026-42082",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00251,
      "epss_percentile": 0.16762,
      "kev": false,
      "kev_due_at": null,
      "vendor": "free5gc",
      "product": "free5gc",
      "cwe": "CWE-358",
      "title": "free5GC: Missing Concurrent NAS SMC Validation During NGAP Handover",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42082"
    },
    {
      "rank": 247,
      "cve_id": "CVE-2026-33552",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00251,
      "epss_percentile": 0.16815,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-269",
      "title": "Northern.tech Mender Enterprise Server before 4.1.1 has Incorrect Access Control.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-33552"
    },
    {
      "rank": 248,
      "cve_id": "CVE-2026-9617",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0025,
      "epss_percentile": 0.16672,
      "kev": false,
      "kev_due_at": null,
      "vendor": "DALIBO",
      "product": "PostgreSQL Anonymizer",
      "cwe": "CWE-89",
      "title": "PostgreSQL Anonymizer: malicious column name allows SQL injection via anon.k_anonymity() function",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9617"
    },
    {
      "rank": 249,
      "cve_id": "CVE-2026-38930",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0025,
      "epss_percentile": 0.1662,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-89",
      "title": "OpenRapid RapidCMS v1.3.1 was discovered to contain an authentication bypass in the /template/default/menu.php component. This vulnerability is exploited via injecting a crafted SQL payload into the name cookie parameter.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-38930"
    },
    {
      "rank": 250,
      "cve_id": "CVE-2026-44838",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0025,
      "epss_percentile": 0.16698,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rabbitmq",
      "product": "rabbitmq-server",
      "cwe": "CWE-863",
      "title": "RabbitMQ MQTT Topic Permission Authorization Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44838"
    },
    {
      "rank": 251,
      "cve_id": "CVE-2026-44681",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00249,
      "epss_percentile": 0.16537,
      "kev": false,
      "kev_due_at": null,
      "vendor": "authlib",
      "product": "authlib",
      "cwe": "CWE-601",
      "title": "Authlib: Open Redirect in Authlib OIDC Implicit/Hybrid Authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44681"
    },
    {
      "rank": 252,
      "cve_id": "CVE-2024-47270",
      "cvss_base": 2.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00249,
      "epss_percentile": 0.16606,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Synology",
      "product": "Surveillance Station",
      "cwe": "CWE-281",
      "title": "Improper preservation of permissions vulnerability in Archiving Push functionality in Synology Surveillance Station before 9.2.2-11575 and 9.2.2-9575 allows remote authenticated users with administrator privileges to limited file write via unspecified vectors.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-47270"
    },
    {
      "rank": 253,
      "cve_id": "CVE-2024-47272",
      "cvss_base": 2.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00249,
      "epss_percentile": 0.16605,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Synology",
      "product": "Surveillance Station",
      "cwe": "CWE-863",
      "title": "Incorrect authorization vulnerability in IO Module functionality in Synology Surveillance Station before 9.2.2-11575 and 9.2.2-9575 allows remote authenticated users with administrator privileges to limited file write via unspecified vectors.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-47272"
    },
    {
      "rank": 254,
      "cve_id": "CVE-2026-42732",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00248,
      "epss_percentile": 0.16399,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ads by WPQuads",
      "product": "Ads by WPQuads",
      "cwe": "CWE-1284",
      "title": "WordPress Ads by WPQuads plugin <= 3.0.2 - Broken Authentication vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42732"
    },
    {
      "rank": 255,
      "cve_id": "CVE-2026-45108",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00246,
      "epss_percentile": 0.16119,
      "kev": false,
      "kev_due_at": null,
      "vendor": "himmelblau-idm",
      "product": "himmelblau",
      "cwe": "CWE-863",
      "title": "Himmelblau: Authentication Bypass via Cross-User Local Session Impersonation in Device Authorization Grant (DAG) Flow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45108"
    },
    {
      "rank": 256,
      "cve_id": "CVE-2026-45137",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00246,
      "epss_percentile": 0.16166,
      "kev": false,
      "kev_due_at": null,
      "vendor": "solana-foundation",
      "product": "anchor",
      "cwe": "CWE-20",
      "title": "Anchor: Program<'info, System> is not properly validated",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45137"
    },
    {
      "rank": 257,
      "cve_id": "CVE-2026-42740",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00245,
      "epss_percentile": 0.1608,
      "kev": false,
      "kev_due_at": null,
      "vendor": "tainacan",
      "product": "Tainacan",
      "cwe": "CWE-89",
      "title": "WordPress Tainacan plugin <= 1.0.3 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42740"
    },
    {
      "rank": 258,
      "cve_id": "CVE-2026-42747",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00245,
      "epss_percentile": 0.16081,
      "kev": false,
      "kev_due_at": null,
      "vendor": "hassantafreshi",
      "product": "Easy Form Builder",
      "cwe": "CWE-89",
      "title": "WordPress Easy Form Builder plugin <= 4.0.6 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42747"
    },
    {
      "rank": 259,
      "cve_id": "CVE-2026-44521",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00243,
      "epss_percentile": 0.15768,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Studio-42",
      "product": "elFinder",
      "cwe": "CWE-89",
      "title": "elFinder: SQL Injection MySQL Volume Driver (elFinderVolumeMySQL)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44521"
    },
    {
      "rank": 260,
      "cve_id": "CVE-2026-45089",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00243,
      "epss_percentile": 0.15785,
      "kev": false,
      "kev_due_at": null,
      "vendor": "hahwul",
      "product": "dalfox",
      "cwe": "CWE-73",
      "title": "Dalfox: Unauthenticated Arbitrary File Create/Append via `output` Option in Dalfox Server Mode",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45089"
    },
    {
      "rank": 261,
      "cve_id": "CVE-2026-6052",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00243,
      "epss_percentile": 0.1571,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Db2",
      "cwe": "CWE-400",
      "title": "IBM® Db2® is vulnerable to running out of memory when executing certain queries with MDC tables",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6052"
    },
    {
      "rank": 262,
      "cve_id": "CVE-2026-2601",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00243,
      "epss_percentile": 0.15739,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GitLab",
      "product": "GitLab",
      "cwe": "CWE-862",
      "title": "Missing Authorization in GitLab",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-2601"
    },
    {
      "rank": 263,
      "cve_id": "CVE-2026-44988",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00242,
      "epss_percentile": 0.15636,
      "kev": false,
      "kev_due_at": null,
      "vendor": "LibVNC",
      "product": "libvncserver",
      "cwe": "CWE-787",
      "title": "LibVNCClient Tight Gradient decoding allows malicious server-triggered heap/stack OOB writes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44988"
    },
    {
      "rank": 264,
      "cve_id": "CVE-2026-42726",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00242,
      "epss_percentile": 0.15646,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Strategy11 Team",
      "product": "AWP Classifieds",
      "cwe": "CWE-862",
      "title": "WordPress AWP Classifieds plugin <= 4.4.5 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42726"
    },
    {
      "rank": 265,
      "cve_id": "CVE-2026-44320",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00241,
      "epss_percentile": 0.15483,
      "kev": false,
      "kev_due_at": null,
      "vendor": "free5gc",
      "product": "free5gc",
      "cwe": "CWE-306",
      "title": "free5GC: NEF nnef-callback route group is unauthenticated; forged callback requests are accepted into the processing path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44320"
    },
    {
      "rank": 266,
      "cve_id": "CVE-2026-6936",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0024,
      "epss_percentile": 0.15379,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "i",
      "cwe": "CWE-674",
      "title": "IBM i is Affected by a Denial of Service Vulnerability []",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6936"
    },
    {
      "rank": 267,
      "cve_id": "CVE-2026-42878",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0024,
      "epss_percentile": 0.15448,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NeoRazorX",
      "product": "facturascripts",
      "cwe": "CWE-200",
      "title": "FacturaScripts: Unauthenticated phpinfo() Disclosure via Installer Endpoint in FacturaScripts",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42878"
    },
    {
      "rank": 268,
      "cve_id": "CVE-2026-40823",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00239,
      "epss_percentile": 0.15276,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MB connect line",
      "product": "mbCONNECT24",
      "cwe": "CWE-89",
      "title": "Authenticated SQLi in DevSerialReset function",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40823"
    },
    {
      "rank": 269,
      "cve_id": "CVE-2026-40824",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00239,
      "epss_percentile": 0.15276,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MB connect line",
      "product": "mbCONNECT24",
      "cwe": "CWE-89",
      "title": "Authenticated SQLi in accountstatus view",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40824"
    },
    {
      "rank": 270,
      "cve_id": "CVE-2026-40825",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00239,
      "epss_percentile": 0.15276,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MB connect line",
      "product": "mbCONNECT24",
      "cwe": "CWE-89",
      "title": "Authenticated SQLi in accountstatus view",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40825"
    },
    {
      "rank": 271,
      "cve_id": "CVE-2026-42745",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00238,
      "epss_percentile": 0.15092,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ZAYTECH",
      "product": "Smart Online Order for Clover",
      "cwe": "CWE-288",
      "title": "WordPress Smart Online Order for Clover plugin <= 1.6.0 - Broken Authentication vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42745"
    },
    {
      "rank": 272,
      "cve_id": "CVE-2026-7254",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00238,
      "epss_percentile": 0.15045,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "OPENBMC",
      "cwe": "CWE-1284",
      "title": "Open BMC Denial of Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7254"
    },
    {
      "rank": 273,
      "cve_id": "CVE-2026-3348",
      "cvss_base": 4.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00237,
      "epss_percentile": 0.15032,
      "kev": false,
      "kev_due_at": null,
      "vendor": "minhnhut",
      "product": "MinhNhut Link Gateway",
      "cwe": "CWE-79",
      "title": "MinhNhut Link Gateway <= 3.6.1 - Authenticated (Admin+) Stored Cross-Site Scripting via Plugin Settings",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-3348"
    },
    {
      "rank": 274,
      "cve_id": "CVE-2026-42755",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00236,
      "epss_percentile": 0.14906,
      "kev": false,
      "kev_due_at": null,
      "vendor": "RealMag777",
      "product": "TableOn",
      "cwe": "CWE-89",
      "title": "WordPress TableOn plugin <= 1.0.5.1 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42755"
    },
    {
      "rank": 275,
      "cve_id": "CVE-2026-47119",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00236,
      "epss_percentile": 0.14792,
      "kev": false,
      "kev_due_at": null,
      "vendor": "3clyp50",
      "product": "agent-zero",
      "cwe": "CWE-79",
      "title": "Agent Zero < 1.15 Stored XSS via image_get API Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47119"
    },
    {
      "rank": 276,
      "cve_id": "CVE-2026-9156",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00235,
      "epss_percentile": 0.14688,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tanium",
      "product": "Tanium Server",
      "cwe": "CWE-772",
      "title": "Tanium addressed a denial of service vulnerability in Tanium Server.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9156"
    },
    {
      "rank": 277,
      "cve_id": "CVE-2026-2030",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00235,
      "epss_percentile": 0.14716,
      "kev": false,
      "kev_due_at": null,
      "vendor": "livemesh",
      "product": "WPBakery Page Builder Addons by Livemesh",
      "cwe": "CWE-79",
      "title": "WPBakery Page Builder Addons by Livemesh <= 3.9.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-2030"
    },
    {
      "rank": 278,
      "cve_id": "CVE-2026-8866",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00235,
      "epss_percentile": 0.14715,
      "kev": false,
      "kev_due_at": null,
      "vendor": "bradyholt",
      "product": "jQuery googleslides",
      "cwe": "CWE-79",
      "title": "jQuery googleslides <= 1.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8866"
    },
    {
      "rank": 279,
      "cve_id": "CVE-2026-8868",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00235,
      "epss_percentile": 0.14716,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jonathan-robrecht",
      "product": "Single Mailchimp",
      "cwe": "CWE-79",
      "title": "Single Mailchimp <= 1.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8868"
    },
    {
      "rank": 280,
      "cve_id": "CVE-2026-8869",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00235,
      "epss_percentile": 0.14716,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mutualfunddata",
      "product": "Mutual Funds Data",
      "cwe": "CWE-79",
      "title": "Mutual Funds Data <= 1.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'title' Shortcode Attribute",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8869"
    },
    {
      "rank": 281,
      "cve_id": "CVE-2026-8877",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00235,
      "epss_percentile": 0.14715,
      "kev": false,
      "kev_due_at": null,
      "vendor": "esiteq",
      "product": "Responsive Video Embedder",
      "cwe": "CWE-79",
      "title": "Responsive Video Embedder <= 0.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8877"
    },
    {
      "rank": 282,
      "cve_id": "CVE-2026-8887",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00235,
      "epss_percentile": 0.14717,
      "kev": false,
      "kev_due_at": null,
      "vendor": "konforti",
      "product": "Listen Shortcode",
      "cwe": "CWE-79",
      "title": "Listen Shortcode <= 1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8887"
    },
    {
      "rank": 283,
      "cve_id": "CVE-2026-8897",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00235,
      "epss_percentile": 0.14715,
      "kev": false,
      "kev_due_at": null,
      "vendor": "vincentastolfi",
      "product": "Shortcode Buddy",
      "cwe": "CWE-79",
      "title": "Shortcode Buddy <= 0.1.9.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8897"
    },
    {
      "rank": 284,
      "cve_id": "CVE-2026-8898",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00235,
      "epss_percentile": 0.14714,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ruchit47",
      "product": "Events In City",
      "cwe": "CWE-79",
      "title": "Events In City <= 3.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8898"
    },
    {
      "rank": 285,
      "cve_id": "CVE-2026-45090",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00231,
      "epss_percentile": 0.14209,
      "kev": false,
      "kev_due_at": null,
      "vendor": "hahwul",
      "product": "dalfox",
      "cwe": "CWE-362",
      "title": "Dalfox: Unauthenticated Remote DoS via Closed-Channel Write in `ParameterAnalysis` (server mode)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45090"
    },
    {
      "rank": 286,
      "cve_id": "CVE-2026-49059",
      "cvss_base": 4.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00231,
      "epss_percentile": 0.14268,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Facebook",
      "product": "Facebook for WooCommerce",
      "cwe": "CWE-601",
      "title": "WordPress Facebook for WooCommerce plugin <= 3.7.0 - Open Redirection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49059"
    },
    {
      "rank": 287,
      "cve_id": "CVE-2026-48971",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00231,
      "epss_percentile": 0.14238,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WebToffee",
      "product": "Product Import Export for WooCommerce",
      "cwe": "CWE-862",
      "title": "WordPress Product Import Export for WooCommerce plugin <= 2.5.6 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48971"
    },
    {
      "rank": 288,
      "cve_id": "CVE-2024-47269",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0023,
      "epss_percentile": 0.14103,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Synology",
      "product": "Surveillance Station",
      "cwe": "CWE-319",
      "title": "Cleartext transmission of sensitive information vulnerability in Export Key functionality in Synology Surveillance Station before 9.2.2-11575 and 9.2.2-9575 allows remote authenticated users with administrator privileges to obtain sensitive information via unspecified vectors.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-47269"
    },
    {
      "rank": 289,
      "cve_id": "CVE-2026-2280",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0023,
      "epss_percentile": 0.14118,
      "kev": false,
      "kev_due_at": null,
      "vendor": "larsdrasmussen",
      "product": "rexCrawler",
      "cwe": "CWE-79",
      "title": "rexCrawler <= 1.0.15 - Authenticated (Administrator+) Stored Cross-Site Scripting via Settings",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-2280"
    },
    {
      "rank": 290,
      "cve_id": "CVE-2026-2288",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0023,
      "epss_percentile": 0.14118,
      "kev": false,
      "kev_due_at": null,
      "vendor": "silvercover",
      "product": "myLinksDump",
      "cwe": "CWE-79",
      "title": "myLinksDump <= 1.6 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'link_title' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-2288"
    },
    {
      "rank": 291,
      "cve_id": "CVE-2026-42761",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00229,
      "epss_percentile": 0.14015,
      "kev": false,
      "kev_due_at": null,
      "vendor": "RealMag777",
      "product": "Active Products Tables for WooCommerce",
      "cwe": "CWE-89",
      "title": "WordPress Active Products Tables for WooCommerce plugin <= 1.0.9 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42761"
    },
    {
      "rank": 292,
      "cve_id": "CVE-2026-42879",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00229,
      "epss_percentile": 0.13995,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NeoRazorX",
      "product": "facturascripts",
      "cwe": "CWE-94",
      "title": "FacturaScripts: Authenticated Remote Code Execution (RCE) via GIF Image Upload in Product Images",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42879"
    },
    {
      "rank": 293,
      "cve_id": "CVE-2026-8405",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00228,
      "epss_percentile": 0.13879,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Guardium Data Protection",
      "cwe": "CWE-200",
      "title": "IBM Guardium Data Protection is affected by Exposure of Sensitive Information vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8405"
    },
    {
      "rank": 294,
      "cve_id": "CVE-2026-48149",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00226,
      "epss_percentile": 0.13543,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Budibase",
      "product": "budibase",
      "cwe": "CWE-79",
      "title": "Budibase: Stored XSS in Text component: BASIC users execute JS in admin session via MarkdownViewer innerHTML + CDN+srcdoc CSP bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48149"
    },
    {
      "rank": 295,
      "cve_id": "CVE-2026-48148",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00226,
      "epss_percentile": 0.13622,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Budibase",
      "product": "budibase",
      "cwe": "CWE-918",
      "title": "Budibase: Unvalidated VectorDB Host Parameter Enables SSRF",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48148"
    },
    {
      "rank": 296,
      "cve_id": "CVE-2026-46538",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00225,
      "epss_percentile": 0.13419,
      "kev": false,
      "kev_due_at": null,
      "vendor": "microsoft",
      "product": "UFO",
      "cwe": "CWE-294",
      "title": "Microsoft UFO accepts cross-device TASK_END messages by session_id only, allowing peer task-result injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46538"
    },
    {
      "rank": 297,
      "cve_id": "CVE-2026-48151",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00224,
      "epss_percentile": 0.13312,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Budibase",
      "product": "budibase",
      "cwe": "CWE-862",
      "title": "Budibase: Webhook schema endpoint authorization bypass allows unauthenticated mutation of webhook and automation schema",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48151"
    },
    {
      "rank": 298,
      "cve_id": "CVE-2026-46427",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00223,
      "epss_percentile": 0.13226,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Budibase",
      "product": "budibase",
      "cwe": "CWE-200",
      "title": "Budibase: Snowflake private key returned unmasked from datasource API to BASIC users",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46427"
    },
    {
      "rank": 299,
      "cve_id": "CVE-2026-40833",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00223,
      "epss_percentile": 0.13223,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MB connect line",
      "product": "mbCONNECT24",
      "cwe": "CWE-89",
      "title": "Authenticated SQLi in saveDashboardLayout function",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40833"
    },
    {
      "rank": 300,
      "cve_id": "CVE-2026-40834",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00223,
      "epss_percentile": 0.13224,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MB connect line",
      "product": "mbCONNECT24",
      "cwe": "CWE-89",
      "title": "Authenticated SQLi in saveDashboardLayout function",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40834"
    },
    {
      "rank": 301,
      "cve_id": "CVE-2026-40836",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00223,
      "epss_percentile": 0.13223,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MB connect line",
      "product": "mbCONNECT24",
      "cwe": "CWE-89",
      "title": "Authenticated SQLi in inmessage model",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40836"
    },
    {
      "rank": 302,
      "cve_id": "CVE-2026-48918",
      "cvss_base": 6.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00223,
      "epss_percentile": 0.13152,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jenkins Project",
      "product": "Jenkins Active Directory Plugin",
      "cwe": "CWE-918",
      "title": "Jenkins Active Directory Plugin 2.41 and earlier follows LDAP referrals by default.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48918"
    },
    {
      "rank": 303,
      "cve_id": "CVE-2026-3895",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00223,
      "epss_percentile": 0.13162,
      "kev": false,
      "kev_due_at": null,
      "vendor": "livemesh",
      "product": "WPBakery Page Builder Addons by Livemesh",
      "cwe": "CWE-862",
      "title": "WPBakery Page Builder Addons by Livemesh <= 3.9.4 - Missing Authorization to Authenticated (Subscriber+) Stored Cross-Site Scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-3895"
    },
    {
      "rank": 304,
      "cve_id": "CVE-2026-3896",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00223,
      "epss_percentile": 0.13161,
      "kev": false,
      "kev_due_at": null,
      "vendor": "livemesh",
      "product": "Livemesh SiteOrigin Widgets",
      "cwe": "CWE-862",
      "title": "Livemesh SiteOrigin Widgets <= 3.9.2 - Missing Authorization to Authenticated (Subscriber+) Stored Cross-Site Scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-3896"
    },
    {
      "rank": 305,
      "cve_id": "CVE-2026-3897",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00223,
      "epss_percentile": 0.13161,
      "kev": false,
      "kev_due_at": null,
      "vendor": "livemesh",
      "product": "Livemesh Addons for Beaver Builder",
      "cwe": "CWE-862",
      "title": "Livemesh Addons for Beaver Builder <= 3.9.2 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Missing Authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-3897"
    },
    {
      "rank": 306,
      "cve_id": "CVE-2026-9609",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": 0.00223,
      "epss_percentile": 0.13148,
      "kev": false,
      "kev_due_at": null,
      "vendor": "QianFox",
      "product": "FoxCMS",
      "cwe": "CWE-640",
      "title": "QianFox FoxCMS Admin.php edit password recovery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9609"
    },
    {
      "rank": 307,
      "cve_id": "CVE-2026-49051",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0022,
      "epss_percentile": 0.12858,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Prasad Kirpekar",
      "product": "WP Meta and Date Remover",
      "cwe": "CWE-862",
      "title": "WordPress WP Meta and Date Remover plugin <= 2.3.6 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49051"
    },
    {
      "rank": 308,
      "cve_id": "CVE-2026-1248",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00219,
      "epss_percentile": 0.12709,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Business Automation Workflow containers and traditional",
      "cwe": "CWE-209",
      "title": "IBM Business Automation Workflow information leak",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-1248"
    },
    {
      "rank": 309,
      "cve_id": "CVE-2026-9712",
      "cvss_base": 3.8,
      "cvss_severity": "LOW",
      "epss_score": 0.00219,
      "epss_percentile": 0.12683,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pretix",
      "product": "pretix",
      "cwe": "CWE-639",
      "title": "Insecure direct object reference",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9712"
    },
    {
      "rank": 310,
      "cve_id": "CVE-2025-41669",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00218,
      "epss_percentile": 0.12544,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Phoenix Contact",
      "product": "AXC F 1152",
      "cwe": "CWE-347",
      "title": "Insufficient Verification of Data Authenticity",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-41669"
    },
    {
      "rank": 311,
      "cve_id": "CVE-2022-41656",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00218,
      "epss_percentile": 0.12613,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Bizswoop",
      "product": "Account Manager for WooCommerce",
      "cwe": "CWE-862",
      "title": "WordPress Account Manager for WooCommerce plugin <= 2.1.2 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2022-41656"
    },
    {
      "rank": 312,
      "cve_id": "CVE-2026-48146",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00217,
      "epss_percentile": 0.12387,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Budibase",
      "product": "budibase",
      "cwe": "CWE-918",
      "title": "Budibase: SSRF via OAuth2 Config Validation — Missing fetchWithBlacklist Protection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48146"
    },
    {
      "rank": 313,
      "cve_id": "CVE-2026-8884",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00217,
      "epss_percentile": 0.12452,
      "kev": false,
      "kev_due_at": null,
      "vendor": "neilmccutcheon",
      "product": "Instant-Quote.co Quotation Page",
      "cwe": "CWE-79",
      "title": "Instant-Quote.co Quotation Page <= 1.3.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8884"
    },
    {
      "rank": 314,
      "cve_id": "CVE-2026-49102",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00216,
      "epss_percentile": 0.12351,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Webmin",
      "product": "Webmin",
      "cwe": "CWE-79",
      "title": "Webmin before 2.640 allows mailboxes/detach.cgi XSS via an SVG document attachment that is viewed in the mailboxes component, because image/svg+xml is used instead of a safe type (e.g., text/plain).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49102"
    },
    {
      "rank": 315,
      "cve_id": "CVE-2026-44830",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00215,
      "epss_percentile": 0.12154,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dataojitori",
      "product": "nocturne_memory",
      "cwe": "CWE-306",
      "title": "Empty API_TOKEN disables authentication on network-reachable HTTP/SSE transport",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44830"
    },
    {
      "rank": 316,
      "cve_id": "CVE-2026-5516",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00213,
      "epss_percentile": 0.11907,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "WebSphere Application Server - Liberty",
      "cwe": "CWE-362",
      "title": "IBM WebSphere Application Server Liberty is affected by a security bypass vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-5516"
    },
    {
      "rank": 317,
      "cve_id": "CVE-2026-49045",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00213,
      "epss_percentile": 0.11863,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WP Media",
      "product": "Adminimize",
      "cwe": "CWE-862",
      "title": "WordPress Adminimize plugin <= 1.11.11 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49045"
    },
    {
      "rank": 318,
      "cve_id": "CVE-2026-49054",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00213,
      "epss_percentile": 0.11864,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mamunur Rashid",
      "product": "The Post Grid",
      "cwe": "CWE-862",
      "title": "WordPress The Post Grid plugin <= 7.9.2 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49054"
    },
    {
      "rank": 319,
      "cve_id": "CVE-2026-42280",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00211,
      "epss_percentile": 0.11683,
      "kev": false,
      "kev_due_at": null,
      "vendor": "auth0",
      "product": "auth0.js",
      "cwe": "CWE-863",
      "title": "Improper Permission Checking in Auth.js SDK",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42280"
    },
    {
      "rank": 320,
      "cve_id": "CVE-2026-8707",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00211,
      "epss_percentile": 0.11642,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nsthemes",
      "product": "NS Product icon badge",
      "cwe": "CWE-79",
      "title": "NS Product icon badge <= 1.2.4 - Reflected Cross-Site Scripting via PHP_SELF",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8707"
    },
    {
      "rank": 321,
      "cve_id": "CVE-2026-48924",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00208,
      "epss_percentile": 0.1124,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jenkins Project",
      "product": "Jenkins Bitbucket OAuth Plugin",
      "cwe": "CWE-601",
      "title": "Jenkins Bitbucket OAuth Plugin 0.17 and earlier does not restrict the redirect URL after login, allowing attackers to perform phishing attacks.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48924"
    },
    {
      "rank": 322,
      "cve_id": "CVE-2026-44720",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00207,
      "epss_percentile": 0.11183,
      "kev": false,
      "kev_due_at": null,
      "vendor": "th30d4y",
      "product": "OpenLearnX",
      "cwe": "CWE-287",
      "title": "OpenLearnX: Critical Authentication Bypass via JWT Signature Verification Disabled Leading to Account Takeover",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44720"
    },
    {
      "rank": 323,
      "cve_id": "CVE-2026-42744",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00207,
      "epss_percentile": 0.11128,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ads by WPQuads",
      "product": "Ads by WPQuads",
      "cwe": "CWE-1284",
      "title": "WordPress Ads by WPQuads plugin <= 3.0.2 - Bypass Vulnerability vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42744"
    },
    {
      "rank": 324,
      "cve_id": "CVE-2026-9608",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00206,
      "epss_percentile": 0.11002,
      "kev": false,
      "kev_due_at": null,
      "vendor": "QianFox",
      "product": "FoxCMS",
      "cwe": "CWE-79",
      "title": "QianFox FoxCMS Administrator Backend edit cross site scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9608"
    },
    {
      "rank": 325,
      "cve_id": "CVE-2026-8844",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00204,
      "epss_percentile": 0.10747,
      "kev": false,
      "kev_due_at": null,
      "vendor": "kevin1804",
      "product": "Responsive Check",
      "cwe": "CWE-79",
      "title": "Responsive Check <= 0.0.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8844"
    },
    {
      "rank": 326,
      "cve_id": "CVE-2026-42754",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00203,
      "epss_percentile": 0.10654,
      "kev": false,
      "kev_due_at": null,
      "vendor": "phbernard",
      "product": "Favicon",
      "cwe": "CWE-79",
      "title": "WordPress Favicon plugin <= 1.3.46 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42754"
    },
    {
      "rank": 327,
      "cve_id": "CVE-2026-2253",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00201,
      "epss_percentile": 0.103,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hitachi Vantara",
      "product": "Pentaho Data Integration and Analytics",
      "cwe": "CWE-611",
      "title": "Hitachi Vantara Pentaho Data Integration & Analytics - Improper Restriction of XML External Entity Reference",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-2253"
    },
    {
      "rank": 328,
      "cve_id": "CVE-2026-45081",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00201,
      "epss_percentile": 0.10302,
      "kev": false,
      "kev_due_at": null,
      "vendor": "frappe",
      "product": "hrms",
      "cwe": "CWE-863",
      "title": "Frappe HR: Permission Bypass in HRMS Leave Details API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45081"
    },
    {
      "rank": 329,
      "cve_id": "CVE-2026-48973",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.002,
      "epss_percentile": 0.10204,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Benbodhi",
      "product": "SVG Support",
      "cwe": "CWE-862",
      "title": "WordPress SVG Support plugin <= 2.5.14 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48973"
    },
    {
      "rank": 330,
      "cve_id": "CVE-2026-45134",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00199,
      "epss_percentile": 0.10124,
      "kev": false,
      "kev_due_at": null,
      "vendor": "langchain-ai",
      "product": "langsmith-sdk",
      "cwe": "CWE-502",
      "title": "LangSmith Client SDK: Public prompt pull deserializes untrusted manifests without trust boundary warning",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45134"
    },
    {
      "rank": 331,
      "cve_id": "CVE-2026-44971",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00198,
      "epss_percentile": 0.09943,
      "kev": false,
      "kev_due_at": null,
      "vendor": "DataDog",
      "product": "guarddog",
      "cwe": "CWE-918",
      "title": "GuardDog: Blind GitHub URL rewrite in remote project scanning causes SSRF and `GH_TOKEN` exfiltration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44971"
    },
    {
      "rank": 332,
      "cve_id": "CVE-2026-8842",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00198,
      "epss_percentile": 0.09915,
      "kev": false,
      "kev_due_at": null,
      "vendor": "morettolss",
      "product": "Google+ Link Name",
      "cwe": "CWE-79",
      "title": "Google+ Link Name <= 1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8842"
    },
    {
      "rank": 333,
      "cve_id": "CVE-2026-8847",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00198,
      "epss_percentile": 0.09915,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mshomali",
      "product": "Dideo",
      "cwe": "CWE-79",
      "title": "Dideo <= 1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8847"
    },
    {
      "rank": 334,
      "cve_id": "CVE-2026-8867",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00198,
      "epss_percentile": 0.09915,
      "kev": false,
      "kev_due_at": null,
      "vendor": "fides-it",
      "product": "Post Categories Gallery",
      "cwe": "CWE-79",
      "title": "Post Categories Gallery <= 1.0.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8867"
    },
    {
      "rank": 335,
      "cve_id": "CVE-2026-8886",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00198,
      "epss_percentile": 0.09914,
      "kev": false,
      "kev_due_at": null,
      "vendor": "huankong",
      "product": "hk_shortcode",
      "cwe": "CWE-79",
      "title": "hk_shortcode <= 1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'title' Shortcode Attribute",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8886"
    },
    {
      "rank": 336,
      "cve_id": "CVE-2026-8899",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00198,
      "epss_percentile": 0.09916,
      "kev": false,
      "kev_due_at": null,
      "vendor": "gapgag55",
      "product": "Auto Thumbnails",
      "cwe": "CWE-79",
      "title": "Auto Thumbnails <= 1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8899"
    },
    {
      "rank": 337,
      "cve_id": "CVE-2026-9022",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00197,
      "epss_percentile": 0.09856,
      "kev": false,
      "kev_due_at": null,
      "vendor": "dkjensen",
      "product": "Splide Carousel Block",
      "cwe": "CWE-79",
      "title": "Splide Carousel Block <= 1.7.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'url' Block Attribute",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9022"
    },
    {
      "rank": 338,
      "cve_id": "CVE-2026-6287",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00197,
      "epss_percentile": 0.09802,
      "kev": false,
      "kev_due_at": null,
      "vendor": "devitemsllc",
      "product": "ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin",
      "cwe": "CWE-79",
      "title": "ShopLentor - WooCommerce Builder for Elementor & Gutenberg <= 3.3.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Product Grid 'blockUniqId' Block Attribute",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6287"
    },
    {
      "rank": 339,
      "cve_id": "CVE-2026-5296",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00196,
      "epss_percentile": 0.09645,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GitLab",
      "product": "GitLab",
      "cwe": "CWE-862",
      "title": "Missing Authorization in GitLab",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-5296"
    },
    {
      "rank": 340,
      "cve_id": "CVE-2026-42746",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00195,
      "epss_percentile": 0.09543,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ZAYTECH",
      "product": "Smart Online Order for Clover",
      "cwe": "CWE-201",
      "title": "WordPress Smart Online Order for Clover plugin <= 1.6.0 - Sensitive Data Exposure vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42746"
    },
    {
      "rank": 341,
      "cve_id": "CVE-2026-8872",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00193,
      "epss_percentile": 0.0937,
      "kev": false,
      "kev_due_at": null,
      "vendor": "fides-it",
      "product": "Animate Your Content",
      "cwe": "CWE-79",
      "title": "Animate Your Content <= 1.0.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8872"
    },
    {
      "rank": 342,
      "cve_id": "CVE-2026-8891",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00193,
      "epss_percentile": 0.09365,
      "kev": false,
      "kev_due_at": null,
      "vendor": "bitform",
      "product": "BitForm – Data management solution for WordPress",
      "cwe": "CWE-79",
      "title": "BitForm <= 1.1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8891"
    },
    {
      "rank": 343,
      "cve_id": "CVE-2026-9607",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00192,
      "epss_percentile": 0.09265,
      "kev": false,
      "kev_due_at": null,
      "vendor": "itsourcecode",
      "product": "Courier Management System",
      "cwe": "CWE-74",
      "title": "itsourcecode Courier Management System parcel_list.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9607"
    },
    {
      "rank": 344,
      "cve_id": "CVE-2026-8042",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00191,
      "epss_percentile": 0.09103,
      "kev": false,
      "kev_due_at": null,
      "vendor": "octalmage",
      "product": "Github Shortcode",
      "cwe": "CWE-79",
      "title": "Github Shortcode <= 0.1 - Authenticated (Contributor+) Stored Cross-Site Scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8042"
    },
    {
      "rank": 345,
      "cve_id": "CVE-2026-5065",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0019,
      "epss_percentile": 0.09044,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Controller",
      "cwe": "CWE-798",
      "title": "IBM Controller is affected by vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-5065"
    },
    {
      "rank": 346,
      "cve_id": "CVE-2025-41670",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.0019,
      "epss_percentile": 0.08962,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Phoenix Contact",
      "product": "AXC F 1152",
      "cwe": "CWE-427",
      "title": "Untrusted Search Path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-41670"
    },
    {
      "rank": 347,
      "cve_id": "CVE-2026-8143",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.0019,
      "epss_percentile": 0.09025,
      "kev": false,
      "kev_due_at": null,
      "vendor": "omnivo",
      "product": "Booking Calendar – Event Calendar",
      "cwe": "CWE-79",
      "title": "Booking Calendar – Event Calendar <= 2.1.6 - Unauthenticated Stored Cross-Site Scripting via Multiple Parameters",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8143"
    },
    {
      "rank": 348,
      "cve_id": "CVE-2026-8870",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0019,
      "epss_percentile": 0.09002,
      "kev": false,
      "kev_due_at": null,
      "vendor": "adnanmoqsood",
      "product": "Team Master – A Modern WordPress Team Showcase",
      "cwe": "CWE-79",
      "title": "Team Master <= 1.1.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8870"
    },
    {
      "rank": 349,
      "cve_id": "CVE-2026-45136",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00188,
      "epss_percentile": 0.08752,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cnighswonger",
      "product": "claude-code-cache-fix",
      "cwe": "CWE-78",
      "title": "claude-code-cache-fix: Local code execution via Python triple-quote injection in tools/quota-statusline.sh",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45136"
    },
    {
      "rank": 350,
      "cve_id": "CVE-2026-8040",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00187,
      "epss_percentile": 0.08639,
      "kev": false,
      "kev_due_at": null,
      "vendor": "yehudah",
      "product": "faq shortocde",
      "cwe": "CWE-79",
      "title": "faq shortocde <= 1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'color' Shortcode Attribute",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8040"
    },
    {
      "rank": 351,
      "cve_id": "CVE-2026-8048",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00187,
      "epss_percentile": 0.08638,
      "kev": false,
      "kev_due_at": null,
      "vendor": "paulpela",
      "product": "My Email Shortcode",
      "cwe": "CWE-79",
      "title": "My Email Shortcode <= 0.91 - [Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')]",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8048"
    },
    {
      "rank": 352,
      "cve_id": "CVE-2026-8698",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00187,
      "epss_percentile": 0.0864,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cryptoprijzen",
      "product": "Cryptocurrency Prijsvergelijking Widget",
      "cwe": "CWE-79",
      "title": "Cryptocurrency Prijsvergelijking Widget <= 1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'width' Shortcode Attribute",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8698"
    },
    {
      "rank": 353,
      "cve_id": "CVE-2026-8701",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00187,
      "epss_percentile": 0.08644,
      "kev": false,
      "kev_due_at": null,
      "vendor": "golzarrahman",
      "product": "GNTT Post Title Ticker",
      "cwe": "CWE-79",
      "title": "GNTT Post Title Ticker <= 1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8701"
    },
    {
      "rank": 354,
      "cve_id": "CVE-2026-8703",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00187,
      "epss_percentile": 0.08644,
      "kev": false,
      "kev_due_at": null,
      "vendor": "codycave",
      "product": "Endless Scroll",
      "cwe": "CWE-79",
      "title": "Endless Scroll <= 1.0.0 - [Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')]",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8703"
    },
    {
      "rank": 355,
      "cve_id": "CVE-2026-8837",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00187,
      "epss_percentile": 0.08646,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ektorcaba",
      "product": "WP Iframe Geo Style for Amazon affiliates",
      "cwe": "CWE-79",
      "title": "WP Iframe Geo Style for Amazon affiliates <= 1.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'adid' Shortcode Attribute",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8837"
    },
    {
      "rank": 356,
      "cve_id": "CVE-2026-8845",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00187,
      "epss_percentile": 0.08647,
      "kev": false,
      "kev_due_at": null,
      "vendor": "samiullah-kaifi",
      "product": "Islamic Database",
      "cwe": "CWE-79",
      "title": "Islamic Database <= 1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8845"
    },
    {
      "rank": 357,
      "cve_id": "CVE-2026-8846",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00187,
      "epss_percentile": 0.08641,
      "kev": false,
      "kev_due_at": null,
      "vendor": "eldougo",
      "product": "Tuxquote",
      "cwe": "CWE-79",
      "title": "Tuxquote <= 1.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8846"
    },
    {
      "rank": 358,
      "cve_id": "CVE-2026-8871",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00187,
      "epss_percentile": 0.08646,
      "kev": false,
      "kev_due_at": null,
      "vendor": "thomstark",
      "product": "Formidable Kinetic",
      "cwe": "CWE-79",
      "title": "Formidable Kinetic <= 1.1.01 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8871"
    },
    {
      "rank": 359,
      "cve_id": "CVE-2026-8873",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00187,
      "epss_percentile": 0.08646,
      "kev": false,
      "kev_due_at": null,
      "vendor": "celloexpressions",
      "product": "Content Slideshow",
      "cwe": "CWE-79",
      "title": "Content Slideshow <= 2.4.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8873"
    },
    {
      "rank": 360,
      "cve_id": "CVE-2026-8875",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00187,
      "epss_percentile": 0.08645,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cuamckuy",
      "product": "Easy Prism Syntax Highlighter",
      "cwe": "CWE-79",
      "title": "Easy Prism Syntax Highlighter <= 1.0.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8875"
    },
    {
      "rank": 361,
      "cve_id": "CVE-2026-8894",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00187,
      "epss_percentile": 0.08641,
      "kev": false,
      "kev_due_at": null,
      "vendor": "vinaysankhyan",
      "product": "iWR Tooltip",
      "cwe": "CWE-79",
      "title": "iWR Tooltip <= 1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8894"
    },
    {
      "rank": 362,
      "cve_id": "CVE-2026-49053",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00187,
      "epss_percentile": 0.0867,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Wpmet",
      "product": "ElementsKit Elementor addons Lite",
      "cwe": "CWE-862",
      "title": "WordPress ElementsKit Elementor addons Lite plugin <= 3.9.6 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49053"
    },
    {
      "rank": 363,
      "cve_id": "CVE-2026-8716",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00187,
      "epss_percentile": 0.08708,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GitLab",
      "product": "GitLab",
      "cwe": "CWE-706",
      "title": "Use of Incorrectly-Resolved Name or Reference in GitLab",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8716"
    },
    {
      "rank": 364,
      "cve_id": "CVE-2026-6938",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00185,
      "epss_percentile": 0.08374,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Db2",
      "cwe": "CWE-285",
      "title": "IBM® Db2® is vulnerable to authorization bypass when uploading to a remote object storage path with a special query",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6938"
    },
    {
      "rank": 365,
      "cve_id": "CVE-2026-45984",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00184,
      "epss_percentile": 0.0832,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-416",
      "title": "gfs2: Fix use-after-free in iomap inline data write path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45984"
    },
    {
      "rank": 366,
      "cve_id": "CVE-2026-42753",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00184,
      "epss_percentile": 0.08368,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WC Lovers",
      "product": "WCFM Membership",
      "cwe": "CWE-862",
      "title": "WordPress WCFM Membership plugin <= 2.11.10 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42753"
    },
    {
      "rank": 367,
      "cve_id": "CVE-2026-23679",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00184,
      "epss_percentile": 0.08355,
      "kev": false,
      "kev_due_at": null,
      "vendor": "libusb",
      "product": "libusb",
      "cwe": "CWE-125",
      "title": "libusb < 1.0.30 NULL Pointer Dereference in parse_interface()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-23679"
    },
    {
      "rank": 368,
      "cve_id": "CVE-2025-67903",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00183,
      "epss_percentile": 0.08186,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-347",
      "title": "Northern.tech Mender Client 5 before 5.0.4 allows a Cryptographic signature verification bypass.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-67903"
    },
    {
      "rank": 369,
      "cve_id": "CVE-2026-45878",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00182,
      "epss_percentile": 0.08057,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/amdkfd: Fix watch_id bounds checking in debug address watch v2",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45878"
    },
    {
      "rank": 370,
      "cve_id": "CVE-2026-48968",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00182,
      "epss_percentile": 0.08075,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Averta",
      "product": "Master Slider",
      "cwe": "CWE-79",
      "title": "WordPress Master Slider plugin <= 3.10.8 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48968"
    },
    {
      "rank": 371,
      "cve_id": "CVE-2026-49044",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00182,
      "epss_percentile": 0.08075,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Justin Kruit",
      "product": "Advanced Custom Fields: Font Awesome Field",
      "cwe": "CWE-79",
      "title": "WordPress Advanced Custom Fields: Font Awesome Field plugin <= 5.0.2 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49044"
    },
    {
      "rank": 372,
      "cve_id": "CVE-2026-42728",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00181,
      "epss_percentile": 0.08039,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HT Plugins",
      "product": "HT Contact Form 7",
      "cwe": "CWE-79",
      "title": "WordPress HT Contact Form 7 plugin <= 2.8.2 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42728"
    },
    {
      "rank": 373,
      "cve_id": "CVE-2026-42729",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00181,
      "epss_percentile": 0.08039,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Property Hive",
      "product": "PropertyHive",
      "cwe": "CWE-79",
      "title": "WordPress PropertyHive plugin <= 2.2.2 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42729"
    },
    {
      "rank": 374,
      "cve_id": "CVE-2025-22741",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0018,
      "epss_percentile": 0.07869,
      "kev": false,
      "kev_due_at": null,
      "vendor": "RiceTheme",
      "product": "Felan Framework",
      "cwe": "CWE-79",
      "title": "WordPress Felan Framework plugin <= 1.1.3 - Reflected Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-22741"
    },
    {
      "rank": 375,
      "cve_id": "CVE-2025-52747",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0018,
      "epss_percentile": 0.07861,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jthemes",
      "product": "Themebox - Digital Products Ecommerce",
      "cwe": "CWE-79",
      "title": "WordPress Themebox - Digital Products Ecommerce theme <= 1.4.2 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-52747"
    },
    {
      "rank": 376,
      "cve_id": "CVE-2026-42733",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0018,
      "epss_percentile": 0.07863,
      "kev": false,
      "kev_due_at": null,
      "vendor": "RealMag777",
      "product": "WPCS",
      "cwe": "CWE-79",
      "title": "WordPress WPCS plugin <= 1.3.1 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42733"
    },
    {
      "rank": 377,
      "cve_id": "CVE-2026-42734",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0018,
      "epss_percentile": 0.07872,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dylan Kuhn",
      "product": "Geo Mashup",
      "cwe": "CWE-79",
      "title": "WordPress Geo Mashup plugin <= 1.13.19 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42734"
    },
    {
      "rank": 378,
      "cve_id": "CVE-2026-44839",
      "cvss_base": 5.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0018,
      "epss_percentile": 0.07925,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rabbitmq",
      "product": "rabbitmq-server",
      "cwe": "CWE-80",
      "title": "RabbitMQ: Unsanitized vhost names allow for XSS in management UI",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44839"
    },
    {
      "rank": 379,
      "cve_id": "CVE-2026-48923",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0018,
      "epss_percentile": 0.07936,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jenkins Project",
      "product": "Jenkins AppSpider Plugin",
      "cwe": "CWE-269",
      "title": "Jenkins AppSpider Plugin 1.0.17 and earlier does not perform a permission check in a method implementing form validation, allowing attackers with Overall/Read permission to connect to an attacker-specified URL.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48923"
    },
    {
      "rank": 380,
      "cve_id": "CVE-2026-44710",
      "cvss_base": 4.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00178,
      "epss_percentile": 0.07658,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mcdope",
      "product": "pam_usb",
      "cwe": "CWE-476",
      "title": "pam_usb: NULL pointer dereference from UDisks device fields causes PAM crash and login denial-of-service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44710"
    },
    {
      "rank": 381,
      "cve_id": "CVE-2026-45933",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00177,
      "epss_percentile": 0.07538,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "bpf: Preserve id of register in sync_linked_regs()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45933"
    },
    {
      "rank": 382,
      "cve_id": "CVE-2026-6051",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00177,
      "epss_percentile": 0.07588,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Db2",
      "cwe": "CWE-400",
      "title": "IBM® Db2® is vulnerable to a denial of service when executing a specially crafted query with a small statement heap",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6051"
    },
    {
      "rank": 383,
      "cve_id": "CVE-2026-46018",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00177,
      "epss_percentile": 0.07582,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ALSA: usb-audio: stop parsing UAC2 rates at MAX_NR_RATES",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46018"
    },
    {
      "rank": 384,
      "cve_id": "CVE-2026-48927",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00176,
      "epss_percentile": 0.07387,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jenkins Project",
      "product": "Jenkins buildgraph-view Plugin",
      "cwe": "CWE-79",
      "title": "Jenkins buildgraph-view Plugin 1.8 and earlier does not escape the build URL, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to configure jobs or views.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48927"
    },
    {
      "rank": 385,
      "cve_id": "CVE-2026-48153",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00175,
      "epss_percentile": 0.07254,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Budibase",
      "product": "budibase",
      "cwe": "CWE-918",
      "title": "Budibase: SSRF via OAuth2 token endpoint URL reaches internal hosts and cloud metadata",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48153"
    },
    {
      "rank": 386,
      "cve_id": "CVE-2026-45852",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00175,
      "epss_percentile": 0.07237,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-415",
      "title": "RDMA/rxe: Fix double free in rxe_srq_from_init",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45852"
    },
    {
      "rank": 387,
      "cve_id": "CVE-2026-46426",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00175,
      "epss_percentile": 0.07312,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Budibase",
      "product": "budibase",
      "cwe": "CWE-79",
      "title": "Budibase: Unrestricted Upload of File with Dangerous Type",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46426"
    },
    {
      "rank": 388,
      "cve_id": "CVE-2026-45931",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00173,
      "epss_percentile": 0.07113,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "accel/amdxdna: Hold mm structure across iommu_sva_unbind_device()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45931"
    },
    {
      "rank": 389,
      "cve_id": "CVE-2026-44247",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00173,
      "epss_percentile": 0.07039,
      "kev": false,
      "kev_due_at": null,
      "vendor": "volcano-sh",
      "product": "volcano",
      "cwe": "CWE-400",
      "title": "Volcano: Webhook server vulnerable to OOM due to unbounded HTTP request body size",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44247"
    },
    {
      "rank": 390,
      "cve_id": "CVE-2026-48926",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00171,
      "epss_percentile": 0.06862,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jenkins Project",
      "product": "Jenkins Job Import Plugin",
      "cwe": "CWE-269",
      "title": "Jenkins Job Import Plugin 143.v044a_2e819b_27 and earlier does not perform a permission check in an HTTP endpoint, allowing attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48926"
    },
    {
      "rank": 391,
      "cve_id": "CVE-2026-45991",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00169,
      "epss_percentile": 0.06637,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-787",
      "title": "udf: fix partition descriptor append bookkeeping",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45991"
    },
    {
      "rank": 392,
      "cve_id": "CVE-2026-48999",
      "cvss_base": 5.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00169,
      "epss_percentile": 0.06635,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ZTE",
      "product": "ZXUniPOS NDS-LTE",
      "cwe": "CWE-79",
      "title": "Stored Cross-Site Scripting (XSS) vulnerability in ZTE ZXUniPOS NDS-LTE product",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48999"
    },
    {
      "rank": 393,
      "cve_id": "CVE-2026-44711",
      "cvss_base": 7.9,
      "cvss_severity": "HIGH",
      "epss_score": 0.00166,
      "epss_percentile": 0.06352,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mcdope",
      "product": "pam_usb",
      "cwe": "CWE-59",
      "title": "pam_usb: Symlink attacks on pad directory and pad files enable authentication bypass and root file corruption",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44711"
    },
    {
      "rank": 394,
      "cve_id": "CVE-2026-46081",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00166,
      "epss_percentile": 0.0635,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-787",
      "title": "crypto: acomp - fix wrong pointer stored by acomp_save_req()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46081"
    },
    {
      "rank": 395,
      "cve_id": "CVE-2026-44473",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00166,
      "epss_percentile": 0.06302,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ellanetworks",
      "product": "core",
      "cwe": "CWE-358",
      "title": "Ella Core: UE Downlink Redirection via Forged PDUSessionResourceSetupResponse",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44473"
    },
    {
      "rank": 396,
      "cve_id": "CVE-2026-45872",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00166,
      "epss_percentile": 0.06292,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-401",
      "title": "scsi: smartpqi: Fix memory leak in pqi_report_phys_luns()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45872"
    },
    {
      "rank": 397,
      "cve_id": "CVE-2026-45875",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00166,
      "epss_percentile": 0.06292,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-401",
      "title": "mfd: arizona: Fix regulator resource leak on wm5102_clear_write_sequencer() failure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45875"
    },
    {
      "rank": 398,
      "cve_id": "CVE-2026-45856",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00165,
      "epss_percentile": 0.06168,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-125",
      "title": "RDMA/uverbs: Validate wqe_size before using it in ib_uverbs_post_send",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45856"
    },
    {
      "rank": 399,
      "cve_id": "CVE-2026-42877",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00165,
      "epss_percentile": 0.06224,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NeoRazorX",
      "product": "facturascripts",
      "cwe": "CWE-79",
      "title": "FacturaScripts: Stored XSS via product reference in sales/purchases",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42877"
    },
    {
      "rank": 400,
      "cve_id": "CVE-2026-2255",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00165,
      "epss_percentile": 0.06222,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hitachi Vantara",
      "product": "Pentaho Data Integration and Analytics",
      "cwe": "CWE-522",
      "title": "Hitachi Vantara Pentaho Data Integration & Analytics - Insufficiently Protected Credentials",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-2255"
    },
    {
      "rank": 401,
      "cve_id": "CVE-2026-45867",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00164,
      "epss_percentile": 0.06084,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-416",
      "title": "power: supply: act8945a: Fix use-after-free in power_supply_changed()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45867"
    },
    {
      "rank": 402,
      "cve_id": "CVE-2026-6268",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00164,
      "epss_percentile": 0.06056,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "EventPress",
      "cwe": "CWE-79",
      "title": "EventPress < 22.2 – Reflected Cross-Site Scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6268"
    },
    {
      "rank": 403,
      "cve_id": "CVE-2026-45855",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00164,
      "epss_percentile": 0.06137,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ata: libata-scsi: avoid Non-NCQ command starvation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45855"
    },
    {
      "rank": 404,
      "cve_id": "CVE-2026-45853",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00163,
      "epss_percentile": 0.06038,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-787",
      "title": "drm/amdgpu: Use kvfree instead of kfree in amdgpu_gmc_get_nps_memranges()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45853"
    },
    {
      "rank": 405,
      "cve_id": "CVE-2026-45861",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00163,
      "epss_percentile": 0.06012,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-416",
      "title": "gfs2: Fix slab-use-after-free in qd_put",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45861"
    },
    {
      "rank": 406,
      "cve_id": "CVE-2026-45989",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00163,
      "epss_percentile": 0.06012,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-416",
      "title": "of: unittest: fix use-after-free in testdrv_probe()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45989"
    },
    {
      "rank": 407,
      "cve_id": "CVE-2026-45871",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00163,
      "epss_percentile": 0.06006,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "tpm: st33zp24: Fix missing cleanup on get_burstcount() error",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45871"
    },
    {
      "rank": 408,
      "cve_id": "CVE-2026-45918",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00163,
      "epss_percentile": 0.05978,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-476",
      "title": "ovpn: tcp - don't deref NULL sk_socket member after tcp_close()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45918"
    },
    {
      "rank": 409,
      "cve_id": "CVE-2026-46019",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00163,
      "epss_percentile": 0.05967,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-401",
      "title": "crypto: atmel-aes - Fix 3-page memory leak in atmel_aes_buff_cleanup",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46019"
    },
    {
      "rank": 410,
      "cve_id": "CVE-2026-46424",
      "cvss_base": 4.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00163,
      "epss_percentile": 0.05998,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Budibase",
      "product": "budibase",
      "cwe": "CWE-269",
      "title": "Budibase: Missing Cache Invalidation on Public API Role Unassignment Allows Revoked Users to Retain Privileges for Up to 1 Hour",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46424"
    },
    {
      "rank": 411,
      "cve_id": "CVE-2026-45896",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00162,
      "epss_percentile": 0.05868,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-129",
      "title": "mtd: intel-dg: Fix accessing regions before setting nregions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45896"
    },
    {
      "rank": 412,
      "cve_id": "CVE-2026-45909",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00162,
      "epss_percentile": 0.05868,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "clk: mediatek: Drop __initconst from gates",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45909"
    },
    {
      "rank": 413,
      "cve_id": "CVE-2026-45947",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00162,
      "epss_percentile": 0.05901,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-401",
      "title": "drm/amdgpu: Fix memory leak in amdgpu_acpi_enumerate_xcc()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45947"
    },
    {
      "rank": 414,
      "cve_id": "CVE-2026-38931",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00162,
      "epss_percentile": 0.05883,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-79",
      "title": "A stored cross-site scripting (XSS) vulnerability in the /admin/config-module.php component of creatorsofcode simplephp GitHub commit 5184cff (Latest as of 2026-02-27) via injecting a crafted payload.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-38931"
    },
    {
      "rank": 415,
      "cve_id": "CVE-2026-49047",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00162,
      "epss_percentile": 0.05871,
      "kev": false,
      "kev_due_at": null,
      "vendor": "DearHive",
      "product": "DearFlip",
      "cwe": "CWE-862",
      "title": "WordPress DearFlip plugin <= 2.4.27 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49047"
    },
    {
      "rank": 416,
      "cve_id": "CVE-2026-45866",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0016,
      "epss_percentile": 0.05647,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-416",
      "title": "serial: caif: fix use-after-free in caif_serial ldisc_close()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45866"
    },
    {
      "rank": 417,
      "cve_id": "CVE-2026-45879",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0016,
      "epss_percentile": 0.05648,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-416",
      "title": "power: supply: bq25980: Fix use-after-free in power_supply_changed()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45879"
    },
    {
      "rank": 418,
      "cve_id": "CVE-2026-45885",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0016,
      "epss_percentile": 0.05646,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-416",
      "title": "power: supply: cpcap-battery: Fix use-after-free in power_supply_changed()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45885"
    },
    {
      "rank": 419,
      "cve_id": "CVE-2026-45902",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0016,
      "epss_percentile": 0.05647,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-416",
      "title": "power: supply: bq256xx: Fix use-after-free in power_supply_changed()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45902"
    },
    {
      "rank": 420,
      "cve_id": "CVE-2026-45916",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0016,
      "epss_percentile": 0.05648,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-416",
      "title": "power: supply: sbs-battery: Fix use-after-free in power_supply_changed()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45916"
    },
    {
      "rank": 421,
      "cve_id": "CVE-2026-45946",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0016,
      "epss_percentile": 0.05647,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-416",
      "title": "power: supply: ab8500: Fix use-after-free in power_supply_changed()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45946"
    },
    {
      "rank": 422,
      "cve_id": "CVE-2025-71304",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0016,
      "epss_percentile": 0.05703,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "smack: /smack/doi: accept previously used values",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-71304"
    },
    {
      "rank": 423,
      "cve_id": "CVE-2025-71305",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0016,
      "epss_percentile": 0.05702,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/display/dp_mst: Add protection against 0 vcpi",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-71305"
    },
    {
      "rank": 424,
      "cve_id": "CVE-2026-45847",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0016,
      "epss_percentile": 0.057,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-617",
      "title": "net: remove WARN_ON_ONCE when accessing forward path array",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45847"
    },
    {
      "rank": 425,
      "cve_id": "CVE-2026-45848",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0016,
      "epss_percentile": 0.057,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-476",
      "title": "apparmor: fix NULL sock in aa_sock_file_perm",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45848"
    },
    {
      "rank": 426,
      "cve_id": "CVE-2026-45850",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0016,
      "epss_percentile": 0.05743,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ipvs: skip ipv6 extension headers for csum checks",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45850"
    },
    {
      "rank": 427,
      "cve_id": "CVE-2026-45857",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0016,
      "epss_percentile": 0.057,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-476",
      "title": "scsi: csiostor: Fix dereference of null pointer rn",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45857"
    },
    {
      "rank": 428,
      "cve_id": "CVE-2026-45869",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0016,
      "epss_percentile": 0.05701,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-476",
      "title": "power: supply: wm97xx: Fix NULL pointer dereference in power_supply_changed()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45869"
    },
    {
      "rank": 429,
      "cve_id": "CVE-2026-45870",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0016,
      "epss_percentile": 0.05701,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-401",
      "title": "SUNRPC: auth_gss: fix memory leaks in XDR decoding error paths",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45870"
    },
    {
      "rank": 430,
      "cve_id": "CVE-2026-45873",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0016,
      "epss_percentile": 0.05742,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "netfilter: nft_set_rbtree: check for partial overlaps in anonymous sets",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45873"
    },
    {
      "rank": 431,
      "cve_id": "CVE-2026-45877",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0016,
      "epss_percentile": 0.05688,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-476",
      "title": "HID: intel-ish-hid: fix NULL-ptr-deref in ishtp_bus_remove_all_clients",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45877"
    },
    {
      "rank": 432,
      "cve_id": "CVE-2026-45886",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0016,
      "epss_percentile": 0.057,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-908",
      "title": "bpf: Fix bpf_xdp_store_bytes proto for read-only arg",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45886"
    },
    {
      "rank": 433,
      "cve_id": "CVE-2026-45892",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0016,
      "epss_percentile": 0.05743,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ext4: drop extent cache after doing PARTIAL_VALID1 zeroout",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45892"
    },
    {
      "rank": 434,
      "cve_id": "CVE-2026-45899",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0016,
      "epss_percentile": 0.05703,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ext4: drop extent cache when splitting extent fails",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45899"
    },
    {
      "rank": 435,
      "cve_id": "CVE-2026-45915",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0016,
      "epss_percentile": 0.05743,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "fat: avoid parent link count underflow in rmdir",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45915"
    },
    {
      "rank": 436,
      "cve_id": "CVE-2026-45923",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0016,
      "epss_percentile": 0.05743,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net: usb: catc: enable basic endpoint checking",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45923"
    },
    {
      "rank": 437,
      "cve_id": "CVE-2026-45948",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0016,
      "epss_percentile": 0.05701,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-401",
      "title": "ext4: fix memory leak in ext4_ext_shift_extents()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45948"
    },
    {
      "rank": 438,
      "cve_id": "CVE-2026-45962",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0016,
      "epss_percentile": 0.05702,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ublk: Validate SQE128 flag before accessing the cmd",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45962"
    },
    {
      "rank": 439,
      "cve_id": "CVE-2026-45964",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0016,
      "epss_percentile": 0.05701,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-401",
      "title": "SUNRPC: fix gss_auth kref leak in gss_alloc_msg error path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45964"
    },
    {
      "rank": 440,
      "cve_id": "CVE-2026-45965",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0016,
      "epss_percentile": 0.05702,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-476",
      "title": "apparmor: fix invalid deref of rawdata when export_binary is unset",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45965"
    },
    {
      "rank": 441,
      "cve_id": "CVE-2026-45882",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00159,
      "epss_percentile": 0.05571,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-416",
      "title": "power: supply: pm8916_bms_vm: Fix use-after-free in power_supply_changed()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45882"
    },
    {
      "rank": 442,
      "cve_id": "CVE-2026-45851",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00159,
      "epss_percentile": 0.05582,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-125",
      "title": "efi: Fix reservation of unaccepted memory table",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45851"
    },
    {
      "rank": 443,
      "cve_id": "CVE-2026-45022",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00159,
      "epss_percentile": 0.05624,
      "kev": false,
      "kev_due_at": null,
      "vendor": "go-git",
      "product": "go-git",
      "cwe": "CWE-180",
      "title": "go-git: Improper parsing of specially crafted objects may lead to inconsistent interpretation compared to upstream Git",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45022"
    },
    {
      "rank": 444,
      "cve_id": "CVE-2026-45858",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00159,
      "epss_percentile": 0.05605,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ext4: don't zero the entire extent if EXT4_EXT_DATA_PARTIAL_VALID1",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45858"
    },
    {
      "rank": 445,
      "cve_id": "CVE-2026-45884",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00159,
      "epss_percentile": 0.05605,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-191",
      "title": "apparmor: avoid per-cpu hold underflow in aa_get_buffer",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45884"
    },
    {
      "rank": 446,
      "cve_id": "CVE-2026-45888",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00159,
      "epss_percentile": 0.05606,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-401",
      "title": "md/raid1: fix memory leak in raid1_run()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45888"
    },
    {
      "rank": 447,
      "cve_id": "CVE-2026-45895",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00159,
      "epss_percentile": 0.05605,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "quota: fix livelock between quotactl and freeze_super",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45895"
    },
    {
      "rank": 448,
      "cve_id": "CVE-2026-45913",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00159,
      "epss_percentile": 0.05606,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net: bridge: mcast: always update mdb_n_entries for vlan contexts",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45913"
    },
    {
      "rank": 449,
      "cve_id": "CVE-2026-45922",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00159,
      "epss_percentile": 0.05606,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-401",
      "title": "RDMA/mlx5: Fix memory leak in GET_DATA_DIRECT_SYSFS_PATH handler",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45922"
    },
    {
      "rank": 450,
      "cve_id": "CVE-2026-45925",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00159,
      "epss_percentile": 0.05606,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "thermal/of: Fix reference leak in thermal_of_cm_lookup()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45925"
    },
    {
      "rank": 451,
      "cve_id": "CVE-2026-45973",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00159,
      "epss_percentile": 0.05607,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "RDMA/mlx5: Fix UMR hang in LAG error state unload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45973"
    },
    {
      "rank": 452,
      "cve_id": "CVE-2026-46000",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00159,
      "epss_percentile": 0.05607,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "rxrpc: Fix conn-level packet handling to unshare RESPONSE packets",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46000"
    },
    {
      "rank": 453,
      "cve_id": "CVE-2026-44713",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00158,
      "epss_percentile": 0.05468,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mcdope",
      "product": "pam_usb",
      "cwe": "CWE-78",
      "title": "pam_usb: Command injection via $TMUX environment variable leads to RCE as root",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44713"
    },
    {
      "rank": 454,
      "cve_id": "CVE-2026-45940",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00158,
      "epss_percentile": 0.05441,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net: stmmac: fix oops when split header is enabled",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45940"
    },
    {
      "rank": 455,
      "cve_id": "CVE-2026-45929",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00157,
      "epss_percentile": 0.05401,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-416",
      "title": "ovpn: fix possible use-after-free in ovpn_net_xmit",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45929"
    },
    {
      "rank": 456,
      "cve_id": "CVE-2026-45903",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00157,
      "epss_percentile": 0.05414,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-125",
      "title": "bpf: Fix memory access flags in helper prototypes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45903"
    },
    {
      "rank": 457,
      "cve_id": "CVE-2026-6565",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00156,
      "epss_percentile": 0.05301,
      "kev": false,
      "kev_due_at": null,
      "vendor": "analogwp",
      "product": "Style Kits for Elementor",
      "cwe": "CWE-79",
      "title": "Style Kits – Advanced Theme Styles for Elementor <= 2.5.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Kit Title",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6565"
    },
    {
      "rank": 458,
      "cve_id": "CVE-2026-8702",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00156,
      "epss_percentile": 0.05298,
      "kev": false,
      "kev_due_at": null,
      "vendor": "garber",
      "product": "GBI To Print",
      "cwe": "CWE-79",
      "title": "GBI To Print <= 1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'div' Shortcode Attribute",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8702"
    },
    {
      "rank": 459,
      "cve_id": "CVE-2026-45864",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00156,
      "epss_percentile": 0.05254,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-835",
      "title": "fs/ntfs3: prevent infinite loops caused by the next valid being the same",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45864"
    },
    {
      "rank": 460,
      "cve_id": "CVE-2026-45865",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00156,
      "epss_percentile": 0.05255,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "mctp i2c: initialise event handler read bytes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45865"
    },
    {
      "rank": 461,
      "cve_id": "CVE-2026-45868",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00156,
      "epss_percentile": 0.05255,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "pinctrl: single: fix refcount leak in pcs_add_gpio_func()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45868"
    },
    {
      "rank": 462,
      "cve_id": "CVE-2026-45881",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00156,
      "epss_percentile": 0.05255,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-401",
      "title": "soc: mediatek: svs: Fix memory leak in svs_enable_debug_write()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45881"
    },
    {
      "rank": 463,
      "cve_id": "CVE-2026-45883",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00156,
      "epss_percentile": 0.05256,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-401",
      "title": "iio: sca3000: Fix a resource leak in sca3000_probe()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45883"
    },
    {
      "rank": 464,
      "cve_id": "CVE-2026-45904",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00156,
      "epss_percentile": 0.05256,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-674",
      "title": "powerpc/eeh: fix recursive pci_lock_rescan_remove locking in EEH event handling",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45904"
    },
    {
      "rank": 465,
      "cve_id": "CVE-2026-45911",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00156,
      "epss_percentile": 0.05254,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-476",
      "title": "usb: cdns3: fix role switching during resume",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45911"
    },
    {
      "rank": 466,
      "cve_id": "CVE-2026-45863",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00155,
      "epss_percentile": 0.05178,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-401",
      "title": "i3c: dw: Fix memory leak in dw_i3c_master_i2c_xfers()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45863"
    },
    {
      "rank": 467,
      "cve_id": "CVE-2026-45874",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00155,
      "epss_percentile": 0.05176,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-476",
      "title": "phy: freescale: imx8qm-hsio: fix NULL pointer dereference",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45874"
    },
    {
      "rank": 468,
      "cve_id": "CVE-2026-45880",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00155,
      "epss_percentile": 0.05176,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "PCI/P2PDMA: Release per-CPU pgmap ref when vm_insert_page() fails",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45880"
    },
    {
      "rank": 469,
      "cve_id": "CVE-2026-45897",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00155,
      "epss_percentile": 0.05166,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "netfilter: nft_counter: serialize reset with spinlock",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45897"
    },
    {
      "rank": 470,
      "cve_id": "CVE-2026-45900",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00155,
      "epss_percentile": 0.05178,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-401",
      "title": "crypto: caam - fix netdev memory leak in dpaa2_caam_probe",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45900"
    },
    {
      "rank": 471,
      "cve_id": "CVE-2026-45901",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00155,
      "epss_percentile": 0.05177,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "netfilter: nf_tables: revert commit_mutex usage in reset path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45901"
    },
    {
      "rank": 472,
      "cve_id": "CVE-2026-44712",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00154,
      "epss_percentile": 0.05137,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mcdope",
      "product": "pam_usb",
      "cwe": "CWE-78",
      "title": "pam_usb: Shell injection via device UUID and username in pamusb-conf and pamusb-agent",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44712"
    },
    {
      "rank": 473,
      "cve_id": "CVE-2026-2254",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00154,
      "epss_percentile": 0.05047,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hitachi Vantara",
      "product": "Pentaho Data Integration and Analytics",
      "cwe": "CWE-732",
      "title": "Hitachi Vantara Pentaho Data Integration & Analytics - Incorrect Permission Assignment for Critical Resource",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-2254"
    },
    {
      "rank": 474,
      "cve_id": "CVE-2026-45854",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00153,
      "epss_percentile": 0.05012,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "crypto: inside-secure/eip93 - unregister only available algorithm",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45854"
    },
    {
      "rank": 475,
      "cve_id": "CVE-2026-45876",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00153,
      "epss_percentile": 0.05012,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-476",
      "title": "arm64/gcs: Fix error handling in arch_set_shadow_stack_status()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45876"
    },
    {
      "rank": 476,
      "cve_id": "CVE-2026-45887",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00153,
      "epss_percentile": 0.05014,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-401",
      "title": "af_unix: Fix memleak of newsk in unix_stream_connect().",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45887"
    },
    {
      "rank": 477,
      "cve_id": "CVE-2026-45889",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00153,
      "epss_percentile": 0.05014,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-369",
      "title": "mptcp: do not account for OoO in mptcp_rcvbuf_grow()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45889"
    },
    {
      "rank": 478,
      "cve_id": "CVE-2026-45908",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00153,
      "epss_percentile": 0.05014,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-401",
      "title": "accel/amdxdna: Fix memory leak in amdxdna_ubuf_map",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45908"
    },
    {
      "rank": 479,
      "cve_id": "CVE-2026-42738",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00152,
      "epss_percentile": 0.04851,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ZAYTECH",
      "product": "Smart Online Order for Clover",
      "cwe": "CWE-79",
      "title": "WordPress Smart Online Order for Clover plugin <= 1.6.0 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42738"
    },
    {
      "rank": 480,
      "cve_id": "CVE-2026-42739",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00152,
      "epss_percentile": 0.04851,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IniLerm",
      "product": "Advanced IP Blocker",
      "cwe": "CWE-79",
      "title": "WordPress Advanced IP Blocker plugin <= 8.10.7 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42739"
    },
    {
      "rank": 481,
      "cve_id": "CVE-2026-42759",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00152,
      "epss_percentile": 0.04851,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Timo",
      "product": "Affiliate Super Assistent",
      "cwe": "CWE-79",
      "title": "WordPress Affiliate Super Assistent plugin <= 1.10.1 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42759"
    },
    {
      "rank": 482,
      "cve_id": "CVE-2026-49052",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00152,
      "epss_percentile": 0.04904,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Wpmet",
      "product": "ElementsKit Elementor addons Lite",
      "cwe": "CWE-862",
      "title": "WordPress ElementsKit Elementor addons Lite plugin <= 3.9.6 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49052"
    },
    {
      "rank": 483,
      "cve_id": "CVE-2026-3623",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00151,
      "epss_percentile": 0.04766,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Netezza Performance Server Replication Services",
      "cwe": "CWE-250",
      "title": "Vulnerabilities exists in IBM Netezza Performance Server Replication Services",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-3623"
    },
    {
      "rank": 484,
      "cve_id": "CVE-2026-44709",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00151,
      "epss_percentile": 0.0484,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mcdope",
      "product": "pam_usb",
      "cwe": "CWE-78",
      "title": "pam_usb: PINENTRY_FALLBACK_APP environment variable allows arbitrary command execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44709"
    },
    {
      "rank": 485,
      "cve_id": "CVE-2025-71306",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0015,
      "epss_percentile": 0.04709,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-125",
      "title": "ima: Fix stack-out-of-bounds in is_bprm_creds_for_exec()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-71306"
    },
    {
      "rank": 486,
      "cve_id": "CVE-2026-46055",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0015,
      "epss_percentile": 0.04709,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "apparmor: Fix string overrun due to missing termination",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46055"
    },
    {
      "rank": 487,
      "cve_id": "CVE-2026-45335",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0015,
      "epss_percentile": 0.04709,
      "kev": false,
      "kev_due_at": null,
      "vendor": "LabRedesCefetRJ",
      "product": "WeGIA",
      "cwe": "CWE-601",
      "title": "WeGIA: Middleware whitelist bypass → open redirect via InternoControle.nextPage",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45335"
    },
    {
      "rank": 488,
      "cve_id": "CVE-2026-45862",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00149,
      "epss_percentile": 0.0465,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "iommu/vt-d: Flush cache for PASID table before using it",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45862"
    },
    {
      "rank": 489,
      "cve_id": "CVE-2026-45894",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00149,
      "epss_percentile": 0.04583,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "iommu/vt-d: Clear Present bit before tearing down PASID entry",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45894"
    },
    {
      "rank": 490,
      "cve_id": "CVE-2026-45935",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00149,
      "epss_percentile": 0.04631,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-125",
      "title": "fs/ntfs3: Fix slab-out-of-bounds read in DeleteIndexEntryRoot",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45935"
    },
    {
      "rank": 491,
      "cve_id": "CVE-2026-48065",
      "cvss_base": 6.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00149,
      "epss_percentile": 0.04654,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mcdope",
      "product": "pam_usb",
      "cwe": "CWE-122",
      "title": "pam_usb: Unchecked integer multiplication before xmalloc() in conf.c allows heap-based buffer overflow on 32-bit targets",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48065"
    },
    {
      "rank": 492,
      "cve_id": "CVE-2026-44475",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00148,
      "epss_percentile": 0.04517,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ellanetworks",
      "product": "core",
      "cwe": "CWE-358",
      "title": "Ella Core: UE Security Capability bypass on NGAP PathSwitchRequest",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44475"
    },
    {
      "rank": 493,
      "cve_id": "CVE-2026-21785",
      "cvss_base": 4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00148,
      "epss_percentile": 0.04577,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HCLSoftware",
      "product": "BigFix Remote Control Server",
      "cwe": "CWE-1021",
      "title": "HCL BigFix Remote Control Server WebUI is affected by a misconfigured Content Security Policy",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-21785"
    },
    {
      "rank": 494,
      "cve_id": "CVE-2026-46029",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00147,
      "epss_percentile": 0.04453,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "mm/slab: return NULL early from kmalloc_nolock() in NMI on UP",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46029"
    },
    {
      "rank": 495,
      "cve_id": "CVE-2026-45920",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00146,
      "epss_percentile": 0.04371,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-415",
      "title": "ext4: fix dirtyclusters double decrement on fs shutdown",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45920"
    },
    {
      "rank": 496,
      "cve_id": "CVE-2026-45718",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00146,
      "epss_percentile": 0.04398,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Budibase",
      "product": "budibase",
      "cwe": "CWE-863",
      "title": "Budibase: Row Action Trigger Bypasses View Row Filter Security Boundary Allowing Action on Out-of-Scope Rows",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45718"
    },
    {
      "rank": 497,
      "cve_id": "CVE-2026-9674",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00146,
      "epss_percentile": 0.04393,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jenkins Project",
      "product": "Jenkins Multijob Plugin",
      "cwe": "CWE-352",
      "title": "A cross-site request forgery (CSRF) vulnerability in Jenkins Multijob Plugin 662.vd2e0001f6b_b_d and earlier allows attackers to resume failed Multijob builds.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9674"
    },
    {
      "rank": 498,
      "cve_id": "CVE-2026-46022",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00145,
      "epss_percentile": 0.04332,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-125",
      "title": "misc: ibmasm: fix OOB MMIO read in ibmasm_handle_mouse_interrupt()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46022"
    },
    {
      "rank": 499,
      "cve_id": "CVE-2026-8911",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00145,
      "epss_percentile": 0.04269,
      "kev": false,
      "kev_due_at": null,
      "vendor": "godlessons",
      "product": "WP AutoBuzz",
      "cwe": "CWE-352",
      "title": "WP AutoBuzz <= 1.1.1 - Cross-Site Request Forgery to Stored Cross-Site Scripting via 'googleAccount' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8911"
    },
    {
      "rank": 500,
      "cve_id": "CVE-2026-46006",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00143,
      "epss_percentile": 0.04107,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-787",
      "title": "drm/nouveau: fix u32 overflow in pushbuf reloc bounds check",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46006"
    },
    {
      "rank": 501,
      "cve_id": "CVE-2026-45961",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00143,
      "epss_percentile": 0.04146,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-401",
      "title": "gfs2: fix memory leaks in gfs2_fill_super error path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45961"
    },
    {
      "rank": 502,
      "cve_id": "CVE-2026-46062",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00142,
      "epss_percentile": 0.03971,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-190",
      "title": "ntfs3: fix integer overflow in run_unpack() volume boundary check",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46062"
    },
    {
      "rank": 503,
      "cve_id": "CVE-2026-42762",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00142,
      "epss_percentile": 0.03989,
      "kev": false,
      "kev_due_at": null,
      "vendor": "e4jvikwp",
      "product": "VikBooking Hotel Booking Engine & PMS",
      "cwe": "CWE-79",
      "title": "WordPress VikBooking Hotel Booking Engine & PMS plugin <= 1.8.9 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42762"
    },
    {
      "rank": 504,
      "cve_id": "CVE-2026-45993",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00142,
      "epss_percentile": 0.03998,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "LoongArch: Add spectre boundry for syscall dispatch table",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45993"
    },
    {
      "rank": 505,
      "cve_id": "CVE-2026-46100",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00141,
      "epss_percentile": 0.03933,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "fs: afs: revert mmap_prepare() change",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46100"
    },
    {
      "rank": 506,
      "cve_id": "CVE-2026-47274",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00141,
      "epss_percentile": 0.03959,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mcdope",
      "product": "pam_usb",
      "cwe": "CWE-427",
      "title": "pam_usb: Uncontrolled search path in pam_usb tools allows privilege escalation via PATH manipulation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47274"
    },
    {
      "rank": 507,
      "cve_id": "CVE-2026-8938",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0014,
      "epss_percentile": 0.03847,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nakamura1458",
      "product": "auto making JSON-LD",
      "cwe": "CWE-352",
      "title": "auto making JSON-LD <= 4.5.3 - Cross-Site Request Forgery to Plugin Certification Settings via Nonce Validation Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8938"
    },
    {
      "rank": 508,
      "cve_id": "CVE-2026-8939",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0014,
      "epss_percentile": 0.03848,
      "kev": false,
      "kev_due_at": null,
      "vendor": "simonailie",
      "product": "Search Simple Fields",
      "cwe": "CWE-352",
      "title": "Search Simple Fields <= 0.2 - Cross-Site Request Forgery to Plugin Settings Update",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8939"
    },
    {
      "rank": 509,
      "cve_id": "CVE-2026-8941",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0014,
      "epss_percentile": 0.03846,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wmark",
      "product": "CDN Linker lite",
      "cwe": "CWE-352",
      "title": "CDN Linker lite <= 1.3.1 - Cross-Site Request Forgery to Plugin Settings Update",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8941"
    },
    {
      "rank": 510,
      "cve_id": "CVE-2026-8943",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0014,
      "epss_percentile": 0.03847,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rchmura",
      "product": "GoStats for WordPress",
      "cwe": "CWE-352",
      "title": "GoStats for WordPress <= 1.4 - Cross-Site Request Forgery via gostats_manage() Function",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8943"
    },
    {
      "rank": 511,
      "cve_id": "CVE-2023-52945",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00139,
      "epss_percentile": 0.03751,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Synology",
      "product": "BeeDrive for desktop",
      "cwe": "CWE-427",
      "title": "Uncontrolled search path element vulnerability in OpenSSL DLL component in Synology BeeDrive for desktop before 1.3.2-13814 allows local users to execute arbitrary code via unspecified vectors.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2023-52945"
    },
    {
      "rank": 512,
      "cve_id": "CVE-2026-45996",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00139,
      "epss_percentile": 0.03764,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-416",
      "title": "spi: imx: fix use-after-free on unbind",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45996"
    },
    {
      "rank": 513,
      "cve_id": "CVE-2026-46036",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00139,
      "epss_percentile": 0.03721,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-416",
      "title": "vfio/cdx: Serialize VFIO_DEVICE_SET_IRQS with a per-device mutex",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46036"
    },
    {
      "rank": 514,
      "cve_id": "CVE-2026-46069",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00139,
      "epss_percentile": 0.03764,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-416",
      "title": "wifi: mwifiex: fix use-after-free in mwifiex_adapter_cleanup()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46069"
    },
    {
      "rank": 515,
      "cve_id": "CVE-2026-45994",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00139,
      "epss_percentile": 0.03774,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-125",
      "title": "ibmasm: fix OOB reads in command_file_write due to missing size checks",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45994"
    },
    {
      "rank": 516,
      "cve_id": "CVE-2026-46064",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00139,
      "epss_percentile": 0.03774,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-125",
      "title": "ibmasm: fix heap over-read in ibmasm_send_i2o_message()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46064"
    },
    {
      "rank": 517,
      "cve_id": "CVE-2026-8903",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00139,
      "epss_percentile": 0.0373,
      "kev": false,
      "kev_due_at": null,
      "vendor": "youtag",
      "product": "Two-factor authentication (formerly IP Vault)",
      "cwe": "CWE-352",
      "title": "Two-factor authentication (formerly IP Vault) <= 2.1 - Cross-Site Request Forgery to Settings Update",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8903"
    },
    {
      "rank": 518,
      "cve_id": "CVE-2026-46079",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00138,
      "epss_percentile": 0.03698,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-476",
      "title": "rbd: fix null-ptr-deref when device_add_disk() fails",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46079"
    },
    {
      "rank": 519,
      "cve_id": "CVE-2026-46097",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00137,
      "epss_percentile": 0.03587,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-416",
      "title": "Input: edt-ft5x06 - fix use-after-free in debugfs teardown",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46097"
    },
    {
      "rank": 520,
      "cve_id": "CVE-2025-71307",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00137,
      "epss_percentile": 0.03607,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-476",
      "title": "drm/panthor: Fix NULL pointer dereference on panthor_fw_unplug",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-71307"
    },
    {
      "rank": 521,
      "cve_id": "CVE-2025-71308",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00137,
      "epss_percentile": 0.03607,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-476",
      "title": "accel/amdxdna: Fix potential NULL pointer dereference in context cleanup",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-71308"
    },
    {
      "rank": 522,
      "cve_id": "CVE-2025-71312",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00137,
      "epss_percentile": 0.03608,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-401",
      "title": "fs/ntfs3: fix ntfs_mount_options leak in ntfs_fill_super()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-71312"
    },
    {
      "rank": 523,
      "cve_id": "CVE-2026-45027",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00136,
      "epss_percentile": 0.03528,
      "kev": false,
      "kev_due_at": null,
      "vendor": "LabRedesCefetRJ",
      "product": "WeGIA",
      "cwe": "CWE-759",
      "title": "WeGIA: Use of Weak Password Hashing Algorithm (SHA-256, no salt) in html/login.php",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45027"
    },
    {
      "rank": 524,
      "cve_id": "CVE-2025-68712",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00136,
      "epss_percentile": 0.03511,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-285",
      "title": "SpSoft AppLock (com.sp.protector.free) 7.9.40 for Android allows a local attacker with physical access to bypass fingerprint or PIN authentication. Although the app integrates Android's biometric mechanisms, the lock is implemented with a custom overlay that fails to consistently enforce authentication. By navigating cascading interface flows - insecure navigation through exposed routes facilitates app control evasion {I.N.T.E.R.F.A.C.E] via advertisement or browser intents - an attacker can exit the lock interface without re-authentication and access protected apps (e.g., Chrome). This results in information disclosure and privilege escalation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-68712"
    },
    {
      "rank": 525,
      "cve_id": "CVE-2026-45849",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00136,
      "epss_percentile": 0.03492,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-667",
      "title": "net: mscc: ocelot: add missing lock protection in ocelot_port_xmit_inj()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45849"
    },
    {
      "rank": 526,
      "cve_id": "CVE-2026-46080",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00136,
      "epss_percentile": 0.03492,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ocfs2: split transactions in dio completion to avoid credit exhaustion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46080"
    },
    {
      "rank": 527,
      "cve_id": "CVE-2026-46092",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00136,
      "epss_percentile": 0.03493,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-476",
      "title": "wifi: rtw88: check for PCI upstream bridge existence",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46092"
    },
    {
      "rank": 528,
      "cve_id": "CVE-2026-46034",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00135,
      "epss_percentile": 0.03457,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-476",
      "title": "vfio/cdx: Fix NULL pointer dereference in interrupt trigger path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46034"
    },
    {
      "rank": 529,
      "cve_id": "CVE-2026-46041",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00135,
      "epss_percentile": 0.03457,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "greybus: gb-beagleplay: fix sleep in atomic context in hdlc_tx_frames()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46041"
    },
    {
      "rank": 530,
      "cve_id": "CVE-2026-46089",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00135,
      "epss_percentile": 0.03457,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "zram: do not forget to endio for partial discard requests",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46089"
    },
    {
      "rank": 531,
      "cve_id": "CVE-2026-45945",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00134,
      "epss_percentile": 0.03366,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-362",
      "title": "iommu/vt-d: Fix race condition during PASID entry replacement",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45945"
    },
    {
      "rank": 532,
      "cve_id": "CVE-2026-45932",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00134,
      "epss_percentile": 0.03348,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "bpf: Fix tcx/netkit detach permissions when prog fd isn't given",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45932"
    },
    {
      "rank": 533,
      "cve_id": "CVE-2026-44474",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00134,
      "epss_percentile": 0.03354,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ellanetworks",
      "product": "core",
      "cwe": "CWE-358",
      "title": "Ella Core: Handover failures during concurrent Security Mode Command",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44474"
    },
    {
      "rank": 534,
      "cve_id": "CVE-2026-40851",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00133,
      "epss_percentile": 0.03271,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MB connect line",
      "product": "mbNET/mbNET.rokey",
      "cwe": "CWE-1287",
      "title": "Command injection via USB",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40851"
    },
    {
      "rank": 535,
      "cve_id": "CVE-2026-45839",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00133,
      "epss_percentile": 0.03317,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-129",
      "title": "bpf: reject negative CO-RE accessor indices in bpf_core_parse_spec()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45839"
    },
    {
      "rank": 536,
      "cve_id": "CVE-2026-45990",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00133,
      "epss_percentile": 0.03306,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-190",
      "title": "slub: fix data loss and overflow in krealloc()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45990"
    },
    {
      "rank": 537,
      "cve_id": "CVE-2026-45998",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00132,
      "epss_percentile": 0.03228,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-416",
      "title": "rxrpc: Fix potential UAF after skb_unshare() failure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45998"
    },
    {
      "rank": 538,
      "cve_id": "CVE-2026-46021",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00132,
      "epss_percentile": 0.03219,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-401",
      "title": "thermal: core: Fix thermal zone governor cleanup issues",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46021"
    },
    {
      "rank": 539,
      "cve_id": "CVE-2026-45999",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00131,
      "epss_percentile": 0.03164,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-191",
      "title": "erofs: fix unsigned underflow in z_erofs_lz4_handle_overlap()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45999"
    },
    {
      "rank": 540,
      "cve_id": "CVE-2026-46078",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00131,
      "epss_percentile": 0.03164,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-125",
      "title": "erofs: fix the out-of-bounds nameoff handling for trailing dirents",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46078"
    },
    {
      "rank": 541,
      "cve_id": "CVE-2026-46074",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00131,
      "epss_percentile": 0.03181,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-401",
      "title": "spi: ch341: fix memory leaks on probe failures",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46074"
    },
    {
      "rank": 542,
      "cve_id": "CVE-2026-2607",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00131,
      "epss_percentile": 0.03143,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "MQ Operator",
      "cwe": "CWE-532",
      "title": "Multiple vulnerabilities in IBM MQ Operator and Queue manager container images",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-2607"
    },
    {
      "rank": 543,
      "cve_id": "CVE-2026-42750",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0013,
      "epss_percentile": 0.03101,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Nexcess",
      "product": "WPComplete",
      "cwe": "CWE-79",
      "title": "WordPress WPComplete plugin <= 2.9.5.4 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42750"
    },
    {
      "rank": 544,
      "cve_id": "CVE-2026-42751",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0013,
      "epss_percentile": 0.03099,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wpdevelop",
      "product": "Booking Manager",
      "cwe": "CWE-79",
      "title": "WordPress Booking Manager plugin <= 2.1.18 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42751"
    },
    {
      "rank": 545,
      "cve_id": "CVE-2026-45919",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0013,
      "epss_percentile": 0.03111,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-835",
      "title": "sched/rt: Skip currently executing CPU in rto_next_cpu()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45919"
    },
    {
      "rank": 546,
      "cve_id": "CVE-2026-45968",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0013,
      "epss_percentile": 0.03095,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-476",
      "title": "cpuidle: Skip governor when only one idle state is available",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45968"
    },
    {
      "rank": 547,
      "cve_id": "CVE-2026-45982",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0013,
      "epss_percentile": 0.03074,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-476",
      "title": "ACPICA: Fix NULL pointer dereference in acpi_ev_address_space_dispatch()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45982"
    },
    {
      "rank": 548,
      "cve_id": "CVE-2026-46023",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0013,
      "epss_percentile": 0.03095,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-190",
      "title": "dm mirror: fix integer overflow in create_dirty_log()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46023"
    },
    {
      "rank": 549,
      "cve_id": "CVE-2026-47104",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0013,
      "epss_percentile": 0.0308,
      "kev": false,
      "kev_due_at": null,
      "vendor": "libusb",
      "product": "libusb",
      "cwe": "CWE-125",
      "title": "libusb < 1.0.30 Out-of-Bounds Read in parse_iad_array()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47104"
    },
    {
      "rank": 550,
      "cve_id": "CVE-2026-45891",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00129,
      "epss_percentile": 0.0302,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-415",
      "title": "net: hns3: fix double free issue for tx spare buffer",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45891"
    },
    {
      "rank": 551,
      "cve_id": "CVE-2026-46001",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00129,
      "epss_percentile": 0.02957,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-787",
      "title": "hwmon: (pt5161l) Fix bugs in pt5161l_read_block_data()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46001"
    },
    {
      "rank": 552,
      "cve_id": "CVE-2026-46004",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00129,
      "epss_percentile": 0.03022,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-416",
      "title": "ALSA: caiaq: Handle probe errors properly",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46004"
    },
    {
      "rank": 553,
      "cve_id": "CVE-2026-46015",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00129,
      "epss_percentile": 0.03021,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "tcp: call sk_data_ready() after listener migration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46015"
    },
    {
      "rank": 554,
      "cve_id": "CVE-2026-46053",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00129,
      "epss_percentile": 0.03025,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net: rds: fix MR cleanup on copy error",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46053"
    },
    {
      "rank": 555,
      "cve_id": "CVE-2026-46065",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00129,
      "epss_percentile": 0.03014,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-401",
      "title": "fbdev: defio: Disconnect deferred I/O from the lifetime of struct fb_info",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46065"
    },
    {
      "rank": 556,
      "cve_id": "CVE-2026-46068",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00129,
      "epss_percentile": 0.02955,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-787",
      "title": "crypto: nx - fix bounce buffer leaks in nx842_crypto_{alloc,free}_ctx",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46068"
    },
    {
      "rank": 557,
      "cve_id": "CVE-2026-46075",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00129,
      "epss_percentile": 0.03026,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-416",
      "title": "crypto: atmel-sha204a - Fix potential UAF and memory leak in remove path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46075"
    },
    {
      "rank": 558,
      "cve_id": "CVE-2026-46084",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00129,
      "epss_percentile": 0.0295,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-416",
      "title": "RDMA/mana_ib: Disable RX steering on RSS QP destroy",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46084"
    },
    {
      "rank": 559,
      "cve_id": "CVE-2026-46093",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00129,
      "epss_percentile": 0.02948,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "mm/vmalloc: take vmap_purge_lock in shrinker",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46093"
    },
    {
      "rank": 560,
      "cve_id": "CVE-2026-46033",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00129,
      "epss_percentile": 0.02973,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-125",
      "title": "crypto: authencesn - reject short ahash digests during instance creation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46033"
    },
    {
      "rank": 561,
      "cve_id": "CVE-2026-45840",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00129,
      "epss_percentile": 0.03011,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "openvswitch: cap upcall PID array size and pre-size vport replies",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45840"
    },
    {
      "rank": 562,
      "cve_id": "CVE-2026-45844",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00129,
      "epss_percentile": 0.03012,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "netfilter: arp_tables: fix IEEE1394 ARP payload parsing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45844"
    },
    {
      "rank": 563,
      "cve_id": "CVE-2026-45930",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00128,
      "epss_percentile": 0.02882,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net: mctp: ensure our nlmsg responses are initialised",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45930"
    },
    {
      "rank": 564,
      "cve_id": "CVE-2026-45974",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00128,
      "epss_percentile": 0.02877,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "btrfs: fix invalid leaf access in btrfs_quota_enable() if ref key not found",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45974"
    },
    {
      "rank": 565,
      "cve_id": "CVE-2026-46005",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00128,
      "epss_percentile": 0.02892,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-401",
      "title": "xfs: fix a resource leak in xfs_alloc_buftarg()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46005"
    },
    {
      "rank": 566,
      "cve_id": "CVE-2026-46026",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00128,
      "epss_percentile": 0.02883,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net: qrtr: ns: Limit the maximum number of lookups",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46026"
    },
    {
      "rank": 567,
      "cve_id": "CVE-2026-48792",
      "cvss_base": 4.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00128,
      "epss_percentile": 0.02922,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mcdope",
      "product": "pam_usb",
      "cwe": "CWE-390",
      "title": "pam_usb: pusb_has_virtual_input_device() silently discards EACCES, disabling remote desktop detection under non-root execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48792"
    },
    {
      "rank": 568,
      "cve_id": "CVE-2026-7614",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00128,
      "epss_percentile": 0.02894,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mkhfr",
      "product": "Old Posts Highlighter",
      "cwe": "CWE-352",
      "title": "Old Posts Highlighter <= 1.0.3 - Cross-Site Request Forgery to Settings Update",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7614"
    },
    {
      "rank": 569,
      "cve_id": "CVE-2026-8708",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00128,
      "epss_percentile": 0.02896,
      "kev": false,
      "kev_due_at": null,
      "vendor": "shra",
      "product": "Genzel breadcrumbs",
      "cwe": "CWE-352",
      "title": "Genzel breadcrumbs <= 1.2 - Cross-Site Request Forgery to Settings Update via Plugin Settings Page",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8708"
    },
    {
      "rank": 570,
      "cve_id": "CVE-2026-9236",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00128,
      "epss_percentile": 0.02895,
      "kev": false,
      "kev_due_at": null,
      "vendor": "creativemindssolutions",
      "product": "CM Ad Changer – A simple tool to control and optimize your site's banners",
      "cwe": "CWE-352",
      "title": "CM Ad Changer <= 2.0.7 - Cross-Site Request Forgery to Campaign Deletion via Campaign Management",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9236"
    },
    {
      "rank": 571,
      "cve_id": "CVE-2026-45959",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00127,
      "epss_percentile": 0.02787,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-476",
      "title": "crypto: ccp - Fix a crash due to incorrect cleanup usage of kfree",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45959"
    },
    {
      "rank": 572,
      "cve_id": "CVE-2026-46045",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00127,
      "epss_percentile": 0.02809,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-787",
      "title": "md/md-llbitmap: skip reading rdevs that are not in_sync",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46045"
    },
    {
      "rank": 573,
      "cve_id": "CVE-2026-45944",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00127,
      "epss_percentile": 0.0277,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "iommu/vt-d: Clear Present bit before tearing down context entry",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45944"
    },
    {
      "rank": 574,
      "cve_id": "CVE-2025-15649",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00127,
      "epss_percentile": 0.02787,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PMQS",
      "product": "IO::Uncompress::Unzip",
      "cwe": "CWE-248",
      "title": "IO::Uncompress::Unzip versions before 2.215 for Perl propagate uncaught exception when parsing zip header with malformed DOS date",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-15649"
    },
    {
      "rank": 575,
      "cve_id": "CVE-2026-45838",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00127,
      "epss_percentile": 0.02751,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-476",
      "title": "bpf: fix end-of-list detection in cgroup_storage_get_next_key()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45838"
    },
    {
      "rank": 576,
      "cve_id": "CVE-2026-45841",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00127,
      "epss_percentile": 0.02752,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-369",
      "title": "netfilter: nfnetlink_osf: fix divide-by-zero in OSF_WSS_MODULO",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45841"
    },
    {
      "rank": 577,
      "cve_id": "CVE-2026-45842",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00127,
      "epss_percentile": 0.02752,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-476",
      "title": "slip: reject VJ receive packets on instances with no rstate array",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45842"
    },
    {
      "rank": 578,
      "cve_id": "CVE-2026-45846",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00127,
      "epss_percentile": 0.02782,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-476",
      "title": "bareudp: fix NULL pointer dereference in bareudp_fill_metadata_dst()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45846"
    },
    {
      "rank": 579,
      "cve_id": "CVE-2026-45928",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00127,
      "epss_percentile": 0.02834,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-401",
      "title": "media: chips-media: wave5: Fix memory leak on codec_info allocation failure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45928"
    },
    {
      "rank": 580,
      "cve_id": "CVE-2026-45914",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00126,
      "epss_percentile": 0.02671,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-416",
      "title": "Revert \"hwmon: (ibmpex) fix use-after-free in high/low store\"",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45914"
    },
    {
      "rank": 581,
      "cve_id": "CVE-2026-45936",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00126,
      "epss_percentile": 0.02676,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-416",
      "title": "power: supply: goldfish: Fix use-after-free in power_supply_changed()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45936"
    },
    {
      "rank": 582,
      "cve_id": "CVE-2026-45956",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00126,
      "epss_percentile": 0.02669,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-416",
      "title": "drm/exynos: vidi: use priv->vidi_dev for ctx lookup in vidi_connection_ioctl()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45956"
    },
    {
      "rank": 583,
      "cve_id": "CVE-2026-45970",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00126,
      "epss_percentile": 0.02669,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-416",
      "title": "bonding: alb: fix UAF in rlb_arp_recv during bond up/down",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45970"
    },
    {
      "rank": 584,
      "cve_id": "CVE-2026-46047",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00126,
      "epss_percentile": 0.02667,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-416",
      "title": "net: qrtr: ns: Fix use-after-free in driver remove()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46047"
    },
    {
      "rank": 585,
      "cve_id": "CVE-2026-45958",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00126,
      "epss_percentile": 0.02664,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-476",
      "title": "drm/exynos: vidi: fix to avoid directly dereferencing user pointer",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45958"
    },
    {
      "rank": 586,
      "cve_id": "CVE-2026-46070",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00126,
      "epss_percentile": 0.02687,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-787",
      "title": "md/raid5: validate payload size before accessing journal metadata",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46070"
    },
    {
      "rank": 587,
      "cve_id": "CVE-2026-45952",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00126,
      "epss_percentile": 0.0272,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "eth: fbnic: Add validation for MTU changes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45952"
    },
    {
      "rank": 588,
      "cve_id": "CVE-2026-45981",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00126,
      "epss_percentile": 0.02727,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-401",
      "title": "s390/cio: Fix device lifecycle handling in css_alloc_subchannel()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45981"
    },
    {
      "rank": 589,
      "cve_id": "CVE-2026-46042",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00126,
      "epss_percentile": 0.02719,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-401",
      "title": "mm/mempolicy: fix memory leaks in weighted_interleave_auto_store()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46042"
    },
    {
      "rank": 590,
      "cve_id": "CVE-2026-45938",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00125,
      "epss_percentile": 0.02627,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-416",
      "title": "power: supply: pm8916_lbc: Fix use-after-free in power_supply_changed()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45938"
    },
    {
      "rank": 591,
      "cve_id": "CVE-2026-46011",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00125,
      "epss_percentile": 0.0263,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-416",
      "title": "media: mtk-jpeg: fix use-after-free in release path due to uncancelled work",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46011"
    },
    {
      "rank": 592,
      "cve_id": "CVE-2026-45893",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00125,
      "epss_percentile": 0.02639,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-125",
      "title": "apparmor: Fix & Optimize table creation from possibly unaligned memory",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45893"
    },
    {
      "rank": 593,
      "cve_id": "CVE-2026-45943",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00125,
      "epss_percentile": 0.0264,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-125",
      "title": "erofs: fix inline data read failure for ztailpacking pclusters",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45943"
    },
    {
      "rank": 594,
      "cve_id": "CVE-2026-45957",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00125,
      "epss_percentile": 0.02623,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-125",
      "title": "rcu: Fix rcu_read_unlock() deadloop due to softirq",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45957"
    },
    {
      "rank": 595,
      "cve_id": "CVE-2026-46094",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00125,
      "epss_percentile": 0.02638,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-125",
      "title": "ext4: fix bounds check in check_xattrs() to prevent out-of-bounds access",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46094"
    },
    {
      "rank": 596,
      "cve_id": "CVE-2026-45951",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00124,
      "epss_percentile": 0.02523,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-416",
      "title": "bpf: Fix a potential use-after-free of BTF object",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45951"
    },
    {
      "rank": 597,
      "cve_id": "CVE-2026-45980",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00124,
      "epss_percentile": 0.0253,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-416",
      "title": "accel/amdxdna: Stop job scheduling across aie2_release_resource()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45980"
    },
    {
      "rank": 598,
      "cve_id": "CVE-2026-45955",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00124,
      "epss_percentile": 0.02552,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "md/md-llbitmap: fix percpu_ref not resurrected on suspend timeout",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45955"
    },
    {
      "rank": 599,
      "cve_id": "CVE-2026-46020",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00124,
      "epss_percentile": 0.02541,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-125",
      "title": "mm/damon/core: validate damos_quota_goal->nid for node_mem_{used,free}_bp",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46020"
    },
    {
      "rank": 600,
      "cve_id": "CVE-2026-8942",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00124,
      "epss_percentile": 0.02546,
      "kev": false,
      "kev_due_at": null,
      "vendor": "lhughes33472",
      "product": "MetaMagic SEO Plugin",
      "cwe": "CWE-352",
      "title": "MetaMagic SEO Plugin <= 1.6 - Cross-Site Request Forgery to Plugin Settings Update via Settings Page",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8942"
    },
    {
      "rank": 601,
      "cve_id": "CVE-2026-46054",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00123,
      "epss_percentile": 0.02497,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-280",
      "title": "selinux: fix overlayfs mmap() and mprotect() access checks",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46054"
    },
    {
      "rank": 602,
      "cve_id": "CVE-2026-45890",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00123,
      "epss_percentile": 0.02461,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "xen-netback: reject zero-queue configuration from guest",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45890"
    },
    {
      "rank": 603,
      "cve_id": "CVE-2026-45912",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00123,
      "epss_percentile": 0.02447,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ext4: don't cache extent during splitting extent",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45912"
    },
    {
      "rank": 604,
      "cve_id": "CVE-2026-45941",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00123,
      "epss_percentile": 0.02491,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-401",
      "title": "tpm: tpm_i2c_infineon: Fix locality leak on get_burstcount() failure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45941"
    },
    {
      "rank": 605,
      "cve_id": "CVE-2026-45960",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00123,
      "epss_percentile": 0.02439,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "hfsplus: return error when node already exists in hfs_bnode_create",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45960"
    },
    {
      "rank": 606,
      "cve_id": "CVE-2026-45969",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00123,
      "epss_percentile": 0.02449,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-476",
      "title": "HID: playstation: Add missing check for input_ff_create_memless",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45969"
    },
    {
      "rank": 607,
      "cve_id": "CVE-2026-45978",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00123,
      "epss_percentile": 0.0246,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-476",
      "title": "staging: greybus: lights: avoid NULL deref",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45978"
    },
    {
      "rank": 608,
      "cve_id": "CVE-2026-45983",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00123,
      "epss_percentile": 0.02413,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "nfsd: never defer requests during idmap lookup",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45983"
    },
    {
      "rank": 609,
      "cve_id": "CVE-2026-45985",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00123,
      "epss_percentile": 0.02429,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ext4: don't set EXT4_GET_BLOCKS_CONVERT when splitting before submitting I/O",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45985"
    },
    {
      "rank": 610,
      "cve_id": "CVE-2026-45986",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00123,
      "epss_percentile": 0.02428,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-401",
      "title": "crypto: ccree - fix a memory leak in cc_mac_digest()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45986"
    },
    {
      "rank": 611,
      "cve_id": "CVE-2026-45987",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00123,
      "epss_percentile": 0.02428,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "KVM: nSVM: Sync interrupt shadow to cached vmcb12 after VMRUN of L2",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45987"
    },
    {
      "rank": 612,
      "cve_id": "CVE-2026-45997",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00123,
      "epss_percentile": 0.02457,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "scsi: sd: fix missing put_disk() when device_add(&disk_dev) fails",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45997"
    },
    {
      "rank": 613,
      "cve_id": "CVE-2026-46002",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00123,
      "epss_percentile": 0.02458,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ext2: reject inodes with zero i_nlink and valid mode in ext2_iget()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46002"
    },
    {
      "rank": 614,
      "cve_id": "CVE-2026-46003",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00123,
      "epss_percentile": 0.02458,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net: qrtr: ns: Limit the total number of nodes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46003"
    },
    {
      "rank": 615,
      "cve_id": "CVE-2026-46009",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00123,
      "epss_percentile": 0.02461,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "PCI: endpoint: pci-epf-ntb: Remove duplicate resource teardown",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46009"
    },
    {
      "rank": 616,
      "cve_id": "CVE-2026-46028",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00123,
      "epss_percentile": 0.02427,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "crypto: algif_aead - snapshot IV for async AEAD requests",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46028"
    },
    {
      "rank": 617,
      "cve_id": "CVE-2026-46038",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00123,
      "epss_percentile": 0.02433,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-401",
      "title": "net: qrtr: ns: Free the node during ctrl_cmd_bye()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46038"
    },
    {
      "rank": 618,
      "cve_id": "CVE-2026-46040",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00123,
      "epss_percentile": 0.02433,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "inotify: fix watch count leak when fsnotify_add_inode_mark_locked() fails",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46040"
    },
    {
      "rank": 619,
      "cve_id": "CVE-2026-46044",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00123,
      "epss_percentile": 0.02418,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ipmi:ssif: Clean up kthread on errors",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46044"
    },
    {
      "rank": 620,
      "cve_id": "CVE-2026-46046",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00123,
      "epss_percentile": 0.02418,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ext4: fix missing brelse() in ext4_xattr_inode_dec_ref_all()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46046"
    },
    {
      "rank": 621,
      "cve_id": "CVE-2026-46048",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00123,
      "epss_percentile": 0.02463,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ALSA: caiaq: fix usb_dev refcount leak on probe failure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46048"
    },
    {
      "rank": 622,
      "cve_id": "CVE-2026-46049",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00123,
      "epss_percentile": 0.02411,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ALSA: ctxfi: Add fallback to default RSR for S/PDIF",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46049"
    },
    {
      "rank": 623,
      "cve_id": "CVE-2026-46072",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00123,
      "epss_percentile": 0.02418,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ntfs3: add buffer boundary checks to run_unpack()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46072"
    },
    {
      "rank": 624,
      "cve_id": "CVE-2026-46077",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00123,
      "epss_percentile": 0.02417,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "crypto: atmel-tdes - fix DMA sync direction",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46077"
    },
    {
      "rank": 625,
      "cve_id": "CVE-2026-46082",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00123,
      "epss_percentile": 0.02416,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "KVM: SVM: Inject #UD for INVLPGA if EFER.SVME=0",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46082"
    },
    {
      "rank": 626,
      "cve_id": "CVE-2026-46083",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00123,
      "epss_percentile": 0.02416,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-401",
      "title": "spi: fix resource leaks on device setup failure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46083"
    },
    {
      "rank": 627,
      "cve_id": "CVE-2026-46086",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00123,
      "epss_percentile": 0.02416,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-476",
      "title": "net: bridge: use a stable FDB dst snapshot in RCU readers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46086"
    },
    {
      "rank": 628,
      "cve_id": "CVE-2026-46088",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00123,
      "epss_percentile": 0.02416,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ALSA: control: Validate buf_len before strnlen() in snd_ctl_elem_init_enum_names()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46088"
    },
    {
      "rank": 629,
      "cve_id": "CVE-2026-46091",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00123,
      "epss_percentile": 0.02424,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "media: rc: igorplugusb: heed coherency rules",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46091"
    },
    {
      "rank": 630,
      "cve_id": "CVE-2026-46098",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00123,
      "epss_percentile": 0.02426,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-476",
      "title": "net: caif: clear client service pointer on teardown",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46098"
    },
    {
      "rank": 631,
      "cve_id": "CVE-2026-46101",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00123,
      "epss_percentile": 0.02426,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "netfilter: reject zero shift in nft_bitwise",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46101"
    },
    {
      "rank": 632,
      "cve_id": "CVE-2026-7365",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00122,
      "epss_percentile": 0.02405,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Operations Analytics - Log Analysis",
      "cwe": "CWE-1392",
      "title": "IBM Operations Analytics - Log Analysis is affected by Information disclosure due to default passwords not being forced to be changed on post-installation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7365"
    },
    {
      "rank": 633,
      "cve_id": "CVE-2026-45917",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00122,
      "epss_percentile": 0.02407,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ipvs: do not keep dest_dst if dev is going down",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45917"
    },
    {
      "rank": 634,
      "cve_id": "CVE-2026-45921",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00122,
      "epss_percentile": 0.02373,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-401",
      "title": "mtd: parsers: Fix memory leak in mtd_parser_tplink_safeloader_parse()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45921"
    },
    {
      "rank": 635,
      "cve_id": "CVE-2026-45950",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00122,
      "epss_percentile": 0.0237,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-401",
      "title": "crypto: starfive - Fix memory leak in starfive_aes_aead_do_one_req()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45950"
    },
    {
      "rank": 636,
      "cve_id": "CVE-2026-45954",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00122,
      "epss_percentile": 0.02403,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-401",
      "title": "fbdev: au1200fb: Fix a memory leak in au1200fb_drv_probe()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45954"
    },
    {
      "rank": 637,
      "cve_id": "CVE-2026-45976",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00122,
      "epss_percentile": 0.02349,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-401",
      "title": "drm/amdgpu: Fix memory leak in amdgpu_ras_init()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45976"
    },
    {
      "rank": 638,
      "cve_id": "CVE-2026-46007",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00122,
      "epss_percentile": 0.02362,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "hwmon: (powerz) Avoid cacheline sharing for DMA buffer",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46007"
    },
    {
      "rank": 639,
      "cve_id": "CVE-2026-46012",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00122,
      "epss_percentile": 0.02366,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-401",
      "title": "rxrpc: Fix memory leaks in rxkad_verify_response()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46012"
    },
    {
      "rank": 640,
      "cve_id": "CVE-2026-46016",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00122,
      "epss_percentile": 0.02371,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-476",
      "title": "remoteproc: xlnx: Only access buffer information if IPI is buffered",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46016"
    },
    {
      "rank": 641,
      "cve_id": "CVE-2026-46073",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00122,
      "epss_percentile": 0.02367,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "hwmon: (powerz) Fix missing usb_kill_urb() on signal interrupt",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46073"
    },
    {
      "rank": 642,
      "cve_id": "CVE-2026-47271",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00122,
      "epss_percentile": 0.02385,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mcdope",
      "product": "pam_usb",
      "cwe": "CWE-476",
      "title": "pam_usb: OOM guards removed by -DNDEBUG cause NULL dereference and authentication process crash",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47271"
    },
    {
      "rank": 643,
      "cve_id": "CVE-2026-46076",
      "cvss_base": 7.9,
      "cvss_severity": "HIGH",
      "epss_score": 0.00121,
      "epss_percentile": 0.02285,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "KVM: nSVM: Raise #UD if unhandled VMMCALL isn't intercepted by L1",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46076"
    },
    {
      "rank": 644,
      "cve_id": "CVE-2026-49000",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00121,
      "epss_percentile": 0.02276,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ZTE",
      "product": "ZXUniPOS NDS-LTE",
      "cwe": "CWE-310",
      "title": "Cryptography Implementation Flaw vulnerability in ZTE ZXUniPOS NDS-LTE product",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49000"
    },
    {
      "rank": 645,
      "cve_id": "CVE-2026-45934",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00121,
      "epss_percentile": 0.02262,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "btrfs: fix EEXIST abort due to non-consecutive gaps in chunk allocation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45934"
    },
    {
      "rank": 646,
      "cve_id": "CVE-2026-45937",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00121,
      "epss_percentile": 0.02242,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "crypto: inside-secure/eip93 - fix kernel panic in driver detach",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45937"
    },
    {
      "rank": 647,
      "cve_id": "CVE-2026-45939",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00121,
      "epss_percentile": 0.02248,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-401",
      "title": "gpib: Fix memory leak in ni_usb_init()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45939"
    },
    {
      "rank": 648,
      "cve_id": "CVE-2026-45953",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00121,
      "epss_percentile": 0.02243,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "md/raid5: fix IO hang with degraded array with llbitmap",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45953"
    },
    {
      "rank": 649,
      "cve_id": "CVE-2026-45966",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00121,
      "epss_percentile": 0.02238,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-476",
      "title": "apparmor: fix NULL pointer dereference in __unix_needs_revalidation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45966"
    },
    {
      "rank": 650,
      "cve_id": "CVE-2026-45971",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00121,
      "epss_percentile": 0.02244,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "bpf: Limit bpf program signature size",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45971"
    },
    {
      "rank": 651,
      "cve_id": "CVE-2026-45977",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00121,
      "epss_percentile": 0.02244,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "fbnic: close fw_log race between users and teardown",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45977"
    },
    {
      "rank": 652,
      "cve_id": "CVE-2026-46030",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00121,
      "epss_percentile": 0.02235,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-401",
      "title": "EDAC/versalnet: Fix device_node leak in mc_probe()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46030"
    },
    {
      "rank": 653,
      "cve_id": "CVE-2026-46035",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00121,
      "epss_percentile": 0.02236,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "mm/page_alloc: return NULL early from alloc_frozen_pages_nolock() in NMI on UP",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46035"
    },
    {
      "rank": 654,
      "cve_id": "CVE-2026-46059",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00121,
      "epss_percentile": 0.02262,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "KVM: nSVM: Always use NextRIP as vmcb02's NextRIP after first L2 VMRUN",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46059"
    },
    {
      "rank": 655,
      "cve_id": "CVE-2026-46060",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00121,
      "epss_percentile": 0.0225,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "crypto: qat - fix IRQ cleanup on 6xxx probe failure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46060"
    },
    {
      "rank": 656,
      "cve_id": "CVE-2026-46066",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00121,
      "epss_percentile": 0.02239,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-193",
      "title": "ceph: fix num_ops off-by-one when crypto allocation fails",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46066"
    },
    {
      "rank": 657,
      "cve_id": "CVE-2026-46071",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00121,
      "epss_percentile": 0.02243,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "KVM: nSVM: Avoid clearing VMCB_LBR in vmcb12",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46071"
    },
    {
      "rank": 658,
      "cve_id": "CVE-2026-46087",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00121,
      "epss_percentile": 0.0224,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-401",
      "title": "mm/damon/stat: fix memory leak on damon_start() failure in damon_stat_start()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46087"
    },
    {
      "rank": 659,
      "cve_id": "CVE-2026-46095",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00121,
      "epss_percentile": 0.02253,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "md/md-llbitmap: raise barrier before state machine transition",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46095"
    },
    {
      "rank": 660,
      "cve_id": "CVE-2026-46096",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00121,
      "epss_percentile": 0.02254,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "tpm2-sessions: Fix missing tpm_buf_destroy() in tpm2_read_public()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46096"
    },
    {
      "rank": 661,
      "cve_id": "CVE-2026-45906",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0012,
      "epss_percentile": 0.02205,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-416",
      "title": "power: supply: pf1550: Fix use-after-free in power_supply_changed()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45906"
    },
    {
      "rank": 662,
      "cve_id": "CVE-2026-45995",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0012,
      "epss_percentile": 0.02206,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-416",
      "title": "io_uring/zcrx: fix user_struct uaf",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45995"
    },
    {
      "rank": 663,
      "cve_id": "CVE-2026-42328",
      "cvss_base": 6.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0012,
      "epss_percentile": 0.02167,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ipld",
      "product": "go-ipld-prime",
      "cwe": "CWE-674",
      "title": "go-ipld-prime: DAG-CBOR and DAG-JSON decoders unbounded recursion depth",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42328"
    },
    {
      "rank": 664,
      "cve_id": "CVE-2026-45845",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0012,
      "epss_percentile": 0.02138,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-476",
      "title": "net/sched: taprio: fix NULL pointer dereference in class dump",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45845"
    },
    {
      "rank": 665,
      "cve_id": "CVE-2026-45924",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0012,
      "epss_percentile": 0.0218,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-667",
      "title": "ksmbd: call ksmbd_vfs_kern_path_end_removing() on some error paths",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45924"
    },
    {
      "rank": 666,
      "cve_id": "CVE-2026-47272",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00119,
      "epss_percentile": 0.02048,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mcdope",
      "product": "pam_usb",
      "cwe": "CWE-287",
      "title": "pam_usb: OTP pad authentication bypass via missing system pad check and uninitialized RNG buffer",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47272"
    },
    {
      "rank": 667,
      "cve_id": "CVE-2026-8906",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00119,
      "epss_percentile": 0.02107,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rahulbhangale",
      "product": "WP Promoter",
      "cwe": "CWE-352",
      "title": "WP Promoter <= 1.3 - Cross-Site Request Forgery to Stored Cross-Site Scripting via 'popup_width' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8906"
    },
    {
      "rank": 668,
      "cve_id": "CVE-2026-45907",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00118,
      "epss_percentile": 0.02037,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-667",
      "title": "net/mlx5e: Fix deadlocks between devlink and netdev instance locks",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45907"
    },
    {
      "rank": 669,
      "cve_id": "CVE-2026-46057",
      "cvss_base": 3.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00118,
      "epss_percentile": 0.02018,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "landlock: Fix LOG_SUBDOMAINS_OFF inheritance across fork()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46057"
    },
    {
      "rank": 670,
      "cve_id": "CVE-2026-46067",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00117,
      "epss_percentile": 0.01962,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-125",
      "title": "mm/damon/core: validate damos_quota_goal->nid for node_memcg_{used,free}_bp",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46067"
    },
    {
      "rank": 671,
      "cve_id": "CVE-2026-45837",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00116,
      "epss_percentile": 0.0191,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-416",
      "title": "bpf: Fix use-after-free in arena_vm_close on fork",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45837"
    },
    {
      "rank": 672,
      "cve_id": "CVE-2026-48066",
      "cvss_base": 5.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00116,
      "epss_percentile": 0.01853,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mcdope",
      "product": "pam_usb",
      "cwe": "CWE-362",
      "title": "pam_usb: Thread-unsafe static pointer in log.c causes data race under concurrent PAM authentication",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48066"
    },
    {
      "rank": 673,
      "cve_id": "CVE-2026-45963",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00116,
      "epss_percentile": 0.01869,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-476",
      "title": "ASoC: nau8821: Cancel delayed work on component remove",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45963"
    },
    {
      "rank": 674,
      "cve_id": "CVE-2026-46032",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00116,
      "epss_percentile": 0.01875,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "KVM: nSVM: Triple fault if restore host CR3 fails on nested #VMEXIT",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46032"
    },
    {
      "rank": 675,
      "cve_id": "CVE-2026-48147",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00115,
      "epss_percentile": 0.01811,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Budibase",
      "product": "budibase",
      "cwe": "CWE-185",
      "title": "Budibase: Unanchored Regex in `matchers.ts` Allows CSRF Bypass via Query String Injection in Budibase Worker",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48147"
    },
    {
      "rank": 676,
      "cve_id": "CVE-2026-46103",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00114,
      "epss_percentile": 0.01753,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-401",
      "title": "can: ucan: fix devres lifetime",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46103"
    },
    {
      "rank": 677,
      "cve_id": "CVE-2026-44972",
      "cvss_base": 5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00113,
      "epss_percentile": 0.01622,
      "kev": false,
      "kev_due_at": null,
      "vendor": "DataDog",
      "product": "guarddog",
      "cwe": "CWE-116",
      "title": "GuardDog: Unsanitized human-readable scan output allows terminal escape injection from malicious package content",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44972"
    },
    {
      "rank": 678,
      "cve_id": "CVE-2024-11399",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00112,
      "epss_percentile": 0.01577,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Synology",
      "product": "BeeDrive for desktop",
      "cwe": "CWE-552",
      "title": "Files or directories accessible to external parties vulnerability in redis-server component in Synology BeeDrive for desktop before 1.3.2-13814 allows local users to conduct denial-of-service attacks via unspecified vectors.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-11399"
    },
    {
      "rank": 679,
      "cve_id": "CVE-2026-45926",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00112,
      "epss_percentile": 0.01588,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-401",
      "title": "rust: pwm: Fix potential memory leak on init error",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45926"
    },
    {
      "rank": 680,
      "cve_id": "CVE-2026-45905",
      "cvss_base": 4.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00111,
      "epss_percentile": 0.01551,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-362",
      "title": "xfrm: fix ip_rt_bug race in icmp_route_lookup reverse path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45905"
    },
    {
      "rank": 681,
      "cve_id": "CVE-2026-49001",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00109,
      "epss_percentile": 0.01416,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ZTE",
      "product": "ZXUniPOS NDS-LTE",
      "cwe": "CWE-352",
      "title": "Cross-Site Request Forgery (CSRF) vulnerability in ZTE ZXUniPOS NDS-LTE product",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49001"
    },
    {
      "rank": 682,
      "cve_id": "CVE-2026-47270",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00108,
      "epss_percentile": 0.01356,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mcdope",
      "product": "pam_usb",
      "cwe": "CWE-362",
      "title": "pam_usb: strtok() race condition in multi-threaded PAM hosts can corrupt deny_remote result",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47270"
    },
    {
      "rank": 683,
      "cve_id": "CVE-2026-45967",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00107,
      "epss_percentile": 0.01337,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "bpf: Return proper address for non-zero offsets in insn array",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45967"
    },
    {
      "rank": 684,
      "cve_id": "CVE-2026-45975",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00107,
      "epss_percentile": 0.01339,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ublk: use READ_ONCE() to read struct ublksrv_ctrl_cmd",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45975"
    },
    {
      "rank": 685,
      "cve_id": "CVE-2026-45979",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00107,
      "epss_percentile": 0.0134,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/amdgpu: clean up the amdgpu_cs_parser_bos",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45979"
    },
    {
      "rank": 686,
      "cve_id": "CVE-2026-46013",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00107,
      "epss_percentile": 0.01332,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "mm/memfd_luo: fix physical address conversion in put_folios cleanup",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46013"
    },
    {
      "rank": 687,
      "cve_id": "CVE-2025-71309",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00106,
      "epss_percentile": 0.01269,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-667",
      "title": "fs/ntfs3: fix deadlock in ni_read_folio_cmpr",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-71309"
    },
    {
      "rank": 688,
      "cve_id": "CVE-2026-45046",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00106,
      "epss_percentile": 0.01258,
      "kev": false,
      "kev_due_at": null,
      "vendor": "safedep",
      "product": "gryph",
      "cwe": "CWE-212",
      "title": "Gryph Agents Payload Filter Fails to Strip Tool Payload for Sensitive Content",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45046"
    },
    {
      "rank": 689,
      "cve_id": "CVE-2026-46017",
      "cvss_base": 4.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00105,
      "epss_percentile": 0.01203,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-362",
      "title": "mm: fix deferred split queue races during migration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46017"
    },
    {
      "rank": 690,
      "cve_id": "CVE-2026-48925",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00105,
      "epss_percentile": 0.01204,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jenkins Project",
      "product": "Jenkins GitHub Integration Plugin",
      "cwe": "CWE-352",
      "title": "A cross-site request forgery (CSRF) vulnerability in Jenkins GitHub Integration Plugin 0.7.3 and earlier allows attackers to attackers to trigger a build for a pull request.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48925"
    },
    {
      "rank": 691,
      "cve_id": "CVE-2026-46090",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00103,
      "epss_percentile": 0.01128,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-416",
      "title": "ALSA: aloop: Fix peer runtime UAF during format-change stop",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46090"
    },
    {
      "rank": 692,
      "cve_id": "CVE-2026-45910",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00102,
      "epss_percentile": 0.01063,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-362",
      "title": "RDMA/rxe: Fix race condition in QP timer handlers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45910"
    },
    {
      "rank": 693,
      "cve_id": "CVE-2026-49014",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00102,
      "epss_percentile": 0.01088,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GDAL",
      "product": "GDAL",
      "cwe": "CWE-121",
      "title": "In GDAL 3.1.0 through 3.13.0, scanForGeometryContainers in the netCDF driver allows code execution via a stack-based buffer overflow. It reads a geometry attribute into a fixed-size stack buffer without validating the attribute length. The attacker embeds the exploit as an oversized geometry attribute in a crafted NetCDF file. This achieves arbitrary code execution on the server running GDAL. This is in frmts/netcdf/netcdfsg.cpp.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49014"
    },
    {
      "rank": 694,
      "cve_id": "CVE-2025-71303",
      "cvss_base": 4.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00102,
      "epss_percentile": 0.01052,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-362",
      "title": "accel/amdxdna: Fix race condition when checking rpm_on",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-71303"
    },
    {
      "rank": 695,
      "cve_id": "CVE-2026-5515",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.001,
      "epss_percentile": 0.00987,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "App Connect Enterprise",
      "cwe": "CWE-922",
      "title": "IBM App Connect Enterprise is vulnerable to a confidential disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-5515"
    },
    {
      "rank": 696,
      "cve_id": "CVE-2026-45942",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00099,
      "epss_percentile": 0.00944,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-362",
      "title": "ext4: fix e4b bitmap inconsistency reports",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45942"
    },
    {
      "rank": 697,
      "cve_id": "CVE-2026-41009",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00099,
      "epss_percentile": 0.00937,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cloud Foundry Foundation",
      "product": "BOSH Director",
      "cwe": "CWE-22",
      "title": "Local Blobstore may allow arbitrary reads/deletes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41009"
    },
    {
      "rank": 698,
      "cve_id": "CVE-2026-6053",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00098,
      "epss_percentile": 0.00878,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Db2",
      "cwe": "CWE-770",
      "title": "IBM® Db2® is vulnerable to a denial of service when a specially crafted query is run with range partitioned tables",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6053"
    },
    {
      "rank": 699,
      "cve_id": "CVE-2026-46058",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00097,
      "epss_percentile": 0.00849,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-362",
      "title": "media: amphion: Fix race between m2m job_abort and device_run",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46058"
    },
    {
      "rank": 700,
      "cve_id": "CVE-2026-30498",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00097,
      "epss_percentile": 0.00857,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-352",
      "title": "A Cross-Site Request Forgery (CSRF) vulnerability was discovered in the delete.php endpoint of Jason2605 AdminPanel 4.0.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-30498"
    },
    {
      "rank": 701,
      "cve_id": "CVE-2026-46050",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00095,
      "epss_percentile": 0.00733,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-667",
      "title": "md/raid10: fix deadlock with check operation and nowait requests",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46050"
    },
    {
      "rank": 702,
      "cve_id": "CVE-2026-46051",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00095,
      "epss_percentile": 0.00733,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-667",
      "title": "md/raid5: fix soft lockup in retry_aligned_read()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46051"
    },
    {
      "rank": 703,
      "cve_id": "CVE-2026-46061",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00094,
      "epss_percentile": 0.00707,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-667",
      "title": "jbd2: fix deadlock in jbd2_journal_cancel_revoke()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46061"
    },
    {
      "rank": 704,
      "cve_id": "CVE-2026-46063",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00094,
      "epss_percentile": 0.00708,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-667",
      "title": "x86/shstk: Prevent deadlock during shstk sigreturn",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46063"
    },
    {
      "rank": 705,
      "cve_id": "CVE-2026-46014",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00093,
      "epss_percentile": 0.00664,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-667",
      "title": "KVM: SVM: Add missing save/restore handling of LBR MSRs",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46014"
    },
    {
      "rank": 706,
      "cve_id": "CVE-2026-2237",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00092,
      "epss_percentile": 0.00593,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Synology",
      "product": "Storage Manager",
      "cwe": "CWE-598",
      "title": "A use of get request method with sensitive query strings vulnerability in volume encryption of Synology Storage Manager package before 1.0.1-1100 allows local users on Windows to obtain sensitive information.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-2237"
    },
    {
      "rank": 707,
      "cve_id": "CVE-2026-9759",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00092,
      "epss_percentile": 0.00604,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Wireshark Foundation",
      "product": "Wireshark",
      "cwe": "CWE-476",
      "title": "NULL Pointer Dereference in Wireshark",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9759"
    },
    {
      "rank": 708,
      "cve_id": "CVE-2026-45927",
      "cvss_base": 4.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00092,
      "epss_percentile": 0.00592,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-367",
      "title": "bpf: Require frozen map for calculating map hash",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45927"
    },
    {
      "rank": 709,
      "cve_id": "CVE-2026-45949",
      "cvss_base": 4.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00088,
      "epss_percentile": 0.0046,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-362",
      "title": "hwrng: core - use RCU and work_struct to fix race condition",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45949"
    },
    {
      "rank": 710,
      "cve_id": "CVE-2026-46025",
      "cvss_base": 4.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00088,
      "epss_percentile": 0.00453,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-362",
      "title": "mm/damon/core: fix damon_call() vs kdamond_fn() exit race",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46025"
    },
    {
      "rank": 711,
      "cve_id": "CVE-2025-13593",
      "cvss_base": 5.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00086,
      "epss_percentile": 0.00384,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Synology",
      "product": "ActiveProtect Agent",
      "cwe": "CWE-346",
      "title": "Origin validation error vulnerability in Synology ActiveProtect Agent before 1.1.0-0439 allows local users to write arbitrary files with restricted content and conduct denial-of-service during installation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-13593"
    },
    {
      "rank": 712,
      "cve_id": "CVE-2025-66592",
      "cvss_base": 5.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00086,
      "epss_percentile": 0.00384,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Synology",
      "product": "Synology Active Backup for Business Agent",
      "cwe": "CWE-346",
      "title": "An origin validation error vulnerability in Synology Active Backup for Business Agent before 3.1.0-4967 allows local users to write arbitrary files with restricted content and conduct denial-of-service during installation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-66592"
    },
    {
      "rank": 713,
      "cve_id": "CVE-2025-66593",
      "cvss_base": 5.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00086,
      "epss_percentile": 0.00384,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Synology",
      "product": "Synology Assistant",
      "cwe": "CWE-346",
      "title": "An origin validation error vulnerability in Synology Assistant before 7.0.6-50085 allows local users to write arbitrary files with restricted content and conduct denial-of-service during installation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-66593"
    },
    {
      "rank": 714,
      "cve_id": "CVE-2026-41704",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00083,
      "epss_percentile": 0.00299,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cloud Foundry Foundation",
      "product": "BOSH Director",
      "cwe": "CWE-284",
      "title": "Compromised VM can make arbitrary blobstore deletes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41704"
    },
    {
      "rank": 715,
      "cve_id": "CVE-2026-46008",
      "cvss_base": 4.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00079,
      "epss_percentile": 0.00166,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-362",
      "title": "mm/damon/core: fix damos_walk() vs kdamond_fn() exit race",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46008"
    }
  ],
  "transactions": [
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-42081",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-42081 (free5gc). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-42082",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-42082 (free5gc). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-42083",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-42083 (free5gc). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-42184",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-42184 (tauri-apps tauri). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-42459",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-42459 (free5gc). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-44315",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-44315 (free5gc). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-44316",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-44316 (free5gc). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-44317",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-44317 (free5gc). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-44318",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-44318 (free5gc). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-44319",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-44319 (free5gc). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-44320",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-44320 (free5gc). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-44321",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-44321 (free5gc). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-44322",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-44322 (free5gc). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-44323",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-44323 (free5gc). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-44324",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-44324 (free5gc). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-44325",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-44325 (free5gc). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-44326",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-44326 (free5gc). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-44327",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-44327 (free5gc). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-44328",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-44328 (free5gc). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-44329",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-44329 (free5gc). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-44330",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-44330 (free5gc). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-44345",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-44345 (BentoML). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-44346",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-44346 (BentoML). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-44353",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-44353 (streamlink). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-44660",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-44660 (ultrajson). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-44681",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-44681 (authlib). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-45104",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-45104 (MapServer). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-45136",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-45136 (cnighswonger claude-code-cache-fix). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-48027",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-48027 (nrwl nx-console). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-9617",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-9617 (DALIBO PostgreSQL Anonymizer). Public exploit reference added."
    }
  ],
  "attribution": "CVE Program, NVD (NIST), CISA KEV, FIRST EPSS, OSV. See /security/methodology/."
}
