{
  "day": "2026-05-28",
  "boundary": "UTC calendar day",
  "published_count": 542,
  "by_severity": {
    "CRITICAL": 56,
    "HIGH": 278,
    "MEDIUM": 194,
    "LOW": 14
  },
  "kev_count": 0,
  "exploit_reference_count": 30,
  "awaiting_enrichment_count": 0,
  "ranking": "Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.",
  "results": [
    {
      "rank": 1,
      "cve_id": "CVE-2026-4408",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.02501,
      "epss_percentile": 0.83417,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-78",
      "title": "Samba: remote code execution in samr",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-4408"
    },
    {
      "rank": 2,
      "cve_id": "CVE-2026-39929",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.01403,
      "epss_percentile": 0.70379,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Lakeside Software, LLC.",
      "product": "SysTrack Agent",
      "cwe": "CWE-125",
      "title": "Lakeside SysTrack Agent LsiAgent.exe Out-of-Bounds Read via UDP",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39929"
    },
    {
      "rank": 3,
      "cve_id": "CVE-2026-38704",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.01269,
      "epss_percentile": 0.67455,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-77",
      "title": "A command injection vulnerability exists in the WireGuard VPN feature of InHand Networks IR302 firmware V3.5.108, IR305 firmware V1.0.118, IR315 firmware V1.0.118, IR615 firmware V1.0.118, and earlier versions. Attackers can exploit this vulnerability to obtain ROOT privileges on remote target devices.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-38704"
    },
    {
      "rank": 4,
      "cve_id": "CVE-2026-38702",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.01243,
      "epss_percentile": 0.66828,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-77",
      "title": "A command injection vulnerability exists in the Admin Access feature of InHand Networks IR302 firmware V3.5.108, IR305 firmware V1.0.118, IR315 firmware V1.0.118, IR615 firmware V1.0.118, and earlier versions. Attackers can exploit this vulnerability to obtain ROOT privileges on remote target devices.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-38702"
    },
    {
      "rank": 5,
      "cve_id": "CVE-2026-38703",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.01243,
      "epss_percentile": 0.66828,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-77",
      "title": "A command injection vulnerability exists in the ZeroTier VPN feature of InHand Networks IR302 firmware V3.5.108, IR305 firmware V1.0.118, IR315 firmware V1.0.118, IR615 firmware V1.0.118, and earlier versions. Attackers can exploit this vulnerability to obtain ROOT privileges on remote target devices.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-38703"
    },
    {
      "rank": 6,
      "cve_id": "CVE-2026-38707",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.01243,
      "epss_percentile": 0.66828,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-77",
      "title": "A command injection vulnerability exists in the IPSec VPN feature of InHand Networks IR302 firmware V3.5.108, IR305 firmware V1.0.118, IR315 firmware V1.0.118, IR615 firmware V1.0.118, and earlier versions. Attackers can exploit this vulnerability to obtain ROOT privileges on remote target devices.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-38707"
    },
    {
      "rank": 7,
      "cve_id": "CVE-2026-45292",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.01097,
      "epss_percentile": 0.6298,
      "kev": false,
      "kev_due_at": null,
      "vendor": "open-telemetry",
      "product": "opentelemetry-java",
      "cwe": "CWE-770",
      "title": "opentelemetry-java: Unbounded Memory Allocation in W3C Baggage Propagation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45292"
    },
    {
      "rank": 8,
      "cve_id": "CVE-2026-45332",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.01072,
      "epss_percentile": 0.62239,
      "kev": false,
      "kev_due_at": null,
      "vendor": "marcantondahmen",
      "product": "automad",
      "cwe": "CWE-200",
      "title": "Automad Broken Access Control: unauthenticated exposure of administrator bcrypt password hashes and TOTP secrets via public API endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45332"
    },
    {
      "rank": 9,
      "cve_id": "CVE-2026-8809",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.008,
      "epss_percentile": 0.53716,
      "kev": false,
      "kev_due_at": null,
      "vendor": "hwk-fr",
      "product": "Advanced Custom Fields: Extended",
      "cwe": "CWE-269",
      "title": "Advanced Custom Fields: Extended <= 0.9.2.5 - Unauthenticated Privilege Escalation via Validation Bypass to '_acf_post_id' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8809"
    },
    {
      "rank": 10,
      "cve_id": "CVE-2026-4944",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00747,
      "epss_percentile": 0.52023,
      "kev": false,
      "kev_due_at": null,
      "vendor": "vllm-project",
      "product": "vllm-project/vllm",
      "cwe": "CWE-22",
      "title": "Hardcoded trust_remote_code=True in vllm-project/vllm Bypasses User Security Control",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-4944"
    },
    {
      "rank": 11,
      "cve_id": "CVE-2026-6226",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00739,
      "epss_percentile": 0.51766,
      "kev": false,
      "kev_due_at": null,
      "vendor": "shabti",
      "product": "Frontend Admin by DynamiApps",
      "cwe": "CWE-269",
      "title": "Frontend Admin by DynamiApps <= 3.29.2 - Unauthenticated Privilege Escalation via Form Configuration Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6226"
    },
    {
      "rank": 12,
      "cve_id": "CVE-2026-46840",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00725,
      "epss_percentile": 0.51255,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle REST Data Services",
      "cwe": "CWE-284",
      "title": "Vulnerability in Oracle REST Data Services (component: Backend-as-a-Service). Supported versions that are affected are 24.2.0-26.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle REST Data Services. While the vulnerability is in Oracle REST Data Services, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle REST Data Services. CVSS 3.1 Base Score 10.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46840"
    },
    {
      "rank": 13,
      "cve_id": "CVE-2026-9227",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00684,
      "epss_percentile": 0.49747,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cssigniterteam",
      "product": "GutenBee – Gutenberg Blocks",
      "cwe": "CWE-434",
      "title": "GutenBee <= 2.20.1 - Authenticated (Author+) Arbitrary File Upload via wp_check_filetype_and_ext Filter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9227"
    },
    {
      "rank": 14,
      "cve_id": "CVE-2026-46195",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00675,
      "epss_percentile": 0.49397,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-476",
      "title": "smb: client: validate dacloffset before building DACL pointers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46195"
    },
    {
      "rank": 15,
      "cve_id": "CVE-2026-8979",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00612,
      "epss_percentile": 0.46642,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mennekes",
      "product": "Amtron",
      "cwe": "CWE-287",
      "title": "Authentication Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8979"
    },
    {
      "rank": 16,
      "cve_id": "CVE-2026-44885",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00606,
      "epss_percentile": 0.46368,
      "kev": false,
      "kev_due_at": null,
      "vendor": "portainer",
      "product": "portainer",
      "cwe": "CWE-22",
      "title": "Portainer: Path traversal in backup archive extraction allows arbitrary file write",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44885"
    },
    {
      "rank": 17,
      "cve_id": "CVE-2026-10044",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.006,
      "epss_percentile": 0.46088,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Usagi-org",
      "product": "ai-goofish-monitor",
      "cwe": "CWE-36",
      "title": "ai-goofish-monitor Unauthenticated Arbitrary File Read via GET /api/prompts/",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10044"
    },
    {
      "rank": 18,
      "cve_id": "CVE-2026-46133",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00574,
      "epss_percentile": 0.44877,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-125",
      "title": "RDMA/rxe: Reject unknown opcodes before ICRC processing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46133"
    },
    {
      "rank": 19,
      "cve_id": "CVE-2026-44604",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00567,
      "epss_percentile": 0.44536,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Hardened Images",
      "cwe": "CWE-78",
      "title": "Rpm: command injection in rpmuncompress dountar() via unescaped archive top-level directory name in popen() shell command",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44604"
    },
    {
      "rank": 20,
      "cve_id": "CVE-2026-6937",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00561,
      "epss_percentile": 0.4423,
      "kev": false,
      "kev_due_at": null,
      "vendor": "croixhaug",
      "product": "Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin",
      "cwe": "CWE-862",
      "title": "Appointment Booking Calendar <= 1.6.11.8 - Missing Authorization to Unauthenticated Arbitrary Modification via Bulk Appointments REST API Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6937"
    },
    {
      "rank": 21,
      "cve_id": "CVE-2026-7797",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00554,
      "epss_percentile": 0.43842,
      "kev": false,
      "kev_due_at": null,
      "vendor": "croixhaug",
      "product": "Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin",
      "cwe": "CWE-89",
      "title": "Appointment Booking Calendar <= 1.6.11.8 - Unauthenticated SQL Injection via 'append_where_sql' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7797"
    },
    {
      "rank": 22,
      "cve_id": "CVE-2026-24444",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00535,
      "epss_percentile": 0.42886,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SDMC Technology Co., Ltd",
      "product": "NE6037",
      "cwe": "CWE-798",
      "title": "SDMC NE6037 Hardcoded Password via mgmt.php/npcmd.php",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-24444"
    },
    {
      "rank": 23,
      "cve_id": "CVE-2025-48977",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00527,
      "epss_percentile": 0.42404,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Ignite",
      "cwe": "CWE-23",
      "title": "Apache Ignite: REST HTTP arbitrary file read vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-48977"
    },
    {
      "rank": 24,
      "cve_id": "CVE-2026-46119",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00525,
      "epss_percentile": 0.42294,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-125",
      "title": "libceph: Fix slab-out-of-bounds access in auth message processing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46119"
    },
    {
      "rank": 25,
      "cve_id": "CVE-2026-9804",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00516,
      "epss_percentile": 0.41771,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Container Native Virtualization 4.17",
      "cwe": "CWE-59",
      "title": "Kubevirt: kubevirt: vmexport directory symlink escape enables exporter pod file read",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9804"
    },
    {
      "rank": 26,
      "cve_id": "CVE-2026-45261",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00515,
      "epss_percentile": 0.41667,
      "kev": false,
      "kev_due_at": null,
      "vendor": "gitbutlerapp",
      "product": "gitbutler",
      "cwe": "CWE-94",
      "title": "GitButler: Link injection via forge integration enables arbitrary script execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45261"
    },
    {
      "rank": 27,
      "cve_id": "CVE-2026-32997",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00514,
      "epss_percentile": 0.41626,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Veeam",
      "product": "Backup and Replication",
      "cwe": "CWE-36",
      "title": "A vulnerability allowing an authenticated user with the Backup Administrator role to write arbitrary files on Linux-based Veeam Backup & Replication server.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-32997"
    },
    {
      "rank": 28,
      "cve_id": "CVE-2026-46185",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00513,
      "epss_percentile": 0.41545,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-125",
      "title": "smb/client: fix out-of-bounds read in symlink_data()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46185"
    },
    {
      "rank": 29,
      "cve_id": "CVE-2026-49127",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0051,
      "epss_percentile": 0.41406,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MusicPlayerDaemon",
      "product": "MPD",
      "cwe": "CWE-193",
      "title": "Music Player Daemon < 0.24.11 Stack Buffer Overflow via pcm_unpack_24be",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49127"
    },
    {
      "rank": 30,
      "cve_id": "CVE-2026-8697",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.0051,
      "epss_percentile": 0.41367,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TP-Link Systems Inc.",
      "product": "Archer C64 v1.0",
      "cwe": "CWE-306",
      "title": "Improper Authentication Rate Limiting on TP-Link's Archer C64",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8697"
    },
    {
      "rank": 31,
      "cve_id": "CVE-2026-49238",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00505,
      "epss_percentile": 0.41076,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Canonical",
      "product": "Multipass",
      "cwe": "CWE-22",
      "title": "SFTP Server VM Escape in Canonical Multipass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49238"
    },
    {
      "rank": 32,
      "cve_id": "CVE-2026-7048",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00504,
      "epss_percentile": 0.41003,
      "kev": false,
      "kev_due_at": null,
      "vendor": "10web",
      "product": "Photo Gallery by 10Web – Mobile-Friendly Image Gallery",
      "cwe": "CWE-89",
      "title": "Photo Gallery by 10Web <= 1.8.40 - Authenticated (Contributor+) SQL Injection via 'order_by' Shortcode Attribute",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7048"
    },
    {
      "rank": 33,
      "cve_id": "CVE-2026-41184",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00504,
      "epss_percentile": 0.41004,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tigera",
      "product": "Calico",
      "cwe": "CWE-532",
      "title": "ServiceAccount token disclosure via install-cni container logs",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41184"
    },
    {
      "rank": 34,
      "cve_id": "CVE-2026-49128",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00501,
      "epss_percentile": 0.4083,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MusicPlayerDaemon",
      "product": "MPD",
      "cwe": "CWE-22",
      "title": "Music Player Daemon < 0.24.11 Path Traversal via LocalStorage URI Handling",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49128"
    },
    {
      "rank": 35,
      "cve_id": "CVE-2026-46177",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00501,
      "epss_percentile": 0.40833,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ipmi: Add limits to event and receive message requests",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46177"
    },
    {
      "rank": 36,
      "cve_id": "CVE-2026-46110",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.005,
      "epss_percentile": 0.4077,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-476",
      "title": "net: stmmac: Prevent NULL deref when RX memory exhausted",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46110"
    },
    {
      "rank": 37,
      "cve_id": "CVE-2026-46115",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00491,
      "epss_percentile": 0.40211,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "block: add pgmap check to biovec_phys_mergeable",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46115"
    },
    {
      "rank": 38,
      "cve_id": "CVE-2026-44477",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0048,
      "epss_percentile": 0.39548,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cloudnative-pg",
      "product": "cloudnative-pg",
      "cwe": "CWE-250",
      "title": "CloudNativePG: Metrics exporter allows privilege escalation to PostgreSQL superuser and OS RCE",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44477"
    },
    {
      "rank": 39,
      "cve_id": "CVE-2026-46155",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00478,
      "epss_percentile": 0.39383,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-125",
      "title": "smb/client: fix out-of-bounds read in smb2_compound_op()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46155"
    },
    {
      "rank": 40,
      "cve_id": "CVE-2026-9801",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00477,
      "epss_percentile": 0.39356,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat build of Keycloak 26.4",
      "cwe": "CWE-1284",
      "title": "Keycloak: keycloak: denial of service via malformed ldap password policy response",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9801"
    },
    {
      "rank": 41,
      "cve_id": "CVE-2026-43898",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00472,
      "epss_percentile": 0.38983,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nyariv",
      "product": "SandboxJS",
      "cwe": "CWE-94",
      "title": "SandboxJS: Sandbox escape via Function.caller leakage of internal call op",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43898"
    },
    {
      "rank": 42,
      "cve_id": "CVE-2026-41565",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00469,
      "epss_percentile": 0.3881,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MIK",
      "product": "CryptX",
      "cwe": "CWE-121",
      "title": "CryptX versions before 0.088_001 for Perl have a stack buffer overflow in four AEAD decrypt_verify helpers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41565"
    },
    {
      "rank": 43,
      "cve_id": "CVE-2026-46114",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00467,
      "epss_percentile": 0.38677,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-476",
      "title": "RDMA/rxe: Reject non-8-byte ATOMIC_WRITE payloads",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46114"
    },
    {
      "rank": 44,
      "cve_id": "CVE-2026-34311",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00461,
      "epss_percentile": 0.38313,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Hospitality OPERA 5 Property Services",
      "cwe": null,
      "title": "Vulnerability in the Oracle Hospitality OPERA 5 Property Services product of Oracle Hospitality Applications (component: Opera). Supported versions that are affected are 5.6.19.24, 5.6.22, 5.6.25.19, 5.6.27.6 and 5.6.28. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hospitality OPERA 5 Property Services. Successful attacks of this vulnerability can result in takeover of Oracle Hospitality OPERA 5 Property Services. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34311"
    },
    {
      "rank": 45,
      "cve_id": "CVE-2026-45344",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00456,
      "epss_percentile": 0.37981,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Kovah",
      "product": "LinkAce",
      "cwe": "CWE-74",
      "title": "LinkAce: Setup database password newline injection enables pre-auth RCE on uninitialized instances",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45344"
    },
    {
      "rank": 46,
      "cve_id": "CVE-2026-33590",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00452,
      "epss_percentile": 0.37679,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Portainer",
      "product": "Portainer Community Edition",
      "cwe": "CWE-276",
      "title": "Insecure default permissions in Portainer CE",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-33590"
    },
    {
      "rank": 47,
      "cve_id": "CVE-2026-9009",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00446,
      "epss_percentile": 0.37308,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CodeRevolution",
      "product": "Crawlomatic Multipage Scraper Post Generator",
      "cwe": "CWE-434",
      "title": "Crawlomatic Multipage Scraper Post Generator <= 2.7.2 - Authenticated (Author+) Remote Code Execution via 'callback_raw' Shortcode Attribute",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9009"
    },
    {
      "rank": 48,
      "cve_id": "CVE-2026-44462",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00438,
      "epss_percentile": 0.36687,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zed-industries",
      "product": "zed",
      "cwe": "CWE-184",
      "title": "Zed: Allowlist Bypass via Bash Variable Expansion Chain in Terminal Tool Permissions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44462"
    },
    {
      "rank": 49,
      "cve_id": "CVE-2026-7634",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00436,
      "epss_percentile": 0.36496,
      "kev": false,
      "kev_due_at": null,
      "vendor": "veronalabs",
      "product": "SlimStat Analytics",
      "cwe": "CWE-79",
      "title": "SlimStat Analytics <= 5.4.11 - Unauthenticated Stored Cross-Site Scripting via User-Agent Header",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7634"
    },
    {
      "rank": 50,
      "cve_id": "CVE-2026-46775",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00431,
      "epss_percentile": 0.36133,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle REST Data Services",
      "cwe": "CWE-400",
      "title": "Vulnerability in Oracle REST Data Services (component: Core). Supported versions that are affected are 24.2.0-26.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle REST Data Services. While the vulnerability is in Oracle REST Data Services, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle REST Data Services. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46775"
    },
    {
      "rank": 51,
      "cve_id": "CVE-2026-46137",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00426,
      "epss_percentile": 0.35718,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-362",
      "title": "mptcp: pm: ADD_ADDR rtx: fix potential data-race",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46137"
    },
    {
      "rank": 52,
      "cve_id": "CVE-2026-46124",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00425,
      "epss_percentile": 0.35657,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "isofs: validate block number from NFS file handle in isofs_export_iget",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46124"
    },
    {
      "rank": 53,
      "cve_id": "CVE-2026-9094",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0042,
      "epss_percentile": 0.35196,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Casdoor",
      "product": "Casdoor",
      "cwe": null,
      "title": "CVE-2026-9094",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9094"
    },
    {
      "rank": 54,
      "cve_id": "CVE-2026-7802",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00417,
      "epss_percentile": 0.34992,
      "kev": false,
      "kev_due_at": null,
      "vendor": "shabti",
      "product": "Frontend Admin by DynamiApps",
      "cwe": "CWE-862",
      "title": "Frontend Admin by DynamiApps <= 3.29.2 - Missing Authorization to Authenticated (Subscriber+) Account Takeover via 'user_id' URL Query Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7802"
    },
    {
      "rank": 55,
      "cve_id": "CVE-2026-9803",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00417,
      "epss_percentile": 0.34981,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat build of Keycloak 26.4",
      "cwe": "CWE-125",
      "title": "Keycloak: keycloak: denial of service via malformed authorization header",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9803"
    },
    {
      "rank": 56,
      "cve_id": "CVE-2026-44881",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00416,
      "epss_percentile": 0.34902,
      "kev": false,
      "kev_due_at": null,
      "vendor": "portainer",
      "product": "portainer",
      "cwe": "CWE-59",
      "title": "Portainer: Arbitrary File Read via Git Symlink Injection in Stack Auto-Update",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44881"
    },
    {
      "rank": 57,
      "cve_id": "CVE-2026-9939",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00412,
      "epss_percentile": 0.34522,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-122",
      "title": "Heap buffer overflow in WebCodecs in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9939"
    },
    {
      "rank": 58,
      "cve_id": "CVE-2026-9097",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00405,
      "epss_percentile": 0.33935,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Casdoor",
      "product": "Casdoor",
      "cwe": null,
      "title": "CVE-2026-9097",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9097"
    },
    {
      "rank": 59,
      "cve_id": "CVE-2026-32998",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00403,
      "epss_percentile": 0.33701,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Veeam",
      "product": "Service Provider Console",
      "cwe": "CWE-233",
      "title": "This vulnerability in Veeam Service Provider Console allows for remote code execution.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-32998"
    },
    {
      "rank": 60,
      "cve_id": "CVE-2026-46135",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00397,
      "epss_percentile": 0.33062,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-362",
      "title": "nvmet-tcp: fix race between ICReq handling and queue teardown",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46135"
    },
    {
      "rank": 61,
      "cve_id": "CVE-2026-48526",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00395,
      "epss_percentile": 0.32844,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jpadilla",
      "product": "pyjwt",
      "cwe": "CWE-287",
      "title": "PyJWT: Public-key JWK accepted as HMAC secret enables forged HS256 tokens when mixed families are allowed",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48526"
    },
    {
      "rank": 62,
      "cve_id": "CVE-2026-35672",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00384,
      "epss_percentile": 0.31683,
      "kev": false,
      "kev_due_at": null,
      "vendor": "thorsten",
      "product": "phpMyFAQ",
      "cwe": "CWE-1188",
      "title": "phpMyFAQ - Authentication Bypass via Empty API Token",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-35672"
    },
    {
      "rank": 63,
      "cve_id": "CVE-2026-9952",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00383,
      "epss_percentile": 0.31631,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in WebAudio in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9952"
    },
    {
      "rank": 64,
      "cve_id": "CVE-2026-32847",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00376,
      "epss_percentile": 0.30901,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HKUDS",
      "product": "DeepCode",
      "cwe": "CWE-22",
      "title": "DeepCode 1.2.0 Path Traversal via SPA Catch-All Route in main.py",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-32847"
    },
    {
      "rank": 65,
      "cve_id": "CVE-2026-7526",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00376,
      "epss_percentile": 0.30915,
      "kev": false,
      "kev_due_at": null,
      "vendor": "smub",
      "product": "PDF Embedder",
      "cwe": "CWE-200",
      "title": "PDF Embedder <= 4.9.3 - Authenticated (Contributor+) Information Exposure via Block Editor Page",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7526"
    },
    {
      "rank": 66,
      "cve_id": "CVE-2026-45288",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00375,
      "epss_percentile": 0.30751,
      "kev": false,
      "kev_due_at": null,
      "vendor": "JasperFx",
      "product": "marten",
      "cwe": "CWE-89",
      "title": "Marten has an SQL injection vulnerability in its full-text search regConfig parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45288"
    },
    {
      "rank": 67,
      "cve_id": "CVE-2026-45311",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00375,
      "epss_percentile": 0.30772,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hmbown",
      "product": "CodeWhale",
      "cwe": "CWE-94",
      "title": "CodeWhale: run_tests Tool Enables RCE via Malicious Repository Without Approval",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45311"
    },
    {
      "rank": 68,
      "cve_id": "CVE-2026-9872",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00374,
      "epss_percentile": 0.30695,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-787",
      "title": "Out of bounds write in GPU in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9872"
    },
    {
      "rank": 69,
      "cve_id": "CVE-2026-40914",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00372,
      "epss_percentile": 0.30454,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Artemis Stomp Protocol",
      "cwe": "CWE-863",
      "title": "Apache Artemis Stomp Protocol, Apache ActiveMQ Artemis Stomp Protocol: Address routing-type can be updated by STOMP protocol user without the createAddress permission",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40914"
    },
    {
      "rank": 70,
      "cve_id": "CVE-2026-48525",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0037,
      "epss_percentile": 0.30284,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jpadilla",
      "product": "pyjwt",
      "cwe": "CWE-400",
      "title": "PyJWT: Unauthenticated DoS via unbounded Base64URL decoding of unused payload segment in b64=false detached JWS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48525"
    },
    {
      "rank": 71,
      "cve_id": "CVE-2026-9828",
      "cvss_base": 2.9,
      "cvss_severity": "LOW",
      "epss_score": 0.0037,
      "epss_percentile": 0.30212,
      "kev": false,
      "kev_due_at": null,
      "vendor": "QOS.CH Sarl",
      "product": "logback",
      "cwe": "CWE-502",
      "title": "Logback deserialization whitelist bypass for java.lang and java.util",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9828"
    },
    {
      "rank": 72,
      "cve_id": "CVE-2026-45076",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00369,
      "epss_percentile": 0.30094,
      "kev": false,
      "kev_due_at": null,
      "vendor": "element-hq",
      "product": "synapse",
      "cwe": "CWE-20",
      "title": "Synapse pagination denial of service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45076"
    },
    {
      "rank": 73,
      "cve_id": "CVE-2026-9884",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00368,
      "epss_percentile": 0.30005,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Browser in Google Chrome on Mac prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9884"
    },
    {
      "rank": 74,
      "cve_id": "CVE-2026-44543",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00368,
      "epss_percentile": 0.30039,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rancher",
      "product": "local-path-provisioner",
      "cwe": "CWE-269",
      "title": "Local Path Provisioner: HelperPod Template Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44543"
    },
    {
      "rank": 75,
      "cve_id": "CVE-2026-48116",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00366,
      "epss_percentile": 0.29871,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mintplex-Labs",
      "product": "anything-llm",
      "cwe": "CWE-77",
      "title": "AnythingLLM: RCE via ripgrep --pre argument injection in filesystem-search-files agent skill",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48116"
    },
    {
      "rank": 76,
      "cve_id": "CVE-2026-5737",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00366,
      "epss_percentile": 0.29855,
      "kev": false,
      "kev_due_at": null,
      "vendor": "bensibley",
      "product": "Independent Analytics – WordPress Analytics Plugin",
      "cwe": "CWE-918",
      "title": "Independent Analytics <= 2.14.9 - Unauthenticated Server-Side Request Forgery via Tracking Route",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-5737"
    },
    {
      "rank": 77,
      "cve_id": "CVE-2026-9093",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00365,
      "epss_percentile": 0.29728,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Casdoor",
      "product": "Casdoor",
      "cwe": null,
      "title": "CVE-2026-9093",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9093"
    },
    {
      "rank": 78,
      "cve_id": "CVE-2026-44593",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00362,
      "epss_percentile": 0.29455,
      "kev": false,
      "kev_due_at": null,
      "vendor": "esm-dev",
      "product": "esm.sh",
      "cwe": "CWE-22",
      "title": "esm.sh: Legacy Route Path Traversal Can Lead to RCE",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44593"
    },
    {
      "rank": 79,
      "cve_id": "CVE-2026-30761",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00358,
      "epss_percentile": 0.29084,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-434",
      "title": "An arbitrary file upload vulnerability in the pages/admin.uploadmapimg.php component of SourceBans Material Admin v1.1.6 allows attackers to execute arbitrary code via uploading a crafted image file.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-30761"
    },
    {
      "rank": 80,
      "cve_id": "CVE-2026-9962",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00355,
      "epss_percentile": 0.2872,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in WebRTC in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9962"
    },
    {
      "rank": 81,
      "cve_id": "CVE-2026-9795",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00354,
      "epss_percentile": 0.28644,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat build of Keycloak 26.4",
      "cwe": "CWE-266",
      "title": "Keycloak: keycloak: privilege escalation via improper scope mapping enforcement",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9795"
    },
    {
      "rank": 82,
      "cve_id": "CVE-2026-46839",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00352,
      "epss_percentile": 0.2846,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle REST Data Services",
      "cwe": "CWE-284",
      "title": "Vulnerability in Oracle REST Data Services (component: Core). Supported versions that are affected are 24.2.0-26.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle REST Data Services. While the vulnerability is in Oracle REST Data Services, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle REST Data Services. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46839"
    },
    {
      "rank": 83,
      "cve_id": "CVE-2026-7651",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0035,
      "epss_percentile": 0.2818,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wpeverest",
      "product": "User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder",
      "cwe": "CWE-639",
      "title": "User Registration & Membership <= 5.1.5 - Authenticated (Subscriber+) Insecure Direct Object Reference to Arbitrary Media Deletion via 'profile-pic-url' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7651"
    },
    {
      "rank": 84,
      "cve_id": "CVE-2026-44657",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00349,
      "epss_percentile": 0.28109,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mantisbt",
      "product": "mantisbt",
      "cwe": "CWE-79",
      "title": "MantisBT: Stored XSS in File Download",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44657"
    },
    {
      "rank": 85,
      "cve_id": "CVE-2026-9798",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00348,
      "epss_percentile": 0.27982,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat build of Keycloak 26.4",
      "cwe": "CWE-305",
      "title": "Keycloak: keycloak: brute-force protection bypass in ciba flow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9798"
    },
    {
      "rank": 86,
      "cve_id": "CVE-2026-44849",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00347,
      "epss_percentile": 0.27859,
      "kev": false,
      "kev_due_at": null,
      "vendor": "portainer",
      "product": "portainer",
      "cwe": "CWE-862",
      "title": "Portainer: Endpoint security bypass via Swarm service create/update",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44849"
    },
    {
      "rank": 87,
      "cve_id": "CVE-2026-2374",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00346,
      "epss_percentile": 0.2776,
      "kev": false,
      "kev_due_at": null,
      "vendor": "robertpeake",
      "product": "Login No Captcha reCAPTCHA",
      "cwe": "CWE-79",
      "title": "Login No Captcha reCAPTCHA <= 1.8.0 - Unauthenticated Stored Cross-Site Scripting via PHP_SELF",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-2374"
    },
    {
      "rank": 88,
      "cve_id": "CVE-2026-41141",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00346,
      "epss_percentile": 0.27754,
      "kev": false,
      "kev_due_at": null,
      "vendor": "espocrm",
      "product": "espocrm",
      "cwe": "CWE-639",
      "title": "EspoCRM: IDOR in EmailTemplate Prepare Endpoint Leaks Entity Data via Email Address Lookup",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41141"
    },
    {
      "rank": 89,
      "cve_id": "CVE-2026-45017",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00336,
      "epss_percentile": 0.26612,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jg-rp",
      "product": "liquid",
      "cwe": "CWE-22",
      "title": "Python Liquid: Absolute paths escape filesystem loader search path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45017"
    },
    {
      "rank": 90,
      "cve_id": "CVE-2026-48524",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00336,
      "epss_percentile": 0.26625,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jpadilla",
      "product": "pyjwt",
      "cwe": "CWE-460",
      "title": "PyJWT: PyJWKClient unbounded JWKS endpoint requests via attacker-controlled kid values (DoS)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48524"
    },
    {
      "rank": 91,
      "cve_id": "CVE-2026-44882",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00335,
      "epss_percentile": 0.26537,
      "kev": false,
      "kev_due_at": null,
      "vendor": "portainer",
      "product": "portainer",
      "cwe": "CWE-863",
      "title": "Portainer: Kubernetes middleware continues after token validation failure, bypassing endpoint authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44882"
    },
    {
      "rank": 92,
      "cve_id": "CVE-2026-37266",
      "cvss_base": 8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00334,
      "epss_percentile": 0.26365,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-98",
      "title": "An issue in Responsive File Manager Responsive FileManager Version 9.14.0 allows a remote attacker to execute arbitrary code via the force_download.php component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-37266"
    },
    {
      "rank": 93,
      "cve_id": "CVE-2026-7552",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00333,
      "epss_percentile": 0.26339,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cyberhobo",
      "product": "Geo Mashup",
      "cwe": "CWE-862",
      "title": "Geo Mashup <= 1.13.19 - Missing Authorization to Unauthenticated Plugin Settings Disclosure via 'geo_mashup_content' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7552"
    },
    {
      "rank": 94,
      "cve_id": "CVE-2026-42399",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00332,
      "epss_percentile": 0.26248,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Elastic",
      "product": "Kibana",
      "cwe": "CWE-400",
      "title": "Uncontrolled Resource Consumption in Kibana Leading to Denial of Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42399"
    },
    {
      "rank": 95,
      "cve_id": "CVE-2026-42400",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00332,
      "epss_percentile": 0.26248,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Elastic",
      "product": "Kibana",
      "cwe": "CWE-400",
      "title": "Uncontrolled Resource Consumption in Kibana Leading to Denial of Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42400"
    },
    {
      "rank": 96,
      "cve_id": "CVE-2026-8980",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00331,
      "epss_percentile": 0.26126,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mennekes",
      "product": "Amtron",
      "cwe": "CWE-269",
      "title": "Privilege Escalation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8980"
    },
    {
      "rank": 97,
      "cve_id": "CVE-2026-9794",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00331,
      "epss_percentile": 0.26153,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat build of Keycloak 26.4",
      "cwe": "CWE-209",
      "title": "Keycloak: keycloak: information disclosure via saml ecp endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9794"
    },
    {
      "rank": 98,
      "cve_id": "CVE-2026-46819",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0033,
      "epss_percentile": 0.25981,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Internet Procurement Connector",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Internet Procurement Connector product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Internet Procurement Connector. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Internet Procurement Connector accessible data as well as unauthorized access to critical data or complete access to all Oracle Internet Procurement Connector accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46819"
    },
    {
      "rank": 99,
      "cve_id": "CVE-2026-9096",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0033,
      "epss_percentile": 0.26036,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Casdoor",
      "product": "Casdoor",
      "cwe": null,
      "title": "CVE-2026-9096",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9096"
    },
    {
      "rank": 100,
      "cve_id": "CVE-2026-42999",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00329,
      "epss_percentile": 0.25942,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenStack",
      "product": "Keystone",
      "cwe": "CWE-863",
      "title": "An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone RBAC policy enforcer in enforce_call unconditionally merges the raw JSON request body into the policy enforcement dictionary via policy_dict.update(json_input.copy()), overwriting trusted target data that was previously set from database lookups. Because flask.request.get_json is called with force=True, this works regardless of Content-Type or HTTP method. Any authenticated user can inject arbitrary policy target attributes (e.g., user_id, project_id) into the request body to bypass RBAC checks and perform unauthorized operations on resources belonging to other users or projects. This was introduced in commit 5ea59f52 (Rocky/14.0.0).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42999"
    },
    {
      "rank": 101,
      "cve_id": "CVE-2026-44848",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00328,
      "epss_percentile": 0.25799,
      "kev": false,
      "kev_due_at": null,
      "vendor": "portainer",
      "product": "portainer",
      "cwe": "CWE-862",
      "title": "Portainer: Missing authorization on Docker plugin endpoints allows host RCE",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44848"
    },
    {
      "rank": 102,
      "cve_id": "CVE-2026-46833",
      "cvss_base": 9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00328,
      "epss_percentile": 0.25833,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Database Server",
      "cwe": null,
      "title": "Vulnerability in the Net Service component of Oracle Database Server. Supported versions that are affected are 23.4.0-23.26.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TLS to compromise Net Service. While the vulnerability is in Net Service, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Net Service. CVSS 3.1 Base Score 9.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46833"
    },
    {
      "rank": 103,
      "cve_id": "CVE-2026-43000",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00328,
      "epss_percentile": 0.25732,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenStack",
      "product": "Keystone",
      "cwe": "CWE-863",
      "title": "An issue was discovered in OpenStack Keystone before 29.0.2. When combined with an application credential impersonation vulnerability, an attacker with the member role on a project can escalate to admin by chaining unrestricted application credentials with Keystone trusts. The impersonated token carries the victim's identity, which passes the trustor validation check. Keystone then validates the delegated roles against the victim's actual role assignments in the database, not the roles on the requesting token. This allows the attacker to create a trust delegating the victim's admin role to themselves. The trust persists independently, and additional trusts and application credentials can be created to maintain access. All actions are logged under the victim's identity.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43000"
    },
    {
      "rank": 104,
      "cve_id": "CVE-2026-44672",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00325,
      "epss_percentile": 0.25484,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mapfish",
      "product": "mapfish-print",
      "cwe": "CWE-94",
      "title": "mapfish-print: Remote Code Injection (RCE) in Dynamic table",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44672"
    },
    {
      "rank": 105,
      "cve_id": "CVE-2026-9910",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00325,
      "epss_percentile": 0.25505,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-125",
      "title": "Out of bounds memory access in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9910"
    },
    {
      "rank": 106,
      "cve_id": "CVE-2026-8915",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00324,
      "epss_percentile": 0.25352,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Samsung Open Source",
      "product": "Escargot",
      "cwe": "CWE-787",
      "title": "Out-of-bounds write vulnerability in Samsung Open Source Escargot allows Overflow Buffers. This issue affects Escargot: 36f5fb58366a67b713c02f6fd985e924fcc09e31.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8915"
    },
    {
      "rank": 107,
      "cve_id": "CVE-2026-35675",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00324,
      "epss_percentile": 0.2533,
      "kev": false,
      "kev_due_at": null,
      "vendor": "thorsten",
      "product": "phpMyFAQ",
      "cwe": "CWE-307",
      "title": "phpMyFAQ - Authentication Bypass via Missing Password Reset Token in /api/user/password/update",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-35675"
    },
    {
      "rank": 108,
      "cve_id": "CVE-2026-41185",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00323,
      "epss_percentile": 0.25165,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tigera",
      "product": "Calico",
      "cwe": "CWE-532",
      "title": "ServiceAccount token disclosure via Azure IPAM CNI plugin logs",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41185"
    },
    {
      "rank": 109,
      "cve_id": "CVE-2026-9091",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00322,
      "epss_percentile": 0.25092,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Casdoor",
      "product": "Casdoor",
      "cwe": null,
      "title": "CVE-2026-9091",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9091"
    },
    {
      "rank": 110,
      "cve_id": "CVE-2026-44594",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00321,
      "epss_percentile": 0.24979,
      "kev": false,
      "kev_due_at": null,
      "vendor": "esm-dev",
      "product": "esm.sh",
      "cwe": "CWE-22",
      "title": "esm.sh: Path Traversal via package.json browser field allows reading arbitrary server files",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44594"
    },
    {
      "rank": 111,
      "cve_id": "CVE-2026-6816",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00321,
      "epss_percentile": 0.24943,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Drupal",
      "product": "TFA Basic Plugins",
      "cwe": "CWE-267",
      "title": "TFA Basic Plugins - Access Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6816"
    },
    {
      "rank": 112,
      "cve_id": "CVE-2026-9938",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00319,
      "epss_percentile": 0.24793,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-94",
      "title": "Inappropriate implementation in V8 in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9938"
    },
    {
      "rank": 113,
      "cve_id": "CVE-2026-10013",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00319,
      "epss_percentile": 0.24797,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in WebCodecs in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10013"
    },
    {
      "rank": 114,
      "cve_id": "CVE-2024-47096",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00319,
      "epss_percentile": 0.24783,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Follet School Solutions",
      "product": "Destiny",
      "cwe": "CWE-79",
      "title": "Reflected Cross-Site Scripting in Follet School Solutions Destiny",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-47096"
    },
    {
      "rank": 115,
      "cve_id": "CVE-2024-47097",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00319,
      "epss_percentile": 0.24783,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Follet School Solutions",
      "product": "Destiny",
      "cwe": "CWE-79",
      "title": "Reflected Cross-Site Scripting in Follet School Solutions Destiny",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-47097"
    },
    {
      "rank": 116,
      "cve_id": "CVE-2026-45323",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00317,
      "epss_percentile": 0.24496,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jpettitt",
      "product": "meshcore-card",
      "cwe": "CWE-79",
      "title": "MeshCore Card: XSS vulnerability through meshcore node name",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45323"
    },
    {
      "rank": 117,
      "cve_id": "CVE-2026-9645",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00316,
      "epss_percentile": 0.24388,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ScadaBR",
      "product": "ScadaBR",
      "cwe": "CWE-78",
      "title": "ScadaBR Authenticated Remote Code Execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9645"
    },
    {
      "rank": 118,
      "cve_id": "CVE-2026-9092",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00316,
      "epss_percentile": 0.24417,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Casdoor",
      "product": "Casdoor",
      "cwe": null,
      "title": "CVE-2026-9092",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9092"
    },
    {
      "rank": 119,
      "cve_id": "CVE-2026-46509",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00316,
      "epss_percentile": 0.24451,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ranfdev",
      "product": "deepobj",
      "cwe": "CWE-1321",
      "title": "deepobj: Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46509"
    },
    {
      "rank": 120,
      "cve_id": "CVE-2026-44883",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00316,
      "epss_percentile": 0.24409,
      "kev": false,
      "kev_due_at": null,
      "vendor": "portainer",
      "product": "portainer",
      "cwe": "CWE-598",
      "title": "Portainer: JWT accepted in URL query leaks tokens to logs and referers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44883"
    },
    {
      "rank": 121,
      "cve_id": "CVE-2026-32999",
      "cvss_base": 9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00313,
      "epss_percentile": 0.24138,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WebPros",
      "product": "Comet Backup",
      "cwe": "CWE-94",
      "title": "Insufficient character filtering in backup agent signing module on Comet Backup server allows authenticated tenant administrator to execute an arbitrary code on behalf of a privileged user on the affected server and connected devices.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-32999"
    },
    {
      "rank": 122,
      "cve_id": "CVE-2026-9878",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00312,
      "epss_percentile": 0.2402,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Critical)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9878"
    },
    {
      "rank": 123,
      "cve_id": "CVE-2026-44796",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00312,
      "epss_percentile": 0.23976,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nautobot",
      "product": "nautobot",
      "cwe": "CWE-400",
      "title": "Nautobot: Object bulk rename UI actions vulnerable to denial of service by crafted regular expression (REDoS)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44796"
    },
    {
      "rank": 124,
      "cve_id": "CVE-2026-45044",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0031,
      "epss_percentile": 0.2381,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rustfs",
      "product": "rustfs",
      "cwe": "CWE-306",
      "title": "RustFS: Authentication bypass in /profile/cpu and /profile/memory allows unauthenticated access to profiling handlers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45044"
    },
    {
      "rank": 125,
      "cve_id": "CVE-2026-44973",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0031,
      "epss_percentile": 0.23796,
      "kev": false,
      "kev_due_at": null,
      "vendor": "go-git",
      "product": "go-billy",
      "cwe": "CWE-22",
      "title": "Billy: Path traversal vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44973"
    },
    {
      "rank": 126,
      "cve_id": "CVE-2026-47136",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0031,
      "epss_percentile": 0.23811,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rustfs",
      "product": "rustfs",
      "cwe": "CWE-200",
      "title": "RustFS: Unauthenticated RustFS console license endpoint exposes license metadata",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47136"
    },
    {
      "rank": 127,
      "cve_id": "CVE-2026-30760",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00308,
      "epss_percentile": 0.23565,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-20",
      "title": "An issue in SourceBans Material Admin before v.1.1.6 (3ecd95e) allows attackers to manipulate arbitrary user data in the web app via a crafted XAJAX call.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-30760"
    },
    {
      "rank": 128,
      "cve_id": "CVE-2026-45343",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00306,
      "epss_percentile": 0.23296,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Kovah",
      "product": "LinkAce",
      "cwe": "CWE-79",
      "title": "LinkAce - Stored XSS via Unsanitized SSO User's Name Rendered in Admin Audit Log Allows Session Hijacking",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45343"
    },
    {
      "rank": 129,
      "cve_id": "CVE-2026-9927",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00303,
      "epss_percentile": 0.22981,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9927"
    },
    {
      "rank": 130,
      "cve_id": "CVE-2026-9928",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00303,
      "epss_percentile": 0.22979,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-125",
      "title": "Out of bounds read in ANGLE in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9928"
    },
    {
      "rank": 131,
      "cve_id": "CVE-2026-9941",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00303,
      "epss_percentile": 0.22978,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9941"
    },
    {
      "rank": 132,
      "cve_id": "CVE-2026-9945",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00303,
      "epss_percentile": 0.22978,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Media in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9945"
    },
    {
      "rank": 133,
      "cve_id": "CVE-2026-9947",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00303,
      "epss_percentile": 0.22979,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in XML in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9947"
    },
    {
      "rank": 134,
      "cve_id": "CVE-2026-42998",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00303,
      "epss_percentile": 0.23025,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenStack",
      "product": "Keystone",
      "cwe": "CWE-863",
      "title": "An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone application credential authentication plugin does not verify that the user supplied in the authentication request matches the owner of the application credential. An attacker can authenticate with their own application credential ID and secret while specifying a different user's name and domain in the request body. Keystone issues a token attributed to the victim user. The impersonated token is project-scoped and carries the intersection of the application credential's roles and the victim's actual roles on the project. This enables audit evasion, reading the victim's credentials, and acting as the victim within shared projects.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42998"
    },
    {
      "rank": 135,
      "cve_id": "CVE-2026-35671",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00303,
      "epss_percentile": 0.23011,
      "kev": false,
      "kev_due_at": null,
      "vendor": "thorsten",
      "product": "phpMyFAQ",
      "cwe": "CWE-266",
      "title": "phpMyFAQ - Insecure Direct Object Reference in User Password API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-35671"
    },
    {
      "rank": 136,
      "cve_id": "CVE-2026-46125",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00302,
      "epss_percentile": 0.22907,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-416",
      "title": "wifi: mac80211: remove station if connection prep fails",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46125"
    },
    {
      "rank": 137,
      "cve_id": "CVE-2026-9873",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00301,
      "epss_percentile": 0.22738,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Network in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Critical)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9873"
    },
    {
      "rank": 138,
      "cve_id": "CVE-2026-42398",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.003,
      "epss_percentile": 0.22605,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Elastic",
      "product": "Kibana",
      "cwe": "CWE-918",
      "title": "Server-Side Request Forgery (SSRF) in Kibana Leading to Unauthorized Network Access",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42398"
    },
    {
      "rank": 139,
      "cve_id": "CVE-2026-9802",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.003,
      "epss_percentile": 0.22688,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat build of Keycloak 26.4",
      "cwe": "CWE-613",
      "title": "Keycloak: keycloak: unauthorized account access via replayed refresh tokens after cluster restart",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9802"
    },
    {
      "rank": 140,
      "cve_id": "CVE-2026-9015",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.003,
      "epss_percentile": 0.22698,
      "kev": false,
      "kev_due_at": null,
      "vendor": "equalizedigital",
      "product": "Equalize Digital Accessibility Checker – WCAG, ADA, EAA and Section 508 compliance",
      "cwe": "CWE-862",
      "title": "Equalize Digital Accessibility Checker <= 1.42.0 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Accessibility Issue Modification via edac_insert_ignore_data AJAX Action",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9015"
    },
    {
      "rank": 141,
      "cve_id": "CVE-2026-44655",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00298,
      "epss_percentile": 0.22403,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mantisbt",
      "product": "mantisbt",
      "cwe": "CWE-79",
      "title": "MantisBT: Stored XSS on Move Attachments Admin Page",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44655"
    },
    {
      "rank": 142,
      "cve_id": "CVE-2026-9095",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00298,
      "epss_percentile": 0.22473,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Casdoor",
      "product": "Casdoor",
      "cwe": "CWE-294",
      "title": "CVE-2026-9095",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9095"
    },
    {
      "rank": 143,
      "cve_id": "CVE-2026-44465",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00297,
      "epss_percentile": 0.22328,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zed-industries",
      "product": "zed",
      "cwe": "CWE-78",
      "title": "Zed: Zed IDE Arbitrary Code Execution via untrusted repository with poisoned .git/config",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44465"
    },
    {
      "rank": 144,
      "cve_id": "CVE-2026-9976",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00296,
      "epss_percentile": 0.22197,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-94",
      "title": "Inappropriate implementation in USB in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9976"
    },
    {
      "rank": 145,
      "cve_id": "CVE-2026-9995",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00296,
      "epss_percentile": 0.22199,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in WebXR in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9995"
    },
    {
      "rank": 146,
      "cve_id": "CVE-2026-45364",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00295,
      "epss_percentile": 0.22084,
      "kev": false,
      "kev_due_at": null,
      "vendor": "better-auth",
      "product": "better-auth",
      "cwe": "CWE-307",
      "title": "Better Auth: Rate limiter keys IPv6 addresses individually and is bypassable via prefix rotation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45364"
    },
    {
      "rank": 147,
      "cve_id": "CVE-2026-49299",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00295,
      "epss_percentile": 0.22099,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenStack",
      "product": "Neutron",
      "cwe": "CWE-863",
      "title": "In OpenStack Neutron before 28.0.1, the tagging controller enforces plural policy action names on single-tag write operations while the defined policy rules use singular names. The mismatched names evaluate as allowed under the default policy, permitting a project reader to create and update tags on same-project resources. Deployments running Neutron 26.0.0 or later are affected.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49299"
    },
    {
      "rank": 148,
      "cve_id": "CVE-2026-7052",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00292,
      "epss_percentile": 0.21832,
      "kev": false,
      "kev_due_at": null,
      "vendor": "htplugins",
      "product": "HT Contact Form – Drag & Drop Form Builder for WordPress",
      "cwe": "CWE-79",
      "title": "HT Contact Form <= 2.8.2 - Unauthenticated Stored Cross-Site Scripting via File Upload Field",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7052"
    },
    {
      "rank": 149,
      "cve_id": "CVE-2026-41160",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00292,
      "epss_percentile": 0.21807,
      "kev": false,
      "kev_due_at": null,
      "vendor": "espocrm",
      "product": "espocrm",
      "cwe": "CWE-284",
      "title": "EspoCRM: Broken Access Control / IDOR in Note Pinning API allows unauthorized modification of notes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41160"
    },
    {
      "rank": 150,
      "cve_id": "CVE-2026-9879",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00291,
      "epss_percentile": 0.21666,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-787",
      "title": "Out of bounds write in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9879"
    },
    {
      "rank": 151,
      "cve_id": "CVE-2026-9883",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00291,
      "epss_percentile": 0.21664,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Base in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9883"
    },
    {
      "rank": 152,
      "cve_id": "CVE-2026-9896",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00291,
      "epss_percentile": 0.21664,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-787",
      "title": "Out of bounds write in V8 in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9896"
    },
    {
      "rank": 153,
      "cve_id": "CVE-2026-9897",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00291,
      "epss_percentile": 0.21664,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in DOM in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9897"
    },
    {
      "rank": 154,
      "cve_id": "CVE-2026-9969",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00291,
      "epss_percentile": 0.21665,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9969"
    },
    {
      "rank": 155,
      "cve_id": "CVE-2026-6427",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00291,
      "epss_percentile": 0.21679,
      "kev": false,
      "kev_due_at": null,
      "vendor": "a3rev",
      "product": "a3 Lazy Load",
      "cwe": "CWE-79",
      "title": "a3 Lazy Load <= 2.7.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via Video Element",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6427"
    },
    {
      "rank": 156,
      "cve_id": "CVE-2026-37579",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.0029,
      "epss_percentile": 0.21603,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-502",
      "title": "An issue in SMSGate sms-core<=2.1.13.6 allows a remote attacker to execute arbitrary code via the Cmpp7FDeliverRequestMessageCodec.java component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-37579"
    },
    {
      "rank": 157,
      "cve_id": "CVE-2026-46822",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00283,
      "epss_percentile": 0.20922,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle iAssets",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle iAssets product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle iAssets. While the vulnerability is in Oracle iAssets, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle iAssets. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46822"
    },
    {
      "rank": 158,
      "cve_id": "CVE-2026-46826",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00283,
      "epss_percentile": 0.20922,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Payroll",
      "cwe": "CWE-306",
      "title": "Vulnerability in the Oracle Payroll product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Payroll. Successful attacks of this vulnerability can result in takeover of Oracle Payroll. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46826"
    },
    {
      "rank": 159,
      "cve_id": "CVE-2026-32995",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00283,
      "epss_percentile": 0.20902,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Rocket.Chat",
      "product": "Rocket.Chat",
      "cwe": "CWE-284",
      "title": "The Rocket.Chat DDP method autoTranslate.translateMessage in versions <8.5.0, <8.4.2, <8.3.4, <8.2.4, <8.1.5, <8.0.5, <7.13.8, and <7.10.12 accepts a client-supplied IMessage object and passes it directly to translateMessage() without checking Meteor.userId() or verifying room membership. Any authenticated DDP user can read the content of any message by ID from any room (private channels, DMs, E2EE rooms) by calling this method.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-32995"
    },
    {
      "rank": 160,
      "cve_id": "CVE-2026-46198",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00281,
      "epss_percentile": 0.2071,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-190",
      "title": "batman-adv: fix integer overflow on buff_pos",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46198"
    },
    {
      "rank": 161,
      "cve_id": "CVE-2026-49129",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00281,
      "epss_percentile": 0.20647,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MusicPlayerDaemon",
      "product": "MPD",
      "cwe": "CWE-918",
      "title": "Music Player Daemon < 0.24.11 SSRF via CurlInputPlugin",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49129"
    },
    {
      "rank": 162,
      "cve_id": "CVE-2026-47759",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00281,
      "epss_percentile": 0.20699,
      "kev": false,
      "kev_due_at": null,
      "vendor": "tinymce",
      "product": "tinymce",
      "cwe": "CWE-79",
      "title": "TinyMCE Cross-Site Scripting (XSS) vulnerability using through data-mce- prefixed src, href, style attributes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47759"
    },
    {
      "rank": 163,
      "cve_id": "CVE-2026-47762",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00281,
      "epss_percentile": 0.20699,
      "kev": false,
      "kev_due_at": null,
      "vendor": "tinymce",
      "product": "tinymce",
      "cwe": "CWE-79",
      "title": "TinyMCE Cross-Site Scripting (XSS) vulnerability through `mce:protected` comments",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47762"
    },
    {
      "rank": 164,
      "cve_id": "CVE-2026-41897",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00281,
      "epss_percentile": 0.20683,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mantisbt",
      "product": "mantisbt",
      "cwe": "CWE-79",
      "title": "MantisBT: Reflected XSS in Rendering Dynamic Custom Textarea Field",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41897"
    },
    {
      "rank": 165,
      "cve_id": "CVE-2026-9957",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0028,
      "epss_percentile": 0.20508,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in PDF in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted PDF file. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9957"
    },
    {
      "rank": 166,
      "cve_id": "CVE-2026-9968",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0028,
      "epss_percentile": 0.20598,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-472",
      "title": "Integer overflow in V8 in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9968"
    },
    {
      "rank": 167,
      "cve_id": "CVE-2026-9973",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0028,
      "epss_percentile": 0.20603,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-787",
      "title": "Out of bounds write in V8 in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9973"
    },
    {
      "rank": 168,
      "cve_id": "CVE-2026-9963",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00278,
      "epss_percentile": 0.20289,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-457",
      "title": "Uninitialized Use in iOS in Google Chrome on iOS prior to 148.0.7778.216 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9963"
    },
    {
      "rank": 169,
      "cve_id": "CVE-2026-46138",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00277,
      "epss_percentile": 0.20182,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-125",
      "title": "Bluetooth: hci_event: Fix OOB read and infinite loop in hci_le_create_big_complete_evt",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46138"
    },
    {
      "rank": 170,
      "cve_id": "CVE-2026-44798",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00277,
      "epss_percentile": 0.20218,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nautobot",
      "product": "nautobot",
      "cwe": "CWE-471",
      "title": "Nautobot: GitRepository.current_head field should not be writable through REST API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44798"
    },
    {
      "rank": 171,
      "cve_id": "CVE-2026-33464",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00275,
      "epss_percentile": 0.19987,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Elastic",
      "product": "Kibana",
      "cwe": "CWE-400",
      "title": "Uncontrolled Resource Consumption in Kibana Leading to Denial of Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-33464"
    },
    {
      "rank": 172,
      "cve_id": "CVE-2026-46212",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00274,
      "epss_percentile": 0.19824,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-416",
      "title": "batman-adv: bla: prevent use-after-free when deleting claims",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46212"
    },
    {
      "rank": 173,
      "cve_id": "CVE-2026-46834",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00274,
      "epss_percentile": 0.19839,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Database Server",
      "cwe": "CWE-400",
      "title": "Vulnerability in the Net Service component of Oracle Database Server. Supported versions that are affected are 23.4.0-23.26.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via TLS to compromise Net Service. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Net Service. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46834"
    },
    {
      "rank": 174,
      "cve_id": "CVE-2026-46835",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00274,
      "epss_percentile": 0.19838,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Database Server",
      "cwe": "CWE-400",
      "title": "Vulnerability in the Net Service component of Oracle Database Server. Supported versions that are affected are 23.4.0-23.26.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via TLS to compromise Net Service. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Net Service. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46835"
    },
    {
      "rank": 175,
      "cve_id": "CVE-2026-46829",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00273,
      "epss_percentile": 0.19814,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle REST Data Services",
      "cwe": "CWE-400",
      "title": "Vulnerability in Oracle REST Data Services (component: Mongoapi). Supported versions that are affected are 24.2.0-26.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle REST Data Services. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle REST Data Services. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46829"
    },
    {
      "rank": 176,
      "cve_id": "CVE-2026-9917",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0027,
      "epss_percentile": 0.19264,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-457",
      "title": "Uninitialized Use in WebGL in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9917"
    },
    {
      "rank": 177,
      "cve_id": "CVE-2026-49094",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0027,
      "epss_percentile": 0.19231,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Elastic",
      "product": "Kibana",
      "cwe": "CWE-400",
      "title": "Uncontrolled Resource Consumption in Kibana Leading to Denial of Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49094"
    },
    {
      "rank": 178,
      "cve_id": "CVE-2026-45039",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00268,
      "epss_percentile": 0.19083,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rustfs",
      "product": "rustfs",
      "cwe": "CWE-798",
      "title": "RustFS: Internode RPC HMAC secret falls back to public default credential, enabling peer impersonation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45039"
    },
    {
      "rank": 179,
      "cve_id": "CVE-2026-46837",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00268,
      "epss_percentile": 0.19059,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Flow Manufacturing",
      "cwe": "CWE-269",
      "title": "Vulnerability in the Oracle Flow Manufacturing product of Oracle E-Business Suite (component: Security). Supported versions that are affected are 12.2.9-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via SQL to compromise Oracle Flow Manufacturing. Successful attacks of this vulnerability can result in takeover of Oracle Flow Manufacturing. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46837"
    },
    {
      "rank": 180,
      "cve_id": "CVE-2026-9792",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00268,
      "epss_percentile": 0.1903,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat build of Keycloak 26.4",
      "cwe": "CWE-280",
      "title": "Keycloak: keycloak: security restriction bypass allows unauthorized ropc token acquisition",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9792"
    },
    {
      "rank": 181,
      "cve_id": "CVE-2026-9893",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00267,
      "epss_percentile": 0.18997,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Skia in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9893"
    },
    {
      "rank": 182,
      "cve_id": "CVE-2026-35277",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00267,
      "epss_percentile": 0.18953,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle REST Data Services",
      "cwe": "CWE-400",
      "title": "Vulnerability in Oracle REST Data Services (component: Core). Supported versions that are affected are 24.2.0-26.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle REST Data Services. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle REST Data Services accessible data as well as unauthorized access to critical data or complete access to all Oracle REST Data Services accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-35277"
    },
    {
      "rank": 183,
      "cve_id": "CVE-2026-46824",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00264,
      "epss_percentile": 0.18446,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Universal Work Queue",
      "cwe": "CWE-269",
      "title": "Vulnerability in the Oracle Universal Work Queue product of Oracle E-Business Suite (component: Work Provider Site Level Administration). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Universal Work Queue. While the vulnerability is in Oracle Universal Work Queue, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Universal Work Queue. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46824"
    },
    {
      "rank": 184,
      "cve_id": "CVE-2026-47761",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00264,
      "epss_percentile": 0.18429,
      "kev": false,
      "kev_due_at": null,
      "vendor": "tinymce",
      "product": "tinymce",
      "cwe": "CWE-79",
      "title": "TinyMCE Cross-Site Scripting (XSS) vulnerability using media plugin `data-mce-object` injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47761"
    },
    {
      "rank": 185,
      "cve_id": "CVE-2026-43979",
      "cvss_base": 5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00263,
      "epss_percentile": 0.18332,
      "kev": false,
      "kev_due_at": null,
      "vendor": "LearningCircuit",
      "product": "local-deep-research",
      "cwe": "CWE-79",
      "title": "Local Deep Research: HTML Injection via Unescaped User Input in PDF Export (`pdf_service.py:_markdown_to_html`)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43979"
    },
    {
      "rank": 186,
      "cve_id": "CVE-2026-46238",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00262,
      "epss_percentile": 0.18179,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "batman-adv: stop caching unowned originator pointers in BAT IV",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46238"
    },
    {
      "rank": 187,
      "cve_id": "CVE-2026-49095",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00262,
      "epss_percentile": 0.18126,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Elastic",
      "product": "Kibana",
      "cwe": "CWE-20",
      "title": "Improper Input Validation in Kibana Fleet Leading to Privilege Escalation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49095"
    },
    {
      "rank": 188,
      "cve_id": "CVE-2026-46821",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00261,
      "epss_percentile": 0.18062,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Financials Common Modules",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Financials Common Modules product of Oracle E-Business Suite (component: Common Components). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Financials Common Modules. While the vulnerability is in Oracle Financials Common Modules, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Financials Common Modules accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46821"
    },
    {
      "rank": 189,
      "cve_id": "CVE-2026-10005",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00261,
      "epss_percentile": 0.17994,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in WebAppInstalls in Google Chrome on Mac prior to 148.0.7778.216 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10005"
    },
    {
      "rank": 190,
      "cve_id": "CVE-2026-46818",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00261,
      "epss_percentile": 0.17977,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Payments",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Payments. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Payments accessible data as well as unauthorized access to critical data or complete access to all Oracle Payments accessible data. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46818"
    },
    {
      "rank": 191,
      "cve_id": "CVE-2026-45374",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0026,
      "epss_percentile": 0.17902,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hmbown",
      "product": "CodeWhale",
      "cwe": "CWE-94",
      "title": "CodeWhale: task_create Insecure Defaults Enable RCE via Prompt Injection in Project Files",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45374"
    },
    {
      "rank": 192,
      "cve_id": "CVE-2026-42071",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.0026,
      "epss_percentile": 0.17943,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mantisbt",
      "product": "mantisbt",
      "cwe": "CWE-862",
      "title": "MantisBT: Private Bugnote Attachment Content Leak via REST API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42071"
    },
    {
      "rank": 193,
      "cve_id": "CVE-2026-49130",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0026,
      "epss_percentile": 0.1786,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MusicPlayerDaemon",
      "product": "MPD",
      "cwe": "CWE-93",
      "title": "Music Player Daemon < 0.24.11 CRLF Injection via XspfPlaylistPlugin.cxx",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49130"
    },
    {
      "rank": 194,
      "cve_id": "CVE-2026-47676",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0026,
      "epss_percentile": 0.17851,
      "kev": false,
      "kev_due_at": null,
      "vendor": "honojs",
      "product": "hono",
      "cwe": "CWE-444",
      "title": "Hono: app.mount() strips mount prefix using undecoded path, causing incorrect routing for percent-encoded paths",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47676"
    },
    {
      "rank": 195,
      "cve_id": "CVE-2026-9940",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00259,
      "epss_percentile": 0.17732,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-122",
      "title": "Heap buffer overflow in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9940"
    },
    {
      "rank": 196,
      "cve_id": "CVE-2026-46232",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00258,
      "epss_percentile": 0.17646,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "HID: playstation: Clamp num_touch_reports",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46232"
    },
    {
      "rank": 197,
      "cve_id": "CVE-2026-9806",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00258,
      "epss_percentile": 0.17646,
      "kev": false,
      "kev_due_at": null,
      "vendor": "misp",
      "product": "cti-transmute",
      "cwe": "CWE-79",
      "title": "Stored Cross-Site Scripting (XSS) in CTI Transmute Notification Panel via Malicious Convert Names",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9806"
    },
    {
      "rank": 198,
      "cve_id": "CVE-2026-42070",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00258,
      "epss_percentile": 0.17726,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mantisbt",
      "product": "mantisbt",
      "cwe": "CWE-863",
      "title": "MantisBT: Authorization Bypass in Bugnote Editing via Issue Update API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42070"
    },
    {
      "rank": 199,
      "cve_id": "CVE-2026-46843",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00258,
      "epss_percentile": 0.17707,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle REST Data Services",
      "cwe": "CWE-400",
      "title": "Vulnerability in Oracle REST Data Services (component: Core). Supported versions that are affected are 24.2.0-26.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle REST Data Services. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle REST Data Services. CVSS 3.1 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46843"
    },
    {
      "rank": 200,
      "cve_id": "CVE-2026-44461",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00257,
      "epss_percentile": 0.17552,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zed-industries",
      "product": "zed",
      "cwe": "CWE-78",
      "title": "Zed: Remote Command Injection via Unquoted Environment Variable Keys (SSH / WSL Remote)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44461"
    },
    {
      "rank": 201,
      "cve_id": "CVE-2026-5343",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00257,
      "epss_percentile": 0.17519,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Drupal",
      "product": "SAML SSO - Service Provider",
      "cwe": "CWE-754",
      "title": "SAML SSO - Service Provider - Critical - Authentication bypass - SA-CONTRIB-2026-031",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-5343"
    },
    {
      "rank": 202,
      "cve_id": "CVE-2026-44884",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00257,
      "epss_percentile": 0.17589,
      "kev": false,
      "kev_due_at": null,
      "vendor": "portainer",
      "product": "portainer",
      "cwe": "CWE-862",
      "title": "Portainer: Missing authorization on custom template file endpoint exposes template content",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44884"
    },
    {
      "rank": 203,
      "cve_id": "CVE-2026-9983",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00255,
      "epss_percentile": 0.17268,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-843",
      "title": "Type Confusion in Skia in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9983"
    },
    {
      "rank": 204,
      "cve_id": "CVE-2026-9901",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00255,
      "epss_percentile": 0.17247,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9901"
    },
    {
      "rank": 205,
      "cve_id": "CVE-2026-9909",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00255,
      "epss_percentile": 0.17247,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-472",
      "title": "Integer overflow in Skia in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9909"
    },
    {
      "rank": 206,
      "cve_id": "CVE-2026-9922",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00255,
      "epss_percentile": 0.17248,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in GPU in Google Chrome on Mac prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9922"
    },
    {
      "rank": 207,
      "cve_id": "CVE-2026-9934",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00255,
      "epss_percentile": 0.17247,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Aura in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9934"
    },
    {
      "rank": 208,
      "cve_id": "CVE-2026-9956",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00255,
      "epss_percentile": 0.17248,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in iOS in Google Chrome on iOS prior to 148.0.7778.216 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9956"
    },
    {
      "rank": 209,
      "cve_id": "CVE-2026-9923",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00253,
      "epss_percentile": 0.1701,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Skia in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9923"
    },
    {
      "rank": 210,
      "cve_id": "CVE-2026-10007",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00252,
      "epss_percentile": 0.16953,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in SVG in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10007"
    },
    {
      "rank": 211,
      "cve_id": "CVE-2026-10015",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00252,
      "epss_percentile": 0.16953,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-472",
      "title": "Integer overflow in WTF in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10015"
    },
    {
      "rank": 212,
      "cve_id": "CVE-2026-10016",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00252,
      "epss_percentile": 0.16953,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in DOM in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10016"
    },
    {
      "rank": 213,
      "cve_id": "CVE-2026-46827",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0025,
      "epss_percentile": 0.16619,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Payroll",
      "cwe": "CWE-269",
      "title": "Vulnerability in the Oracle Payroll product of Oracle E-Business Suite (component: Self Service Manager). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Payroll. Successful attacks of this vulnerability can result in takeover of Oracle Payroll. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46827"
    },
    {
      "rank": 214,
      "cve_id": "CVE-2026-7621",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0025,
      "epss_percentile": 0.16686,
      "kev": false,
      "kev_due_at": null,
      "vendor": "smtp2go",
      "product": "SMTP2GO for WordPress – Email Made Easy",
      "cwe": "CWE-862",
      "title": "SMTP2GO for WordPress <= 1.16.0 - Missing Authorization to Authenticated (Subscriber+) Log Read/Truncate",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7621"
    },
    {
      "rank": 215,
      "cve_id": "CVE-2026-44394",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00249,
      "epss_percentile": 0.16557,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenStack",
      "product": "Keystone",
      "cwe": "CWE-863",
      "title": "An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone federated token rescoping mechanism does not propagate the original token's expiry to the newly issued token. When a federated user rescopes a token via POST /v3/auth/tokens, the handle_scoped_token() function in the mapped authentication plugin returns response data without an expires_at value. The token provider falls back to issuing a token with a fresh default TTL. By rescoping repeatedly before each token expires, a user can maintain access indefinitely, bypassing operator-configured token lifetime policies. This is a variant of CVE-2012-3426. Only deployments using federated identity (SAML2, OpenID Connect) are affected.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44394"
    },
    {
      "rank": 216,
      "cve_id": "CVE-2026-6455",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00248,
      "epss_percentile": 0.16366,
      "kev": false,
      "kev_due_at": null,
      "vendor": "yudiz",
      "product": "WP Contact Form 7 DB Handler",
      "cwe": "CWE-352",
      "title": "WP Contact Form 7 DB Handler <= 3.0 - Cross-Site Request Forgery to Arbitrary File Deletion via 'contact_form' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6455"
    },
    {
      "rank": 217,
      "cve_id": "CVE-2026-9912",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00247,
      "epss_percentile": 0.16347,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-200",
      "title": "Inappropriate implementation in GPU in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9912"
    },
    {
      "rank": 218,
      "cve_id": "CVE-2026-9953",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00247,
      "epss_percentile": 0.16347,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-125",
      "title": "Out of bounds read in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9953"
    },
    {
      "rank": 219,
      "cve_id": "CVE-2026-46526",
      "cvss_base": 5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00247,
      "epss_percentile": 0.16324,
      "kev": false,
      "kev_due_at": null,
      "vendor": "LearningCircuit",
      "product": "local-deep-research",
      "cwe": "CWE-918",
      "title": "Local Deep Research: SSRF bypass in `safe_get`",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46526"
    },
    {
      "rank": 220,
      "cve_id": "CVE-2026-9037",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00246,
      "epss_percentile": 0.16126,
      "kev": false,
      "kev_due_at": null,
      "vendor": "XCharge",
      "product": "C6",
      "cwe": "CWE-494",
      "title": "Download of code without integrity check in XCharge C6",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9037"
    },
    {
      "rank": 221,
      "cve_id": "CVE-2026-9915",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00246,
      "epss_percentile": 0.16099,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-122",
      "title": "Heap buffer overflow in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9915"
    },
    {
      "rank": 222,
      "cve_id": "CVE-2026-9924",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00246,
      "epss_percentile": 0.161,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-122",
      "title": "Heap buffer overflow in ANGLE in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9924"
    },
    {
      "rank": 223,
      "cve_id": "CVE-2026-9926",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00246,
      "epss_percentile": 0.161,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-122",
      "title": "Heap buffer overflow in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9926"
    },
    {
      "rank": 224,
      "cve_id": "CVE-2026-9891",
      "cvss_base": 9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00245,
      "epss_percentile": 0.16073,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Extensions in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted Chrome Extension. (Chromium security severity: Critical)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9891"
    },
    {
      "rank": 225,
      "cve_id": "CVE-2026-47674",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00244,
      "epss_percentile": 0.15896,
      "kev": false,
      "kev_due_at": null,
      "vendor": "honojs",
      "product": "hono",
      "cwe": "CWE-185",
      "title": "Hono: IP Restriction bypasses static deny rules for non-canonical IPv6",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47674"
    },
    {
      "rank": 226,
      "cve_id": "CVE-2026-9875",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00243,
      "epss_percentile": 0.15742,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-125",
      "title": "Out of bounds read in WebGL in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9875"
    },
    {
      "rank": 227,
      "cve_id": "CVE-2026-9876",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00243,
      "epss_percentile": 0.15741,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in WebGL in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9876"
    },
    {
      "rank": 228,
      "cve_id": "CVE-2026-9886",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00243,
      "epss_percentile": 0.15741,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Base in Google Chrome on Mac prior to 148.0.7778.216 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9886"
    },
    {
      "rank": 229,
      "cve_id": "CVE-2026-9918",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00243,
      "epss_percentile": 0.15832,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-269",
      "title": "Inappropriate implementation in Tint in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9918"
    },
    {
      "rank": 230,
      "cve_id": "CVE-2026-9967",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00243,
      "epss_percentile": 0.15741,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-787",
      "title": "Out of bounds write in GPU in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9967"
    },
    {
      "rank": 231,
      "cve_id": "CVE-2026-9961",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00243,
      "epss_percentile": 0.15742,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in SurfaceCapture in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9961"
    },
    {
      "rank": 232,
      "cve_id": "CVE-2026-9965",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00243,
      "epss_percentile": 0.1574,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-787",
      "title": "Out of bounds write in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9965"
    },
    {
      "rank": 233,
      "cve_id": "CVE-2026-3173",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00243,
      "epss_percentile": 0.15813,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mr2p",
      "product": "Meta Field Block – Display custom fields in the Block Editor without coding",
      "cwe": "CWE-639",
      "title": "Meta Field Block <= 1.5.1 - Insecure Direct Object Reference to Authenticated (Contributor+) Arbitrary User Meta Exposure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-3173"
    },
    {
      "rank": 234,
      "cve_id": "CVE-2026-8689",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00242,
      "epss_percentile": 0.15699,
      "kev": false,
      "kev_due_at": null,
      "vendor": "themeisle",
      "product": "Visualizer: Tables and Charts Manager for WordPress",
      "cwe": "CWE-862",
      "title": "Visualizer: Tables and Charts Manager for WordPress <= 3.11.14 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Chart Creation and Modification via renderChartPages() and uploadData() Functions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8689"
    },
    {
      "rank": 235,
      "cve_id": "CVE-2026-35676",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00241,
      "epss_percentile": 0.1559,
      "kev": false,
      "kev_due_at": null,
      "vendor": "thorsten",
      "product": "phpMyFAQ",
      "cwe": "CWE-640",
      "title": "phpMyFAQ - Unauthenticated Password Reset via User Password Update Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-35676"
    },
    {
      "rank": 236,
      "cve_id": "CVE-2026-45041",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00239,
      "epss_percentile": 0.15307,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rustfs",
      "product": "rustfs",
      "cwe": "CWE-321",
      "title": "RustFS: Hard-coded RSA private key in license verifier permits arbitrary license forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45041"
    },
    {
      "rank": 237,
      "cve_id": "CVE-2026-45373",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00239,
      "epss_percentile": 0.15218,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hmbown",
      "product": "CodeWhale",
      "cwe": "CWE-918",
      "title": "CodeWhale: SSRF‌ IPV6 bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45373"
    },
    {
      "rank": 238,
      "cve_id": "CVE-2026-9908",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00238,
      "epss_percentile": 0.1506,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-125",
      "title": "Out of bounds read in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9908"
    },
    {
      "rank": 239,
      "cve_id": "CVE-2026-33463",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00238,
      "epss_percentile": 0.15053,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Elastic",
      "product": "Kibana",
      "cwe": "CWE-672",
      "title": "Operation on a Resource after Expiration or Termination in Kibana Leading to Unauthorized File Access",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-33463"
    },
    {
      "rank": 240,
      "cve_id": "CVE-2026-9921",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00238,
      "epss_percentile": 0.15078,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-457",
      "title": "Uninitialized Use in WebGL in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker to leak cross-origin information via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9921"
    },
    {
      "rank": 241,
      "cve_id": "CVE-2026-9935",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00238,
      "epss_percentile": 0.15078,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-457",
      "title": "Uninitialized Use in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9935"
    },
    {
      "rank": 242,
      "cve_id": "CVE-2026-9914",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00237,
      "epss_percentile": 0.15028,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9914"
    },
    {
      "rank": 243,
      "cve_id": "CVE-2026-33462",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00236,
      "epss_percentile": 0.14816,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Elastic",
      "product": "Kibana",
      "cwe": "CWE-22",
      "title": "Path Traversal in Kibana Leading to Unauthorized Deletion of User Accounts",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-33462"
    },
    {
      "rank": 244,
      "cve_id": "CVE-2026-44797",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00235,
      "epss_percentile": 0.14754,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nautobot",
      "product": "nautobot",
      "cwe": "CWE-918",
      "title": "Nautobot: Webhook definitions could be used for server-side request forgery (SSRF)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44797"
    },
    {
      "rank": 245,
      "cve_id": "CVE-2026-9960",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00235,
      "epss_percentile": 0.14729,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-472",
      "title": "Integer overflow in PDFium in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to execute arbitrary code inside a sandbox via a crafted font file. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9960"
    },
    {
      "rank": 246,
      "cve_id": "CVE-2026-9874",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00234,
      "epss_percentile": 0.14598,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Dawn in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9874"
    },
    {
      "rank": 247,
      "cve_id": "CVE-2026-45058",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00234,
      "epss_percentile": 0.14528,
      "kev": false,
      "kev_due_at": null,
      "vendor": "electerm",
      "product": "electerm",
      "cwe": "CWE-94",
      "title": "electerm: Import unsafe bookmark data could lead to unsafe operation when click local type bookmark",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45058"
    },
    {
      "rank": 248,
      "cve_id": "CVE-2026-9978",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00234,
      "epss_percentile": 0.14537,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Glic in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9978"
    },
    {
      "rank": 249,
      "cve_id": "CVE-2026-9984",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00234,
      "epss_percentile": 0.14536,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in UI in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9984"
    },
    {
      "rank": 250,
      "cve_id": "CVE-2026-9992",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00234,
      "epss_percentile": 0.14536,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Network in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9992"
    },
    {
      "rank": 251,
      "cve_id": "CVE-2026-10021",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00234,
      "epss_percentile": 0.14537,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in USB in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10021"
    },
    {
      "rank": 252,
      "cve_id": "CVE-2026-45306",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00234,
      "epss_percentile": 0.14619,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pyload",
      "product": "pyload",
      "cwe": "CWE-706",
      "title": "pyLoad: Incomplete Fix for CVE-2026-33509 -storage_folder Bypass via Session Directory",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45306"
    },
    {
      "rank": 253,
      "cve_id": "CVE-2026-9913",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00234,
      "epss_percentile": 0.1461,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-125",
      "title": "Inappropriate implementation in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9913"
    },
    {
      "rank": 254,
      "cve_id": "CVE-2026-9964",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00233,
      "epss_percentile": 0.14409,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Bluetooth in Google Chrome on Mac prior to 148.0.7778.216 allowed an attacker who convinced a user to install a malicious extension to execute arbitrary code via a crafted Chrome Extension. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9964"
    },
    {
      "rank": 255,
      "cve_id": "CVE-2026-44466",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00232,
      "epss_percentile": 0.14279,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zed-industries",
      "product": "zed",
      "cwe": "CWE-78",
      "title": "Zed: Allowlist Bypass via Bash Arithmetic Expansion in Terminal Tool Permissions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44466"
    },
    {
      "rank": 256,
      "cve_id": "CVE-2026-44463",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00232,
      "epss_percentile": 0.14308,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zed-industries",
      "product": "zed",
      "cwe": "CWE-78",
      "title": "Zed: Allowlist Bypass via Environment Variable Injection in Terminal Tool Permissions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44463"
    },
    {
      "rank": 257,
      "cve_id": "CVE-2026-9813",
      "cvss_base": 6.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00232,
      "epss_percentile": 0.14328,
      "kev": false,
      "kev_due_at": null,
      "vendor": "flowintel",
      "product": "flowintel",
      "cwe": "CWE-918",
      "title": "FlowIntel external reference URL probe allows server-side request forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9813"
    },
    {
      "rank": 258,
      "cve_id": "CVE-2026-8682",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00232,
      "epss_percentile": 0.14354,
      "kev": false,
      "kev_due_at": null,
      "vendor": "hasanazizul",
      "product": "3D Viewer – 3D Model Viewer – Augmented Reality – Virtual Try On",
      "cwe": "CWE-862",
      "title": "3D Viewer <= 2.0.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Plugin Settings Modification via settings REST endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8682"
    },
    {
      "rank": 259,
      "cve_id": "CVE-2026-45296",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00231,
      "epss_percentile": 0.14167,
      "kev": false,
      "kev_due_at": null,
      "vendor": "openreplay",
      "product": "openreplay",
      "cwe": "CWE-284",
      "title": "OpenReplay: Cross-tenant information disclosure in app_apikey projectKey routes via missing tenant binding",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45296"
    },
    {
      "rank": 260,
      "cve_id": "CVE-2026-9098",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0023,
      "epss_percentile": 0.14126,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Casdoor",
      "product": "Casdoor",
      "cwe": null,
      "title": "CVE-2026-9098",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9098"
    },
    {
      "rank": 261,
      "cve_id": "CVE-2026-9038",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.0023,
      "epss_percentile": 0.14104,
      "kev": false,
      "kev_due_at": null,
      "vendor": "XCharge",
      "product": "C6",
      "cwe": "CWE-121",
      "title": "Stack-based buffer overflow in XCharge C6",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9038"
    },
    {
      "rank": 262,
      "cve_id": "CVE-2026-10006",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0023,
      "epss_percentile": 0.14137,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-362",
      "title": "Race in WebAudio in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10006"
    },
    {
      "rank": 263,
      "cve_id": "CVE-2026-9880",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00228,
      "epss_percentile": 0.13814,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in WebGL in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9880"
    },
    {
      "rank": 264,
      "cve_id": "CVE-2026-9885",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00228,
      "epss_percentile": 0.13814,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in UI in Google Chrome on Mac prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9885"
    },
    {
      "rank": 265,
      "cve_id": "CVE-2026-9898",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00228,
      "epss_percentile": 0.13815,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in GPU in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9898"
    },
    {
      "rank": 266,
      "cve_id": "CVE-2026-46820",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00227,
      "epss_percentile": 0.13701,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Financials Common Modules",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Financials Common Modules product of Oracle E-Business Suite (component: Common Components). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Financials Common Modules. While the vulnerability is in Oracle Financials Common Modules, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Financials Common Modules accessible data as well as unauthorized update, insert or delete access to some of Oracle Financials Common Modules accessible data. CVSS 3.1 Base Score 8.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46820"
    },
    {
      "rank": 267,
      "cve_id": "CVE-2026-46215",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00227,
      "epss_percentile": 0.13745,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-416",
      "title": "drm: Set old handle to NULL before prime swap in change_handle",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46215"
    },
    {
      "rank": 268,
      "cve_id": "CVE-2026-47074",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00226,
      "epss_percentile": 0.13547,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ex-aws",
      "product": "ex_aws_sns",
      "cwe": "CWE-295",
      "title": "ex_aws_sns SigningCertURL not validated in verify_message/1",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47074"
    },
    {
      "rank": 269,
      "cve_id": "CVE-2026-9972",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00226,
      "epss_percentile": 0.13599,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-457",
      "title": "Uninitialized Use in Gamepad in Google Chrome on Mac prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9972"
    },
    {
      "rank": 270,
      "cve_id": "CVE-2026-45310",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00226,
      "epss_percentile": 0.13524,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hmbown",
      "product": "CodeWhale",
      "cwe": "CWE-918",
      "title": "CodeWhale: SSRF via HTTP Redirect Bypass in fetch_url Tool",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45310"
    },
    {
      "rank": 271,
      "cve_id": "CVE-2026-9658",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00226,
      "epss_percentile": 0.13609,
      "kev": false,
      "kev_due_at": null,
      "vendor": "RRWO",
      "product": "Plack::Middleware::Security::Common",
      "cwe": "CWE-113",
      "title": "Plack::Middleware::Security::Common versions before 0.13.1 for Perl did not block header injections in request paths",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9658"
    },
    {
      "rank": 272,
      "cve_id": "CVE-2026-9999",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00225,
      "epss_percentile": 0.13458,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-269",
      "title": "Inappropriate implementation in ANGLE in Google Chrome on Mac prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9999"
    },
    {
      "rank": 273,
      "cve_id": "CVE-2026-45342",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00225,
      "epss_percentile": 0.1348,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Kovah",
      "product": "LinkAce",
      "cwe": "CWE-639",
      "title": "LinkAce: IDOR in Update Policies Allows Any Authenticated User to Overwrite Other Users' Links, Lists, Tags, and Notes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45342"
    },
    {
      "rank": 274,
      "cve_id": "CVE-2026-9958",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00224,
      "epss_percentile": 0.13324,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in PDFium in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9958"
    },
    {
      "rank": 275,
      "cve_id": "CVE-2026-6720",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00224,
      "epss_percentile": 0.13323,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tigera",
      "product": "Calico",
      "cwe": "CWE-532",
      "title": "Calicoctl leaks cluster credentials to stderr when verbose logging is enabled",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6720"
    },
    {
      "rank": 276,
      "cve_id": "CVE-2026-10008",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00224,
      "epss_percentile": 0.1337,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-457",
      "title": "Uninitialized Use in GPU in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10008"
    },
    {
      "rank": 277,
      "cve_id": "CVE-2026-9877",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00223,
      "epss_percentile": 0.13131,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9877"
    },
    {
      "rank": 278,
      "cve_id": "CVE-2026-9916",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00222,
      "epss_percentile": 0.13109,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-787",
      "title": "Out of bounds write in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9916"
    },
    {
      "rank": 279,
      "cve_id": "CVE-2026-9925",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00222,
      "epss_percentile": 0.13107,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9925"
    },
    {
      "rank": 280,
      "cve_id": "CVE-2026-9931",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00222,
      "epss_percentile": 0.13109,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in GPU in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9931"
    },
    {
      "rank": 281,
      "cve_id": "CVE-2026-9932",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00222,
      "epss_percentile": 0.13107,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in ANGLE in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9932"
    },
    {
      "rank": 282,
      "cve_id": "CVE-2026-9936",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00222,
      "epss_percentile": 0.13108,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in GFX in Google Chrome on Mac prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9936"
    },
    {
      "rank": 283,
      "cve_id": "CVE-2026-9937",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00222,
      "epss_percentile": 0.13107,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in UI in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9937"
    },
    {
      "rank": 284,
      "cve_id": "CVE-2026-9948",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00222,
      "epss_percentile": 0.13106,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Views in Google Chrome on Mac prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9948"
    },
    {
      "rank": 285,
      "cve_id": "CVE-2026-9949",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00222,
      "epss_percentile": 0.13108,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Core in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9949"
    },
    {
      "rank": 286,
      "cve_id": "CVE-2026-9951",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00222,
      "epss_percentile": 0.13109,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in UI in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9951"
    },
    {
      "rank": 287,
      "cve_id": "CVE-2026-9933",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00222,
      "epss_percentile": 0.13106,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Input in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9933"
    },
    {
      "rank": 288,
      "cve_id": "CVE-2026-4334",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00222,
      "epss_percentile": 0.13041,
      "kev": false,
      "kev_due_at": null,
      "vendor": "3uu",
      "product": "Shariff Wrapper",
      "cwe": "CWE-79",
      "title": "Shariff Wrapper <= 4.6.20 - Authenticated (Contributor+) Cross-Site Scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-4334"
    },
    {
      "rank": 289,
      "cve_id": "CVE-2026-45023",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00222,
      "epss_percentile": 0.13039,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Significant-Gravitas",
      "product": "AutoGPT",
      "cwe": "CWE-770",
      "title": "AutoGPT: Credit system bypassed via direct block execution in POST /api/blocks/{block_id}/execute",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45023"
    },
    {
      "rank": 290,
      "cve_id": "CVE-2026-48522",
      "cvss_base": 4.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00222,
      "epss_percentile": 0.13021,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jpadilla",
      "product": "pyjwt",
      "cwe": "CWE-441",
      "title": "PyJWKClient: missing scheme allowlist enables SSRF + token forgery via file://, ftp://, data: schemes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48522"
    },
    {
      "rank": 291,
      "cve_id": "CVE-2026-10003",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00221,
      "epss_percentile": 0.12924,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Views in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10003"
    },
    {
      "rank": 292,
      "cve_id": "CVE-2026-10009",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00221,
      "epss_percentile": 0.12924,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-472",
      "title": "Integer overflow in Skia in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10009"
    },
    {
      "rank": 293,
      "cve_id": "CVE-2026-9882",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00221,
      "epss_percentile": 0.1287,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-190",
      "title": "Integer overflow in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Critical)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9882"
    },
    {
      "rank": 294,
      "cve_id": "CVE-2026-9796",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00219,
      "epss_percentile": 0.12655,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat build of Keycloak 26.6",
      "cwe": "CWE-367",
      "title": "Keycloak: keycloak: privilege escalation via time-of-check to time-of-use (toctou) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9796"
    },
    {
      "rank": 295,
      "cve_id": "CVE-2026-47713",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00219,
      "epss_percentile": 0.12696,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mintplex-Labs",
      "product": "anything-llm",
      "cwe": "CWE-285",
      "title": "AnythingLLM: Legacy mobile device tokens bypass multi-user workspace scoping after mode migration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47713"
    },
    {
      "rank": 296,
      "cve_id": "CVE-2026-9887",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00218,
      "epss_percentile": 0.12512,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Proxy in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code via a crafted PAC script. (Chromium security severity: Critical)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9887"
    },
    {
      "rank": 297,
      "cve_id": "CVE-2026-9228",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00218,
      "epss_percentile": 0.12535,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jetmonsters",
      "product": "Timetable and Event Schedule by MotoPress",
      "cwe": "CWE-639",
      "title": "Timetable and Event Schedule by MotoPress <= 2.4.16 - Insecure Direct Object Reference to Authenticated (Contributor+) Sensitive Information Exposure via action_get_event_data Function",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9228"
    },
    {
      "rank": 298,
      "cve_id": "CVE-2026-9919",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00218,
      "epss_percentile": 0.12565,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-125",
      "title": "Out of bounds read in WebGL in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9919"
    },
    {
      "rank": 299,
      "cve_id": "CVE-2026-46828",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00216,
      "epss_percentile": 0.12318,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Payroll",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Payroll product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Payroll. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Payroll accessible data as well as unauthorized access to critical data or complete access to all Oracle Payroll accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46828"
    },
    {
      "rank": 300,
      "cve_id": "CVE-2026-47675",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00216,
      "epss_percentile": 0.12331,
      "kev": false,
      "kev_due_at": null,
      "vendor": "honojs",
      "product": "hono",
      "cwe": "CWE-113",
      "title": "Hono: Cookie helper does not sanitize sameSite and priority, allowing Set-Cookie injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47675"
    },
    {
      "rank": 301,
      "cve_id": "CVE-2026-7862",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00215,
      "epss_percentile": 0.12247,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Eupago Gateway For Woocommerce",
      "cwe": "CWE-284",
      "title": "Eupago Gateway For Woocommerce < 4.7.2 - Unauthenticated Arbitrary Refund Initiation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7862"
    },
    {
      "rank": 302,
      "cve_id": "CVE-2026-46841",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00215,
      "epss_percentile": 0.12139,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle REST Data Services",
      "cwe": "CWE-200",
      "title": "Vulnerability in Oracle REST Data Services (component: General). Supported versions that are affected are 24.2.0-26.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle REST Data Services. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle REST Data Services accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46841"
    },
    {
      "rank": 303,
      "cve_id": "CVE-2026-9791",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00215,
      "epss_percentile": 0.12154,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat build of Keycloak 26.4",
      "cwe": "CWE-863",
      "title": "Keycloak-rhel9: organization data leak after feature disabled in keycloak",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9791"
    },
    {
      "rank": 304,
      "cve_id": "CVE-2026-9888",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00214,
      "epss_percentile": 0.11974,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in WebView in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9888"
    },
    {
      "rank": 305,
      "cve_id": "CVE-2026-9889",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00214,
      "epss_percentile": 0.11971,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-125",
      "title": "Out of bounds read and write in Dawn in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9889"
    },
    {
      "rank": 306,
      "cve_id": "CVE-2026-9890",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00214,
      "epss_percentile": 0.11971,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in XR in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9890"
    },
    {
      "rank": 307,
      "cve_id": "CVE-2026-9894",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00214,
      "epss_percentile": 0.11973,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in GPU in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9894"
    },
    {
      "rank": 308,
      "cve_id": "CVE-2026-9895",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00214,
      "epss_percentile": 0.11973,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-125",
      "title": "Out of bounds read in GPU in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9895"
    },
    {
      "rank": 309,
      "cve_id": "CVE-2026-9899",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00214,
      "epss_percentile": 0.11974,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9899"
    },
    {
      "rank": 310,
      "cve_id": "CVE-2026-9900",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00214,
      "epss_percentile": 0.11975,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-787",
      "title": "Out of bounds write in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9900"
    },
    {
      "rank": 311,
      "cve_id": "CVE-2026-9902",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00214,
      "epss_percentile": 0.11972,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Accessibility in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9902"
    },
    {
      "rank": 312,
      "cve_id": "CVE-2026-9904",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00214,
      "epss_percentile": 0.11971,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9904"
    },
    {
      "rank": 313,
      "cve_id": "CVE-2026-9905",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00214,
      "epss_percentile": 0.11972,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Accessibility in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9905"
    },
    {
      "rank": 314,
      "cve_id": "CVE-2026-9906",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00214,
      "epss_percentile": 0.11974,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-787",
      "title": "Out of bounds write in GPU in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9906"
    },
    {
      "rank": 315,
      "cve_id": "CVE-2026-9966",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00214,
      "epss_percentile": 0.11975,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-472",
      "title": "Integer overflow in XML in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9966"
    },
    {
      "rank": 316,
      "cve_id": "CVE-2026-9970",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00214,
      "epss_percentile": 0.11972,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in WebGL in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9970"
    },
    {
      "rank": 317,
      "cve_id": "CVE-2026-9975",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00214,
      "epss_percentile": 0.11975,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-125",
      "title": "Out of bounds read and write in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9975"
    },
    {
      "rank": 318,
      "cve_id": "CVE-2026-9954",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00214,
      "epss_percentile": 0.11973,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in TabStrip in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9954"
    },
    {
      "rank": 319,
      "cve_id": "CVE-2026-9241",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00213,
      "epss_percentile": 0.11928,
      "kev": false,
      "kev_due_at": null,
      "vendor": "realmag777",
      "product": "FOX – Currency Switcher Professional for WooCommerce",
      "cwe": "CWE-639",
      "title": "FOX – Currency Switcher Professional for WooCommerce <= 1.4.6 - Authenticated (Subscriber+) Authorization Bypass via User-Controlled Key to 'wooc_order_user_roles' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9241"
    },
    {
      "rank": 320,
      "cve_id": "CVE-2026-46823",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00211,
      "epss_percentile": 0.11741,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Public Sector Financials (International)",
      "cwe": "CWE-863",
      "title": "Vulnerability in the Oracle Public Sector Financials (International) product of Oracle E-Business Suite (component: Authorization). Supported versions that are affected are 12.2.6-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Public Sector Financials (International). While the vulnerability is in Oracle Public Sector Financials (International), attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Public Sector Financials (International) accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46823"
    },
    {
      "rank": 321,
      "cve_id": "CVE-2026-9920",
      "cvss_base": 3.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00211,
      "epss_percentile": 0.11722,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-457",
      "title": "Uninitialized Use in GPU in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9920"
    },
    {
      "rank": 322,
      "cve_id": "CVE-2026-9907",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00209,
      "epss_percentile": 0.11418,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-125",
      "title": "Out of bounds read in Dawn in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9907"
    },
    {
      "rank": 323,
      "cve_id": "CVE-2026-9911",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00209,
      "epss_percentile": 0.11418,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-472",
      "title": "Integer overflow in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9911"
    },
    {
      "rank": 324,
      "cve_id": "CVE-2026-9929",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00209,
      "epss_percentile": 0.11418,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-200",
      "title": "Inappropriate implementation in WebGL in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9929"
    },
    {
      "rank": 325,
      "cve_id": "CVE-2026-9943",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00209,
      "epss_percentile": 0.11419,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-125",
      "title": "Out of bounds read in WebGL in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9943"
    },
    {
      "rank": 326,
      "cve_id": "CVE-2026-9946",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00207,
      "epss_percentile": 0.11175,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9946"
    },
    {
      "rank": 327,
      "cve_id": "CVE-2026-9974",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00207,
      "epss_percentile": 0.11179,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-787",
      "title": "Out of bounds write in GPU in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9974"
    },
    {
      "rank": 328,
      "cve_id": "CVE-2026-45042",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00207,
      "epss_percentile": 0.11124,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rustfs",
      "product": "rustfs",
      "cwe": "CWE-863",
      "title": "RustFS: UploadPartCopy Does Not Enforce Destination Bucket Policy on Copy Source",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45042"
    },
    {
      "rank": 329,
      "cve_id": "CVE-2026-8990",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00207,
      "epss_percentile": 0.11128,
      "kev": false,
      "kev_due_at": null,
      "vendor": "View Concept",
      "product": "Kidsview",
      "cwe": "CWE-288",
      "title": "Authentication Bypass in Kidsview",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8990"
    },
    {
      "rank": 330,
      "cve_id": "CVE-2026-45297",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00207,
      "epss_percentile": 0.1112,
      "kev": false,
      "kev_due_at": null,
      "vendor": "openreplay",
      "product": "openreplay",
      "cwe": "CWE-285",
      "title": "Cross-tenant IDOR on feature-flag and assist-stats routes via {project_id} case mismatch",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45297"
    },
    {
      "rank": 331,
      "cve_id": "CVE-2026-44850",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00206,
      "epss_percentile": 0.10954,
      "kev": false,
      "kev_due_at": null,
      "vendor": "portainer",
      "product": "portainer",
      "cwe": "CWE-863",
      "title": "Portainer: Bind-mount restriction bypass via HostConfig.Mounts",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44850"
    },
    {
      "rank": 332,
      "cve_id": "CVE-2026-9892",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00206,
      "epss_percentile": 0.10938,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-269",
      "title": "Inappropriate implementation in Skia in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9892"
    },
    {
      "rank": 333,
      "cve_id": "CVE-2026-7660",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00205,
      "epss_percentile": 0.10813,
      "kev": false,
      "kev_due_at": null,
      "vendor": "davidanderson",
      "product": "Easy Updates Manager",
      "cwe": "CWE-79",
      "title": "Easy Updates Manager <= 9.0.20 - Reflected Cross-Site Scripting via 'paged' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7660"
    },
    {
      "rank": 334,
      "cve_id": "CVE-2026-45410",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00205,
      "epss_percentile": 0.10857,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mauriceboe",
      "product": "TREK",
      "cwe": "CWE-203",
      "title": "Time-based user enumeration in TREK authentication endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45410"
    },
    {
      "rank": 335,
      "cve_id": "CVE-2026-46830",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00205,
      "epss_percentile": 0.10905,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle REST Data Services",
      "cwe": "CWE-200",
      "title": "Vulnerability in Oracle REST Data Services (component: Mongoapi). Supported versions that are affected are 24.2.0-26.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle REST Data Services. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle REST Data Services accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46830"
    },
    {
      "rank": 336,
      "cve_id": "CVE-2026-45021",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00204,
      "epss_percentile": 0.10694,
      "kev": false,
      "kev_due_at": null,
      "vendor": "kumahq",
      "product": "kuma",
      "cwe": "CWE-346",
      "title": "Kuma: Default kuma-cp leaks admin token cross-origin via CORS wildcard + LocalhostIsAdmin",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45021"
    },
    {
      "rank": 337,
      "cve_id": "CVE-2026-9881",
      "cvss_base": 9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00203,
      "epss_percentile": 0.10573,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Bluetooth in Google Chrome on Mac prior to 148.0.7778.216 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted Chrome Extension. (Chromium security severity: Critical)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9881"
    },
    {
      "rank": 338,
      "cve_id": "CVE-2026-46166",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00203,
      "epss_percentile": 0.10561,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-416",
      "title": "wifi: mac80211: use safe list iteration in radar detect work",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46166"
    },
    {
      "rank": 339,
      "cve_id": "CVE-2026-9090",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00201,
      "epss_percentile": 0.1037,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Casdoor",
      "product": "Casdoor",
      "cwe": null,
      "title": "CVE-2026-9090",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9090"
    },
    {
      "rank": 340,
      "cve_id": "CVE-2026-45348",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00199,
      "epss_percentile": 0.10081,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pyload",
      "product": "pyload",
      "cwe": "CWE-79",
      "title": "pyLoad: Stored XSS in Downloads view via unsanitized link URL in packages.js template literal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45348"
    },
    {
      "rank": 341,
      "cve_id": "CVE-2026-49093",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00199,
      "epss_percentile": 0.10113,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Elastic",
      "product": "Kibana",
      "cwe": "CWE-918",
      "title": "Server-Side Request Forgery (SSRF) in Kibana Leading to Unauthorized Network Access",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49093"
    },
    {
      "rank": 342,
      "cve_id": "CVE-2026-47673",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00199,
      "epss_percentile": 0.1004,
      "kev": false,
      "kev_due_at": null,
      "vendor": "honojs",
      "product": "hono",
      "cwe": "CWE-285",
      "title": "Hono: JWT middleware accepts any Authorization scheme, not only Bearer",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47673"
    },
    {
      "rank": 343,
      "cve_id": "CVE-2026-9942",
      "cvss_base": 5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00199,
      "epss_percentile": 0.10078,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-457",
      "title": "Uninitialized Use in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9942"
    },
    {
      "rank": 344,
      "cve_id": "CVE-2026-9950",
      "cvss_base": 3.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00199,
      "epss_percentile": 0.10133,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in iOS in Google Chrome on iOS prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to bypass same origin policy via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9950"
    },
    {
      "rank": 345,
      "cve_id": "CVE-2026-10020",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00198,
      "epss_percentile": 0.09949,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in Skia in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10020"
    },
    {
      "rank": 346,
      "cve_id": "CVE-2026-9944",
      "cvss_base": 3.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00197,
      "epss_percentile": 0.09851,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-457",
      "title": "Uninitialized Use in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9944"
    },
    {
      "rank": 347,
      "cve_id": "CVE-2026-9955",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00194,
      "epss_percentile": 0.09416,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-200",
      "title": "Inappropriate implementation in iOS in Google Chrome on iOS prior to 148.0.7778.216 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9955"
    },
    {
      "rank": 348,
      "cve_id": "CVE-2026-9807",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00193,
      "epss_percentile": 0.09357,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GitLab",
      "product": "GitLab",
      "cwe": "CWE-863",
      "title": "Incorrect Authorization in GitLab",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9807"
    },
    {
      "rank": 349,
      "cve_id": "CVE-2026-45403",
      "cvss_base": 2.5,
      "cvss_severity": "LOW",
      "epss_score": 0.00193,
      "epss_percentile": 0.09289,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mintplex-Labs",
      "product": "anything-llm",
      "cwe": "CWE-59",
      "title": "AnythingLLM: filesystem-copy-file follows nested symlinks and copies files from outside the allowed directory",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45403"
    },
    {
      "rank": 350,
      "cve_id": "CVE-2026-9981",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00191,
      "epss_percentile": 0.09087,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-200",
      "title": "Inappropriate implementation in Skia in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9981"
    },
    {
      "rank": 351,
      "cve_id": "CVE-2026-9996",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00191,
      "epss_percentile": 0.09087,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-125",
      "title": "Out of bounds read in WebRTC in Google Chrome on Mac prior to 148.0.7778.216 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9996"
    },
    {
      "rank": 352,
      "cve_id": "CVE-2026-10018",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00191,
      "epss_percentile": 0.09087,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-472",
      "title": "Integer overflow in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10018"
    },
    {
      "rank": 353,
      "cve_id": "CVE-2026-47760",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00191,
      "epss_percentile": 0.09098,
      "kev": false,
      "kev_due_at": null,
      "vendor": "tinymce",
      "product": "tinymce",
      "cwe": "CWE-79",
      "title": "TinyMCE Cross-Site Scripting (XSS) vulnerability using sanitization bypass through nested SVGs",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47760"
    },
    {
      "rank": 354,
      "cve_id": "CVE-2026-9930",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00191,
      "epss_percentile": 0.09084,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-787",
      "title": "Out of bounds write in Dawn in Google Chrome on Mac prior to 148.0.7778.216 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9930"
    },
    {
      "rank": 355,
      "cve_id": "CVE-2026-10019",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0019,
      "epss_percentile": 0.0898,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-472",
      "title": "Integer overflow in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10019"
    },
    {
      "rank": 356,
      "cve_id": "CVE-2026-9039",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00185,
      "epss_percentile": 0.08455,
      "kev": false,
      "kev_due_at": null,
      "vendor": "XCharge",
      "product": "C6",
      "cwe": "CWE-1188",
      "title": "Initialization of a resource with an insecure default in XCharge C6",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9039"
    },
    {
      "rank": 357,
      "cve_id": "CVE-2026-10000",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00185,
      "epss_percentile": 0.08455,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Passwords in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10000"
    },
    {
      "rank": 358,
      "cve_id": "CVE-2026-10014",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00185,
      "epss_percentile": 0.08454,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in WebMIDI in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10014"
    },
    {
      "rank": 359,
      "cve_id": "CVE-2026-10017",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00185,
      "epss_percentile": 0.08454,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-125",
      "title": "Out of bounds read in Headless in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10017"
    },
    {
      "rank": 360,
      "cve_id": "CVE-2026-9977",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00184,
      "epss_percentile": 0.08368,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in WebShare in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9977"
    },
    {
      "rank": 361,
      "cve_id": "CVE-2026-9982",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00184,
      "epss_percentile": 0.08369,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9982"
    },
    {
      "rank": 362,
      "cve_id": "CVE-2026-46842",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00183,
      "epss_percentile": 0.08225,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle REST Data Services",
      "cwe": "CWE-284",
      "title": "Vulnerability in Oracle REST Data Services (component: Core). Supported versions that are affected are 24.2.0-26.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle REST Data Services. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle REST Data Services accessible data. CVSS 3.1 Base Score 5.3 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46842"
    },
    {
      "rank": 363,
      "cve_id": "CVE-2026-9994",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00182,
      "epss_percentile": 0.08074,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Core in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9994"
    },
    {
      "rank": 364,
      "cve_id": "CVE-2026-9985",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00182,
      "epss_percentile": 0.08127,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in Media in Google Chrome on ChromeOS prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9985"
    },
    {
      "rank": 365,
      "cve_id": "CVE-2026-44358",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00181,
      "epss_percentile": 0.08046,
      "kev": false,
      "kev_due_at": null,
      "vendor": "espressif",
      "product": "shared-github-dangerjs",
      "cwe": "CWE-427",
      "title": "Espressif Shared GitHub DangerJS: Untrusted Search Path in DangerJS Action Entrypoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44358"
    },
    {
      "rank": 366,
      "cve_id": "CVE-2026-10028",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00181,
      "epss_percentile": 0.07983,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-835",
      "title": "Glib-networking: infinite loop in glib-networking gnutls backend allows remote denial of service via circular certificate chain",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10028"
    },
    {
      "rank": 367,
      "cve_id": "CVE-2026-10002",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0018,
      "epss_percentile": 0.07907,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in PDFium in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10002"
    },
    {
      "rank": 368,
      "cve_id": "CVE-2026-9997",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00178,
      "epss_percentile": 0.0764,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Input in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9997"
    },
    {
      "rank": 369,
      "cve_id": "CVE-2026-44794",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00177,
      "epss_percentile": 0.07577,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nautobot",
      "product": "nautobot",
      "cwe": "CWE-862",
      "title": "Nautobot: REST API permits creation of GenericForeignKey references to objects that the user should not be able to reference",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44794"
    },
    {
      "rank": 370,
      "cve_id": "CVE-2026-46561",
      "cvss_base": 5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00176,
      "epss_percentile": 0.07383,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pyload",
      "product": "pyload",
      "cwe": "CWE-918",
      "title": "pyLoad: SSRF via HTTP Redirect Bypass in parse_urls API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46561"
    },
    {
      "rank": 371,
      "cve_id": "CVE-2026-9988",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00173,
      "epss_percentile": 0.07047,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in WebRTC in Google Chrome on Linux prior to 148.0.7778.216 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9988"
    },
    {
      "rank": 372,
      "cve_id": "CVE-2026-9998",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00173,
      "epss_percentile": 0.07046,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-472",
      "title": "Integer overflow in Skia in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9998"
    },
    {
      "rank": 373,
      "cve_id": "CVE-2026-10001",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00173,
      "epss_percentile": 0.07047,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in PerformanceManager in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10001"
    },
    {
      "rank": 374,
      "cve_id": "CVE-2026-10012",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00173,
      "epss_percentile": 0.07046,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Skia in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10012"
    },
    {
      "rank": 375,
      "cve_id": "CVE-2026-9990",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00173,
      "epss_percentile": 0.07046,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in WebAppInstalls in Google Chrome on Mac prior to 148.0.7778.216 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9990"
    },
    {
      "rank": 376,
      "cve_id": "CVE-2026-46152",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00167,
      "epss_percentile": 0.06455,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-1058",
      "title": "wifi: mac80211: drop stray 'static' from fast-RX rx_result",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46152"
    },
    {
      "rank": 377,
      "cve_id": "CVE-2026-9673",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00166,
      "epss_percentile": 0.06351,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "json-2-csv",
      "cwe": "CWE-1236",
      "title": "Versions of the package json-2-csv from 3.15.0 and before 5.5.11 are vulnerable to CSV Injection via the preventCsvInjection option which can be bypassed. An attacker can inject formulas into CSV files, which execute when the files are opened in spreadsheet applications.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9673"
    },
    {
      "rank": 378,
      "cve_id": "CVE-2026-9993",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00164,
      "epss_percentile": 0.0613,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Views in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted PDF file. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9993"
    },
    {
      "rank": 379,
      "cve_id": "CVE-2026-10004",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00164,
      "epss_percentile": 0.06146,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in Passwords in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10004"
    },
    {
      "rank": 380,
      "cve_id": "CVE-2026-10011",
      "cvss_base": 3.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00164,
      "epss_percentile": 0.06066,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-200",
      "title": "Inappropriate implementation in Skia in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10011"
    },
    {
      "rank": 381,
      "cve_id": "CVE-2026-9903",
      "cvss_base": 5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00161,
      "epss_percentile": 0.05834,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in Site Isolation in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted MHTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9903"
    },
    {
      "rank": 382,
      "cve_id": "CVE-2026-9971",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00159,
      "epss_percentile": 0.05581,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-79",
      "title": "Inappropriate implementation in iOS in Google Chrome on iOS prior to 148.0.7778.216 allowed a remote attacker who convinced a user to engage in specific UI gestures to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9971"
    },
    {
      "rank": 383,
      "cve_id": "CVE-2026-9793",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00158,
      "epss_percentile": 0.0545,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat build of Keycloak 26.4",
      "cwe": "CWE-347",
      "title": "Keycloak: keycloak: security policy bypass in jwe-encrypted request object processing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9793"
    },
    {
      "rank": 384,
      "cve_id": "CVE-2026-9646",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00158,
      "epss_percentile": 0.05515,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ScadaBR",
      "product": "ScadaBR",
      "cwe": "CWE-80",
      "title": "ScadaBR Unauthenticated Reflected Cross-Site Scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9646"
    },
    {
      "rank": 385,
      "cve_id": "CVE-2026-9644",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00156,
      "epss_percentile": 0.05299,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nhadjidimitrov",
      "product": "LiveSmart Video Chat Live Video Chat",
      "cwe": "CWE-79",
      "title": "LiveSmart Video Chat <= 1.2 - Authenticated (Contributor+) Stored Cross-Site Scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9644"
    },
    {
      "rank": 386,
      "cve_id": "CVE-2026-46113",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00154,
      "epss_percentile": 0.05096,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-416",
      "title": "KVM: x86: Fix shadow paging use-after-free due to unexpected GFN",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46113"
    },
    {
      "rank": 387,
      "cve_id": "CVE-2026-32996",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00154,
      "epss_percentile": 0.05063,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Veeam",
      "product": "Backup and Replication",
      "cwe": "CWE-532",
      "title": "This vulnerability in Veeam Agent for Microsoft Windows allows for Local Privilege Escalation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-32996"
    },
    {
      "rank": 388,
      "cve_id": "CVE-2026-45307",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00153,
      "epss_percentile": 0.05015,
      "kev": false,
      "kev_due_at": null,
      "vendor": "murtaza-nasir",
      "product": "speakr",
      "cwe": "CWE-601",
      "title": "Speakr: Open redirect in is_safe_url via parser mismatch on next parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45307"
    },
    {
      "rank": 389,
      "cve_id": "CVE-2026-9789",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00152,
      "epss_percentile": 0.0485,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Acer",
      "product": "NitrorSense V3",
      "cwe": "CWE-22",
      "title": "NitroSense V3: Security Vulnerability Information",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9789"
    },
    {
      "rank": 390,
      "cve_id": "CVE-2026-45040",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00152,
      "epss_percentile": 0.04865,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rustfs",
      "product": "rustfs",
      "cwe": "CWE-312",
      "title": "RustFS: Sensitive Information Leakage (SessionToken and SecretAccessKey) in RustFS Logs [Debug Mode]",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45040"
    },
    {
      "rank": 391,
      "cve_id": "CVE-2026-10022",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00151,
      "epss_percentile": 0.04832,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-843",
      "title": "Type Confusion in V8 in Google Chrome prior to 148.0.7778.216 allowed an attacker who convinced a user to install a malicious extension to execute arbitrary code inside a sandbox via a crafted Chrome Extension. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10022"
    },
    {
      "rank": 392,
      "cve_id": "CVE-2026-9986",
      "cvss_base": 4.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00145,
      "epss_percentile": 0.04244,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in OptimizationGuide in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to perform UI spoofing via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9986"
    },
    {
      "rank": 393,
      "cve_id": "CVE-2026-46189",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00143,
      "epss_percentile": 0.04151,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-415",
      "title": "RDMA/vmw_pvrdma: Fix double free on pvrdma_alloc_ucontext() error path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46189"
    },
    {
      "rank": 394,
      "cve_id": "CVE-2026-46145",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00142,
      "epss_percentile": 0.03981,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-787",
      "title": "RDMA/mana: Validate rx_hash_key_len",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46145"
    },
    {
      "rank": 395,
      "cve_id": "CVE-2026-46176",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00142,
      "epss_percentile": 0.03981,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-825",
      "title": "RDMA/mlx5: Fix error path fall-through in mlx5_ib_dev_res_srq_init()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46176"
    },
    {
      "rank": 396,
      "cve_id": "CVE-2026-46123",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00142,
      "epss_percentile": 0.03984,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-787",
      "title": "Bluetooth: virtio_bt: clamp rx length before skb_put",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46123"
    },
    {
      "rank": 397,
      "cve_id": "CVE-2026-46150",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00142,
      "epss_percentile": 0.04044,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "fanotify: fix false positive on permission events",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46150"
    },
    {
      "rank": 398,
      "cve_id": "CVE-2026-46205",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00141,
      "epss_percentile": 0.03937,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "staging: media: atomisp: Disallow all private IOCTLs",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46205"
    },
    {
      "rank": 399,
      "cve_id": "CVE-2026-49237",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00141,
      "epss_percentile": 0.0395,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Canonical",
      "product": "Multipass",
      "cwe": "CWE-276",
      "title": "Local Privilege Escalation in Canonical Multipass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49237"
    },
    {
      "rank": 400,
      "cve_id": "CVE-2026-4377",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00141,
      "epss_percentile": 0.0393,
      "kev": false,
      "kev_due_at": null,
      "vendor": "D-Link Corporation",
      "product": "DWR-X1820",
      "cwe": "CWE-1391",
      "title": "Use of Weak Credentials in D-Link DWR-X1820 router",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-4377"
    },
    {
      "rank": 401,
      "cve_id": "CVE-2026-42401",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00141,
      "epss_percentile": 0.03944,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Elastic",
      "product": "Kibana",
      "cwe": "CWE-79",
      "title": "Improper Neutralization of Input During Web Page Generation in Kibana Leading to Stored HTML Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42401"
    },
    {
      "rank": 402,
      "cve_id": "CVE-2026-9991",
      "cvss_base": 3.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00141,
      "epss_percentile": 0.03942,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-200",
      "title": "Inappropriate implementation in Media in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9991"
    },
    {
      "rank": 403,
      "cve_id": "CVE-2026-46129",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00139,
      "epss_percentile": 0.03726,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-415",
      "title": "btrfs: fix double free in create_space_info() error path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46129"
    },
    {
      "rank": 404,
      "cve_id": "CVE-2026-46197",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00139,
      "epss_percentile": 0.03725,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-787",
      "title": "drm/amdkfd: validate SVM ioctl nattr against buffer size",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46197"
    },
    {
      "rank": 405,
      "cve_id": "CVE-2026-46206",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00139,
      "epss_percentile": 0.03725,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "batman-adv: reject new tp_meter sessions during teardown",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46206"
    },
    {
      "rank": 406,
      "cve_id": "CVE-2026-46208",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00139,
      "epss_percentile": 0.03723,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "batman-adv: stop tp_meter sessions during mesh teardown",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46208"
    },
    {
      "rank": 407,
      "cve_id": "CVE-2026-46209",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00139,
      "epss_percentile": 0.03726,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-787",
      "title": "drm/gem: Fix inconsistent plane dimension calculation in drm_gem_fb_init_with_funcs()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46209"
    },
    {
      "rank": 408,
      "cve_id": "CVE-2026-46149",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00139,
      "epss_percentile": 0.03739,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-674",
      "title": "scsi: target: configfs: Bound snprintf() return in tg_pt_gp_members_show()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46149"
    },
    {
      "rank": 409,
      "cve_id": "CVE-2026-46162",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00138,
      "epss_percentile": 0.03658,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-415",
      "title": "ice: fix double free in ice_sf_eth_activate() error path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46162"
    },
    {
      "rank": 410,
      "cve_id": "CVE-2026-46201",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00138,
      "epss_percentile": 0.03646,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-401",
      "title": "drm/xe: Fix dma-buf attachment leak in xe_gem_prime_import()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46201"
    },
    {
      "rank": 411,
      "cve_id": "CVE-2026-9618",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00138,
      "epss_percentile": 0.03653,
      "kev": false,
      "kev_due_at": null,
      "vendor": "peachpay",
      "product": "PeachPay — Payments & Express Checkout for WooCommerce (supports Stripe, PayPal, Square, Authorize.net, NMI)",
      "cwe": "CWE-352",
      "title": "PeachPay <= 1.120.46 - Cross-Site Request Forgery to Stripe Unlink",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9618"
    },
    {
      "rank": 412,
      "cve_id": "CVE-2026-9959",
      "cvss_base": 3.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00137,
      "epss_percentile": 0.03609,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-362",
      "title": "Race in WebRTC in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9959"
    },
    {
      "rank": 413,
      "cve_id": "CVE-2026-46164",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00136,
      "epss_percentile": 0.03542,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-415",
      "title": "btrfs: fix double free in create_space_info_sub_group() error path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46164"
    },
    {
      "rank": 414,
      "cve_id": "CVE-2026-46174",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00135,
      "epss_percentile": 0.03441,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "x86/CPU/AMD: Prevent improper isolation of shared resources in Zen2's op cache",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46174"
    },
    {
      "rank": 415,
      "cve_id": "CVE-2026-46180",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00135,
      "epss_percentile": 0.0342,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-416",
      "title": "wifi: brcmfmac: Fix potential use-after-free issue when stopping watchdog task",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46180"
    },
    {
      "rank": 416,
      "cve_id": "CVE-2026-46219",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00135,
      "epss_percentile": 0.03419,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-416",
      "title": "spi: mpc52xx: fix use-after-free on unbind",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46219"
    },
    {
      "rank": 417,
      "cve_id": "CVE-2026-7533",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00135,
      "epss_percentile": 0.03449,
      "kev": false,
      "kev_due_at": null,
      "vendor": "smub",
      "product": "Easy Digital Downloads – eCommerce Payments and Subscriptions made easy",
      "cwe": "CWE-352",
      "title": "Easy Digital Downloads <= 3.6.7 - Cross-Site Request Forgery to Payment Account Hijacking via 'square_tokens' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7533"
    },
    {
      "rank": 418,
      "cve_id": "CVE-2026-46117",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00132,
      "epss_percentile": 0.03228,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-617",
      "title": "RDMA/mana: Remove user triggerable WARN_ON() in mana_ib_create_qp_rss()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46117"
    },
    {
      "rank": 419,
      "cve_id": "CVE-2026-46140",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00131,
      "epss_percentile": 0.03133,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-125",
      "title": "Bluetooth: btmtk: validate WMT event SKB length before struct access",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46140"
    },
    {
      "rank": 420,
      "cve_id": "CVE-2026-46190",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00131,
      "epss_percentile": 0.03158,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-125",
      "title": "mtd: spi-nor: debugfs: fix out-of-bounds read in spi_nor_params_show()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46190"
    },
    {
      "rank": 421,
      "cve_id": "CVE-2026-46191",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00131,
      "epss_percentile": 0.03167,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-125",
      "title": "fbcon: Avoid OOB font access if console rotation fails",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46191"
    },
    {
      "rank": 422,
      "cve_id": "CVE-2026-46199",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00131,
      "epss_percentile": 0.03158,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-125",
      "title": "drm/amdgpu/vcn4: Prevent OOB reads when parsing dec msg",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46199"
    },
    {
      "rank": 423,
      "cve_id": "CVE-2026-46203",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00131,
      "epss_percentile": 0.03132,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-125",
      "title": "spi: cadence-quadspi: fix unclocked access on unbind",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46203"
    },
    {
      "rank": 424,
      "cve_id": "CVE-2026-46204",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00131,
      "epss_percentile": 0.03132,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-125",
      "title": "drm/amdgpu/vcn4: Prevent OOB reads when parsing IB",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46204"
    },
    {
      "rank": 425,
      "cve_id": "CVE-2026-46218",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00131,
      "epss_percentile": 0.03167,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/amdgpu: Add bounds checking to ib_{get,set}_value",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46218"
    },
    {
      "rank": 426,
      "cve_id": "CVE-2026-46116",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0013,
      "epss_percentile": 0.03059,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-416",
      "title": "xfrm: defensively unhash xfrm_state lists in __xfrm_state_delete",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46116"
    },
    {
      "rank": 427,
      "cve_id": "CVE-2026-46169",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0013,
      "epss_percentile": 0.03095,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-908",
      "title": "hfsplus: fix uninit-value by validating catalog record size",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46169"
    },
    {
      "rank": 428,
      "cve_id": "CVE-2026-46107",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00129,
      "epss_percentile": 0.03023,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-191",
      "title": "dm-thin: fix metadata refcount underflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46107"
    },
    {
      "rank": 429,
      "cve_id": "CVE-2026-46122",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00129,
      "epss_percentile": 0.03012,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-129",
      "title": "wifi: b43: enforce bounds check on firmware key index in b43_rx()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46122"
    },
    {
      "rank": 430,
      "cve_id": "CVE-2026-46136",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00129,
      "epss_percentile": 0.03017,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-787",
      "title": "wifi: mt76: mt7921: fix a potential clc buffer length underflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46136"
    },
    {
      "rank": 431,
      "cve_id": "CVE-2026-46163",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00129,
      "epss_percentile": 0.03019,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-129",
      "title": "wifi: b43legacy: enforce bounds check on firmware key index in RX path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46163"
    },
    {
      "rank": 432,
      "cve_id": "CVE-2026-46178",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00129,
      "epss_percentile": 0.03015,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-401",
      "title": "RDMA/mlx4: Fix resource leak on error in mlx4_ib_create_srq()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46178"
    },
    {
      "rank": 433,
      "cve_id": "CVE-2026-46210",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00129,
      "epss_percentile": 0.0303,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-416",
      "title": "media: iris: fix use-after-free of fmt_src during MBPF check",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46210"
    },
    {
      "rank": 434,
      "cve_id": "CVE-2026-46234",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00129,
      "epss_percentile": 0.03009,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-787",
      "title": "vsock: fix buffer size clamping order",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46234"
    },
    {
      "rank": 435,
      "cve_id": "CVE-2026-48735",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00128,
      "epss_percentile": 0.02917,
      "kev": false,
      "kev_due_at": null,
      "vendor": "py-pdf",
      "product": "pypdf",
      "cwe": "CWE-770",
      "title": "pypdf: Manipulated XMP metadata streams can exhaust RAM",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48735"
    },
    {
      "rank": 436,
      "cve_id": "CVE-2026-45078",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00128,
      "epss_percentile": 0.02911,
      "kev": false,
      "kev_due_at": null,
      "vendor": "element-hq",
      "product": "synapse",
      "cwe": "CWE-770",
      "title": "Synapse CPU starvation (Denial of Service)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45078"
    },
    {
      "rank": 437,
      "cve_id": "CVE-2026-46127",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00128,
      "epss_percentile": 0.02886,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-476",
      "title": "RDMA/ocrdma: Don't NULL deref uctx on errors in ocrdma_copy_pd_uresp()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46127"
    },
    {
      "rank": 438,
      "cve_id": "CVE-2026-46128",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00128,
      "epss_percentile": 0.0288,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ipmi: Check event message buffer response for bad data",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46128"
    },
    {
      "rank": 439,
      "cve_id": "CVE-2026-46132",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00128,
      "epss_percentile": 0.02885,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-908",
      "title": "net: rtnetlink: zero ifla_vf_broadcast to avoid stack infoleak in rtnl_fill_vfinfo",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46132"
    },
    {
      "rank": 440,
      "cve_id": "CVE-2026-46143",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00128,
      "epss_percentile": 0.0287,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-401",
      "title": "ASoC: qcom: q6apm-lpass-dai: Fix multiple graph opens",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46143"
    },
    {
      "rank": 441,
      "cve_id": "CVE-2026-46146",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00128,
      "epss_percentile": 0.02888,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-835",
      "title": "ALSA: usb-audio: Avoid potential endless loop in convert_chmap_v3()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46146"
    },
    {
      "rank": 442,
      "cve_id": "CVE-2026-46160",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00128,
      "epss_percentile": 0.02889,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "btrfs: fix missing last_unlink_trans update when removing a directory",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46160"
    },
    {
      "rank": 443,
      "cve_id": "CVE-2026-46161",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00128,
      "epss_percentile": 0.02888,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-369",
      "title": "md/raid10: fix divide-by-zero in setup_geo() with zero far_copies",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46161"
    },
    {
      "rank": 444,
      "cve_id": "CVE-2026-46167",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00128,
      "epss_percentile": 0.02889,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-908",
      "title": "usb: usblp: fix uninitialized heap leak via LPGETSTATUS ioctl",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46167"
    },
    {
      "rank": 445,
      "cve_id": "CVE-2026-46168",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00128,
      "epss_percentile": 0.02889,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "mptcp: fix scheduling with atomic in timestamp sockopt",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46168"
    },
    {
      "rank": 446,
      "cve_id": "CVE-2026-46172",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00128,
      "epss_percentile": 0.02884,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ipv6: xfrm6: release dst on error in xfrm6_rcv_encap()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46172"
    },
    {
      "rank": 447,
      "cve_id": "CVE-2026-46184",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00128,
      "epss_percentile": 0.02892,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-369",
      "title": "sound: ua101: fix division by zero at probe",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46184"
    },
    {
      "rank": 448,
      "cve_id": "CVE-2026-46193",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00128,
      "epss_percentile": 0.02892,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "xfrm: ah: account for ESN high bits in async callbacks",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46193"
    },
    {
      "rank": 449,
      "cve_id": "CVE-2026-46196",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00128,
      "epss_percentile": 0.02891,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "tracepoint: balance regfunc() on func_add() failure in tracepoint_add_func()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46196"
    },
    {
      "rank": 450,
      "cve_id": "CVE-2026-46202",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00128,
      "epss_percentile": 0.02905,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "HID: appletb-kbd: run inactivity autodim from workqueues",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46202"
    },
    {
      "rank": 451,
      "cve_id": "CVE-2026-46214",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00128,
      "epss_percentile": 0.02885,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "vsock/virtio: fix accept queue count leak on transport mismatch",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46214"
    },
    {
      "rank": 452,
      "cve_id": "CVE-2026-9979",
      "cvss_base": 5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00128,
      "epss_percentile": 0.02872,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in Input in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9979"
    },
    {
      "rank": 453,
      "cve_id": "CVE-2026-46105",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00127,
      "epss_percentile": 0.02807,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "scsi: mpt3sas: Limit NVMe request size to 2 MiB",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46105"
    },
    {
      "rank": 454,
      "cve_id": "CVE-2026-46126",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00127,
      "epss_percentile": 0.02832,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "RDMA/mana: Fix mana_destroy_wq_obj() cleanup in mana_ib_create_qp_rss()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46126"
    },
    {
      "rank": 455,
      "cve_id": "CVE-2026-46131",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00127,
      "epss_percentile": 0.02815,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "KVM: x86: check for nEPT/nNPT in slow flush hypercalls",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46131"
    },
    {
      "rank": 456,
      "cve_id": "CVE-2026-46142",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00127,
      "epss_percentile": 0.02836,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net: libwx: fix VF illegal register access",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46142"
    },
    {
      "rank": 457,
      "cve_id": "CVE-2026-46144",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00127,
      "epss_percentile": 0.02837,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "RDMA/mana: Fix error unwind in mana_ib_create_qp_rss()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46144"
    },
    {
      "rank": 458,
      "cve_id": "CVE-2026-46158",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00127,
      "epss_percentile": 0.02834,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "mptcp: pm: ADD_ADDR rtx: always decrease sk refcount",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46158"
    },
    {
      "rank": 459,
      "cve_id": "CVE-2026-46170",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00127,
      "epss_percentile": 0.02832,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "mptcp: pm: ADD_ADDR rtx: free sk if last",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46170"
    },
    {
      "rank": 460,
      "cve_id": "CVE-2026-46188",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00127,
      "epss_percentile": 0.02834,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-476",
      "title": "octeon_ep_vf: add NULL check for napi_build_skb()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46188"
    },
    {
      "rank": 461,
      "cve_id": "CVE-2026-46200",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00127,
      "epss_percentile": 0.02833,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "spi: mpc52xx: fix controller deregistration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46200"
    },
    {
      "rank": 462,
      "cve_id": "CVE-2026-46207",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00127,
      "epss_percentile": 0.02831,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-401",
      "title": "vsock/virtio: fix empty payload in tap skb for non-linear buffers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46207"
    },
    {
      "rank": 463,
      "cve_id": "CVE-2026-46211",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00127,
      "epss_percentile": 0.02831,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-476",
      "title": "drm/msm/gem: fix error handling in msm_ioctl_gem_info_get_metadata()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46211"
    },
    {
      "rank": 464,
      "cve_id": "CVE-2026-46216",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00127,
      "epss_percentile": 0.0283,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-476",
      "title": "drm/xe/hdcp: Add NULL check for media_gt in intel_hdcp_gsc_check_status()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46216"
    },
    {
      "rank": 465,
      "cve_id": "CVE-2026-48523",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00127,
      "epss_percentile": 0.02758,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jpadilla",
      "product": "pyjwt",
      "cwe": "CWE-347",
      "title": "PyJWT: Algorithm allow-list bypass when decoding with `PyJWK` / `PyJWKClient` keys",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48523"
    },
    {
      "rank": 466,
      "cve_id": "CVE-2026-48155",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00127,
      "epss_percentile": 0.02792,
      "kev": false,
      "kev_due_at": null,
      "vendor": "py-pdf",
      "product": "pypdf",
      "cwe": "CWE-400",
      "title": "pypdf: Possible large memory usage for large offsets for layout mode text",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48155"
    },
    {
      "rank": 467,
      "cve_id": "CVE-2026-46120",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00126,
      "epss_percentile": 0.02673,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-416",
      "title": "ip6_gre: Use cached t->net in ip6erspan_changelink().",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46120"
    },
    {
      "rank": 468,
      "cve_id": "CVE-2026-46173",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00126,
      "epss_percentile": 0.02675,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-787",
      "title": "exit: prevent preemption of oopsing TASK_DEAD task",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46173"
    },
    {
      "rank": 469,
      "cve_id": "CVE-2026-46134",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00126,
      "epss_percentile": 0.02721,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-476",
      "title": "platform/chrome: cros_ec_typec: Init mutex in Thunderbolt registration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46134"
    },
    {
      "rank": 470,
      "cve_id": "CVE-2026-46147",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00126,
      "epss_percentile": 0.02707,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-401",
      "title": "KVM: arm64: Fix pin leak and publication ordering in __pkvm_init_vcpu()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46147"
    },
    {
      "rank": 471,
      "cve_id": "CVE-2026-46171",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00126,
      "epss_percentile": 0.02721,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-401",
      "title": "riscv: kvm: fix vector context allocation leak",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46171"
    },
    {
      "rank": 472,
      "cve_id": "CVE-2026-46182",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00126,
      "epss_percentile": 0.02717,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-401",
      "title": "pseries/papr-hvpipe: Prevent kernel stack memory leak to userspace",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46182"
    },
    {
      "rank": 473,
      "cve_id": "CVE-2026-42250",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00126,
      "epss_percentile": 0.02744,
      "kev": false,
      "kev_due_at": null,
      "vendor": "bzip2",
      "product": "bzip2",
      "cwe": "CWE-787",
      "title": "Off-by-One Leading to Out-of-Bounds Write in bzip2",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42250"
    },
    {
      "rank": 474,
      "cve_id": "CVE-2026-46111",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00125,
      "epss_percentile": 0.02631,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-416",
      "title": "Bluetooth: hci_conn: fix potential UAF in create_big_sync",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46111"
    },
    {
      "rank": 475,
      "cve_id": "CVE-2026-46121",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00125,
      "epss_percentile": 0.02618,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-416",
      "title": "mm/damon/sysfs-schemes: protect memcg_path kfree() with damon_sysfs_lock",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46121"
    },
    {
      "rank": 476,
      "cve_id": "CVE-2026-46241",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00125,
      "epss_percentile": 0.02612,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-416",
      "title": "spi: mpc52xx: fix use-after-free on registration failure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46241"
    },
    {
      "rank": 477,
      "cve_id": "CVE-2026-10010",
      "cvss_base": 5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00125,
      "epss_percentile": 0.02644,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-346",
      "title": "Inappropriate implementation in Input in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10010"
    },
    {
      "rank": 478,
      "cve_id": "CVE-2026-46213",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00124,
      "epss_percentile": 0.0253,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-416",
      "title": "HID: appletb-kbd: fix UAF in inactivity-timer cleanup path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46213"
    },
    {
      "rank": 479,
      "cve_id": "CVE-2026-46240",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00124,
      "epss_percentile": 0.02527,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-416",
      "title": "media: iris: Fix use-after-free in iris_release_internal_buffers()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46240"
    },
    {
      "rank": 480,
      "cve_id": "CVE-2026-46130",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00124,
      "epss_percentile": 0.02539,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-125",
      "title": "dm-verity-fec: fix reading parity bytes split across blocks (take 3)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46130"
    },
    {
      "rank": 481,
      "cve_id": "CVE-2026-46175",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00124,
      "epss_percentile": 0.02552,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "f2fs: fix fsck inconsistency caused by FGGC of node block",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46175"
    },
    {
      "rank": 482,
      "cve_id": "CVE-2026-48156",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00124,
      "epss_percentile": 0.02553,
      "kev": false,
      "kev_due_at": null,
      "vendor": "py-pdf",
      "product": "pypdf",
      "cwe": "CWE-834",
      "title": "pypdf: Possible long runtimes for zero-only width values in cross-reference streams",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48156"
    },
    {
      "rank": 483,
      "cve_id": "CVE-2026-9980",
      "cvss_base": 5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00124,
      "epss_percentile": 0.0257,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in Printing in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9980"
    },
    {
      "rank": 484,
      "cve_id": "CVE-2026-46108",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00123,
      "epss_percentile": 0.0244,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ipmi:si: Return state to normal if message allocation fails",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46108"
    },
    {
      "rank": 485,
      "cve_id": "CVE-2026-46109",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00123,
      "epss_percentile": 0.02439,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-401",
      "title": "usb: ulpi: fix memory leak on ulpi_register() error paths",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46109"
    },
    {
      "rank": 486,
      "cve_id": "CVE-2026-46151",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00123,
      "epss_percentile": 0.02441,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-401",
      "title": "usb: usblp: fix heap leak in IEEE 1284 device ID via short response",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46151"
    },
    {
      "rank": 487,
      "cve_id": "CVE-2026-46186",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00123,
      "epss_percentile": 0.0246,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-908",
      "title": "Bluetooth: virtio_bt: validate rx pkt_type header length",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46186"
    },
    {
      "rank": 488,
      "cve_id": "CVE-2026-6891",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00123,
      "epss_percentile": 0.02483,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Canon Inc.",
      "product": "My Image Garden for macOS",
      "cwe": "CWE-59",
      "title": "Improper handling of symbolic links in the installer of My Image Garden for macOS Version 3.6.8 or earlier may allow a local attacker with login privileges to exploit a specially crafted symbolic link during installation to modify permissions of files for which they would not normally have authorization.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6891"
    },
    {
      "rank": 489,
      "cve_id": "CVE-2026-46230",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00122,
      "epss_percentile": 0.02384,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-125",
      "title": "drm/amdgpu/vcn3: Prevent OOB reads when parsing dec msg",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46230"
    },
    {
      "rank": 490,
      "cve_id": "CVE-2026-46106",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00122,
      "epss_percentile": 0.02333,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "eventfs: Hold eventfs_mutex and SRCU when remount walks events",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46106"
    },
    {
      "rank": 491,
      "cve_id": "CVE-2026-46139",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00122,
      "epss_percentile": 0.0237,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-908",
      "title": "smb: client: use kzalloc to zero-initialize security descriptor buffer",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46139"
    },
    {
      "rank": 492,
      "cve_id": "CVE-2026-46179",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00122,
      "epss_percentile": 0.02403,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ASoC: SOF: Don't allow pointer operations on unconfigured streams",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46179"
    },
    {
      "rank": 493,
      "cve_id": "CVE-2026-45366",
      "cvss_base": 4.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00122,
      "epss_percentile": 0.02386,
      "kev": false,
      "kev_due_at": null,
      "vendor": "universal-tool-calling-protocol",
      "product": "typescript-utcp",
      "cwe": "CWE-918",
      "title": "typescript-utcp: SSRF via attacker-controlled OpenAPI servers[0].url in HTTP communication protocol",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45366"
    },
    {
      "rank": 494,
      "cve_id": "CVE-2026-46104",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00121,
      "epss_percentile": 0.02253,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "selinux: use sk blob accessor in socket permission helpers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46104"
    },
    {
      "rank": 495,
      "cve_id": "CVE-2026-46118",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00121,
      "epss_percentile": 0.02233,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-476",
      "title": "pseries/papr-hvpipe: Fix null ptr deref in papr_hvpipe_dev_create_handle()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46118"
    },
    {
      "rank": 496,
      "cve_id": "CVE-2026-46141",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00121,
      "epss_percentile": 0.02245,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-401",
      "title": "powerpc/xive: fix kmemleak caused by incorrect chip_data lookup",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46141"
    },
    {
      "rank": 497,
      "cve_id": "CVE-2026-46148",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00121,
      "epss_percentile": 0.02224,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "spi: microchip-core-qspi: control built-in cs manually",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46148"
    },
    {
      "rank": 498,
      "cve_id": "CVE-2026-46192",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00121,
      "epss_percentile": 0.0226,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "spi: microchip-core-qspi: don't attempt to transmit during emulated read-only dual/quad operations",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46192"
    },
    {
      "rank": 499,
      "cve_id": "CVE-2026-46183",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0012,
      "epss_percentile": 0.02211,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-415",
      "title": "mm/damon/sysfs-schemes: protect path kfree() with damon_sysfs_lock",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46183"
    },
    {
      "rank": 500,
      "cve_id": "CVE-2026-46154",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.0012,
      "epss_percentile": 0.02161,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-416",
      "title": "sched_ext: Read scx_root under scx_cgroup_ops_rwsem in cgroup setters",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46154"
    },
    {
      "rank": 501,
      "cve_id": "CVE-2026-46220",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00119,
      "epss_percentile": 0.02102,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-617",
      "title": "drm/amdgpu/sdma4: replace BUG_ON with WARN_ON in fence emission",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46220"
    },
    {
      "rank": 502,
      "cve_id": "CVE-2026-46225",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00119,
      "epss_percentile": 0.02062,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "spi: rspi: fix controller deregistration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46225"
    },
    {
      "rank": 503,
      "cve_id": "CVE-2026-46226",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00119,
      "epss_percentile": 0.02055,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "spi: fsl: fix controller deregistration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46226"
    },
    {
      "rank": 504,
      "cve_id": "CVE-2026-46229",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00119,
      "epss_percentile": 0.02061,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/amdkfd: Clear VRAM on allocation to prevent stale data exposure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46229"
    },
    {
      "rank": 505,
      "cve_id": "CVE-2026-46231",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00119,
      "epss_percentile": 0.021,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "batman-adv: bla: put backbone reference on failed claim hash insert",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46231"
    },
    {
      "rank": 506,
      "cve_id": "CVE-2026-46233",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00119,
      "epss_percentile": 0.02101,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-476",
      "title": "batman-adv: bla: only purge non-released claims",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46233"
    },
    {
      "rank": 507,
      "cve_id": "CVE-2026-46235",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00119,
      "epss_percentile": 0.02102,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-476",
      "title": "media: saa7164: add ioremap return checks and cleanups",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46235"
    },
    {
      "rank": 508,
      "cve_id": "CVE-2026-46236",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00119,
      "epss_percentile": 0.021,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "media: rc: xbox_remote: heed DMA restrictions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46236"
    },
    {
      "rank": 509,
      "cve_id": "CVE-2026-46221",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00117,
      "epss_percentile": 0.0198,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-401",
      "title": "EDAC/versalnet: Fix device name memory leak",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46221"
    },
    {
      "rank": 510,
      "cve_id": "CVE-2026-46224",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00117,
      "epss_percentile": 0.0197,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-401",
      "title": "drm/xe: Fix bo leak in xe_dma_buf_init_obj() on allocation failure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46224"
    },
    {
      "rank": 511,
      "cve_id": "CVE-2026-46228",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00117,
      "epss_percentile": 0.01981,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-401",
      "title": "spi: ch341: fix devres lifetime",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46228"
    },
    {
      "rank": 512,
      "cve_id": "CVE-2026-35266",
      "cvss_base": 7.9,
      "cvss_severity": "HIGH",
      "epss_score": 0.00115,
      "epss_percentile": 0.01829,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle REST Data Services",
      "cwe": "CWE-400",
      "title": "Vulnerability in Oracle REST Data Services (component: Core). Supported versions that are affected are 24.2.0-26.1.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle REST Data Services. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle REST Data Services, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle REST Data Services accessible data as well as unauthorized access to critical data or complete access to all Oracle REST Data Services accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle REST Data Services. CVSS 3.1 Base Score 7.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-35266"
    },
    {
      "rank": 513,
      "cve_id": "CVE-2026-45353",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00114,
      "epss_percentile": 0.01774,
      "kev": false,
      "kev_due_at": null,
      "vendor": "electerm",
      "product": "electerm",
      "cwe": "CWE-94",
      "title": "electerm: Local code through electerm's single-instance socket",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45353"
    },
    {
      "rank": 514,
      "cve_id": "CVE-2026-46181",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00114,
      "epss_percentile": 0.0169,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-366",
      "title": "RDMA/mlx4: Fix mis-use of RCU in mlx4_srq_event()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46181"
    },
    {
      "rank": 515,
      "cve_id": "CVE-2026-47331",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00114,
      "epss_percentile": 0.0171,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Canonical",
      "product": "Ubuntu Linux",
      "cwe": "CWE-416",
      "title": "Use-after-free in Ubuntu Linux AppArmor notification handling",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47331"
    },
    {
      "rank": 516,
      "cve_id": "CVE-2026-46153",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00112,
      "epss_percentile": 0.01582,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "8021q: delete cleared egress QoS mappings",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46153"
    },
    {
      "rank": 517,
      "cve_id": "CVE-2026-46685",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00108,
      "epss_percentile": 0.01367,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rustfs",
      "product": "rustfs",
      "cwe": "CWE-306",
      "title": "RustFS: Reflective CORS with credentials on S3 listener; unauthenticated license metadata endpoint on console",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46685"
    },
    {
      "rank": 518,
      "cve_id": "CVE-2026-47333",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00107,
      "epss_percentile": 0.01291,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Canonical",
      "product": "Ubuntu Linux",
      "cwe": "CWE-125",
      "title": "Out-of-bounds read in Ubuntu Linux AppArmor notification handling",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47333"
    },
    {
      "rank": 519,
      "cve_id": "CVE-2026-9989",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00107,
      "epss_percentile": 0.01294,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-346",
      "title": "Inappropriate implementation in Media in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to bypass same origin policy via a crafted video file. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9989"
    },
    {
      "rank": 520,
      "cve_id": "CVE-2026-47332",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00106,
      "epss_percentile": 0.0128,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Canonical",
      "product": "Ubuntu Linux",
      "cwe": "CWE-125",
      "title": "Out-of-bounds read in Ubuntu Linux AppArmor notification handling",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47332"
    },
    {
      "rank": 521,
      "cve_id": "CVE-2026-45787",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00105,
      "epss_percentile": 0.01217,
      "kev": false,
      "kev_due_at": null,
      "vendor": "electerm",
      "product": "electerm",
      "cwe": "CWE-326",
      "title": "electerm's encrypt method not safe enough",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45787"
    },
    {
      "rank": 522,
      "cve_id": "CVE-2026-46222",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00105,
      "epss_percentile": 0.01199,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-476",
      "title": "media: rockchip: rkcif: Add missing MUST_CONNECT flag to pads",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46222"
    },
    {
      "rank": 523,
      "cve_id": "CVE-2026-46239",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00105,
      "epss_percentile": 0.012,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "media: i2c: ov5647: Fix runtime PM refcount leak in s_ctrl",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46239"
    },
    {
      "rank": 524,
      "cve_id": "CVE-2026-46227",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00104,
      "epss_percentile": 0.01146,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-416",
      "title": "sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46227"
    },
    {
      "rank": 525,
      "cve_id": "CVE-2026-46112",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.001,
      "epss_percentile": 0.00961,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-667",
      "title": "RDMA/hns: Fix unlocked call to hns_roce_qp_remove()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46112"
    },
    {
      "rank": 526,
      "cve_id": "CVE-2026-9987",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00099,
      "epss_percentile": 0.00943,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in WebAppInstalls in Google Chrome on Android prior to 148.0.7778.216 allowed a local attacker to execute arbitrary code via a malicious file. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9987"
    },
    {
      "rank": 527,
      "cve_id": "CVE-2026-46157",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00099,
      "epss_percentile": 0.00944,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-362",
      "title": "ALSA: pcm: oss: Fix data race at accessing runtime.oss.trigger",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46157"
    },
    {
      "rank": 528,
      "cve_id": "CVE-2026-46165",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00099,
      "epss_percentile": 0.00922,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-667",
      "title": "openvswitch: vport: fix self-deadlock on release of tunnel ports",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46165"
    },
    {
      "rank": 529,
      "cve_id": "CVE-2026-34126",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00097,
      "epss_percentile": 0.00833,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TP-Link Systems Inc.",
      "product": "Tapo L535E v1.0, v3.0",
      "cwe": "CWE-319",
      "title": "Bluetooth Communication Uses Unencrypted Transmission During Initial Setup on TP-Link's Tapo L535E, P300 and D100C",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34126"
    },
    {
      "rank": 530,
      "cve_id": "CVE-2026-47335",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00097,
      "epss_percentile": 0.00858,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Canonical",
      "product": "Ubuntu Linux",
      "cwe": "CWE-476",
      "title": "NULL pointer dereference in Ubuntu Linux AppArmor notification handling",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47335"
    },
    {
      "rank": 531,
      "cve_id": "CVE-2026-46156",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00095,
      "epss_percentile": 0.00722,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-667",
      "title": "LoongArch: Fix potential ADE in loongson_gpu_fixup_dma_hang()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46156"
    },
    {
      "rank": 532,
      "cve_id": "CVE-2026-47336",
      "cvss_base": 3.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00094,
      "epss_percentile": 0.00697,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Canonical",
      "product": "Ubuntu Linux",
      "cwe": "CWE-457",
      "title": "Use of uninitialized value in Ubuntu Linux AppArmor IPv4/IPv6 socket mediation rules",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47336"
    },
    {
      "rank": 533,
      "cve_id": "CVE-2026-47337",
      "cvss_base": 3.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00094,
      "epss_percentile": 0.00677,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Canonical",
      "product": "Ubuntu Linux",
      "cwe": "CWE-476",
      "title": "NULL pointer dereference in Ubuntu Linux AppArmor IPv4/IPv6 socket mediation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47337"
    },
    {
      "rank": 534,
      "cve_id": "CVE-2026-47328",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00093,
      "epss_percentile": 0.00666,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Canonical",
      "product": "Ubuntu Linux",
      "cwe": "CWE-590",
      "title": "Invalid pointer deallocation in Ubuntu Linux AppArmor notification handling",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47328"
    },
    {
      "rank": 535,
      "cve_id": "CVE-2026-47326",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00093,
      "epss_percentile": 0.00667,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Canonical",
      "product": "Ubuntu Linux",
      "cwe": "CWE-401",
      "title": "Memory leak in Ubuntu Linux AppArmor large notification response allocation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47326"
    },
    {
      "rank": 536,
      "cve_id": "CVE-2026-46159",
      "cvss_base": 4.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00093,
      "epss_percentile": 0.00662,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-367",
      "title": "btrfs: fix btrfs_ioctl_space_info() slot_count TOCTOU which can lead to info-leak",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46159"
    },
    {
      "rank": 537,
      "cve_id": "CVE-2026-46187",
      "cvss_base": 4.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00093,
      "epss_percentile": 0.00662,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-362",
      "title": "wifi: rsi: fix kthread lifetime race between self-exit and external-stop",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46187"
    },
    {
      "rank": 538,
      "cve_id": "CVE-2026-47329",
      "cvss_base": 3.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00092,
      "epss_percentile": 0.006,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Canonical",
      "product": "Ubuntu Linux",
      "cwe": "CWE-1284",
      "title": "Incorrect validation of field size in Ubuntu Linux AppArmor notification responses",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47329"
    },
    {
      "rank": 539,
      "cve_id": "CVE-2026-47330",
      "cvss_base": 3.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00092,
      "epss_percentile": 0.00601,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Canonical",
      "product": "Ubuntu Linux",
      "cwe": "CWE-457",
      "title": "Use of uninitialized value in Ubuntu Linux AppArmor notification handling",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47330"
    },
    {
      "rank": 540,
      "cve_id": "CVE-2026-47327",
      "cvss_base": 3.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00091,
      "epss_percentile": 0.0058,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Canonical",
      "product": "Ubuntu Linux",
      "cwe": "CWE-476",
      "title": "NULL pointer dereference in Ubuntu Linux AppArmor notification handling",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47327"
    },
    {
      "rank": 541,
      "cve_id": "CVE-2026-46223",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00083,
      "epss_percentile": 0.00304,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-667",
      "title": "cgroup: Defer css percpu_ref kill on rmdir until cgroup is depopulated",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46223"
    },
    {
      "rank": 542,
      "cve_id": "CVE-2026-47334",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00078,
      "epss_percentile": 0.00148,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Canonical",
      "product": "Ubuntu Linux",
      "cwe": "CWE-833",
      "title": "Deadlock or kernel panic in Ubuntu Linux AppArmor notification handling",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47334"
    }
  ],
  "transactions": [
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-32847",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-32847 (HKUDS DeepCode). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-42998",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-42998 (OpenStack Keystone). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-42999",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-42999 (OpenStack Keystone). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-43000",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-43000 (OpenStack Keystone). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-43898",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-43898 (nyariv SandboxJS). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-44394",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-44394 (OpenStack Keystone). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-44461",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-44461 (zed-industries zed). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-44462",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-44462 (zed-industries zed). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-44463",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-44463 (zed-industries zed). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-44465",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-44465 (zed-industries zed). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-44466",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-44466 (zed-industries zed). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-44848",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-44848 (portainer). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-44849",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-44849 (portainer). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-44850",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-44850 (portainer). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-44881",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-44881 (portainer). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-44882",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-44882 (portainer). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-44883",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-44883 (portainer). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-44884",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-44884 (portainer). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-44885",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-44885 (portainer). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-45323",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-45323 (jpettitt meshcore-card). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-45403",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-45403 (Mintplex-Labs anything-llm). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-47713",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-47713 (Mintplex-Labs anything-llm). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-48116",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-48116 (Mintplex-Labs anything-llm). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-48522",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-48522 (jpadilla pyjwt). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-48523",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-48523 (jpadilla pyjwt). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-48525",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-48525 (jpadilla pyjwt). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-48526",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-48526 (jpadilla pyjwt). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-49237",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-49237 (Canonical Multipass). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-49238",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-49238 (Canonical Multipass). Public exploit reference added."
    },
    {
      "type": "DUE_DATE_PASSED",
      "cve_id": "CVE-2026-9082",
      "detail": "DUE DATE PASSED — CVE-2026-9082 (Drupal core). CISA remediation deadline was May 27, 2026; still in catalog."
    }
  ],
  "attribution": "CVE Program, NVD (NIST), CISA KEV, FIRST EPSS, OSV. See /security/methodology/."
}
