{
  "day": "2026-05-29",
  "boundary": "UTC calendar day",
  "published_count": 249,
  "by_severity": {
    "CRITICAL": 44,
    "HIGH": 105,
    "MEDIUM": 83,
    "LOW": 16
  },
  "kev_count": 1,
  "exploit_reference_count": 17,
  "awaiting_enrichment_count": 1,
  "ranking": "Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.",
  "results": [
    {
      "rank": 1,
      "cve_id": "CVE-2026-0257",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.93905,
      "epss_percentile": 0.99837,
      "kev": true,
      "kev_due_at": "2026-06-01",
      "vendor": "Palo Alto Networks",
      "product": "PAN-OS",
      "cwe": null,
      "title": "Palo Alto Networks PAN-OS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-0257"
    },
    {
      "rank": 2,
      "cve_id": "CVE-2026-8732",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.19272,
      "epss_percentile": 0.97117,
      "kev": false,
      "kev_due_at": null,
      "vendor": "flippercode",
      "product": "WP Maps Pro",
      "cwe": "CWE-306",
      "title": "WP Maps Pro <= 6.1.0 - Unauthenticated Privilege Escalation via Administrator Account Creation to wpgmp_temp_access_ajax AJAX Action",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8732"
    },
    {
      "rank": 3,
      "cve_id": "CVE-2026-49373",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.13026,
      "epss_percentile": 0.96023,
      "kev": false,
      "kev_due_at": null,
      "vendor": "JetBrains",
      "product": "TeamCity",
      "cwe": "CWE-88",
      "title": "In JetBrains TeamCity before 2026.1 remote code execution was possible via Perforce connection settings",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49373"
    },
    {
      "rank": 4,
      "cve_id": "CVE-2026-10060",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.0501,
      "epss_percentile": 0.91552,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TRENDnet",
      "product": "TEW-432BRP",
      "cwe": "CWE-74",
      "title": "TRENDnet TEW-432BRP formSetRoute command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10060"
    },
    {
      "rank": 5,
      "cve_id": "CVE-2026-10061",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.0501,
      "epss_percentile": 0.91553,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TRENDnet",
      "product": "TEW-432BRP",
      "cwe": "CWE-74",
      "title": "TRENDnet TEW-432BRP formWPS command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10061"
    },
    {
      "rank": 6,
      "cve_id": "CVE-2026-44420",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.03665,
      "epss_percentile": 0.88738,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FreeRDP",
      "product": "FreeRDP",
      "cwe": "CWE-122",
      "title": "FreeRDP cliprdr server heap-buffer-overflow via undersized capabilitySetLength in CB_CLIP_CAPS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44420"
    },
    {
      "rank": 7,
      "cve_id": "CVE-2025-41269",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0138,
      "epss_percentile": 0.69934,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Waterfall",
      "product": "WF-500",
      "cwe": "CWE-78",
      "title": "Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Console WebUI in Waterfall WF-500 TX and RX Hosts in version 7.9.1.0 R2502171040 that allows remote unauthenticated attackers to execute arbitrary operating system commands on the device.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-41269"
    },
    {
      "rank": 8,
      "cve_id": "CVE-2025-41270",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0138,
      "epss_percentile": 0.69934,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Waterfall",
      "product": "WF-500",
      "cwe": "CWE-78",
      "title": "Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Console WebUI in Waterfall WF-500 TX and RX Hosts in version 7.9.1.0 R2502171040 that allows remote unauthenticated attackers to execute arbitrary operating system commands on the device.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-41270"
    },
    {
      "rank": 9,
      "cve_id": "CVE-2025-41272",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0138,
      "epss_percentile": 0.69933,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Waterfall",
      "product": "WF-500",
      "cwe": "CWE-78",
      "title": "Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Console WebUI in Waterfall WF-500 TX and RX Hosts in version 7.9.1.0 R2502171040 that allows remote unauthenticated attackers to execute arbitrary operating system commands on the device.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-41272"
    },
    {
      "rank": 10,
      "cve_id": "CVE-2025-41274",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0138,
      "epss_percentile": 0.69934,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Waterfall",
      "product": "WF-500",
      "cwe": "CWE-78",
      "title": "Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Console WebUI in Waterfall WF-500 TX and RX Hosts in version 7.9.1.0 R2502171040 that allows remote unauthenticated attackers to execute arbitrary operating system commands on the device.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-41274"
    },
    {
      "rank": 11,
      "cve_id": "CVE-2025-41275",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0138,
      "epss_percentile": 0.69933,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Waterfall",
      "product": "WF-500",
      "cwe": "CWE-78",
      "title": "Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Console WebUI in Waterfall WF-500 TX and RX Hosts in version 7.9.1.0 R2502171040 that allows remote unauthenticated attackers to execute arbitrary operating system commands on the device.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-41275"
    },
    {
      "rank": 12,
      "cve_id": "CVE-2025-41276",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0138,
      "epss_percentile": 0.69935,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Waterfall",
      "product": "WF-500",
      "cwe": "CWE-78",
      "title": "Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Console WebUI in Waterfall WF-500 TX and RX Hosts in version 7.9.1.0 R2502171040 that allows remote unauthenticated attackers to execute arbitrary operating system commands on the device.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-41276"
    },
    {
      "rank": 13,
      "cve_id": "CVE-2025-41277",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0138,
      "epss_percentile": 0.69934,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Waterfall",
      "product": "WF-500",
      "cwe": "CWE-78",
      "title": "Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Console WebUI in Waterfall WF-500 TX and RX Hosts in version 7.9.1.0 R2502171040 that allows remote unauthenticated attackers to execute arbitrary operating system commands on the device.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-41277"
    },
    {
      "rank": 14,
      "cve_id": "CVE-2026-49199",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.01338,
      "epss_percentile": 0.68984,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Acer",
      "product": "Predator Connect W6x",
      "cwe": "CWE-77",
      "title": "Predator Connect W6x: RCE via MQTT",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49199"
    },
    {
      "rank": 15,
      "cve_id": "CVE-2026-45633",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00922,
      "epss_percentile": 0.57552,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dokploy",
      "product": "dokploy",
      "cwe": "CWE-78",
      "title": "Dokploy: Command Injection in /docker-container-logs Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45633"
    },
    {
      "rank": 16,
      "cve_id": "CVE-2025-41265",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00882,
      "epss_percentile": 0.56357,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Waterfall",
      "product": "WF-500",
      "cwe": "CWE-78",
      "title": "Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Administration WebUI in Waterfall WF-500 TX Host in version 7.9.1.0 R2502171040 that allows remote authenticated attackers to execute arbitrary operating system commands on the WF-500 TX Host.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-41265"
    },
    {
      "rank": 17,
      "cve_id": "CVE-2025-41266",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00882,
      "epss_percentile": 0.56357,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Waterfall",
      "product": "WF-500",
      "cwe": "CWE-78",
      "title": "Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Administration WebUI in Waterfall WF-500 TX Host in version 7.9.1.0 R2502171040 that allows remote authenticated attackers to execute arbitrary operating system commands on the WF-500 TX Host.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-41266"
    },
    {
      "rank": 18,
      "cve_id": "CVE-2025-41279",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00882,
      "epss_percentile": 0.56357,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Waterfall",
      "product": "WF-500",
      "cwe": "CWE-78",
      "title": "Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Administration WebUI in Waterfall WF-500 RX Host in version 7.9.1.0 R2502171040 that allows remote authenticated attackers to execute arbitrary operating system commands on the WF-500 RX Host.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-41279"
    },
    {
      "rank": 19,
      "cve_id": "CVE-2025-41267",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00882,
      "epss_percentile": 0.56357,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Waterfall",
      "product": "WF-500",
      "cwe": "CWE-78",
      "title": "Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Administration WebUI in Waterfall WF-500 TX Host in version 7.9.1.0 R2502171040 that allows remote authenticated attackers to execute arbitrary operating system commands on the WF-500 TX Host.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-41267"
    },
    {
      "rank": 20,
      "cve_id": "CVE-2026-6324",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00872,
      "epss_percentile": 0.5608,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-444",
      "title": "Libsoup: libsoup: http request smuggling via unsigned to signed conversion error",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6324"
    },
    {
      "rank": 21,
      "cve_id": "CVE-2026-45663",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00866,
      "epss_percentile": 0.55846,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dokploy",
      "product": "dokploy",
      "cwe": "CWE-77",
      "title": "Dokploy: Remote Code Execution via destinationPath in Container File Upload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45663"
    },
    {
      "rank": 22,
      "cve_id": "CVE-2026-46372",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00866,
      "epss_percentile": 0.55857,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SillyTavern",
      "product": "SillyTavern",
      "cwe": "CWE-918",
      "title": "SillyTavern: SSRF in SearXNG Search Proxy via Unvalidated baseUrl",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46372"
    },
    {
      "rank": 23,
      "cve_id": "CVE-2026-10063",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00853,
      "epss_percentile": 0.55422,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TRENDnet",
      "product": "TEW-432BRP",
      "cwe": "CWE-119",
      "title": "TRENDnet TEW-432BRP formWPS stack-based overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10063"
    },
    {
      "rank": 24,
      "cve_id": "CVE-2026-45662",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00841,
      "epss_percentile": 0.55044,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dokploy",
      "product": "dokploy",
      "cwe": "CWE-78",
      "title": "Dokploy: Command Injection via incomplete shell escaping in docker logout (registry deletion)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45662"
    },
    {
      "rank": 25,
      "cve_id": "CVE-2026-10062",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00835,
      "epss_percentile": 0.5489,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TRENDnet",
      "product": "TEW-432BRP",
      "cwe": "CWE-119",
      "title": "TRENDnet TEW-432BRP formSetRoute stack-based overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10062"
    },
    {
      "rank": 26,
      "cve_id": "CVE-2026-39276",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00782,
      "epss_percentile": 0.53175,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-22",
      "title": "The template upload feature in Emlog Pro v2.6.9 has a path traversal vulnerability, allowing authenticated administrators to execute arbitrary PHP code. By uploading a malicious ZIP archive containing directory traversal sequences in filenames, an attacker can overwrite default template files or directly include malicious code files in the current template.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39276"
    },
    {
      "rank": 27,
      "cve_id": "CVE-2026-45630",
      "cvss_base": 9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00763,
      "epss_percentile": 0.52561,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dokploy",
      "product": "dokploy",
      "cwe": "CWE-78",
      "title": "Dokploy: Authenticated Remote Code Execution via Command Injection in updateTraefikConfig Echo Statement",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45630"
    },
    {
      "rank": 28,
      "cve_id": "CVE-2026-45629",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00758,
      "epss_percentile": 0.52375,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dokploy",
      "product": "dokploy",
      "cwe": "CWE-78",
      "title": "Dokploy: Authenticated Remote Code Execution via Command Injection in /listen-deployment WebSocket Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45629"
    },
    {
      "rank": 29,
      "cve_id": "CVE-2026-49377",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00695,
      "epss_percentile": 0.50163,
      "kev": false,
      "kev_due_at": null,
      "vendor": "JetBrains",
      "product": "TeamCity",
      "cwe": "CWE-526",
      "title": "In JetBrains TeamCity before 2025.11.2 exposure of sensitive data via default agent parameters",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49377"
    },
    {
      "rank": 30,
      "cve_id": "CVE-2026-44962",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00686,
      "epss_percentile": 0.49839,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WebPros",
      "product": "Plesk",
      "cwe": "CWE-643",
      "title": "Plesk contains an XPath injection vulnerability in the APS Application Catalog search functionality, where user-supplied input is interpolated into XPath queries without proper sanitization. This allows an authenticated, low-privileged user to execute arbitrary operating system commands on the server, resulting in local privilege escalation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44962"
    },
    {
      "rank": 31,
      "cve_id": "CVE-2026-45661",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0066,
      "epss_percentile": 0.48816,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dokploy",
      "product": "dokploy",
      "cwe": "CWE-22",
      "title": "Dokploy: Remote Code Execution through Path Traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45661"
    },
    {
      "rank": 32,
      "cve_id": "CVE-2026-45700",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00629,
      "epss_percentile": 0.47433,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FreeRDP",
      "product": "FreeRDP",
      "cwe": "CWE-787",
      "title": "Heap-buffer-overflow write in planar bitmap decoder",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45700"
    },
    {
      "rank": 33,
      "cve_id": "CVE-2026-5386",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00624,
      "epss_percentile": 0.47256,
      "kev": false,
      "kev_due_at": null,
      "vendor": "KMW",
      "product": "KM-IP521",
      "cwe": "CWE-620",
      "title": "KMW CCTV Security Cameras Unverified Password Change",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-5386"
    },
    {
      "rank": 34,
      "cve_id": "CVE-2026-9051",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00623,
      "epss_percentile": 0.47205,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NI",
      "product": "SystemLink Enterprise",
      "cwe": "CWE-306",
      "title": "Authentication Bypass Vulnerability in NI SystemLink Enterprise",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9051"
    },
    {
      "rank": 35,
      "cve_id": "CVE-2026-10042",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00622,
      "epss_percentile": 0.47145,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zyddnys",
      "product": "manga-image-translator",
      "cwe": "CWE-502",
      "title": "manga-image-translator RCE via Unsafe Pickle Deserialization in Share Model",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10042"
    },
    {
      "rank": 36,
      "cve_id": "CVE-2026-9559",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00583,
      "epss_percentile": 0.45312,
      "kev": false,
      "kev_due_at": null,
      "vendor": null,
      "product": "mautic/core",
      "cwe": "CWE-22",
      "title": "A path traversal vulnerability exists in the campaign import feature of Mautic 7. When extracting uploaded ZIP files during campaign imports, a flaw in the validation logic allows file paths to escape the intended temporary directories. An authenticated user with campaign import privileges (campaign:imports:create) can write arbitrary PHP files to sensitive system directories. An attacker can exploit this to overwrite critical internal configuration or cache components, resulting in Remote Code Execution (RCE) under the context of the web server user.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9559"
    },
    {
      "rank": 37,
      "cve_id": "CVE-2026-9558",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00571,
      "epss_percentile": 0.44721,
      "kev": false,
      "kev_due_at": null,
      "vendor": null,
      "product": "mautic/core",
      "cwe": "CWE-1336",
      "title": "A Server-Side Template Injection (SSTI) vulnerability exists in Mautic's theme engine. The platform renders uploaded Twig templates without a sandbox or strict function restrictions. Authenticated users with permissions to create or upload themes can abuse this to execute arbitrary code on the hosting server (Remote Code Execution) or access restricted system files and configuration settings.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9558"
    },
    {
      "rank": 38,
      "cve_id": "CVE-2026-44650",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00567,
      "epss_percentile": 0.44538,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SillyTavern",
      "product": "SillyTavern",
      "cwe": "CWE-22",
      "title": "SillyTavern: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44650"
    },
    {
      "rank": 39,
      "cve_id": "CVE-2018-25393",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00565,
      "epss_percentile": 0.4445,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Navigatecms",
      "product": "Navigate CMS",
      "cwe": "CWE-22",
      "title": "Navigate CMS 2.8.5 Path Traversal via navigate_download.php",
      "url": "https://www.cve.org/CVERecord?id=CVE-2018-25393"
    },
    {
      "rank": 40,
      "cve_id": "CVE-2026-46384",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00529,
      "epss_percentile": 0.42515,
      "kev": false,
      "kev_due_at": null,
      "vendor": "iskorotkov",
      "product": "avro",
      "cwe": "CWE-190",
      "title": "iskorotkov/avro: Integer Overflow in Avro Decoder",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46384"
    },
    {
      "rank": 41,
      "cve_id": "CVE-2018-25388",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00519,
      "epss_percentile": 0.41962,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Sitejo",
      "product": "HaPe PKH",
      "cwe": "CWE-434",
      "title": "HaPe PKH 1.1 Arbitrary File Upload via aksi_foto.php",
      "url": "https://www.cve.org/CVERecord?id=CVE-2018-25388"
    },
    {
      "rank": 42,
      "cve_id": "CVE-2026-49200",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00518,
      "epss_percentile": 0.41867,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Acer",
      "product": "Wave 7 router",
      "cwe": "CWE-532",
      "title": "Acer Wave 7 router: Broken Access Control",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49200"
    },
    {
      "rank": 43,
      "cve_id": "CVE-2026-10108",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00513,
      "epss_percentile": 0.41566,
      "kev": false,
      "kev_due_at": null,
      "vendor": "hanxi",
      "product": "xiaomusic",
      "cwe": "CWE-22",
      "title": "xiaomusic 0.5.7 Path Traversal via GET /music endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10108"
    },
    {
      "rank": 44,
      "cve_id": "CVE-2026-3655",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0051,
      "epss_percentile": 0.41399,
      "kev": false,
      "kev_due_at": null,
      "vendor": "glboy",
      "product": "OTP Login With Phone Number, OTP Verification",
      "cwe": "CWE-287",
      "title": "OTP Login With Phone Number, OTP Verification <= 1.8.60 - Unauthenticated Authentication Bypass via Firebase OTP Verification",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-3655"
    },
    {
      "rank": 45,
      "cve_id": "CVE-2026-10071",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00508,
      "epss_percentile": 0.41246,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Interinfo",
      "product": "DreamMaker",
      "cwe": "CWE-434",
      "title": "Interinfo｜DreamMaker - Arbitrary File Upload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10071"
    },
    {
      "rank": 46,
      "cve_id": "CVE-2026-44421",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00507,
      "epss_percentile": 0.41173,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FreeRDP",
      "product": "FreeRDP",
      "cwe": "CWE-122",
      "title": "FreeRDP RDPGFX CacheToSurface heap-buffer-overflow via clamped-rectangle validation bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44421"
    },
    {
      "rank": 47,
      "cve_id": "CVE-2025-41281",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00505,
      "epss_percentile": 0.41087,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Waterfall",
      "product": "WF-500",
      "cwe": "CWE-78",
      "title": "Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in Waterfall WF-500 RX Host in version 7.9.1.0 R2502171040 that allows attackers with access to the TX Host to execute code on the RX Host when a MySQL connector is configured.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-41281"
    },
    {
      "rank": 48,
      "cve_id": "CVE-2026-46385",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00504,
      "epss_percentile": 0.40982,
      "kev": false,
      "kev_due_at": null,
      "vendor": "iskorotkov",
      "product": "avro",
      "cwe": "CWE-400",
      "title": "iskorotkov/avro: CPU Exhaustion in Avro Decoder",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46385"
    },
    {
      "rank": 49,
      "cve_id": "CVE-2026-45697",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00475,
      "epss_percentile": 0.39253,
      "kev": false,
      "kev_due_at": null,
      "vendor": "verbb",
      "product": "formie",
      "cwe": "CWE-94",
      "title": "Formie: Pre-authenticated server-side template injection in Hidden fields",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45697"
    },
    {
      "rank": 50,
      "cve_id": "CVE-2026-39292",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00472,
      "epss_percentile": 0.39011,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-434",
      "title": "Falco Solutions PHPPageBuilder v0.31.0 contains an unrestricted file upload vulnerability in the pagemanager/pagebuilder module that allows remote attackers to upload arbitrary files and achieve remote code execution. The vulnerability exists due to insufficient validation of uploaded file types and executable content.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39292"
    },
    {
      "rank": 51,
      "cve_id": "CVE-2026-45731",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00469,
      "epss_percentile": 0.38826,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WWBN",
      "product": "AVideo",
      "cwe": "CWE-22",
      "title": "WWBN AVideo: Authenticated Arbitrary File Read in view/update.php",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45731"
    },
    {
      "rank": 52,
      "cve_id": "CVE-2026-10072",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00456,
      "epss_percentile": 0.37963,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Interinfo",
      "product": "DreamMaker",
      "cwe": "CWE-434",
      "title": "Interinfo｜DreamMaker - Arbitrary File Upload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10072"
    },
    {
      "rank": 53,
      "cve_id": "CVE-2026-49366",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00455,
      "epss_percentile": 0.37928,
      "kev": false,
      "kev_due_at": null,
      "vendor": "JetBrains",
      "product": "IntelliJ IDEA",
      "cwe": "CWE-78",
      "title": "In JetBrains IntelliJ IDEA before 2026.1.1 command injection was possible via filename completion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49366"
    },
    {
      "rank": 54,
      "cve_id": "CVE-2026-46337",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00455,
      "epss_percentile": 0.37951,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WWBN",
      "product": "AVideo",
      "cwe": "CWE-22",
      "title": "WWBN AVideo: Unauthenticated Arbitrary Image Read via Path Traversal in `view/img/image404Raw.php`",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46337"
    },
    {
      "rank": 55,
      "cve_id": "CVE-2026-48557",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.0044,
      "epss_percentile": 0.368,
      "kev": false,
      "kev_due_at": null,
      "vendor": "spatie",
      "product": "laravel-medialibrary",
      "cwe": "CWE-184",
      "title": "Spatie Laravel Media Library < 11.23.0 File Upload Restriction Bypass via FileAdder.php",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48557"
    },
    {
      "rank": 56,
      "cve_id": "CVE-2026-10065",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00438,
      "epss_percentile": 0.3664,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Shibby",
      "product": "Tomato",
      "cwe": "CWE-119",
      "title": "Shibby Tomato tomatodata.cgi get_ups_field stack-based overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10065"
    },
    {
      "rank": 57,
      "cve_id": "CVE-2026-10066",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00438,
      "epss_percentile": 0.36641,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Shibby",
      "product": "Tomato",
      "cwe": "CWE-119",
      "title": "Shibby Tomato UPS Service tomatoups.cgi sub_9068 stack-based overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10066"
    },
    {
      "rank": 58,
      "cve_id": "CVE-2026-10067",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00438,
      "epss_percentile": 0.36638,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Shibby",
      "product": "Tomato",
      "cwe": "CWE-119",
      "title": "Shibby Tomato multimon.cgi sub_90F0 stack-based overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10067"
    },
    {
      "rank": 59,
      "cve_id": "CVE-2026-10069",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00438,
      "epss_percentile": 0.36653,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Shibby",
      "product": "Tomato",
      "cwe": "CWE-400",
      "title": "Shibby Tomato miniupnpd resource consumption",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10069"
    },
    {
      "rank": 60,
      "cve_id": "CVE-2025-41268",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00437,
      "epss_percentile": 0.36569,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Waterfall",
      "product": "WF-500",
      "cwe": "CWE-23",
      "title": "Nozomi Networks Labs identified a CWE-23: Relative Path Traversal in the Administration WebUI in Waterfall WF-500 TX and RX Hosts in version 7.9.1.0 R2502171040 that allows remote unauthenticated attackers to delete arbitrary files on the Host machines.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-41268"
    },
    {
      "rank": 61,
      "cve_id": "CVE-2025-41271",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00434,
      "epss_percentile": 0.3635,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Waterfall",
      "product": "WF-500",
      "cwe": "CWE-23",
      "title": "Nozomi Networks Labs identified a CWE-23: Relative Path Traversal in the Console WebUI in Waterfall WF-500 TX and RX Hosts in version 7.9.1.0 R2502171040 that allows remote unauthenticated attackers to read arbitrary files from the device.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-41271"
    },
    {
      "rank": 62,
      "cve_id": "CVE-2026-44422",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00431,
      "epss_percentile": 0.36059,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FreeRDP",
      "product": "FreeRDP",
      "cwe": "CWE-415",
      "title": "FreeRDP RDPEAR NDR ref-id aliasing causes client-side UAF/double-free and type confusion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44422"
    },
    {
      "rank": 63,
      "cve_id": "CVE-2026-46376",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00425,
      "epss_percentile": 0.35633,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FreePBX",
      "product": "security-reporting",
      "cwe": "CWE-798",
      "title": "FreePBX: Unauthenticated Use of Hard-Coded Credentials Vulnerability in FreePBX UCP Interface",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46376"
    },
    {
      "rank": 64,
      "cve_id": "CVE-2026-7786",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00415,
      "epss_percentile": 0.34785,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jinan USR IOT Technology Limited (PUSR)",
      "product": "USR-W610 RS232/485 to Wi-Fi/Ethernet Converter",
      "cwe": "CWE-798",
      "title": "Jinan USR IOT Technology Limited (PUSR) USR-W610 RS232/485 to Wi-Fi/Ethernet Converter Use of Hard-coded Credentials",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7786"
    },
    {
      "rank": 65,
      "cve_id": "CVE-2025-12714",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00411,
      "epss_percentile": 0.34427,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rankmath",
      "product": "Rank Math SEO – AI SEO Tools to Dominate SEO Rankings",
      "cwe": "CWE-862",
      "title": "Rank Math SEO – AI SEO Tools to Dominate SEO Rankings <= 1.0.271 - Missing Authorization to Unauthenticated Homepage Settings Modification",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-12714"
    },
    {
      "rank": 66,
      "cve_id": "CVE-2025-41273",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00407,
      "epss_percentile": 0.34073,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Waterfall",
      "product": "WF-500",
      "cwe": "CWE-288",
      "title": "Nozomi Networks Labs identified a CWE-288: Authentication Bypass Using an Alternate Path or Channel in the Console WebUI in Waterfall WF-500 TX and RX Hosts in version 7.9.1.0 R2502171040 that allows remote unauthenticated attackers to bypass authentication of the Console web application and perform actions as an authenticated user.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-41273"
    },
    {
      "rank": 67,
      "cve_id": "CVE-2026-10064",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00399,
      "epss_percentile": 0.33224,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TRENDnet",
      "product": "TEW-432BRP",
      "cwe": "CWE-119",
      "title": "TRENDnet TEW-432BRP formSetPortTr stack-based overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10064"
    },
    {
      "rank": 68,
      "cve_id": "CVE-2026-41159",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00398,
      "epss_percentile": 0.33194,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mermaid-js",
      "product": "mermaid",
      "cwe": "CWE-94",
      "title": "Mermaid: Improper sanitization of configuration leads to CSS injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41159"
    },
    {
      "rank": 69,
      "cve_id": "CVE-2026-44648",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00394,
      "epss_percentile": 0.32776,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SillyTavern",
      "product": "SillyTavern",
      "cwe": "CWE-613",
      "title": "SillyTavern: Existing sessions are not invalidated after password change, allowing session reuse and account takeover",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44648"
    },
    {
      "rank": 70,
      "cve_id": "CVE-2026-45625",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00387,
      "epss_percentile": 0.32094,
      "kev": false,
      "kev_due_at": null,
      "vendor": "getarcaneapp",
      "product": "arcane",
      "cwe": "CWE-862",
      "title": "Arcane: Missing admin authorization on git repository endpoints allows non-admin users to exfiltrate stored Git credentials and tamper with GitOps configs",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45625"
    },
    {
      "rank": 71,
      "cve_id": "CVE-2026-10075",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00387,
      "epss_percentile": 0.32015,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Interinfo",
      "product": "DreamMaker",
      "cwe": "CWE-36",
      "title": "Interinfo｜DreamMaker - Path Traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10075"
    },
    {
      "rank": 72,
      "cve_id": "CVE-2026-41150",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00384,
      "epss_percentile": 0.31734,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mermaid-js",
      "product": "mermaid",
      "cwe": "CWE-835",
      "title": "Mermaid Gantt Charts are vulnerable to an Infinite Loop DoS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41150"
    },
    {
      "rank": 73,
      "cve_id": "CVE-2026-42500",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00384,
      "epss_percentile": 0.31734,
      "kev": false,
      "kev_due_at": null,
      "vendor": "golang.org/x/image",
      "product": "golang.org/x/image/bmp",
      "cwe": null,
      "title": "Panic when reading out of bound palette index in golang.org/x/image/bmp",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42500"
    },
    {
      "rank": 74,
      "cve_id": "CVE-2026-44697",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.0038,
      "epss_percentile": 0.31293,
      "kev": false,
      "kev_due_at": null,
      "vendor": "klever-io",
      "product": "klever-go",
      "cwe": "CWE-409",
      "title": "Klever-Go MultiDataInterceptor: remote OOM via crafted compressed P2P payload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44697"
    },
    {
      "rank": 75,
      "cve_id": "CVE-2026-8326",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00378,
      "epss_percentile": 0.31096,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Remote Spark (https://www.remotespark.com/)",
      "product": "SparkView",
      "cwe": "CWE-23",
      "title": "Remote Spark SparkView Path Traversal in RDP Drive Redirection leading to RCE",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8326"
    },
    {
      "rank": 76,
      "cve_id": "CVE-2025-11993",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00378,
      "epss_percentile": 0.31047,
      "kev": false,
      "kev_due_at": null,
      "vendor": "sbthemes",
      "product": "WooCommerce Infinite Scroll and Ajax Pagination",
      "cwe": "CWE-502",
      "title": "WooCommerce Infinite Scroll and Ajax Pagination <= 1.8 - Authenticated (Subscriber+) PHP Object Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-11993"
    },
    {
      "rank": 77,
      "cve_id": "CVE-2026-40425",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00376,
      "epss_percentile": 0.30847,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Danelec",
      "product": "MacGregor Voyage Data Recorder (VDR) G4e",
      "cwe": "CWE-552",
      "title": "MacGregor Voyage Data Recorder (VDR) G4e Files or Directories Accessible to External Parties",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40425"
    },
    {
      "rank": 78,
      "cve_id": "CVE-2026-44652",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00375,
      "epss_percentile": 0.30762,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SillyTavern",
      "product": "SillyTavern",
      "cwe": "CWE-918",
      "title": "SillyTavern: SSRF vulnerability in the CORS proxy middleware",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44652"
    },
    {
      "rank": 79,
      "cve_id": "CVE-2026-6824",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00373,
      "epss_percentile": 0.30558,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CP Plus",
      "product": "CP-UNR-108F1 Hardware",
      "cwe": "CWE-79",
      "title": "CP Plus 8 Ch. Network Video Recorder Cross-site Scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6824"
    },
    {
      "rank": 80,
      "cve_id": "CVE-2026-49196",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.0037,
      "epss_percentile": 0.30231,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Acer",
      "product": "Predator Connect W6x",
      "cwe": "CWE-77",
      "title": "Predator Connect W6x: Web Interface Command Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49196"
    },
    {
      "rank": 81,
      "cve_id": "CVE-2026-10073",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00353,
      "epss_percentile": 0.28554,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Interinfo",
      "product": "DreamMaker",
      "cwe": "CWE-23",
      "title": "Interinfo｜DreamMaker - Arbitrary File Read",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10073"
    },
    {
      "rank": 82,
      "cve_id": "CVE-2026-46599",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00353,
      "epss_percentile": 0.28532,
      "kev": false,
      "kev_due_at": null,
      "vendor": "golang.org/x/image",
      "product": "golang.org/x/image/tiff",
      "cwe": "CWE-770",
      "title": "Excessive resource consumption in PackBits decompression in golang.org/x/image/tiff",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46599"
    },
    {
      "rank": 83,
      "cve_id": "CVE-2026-46579",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00352,
      "epss_percentile": 0.28459,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat OpenShift Container Platform 4.12",
      "cwe": "CWE-287",
      "title": "Openshift/router: openshift/router: mtls client certificate spoofing via unstripped x-ssl-client headers on http frontend",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46579"
    },
    {
      "rank": 84,
      "cve_id": "CVE-2026-45631",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00351,
      "epss_percentile": 0.28336,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dokploy",
      "product": "dokploy",
      "cwe": "CWE-798",
      "title": "Dokploy: Pre-Auth Admin Takeover via Hardcoded Authentication Secret",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45631"
    },
    {
      "rank": 85,
      "cve_id": "CVE-2026-9509",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00351,
      "epss_percentile": 0.28332,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Suprema",
      "product": "BioStar 2 (server)",
      "cwe": "CWE-248",
      "title": "Uncaught exception vulnerability in Suprema's BioStar",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9509"
    },
    {
      "rank": 86,
      "cve_id": "CVE-2026-10074",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00347,
      "epss_percentile": 0.27917,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Interinfo",
      "product": "DreamMaker",
      "cwe": "CWE-23",
      "title": "Interinfo｜DreamMaker - Arbitrary File Read",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10074"
    },
    {
      "rank": 87,
      "cve_id": "CVE-2026-9508",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00341,
      "epss_percentile": 0.27234,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Suprema",
      "product": "BioStar 2 (server)",
      "cwe": "CWE-732",
      "title": "Incorrect Permission Assignment for Critical Resource vulnerability in Suprema's BioStar",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9508"
    },
    {
      "rank": 88,
      "cve_id": "CVE-2018-25382",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00334,
      "epss_percentile": 0.26422,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Bylancer",
      "product": "Zechat",
      "cwe": "CWE-89",
      "title": "Zechat 1.5 SQL Injection via uname Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2018-25382"
    },
    {
      "rank": 89,
      "cve_id": "CVE-2018-25385",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00334,
      "epss_percentile": 0.2642,
      "kev": false,
      "kev_due_at": null,
      "vendor": "eregistrasi-kejuaraan-silat",
      "product": "Registrasi Pencak Silat",
      "cwe": "CWE-89",
      "title": "E-Registrasi Pencak Silat 18.10 SQL Injection via id_partai",
      "url": "https://www.cve.org/CVERecord?id=CVE-2018-25385"
    },
    {
      "rank": 90,
      "cve_id": "CVE-2018-25386",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00334,
      "epss_percentile": 0.26421,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Sitejo",
      "product": "HaPe PKH",
      "cwe": "CWE-89",
      "title": "HaPe PKH 1.1 SQL Injection via id Parameter in admin/media.php",
      "url": "https://www.cve.org/CVERecord?id=CVE-2018-25386"
    },
    {
      "rank": 91,
      "cve_id": "CVE-2018-25389",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00334,
      "epss_percentile": 0.26419,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Sitejo",
      "product": "HaPe PKH",
      "cwe": "CWE-89",
      "title": "HaPe PKH 1.1 SQL Injection via nama_kelompok Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2018-25389"
    },
    {
      "rank": 92,
      "cve_id": "CVE-2018-25390",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00334,
      "epss_percentile": 0.26421,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Sitejo",
      "product": "HaPe PKH",
      "cwe": "CWE-89",
      "title": "HaPe PKH 1.1 SQL Injection via desa Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2018-25390"
    },
    {
      "rank": 93,
      "cve_id": "CVE-2018-25394",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00334,
      "epss_percentile": 0.26421,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Kados",
      "product": "Kados R10 GreenBee",
      "cwe": "CWE-89",
      "title": "Kados R10 GreenBee SQL Injection via update_release.php",
      "url": "https://www.cve.org/CVERecord?id=CVE-2018-25394"
    },
    {
      "rank": 94,
      "cve_id": "CVE-2018-25395",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00334,
      "epss_percentile": 0.26422,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Kados",
      "product": "Kados R10 GreenBee",
      "cwe": "CWE-89",
      "title": "Kados R10 GreenBee SQL Injection via update_feature.php",
      "url": "https://www.cve.org/CVERecord?id=CVE-2018-25395"
    },
    {
      "rank": 95,
      "cve_id": "CVE-2018-25398",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00334,
      "epss_percentile": 0.26419,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Open ISES",
      "product": "Open ISES Project",
      "cwe": "CWE-89",
      "title": "The Open ISES Project 3.30A SQL Injection via main.php",
      "url": "https://www.cve.org/CVERecord?id=CVE-2018-25398"
    },
    {
      "rank": 96,
      "cve_id": "CVE-2018-25399",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00334,
      "epss_percentile": 0.26422,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Open ISES",
      "product": "Open ISES Project",
      "cwe": "CWE-89",
      "title": "The Open ISES Project 3.30A SQL Injection via nearby.php",
      "url": "https://www.cve.org/CVERecord?id=CVE-2018-25399"
    },
    {
      "rank": 97,
      "cve_id": "CVE-2018-25400",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00334,
      "epss_percentile": 0.26422,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Open ISES",
      "product": "Open ISES Project",
      "cwe": "CWE-89",
      "title": "The Open ISES Project 3.30A SQL Injection via form_post.php",
      "url": "https://www.cve.org/CVERecord?id=CVE-2018-25400"
    },
    {
      "rank": 98,
      "cve_id": "CVE-2018-25401",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00334,
      "epss_percentile": 0.26419,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Open ISES",
      "product": "Open ISES Project",
      "cwe": "CWE-89",
      "title": "The Open ISES Project 3.30A SQL Injection via sever_graph.php",
      "url": "https://www.cve.org/CVERecord?id=CVE-2018-25401"
    },
    {
      "rank": 99,
      "cve_id": "CVE-2018-25402",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00334,
      "epss_percentile": 0.26419,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Open ISES",
      "product": "Open ISES Project",
      "cwe": "CWE-89",
      "title": "The Open ISES Project 3.30A SQL Injection via inc_types_graph.php",
      "url": "https://www.cve.org/CVERecord?id=CVE-2018-25402"
    },
    {
      "rank": 100,
      "cve_id": "CVE-2018-25403",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00334,
      "epss_percentile": 0.26418,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Open ISES",
      "product": "Open ISES Project",
      "cwe": "CWE-89",
      "title": "The Open ISES Project 3.30A SQL Injection via city_graph.php",
      "url": "https://www.cve.org/CVERecord?id=CVE-2018-25403"
    },
    {
      "rank": 101,
      "cve_id": "CVE-2026-49197",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00332,
      "epss_percentile": 0.26205,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Acer",
      "product": "Predator Connect W6x",
      "cwe": "CWE-287",
      "title": "Predator Connect W6x: Improper Authentication",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49197"
    },
    {
      "rank": 102,
      "cve_id": "CVE-2026-49367",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00332,
      "epss_percentile": 0.2617,
      "kev": false,
      "kev_due_at": null,
      "vendor": "JetBrains",
      "product": "IntelliJ IDEA",
      "cwe": "CWE-862",
      "title": "In JetBrains IntelliJ IDEA before 2026.1.1 command execution was possible via the guest user account",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49367"
    },
    {
      "rank": 103,
      "cve_id": "CVE-2018-25391",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00332,
      "epss_percentile": 0.26219,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Sitejo",
      "product": "HaPe PKH",
      "cwe": "CWE-862",
      "title": "HaPe PKH 1.1 Missing Authorization Allows Unauthenticated Record Deletion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2018-25391"
    },
    {
      "rank": 104,
      "cve_id": "CVE-2026-46527",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00327,
      "epss_percentile": 0.25722,
      "kev": false,
      "kev_due_at": null,
      "vendor": "yhirose",
      "product": "cpp-httplib",
      "cwe": "CWE-476",
      "title": "cpp-httplib: Malicious `X-Forwarded-For` Under Trusted-Proxy Configuration Triggers Empty `vector::front()`, Leading to Undefined Behavior and Server Crash",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46527"
    },
    {
      "rank": 105,
      "cve_id": "CVE-2026-45352",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00327,
      "epss_percentile": 0.25722,
      "kev": false,
      "kev_due_at": null,
      "vendor": "yhirose",
      "product": "cpp-httplib",
      "cwe": "CWE-20",
      "title": "cpp-httplib DoS: Negative chunk-size in chunked Transfer-Encoding",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45352"
    },
    {
      "rank": 106,
      "cve_id": "CVE-2026-44651",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00323,
      "epss_percentile": 0.25219,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SillyTavern",
      "product": "SillyTavern",
      "cwe": "CWE-79",
      "title": "SillyTavern: Reflected XSS vulnerability in the CORS proxy middleware",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44651"
    },
    {
      "rank": 107,
      "cve_id": "CVE-2026-47744",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00321,
      "epss_percentile": 0.2496,
      "kev": false,
      "kev_due_at": null,
      "vendor": "shopperlabs",
      "product": "shopper",
      "cwe": "CWE-269",
      "title": "Shopper: Authorization bypass and RBAC privilege escalation in team settings",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47744"
    },
    {
      "rank": 108,
      "cve_id": "CVE-2026-10105",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00319,
      "epss_percentile": 0.24814,
      "kev": false,
      "kev_due_at": null,
      "vendor": "agno-agi",
      "product": "agno",
      "cwe": "CWE-89",
      "title": "agno 2.6.5 SQL Injection via ClickHouse delete_by_metadata()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10105"
    },
    {
      "rank": 109,
      "cve_id": "CVE-2026-45578",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00318,
      "epss_percentile": 0.24625,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WWBN",
      "product": "AVideo",
      "cwe": "CWE-78",
      "title": "WWBN AVideo Live: OS command injection in on_publish.php execAsync via unescaped m3u8 URL",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45578"
    },
    {
      "rank": 110,
      "cve_id": "CVE-2018-25396",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00313,
      "epss_percentile": 0.24103,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Heatmiser",
      "product": "Heatmiser Wifi Thermostat",
      "cwe": "CWE-256",
      "title": "Heatmiser Wifi Thermostat 1.7 Credential Disclosure via networkSetup.htm",
      "url": "https://www.cve.org/CVERecord?id=CVE-2018-25396"
    },
    {
      "rank": 111,
      "cve_id": "CVE-2026-47266",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00311,
      "epss_percentile": 0.23931,
      "kev": false,
      "kev_due_at": null,
      "vendor": "verbb",
      "product": "formie",
      "cwe": "CWE-639",
      "title": "Formie: Unauthenticated front-end submission editing can overwrite existing submissions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47266"
    },
    {
      "rank": 112,
      "cve_id": "CVE-2026-47179",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00307,
      "epss_percentile": 0.23392,
      "kev": false,
      "kev_due_at": null,
      "vendor": "getarcaneapp",
      "product": "arcane",
      "cwe": "CWE-22",
      "title": "Arcane: Authenticated Arbitrary Host File Read via Docker Compose Include Directives in Arcane",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47179"
    },
    {
      "rank": 113,
      "cve_id": "CVE-2026-6275",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00305,
      "epss_percentile": 0.23184,
      "kev": false,
      "kev_due_at": null,
      "vendor": "statcounter",
      "product": "StatCounter – Free Real Time Visitor Stats",
      "cwe": "CWE-79",
      "title": "StatCounter <= 2.1.1 - Authenticated (Author+) Stored Cross-Site Scripting via Author Nickname",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6275"
    },
    {
      "rank": 114,
      "cve_id": "CVE-2026-44518",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00305,
      "epss_percentile": 0.23165,
      "kev": false,
      "kev_due_at": null,
      "vendor": "open-quantum-safe",
      "product": "liboqs",
      "cwe": "CWE-20",
      "title": "liboqs: XMSS Buffer Overread Bug",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44518"
    },
    {
      "rank": 115,
      "cve_id": "CVE-2026-46344",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00305,
      "epss_percentile": 0.23165,
      "kev": false,
      "kev_due_at": null,
      "vendor": "open-quantum-safe",
      "product": "liboqs",
      "cwe": "CWE-125",
      "title": "liboqs: Heap-buffer-overflow in XMSS verification path via OID-controlled parameter mismatch (xmss_commons.c:194)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46344"
    },
    {
      "rank": 116,
      "cve_id": "CVE-2026-45149",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.003,
      "epss_percentile": 0.22613,
      "kev": false,
      "kev_due_at": null,
      "vendor": "juliangruber",
      "product": "brace-expansion",
      "cwe": "CWE-400",
      "title": "brace-expansion: Large numeric range defeats documented `max` DoS protection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45149"
    },
    {
      "rank": 117,
      "cve_id": "CVE-2026-49372",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00298,
      "epss_percentile": 0.22438,
      "kev": false,
      "kev_due_at": null,
      "vendor": "JetBrains",
      "product": "TeamCity",
      "cwe": "CWE-918",
      "title": "In JetBrains TeamCity before 2026.1, 2025.11.5 unauthenticated SSRF via build status was possible",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49372"
    },
    {
      "rank": 118,
      "cve_id": "CVE-2026-45372",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00295,
      "epss_percentile": 0.22084,
      "kev": false,
      "kev_due_at": null,
      "vendor": "yhirose",
      "product": "cpp-httplib",
      "cwe": "CWE-93",
      "title": "cpp-httplib: HTTP header value percent-decoding in server-side `parse_header` enables CRLF injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45372"
    },
    {
      "rank": 119,
      "cve_id": "CVE-2026-45312",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00294,
      "epss_percentile": 0.21996,
      "kev": false,
      "kev_due_at": null,
      "vendor": "infiniflow",
      "product": "ragflow",
      "cwe": "CWE-1336",
      "title": "RAGFlow: Server-Side Template Injection in Prompt Generator leads to Remote Code Execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45312"
    },
    {
      "rank": 120,
      "cve_id": "CVE-2026-48501",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00289,
      "epss_percentile": 0.21479,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cli",
      "product": "cli",
      "cwe": "CWE-863",
      "title": "GitHub CLI tokens leak via `gh attestation` commands",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48501"
    },
    {
      "rank": 121,
      "cve_id": "CVE-2026-44238",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00289,
      "epss_percentile": 0.21441,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FreePBX",
      "product": "security-reporting",
      "cwe": "CWE-89",
      "title": "FreePBX: Authenticated SQL Injection via ORDER BY in CDR Reports",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44238"
    },
    {
      "rank": 122,
      "cve_id": "CVE-2026-10039",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00288,
      "epss_percentile": 0.21349,
      "kev": false,
      "kev_due_at": null,
      "vendor": "shabti",
      "product": "Frontend Admin by DynamiApps",
      "cwe": "CWE-89",
      "title": "Frontend Admin by DynamiApps <= 3.28.28 - Authenticated (Administrator+) SQL Injection via 'order' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10039"
    },
    {
      "rank": 123,
      "cve_id": "CVE-2026-8995",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00283,
      "epss_percentile": 0.20902,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ays-pro",
      "product": "Poll Maker by AYS – Versus Polls, Anonymous Polls, Image Polls",
      "cwe": "CWE-200",
      "title": "Poll Maker by AYS <= 6.3.7 - Authenticated (Subscriber+) Sensitive Information Exposure in 'ays_poll_get_user_information' AJAX Action",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8995"
    },
    {
      "rank": 124,
      "cve_id": "CVE-2026-46510",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00282,
      "epss_percentile": 0.20777,
      "kev": false,
      "kev_due_at": null,
      "vendor": "kaspernj",
      "product": "form-data-objectizer",
      "cwe": "CWE-1321",
      "title": "Prototype pollution in form-data-objectizer via bracket-notation form keys",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46510"
    },
    {
      "rank": 125,
      "cve_id": "CVE-2026-5768",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0028,
      "epss_percentile": 0.20578,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Fourth Frontier",
      "product": "Frontier X Android application",
      "cwe": "CWE-306",
      "title": "Fourth Frontier Frontier X Mobile Application, Frontier X2 Missing Authentication for Critical Function",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-5768"
    },
    {
      "rank": 126,
      "cve_id": "CVE-2026-10068",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00278,
      "epss_percentile": 0.20346,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Shibby",
      "product": "Tomato",
      "cwe": "CWE-918",
      "title": "Shibby Tomato SUBSCRIBE Call miniupnpd send server-side request forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10068"
    },
    {
      "rank": 127,
      "cve_id": "CVE-2018-25392",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00273,
      "epss_percentile": 0.19767,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Talagasoft",
      "product": "MaxOn ERP",
      "cwe": "CWE-89",
      "title": "MaxOn ERP Software 8.x-9.x SQL Injection via nomor Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2018-25392"
    },
    {
      "rank": 128,
      "cve_id": "CVE-2026-9243",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00273,
      "epss_percentile": 0.19798,
      "kev": false,
      "kev_due_at": null,
      "vendor": "posimyththemes",
      "product": "The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce",
      "cwe": "CWE-79",
      "title": "The Plus Addons for Elementor <= 6.4.15 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'carousel_direction' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9243"
    },
    {
      "rank": 129,
      "cve_id": "CVE-2026-2128",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00273,
      "epss_percentile": 0.19796,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cloudways",
      "product": "Breeze Cache",
      "cwe": "CWE-200",
      "title": "Breeze Cache <= 2.5.2 - Unauthenticated Exposure of Sensitive Information to an Unauthorized Actor via Crafted Login Cookie",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-2128"
    },
    {
      "rank": 130,
      "cve_id": "CVE-2026-44239",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00272,
      "epss_percentile": 0.19681,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FreePBX",
      "product": "security-reporting",
      "cwe": "CWE-98",
      "title": "FreePBX: Authenticated Local File Inclusion in Dashboard Module",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44239"
    },
    {
      "rank": 131,
      "cve_id": "CVE-2018-25404",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0027,
      "epss_percentile": 0.19329,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Open ISES",
      "product": "Open ISES Project",
      "cwe": "CWE-89",
      "title": "The Open ISES Project 3.30A SQL Injection via add_facnote.php",
      "url": "https://www.cve.org/CVERecord?id=CVE-2018-25404"
    },
    {
      "rank": 132,
      "cve_id": "CVE-2026-44285",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00263,
      "epss_percentile": 0.18286,
      "kev": false,
      "kev_due_at": null,
      "vendor": "labring",
      "product": "FastGPT",
      "cwe": "CWE-918",
      "title": "FastGPT: SSRF Protection Bypass via `externalFile` in Dataset Preview API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44285"
    },
    {
      "rank": 133,
      "cve_id": "CVE-2026-49201",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00262,
      "epss_percentile": 0.18203,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Acer",
      "product": "Wave 7 router",
      "cwe": "CWE-798",
      "title": "Acer Wave 7 router: Hardcoded Cryptographic Key",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49201"
    },
    {
      "rank": 134,
      "cve_id": "CVE-2026-49371",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00262,
      "epss_percentile": 0.18155,
      "kev": false,
      "kev_due_at": null,
      "vendor": "JetBrains",
      "product": "TeamCity",
      "cwe": "CWE-79",
      "title": "In JetBrains TeamCity before 2026.1.1 reflected XSS in the keyword filter was possible",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49371"
    },
    {
      "rank": 135,
      "cve_id": "CVE-2026-45582",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00262,
      "epss_percentile": 0.18103,
      "kev": false,
      "kev_due_at": null,
      "vendor": "czlonkowski",
      "product": "n8n-mcp",
      "cwe": "CWE-201",
      "title": "n8n-MCP: Workflow telemetry sanitizer could retain partial values from URL-shaped node parameters",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45582"
    },
    {
      "rank": 136,
      "cve_id": "CVE-2026-9493",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00259,
      "epss_percentile": 0.17806,
      "kev": false,
      "kev_due_at": null,
      "vendor": "BankPro E-Service Technology",
      "product": "Service Center",
      "cwe": "CWE-639",
      "title": "BankPro E-Service Technology｜Service Center - Insecure Direct Object Reference",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9493"
    },
    {
      "rank": 137,
      "cve_id": "CVE-2026-4290",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00258,
      "epss_percentile": 0.177,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WPTravel",
      "product": "WP Travel Pro",
      "cwe": "CWE-862",
      "title": "WP Travel Pro <= 10.6.0 - Missing Authorization to Unauthenticated Arbitrary User Deletion Including Administrators",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-4290"
    },
    {
      "rank": 138,
      "cve_id": "CVE-2026-47740",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00258,
      "epss_percentile": 0.17623,
      "kev": false,
      "kev_due_at": null,
      "vendor": "shopperlabs",
      "product": "shopper",
      "cwe": "CWE-285",
      "title": "Shopper: Authorization bypass in multiple Livewire admin components",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47740"
    },
    {
      "rank": 139,
      "cve_id": "CVE-2026-49386",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00258,
      "epss_percentile": 0.17631,
      "kev": false,
      "kev_due_at": null,
      "vendor": "JetBrains",
      "product": "YouTrack",
      "cwe": "CWE-639",
      "title": "In JetBrains YouTrack before 2026.1.13570 improper access control allowed enumeration of restricted issues and articles on Planning Canvas",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49386"
    },
    {
      "rank": 140,
      "cve_id": "CVE-2026-42965",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00257,
      "epss_percentile": 0.17569,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat OpenShift Container Platform 4.20",
      "cwe": "CWE-918",
      "title": "Openshift/router: openshift/router: cloud metadata ssrf via fqdn-typed endpointslice bypasses destination validation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42965"
    },
    {
      "rank": 141,
      "cve_id": "CVE-2026-49379",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00257,
      "epss_percentile": 0.17594,
      "kev": false,
      "kev_due_at": null,
      "vendor": "JetBrains",
      "product": "TeamCity",
      "cwe": "CWE-522",
      "title": "In JetBrains TeamCity before 2026.1 credentials could be exposed in thread names",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49379"
    },
    {
      "rank": 142,
      "cve_id": "CVE-2026-45632",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00256,
      "epss_percentile": 0.1743,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dokploy",
      "product": "dokploy",
      "cwe": "CWE-78",
      "title": "Dokploy: Schedule Authorization Bypass Enables Host/Server Command Execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45632"
    },
    {
      "rank": 143,
      "cve_id": "CVE-2026-35674",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00253,
      "epss_percentile": 0.17027,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenClaw",
      "product": "OpenClaw",
      "cwe": "CWE-863",
      "title": "OpenClaw < 2026.5.18 - Scope Bypass via Inherited chat.send Route",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-35674"
    },
    {
      "rank": 144,
      "cve_id": "CVE-2026-10107",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.0025,
      "epss_percentile": 0.16707,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jxxghp",
      "product": "MoviePilot",
      "cwe": "CWE-918",
      "title": "MoviePilot v2 SSRF via /api/v1/system/img/{proxy} Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10107"
    },
    {
      "rank": 145,
      "cve_id": "CVE-2026-45577",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00249,
      "epss_percentile": 0.16533,
      "kev": false,
      "kev_due_at": null,
      "vendor": "markmhendrickson",
      "product": "neotoma",
      "cwe": "CWE-288",
      "title": "Neotoma: Unauthenticated Inspector/API access via reverse-proxy loopback auth bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45577"
    },
    {
      "rank": 146,
      "cve_id": "CVE-2026-49370",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00248,
      "epss_percentile": 0.164,
      "kev": false,
      "kev_due_at": null,
      "vendor": "JetBrains",
      "product": "YouTrack",
      "cwe": "CWE-201",
      "title": "In JetBrains YouTrack before 2026.1.13162 information disclosure was possible on fetchApp requests",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49370"
    },
    {
      "rank": 147,
      "cve_id": "CVE-2026-48555",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00248,
      "epss_percentile": 0.1646,
      "kev": false,
      "kev_due_at": null,
      "vendor": "spatie",
      "product": "laravel-medialibrary",
      "cwe": "CWE-918",
      "title": "Spatie Laravel Media Library < 11.23.0 SSRF via addMediaFromUrl()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48555"
    },
    {
      "rank": 148,
      "cve_id": "CVE-2026-47125",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00245,
      "epss_percentile": 0.16066,
      "kev": false,
      "kev_due_at": null,
      "vendor": "getarcaneapp",
      "product": "arcane",
      "cwe": "CWE-862",
      "title": "Arcane: Missing admin authorization on global variables endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47125"
    },
    {
      "rank": 149,
      "cve_id": "CVE-2026-7430",
      "cvss_base": 4.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00244,
      "epss_percentile": 0.15836,
      "kev": false,
      "kev_due_at": null,
      "vendor": "saadiqbal",
      "product": "Post Snippets – Custom WordPress Code Snippets Customizer",
      "cwe": "CWE-79",
      "title": "Post Snippets <= 4.0.19 - Authenticated (Administrator+) Stored Cross-Site Scripting via Import",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7430"
    },
    {
      "rank": 150,
      "cve_id": "CVE-2026-10056",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00242,
      "epss_percentile": 0.15597,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Network Optix",
      "product": "Nx Witness VMS",
      "cwe": "CWE-942",
      "title": "CORS misconfiguration in Nx Witness VMS allows session token exfiltration via cross-origin request",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10056"
    },
    {
      "rank": 151,
      "cve_id": "CVE-2025-11262",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00242,
      "epss_percentile": 0.15676,
      "kev": false,
      "kev_due_at": null,
      "vendor": "linkwhspr",
      "product": "Link Whisper Free",
      "cwe": "CWE-79",
      "title": "Link Whisper Free <= 0.9.0 - Unauthenticated Stored Cross-Site Scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-11262"
    },
    {
      "rank": 152,
      "cve_id": "CVE-2026-39229",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00241,
      "epss_percentile": 0.15474,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-89",
      "title": "Bolt CMS through 3.7.0 allows SQL Injection in the 'order' parameter of the content listing pages. An authenticated attacker with low-level privileges can exploit this through the OrderDirective component. This allows for the extraction of sensitive information",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39229"
    },
    {
      "rank": 153,
      "cve_id": "CVE-2026-32905",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00239,
      "epss_percentile": 0.15181,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenClaw",
      "product": "OpenClaw",
      "cwe": "CWE-862",
      "title": "OpenClaw < 2026.5.4 - Unauthorized Device-Pairing Bootstrap Code Issuance via Chat Command",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-32905"
    },
    {
      "rank": 154,
      "cve_id": "CVE-2026-44287",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00239,
      "epss_percentile": 0.15223,
      "kev": false,
      "kev_due_at": null,
      "vendor": "labring",
      "product": "FastGPT",
      "cwe": "CWE-94",
      "title": "FastGPT: sandbox escape to RCE - code-sandbox regex /\\bimport\\s*\\(/ is bypassable",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44287"
    },
    {
      "rank": 155,
      "cve_id": "CVE-2026-47741",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00239,
      "epss_percentile": 0.1527,
      "kev": false,
      "kev_due_at": null,
      "vendor": "shopperlabs",
      "product": "shopper",
      "cwe": "CWE-362",
      "title": "Shopper: Race condition on Discount.usage_limit allows silent over-redemption",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47741"
    },
    {
      "rank": 156,
      "cve_id": "CVE-2026-34127",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00239,
      "epss_percentile": 0.15295,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TP-Link Systems Inc.",
      "product": "TL-SG108PE v5",
      "cwe": "CWE-79",
      "title": "Stored Cross-Site Scripting (XSS) via Configuration File Import on TP-Link's TL-SG108PE",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34127"
    },
    {
      "rank": 157,
      "cve_id": "CVE-2026-45707",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00235,
      "epss_percentile": 0.14781,
      "kev": false,
      "kev_due_at": null,
      "vendor": "czlonkowski",
      "product": "n8n-mcp",
      "cwe": "CWE-284",
      "title": "n8n-MCP: Multi-tenant MCP requests fall back to process-level n8n credentials when tenant headers are absent or incomplete",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45707"
    },
    {
      "rank": 158,
      "cve_id": "CVE-2026-49374",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00234,
      "epss_percentile": 0.14639,
      "kev": false,
      "kev_due_at": null,
      "vendor": "JetBrains",
      "product": "TeamCity",
      "cwe": "CWE-862",
      "title": "In JetBrains TeamCity before 2026.1 improper permission checks exposed build configuration parameters",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49374"
    },
    {
      "rank": 159,
      "cve_id": "CVE-2026-45628",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0023,
      "epss_percentile": 0.14028,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dokploy",
      "product": "dokploy",
      "cwe": "CWE-20",
      "title": "Dokploy: Command Injection via Unescaped Branch Fields in Deployment Pipeline",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45628"
    },
    {
      "rank": 160,
      "cve_id": "CVE-2026-45551",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0023,
      "epss_percentile": 0.14033,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Intermesh",
      "product": "groupoffice",
      "cwe": "CWE-79",
      "title": "Group-Office: Authenticated Stored XSS in Administrator Context via Arbitrary Cross-User Setting Write",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45551"
    },
    {
      "rank": 161,
      "cve_id": "CVE-2026-48527",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00228,
      "epss_percentile": 0.13819,
      "kev": false,
      "kev_due_at": null,
      "vendor": "haxtheweb",
      "product": "haxcms-nodejs",
      "cwe": "CWE-79",
      "title": "HaxCMS has a stored Cross-Site Scripting (XSS) bypass in saveNode endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48527"
    },
    {
      "rank": 162,
      "cve_id": "CVE-2026-45151",
      "cvss_base": 2.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00227,
      "epss_percentile": 0.13633,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nanomq",
      "product": "nanomq",
      "cwe": "CWE-476",
      "title": "NanoMQ: NULL Pointer Dereference",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45151"
    },
    {
      "rank": 163,
      "cve_id": "CVE-2026-45043",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00226,
      "epss_percentile": 0.13593,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rustfs",
      "product": "rustfs",
      "cwe": "CWE-269",
      "title": "RustFS: ImportIam Allows Creation of Backdoor Service Accounts Under Any Parent Including Root",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45043"
    },
    {
      "rank": 164,
      "cve_id": "CVE-2026-42929",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00226,
      "epss_percentile": 0.13578,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Danelec",
      "product": "MacGregor Voyage Data Recorder (VDR) G4e",
      "cwe": "CWE-798",
      "title": "MacGregor Voyage Data Recorder (VDR) G4e Use of Hard-coded Credentials",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42929"
    },
    {
      "rank": 165,
      "cve_id": "CVE-2026-42941",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00226,
      "epss_percentile": 0.13578,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Danelec",
      "product": "MacGregor Voyage Data Recorder (VDR) G4e",
      "cwe": "CWE-1392",
      "title": "MacGregor Voyage Data Recorder (VDR) G4e Use of Default Credentials",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42941"
    },
    {
      "rank": 166,
      "cve_id": "CVE-2026-43917",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00225,
      "epss_percentile": 0.1348,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dokploy",
      "product": "dokploy",
      "cwe": "CWE-639",
      "title": "Dokploy: Cross-Organization IDOR - Multiple tRPC endpoints missing activeOrganizationId validation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43917"
    },
    {
      "rank": 167,
      "cve_id": "CVE-2026-4776",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00224,
      "epss_percentile": 0.13313,
      "kev": false,
      "kev_due_at": null,
      "vendor": null,
      "product": "mautic/core",
      "cwe": "CWE-89",
      "title": "An SQL injection vulnerability exists in Mautic's API contact filtering mechanism. Due to insufficient recursive sanitization of nested query parameters, an authenticated API user can bypass input filtering and inject arbitrary SQL commands.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-4776"
    },
    {
      "rank": 168,
      "cve_id": "CVE-2026-49375",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00223,
      "epss_percentile": 0.13162,
      "kev": false,
      "kev_due_at": null,
      "vendor": "JetBrains",
      "product": "TeamCity",
      "cwe": "CWE-79",
      "title": "In JetBrains TeamCity before 2026.1, 2025.11.5 reflected XSS was possible on the repository download page",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49375"
    },
    {
      "rank": 169,
      "cve_id": "CVE-2026-47742",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00221,
      "epss_percentile": 0.1288,
      "kev": false,
      "kev_due_at": null,
      "vendor": "shopperlabs",
      "product": "shopper",
      "cwe": "CWE-862",
      "title": "Shopper: Missing authorization on Product admin Livewire sub-form components",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47742"
    },
    {
      "rank": 170,
      "cve_id": "CVE-2026-47745",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00221,
      "epss_percentile": 0.12879,
      "kev": false,
      "kev_due_at": null,
      "vendor": "shopperlabs",
      "product": "shopper",
      "cwe": "CWE-862",
      "title": "Shopper: Missing per-action authorization on PaymentMethods, Currencies and Carriers admin tables",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47745"
    },
    {
      "rank": 171,
      "cve_id": "CVE-2026-49385",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00221,
      "epss_percentile": 0.12882,
      "kev": false,
      "kev_due_at": null,
      "vendor": "JetBrains",
      "product": "YouTrack",
      "cwe": "CWE-862",
      "title": "In JetBrains YouTrack before 2026.1.13570 improper access control allowed low-privileged users to modify service accounts",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49385"
    },
    {
      "rank": 172,
      "cve_id": "CVE-2026-49378",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00219,
      "epss_percentile": 0.12648,
      "kev": false,
      "kev_due_at": null,
      "vendor": "JetBrains",
      "product": "TeamCity",
      "cwe": "CWE-862",
      "title": "In JetBrains TeamCity before 2026.1 credentials parameters were exposed via parameter autocompletion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49378"
    },
    {
      "rank": 173,
      "cve_id": "CVE-2026-44649",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00218,
      "epss_percentile": 0.12517,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SillyTavern",
      "product": "SillyTavern",
      "cwe": "CWE-290",
      "title": "SillyTavern: Authentication Bypass via SSO Header Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44649"
    },
    {
      "rank": 174,
      "cve_id": "CVE-2026-10070",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00218,
      "epss_percentile": 0.12571,
      "kev": false,
      "kev_due_at": null,
      "vendor": "macrozheng",
      "product": "mall",
      "cwe": "CWE-266",
      "title": "macrozheng mall Super Admin Password update improper authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10070"
    },
    {
      "rank": 175,
      "cve_id": "CVE-2026-49376",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00216,
      "epss_percentile": 0.12303,
      "kev": false,
      "kev_due_at": null,
      "vendor": "JetBrains",
      "product": "TeamCity",
      "cwe": "CWE-863",
      "title": "In JetBrains TeamCity before 2026.1 insufficient username validation in the SAML plugin",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49376"
    },
    {
      "rank": 176,
      "cve_id": "CVE-2026-40510",
      "cvss_base": 1,
      "cvss_severity": "LOW",
      "epss_score": 0.00216,
      "epss_percentile": 0.12318,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenSC",
      "product": "OpenSC",
      "cwe": "CWE-121",
      "title": "OpenSC < 0.27.0-rc1 Stack Buffer Overflow via piv_process_history() in card-piv.c",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40510"
    },
    {
      "rank": 177,
      "cve_id": "CVE-2026-49195",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00215,
      "epss_percentile": 0.12244,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Acer",
      "product": "Predator Connect W6x",
      "cwe": "CWE-306",
      "title": "Predator Connect W6x: unauthenticated Debug Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49195"
    },
    {
      "rank": 178,
      "cve_id": "CVE-2018-25384",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00215,
      "epss_percentile": 0.12189,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wikidforum",
      "product": "Wikidforum",
      "cwe": "CWE-79",
      "title": "Wikidforum 2.20 Cross-Site Scripting via reply_text Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2018-25384"
    },
    {
      "rank": 179,
      "cve_id": "CVE-2026-49381",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00213,
      "epss_percentile": 0.11903,
      "kev": false,
      "kev_due_at": null,
      "vendor": "JetBrains",
      "product": "TeamCity",
      "cwe": "CWE-79",
      "title": "In JetBrains TeamCity before 2026.1 stored XSS on the SAML login page was possible",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49381"
    },
    {
      "rank": 180,
      "cve_id": "CVE-2026-6075",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00211,
      "epss_percentile": 0.11653,
      "kev": false,
      "kev_due_at": null,
      "vendor": "dglingren",
      "product": "Media Library Assistant",
      "cwe": "CWE-352",
      "title": "Media Library Assistant <= 3.35 - Cross-Site Request Forgery via Bulk Action Form",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6075"
    },
    {
      "rank": 181,
      "cve_id": "CVE-2026-45626",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0021,
      "epss_percentile": 0.11582,
      "kev": false,
      "kev_due_at": null,
      "vendor": "getarcaneapp",
      "product": "arcane",
      "cwe": "CWE-78",
      "title": "Arcane: OS Command Injection in Volume Browser ListDirectory via path query parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45626"
    },
    {
      "rank": 182,
      "cve_id": "CVE-2026-45294",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0021,
      "epss_percentile": 0.11593,
      "kev": false,
      "kev_due_at": null,
      "vendor": "freescout-help-desk",
      "product": "freescout",
      "cwe": "CWE-203",
      "title": "FreeScout: User Account Enumeration via Password Reset Response Differentiation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45294"
    },
    {
      "rank": 183,
      "cve_id": "CVE-2026-49198",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00208,
      "epss_percentile": 0.11228,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Acer",
      "product": "Predator Connect W6x",
      "cwe": "CWE-284",
      "title": "Predator Connect W6x: MQTT Broker Access Control",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49198"
    },
    {
      "rank": 184,
      "cve_id": "CVE-2026-45609",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00207,
      "epss_percentile": 0.11151,
      "kev": false,
      "kev_due_at": null,
      "vendor": "spring-ai-community",
      "product": "mcp-security",
      "cwe": "CWE-918",
      "title": "mcp-security: Unvalidated URL Fetching (SSRF)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45609"
    },
    {
      "rank": 185,
      "cve_id": "CVE-2026-35630",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00206,
      "epss_percentile": 0.11043,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenClaw",
      "product": "OpenClaw",
      "cwe": "CWE-862",
      "title": "OpenClaw < 2026.5.18 - QQBot Missing Approver Identity Enforcement in Native Approval Buttons",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-35630"
    },
    {
      "rank": 186,
      "cve_id": "CVE-2026-49368",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00206,
      "epss_percentile": 0.1102,
      "kev": false,
      "kev_due_at": null,
      "vendor": "JetBrains",
      "product": "YouTrack",
      "cwe": "CWE-79",
      "title": "In JetBrains YouTrack before 2026.1.13162 stored XSS in project notification templates was possible",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49368"
    },
    {
      "rank": 187,
      "cve_id": "CVE-2026-49369",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00205,
      "epss_percentile": 0.10787,
      "kev": false,
      "kev_due_at": null,
      "vendor": "JetBrains",
      "product": "YouTrack",
      "cwe": "CWE-863",
      "title": "In JetBrains YouTrack before 2026.1.13162 information disclosure was possible on Users and Groups pages",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49369"
    },
    {
      "rank": 188,
      "cve_id": "CVE-2026-9189",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00204,
      "epss_percentile": 0.10758,
      "kev": false,
      "kev_due_at": null,
      "vendor": "scottpaterson",
      "product": "Contact Form 7 – PayPal & Stripe Add-on",
      "cwe": "CWE-345",
      "title": "Contact Form 7 – PayPal & Stripe Add-on <= 2.4.9 - Unauthenticated Payment Bypass via Insufficient Verification of Data Authenticity via PayPal IPN Handler ('invoice'/'mc_gross' Verification)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9189"
    },
    {
      "rank": 189,
      "cve_id": "CVE-2026-44237",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00201,
      "epss_percentile": 0.10309,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FreePBX",
      "product": "security-reporting",
      "cwe": "CWE-1390",
      "title": "FreePBX: Authenticated Access can lead to Subsequent OAuth2 Authentication Bypass in API Module",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44237"
    },
    {
      "rank": 190,
      "cve_id": "CVE-2026-9808",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00201,
      "epss_percentile": 0.10404,
      "kev": false,
      "kev_due_at": null,
      "vendor": null,
      "product": "mautic/core",
      "cwe": "CWE-863",
      "title": "An authorization bypass vulnerability exists in the Mautic 7 API v2 endpoints (utilizing API Platform). Under certain conditions, roles configured with owner-scope restrictions (such as `viewown` or `editown`) are not properly enforced. This allows low-privilege authenticated API users to bypass ownership-logic controls and access or modify resources belonging to other users.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9808"
    },
    {
      "rank": 191,
      "cve_id": "CVE-2026-45615",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00197,
      "epss_percentile": 0.09797,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mouse07410",
      "product": "asn1c",
      "cwe": "CWE-20",
      "title": "mouse07410/asn1c: 1-byte Heap Out-of-Bounds Read in `INTEGER_decode_oer` via Malformed OER Payload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45615"
    },
    {
      "rank": 192,
      "cve_id": "CVE-2026-9714",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00197,
      "epss_percentile": 0.09858,
      "kev": false,
      "kev_due_at": null,
      "vendor": "creaweb2b",
      "product": "Simple Divi Shortcode",
      "cwe": "CWE-79",
      "title": "Simple Divi Shortcode <= 1.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'id' Shortcode Attribute",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9714"
    },
    {
      "rank": 193,
      "cve_id": "CVE-2026-10078",
      "cvss_base": 2.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00196,
      "epss_percentile": 0.09721,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Quay 3",
      "cwe": "CWE-598",
      "title": "Quay/config-tool: quay/config-tool: gitlab oauth client_secret exposed in url querystring",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10078"
    },
    {
      "rank": 194,
      "cve_id": "CVE-2026-45620",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00193,
      "epss_percentile": 0.0935,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WWBN",
      "product": "AVideo",
      "cwe": "CWE-204",
      "title": "AVideo CVE-2026-43881 incomplete fix - `objects/mention.json.php:17` is an unauthenticated user enumeration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45620"
    },
    {
      "rank": 195,
      "cve_id": "CVE-2026-10052",
      "cvss_base": 4.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00186,
      "epss_percentile": 0.08532,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Quay 3",
      "cwe": "CWE-918",
      "title": "Quay/config-tool: quay/config-tool: ssrf via unfiltered ldap and smtp config validation endpoints",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10052"
    },
    {
      "rank": 196,
      "cve_id": "CVE-2026-45627",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00185,
      "epss_percentile": 0.08377,
      "kev": false,
      "kev_due_at": null,
      "vendor": "getarcaneapp",
      "product": "arcane",
      "cwe": "CWE-79",
      "title": "Arcane: Unauthenticated reflected XSS via SVG color parameter in /api/app-images/logo enables admin account takeover",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45627"
    },
    {
      "rank": 197,
      "cve_id": "CVE-2026-33386",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00185,
      "epss_percentile": 0.08456,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenSolution",
      "product": "QuickCMS",
      "cwe": "CWE-79",
      "title": "XSS in QuickCMS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-33386"
    },
    {
      "rank": 198,
      "cve_id": "CVE-2026-10101",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00182,
      "epss_percentile": 0.0809,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Multicluster Engine for Kubernetes",
      "cwe": "CWE-201",
      "title": "Assisted-service: assisted-service: infraenv status leaks referenced pull-secret contents to namespace view users",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10101"
    },
    {
      "rank": 199,
      "cve_id": "CVE-2018-25383",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00181,
      "epss_percentile": 0.08036,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Commentcamarche",
      "product": "Free MP3 CD Ripper",
      "cwe": "CWE-121",
      "title": "Free MP3 CD Ripper 2.8 Buffer Overflow SEH DEP Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2018-25383"
    },
    {
      "rank": 200,
      "cve_id": "CVE-2026-49384",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00181,
      "epss_percentile": 0.0799,
      "kev": false,
      "kev_due_at": null,
      "vendor": "JetBrains",
      "product": "PyCharm",
      "cwe": "CWE-79",
      "title": "In JetBrains PyCharm before 2025.3.4 stored XSS in Jupyter notebook Markdown cells was possible",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49384"
    },
    {
      "rank": 201,
      "cve_id": "CVE-2026-49316",
      "cvss_base": 4.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00181,
      "epss_percentile": 0.07972,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Indian Motorcycle",
      "product": "Scout Bobber + Tech",
      "cwe": "CWE-440",
      "title": "Indian Scout Bobber 2025 WCM CAN bus-off attack silently bypasses anti-theft shutdown",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49316"
    },
    {
      "rank": 202,
      "cve_id": "CVE-2026-10057",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00176,
      "epss_percentile": 0.07478,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ITP Technology",
      "product": "ITS Intelligent SCADA System",
      "cwe": "CWE-79",
      "title": "ITP Technology｜ITS Intelligent SCADA System - Stored Cross-Site Scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10057"
    },
    {
      "rank": 203,
      "cve_id": "CVE-2026-10058",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00176,
      "epss_percentile": 0.07478,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ITP Technology",
      "product": "ITS Intelligent SCADA System",
      "cwe": "CWE-79",
      "title": "ITP Technology｜ITS Intelligent SCADA System - Stored Cross-Site Scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10058"
    },
    {
      "rank": 204,
      "cve_id": "CVE-2018-25387",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00175,
      "epss_percentile": 0.07351,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Sitejo",
      "product": "HaPe PKH",
      "cwe": "CWE-352",
      "title": "HaPe PKH 1.1 Cross-Site Request Forgery via aksi_user.php",
      "url": "https://www.cve.org/CVERecord?id=CVE-2018-25387"
    },
    {
      "rank": 205,
      "cve_id": "CVE-2026-49324",
      "cvss_base": 4.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00174,
      "epss_percentile": 0.07194,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Indian Motorcycle",
      "product": "Scout Bobber + Tech",
      "cwe": "CWE-307",
      "title": "Indian Scout Bobber 2025 WCM brute-force",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49324"
    },
    {
      "rank": 206,
      "cve_id": "CVE-2026-32906",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00173,
      "epss_percentile": 0.07088,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenClaw",
      "product": "OpenClaw",
      "cwe": "CWE-863",
      "title": "OpenClaw < 2026.5.12 - Privilege Escalation in Slack Plugin Approvals via Exec Approver Gate",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-32906"
    },
    {
      "rank": 207,
      "cve_id": "CVE-2026-9831",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00172,
      "epss_percentile": 0.07006,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Extreme Networks",
      "product": "Extreme Platform ONE",
      "cwe": "CWE-362",
      "title": "ExtremeCloud IQ Cross Tenant Data Exposure via Extreme Platform One Authentication Race Condition",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9831"
    },
    {
      "rank": 208,
      "cve_id": "CVE-2026-45668",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0017,
      "epss_percentile": 0.06751,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TriliumNext",
      "product": "Trilium",
      "cwe": "CWE-22",
      "title": "Trilium Notes : Note Import to RCE via #docName Path Traversal (Safe Import Enabled)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45668"
    },
    {
      "rank": 209,
      "cve_id": "CVE-2026-49380",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0017,
      "epss_percentile": 0.06796,
      "kev": false,
      "kev_due_at": null,
      "vendor": "JetBrains",
      "product": "TeamCity",
      "cwe": "CWE-601",
      "title": "In JetBrains TeamCity before 2026.1 open redirect in the SAML plugin was possible",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49380"
    },
    {
      "rank": 210,
      "cve_id": "CVE-2026-42951",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00169,
      "epss_percentile": 0.06647,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Danelec",
      "product": "MacGregor Voyage Data Recorder (VDR) G4e",
      "cwe": "CWE-522",
      "title": "MacGregor Voyage Data Recorder (VDR) G4e Insufficiently Protected Credentials",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42951"
    },
    {
      "rank": 211,
      "cve_id": "CVE-2026-9809",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00164,
      "epss_percentile": 0.06066,
      "kev": false,
      "kev_due_at": null,
      "vendor": null,
      "product": "mautic/core",
      "cwe": "CWE-79",
      "title": "A stored Cross-Site Scripting (XSS) vulnerability exists in the Projects component of Mautic 7. When displaying project tags and popovers on administrative detail views (such as campaigns, emails, or forms), user-supplied project names are rendered without proper sanitization. An authenticated user with permissions to create or edit projects can exploit this to inject malicious script payloads. When an administrative user views an entity associated with a compromised project and hovers over its tag, the injected script executes within the context of their active browser session. This could allow an attacker to perform administrative actions on behalf of the victim, alter system configurations, or exfiltrate sensitive data.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9809"
    },
    {
      "rank": 212,
      "cve_id": "CVE-2018-25397",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00162,
      "epss_percentile": 0.0586,
      "kev": false,
      "kev_due_at": null,
      "vendor": "joeyrush",
      "product": "PHP-SHOP master",
      "cwe": "CWE-352",
      "title": "PHP-SHOP 1.0 Cross-Site Request Forgery via users.php",
      "url": "https://www.cve.org/CVERecord?id=CVE-2018-25397"
    },
    {
      "rank": 213,
      "cve_id": "CVE-2026-47694",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00162,
      "epss_percentile": 0.05891,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WWBN",
      "product": "AVideo",
      "cwe": "CWE-79",
      "title": "WWBN AVideo: Stored XSS via unescaped Gallery category description",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47694"
    },
    {
      "rank": 214,
      "cve_id": "CVE-2026-49325",
      "cvss_base": 4.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0016,
      "epss_percentile": 0.05722,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Indian Motorcycle",
      "product": "Scout Bobber + Tech",
      "cwe": "CWE-693",
      "title": "Indian Scout Bobber 2025 WCM voltage-based shutdown",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49325"
    },
    {
      "rank": 215,
      "cve_id": "CVE-2025-14042",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00159,
      "epss_percentile": 0.05609,
      "kev": false,
      "kev_due_at": null,
      "vendor": "themesuite",
      "product": "Automotive Car Dealership Business WordPress Theme",
      "cwe": "CWE-79",
      "title": "Automotive Car Dealership Business WordPress Theme <= 13.4.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Portfolio Project Details",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-14042"
    },
    {
      "rank": 216,
      "cve_id": "CVE-2026-36324",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00155,
      "epss_percentile": 0.05148,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-79",
      "title": "SourceCodester Doctor Appointment System 1.0 is vulnerable to Cross Site Scripting (XSS) due to improper handling of user supplied input in the user registration functionality in register.php.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-36324"
    },
    {
      "rank": 217,
      "cve_id": "CVE-2026-35673",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00155,
      "epss_percentile": 0.05186,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenClaw",
      "product": "OpenClaw",
      "cwe": "CWE-863",
      "title": "OpenClaw < 2026.4.29 - SSRF Policy Bypass via Browser Debug/Export Routes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-35673"
    },
    {
      "rank": 218,
      "cve_id": "CVE-2026-48810",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00155,
      "epss_percentile": 0.05203,
      "kev": false,
      "kev_due_at": null,
      "vendor": "freescout-help-desk",
      "product": "freescout",
      "cwe": "CWE-285",
      "title": "FreeScout: Thread Edit Authorization Bypass via Missing Mailbox Check",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48810"
    },
    {
      "rank": 219,
      "cve_id": "CVE-2026-48811",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00155,
      "epss_percentile": 0.05203,
      "kev": false,
      "kev_due_at": null,
      "vendor": "freescout-help-desk",
      "product": "freescout",
      "cwe": "CWE-862",
      "title": "FreeScout: Thread Deletion Bypasses Mailbox Access Revocation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48811"
    },
    {
      "rank": 220,
      "cve_id": "CVE-2026-33384",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00154,
      "epss_percentile": 0.05104,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenSolution",
      "product": "QuickCMS",
      "cwe": "CWE-384",
      "title": "Session Fixation in QuickCMS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-33384"
    },
    {
      "rank": 221,
      "cve_id": "CVE-2026-45660",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00151,
      "epss_percentile": 0.04818,
      "kev": false,
      "kev_due_at": null,
      "vendor": "statamic",
      "product": "cms",
      "cwe": "CWE-918",
      "title": "Statamic: Server-Side Request Forgery via Glide",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45660"
    },
    {
      "rank": 222,
      "cve_id": "CVE-2026-34507",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00148,
      "epss_percentile": 0.04503,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenClaw",
      "product": "OpenClaw",
      "cwe": "CWE-863",
      "title": "OpenClaw < 2026.4.29 - Policy Bypass in QQBot Admin Commands via DM-only and allowFrom Checks",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34507"
    },
    {
      "rank": 223,
      "cve_id": "CVE-2025-41280",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00146,
      "epss_percentile": 0.04398,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Waterfall",
      "product": "WF-500",
      "cwe": "CWE-23",
      "title": "Nozomi Networks Labs identified a CWE-23: Relative Path Traversal (Zip Slip) in Waterfall WF-500 RX Host in version 7.9.1.0 R2502171040 that allows attackers with access to the TX Host to execute code on the RX Host when a MySQL connector is configured and file compression is enabled.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-41280"
    },
    {
      "rank": 224,
      "cve_id": "CVE-2026-9557",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00146,
      "epss_percentile": 0.04354,
      "kev": false,
      "kev_due_at": null,
      "vendor": null,
      "product": "mautic/core",
      "cwe": "CWE-918",
      "title": "A Server-Side Request Forgery (SSRF) vulnerability exists in Mautic's Focus component. Due to insufficient validation of user-supplied URLs, an authenticated user can trigger outbound HTTP requests from the hosting server, enabling internal network reconnaissance or forcing requests to arbitrary internal or external destinations.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9557"
    },
    {
      "rank": 225,
      "cve_id": "CVE-2026-40528",
      "cvss_base": 1,
      "cvss_severity": "LOW",
      "epss_score": 0.00146,
      "epss_percentile": 0.04392,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenSC",
      "product": "OpenSC",
      "cwe": "CWE-121",
      "title": "OpenSC < 0.27.0 Buffer Overrun in do_key_value() via profile.c",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40528"
    },
    {
      "rank": 226,
      "cve_id": "CVE-2026-47123",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00145,
      "epss_percentile": 0.04291,
      "kev": false,
      "kev_due_at": null,
      "vendor": "freescout-help-desk",
      "product": "freescout",
      "cwe": "CWE-290",
      "title": "FreeScout: Agent Impersonation via Missing HMAC Verification on Notification Reply Message-ID Path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47123"
    },
    {
      "rank": 227,
      "cve_id": "CVE-2026-45555",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00143,
      "epss_percentile": 0.04122,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MarcelRoozekrans",
      "product": "roslyn-codelens-mcp",
      "cwe": "CWE-94",
      "title": "Roslyn CodeLens MCP Server: Untrusted Roslyn Analyzer Execution via get_diagnostics Leads to Arbitrary Code Execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45555"
    },
    {
      "rank": 228,
      "cve_id": "CVE-2026-49317",
      "cvss_base": 1,
      "cvss_severity": "LOW",
      "epss_score": 0.00143,
      "epss_percentile": 0.04062,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Indian Motorcycle",
      "product": "Scout Bobber + Tech",
      "cwe": "CWE-636",
      "title": "Indian Scout Bobber 2025 Infotainment Digital Round skips PIN entry when WCM is silent at boot",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49317"
    },
    {
      "rank": 229,
      "cve_id": "CVE-2026-49318",
      "cvss_base": 1,
      "cvss_severity": "LOW",
      "epss_score": 0.00143,
      "epss_percentile": 0.04062,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Indian Motorcycle",
      "product": "Scout Bobber + Tech",
      "cwe": "CWE-636",
      "title": "Indian Scout Bobber 2025 Infotainment Digital Round skips PIN entry when WCM is silent at boot",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49318"
    },
    {
      "rank": 230,
      "cve_id": "CVE-2026-44611",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00141,
      "epss_percentile": 0.0396,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Danelec",
      "product": "MacGregor Voyage Data Recorder (VDR) G4e",
      "cwe": "CWE-916",
      "title": "MacGregor Voyage Data Recorder (VDR) G4e Use of Password Hash With Insufficient Computational Effort",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44611"
    },
    {
      "rank": 231,
      "cve_id": "CVE-2026-44698",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00136,
      "epss_percentile": 0.03535,
      "kev": false,
      "kev_due_at": null,
      "vendor": "home-assistant",
      "product": "core",
      "cwe": "CWE-94",
      "title": "Home Assistant: Cross-origin iframe access token exfiltration via WebView JS bridge callback injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44698"
    },
    {
      "rank": 232,
      "cve_id": "CVE-2026-45619",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00136,
      "epss_percentile": 0.03471,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WWBN",
      "product": "AVideo",
      "cwe": "CWE-367",
      "title": "AVideo CVE-2026-43884 incomplete fix - `isSSRFSafeURL()` call sites still discard the `$resolvedIP` out-param at master HEAD post",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45619"
    },
    {
      "rank": 233,
      "cve_id": "CVE-2026-45580",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00136,
      "epss_percentile": 0.03501,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WWBN",
      "product": "AVideo",
      "cwe": "CWE-79",
      "title": "WWBN AVideo Live: stored XSS via unescaped stream key in modeYoutubeLive.php class attribute",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45580"
    },
    {
      "rank": 234,
      "cve_id": "CVE-2026-49382",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00135,
      "epss_percentile": 0.03432,
      "kev": false,
      "kev_due_at": null,
      "vendor": "JetBrains",
      "product": "IntelliJ IDEA",
      "cwe": "CWE-1336",
      "title": "In JetBrains IntelliJ IDEA before 2026.1 code execution was possible via template injection in the Copyright plugin",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49382"
    },
    {
      "rank": 235,
      "cve_id": "CVE-2026-7480",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00135,
      "epss_percentile": 0.03461,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ASUS",
      "product": "ASUS System Control Interface",
      "cwe": "CWE-732",
      "title": "An Incorrect Permission Assignment for Critical Resource vulnerability in ASUS System Control Interface allows a local user to elevate privileges to SYSTEM and execute arbitrary code via a crafted RPC call that bypass the validation mechanism. Refer to the 'Security Update for ASUS System Control Interface' section on the ASUS Security Advisory for more information.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7480"
    },
    {
      "rank": 236,
      "cve_id": "CVE-2026-9811",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00133,
      "epss_percentile": 0.03273,
      "kev": false,
      "kev_due_at": null,
      "vendor": null,
      "product": "mautic/core",
      "cwe": "CWE-79",
      "title": "A stored Cross-Site Scripting (XSS) vulnerability exists in the project selector component of Mautic 7. When rendering selection menus for associating projects with system entities, the application fails to sanitize project names returned via AJAX before injecting them into the DOM as option fields. An authenticated user with permissions to create projects can exploit this to store a malicious script payload in the project's name. When another administrative user subsequently opens an entity editor containing the project selector, the injected script executes within the context of their active browser session. This could allow an attacker to hijack the session, perform unauthorized state coordination, or access organizational data within the dashboard.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9811"
    },
    {
      "rank": 237,
      "cve_id": "CVE-2026-4387",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": 0.00132,
      "epss_percentile": 0.03229,
      "kev": false,
      "kev_due_at": null,
      "vendor": "StrongDM",
      "product": "StrongDM Desktop Application",
      "cwe": "CWE-312",
      "title": "Unencrypted storage of authentication state in StrongDM Desktop Application state.kv file",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-4387"
    },
    {
      "rank": 238,
      "cve_id": "CVE-2026-10099",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00125,
      "epss_percentile": 0.02618,
      "kev": false,
      "kev_due_at": null,
      "vendor": "XX-net",
      "product": "XX-Net",
      "cwe": "CWE-1286",
      "title": "XX-Net V5.16.6 WebSocket Frame Parsing Data Corruption via simple_http_server.py",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10099"
    },
    {
      "rank": 239,
      "cve_id": "CVE-2026-6892",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00123,
      "epss_percentile": 0.02483,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Canon Inc.",
      "product": "Canon PIXUS iX6800 Series CUPS Printer Driver for macOS",
      "cwe": "CWE-59",
      "title": "Improper handling of symbolic links in the installer of CUPS Printer Driver for macOS(*) may allow a local attacker with login privileges to exploit a specially crafted symbolic link during installation to modify permissions of directories for which they would not normally have authorization. *:Canon PIXUS iX6800 Series CUPS Printer Driver for macOS Version 16.91.0.0 or earlier (Japan) Canon PIXMA MG2500 Series and iX6800 Series CUPS Printer Driver for macOS Version 16.91.0.0 or earlier (US and Europe)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6892"
    },
    {
      "rank": 240,
      "cve_id": "CVE-2025-41278",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0012,
      "epss_percentile": 0.02217,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Waterfall",
      "product": "WF-500",
      "cwe": "CWE-125",
      "title": "Nozomi Networks Labs identified a CWE-125: Out-of-bounds Read in Waterfall WF-500 RX Host in version 7.10.0.0 R2601141040 that allows attackers with access to the TX Host to execute code on the RX Host.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-41278"
    },
    {
      "rank": 241,
      "cve_id": "CVE-2026-47696",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0012,
      "epss_percentile": 0.02174,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WWBN",
      "product": "AVideo",
      "cwe": "CWE-345",
      "title": "WWBN AVideo: Authenticated wallet credit bypass in AuthorizeNet processPayment endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47696"
    },
    {
      "rank": 242,
      "cve_id": "CVE-2026-45613",
      "cvss_base": 3.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00111,
      "epss_percentile": 0.01543,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rizinorg",
      "product": "rizin",
      "cwe": "CWE-125",
      "title": "Rizin: Heap-buffer-overflow in OMF parser",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45613"
    },
    {
      "rank": 243,
      "cve_id": "CVE-2026-45610",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0011,
      "epss_percentile": 0.01467,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WWBN",
      "product": "AVideo",
      "cwe": "CWE-306",
      "title": "WWBN AVideo plugin/LoginControl/set.json.php: 2FA toggle endpoint has no CSRF protection, letting an attacker page silently disable a logged-in victim's 2FA",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45610"
    },
    {
      "rank": 244,
      "cve_id": "CVE-2026-49383",
      "cvss_base": 3.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00109,
      "epss_percentile": 0.01415,
      "kev": false,
      "kev_due_at": null,
      "vendor": "JetBrains",
      "product": "IntelliJ IDEA",
      "cwe": "CWE-611",
      "title": "In JetBrains IntelliJ IDEA before 2026.1 xXE in the UI Designer form parser was possible",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49383"
    },
    {
      "rank": 245,
      "cve_id": "CVE-2026-49323",
      "cvss_base": 4.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00107,
      "epss_percentile": 0.01285,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Indian Motorcycle",
      "product": "Scout Bobber + Tech",
      "cwe": "CWE-327",
      "title": "Indian Scout Bobber 2025 WCM-to-ECM weak authentication",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49323"
    },
    {
      "rank": 246,
      "cve_id": "CVE-2026-49322",
      "cvss_base": 4.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00103,
      "epss_percentile": 0.01131,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Indian Motorcycle",
      "product": "Scout Bobber + Tech",
      "cwe": "CWE-294",
      "title": "Indian Scout Bobber 2025 Infotainment-to-WCM weak authentication allows recovery of user PIN from observed exchange",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49322"
    },
    {
      "rank": 247,
      "cve_id": "CVE-2026-45324",
      "cvss_base": 3.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00101,
      "epss_percentile": 0.01027,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rizinorg",
      "product": "rizin",
      "cwe": "CWE-415",
      "title": "Rizin: Double free in cmd_search.c",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45324"
    },
    {
      "rank": 248,
      "cve_id": "CVE-2026-44640",
      "cvss_base": 4.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00096,
      "epss_percentile": 0.00807,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nanomq",
      "product": "nanomq",
      "cwe": "CWE-843",
      "title": "NanoMQ: QUIC Dialer Close Type Confusion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44640"
    },
    {
      "rank": 249,
      "cve_id": "CVE-2026-8070",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.0009,
      "epss_percentile": 0.00521,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ASUS",
      "product": "Armoury Crate",
      "cwe": "CWE-732",
      "title": "Incorrect permission assignment for a critical resource in Armoury Crate allows a local user to bypass the driver’s validation mechanism, resulting in unauthorized read and write access to physical memory.Refer to the ' Security Update for Armoury Crate App ' section on the ASUS Security Advisory for more information.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8070"
    }
  ],
  "transactions": [
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-39276",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-39276. Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-44421",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-44421 (FreeRDP). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-44422",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-44422 (FreeRDP). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-45352",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-45352 (yhirose cpp-httplib). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-45372",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-45372 (yhirose cpp-httplib). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-45700",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-45700 (FreeRDP). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-45731",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-45731 (WWBN AVideo). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-46337",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-46337 (WWBN AVideo). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-46527",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-46527 (yhirose cpp-httplib). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-47694",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-47694 (WWBN AVideo). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-47696",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-47696 (WWBN AVideo). Public exploit reference added."
    }
  ],
  "attribution": "CVE Program, NVD (NIST), CISA KEV, FIRST EPSS, OSV. See /security/methodology/."
}
