{
  "day": "2026-06-01",
  "boundary": "UTC calendar day",
  "published_count": 377,
  "by_severity": {
    "CRITICAL": 22,
    "HIGH": 136,
    "MEDIUM": 144,
    "LOW": 74
  },
  "kev_count": 1,
  "exploit_reference_count": 15,
  "awaiting_enrichment_count": 1,
  "ranking": "Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.",
  "results": [
    {
      "rank": 1,
      "cve_id": "CVE-2024-21182",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.4997,
      "epss_percentile": 0.98807,
      "kev": true,
      "kev_due_at": "2026-06-04",
      "vendor": "Oracle",
      "product": "WebLogic Server",
      "cwe": null,
      "title": "Oracle WebLogic Server",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-21182"
    },
    {
      "rank": 2,
      "cve_id": "CVE-2026-0826",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.24469,
      "epss_percentile": 0.97696,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HP Inc.",
      "product": "poly_trio_8300",
      "cwe": "CWE-121",
      "title": "Poly Voice – Possible Remote Control of Certain Poly Devices",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-0826"
    },
    {
      "rank": 3,
      "cve_id": "CVE-2026-44825",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.02161,
      "epss_percentile": 0.80754,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Solr",
      "cwe": "CWE-798",
      "title": "Apache Solr: Enabling BasicAuth using bin/solr CLI configures additional insecure users",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44825"
    },
    {
      "rank": 4,
      "cve_id": "CVE-2026-9614",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0144,
      "epss_percentile": 0.71056,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ivanti",
      "product": "Neurons for ITSM (On-Premises)",
      "cwe": "CWE-284",
      "title": "An Improper Access Control vulnerability in Ivanti Neurons for ITSM (cloud and on-premises) allows a remote authenticated attacker to gain administrative access.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9614"
    },
    {
      "rank": 5,
      "cve_id": "CVE-2026-10273",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.01367,
      "epss_percentile": 0.69664,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "php-censor",
      "cwe": "CWE-77",
      "title": "php-censor Webhook Endpoint GitBuild.php os command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10273"
    },
    {
      "rank": 6,
      "cve_id": "CVE-2026-10214",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.01336,
      "epss_percentile": 0.6895,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zhayujie",
      "product": "chatgpt-on-wechat",
      "cwe": "CWE-77",
      "title": "zhayujie chatgpt-on-wechat Bash Tool bash.py _get_safety_warning os command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10214"
    },
    {
      "rank": 7,
      "cve_id": "CVE-2026-10219",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.01336,
      "epss_percentile": 0.68949,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nextlevelbuilder",
      "product": "GoClaw",
      "cwe": "CWE-77",
      "title": "nextlevelbuilder GoClaw write_file Tool fsbridge.go FsBridge.WriteFile os command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10219"
    },
    {
      "rank": 8,
      "cve_id": "CVE-2026-42253",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.01107,
      "epss_percentile": 0.63229,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache ActiveMQ",
      "cwe": "CWE-79",
      "title": "Apache ActiveMQ, Apache ActiveMQ Web: HTTP Response Header Injection via JMS Message Properties",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42253"
    },
    {
      "rank": 9,
      "cve_id": "CVE-2026-49121",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.01104,
      "epss_percentile": 0.63168,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ROCm",
      "product": "aiter",
      "cwe": "CWE-502",
      "title": "AI Tensor Engine for ROCm (AITER) 0.1.14 Unauthenticated RCE via MessageQueue.recv() Pickle Deserialization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49121"
    },
    {
      "rank": 10,
      "cve_id": "CVE-2026-10279",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.01088,
      "epss_percentile": 0.62669,
      "kev": false,
      "kev_due_at": null,
      "vendor": "hiraishikentaro",
      "product": "wezterm-mcp",
      "cwe": "CWE-77",
      "title": "hiraishikentaro wezterm-mcp switch_pane/write_to_specific_pane wezterm_executor.ts os command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10279"
    },
    {
      "rank": 11,
      "cve_id": "CVE-2018-25427",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00923,
      "epss_percentile": 0.57597,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Armcode",
      "product": "Arm Whois",
      "cwe": "CWE-121",
      "title": "Arm Whois 3.11 Buffer Overflow via SEH Overwrite",
      "url": "https://www.cve.org/CVERecord?id=CVE-2018-25427"
    },
    {
      "rank": 12,
      "cve_id": "CVE-2026-48188",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00737,
      "epss_percentile": 0.51673,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OTRS AG",
      "product": "OTRS",
      "cwe": "CWE-20",
      "title": "SQL Injection via MySQL Quote Method",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48188"
    },
    {
      "rank": 13,
      "cve_id": "CVE-2026-8931",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0072,
      "epss_percentile": 0.51074,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Disig",
      "product": "Web Signer",
      "cwe": "CWE-94",
      "title": "Critical RCE vulnerability in Disig Web Signer",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8931"
    },
    {
      "rank": 14,
      "cve_id": "CVE-2026-40861",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00691,
      "epss_percentile": 0.50042,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Airflow",
      "cwe": "CWE-59",
      "title": "Apache Airflow: Arbitrary File Read via Log Symlink following in FileTaskHandler",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40861"
    },
    {
      "rank": 15,
      "cve_id": "CVE-2026-10270",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00687,
      "epss_percentile": 0.49883,
      "kev": false,
      "kev_due_at": null,
      "vendor": "D-Link",
      "product": "DI-7001 MINI",
      "cwe": "CWE-119",
      "title": "D-Link DI-7001 MINI API httpd_debug.asp sprintf stack-based overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10270"
    },
    {
      "rank": 16,
      "cve_id": "CVE-2026-45360",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00676,
      "epss_percentile": 0.4944,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Airflow",
      "cwe": "CWE-502",
      "title": "Apache Airflow: Arbitrary import in custom deadline-reference deserialization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45360"
    },
    {
      "rank": 17,
      "cve_id": "CVE-2026-24782",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00667,
      "epss_percentile": 0.49094,
      "kev": false,
      "kev_due_at": null,
      "vendor": "kiteworks",
      "product": "Secure Data Forms",
      "cwe": "CWE-89",
      "title": "Kiteworks Secure Data Forms has a SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-24782"
    },
    {
      "rank": 18,
      "cve_id": "CVE-2026-47294",
      "cvss_base": 8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00662,
      "epss_percentile": 0.48911,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft SharePoint Enterprise Server 2016",
      "cwe": "CWE-78",
      "title": "Microsoft SharePoint Server Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47294"
    },
    {
      "rank": 19,
      "cve_id": "CVE-2026-40961",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00649,
      "epss_percentile": 0.48342,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Airflow",
      "cwe": "CWE-601",
      "title": "Apache Airflow: Open Redirect Bypass Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40961"
    },
    {
      "rank": 20,
      "cve_id": "CVE-2026-37226",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00642,
      "epss_percentile": 0.48033,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-476",
      "title": "FlexRIC v2.0.0 crashes when the iApp receives an E42_RIC_SUBSCRIPTION_REQUEST referencing a non-existent E2 Node. The lookup function returns NULL, which is enforced by assert() in Debug builds (SIGABRT) and dereferenced in Release builds (SIGSEGV). A remote unauthenticated attacker can crash the iApp process (port 36422) by sending a subscription request with an arbitrary global_e2_node_id.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-37226"
    },
    {
      "rank": 21,
      "cve_id": "CVE-2026-37228",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00642,
      "epss_percentile": 0.48033,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-617",
      "title": "FlexRIC v2.0.0 contains a reachable assertion in e2ap_recv_sctp_msg() (src/lib/ep/e2ap_ep.c). The function allocates a fixed 32KB receive buffer and enforces assert(rc < len) on the sctp_recvmsg() return value. A remote unauthenticated attacker can send a single SCTP message with payload >= 32,768 bytes to crash the near-RT RIC, iApp, E2 Agent, or xApp process via SIGABRT. No valid E2AP PDU is required. All four SCTP endpoint types (ports 36421 and 36422) share this vulnerable code path. In Release builds (NDEBUG), the stripped assertion leads to a signed-to-unsigned integer overflow and potential out-of-bounds read.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-37228"
    },
    {
      "rank": 22,
      "cve_id": "CVE-2026-37230",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00642,
      "epss_percentile": 0.48033,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-476",
      "title": "FlexRIC v2.0.0 crashes when the near-RT RIC receives a RIC_INDICATION message with a ran_func_id that does not exist in its registry. The lookup returns NULL, triggering assert() in Debug builds (SIGABRT) or NULL pointer dereference in Release builds (SIGSEGV). A remote unauthenticated attacker can crash the near-RT RIC (port 36421) by sending a crafted RIC_INDICATION with an arbitrary ran_func_id value.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-37230"
    },
    {
      "rank": 23,
      "cve_id": "CVE-2026-10243",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00629,
      "epss_percentile": 0.47425,
      "kev": false,
      "kev_due_at": null,
      "vendor": "code-projects",
      "product": "Smart Parking System",
      "cwe": "CWE-287",
      "title": "code-projects Smart Parking System Admin Endpoint missing authentication",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10243"
    },
    {
      "rank": 24,
      "cve_id": "CVE-2026-37229",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00624,
      "epss_percentile": 0.47217,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-617",
      "title": "FlexRIC v2.0.0 contains a reachable assertion in e2ap_create_pdu() triggered when ASN.1 PER decoding fails. A remote unauthenticated attacker can send any non-PER byte sequence (e.g., a single 0x00 byte) over SCTP to the near-RT RIC (port 36421) or iApp (port 36422) to crash the process via SIGABRT. The assertion is reached before any protocol-level validation occurs. All three E2AP protocol versions (v1.01, v2.03, v3.01) are affected.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-37229"
    },
    {
      "rank": 25,
      "cve_id": "CVE-2026-45505",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.006,
      "epss_percentile": 0.46069,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache ActiveMQ Broker",
      "cwe": "CWE-20",
      "title": "Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Jolokia `addNetworkConnector` Discovery Wrapper Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45505"
    },
    {
      "rank": 26,
      "cve_id": "CVE-2026-49361",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00581,
      "epss_percentile": 0.45174,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Fluss (incubating)",
      "cwe": "CWE-400",
      "title": "Apache Fluss Netty Frame Decoder Memory Exhaustion Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49361"
    },
    {
      "rank": 27,
      "cve_id": "CVE-2026-42359",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00571,
      "epss_percentile": 0.44726,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Airflow",
      "cwe": "CWE-502",
      "title": "Apache Airflow: Authenticated RCE via XCom PATCH endpoint — XComUpdateBody missing FORBIDDEN_XCOM_KEYS validator",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42359"
    },
    {
      "rank": 28,
      "cve_id": "CVE-2026-37235",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0057,
      "epss_percentile": 0.44676,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-284",
      "title": "FlexRIC v2.0.0 trusts the xapp_id field from E42 message payloads without binding it to the sender's SCTP association. The validation function valid_xapp_id() only checks that the value is within the assigned range. A remote unauthenticated attacker can impersonate any xApp by specifying their xapp_id in requests sent to the iApp (port 36422), causing responses to be misrouted to the victim xApp. This can crash the victim xApp, the RIC, or the iApp itself through state inconsistencies in the red-black tree data structure.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-37235"
    },
    {
      "rank": 29,
      "cve_id": "CVE-2026-42588",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00566,
      "epss_percentile": 0.44519,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache ActiveMQ Broker",
      "cwe": "CWE-20",
      "title": "Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Remote Code Execution via Jolokia addNetworkConnector",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42588"
    },
    {
      "rank": 30,
      "cve_id": "CVE-2026-25879",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00554,
      "epss_percentile": 0.43877,
      "kev": false,
      "kev_due_at": null,
      "vendor": "langroid",
      "product": "langroid",
      "cwe": "CWE-89",
      "title": "Langroid has Prompt to SQL Injection, Leading to RCE",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-25879"
    },
    {
      "rank": 31,
      "cve_id": "CVE-2026-7858",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00543,
      "epss_percentile": 0.43281,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dassault Systèmes",
      "product": "Teamwork Cloud - Standard Edition",
      "cwe": "CWE-502",
      "title": "Deserialization of Untrusted Data vulnerability affecting Teamwork Cloud from No Magic Release 2022x through No Magic Release 2026x and Magic Collaboration Studio from CATIA Magic Release 2022x through CATIA Magic Release 2026x",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7858"
    },
    {
      "rank": 32,
      "cve_id": "CVE-2026-48827",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00527,
      "epss_percentile": 0.42437,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache MINA SSHD",
      "cwe": "CWE-22",
      "title": "Apache MINA SSHD: Path traversal in org.apache.sshd:sshd-git",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48827"
    },
    {
      "rank": 33,
      "cve_id": "CVE-2026-9330",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00515,
      "epss_percentile": 0.41707,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "WebSphere Application Server",
      "cwe": "CWE-502",
      "title": "IBM WebSphere Application Server is affected by remote code execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9330"
    },
    {
      "rank": 34,
      "cve_id": "CVE-2024-52011",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00514,
      "epss_percentile": 0.41646,
      "kev": false,
      "kev_due_at": null,
      "vendor": "vitejs",
      "product": "launch-editor",
      "cwe": "CWE-77",
      "title": "launch-editor vulnerable to command injection via the crafted request on Windows",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-52011"
    },
    {
      "rank": 35,
      "cve_id": "CVE-2026-9311",
      "cvss_base": 9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00508,
      "epss_percentile": 0.41259,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "WebSphere Application Server",
      "cwe": "CWE-94",
      "title": "IBM WebSphere Application Server is affected by remote code execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9311"
    },
    {
      "rank": 36,
      "cve_id": "CVE-2026-49328",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00502,
      "epss_percentile": 0.40896,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Fesod (Incubating)",
      "cwe": "CWE-918",
      "title": "Apache Fesod (Incubating): Improper validation of user-supplied URLs leading to SSRF",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49328"
    },
    {
      "rank": 37,
      "cve_id": "CVE-2026-10206",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.005,
      "epss_percentile": 0.40785,
      "kev": false,
      "kev_due_at": null,
      "vendor": "D-Link",
      "product": "DI-8400",
      "cwe": "CWE-119",
      "title": "D-Link DI-8400 dbsrv.asp stack-based overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10206"
    },
    {
      "rank": 38,
      "cve_id": "CVE-2026-10288",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00496,
      "epss_percentile": 0.40516,
      "kev": false,
      "kev_due_at": null,
      "vendor": "code-projects",
      "product": "Hotel and Tourism Reservation System",
      "cwe": "CWE-287",
      "title": "code-projects Hotel and Tourism Reservation System Admin Login login.php password_verify improper authentication",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10288"
    },
    {
      "rank": 39,
      "cve_id": "CVE-2026-49298",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00489,
      "epss_percentile": 0.401,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Airflow",
      "cwe": "CWE-538",
      "title": "Apache Airflow: JWT Token Exposure in KubernetesExecutor Command-Line Arguments",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49298"
    },
    {
      "rank": 40,
      "cve_id": "CVE-2026-37231",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00488,
      "epss_percentile": 0.40062,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-191",
      "title": "FlexRIC v2.0.0 uses a uint16_t counter for xapp_id assignment but stores the value in uint32_t message fields. After 65,530+ E42_SETUP_REQUESTs, the 16-bit counter wraps around and produces duplicate xapp_ids. The iApp (port 36422) crashes when attempting to register a duplicate ID in its internal data structure. A remote attacker can trigger this by repeatedly connecting and requesting new xApp registrations.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-37231"
    },
    {
      "rank": 41,
      "cve_id": "CVE-2026-10259",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00484,
      "epss_percentile": 0.39799,
      "kev": false,
      "kev_due_at": null,
      "vendor": "H3C",
      "product": "Magic B0",
      "cwe": "CWE-119",
      "title": "H3C Magic B0 aspForm SetMobileAPInfoById stack-based overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10259"
    },
    {
      "rank": 42,
      "cve_id": "CVE-2026-40963",
      "cvss_base": 3.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00477,
      "epss_percentile": 0.39353,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Airflow",
      "cwe": "CWE-285",
      "title": "Apache Airflow: DAG authorization bypass on /ui/structure/structure_data",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40963"
    },
    {
      "rank": 43,
      "cve_id": "CVE-2026-41084",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00476,
      "epss_percentile": 0.39261,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Airflow",
      "cwe": "CWE-639",
      "title": "Apache Airflow: API authorization bypass: bulk TaskInstances allows cross-DAG mutation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41084"
    },
    {
      "rank": 44,
      "cve_id": "CVE-2026-45727",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00475,
      "epss_percentile": 0.3925,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CloakHQ",
      "product": "CloakBrowser",
      "cwe": "CWE-22",
      "title": "CloakBrowser: Unauthenticated path traversal via fingerprint parameter in cloakserve leads to arbitrary directory deletion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45727"
    },
    {
      "rank": 45,
      "cve_id": "CVE-2026-10292",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00472,
      "epss_percentile": 0.39036,
      "kev": false,
      "kev_due_at": null,
      "vendor": "UTT",
      "product": "HiPER 1200GW",
      "cwe": "CWE-119",
      "title": "UTT HiPER 1200GW formTaskEdit strcpy stack-based overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10292"
    },
    {
      "rank": 46,
      "cve_id": "CVE-2026-10293",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00472,
      "epss_percentile": 0.39035,
      "kev": false,
      "kev_due_at": null,
      "vendor": "UTT",
      "product": "HiPER 1200GW",
      "cwe": "CWE-119",
      "title": "UTT HiPER 1200GW formFireWall strcpy stack-based overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10293"
    },
    {
      "rank": 47,
      "cve_id": "CVE-2026-48866",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00468,
      "epss_percentile": 0.38769,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Rocketgenius Inc.",
      "product": "Gravity Forms",
      "cwe": "CWE-22",
      "title": "WordPress Gravity Forms plugin <= 2.10.0.1 - Arbitrary File Deletion vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48866"
    },
    {
      "rank": 48,
      "cve_id": "CVE-2026-9319",
      "cvss_base": 9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00458,
      "epss_percentile": 0.38088,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "WebSphere Application Server",
      "cwe": "CWE-502",
      "title": "IBM WebSphere Application Server is affected by a remote code execution vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9319"
    },
    {
      "rank": 49,
      "cve_id": "CVE-2026-37233",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00454,
      "epss_percentile": 0.37833,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-617",
      "title": "FlexRIC v2.0.0 contains an authorization bypass in the iApp's xApp isolation mechanism. The equality function eq_xapp_ric_gen_id() in src/ric/iApp/xapp_ric_id.c compares m0->xapp_id against itself (m0->xapp_id) instead of the other argument (m1->xapp_id), effectively ignoring the xApp identity dimension. A malicious xApp connected to the iApp (port 36422) can delete any other xApp's subscriptions by sending an E42_RIC_SUBSCRIPTION_DELETE_REQUEST with a matching ric_gen_id. This breaks multi-tenant isolation in any deployment with multiple xApps sharing the same RIC.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-37233"
    },
    {
      "rank": 50,
      "cve_id": "CVE-2026-40547",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00447,
      "epss_percentile": 0.37349,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SOPlanning",
      "product": "SOPlanning",
      "cwe": "CWE-22",
      "title": "Path Traversal in SOPlanning",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40547"
    },
    {
      "rank": 51,
      "cve_id": "CVE-2026-49157",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0044,
      "epss_percentile": 0.36782,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache ActiveMQ",
      "cwe": "CWE-276",
      "title": "Apache ActiveMQ: Authenticated low-privilege Web users retain Jolokia broker-management capability by default",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49157"
    },
    {
      "rank": 52,
      "cve_id": "CVE-2026-7770",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00439,
      "epss_percentile": 0.36708,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "i Access Family",
      "cwe": "CWE-74",
      "title": "IBM i Access Client Solutions (ACS) is vulnerable to remote code execution when configured to listen for requests from IBM i Navigator",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7770"
    },
    {
      "rank": 53,
      "cve_id": "CVE-2026-37223",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00437,
      "epss_percentile": 0.36573,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-617",
      "title": "FlexRIC v2.0.0 contains a reachable assertion in the iApp message dispatcher. The dispatcher validates incoming E2AP messages against a 9-entry whitelist using assert(). A remote unauthenticated attacker can send any decodable E2AP PDU with a message type not in the whitelist to crash the iApp process (port 36422) via SIGABRT. Since iApp and the near-RT RIC share one process, this terminates the entire RIC service and disconnects all E2 Nodes and xApps.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-37223"
    },
    {
      "rank": 54,
      "cve_id": "CVE-2026-20452",
      "cvss_base": 8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00435,
      "epss_percentile": 0.36419,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MediaTek, Inc.",
      "product": "MediaTek chipset",
      "cwe": "CWE-122",
      "title": "In wlan AP driver, there is a possible memory corruption due to a heap buffer overflow. This could lead to remote (proximal/adjacent) code execution with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00480138; Issue ID: MSV-6295.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20452"
    },
    {
      "rank": 55,
      "cve_id": "CVE-2026-22872",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0043,
      "epss_percentile": 0.36013,
      "kev": false,
      "kev_due_at": null,
      "vendor": "projectcapsule",
      "product": "capsule",
      "cwe": "CWE-20",
      "title": "Capsule TenantResource RawItems Cluster-Scoped Resource Creation Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-22872"
    },
    {
      "rank": 56,
      "cve_id": "CVE-2026-37222",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00428,
      "epss_percentile": 0.35853,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-617",
      "title": "FlexRIC v2.0.0 uses hardcoded assertions to validate Information Element (IE) counts in decoded E2AP messages. A remote unauthenticated attacker can send a valid E2AP PDU containing an unexpected number of IEs (e.g., an E2setupRequest with extra optional fields) to crash the near-RT RIC (port 36421) or iApp (port 36422) via SIGABRT. The code asserts exact IE counts rather than validating against protocol-specified ranges.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-37222"
    },
    {
      "rank": 57,
      "cve_id": "CVE-2026-37224",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00428,
      "epss_percentile": 0.35853,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-617",
      "title": "FlexRIC v2.0.0 crashes when receiving a duplicate E2_SETUP_REQUEST from the same or spoofed E2 Node. The iApp registry enforces node ID uniqueness via assert() rather than graceful rejection. A remote unauthenticated attacker can crash the iApp process (port 36421) by sending two E2_SETUP_REQUESTs with the same E2 node configuration, triggering SIGABRT.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-37224"
    },
    {
      "rank": 58,
      "cve_id": "CVE-2026-45192",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00425,
      "epss_percentile": 0.35669,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Airflow",
      "cwe": "CWE-200",
      "title": "Apache Airflow: Incomplete Redaction of Sensitive Fields in Connection Extra API Response",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45192"
    },
    {
      "rank": 59,
      "cve_id": "CVE-2026-49136",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00417,
      "epss_percentile": 0.34978,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Anionex",
      "product": "banana-slides",
      "cwe": "CWE-22",
      "title": "Banana Slides 0.4.0 Path Traversal via generate_image() in ai_service.py",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49136"
    },
    {
      "rank": 60,
      "cve_id": "CVE-2026-37225",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00415,
      "epss_percentile": 0.34826,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-617",
      "title": "FlexRIC v2.0.0 crashes when the iApp receives an E42_RIC_SUBSCRIPTION_REQUEST with an empty ricEventTriggerDefinition field. The E42 layer decoder accepts this as valid, but the E2AP encoder asserts a non-empty constraint when forwarding the request. A remote unauthenticated attacker can crash the iApp process (port 36422) via SIGABRT by exploiting this cross-layer validation mismatch.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-37225"
    },
    {
      "rank": 61,
      "cve_id": "CVE-2026-37227",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00415,
      "epss_percentile": 0.34825,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-617",
      "title": "FlexRIC v2.0.0 contains reachable assert(0) calls in stub message handlers for whitelisted but unimplemented E2AP message types in the near-RT RIC. A remote unauthenticated attacker can send a decodable E2AP PDU of such a type (e.g., E2nodeConfigurationUpdate) to crash the near-RT RIC process (port 36421) via SIGABRT. The message passes whitelist validation but triggers an unconditional assertion in the handler.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-37227"
    },
    {
      "rank": 62,
      "cve_id": "CVE-2024-40646",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00414,
      "epss_percentile": 0.34671,
      "kev": false,
      "kev_due_at": null,
      "vendor": "vertex-app",
      "product": "vertex",
      "cwe": "CWE-22",
      "title": "Vertex Vulnerable to Path Traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-40646"
    },
    {
      "rank": 63,
      "cve_id": "CVE-2019-25716",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00413,
      "epss_percentile": 0.34653,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dräger",
      "product": "Infinity Delta",
      "cwe": "CWE-15",
      "title": "Dräger Infinity Delta/Kappa Patient Monitor DoS via Malformed Network Packet",
      "url": "https://www.cve.org/CVERecord?id=CVE-2019-25716"
    },
    {
      "rank": 64,
      "cve_id": "CVE-2026-45156",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00412,
      "epss_percentile": 0.34503,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nextcloud",
      "product": "security-advisories",
      "cwe": "CWE-287",
      "title": "Nextcloud: Authentication Bypass in ID4me handling via Missing JWT Signature Verification in User OIDC",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45156"
    },
    {
      "rank": 65,
      "cve_id": "CVE-2026-10281",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00411,
      "epss_percentile": 0.34396,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Enderfga",
      "product": "claw-orchestrator",
      "cwe": "CWE-287",
      "title": "Enderfga claw-orchestrator API Endpoint embedded-server.ts EmbeddedServer missing authentication",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10281"
    },
    {
      "rank": 66,
      "cve_id": "CVE-2026-10216",
      "cvss_base": 2.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00406,
      "epss_percentile": 0.34013,
      "kev": false,
      "kev_due_at": null,
      "vendor": "unitedbyai",
      "product": "droidclaw",
      "cwe": "CWE-307",
      "title": "unitedbyai droidclaw claim Endpoint pairing.ts excessive authentication",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10216"
    },
    {
      "rank": 67,
      "cve_id": "CVE-2026-40545",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00404,
      "epss_percentile": 0.33795,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SOPlanning",
      "product": "SOPlanning",
      "cwe": "CWE-79",
      "title": "Reflected XSS in SOPlanning",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40545"
    },
    {
      "rank": 68,
      "cve_id": "CVE-2026-42674",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00394,
      "epss_percentile": 0.32786,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AAM Plugin",
      "product": "Advanced Access Manager",
      "cwe": "CWE-290",
      "title": "WordPress Advanced Access Manager plugin <= 7.1.0 - Bypass Vulnerability vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42674"
    },
    {
      "rank": 69,
      "cve_id": "CVE-2026-43624",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00393,
      "epss_percentile": 0.32606,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SWivid",
      "product": "F5-TTS",
      "cwe": "CWE-22",
      "title": "F5-TTS 1.1.20 Path Traversal via finetune_gradio.py create_data_project()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43624"
    },
    {
      "rank": 70,
      "cve_id": "CVE-2026-37232",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00393,
      "epss_percentile": 0.3267,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-369",
      "title": "An issue was discovered in OpenAirInterface5G 2.4.0 (nr-softmodem) in the E2SM-KPM RAN Function's PRB utilization metric calculation. The functions fill_RRU_PrbTotDl() and fill_RRU_PrbTotUl() in openair2/E2AP/RAN_FUNCTION/O-RAN/ran_func_kpm_subs.c (lines 182 and 197) compute PRB usage percentages by dividing by the difference of two consecutive total_prb_aggregate samples without checking for zero. When a malicious xApp sends a high volume of E42_RIC_SUBSCRIPTION_REQUESTs via the FlexRIC iApp (port 36422/SCTP), the E2 Agent generates KPM Indication reports at high frequency. If two consecutive sampling intervals yield identical PRB aggregate values, the divisor becomes zero, triggering SIGFPE and crashing the entire 5G base station process (nr-softmodem). This results in complete 5G cell service interruption for all connected UEs. No authentication is required.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-37232"
    },
    {
      "rank": 71,
      "cve_id": "CVE-2026-40964",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00393,
      "epss_percentile": 0.32635,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cloud Foundry Foundation",
      "product": "log-cache_release",
      "cwe": "CWE-287",
      "title": "Authentication Bypass in cf-auth-proxy in Cloud Foundry Foundation all installations allows an unauthenticated remote attacker to gain read access to every log and metric for every application and platform component via minting a JWT that the cf-auth-proxy accepts as a valid logs.admin token. Affected versions: - log-cache_release: all versions through v3.2.6 (inclusive); fixed in v3.2.7 or later - CF Deployment: all versions through v55.?.0 (inclusive); fixed in v55.?.0 or later (bundles log-cache_release v3.2.7)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40964"
    },
    {
      "rank": 72,
      "cve_id": "CVE-2026-45279",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00392,
      "epss_percentile": 0.32472,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nextcloud",
      "product": "security-advisories",
      "cwe": "CWE-22",
      "title": "Nextcloud: Limited path traversal via template API if using `{lang}` in config",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45279"
    },
    {
      "rank": 73,
      "cve_id": "CVE-2025-70099",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00384,
      "epss_percentile": 0.31764,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-476",
      "title": "A NULL pointer dereference in the ext4_dir_en_get_name_len function in include/ext4_dir.h of lwext4 1.0.0 allows attackers to cause a denial of service by supplying a specially crafted EXT4 filesystem image with malformed directory entries. During directory iteration, the code may fail to validate the directory entry pointer before accessing the name_len field, resulting in a segmentation fault. This affects versions based on (or equivalent to) the 2016-era codebase (1.0.0).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-70099"
    },
    {
      "rank": 74,
      "cve_id": "CVE-2026-42252",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00383,
      "epss_percentile": 0.31625,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Airflow",
      "cwe": "CWE-1336",
      "title": "Apache Airflow: BashOperator Jinja2 injection via dag_run.conf — low-privilege user pattern",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42252"
    },
    {
      "rank": 75,
      "cve_id": "CVE-2026-49139",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00382,
      "epss_percentile": 0.31503,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HKUDS",
      "product": "nanobot",
      "cwe": "CWE-918",
      "title": "Nanobot < 0.2.1 SSRF via Microsoft Teams Channel serviceUrl Poisoning",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49139"
    },
    {
      "rank": 76,
      "cve_id": "CVE-2026-48726",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00382,
      "epss_percentile": 0.31496,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Airflow",
      "cwe": "CWE-613",
      "title": "Apache Airflow: revoke_token() unreachable in FabAuthManager / KeycloakAuthManager logout path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48726"
    },
    {
      "rank": 77,
      "cve_id": "CVE-2026-5419",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00379,
      "epss_percentile": 0.31252,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-208",
      "title": "Gnutls: gnutls: information disclosure via timing side-channel in pkcs#7 padding removal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-5419"
    },
    {
      "rank": 78,
      "cve_id": "CVE-2026-46243",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00377,
      "epss_percentile": 0.30986,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-20",
      "title": "smb: client: reject userspace cifs.spnego descriptions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46243"
    },
    {
      "rank": 79,
      "cve_id": "CVE-2026-10224",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00372,
      "epss_percentile": 0.30532,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NousResearch",
      "product": "hermes-agent",
      "cwe": "CWE-400",
      "title": "NousResearch hermes-agent Webhook Endpoint feishu.py _handle_webhook_request resource consumption",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10224"
    },
    {
      "rank": 80,
      "cve_id": "CVE-2026-10213",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00372,
      "epss_percentile": 0.30487,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AstrBotDevs",
      "product": "AstrBot",
      "cwe": "CWE-22",
      "title": "AstrBotDevs AstrBot API Endpoint delete path traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10213"
    },
    {
      "rank": 81,
      "cve_id": "CVE-2026-10236",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00371,
      "epss_percentile": 0.30423,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "Water Billing Management System",
      "cwe": "CWE-266",
      "title": "SourceCodester Water Billing Management System User Management Endpoint Users.php save improper authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10236"
    },
    {
      "rank": 82,
      "cve_id": "CVE-2026-10532",
      "cvss_base": 2.9,
      "cvss_severity": "LOW",
      "epss_score": 0.0037,
      "epss_percentile": 0.30257,
      "kev": false,
      "kev_due_at": null,
      "vendor": "QOS.CH Sarl",
      "product": "logback",
      "cwe": "CWE-502",
      "title": "Logback deserialization whitelist bypass for Proxy objects",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10532"
    },
    {
      "rank": 83,
      "cve_id": "CVE-2026-49270",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00369,
      "epss_percentile": 0.30085,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache ActiveMQ Broker",
      "cwe": "CWE-1230",
      "title": "Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All: Durable Subscription Disclosure via Crafted BrokerInfo (OpenWire)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49270"
    },
    {
      "rank": 84,
      "cve_id": "CVE-2026-10300",
      "cvss_base": 2.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00368,
      "epss_percentile": 0.29982,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "SGLang",
      "cwe": "CWE-617",
      "title": "SGLang Inference HTTP Endpoint lora_manager.py assertion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10300"
    },
    {
      "rank": 85,
      "cve_id": "CVE-2026-41014",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00366,
      "epss_percentile": 0.29802,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Airflow",
      "cwe": "CWE-862",
      "title": "Apache Airflow: per-DAG RBAC bypass on /ui/partitioned_dag_runs endpoints",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41014"
    },
    {
      "rank": 86,
      "cve_id": "CVE-2026-46764",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00366,
      "epss_percentile": 0.29802,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Airflow",
      "cwe": "CWE-639",
      "title": "Apache Airflow: Event Log detail endpoint bypasses DAG-scoped event log permission filter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46764"
    },
    {
      "rank": 87,
      "cve_id": "CVE-2026-45275",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00358,
      "epss_percentile": 0.29042,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nextcloud",
      "product": "security-advisories",
      "cwe": "CWE-285",
      "title": "Nextcloud: Authorization bypass in approval feature allows unauthorized file sharing with approvers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45275"
    },
    {
      "rank": 88,
      "cve_id": "CVE-2026-45426",
      "cvss_base": 3.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00358,
      "epss_percentile": 0.28992,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Airflow",
      "cwe": "CWE-863",
      "title": "Apache Airflow: Log server JWT authorization bypass via Python lstrip() character stripping allows cross-Dag log access",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45426"
    },
    {
      "rank": 89,
      "cve_id": "CVE-2026-42251",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00356,
      "epss_percentile": 0.28852,
      "kev": false,
      "kev_due_at": null,
      "vendor": "KAMSOFT",
      "product": "KS-SOMED",
      "cwe": "CWE-798",
      "title": "Hard-coded credentials in KS-SOMED",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42251"
    },
    {
      "rank": 90,
      "cve_id": "CVE-2026-10291",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00354,
      "epss_percentile": 0.28647,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Enderfga",
      "product": "claw-orchestrator",
      "cwe": "CWE-400",
      "title": "Enderfga claw-orchestrator Session Grep Endpoint embedded-server.ts validateRegex redos",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10291"
    },
    {
      "rank": 91,
      "cve_id": "CVE-2026-41017",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0035,
      "epss_percentile": 0.28225,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Airflow",
      "cwe": "CWE-614",
      "title": "Apache Airflow: JWT cookie missing Secure flag in JWTRefreshMiddleware behind HTTPS-terminating proxy",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41017"
    },
    {
      "rank": 92,
      "cve_id": "CVE-2026-42358",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00348,
      "epss_percentile": 0.2797,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Airflow",
      "cwe": "CWE-200",
      "title": "Apache Airflow: Variable masker depth-limit bypass returns cleartext nested secrets",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42358"
    },
    {
      "rank": 93,
      "cve_id": "CVE-2026-42360",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00348,
      "epss_percentile": 0.2797,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Airflow",
      "cwe": "CWE-200",
      "title": "Apache Airflow: Rendered template truncation bypasses nested sensitive-key masking",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42360"
    },
    {
      "rank": 94,
      "cve_id": "CVE-2026-46605",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00348,
      "epss_percentile": 0.28014,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache ActiveMQ Broker",
      "cwe": "CWE-285",
      "title": "Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Incomplete authorization during destination removal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46605"
    },
    {
      "rank": 95,
      "cve_id": "CVE-2026-37220",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00347,
      "epss_percentile": 0.27866,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-617",
      "title": "FlexRIC v2.0.0 crashes when an SCTP association is closed before an E2_SETUP_REQUEST is sent. The near-RT RIC assumes a mapping between SCTP association and E2 node always exists in the cleanup path and enforces this via assert(). A remote unauthenticated attacker can crash the near-RT RIC (port 36421) by simply completing an SCTP handshake and immediately disconnecting, without sending any E2AP message.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-37220"
    },
    {
      "rank": 96,
      "cve_id": "CVE-2026-37221",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00347,
      "epss_percentile": 0.27867,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-617",
      "title": "FlexRIC v2.0.0 crashes when receiving a RIC_SUBSCRIPTION_RESPONSE with an unknown ric_id that has no corresponding pending event. The near-RT RIC uses assert() to enforce the existence of a pending event during response processing. A remote unauthenticated attacker can send a forged RIC_SUBSCRIPTION_RESPONSE to the near-RT RIC (port 36421) to cause SIGABRT in Debug builds or NULL pointer dereference (SIGSEGV) in Release builds.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-37221"
    },
    {
      "rank": 97,
      "cve_id": "CVE-2026-40965",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00346,
      "epss_percentile": 0.27709,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cloud Foundry Foundation",
      "product": "uaa_release",
      "cwe": "CWE-200",
      "title": "Cloud Foundry UAA versions v76.12.0 through v78.12.0 are vulnerable to a private key exposure. The server contains a vulnerability where EC (Elliptic Curve) private keys are inadvertently exposed through the public /token_keys endpoint. This endpoint is designed to provide public key material for JWT token verification but incorrectly exposes private key components for EC keys. The vulnerability affects deployments using EC keys for JWT token signing. The vulnerability does not affect RSA key configurations, only deployments using EC keys for JWT signing. Affected versions: - uaa_release: v76.12.0 through v78.12.0 (inclusive); fixed in v78.13.0 or later - CF Deployment: v30.0.0 through v56.0.0 (inclusive); fixed in v56.1.0 or later (bundles uaa_release v78.13.0)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40965"
    },
    {
      "rank": 98,
      "cve_id": "CVE-2026-37234",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00345,
      "epss_percentile": 0.2765,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-400",
      "title": "FlexRIC v2.0.0 allows a single SCTP connection to bind multiple xapp_ids by sending multiple E42_SETUP_REQUESTs. On disconnect, only the first registered xapp_id's resources are cleaned up; subsequent xapp_ids and their subscriptions remain as stale entries. A remote attacker can exploit this to leak subscription state in the iApp, potentially causing resource exhaustion or state corruption over time.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-37234"
    },
    {
      "rank": 99,
      "cve_id": "CVE-2026-49491",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00344,
      "epss_percentile": 0.27588,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Pixastudio",
      "product": "Pixa Bank",
      "cwe": "CWE-89",
      "title": "Pixa Bank 2.0 SQL Injection via agence-ajax.php API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49491"
    },
    {
      "rank": 100,
      "cve_id": "CVE-2018-25428",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00341,
      "epss_percentile": 0.27225,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Paroiciel",
      "product": "Paroiciel",
      "cwe": "CWE-89",
      "title": "Paroiciel 11.20 SQL Injection via tRecIdListe Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2018-25428"
    },
    {
      "rank": 101,
      "cve_id": "CVE-2018-25433",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00341,
      "epss_percentile": 0.27225,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Joomlaextensions",
      "product": "JE Photo Gallery",
      "cwe": "CWE-89",
      "title": "Joomla JE Photo Gallery 1.1 SQL Injection via categoryid",
      "url": "https://www.cve.org/CVERecord?id=CVE-2018-25433"
    },
    {
      "rank": 102,
      "cve_id": "CVE-2018-25434",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00341,
      "epss_percentile": 0.27225,
      "kev": false,
      "kev_due_at": null,
      "vendor": "eliekhoury",
      "product": "WP AutoSuggest",
      "cwe": "CWE-89",
      "title": "WP AutoSuggest 0.24 SQL Injection via autosuggest.php",
      "url": "https://www.cve.org/CVERecord?id=CVE-2018-25434"
    },
    {
      "rank": 103,
      "cve_id": "CVE-2026-10289",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00338,
      "epss_percentile": 0.26859,
      "kev": false,
      "kev_due_at": null,
      "vendor": "code-projects",
      "product": "Hotel and Tourism Reservation System",
      "cwe": "CWE-79",
      "title": "code-projects Hotel and Tourism Reservation System tour.php cross site scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10289"
    },
    {
      "rank": 104,
      "cve_id": "CVE-2026-48208",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00333,
      "epss_percentile": 0.26331,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OTRS AG",
      "product": "OTRS",
      "cwe": "CWE-400",
      "title": "Denial-of-Service via SVG Rendering in Ticket",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48208"
    },
    {
      "rank": 105,
      "cve_id": "CVE-2026-42680",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00331,
      "epss_percentile": 0.26078,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Wasiliy Strecker / ContestGallery developer",
      "product": "Contest Gallery Pro",
      "cwe": "CWE-266",
      "title": "WordPress Contest Gallery Pro plugin <= 29.0.1 - Privilege Escalation vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42680"
    },
    {
      "rank": 106,
      "cve_id": "CVE-2026-8644",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0033,
      "epss_percentile": 0.26027,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "WebSphere Application Server",
      "cwe": "CWE-290",
      "title": "IBM WebSphere Application Server is affected by an identity spoofing vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8644"
    },
    {
      "rank": 107,
      "cve_id": "CVE-2026-10254",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00329,
      "epss_percentile": 0.25847,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "Pet Grooming Management Software",
      "cwe": "CWE-200",
      "title": "SourceCodester Pet Grooming Management Software admin file information disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10254"
    },
    {
      "rank": 108,
      "cve_id": "CVE-2026-48879",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00328,
      "epss_percentile": 0.25763,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Sergey",
      "product": "AIWU",
      "cwe": "CWE-266",
      "title": "WordPress AIWU plugin <= 1.4.17 - Privilege Escalation vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48879"
    },
    {
      "rank": 109,
      "cve_id": "CVE-2026-8643",
      "cvss_base": 4.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0032,
      "epss_percentile": 0.24866,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Python Packaging Authority",
      "product": "pip",
      "cwe": "CWE-22",
      "title": "pip can extract console_scripts and gui_scripts outside installation directory",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8643"
    },
    {
      "rank": 110,
      "cve_id": "CVE-2026-43623",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00318,
      "epss_percentile": 0.24608,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rxi",
      "product": "microtar",
      "cwe": "CWE-121",
      "title": "microtar 0.1.0 Stack-Based Buffer Overflow via raw_to_header()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43623"
    },
    {
      "rank": 111,
      "cve_id": "CVE-2026-45545",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00318,
      "epss_percentile": 0.24684,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nextcloud",
      "product": "security-advisories",
      "cwe": "CWE-89",
      "title": "Nextcloud: SQL Injection in Column Type Parameter Allows Arbitrary SQL Execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45545"
    },
    {
      "rank": 112,
      "cve_id": "CVE-2026-10290",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00318,
      "epss_percentile": 0.24661,
      "kev": false,
      "kev_due_at": null,
      "vendor": "code-projects",
      "product": "Hotel and Tourism Reservation System",
      "cwe": "CWE-74",
      "title": "code-projects Hotel and Tourism Reservation System GET Parameter tour.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10290"
    },
    {
      "rank": 113,
      "cve_id": "CVE-2026-45302",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00315,
      "epss_percentile": 0.24332,
      "kev": false,
      "kev_due_at": null,
      "vendor": "milamer",
      "product": "parse-nested-form-data",
      "cwe": "CWE-1321",
      "title": "Prototype Pollution in parse-nested-form-data via `__proto__` in FormData field names",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45302"
    },
    {
      "rank": 114,
      "cve_id": "CVE-2026-10255",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00311,
      "epss_percentile": 0.23923,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "Pharmacy Sales and Inventory System",
      "cwe": "CWE-266",
      "title": "SourceCodester Pharmacy Sales and Inventory System ShowForm.php sell_statement access control",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10255"
    },
    {
      "rank": 115,
      "cve_id": "CVE-2026-40548",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0031,
      "epss_percentile": 0.23725,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SOPlanning",
      "product": "SOPlanning",
      "cwe": "CWE-434",
      "title": "Unrestricted Upload of File with Dangerous Type in SOPlanning",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40548"
    },
    {
      "rank": 116,
      "cve_id": "CVE-2026-10272",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00307,
      "epss_percentile": 0.2345,
      "kev": false,
      "kev_due_at": null,
      "vendor": "a4m4",
      "product": "Student-Management-System",
      "cwe": "CWE-266",
      "title": "a4m4 Student-Management-System deleteform.php improper authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10272"
    },
    {
      "rank": 117,
      "cve_id": "CVE-2026-10280",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00305,
      "epss_percentile": 0.23158,
      "kev": false,
      "kev_due_at": null,
      "vendor": "horizon921",
      "product": "mcpilot",
      "cwe": "CWE-918",
      "title": "horizon921 mcpilot MCP API Call Endpoint route.ts server-side request forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10280"
    },
    {
      "rank": 118,
      "cve_id": "CVE-2026-10220",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00304,
      "epss_percentile": 0.23135,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NousResearch",
      "product": "hermes-agent",
      "cwe": "CWE-74",
      "title": "NousResearch hermes-agent skills_tool.py skill_view injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10220"
    },
    {
      "rank": 119,
      "cve_id": "CVE-2026-10221",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00304,
      "epss_percentile": 0.23135,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NousResearch",
      "product": "hermes-agent",
      "cwe": "CWE-74",
      "title": "NousResearch hermes-agent run_agent.py _compress_context injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10221"
    },
    {
      "rank": 120,
      "cve_id": "CVE-2026-45722",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00301,
      "epss_percentile": 0.22782,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nextcloud",
      "product": "security-advisories",
      "cwe": "CWE-89",
      "title": "Nextcloud: Tables app allows limited SQLi in ORDER BY with malicious sort order argument for Table Views",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45722"
    },
    {
      "rank": 121,
      "cve_id": "CVE-2026-10271",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00299,
      "epss_percentile": 0.22569,
      "kev": false,
      "kev_due_at": null,
      "vendor": "a4m4",
      "product": "Student-Management-System",
      "cwe": "CWE-698",
      "title": "a4m4 Student-Management-System Admin Endpoint admin redirect",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10271"
    },
    {
      "rank": 122,
      "cve_id": "CVE-2026-10275",
      "cvss_base": 1.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00296,
      "epss_percentile": 0.222,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "OpenSC",
      "cwe": "CWE-119",
      "title": "OpenSC pkcs11-tool Key Generation pkcs11-tool.c test_kpgen_certwrite buffer overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10275"
    },
    {
      "rank": 123,
      "cve_id": "CVE-2026-42679",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00295,
      "epss_percentile": 0.22172,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mamunur Rashid",
      "product": "Classified Listing",
      "cwe": "CWE-22",
      "title": "WordPress Classified Listing plugin <= 5.3.8 - Arbitrary File Download vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42679"
    },
    {
      "rank": 124,
      "cve_id": "CVE-2026-44740",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00295,
      "epss_percentile": 0.2217,
      "kev": false,
      "kev_due_at": null,
      "vendor": "go-git",
      "product": "go-billy",
      "cwe": "CWE-674",
      "title": "go-billy: Lack of depth and cycle detection in symlink resolution may lead to infinite loops and resource exhaustion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44740"
    },
    {
      "rank": 125,
      "cve_id": "CVE-2026-10283",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00295,
      "epss_percentile": 0.22181,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Bottelet",
      "product": "DaybydayCRM",
      "cwe": "CWE-287",
      "title": "Bottelet DaybydayCRM Setting missing authentication",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10283"
    },
    {
      "rank": 126,
      "cve_id": "CVE-2026-40544",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00295,
      "epss_percentile": 0.22102,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SOPlanning",
      "product": "SOPlanning",
      "cwe": "CWE-79",
      "title": "Stored XSS in SOPlanning",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40544"
    },
    {
      "rank": 127,
      "cve_id": "CVE-2026-45282",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00294,
      "epss_percentile": 0.22014,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nextcloud",
      "product": "security-advisories",
      "cwe": "CWE-284",
      "title": "Nextcloud: Logged-in user bypasses share password and download restrictions on Text attachments via documentId leads to unauthorized file access",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45282"
    },
    {
      "rank": 128,
      "cve_id": "CVE-2026-10287",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00294,
      "epss_percentile": 0.22015,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "SEO Meta Tag Extractor",
      "cwe": "CWE-918",
      "title": "SourceCodester SEO Meta Tag Extractor index.php get_headers server-side request forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10287"
    },
    {
      "rank": 129,
      "cve_id": "CVE-2026-45285",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00293,
      "epss_percentile": 0.2186,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nextcloud",
      "product": "security-advisories",
      "cwe": "CWE-862",
      "title": "Nextcloud: Hidden Public Link creation when sharing to a Team External Member",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45285"
    },
    {
      "rank": 130,
      "cve_id": "CVE-2026-42682",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00291,
      "epss_percentile": 0.21671,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tomdever",
      "product": "wpForo Forum",
      "cwe": "CWE-862",
      "title": "WordPress wpForo Forum plugin <= 3.0.6 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42682"
    },
    {
      "rank": 131,
      "cve_id": "CVE-2026-45267",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00291,
      "epss_percentile": 0.21635,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nextcloud",
      "product": "security-advisories",
      "cwe": "CWE-200",
      "title": "Nextcloud: Missing permission check for from submissions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45267"
    },
    {
      "rank": 132,
      "cve_id": "CVE-2026-45690",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0029,
      "epss_percentile": 0.21602,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nextcloud",
      "product": "security-advisories",
      "cwe": "CWE-287",
      "title": "Nextcloud: Two-Factor Authentication Bypass via Pending Session Token Replay",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45690"
    },
    {
      "rank": 133,
      "cve_id": "CVE-2026-45691",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0029,
      "epss_percentile": 0.21602,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nextcloud",
      "product": "security-advisories",
      "cwe": "CWE-287",
      "title": "Nextcloud: Bypass of second factor authentication on DAV endpoints",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45691"
    },
    {
      "rank": 134,
      "cve_id": "CVE-2026-24751",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00289,
      "epss_percentile": 0.21443,
      "kev": false,
      "kev_due_at": null,
      "vendor": "kiteworks",
      "product": "Secure Data Forms",
      "cwe": "CWE-79",
      "title": "Kiteworks Secure Data Forms Vulnerable to Cross-site Scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-24751"
    },
    {
      "rank": 135,
      "cve_id": "CVE-2026-10278",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00288,
      "epss_percentile": 0.21405,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ishayoyo",
      "product": "excel-mcp",
      "cwe": "CWE-22",
      "title": "ishayoyo excel-mcp read_file/write_file index.ts path traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10278"
    },
    {
      "rank": 136,
      "cve_id": "CVE-2026-49138",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00287,
      "epss_percentile": 0.21228,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HKUDS",
      "product": "nanobot",
      "cwe": "CWE-918",
      "title": "Nanobot < 0.2.1 SSRF via web_fetch Tool Redirect Following",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49138"
    },
    {
      "rank": 137,
      "cve_id": "CVE-2026-45281",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00284,
      "epss_percentile": 0.20982,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nextcloud",
      "product": "security-advisories",
      "cwe": "CWE-639",
      "title": "Nextcloud: Cross-Account Calendar Takeover via Unauthorized Group-Member-Set Update",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45281"
    },
    {
      "rank": 138,
      "cve_id": "CVE-2026-24752",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00283,
      "epss_percentile": 0.20838,
      "kev": false,
      "kev_due_at": null,
      "vendor": "kiteworks",
      "product": "Secure Data Forms",
      "cwe": "CWE-79",
      "title": "Kiteworks Secure Data Forms Vulnerable to Cross-site Scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-24752"
    },
    {
      "rank": 139,
      "cve_id": "CVE-2026-45286",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00281,
      "epss_percentile": 0.20627,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nextcloud",
      "product": "security-advisories",
      "cwe": "CWE-200",
      "title": "Nextcloud: Calendar app leaked user identifiers via attendee suggestion endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45286"
    },
    {
      "rank": 140,
      "cve_id": "CVE-2026-10269",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00276,
      "epss_percentile": 0.20149,
      "kev": false,
      "kev_due_at": null,
      "vendor": "decolua",
      "product": "9router",
      "cwe": "CWE-266",
      "title": "decolua 9router HTTP Header dashboardGuard.js isAuthenticated improper authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10269"
    },
    {
      "rank": 141,
      "cve_id": "CVE-2026-10277",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00276,
      "epss_percentile": 0.20149,
      "kev": false,
      "kev_due_at": null,
      "vendor": "j3k0",
      "product": "mcp-google-workspace",
      "cwe": "CWE-266",
      "title": "j3k0 mcp-google-workspace MCP Gmail Tool gmail.ts saveToDisk access control",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10277"
    },
    {
      "rank": 142,
      "cve_id": "CVE-2026-45131",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00275,
      "epss_percentile": 0.19932,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CloudPirates-io",
      "product": "helm-charts",
      "cwe": "CWE-94",
      "title": "CloudPirates Open Source Helm Charts: GitHub Actions pull_request_target workflow allows secret exfiltration via fork pull requests",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45131"
    },
    {
      "rank": 143,
      "cve_id": "CVE-2026-10299",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": 0.00274,
      "epss_percentile": 0.19905,
      "kev": false,
      "kev_due_at": null,
      "vendor": "code-projects",
      "product": "Online Hospital Management System",
      "cwe": "CWE-99",
      "title": "code-projects Online Hospital Management System viewdoctortimings.php resource injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10299"
    },
    {
      "rank": 144,
      "cve_id": "CVE-2026-40543",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00273,
      "epss_percentile": 0.19764,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SOPlanning",
      "product": "SOPlanning",
      "cwe": "CWE-862",
      "title": "Missing Authorization in SOPlanning",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40543"
    },
    {
      "rank": 145,
      "cve_id": "CVE-2018-25429",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00273,
      "epss_percentile": 0.19767,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Paroiciel",
      "product": "Paroiciel",
      "cwe": "CWE-89",
      "title": "Paroiciel 11.20 SQL Injection via zProIdPro Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2018-25429"
    },
    {
      "rank": 146,
      "cve_id": "CVE-2018-25430",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00273,
      "epss_percentile": 0.19766,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Paroiciel",
      "product": "Paroiciel",
      "cwe": "CWE-89",
      "title": "Paroiciel 11.20 SQL Injection via eGeqIdEquipe Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2018-25430"
    },
    {
      "rank": 147,
      "cve_id": "CVE-2018-25431",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00273,
      "epss_percentile": 0.19767,
      "kev": false,
      "kev_due_at": null,
      "vendor": "goFrendiAsgard",
      "product": "No-CMS",
      "cwe": "CWE-89",
      "title": "No-Cms 1.0 SQL Injection via order_by Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2018-25431"
    },
    {
      "rank": 148,
      "cve_id": "CVE-2026-10301",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00273,
      "epss_percentile": 0.1974,
      "kev": false,
      "kev_due_at": null,
      "vendor": "itsourcecode",
      "product": "Fees Management System",
      "cwe": "CWE-79",
      "title": "itsourcecode Fees Management System index.php cross site scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10301"
    },
    {
      "rank": 149,
      "cve_id": "CVE-2026-49134",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0027,
      "epss_percentile": 0.1924,
      "kev": false,
      "kev_due_at": null,
      "vendor": "steipete",
      "product": "CodexBar",
      "cwe": "CWE-377",
      "title": "CodexBar < 0.32.0 Privilege Escalation via CLI Installer Temp File",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49134"
    },
    {
      "rank": 150,
      "cve_id": "CVE-2026-10239",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.0027,
      "epss_percentile": 0.19281,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "JeecgBoot",
      "cwe": "CWE-918",
      "title": "JeecgBoot edit WordUtil.addImage server-side request forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10239"
    },
    {
      "rank": 151,
      "cve_id": "CVE-2026-10240",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.0027,
      "epss_percentile": 0.19279,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "JeecgBoot",
      "cwe": "CWE-918",
      "title": "JeecgBoot test server-side request forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10240"
    },
    {
      "rank": 152,
      "cve_id": "CVE-2026-10241",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.0027,
      "epss_percentile": 0.19278,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jeecgboot",
      "product": "The server processes these URLs",
      "cwe": "CWE-918",
      "title": "jeecgboot The server processes these URLs Cloud Instance Metadata Endpoint debug FileDownloadUtils.download2DiskFromNet server-side request forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10241"
    },
    {
      "rank": 153,
      "cve_id": "CVE-2026-10276",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.0027,
      "epss_percentile": 0.1928,
      "kev": false,
      "kev_due_at": null,
      "vendor": "hekmon8",
      "product": "Jenkins-server-mcp",
      "cwe": "CWE-918",
      "title": "hekmon8 Jenkins-server-mcp get_build_status/get_build_log/trigger_build index.ts jobPath server-side request forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10276"
    },
    {
      "rank": 154,
      "cve_id": "CVE-2026-10249",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00269,
      "epss_percentile": 0.1912,
      "kev": false,
      "kev_due_at": null,
      "vendor": "itsourcecode",
      "product": "Online Blood Bank Management System",
      "cwe": "CWE-74",
      "title": "itsourcecode Online Blood Bank Management System viewrequest.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10249"
    },
    {
      "rank": 155,
      "cve_id": "CVE-2026-10262",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00269,
      "epss_percentile": 0.19117,
      "kev": false,
      "kev_due_at": null,
      "vendor": "code-projects",
      "product": "Real State Services",
      "cwe": "CWE-74",
      "title": "code-projects Real State Services Login loginuser.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10262"
    },
    {
      "rank": 156,
      "cve_id": "CVE-2026-10263",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00269,
      "epss_percentile": 0.1912,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "Computer Repair Shop Management System",
      "cwe": "CWE-74",
      "title": "SourceCodester Computer Repair Shop Management System manage_product.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10263"
    },
    {
      "rank": 157,
      "cve_id": "CVE-2026-45543",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00269,
      "epss_percentile": 0.19166,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nextcloud",
      "product": "security-advisories",
      "cwe": "CWE-552",
      "title": "Nextcloud: Deleting a Forms collaborator share leaves uploaded response files accessible through a lingering Files share",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45543"
    },
    {
      "rank": 158,
      "cve_id": "CVE-2026-49140",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00268,
      "epss_percentile": 0.1906,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HKUDS",
      "product": "nanobot",
      "cwe": "CWE-770",
      "title": "Nanobot < 0.2.1 Denial of Service via Matrix Media Download Handler",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49140"
    },
    {
      "rank": 159,
      "cve_id": "CVE-2026-10222",
      "cvss_base": 2.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00266,
      "epss_percentile": 0.18662,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NousResearch",
      "product": "hermes-agent",
      "cwe": "CWE-74",
      "title": "NousResearch hermes-agent config.py _sanitize_env_lines injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10222"
    },
    {
      "rank": 160,
      "cve_id": "CVE-2026-0080",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00265,
      "epss_percentile": 0.18517,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": "CWE-190",
      "title": "In multiple functions of ubsan_throwing_runtime.cpp, there is a possible way to cause a crash due to an integer overflow. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-0080"
    },
    {
      "rank": 161,
      "cve_id": "CVE-2026-10264",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": 0.00265,
      "epss_percentile": 0.18572,
      "kev": false,
      "kev_due_at": null,
      "vendor": "lharries",
      "product": "whatsapp-mcp",
      "cwe": "CWE-22",
      "title": "lharries whatsapp-mcp Send API Endpoint main.go SendMessageRequest path traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10264"
    },
    {
      "rank": 162,
      "cve_id": "CVE-2026-10208",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00263,
      "epss_percentile": 0.18294,
      "kev": false,
      "kev_due_at": null,
      "vendor": "code-projects",
      "product": "Online Hospital Management System",
      "cwe": "CWE-74",
      "title": "code-projects Online Hospital Management System login_1.php login_user sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10208"
    },
    {
      "rank": 163,
      "cve_id": "CVE-2026-10225",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00263,
      "epss_percentile": 0.18292,
      "kev": false,
      "kev_due_at": null,
      "vendor": "raisulislamg4",
      "product": "student_management_system_by_php",
      "cwe": "CWE-74",
      "title": "raisulislamg4 student_management_system_by_php Login login_check.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10225"
    },
    {
      "rank": 164,
      "cve_id": "CVE-2026-10226",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00263,
      "epss_percentile": 0.18292,
      "kev": false,
      "kev_due_at": null,
      "vendor": "raisulislamg4",
      "product": "student_management_system_by_php",
      "cwe": "CWE-74",
      "title": "raisulislamg4 student_management_system_by_php delete.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10226"
    },
    {
      "rank": 165,
      "cve_id": "CVE-2026-10227",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00263,
      "epss_percentile": 0.18294,
      "kev": false,
      "kev_due_at": null,
      "vendor": "raisulislamg4",
      "product": "student_management_system_by_php",
      "cwe": "CWE-74",
      "title": "raisulislamg4 student_management_system_by_php User Creation add_user_check.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10227"
    },
    {
      "rank": 166,
      "cve_id": "CVE-2026-10250",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00263,
      "epss_percentile": 0.18296,
      "kev": false,
      "kev_due_at": null,
      "vendor": "itsourcecode",
      "product": "Online Blood Bank Management System",
      "cwe": "CWE-74",
      "title": "itsourcecode Online Blood Bank Management System campsdetails.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10250"
    },
    {
      "rank": 167,
      "cve_id": "CVE-2026-10251",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00263,
      "epss_percentile": 0.18296,
      "kev": false,
      "kev_due_at": null,
      "vendor": "itsourcecode",
      "product": "Online House Rental System",
      "cwe": "CWE-74",
      "title": "itsourcecode Online House Rental System ajax.php login sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10251"
    },
    {
      "rank": 168,
      "cve_id": "CVE-2026-10252",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00263,
      "epss_percentile": 0.18299,
      "kev": false,
      "kev_due_at": null,
      "vendor": "itsourcecode",
      "product": "Online House Rental System",
      "cwe": "CWE-74",
      "title": "itsourcecode Online House Rental System manage_tenant.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10252"
    },
    {
      "rank": 169,
      "cve_id": "CVE-2026-10253",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00263,
      "epss_percentile": 0.18293,
      "kev": false,
      "kev_due_at": null,
      "vendor": "itsourcecode",
      "product": "Online House Rental System",
      "cwe": "CWE-74",
      "title": "itsourcecode Online House Rental System manage_payment.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10253"
    },
    {
      "rank": 170,
      "cve_id": "CVE-2026-10260",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00263,
      "epss_percentile": 0.18294,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CodeAstro",
      "product": "Online Job Portal",
      "cwe": "CWE-74",
      "title": "CodeAstro Online Job Portal delete-jobs.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10260"
    },
    {
      "rank": 171,
      "cve_id": "CVE-2026-10261",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00263,
      "epss_percentile": 0.18294,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CodeAstro",
      "product": "Online Job Portal",
      "cwe": "CWE-74",
      "title": "CodeAstro Online Job Portal application_status.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10261"
    },
    {
      "rank": 172,
      "cve_id": "CVE-2026-10237",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": 0.00262,
      "epss_percentile": 0.18142,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "Water Billing Management System",
      "cwe": "CWE-74",
      "title": "SourceCodester Water Billing Management System User Management manage_user sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10237"
    },
    {
      "rank": 173,
      "cve_id": "CVE-2026-45132",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0026,
      "epss_percentile": 0.17888,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CloudPirates-io",
      "product": "helm-charts",
      "cwe": "CWE-94",
      "title": "CloudPirates Open Source Helm Charts: GitHub Actions workflow leaks PAT and SSH signing key via unsafe credential handling",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45132"
    },
    {
      "rank": 174,
      "cve_id": "CVE-2026-10215",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00259,
      "epss_percentile": 0.17799,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dolibarr",
      "product": "ERP CRM",
      "cwe": "CWE-266",
      "title": "Dolibarr ERP CRM Leave Request REST API api_holidays.class.php checkUserAccessToObject improper authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10215"
    },
    {
      "rank": 175,
      "cve_id": "CVE-2022-4991",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00254,
      "epss_percentile": 0.17108,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tychon",
      "product": "Tychon",
      "cwe": null,
      "title": "Tychon is vulnerable to privilege escalation due to OPENSSLDIR location",
      "url": "https://www.cve.org/CVERecord?id=CVE-2022-4991"
    },
    {
      "rank": 176,
      "cve_id": "CVE-2026-0039",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00253,
      "epss_percentile": 0.17087,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": "CWE-190",
      "title": "In multiple functions of ubsan_throwing_runtime.cpp, there is a possible persistent denial of service due to an integer overflow. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-0039"
    },
    {
      "rank": 177,
      "cve_id": "CVE-2026-0040",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00253,
      "epss_percentile": 0.17087,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": "CWE-190",
      "title": "In multiple functions of ubsan_throwing_runtime.cpp, there is a possible way to cause a crash due to an integer overflow. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-0040"
    },
    {
      "rank": 178,
      "cve_id": "CVE-2026-0041",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00253,
      "epss_percentile": 0.17089,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": "CWE-190",
      "title": "In multiple functions of ubsan_throwing_runtime.cpp, there is a possible UBSan failure due to an integer overflow. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-0041"
    },
    {
      "rank": 179,
      "cve_id": "CVE-2026-0044",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00253,
      "epss_percentile": 0.17089,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": "CWE-190",
      "title": "In multiple functions of ubsan_throwing_runtime.cpp, there is a possible way to cause the system to crash due to an integer overflow. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-0044"
    },
    {
      "rank": 180,
      "cve_id": "CVE-2026-0051",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00253,
      "epss_percentile": 0.17088,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": "CWE-20",
      "title": "In multiple functions of ubsan_throwing_runtime.cpp, there is a possible way to cause a system crash due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-0051"
    },
    {
      "rank": 181,
      "cve_id": "CVE-2026-0052",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00253,
      "epss_percentile": 0.17088,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": "CWE-190",
      "title": "In multiple functions of ubsan_throwing_runtime.cpp, there is a possible way to cause a crash due to an integer overflow. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-0052"
    },
    {
      "rank": 182,
      "cve_id": "CVE-2026-10118",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00252,
      "epss_percentile": 0.16957,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-190",
      "title": "Poppler: integer overflow in poppler splashoutputdev::tilingpatternfill leads to heap buffer overflow via unchecked dimension multiplication",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10118"
    },
    {
      "rank": 183,
      "cve_id": "CVE-2026-45810",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00252,
      "epss_percentile": 0.16849,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nextcloud",
      "product": "security-advisories",
      "cwe": "CWE-639",
      "title": "Nextcloud: Propfind requests for file comments allowed to load comments for other files",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45810"
    },
    {
      "rank": 184,
      "cve_id": "CVE-2026-10514",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00251,
      "epss_percentile": 0.16787,
      "kev": false,
      "kev_due_at": null,
      "vendor": "1Panel-dev",
      "product": "CordysCRM",
      "cwe": "CWE-79",
      "title": "1Panel-dev CordysCRM RequestParamTrimConfig.java cross site scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10514"
    },
    {
      "rank": 185,
      "cve_id": "CVE-2026-10242",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.0025,
      "epss_percentile": 0.1664,
      "kev": false,
      "kev_due_at": null,
      "vendor": "itsourcecode",
      "product": "Content Management System",
      "cwe": "CWE-74",
      "title": "itsourcecode Content Management System instructions.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10242"
    },
    {
      "rank": 186,
      "cve_id": "CVE-2026-10296",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.0025,
      "epss_percentile": 0.1664,
      "kev": false,
      "kev_due_at": null,
      "vendor": "itsourcecode",
      "product": "Fees Management System",
      "cwe": "CWE-74",
      "title": "itsourcecode Fees Management System ajax.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10296"
    },
    {
      "rank": 187,
      "cve_id": "CVE-2026-10248",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": 0.00248,
      "epss_percentile": 0.16444,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "Pharmacy Sales and Inventory System",
      "cwe": "CWE-74",
      "title": "SourceCodester Pharmacy Sales and Inventory System Supplier Creation export create_supplier csv injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10248"
    },
    {
      "rank": 188,
      "cve_id": "CVE-2026-42673",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00245,
      "epss_percentile": 0.16028,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Logtivity Activity Logs",
      "product": "Activity Logs, User Activity Tracking, Multisite Activity Log from Logtivity",
      "cwe": "CWE-201",
      "title": "WordPress Activity Logs, User Activity Tracking, Multisite Activity Log from Logtivity plugin <= 3.3.6 - Sensitive Data Exposure vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42673"
    },
    {
      "rank": 189,
      "cve_id": "CVE-2026-41013",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00239,
      "epss_percentile": 0.15196,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CloudFoundry Foundation",
      "product": "smb-volume-release",
      "cwe": "CWE-88",
      "title": "Tenant-controlled comma smuggles arbitrary CIFS mount options",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41013"
    },
    {
      "rank": 190,
      "cve_id": "CVE-2026-42672",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00236,
      "epss_percentile": 0.14905,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Wp Directory Kit",
      "product": "WP Directory Kit",
      "cwe": "CWE-89",
      "title": "WordPress WP Directory Kit plugin <= 1.5.1 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42672"
    },
    {
      "rank": 191,
      "cve_id": "CVE-2026-45729",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00235,
      "epss_percentile": 0.14787,
      "kev": false,
      "kev_due_at": null,
      "vendor": "thorvg",
      "product": "thorvg",
      "cwe": "CWE-476",
      "title": "ThorVG: Null pointer dereference in SVG loader causes crash via 6-byte malformed input",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45729"
    },
    {
      "rank": 192,
      "cve_id": "CVE-2026-42677",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00232,
      "epss_percentile": 0.14351,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ben Balter",
      "product": "WP Document Revisions",
      "cwe": "CWE-862",
      "title": "WordPress WP Document Revisions plugin <= 3.8.1 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42677"
    },
    {
      "rank": 193,
      "cve_id": "CVE-2026-45278",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00232,
      "epss_percentile": 0.14324,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nextcloud",
      "product": "security-advisories",
      "cwe": "CWE-601",
      "title": "Nextcloud: Open Redirect in user_oidc login flow via protocol-relative URL bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45278"
    },
    {
      "rank": 194,
      "cve_id": "CVE-2026-45157",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00231,
      "epss_percentile": 0.14272,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nextcloud",
      "product": "security-advisories",
      "cwe": "CWE-284",
      "title": "Nextcloud: Valid share tokens allow to access tempory upload files of share owner",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45157"
    },
    {
      "rank": 195,
      "cve_id": "CVE-2026-10284",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0023,
      "epss_percentile": 0.14038,
      "kev": false,
      "kev_due_at": null,
      "vendor": "DevaslanPHP",
      "product": "project-management",
      "cwe": "CWE-266",
      "title": "DevaslanPHP project-management Livewire ViewTicket.php doDeleteComment improper authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10284"
    },
    {
      "rank": 196,
      "cve_id": "CVE-2026-10285",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0023,
      "epss_percentile": 0.14038,
      "kev": false,
      "kev_due_at": null,
      "vendor": "DevaslanPHP",
      "product": "project-management",
      "cwe": "CWE-266",
      "title": "DevaslanPHP project-management Ticket KanbanScrumHelper.php recordUpdated improper authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10285"
    },
    {
      "rank": 197,
      "cve_id": "CVE-2026-10533",
      "cvss_base": 5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0023,
      "epss_percentile": 0.14092,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat OpenShift Container Platform 4",
      "cwe": "CWE-770",
      "title": "Openshift: openshift: non-admin user can bypass resourcequota and flood etcd with events causing cluster-wide api degradation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10533"
    },
    {
      "rank": 198,
      "cve_id": "CVE-2026-10218",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.0023,
      "epss_percentile": 0.14038,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nextlevelbuilder",
      "product": "GoClaw",
      "cwe": "CWE-266",
      "title": "nextlevelbuilder GoClaw evolution_handlers.go auth improper authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10218"
    },
    {
      "rank": 199,
      "cve_id": "CVE-2026-45264",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00229,
      "epss_percentile": 0.13927,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nextcloud",
      "product": "security-advisories",
      "cwe": "CWE-284",
      "title": "Nextcloud: ACL Rename Permission Bypass in Team Folders Allows Unauthorized File Renames",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45264"
    },
    {
      "rank": 200,
      "cve_id": "CVE-2026-10210",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00228,
      "epss_percentile": 0.13772,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AstrBotDevs",
      "product": "AstrBot",
      "cwe": "CWE-74",
      "title": "AstrBotDevs AstrBot skill_manager.py _sanitize_prompt_description injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10210"
    },
    {
      "rank": 201,
      "cve_id": "CVE-2026-10223",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00228,
      "epss_percentile": 0.13808,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NousResearch",
      "product": "hermes-agent",
      "cwe": "CWE-74",
      "title": "NousResearch hermes-agent memory_tool.py _scan_memory_content injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10223"
    },
    {
      "rank": 202,
      "cve_id": "CVE-2026-10282",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00227,
      "epss_percentile": 0.13696,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Bottelet",
      "product": "DaybydayCRM",
      "cwe": "CWE-266",
      "title": "Bottelet DaybydayCRM DocumentsController.php view improper authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10282"
    },
    {
      "rank": 203,
      "cve_id": "CVE-2026-45544",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00222,
      "epss_percentile": 0.12993,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nextcloud",
      "product": "security-advisories",
      "cwe": "CWE-1230",
      "title": "Nextcloud: Information Disclosure of view filter metdata via Broken Sensitive Data Masking in ViewService",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45544"
    },
    {
      "rank": 204,
      "cve_id": "CVE-2026-10294",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00222,
      "epss_percentile": 0.13084,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "PackageKit",
      "cwe": "CWE-266",
      "title": "PackageKit API pk-transaction.c g_file_test improper authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10294"
    },
    {
      "rank": 205,
      "cve_id": "CVE-2026-48209",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00219,
      "epss_percentile": 0.1263,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OTRS AG",
      "product": "OTRS",
      "cwe": "CWE-79",
      "title": "Reflected XSS in authenticated agent context",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48209"
    },
    {
      "rank": 206,
      "cve_id": "CVE-2026-48839",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00212,
      "epss_percentile": 0.11766,
      "kev": false,
      "kev_due_at": null,
      "vendor": "VeronaLabs",
      "product": "WP Statistics",
      "cwe": "CWE-79",
      "title": "WordPress WP Statistics plugin <= 14.16.6 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48839"
    },
    {
      "rank": 207,
      "cve_id": "CVE-2026-40546",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00211,
      "epss_percentile": 0.11714,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SOPlanning",
      "product": "SOPlanning",
      "cwe": "CWE-89",
      "title": "Multiple SQL Injections in SOPlanning",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40546"
    },
    {
      "rank": 208,
      "cve_id": "CVE-2026-40989",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00211,
      "epss_percentile": 0.11715,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Spring",
      "product": "Spring Cloud Function",
      "cwe": "CWE-674",
      "title": "Self Routing guard bypassed via function composition",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40989"
    },
    {
      "rank": 209,
      "cve_id": "CVE-2026-40990",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00211,
      "epss_percentile": 0.11715,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Spring",
      "product": "Spring Cloud Function",
      "cwe": "CWE-770",
      "title": "Unbounded cache for function definitions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40990"
    },
    {
      "rank": 210,
      "cve_id": "CVE-2026-45283",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00211,
      "epss_percentile": 0.11688,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nextcloud",
      "product": "security-advisories",
      "cwe": "CWE-287",
      "title": "Nextcloud: Files Lock app allows users to lock and unlock files of other users",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45283"
    },
    {
      "rank": 211,
      "cve_id": "CVE-2026-10212",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00211,
      "epss_percentile": 0.11725,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AstrBotDevs",
      "product": "AstrBot",
      "cwe": "CWE-285",
      "title": "AstrBotDevs AstrBot astr_main_agent.py astr_main_agent authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10212"
    },
    {
      "rank": 212,
      "cve_id": "CVE-2026-10217",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00209,
      "epss_percentile": 0.11434,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nextlevelbuilder",
      "product": "GoClaw",
      "cwe": "CWE-266",
      "title": "nextlevelbuilder GoClaw RoleAdmin Gateway tts_config.go handleSave privileges management",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10217"
    },
    {
      "rank": 213,
      "cve_id": "CVE-2026-10274",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00209,
      "epss_percentile": 0.11443,
      "kev": false,
      "kev_due_at": null,
      "vendor": "indrasishbanerjee",
      "product": "aem-mcp-server",
      "cwe": "CWE-918",
      "title": "indrasishbanerjee aem-mcp-server Axios Request Flow mcp-server.ts getAssetMetadata server-side request forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10274"
    },
    {
      "rank": 214,
      "cve_id": "CVE-2026-10265",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00204,
      "epss_percentile": 0.10759,
      "kev": false,
      "kev_due_at": null,
      "vendor": "itsourcecode",
      "product": "Content Management System",
      "cwe": "CWE-74",
      "title": "itsourcecode Content Management System edit_topic.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10265"
    },
    {
      "rank": 215,
      "cve_id": "CVE-2026-10286",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00204,
      "epss_percentile": 0.10759,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CodeAstro",
      "product": "Payroll System",
      "cwe": "CWE-74",
      "title": "CodeAstro Payroll System home_employee.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10286"
    },
    {
      "rank": 216,
      "cve_id": "CVE-2026-42678",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00203,
      "epss_percentile": 0.10655,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Liquid Web / StellarWP",
      "product": "GiveWP",
      "cwe": "CWE-79",
      "title": "WordPress GiveWP plugin <= 4.14.5 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42678"
    },
    {
      "rank": 217,
      "cve_id": "CVE-2026-45159",
      "cvss_base": 3.5,
      "cvss_severity": "LOW",
      "epss_score": 0.00203,
      "epss_percentile": 0.10555,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nextcloud",
      "product": "security-advisories",
      "cwe": "CWE-639",
      "title": "Nextcloud: Files drop share links for end-to-end encrypted folders allowed to drop files into other folders of the share owner",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45159"
    },
    {
      "rank": 218,
      "cve_id": "CVE-2026-45266",
      "cvss_base": 3.5,
      "cvss_severity": "LOW",
      "epss_score": 0.00203,
      "epss_percentile": 0.10556,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nextcloud",
      "product": "security-advisories",
      "cwe": "CWE-284",
      "title": "Nextcloud: Unauthorized force-mute from missing permission check when using internal signaling",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45266"
    },
    {
      "rank": 219,
      "cve_id": "CVE-2026-30963",
      "cvss_base": 2.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00203,
      "epss_percentile": 0.10572,
      "kev": false,
      "kev_due_at": null,
      "vendor": "projectcapsule",
      "product": "capsule",
      "cwe": "CWE-20",
      "title": "Capsule Namespace Hijacking via subresource",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-30963"
    },
    {
      "rank": 220,
      "cve_id": "CVE-2026-10234",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": 0.00203,
      "epss_percentile": 0.10629,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mettle",
      "product": "sendportal",
      "cwe": "CWE-79",
      "title": "Mettle sendportal Campaign webview cross site scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10234"
    },
    {
      "rank": 221,
      "cve_id": "CVE-2026-10244",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": 0.00203,
      "epss_percentile": 0.10579,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "Pharmacy Sales and Inventory System",
      "cwe": "CWE-79",
      "title": "SourceCodester Pharmacy Sales and Inventory System main create_medicine_name cross site scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10244"
    },
    {
      "rank": 222,
      "cve_id": "CVE-2026-10245",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": 0.00203,
      "epss_percentile": 0.10579,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "Pharmacy Sales and Inventory System",
      "cwe": "CWE-79",
      "title": "SourceCodester Pharmacy Sales and Inventory System main create_supplier cross site scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10245"
    },
    {
      "rank": 223,
      "cve_id": "CVE-2026-48187",
      "cvss_base": 5.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00201,
      "epss_percentile": 0.10342,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OTRS AG",
      "product": "OTRS",
      "cwe": "CWE-400",
      "title": "Email with special content can lead to DoS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48187"
    },
    {
      "rank": 224,
      "cve_id": "CVE-2026-10205",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00201,
      "epss_percentile": 0.10396,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Metasoft 美特软件",
      "product": "MetaCRM",
      "cwe": "CWE-284",
      "title": "Metasoft 美特软件 MetaCRM upload.jsp unrestricted upload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10205"
    },
    {
      "rank": 225,
      "cve_id": "CVE-2026-10211",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00201,
      "epss_percentile": 0.10398,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AstrBotDevs",
      "product": "AstrBot",
      "cwe": "CWE-285",
      "title": "AstrBotDevs AstrBot fs.py _normalize_rw_path authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10211"
    },
    {
      "rank": 226,
      "cve_id": "CVE-2026-45155",
      "cvss_base": 2.6,
      "cvss_severity": "LOW",
      "epss_score": 0.002,
      "epss_percentile": 0.10236,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nextcloud",
      "product": "security-advisories",
      "cwe": "CWE-639",
      "title": "Nextcloud: Private circle can be added to another circle via API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45155"
    },
    {
      "rank": 227,
      "cve_id": "CVE-2026-10209",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.002,
      "epss_percentile": 0.1025,
      "kev": false,
      "kev_due_at": null,
      "vendor": "code-projects",
      "product": "Online Hospital Management System",
      "cwe": "CWE-74",
      "title": "code-projects Online Hospital Management System Appointment appointmentdetail.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10209"
    },
    {
      "rank": 228,
      "cve_id": "CVE-2026-10235",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.002,
      "epss_percentile": 0.10248,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CodeAstro",
      "product": "Ingredients Stock Management System",
      "cwe": "CWE-74",
      "title": "CodeAstro Ingredients Stock Management System stock_manager.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10235"
    },
    {
      "rank": 229,
      "cve_id": "CVE-2026-10256",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.002,
      "epss_percentile": 0.10246,
      "kev": false,
      "kev_due_at": null,
      "vendor": "itsourcecode",
      "product": "Content Management System",
      "cwe": "CWE-74",
      "title": "itsourcecode Content Management System save_comment.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10256"
    },
    {
      "rank": 230,
      "cve_id": "CVE-2026-10257",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.002,
      "epss_percentile": 0.10247,
      "kev": false,
      "kev_due_at": null,
      "vendor": "itsourcecode",
      "product": "Content Management System",
      "cwe": "CWE-74",
      "title": "itsourcecode Content Management System update_ss_img.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10257"
    },
    {
      "rank": 231,
      "cve_id": "CVE-2026-10258",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.002,
      "epss_percentile": 0.10249,
      "kev": false,
      "kev_due_at": null,
      "vendor": "itsourcecode",
      "product": "Content Management System",
      "cwe": "CWE-74",
      "title": "itsourcecode Content Management System add_sub_topic.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10258"
    },
    {
      "rank": 232,
      "cve_id": "CVE-2026-10297",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.002,
      "epss_percentile": 0.10248,
      "kev": false,
      "kev_due_at": null,
      "vendor": "itsourcecode",
      "product": "Fees Management System",
      "cwe": "CWE-74",
      "title": "itsourcecode Fees Management System manage_course.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10297"
    },
    {
      "rank": 233,
      "cve_id": "CVE-2026-10302",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.002,
      "epss_percentile": 0.1025,
      "kev": false,
      "kev_due_at": null,
      "vendor": "itsourcecode",
      "product": "Fees Management System",
      "cwe": "CWE-74",
      "title": "itsourcecode Fees Management System manage_fee.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10302"
    },
    {
      "rank": 234,
      "cve_id": "CVE-2026-9024",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00199,
      "epss_percentile": 0.10081,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dassault Systèmes",
      "product": "DELMIA Service Process Engineer",
      "cwe": "CWE-79",
      "title": "Stored Cross-site Scripting (XSS) vulnerability affecting Process Experience Studio in DELMIA Service Process Engineer from Release 3DEXPERIENCE R2024x through Release 3DEXPERIENCE R2026x",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9024"
    },
    {
      "rank": 235,
      "cve_id": "CVE-2026-10228",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": 0.00199,
      "epss_percentile": 0.10028,
      "kev": false,
      "kev_due_at": null,
      "vendor": "raisulislamg4",
      "product": "student_management_system_by_php",
      "cwe": "CWE-79",
      "title": "raisulislamg4 student_management_system_by_php admission_form_check.php cross site scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10228"
    },
    {
      "rank": 236,
      "cve_id": "CVE-2026-10246",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": 0.00199,
      "epss_percentile": 0.10031,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "Pharmacy Sales and Inventory System",
      "cwe": "CWE-79",
      "title": "SourceCodester Pharmacy Sales and Inventory System main create_medicine_presentation cross site scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10246"
    },
    {
      "rank": 237,
      "cve_id": "CVE-2026-10247",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": 0.00199,
      "epss_percentile": 0.1003,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "Pharmacy Sales and Inventory System",
      "cwe": "CWE-79",
      "title": "SourceCodester Pharmacy Sales and Inventory System main create_generic_name cross site scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10247"
    },
    {
      "rank": 238,
      "cve_id": "CVE-2026-48865",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00198,
      "epss_percentile": 0.09911,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ThimPress",
      "product": "LearnPress",
      "cwe": "CWE-79",
      "title": "WordPress LearnPress plugin <= 4.3.6 - Reflected Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48865"
    },
    {
      "rank": 239,
      "cve_id": "CVE-2026-48189",
      "cvss_base": 5.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00198,
      "epss_percentile": 0.09967,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OTRS AG",
      "product": "OTRS",
      "cwe": "CWE-200",
      "title": "Bypass DedicatedAgentToCustomerGroups Setting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48189"
    },
    {
      "rank": 240,
      "cve_id": "CVE-2026-42671",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00196,
      "epss_percentile": 0.09722,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Paolo",
      "product": "GeoDirectory",
      "cwe": "CWE-862",
      "title": "WordPress GeoDirectory plugin <= 2.8.157 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42671"
    },
    {
      "rank": 241,
      "cve_id": "CVE-2026-45284",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00193,
      "epss_percentile": 0.09384,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nextcloud",
      "product": "security-advisories",
      "cwe": "CWE-284",
      "title": "Nextcloud: Wrong condition in the User OIDC app's LdapService allowed deleted LDAP users to authenticate",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45284"
    },
    {
      "rank": 242,
      "cve_id": "CVE-2026-45701",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00193,
      "epss_percentile": 0.09382,
      "kev": false,
      "kev_due_at": null,
      "vendor": "sulu",
      "product": "sulu",
      "cwe": "CWE-327",
      "title": "Sulu: Weak Cryptographical usage for API Key generation and Reset Tokens",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45701"
    },
    {
      "rank": 243,
      "cve_id": "CVE-2026-45154",
      "cvss_base": 2.6,
      "cvss_severity": "LOW",
      "epss_score": 0.00189,
      "epss_percentile": 0.08923,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nextcloud",
      "product": "security-advisories",
      "cwe": "CWE-284",
      "title": "Nextcloud: Improper Access Control in Collectives",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45154"
    },
    {
      "rank": 244,
      "cve_id": "CVE-2026-43625",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00186,
      "epss_percentile": 0.08566,
      "kev": false,
      "kev_due_at": null,
      "vendor": "steipete",
      "product": "CodexBar",
      "cwe": "CWE-319",
      "title": "CodexBar < 0.32.0 Session Cookie Exposure via HTTP Redirect",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43625"
    },
    {
      "rank": 245,
      "cve_id": "CVE-2026-28511",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00186,
      "epss_percentile": 0.08515,
      "kev": false,
      "kev_due_at": null,
      "vendor": "elabftw",
      "product": "elabftw",
      "cwe": "CWE-200",
      "title": "elabftw has entry title leakage through autocompletion search",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28511"
    },
    {
      "rank": 246,
      "cve_id": "CVE-2026-49267",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00185,
      "epss_percentile": 0.08402,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Airflow",
      "cwe": "CWE-295",
      "title": "Apache Airflow: No certificate validation on SMTP STARTTLS connections",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49267"
    },
    {
      "rank": 247,
      "cve_id": "CVE-2026-23638",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00184,
      "epss_percentile": 0.08358,
      "kev": false,
      "kev_due_at": null,
      "vendor": "kiteworks",
      "product": "Secure Data Forms",
      "cwe": "CWE-639",
      "title": "Kiteworks Secure Data Forms is vulnerable to Authorization Bypass Through User-Controlled Key",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-23638"
    },
    {
      "rank": 248,
      "cve_id": "CVE-2026-8474",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00183,
      "epss_percentile": 0.08166,
      "kev": false,
      "kev_due_at": null,
      "vendor": "StormShield",
      "product": "StormShield Network Security",
      "cwe": "CWE-79",
      "title": "Possible to run a Cross Site Scripting request on the login API available on Stormshield SNS appliances.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8474"
    },
    {
      "rank": 249,
      "cve_id": "CVE-2026-35563",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00182,
      "epss_percentile": 0.0806,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Directory LDAP API",
      "cwe": "CWE-297",
      "title": "Apache Directory LDAP API: LDAP client implementation does not verify if the server certificate matches the intended LDAP hostname",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-35563"
    },
    {
      "rank": 250,
      "cve_id": "CVE-2026-40549",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00182,
      "epss_percentile": 0.08111,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SOPlanning",
      "product": "SOPlanning",
      "cwe": "CWE-352",
      "title": "Cross-Site Request Forgery in SOPlanning",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40549"
    },
    {
      "rank": 251,
      "cve_id": "CVE-2026-44211",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0018,
      "epss_percentile": 0.07932,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cline",
      "product": "cline",
      "cwe": "CWE-306",
      "title": "Cline Kanban Server has a Cross-Origin WebSocket Hijacking Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44211"
    },
    {
      "rank": 252,
      "cve_id": "CVE-2026-42675",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00178,
      "epss_percentile": 0.07619,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Themefic",
      "product": "Hydra Booking",
      "cwe": "CWE-862",
      "title": "WordPress Hydra Booking plugin <= 1.1.41 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42675"
    },
    {
      "rank": 253,
      "cve_id": "CVE-2026-24753",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00174,
      "epss_percentile": 0.0723,
      "kev": false,
      "kev_due_at": null,
      "vendor": "kiteworks",
      "product": "Secure Data Forms",
      "cwe": "CWE-639",
      "title": "Kiteworks Secure Data Forms is vulnerable to Authorization Bypass Through User-Controlled Key",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-24753"
    },
    {
      "rank": 254,
      "cve_id": "CVE-2026-48559",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00171,
      "epss_percentile": 0.0687,
      "kev": false,
      "kev_due_at": null,
      "vendor": "epoupon",
      "product": "lms",
      "cwe": "CWE-79",
      "title": "Lightweight Music Server 3.76.0 Stored XSS via Media File Metadata Tags",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48559"
    },
    {
      "rank": 255,
      "cve_id": "CVE-2026-9048",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00163,
      "epss_percentile": 0.06011,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Revolution Slider",
      "product": "Slider Revolution",
      "cwe": "CWE-863",
      "title": "Slider Revolution 7.0.0 - 7.0.14 - Incorrect Authorization to Authenticated (Contributor+) Sensitive Information Exposure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9048"
    },
    {
      "rank": 256,
      "cve_id": "CVE-2018-25432",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00162,
      "epss_percentile": 0.05909,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Armcode",
      "product": "Arm Whois",
      "cwe": "CWE-120",
      "title": "Arm Whois 3.11 Buffer Overflow via ASLR Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2018-25432"
    },
    {
      "rank": 257,
      "cve_id": "CVE-2026-8501",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00162,
      "epss_percentile": 0.05902,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Symantec",
      "product": "PC Tools Internet Security",
      "cwe": "CWE-782",
      "title": "CVE-2026-8501",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8501"
    },
    {
      "rank": 258,
      "cve_id": "CVE-2025-55664",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00158,
      "epss_percentile": 0.05511,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-122",
      "title": "A heap buffer overflow in the m2tsdmx_send_packet function (filters/dmx_m2ts.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service (DoS) via supplying a crafted MP4 file.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-55664"
    },
    {
      "rank": 259,
      "cve_id": "CVE-2026-9308",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00157,
      "epss_percentile": 0.05419,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox for iOS",
      "cwe": "CWE-79",
      "title": "Arbitrary JavaScript execution in Reader View due to wrong HTML replacement order",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9308"
    },
    {
      "rank": 260,
      "cve_id": "CVE-2026-9309",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00157,
      "epss_percentile": 0.05419,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox for iOS",
      "cwe": "CWE-79",
      "title": "Arbitrary JavaScript execution in internal pages via Reader View JSON-LD injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9309"
    },
    {
      "rank": 261,
      "cve_id": "CVE-2018-25435",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00156,
      "epss_percentile": 0.05352,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zeuscart",
      "product": "ZeusCart",
      "cwe": "CWE-352",
      "title": "ZeusCart 4.0 Deactivate Customer Accounts CSRF",
      "url": "https://www.cve.org/CVERecord?id=CVE-2018-25435"
    },
    {
      "rank": 262,
      "cve_id": "CVE-2026-45153",
      "cvss_base": 4.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00153,
      "epss_percentile": 0.05021,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nextcloud",
      "product": "security-advisories",
      "cwe": "CWE-287",
      "title": "Nextcloud: PIN bypass in PassCodeActivity via back button",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45153"
    },
    {
      "rank": 263,
      "cve_id": "CVE-2026-9050",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00153,
      "epss_percentile": 0.05027,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Revolution Slider",
      "product": "Slider Revolution",
      "cwe": "CWE-862",
      "title": "Slider Revolution 6.0.0-6.7.55 and 7.0.0-7.0.14 - Missing Authorization to Authenticated (Contributor+) Arbitrary Plugin Deactivation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9050"
    },
    {
      "rank": 264,
      "cve_id": "CVE-2026-24756",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00152,
      "epss_percentile": 0.04909,
      "kev": false,
      "kev_due_at": null,
      "vendor": "kiteworks",
      "product": "Secure Data Forms",
      "cwe": "CWE-639",
      "title": "Kiteworks Secure Data Forms is vulnerable to Authorization Bypass Through User-Controlled Key",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-24756"
    },
    {
      "rank": 265,
      "cve_id": "CVE-2026-38950",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00144,
      "epss_percentile": 0.04208,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-502",
      "title": "An issue in ESA AnomalyMatch before 1.3.1 allow attackers to execute arbitrary code via crafted model checkpoint files. The affected components load model files from session directories using torch.load() with unrestricted deserialization.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-38950"
    },
    {
      "rank": 266,
      "cve_id": "CVE-2025-60481",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00143,
      "epss_percentile": 0.04122,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-476",
      "title": "A NULL pointer dereference in the gf_odf_ac4_cfg_dsi_v1 function (/odf/descriptors.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted AC4 file.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-60481"
    },
    {
      "rank": 267,
      "cve_id": "CVE-2025-60483",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00143,
      "epss_percentile": 0.04122,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-476",
      "title": "A NULL pointer dereference in the gf_ac4_pres_b_4_back_channels_present function (/media_tools/av_parsers.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted AC4 file.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-60483"
    },
    {
      "rank": 268,
      "cve_id": "CVE-2025-60485",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00143,
      "epss_percentile": 0.04122,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-476",
      "title": "A segmentation violation in the gf_isom_apple_set_tag_ex function (/isomedia/isom_write.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted MP4 file.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-60485"
    },
    {
      "rank": 269,
      "cve_id": "CVE-2026-34193",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00143,
      "epss_percentile": 0.04092,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Imagination Technologies",
      "product": "Graphics DDK",
      "cwe": "CWE-823",
      "title": "GPU DDK - Arbitrary write via UFO updates due insufficient pointer validation in rgxfw_to_ptr()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34193"
    },
    {
      "rank": 270,
      "cve_id": "CVE-2026-48190",
      "cvss_base": 3.5,
      "cvss_severity": "LOW",
      "epss_score": 0.00143,
      "epss_percentile": 0.04103,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OTRS AG",
      "product": "OTRS",
      "cwe": "CWE-276",
      "title": "Incorrect handling of permissions in External Interface Config Item List module",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48190"
    },
    {
      "rank": 271,
      "cve_id": "CVE-2026-48191",
      "cvss_base": 3.5,
      "cvss_severity": "LOW",
      "epss_score": 0.00143,
      "epss_percentile": 0.04103,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OTRS AG",
      "product": "OTRS",
      "cwe": "CWE-276",
      "title": "Wrong Permission Handling in Document Search Article Meta Filters",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48191"
    },
    {
      "rank": 272,
      "cve_id": "CVE-2026-42681",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00142,
      "epss_percentile": 0.0399,
      "kev": false,
      "kev_due_at": null,
      "vendor": "E2Pdf.com",
      "product": "e2pdf",
      "cwe": "CWE-79",
      "title": "WordPress e2pdf plugin <= 1.32.14 - Reflected Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42681"
    },
    {
      "rank": 273,
      "cve_id": "CVE-2026-42683",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00142,
      "epss_percentile": 0.03989,
      "kev": false,
      "kev_due_at": null,
      "vendor": "e4jvikwp",
      "product": "VikBooking Hotel Booking Engine & PMS",
      "cwe": "CWE-79",
      "title": "WordPress VikBooking Hotel Booking Engine & PMS plugin <= 1.8.8 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42683"
    },
    {
      "rank": 274,
      "cve_id": "CVE-2026-24761",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00142,
      "epss_percentile": 0.04041,
      "kev": false,
      "kev_due_at": null,
      "vendor": "kiteworks",
      "product": "Secure Data Forms",
      "cwe": "CWE-639",
      "title": "Kiteworks Secure Data Forms is vulnerable to Authorization Bypass Through User-Controlled Key",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-24761"
    },
    {
      "rank": 275,
      "cve_id": "CVE-2026-24755",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00138,
      "epss_percentile": 0.0364,
      "kev": false,
      "kev_due_at": null,
      "vendor": "kiteworks",
      "product": "Secure Data Forms",
      "cwe": "CWE-639",
      "title": "Kiteworks Secure Data Forms is vulnerable to Authorization Bypass Through User-Controlled Key",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-24755"
    },
    {
      "rank": 276,
      "cve_id": "CVE-2026-24754",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00136,
      "epss_percentile": 0.03501,
      "kev": false,
      "kev_due_at": null,
      "vendor": "kiteworks",
      "product": "security-advisories",
      "cwe": "CWE-79",
      "title": "Kiteworks Secure Data Forms Vulnerable to Cross-site Scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-24754"
    },
    {
      "rank": 277,
      "cve_id": "CVE-2025-60495",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00133,
      "epss_percentile": 0.03327,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-476",
      "title": "A segmentation violation in the gf_media_get_color_info function (/media_tools/isom_tools.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted data file.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-60495"
    },
    {
      "rank": 278,
      "cve_id": "CVE-2026-43958",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00132,
      "epss_percentile": 0.03247,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-121",
      "title": "Rrdtool: rrdtool: stack buffer overflow allows local code execution or denial of service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43958"
    },
    {
      "rank": 279,
      "cve_id": "CVE-2026-0055",
      "cvss_base": 6.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00132,
      "epss_percentile": 0.03199,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": "CWE-22",
      "title": "In createSessionInternal of PackageInstallerService.java, there is a possible to update a Device Policy Controller (DPC) into an invalid directory due to a path traversal error. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-0055"
    },
    {
      "rank": 280,
      "cve_id": "CVE-2026-42676",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0013,
      "epss_percentile": 0.03105,
      "kev": false,
      "kev_due_at": null,
      "vendor": "myCred",
      "product": "myCred",
      "cwe": "CWE-79",
      "title": "WordPress myCred plugin <= 3.0.4 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42676"
    },
    {
      "rank": 281,
      "cve_id": "CVE-2025-60486",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0013,
      "epss_percentile": 0.03057,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-416",
      "title": "A heap use-after-free in the dasher_process function (/filters/dasher.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted MPEG-2 file.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-60486"
    },
    {
      "rank": 282,
      "cve_id": "CVE-2026-45277",
      "cvss_base": 3.3,
      "cvss_severity": "LOW",
      "epss_score": 0.0013,
      "epss_percentile": 0.03067,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nextcloud",
      "product": "security-advisories",
      "cwe": "CWE-200",
      "title": "Nextcloud: Information disclosure in Nextcloud Approval app via fileId parameter reveals workflow associations",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45277"
    },
    {
      "rank": 283,
      "cve_id": "CVE-2026-49135",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00129,
      "epss_percentile": 0.03031,
      "kev": false,
      "kev_due_at": null,
      "vendor": "steipete",
      "product": "CodexBar",
      "cwe": "CWE-59",
      "title": "CodexBar < 0.32.0 Insecure Temporary File Handling in Notarization Workflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49135"
    },
    {
      "rank": 284,
      "cve_id": "CVE-2026-10230",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00127,
      "epss_percentile": 0.02756,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "Assimp",
      "cwe": "CWE-119",
      "title": "Assimp Half-Life 1 MDL Loader HL1MDLLoader.cpp read_animations heap-based overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10230"
    },
    {
      "rank": 285,
      "cve_id": "CVE-2026-10229",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00125,
      "epss_percentile": 0.02635,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "Assimp",
      "cwe": "CWE-119",
      "title": "Assimp Half-Life 1 MDL Loader HL1MDLLoader.cpp read_meshes heap-based overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10229"
    },
    {
      "rank": 286,
      "cve_id": "CVE-2026-10231",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00124,
      "epss_percentile": 0.02556,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "Assimp",
      "cwe": "CWE-119",
      "title": "Assimp Half-Life 1 MDL Loader HL1MDLLoader.cpp extract_anim_value heap-based overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10231"
    },
    {
      "rank": 287,
      "cve_id": "CVE-2026-0072",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00122,
      "epss_percentile": 0.02398,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android XR",
      "cwe": "CWE-285",
      "title": "In addInputMethodListener of com.android.server.inputmethod.InputMethodManagerService, there is a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-0072"
    },
    {
      "rank": 288,
      "cve_id": "CVE-2026-0097",
      "cvss_base": 8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00121,
      "epss_percentile": 0.02293,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": "CWE-693",
      "title": "In multiple locations, there is a possible way to bypass user interaction when pairing an LE device due to a logic error. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-0097"
    },
    {
      "rank": 289,
      "cve_id": "CVE-2026-10267",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00121,
      "epss_percentile": 0.0227,
      "kev": false,
      "kev_due_at": null,
      "vendor": "janet-lang",
      "product": "janet",
      "cwe": "CWE-119",
      "title": "janet-lang janet debug.c doframe out-of-bounds",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10267"
    },
    {
      "rank": 290,
      "cve_id": "CVE-2026-0046",
      "cvss_base": 6.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0012,
      "epss_percentile": 0.02174,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": "CWE-269",
      "title": "In InputInterceptor of Letterbox.java, there is a possible way to trick a user into accepting a permission due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-0046"
    },
    {
      "rank": 291,
      "cve_id": "CVE-2026-10268",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": 0.0012,
      "epss_percentile": 0.02216,
      "kev": false,
      "kev_due_at": null,
      "vendor": "janet-lang",
      "product": "janet",
      "cwe": "CWE-189",
      "title": "janet-lang janet marsh.c unmarshal_one_fiber integer overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10268"
    },
    {
      "rank": 292,
      "cve_id": "CVE-2026-10295",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": 0.0012,
      "epss_percentile": 0.02215,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "Customer Review App",
      "cwe": "CWE-404",
      "title": "SourceCodester Customer Review App review_app.py get_all_reviews denial of service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10295"
    },
    {
      "rank": 293,
      "cve_id": "CVE-2019-25718",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00118,
      "epss_percentile": 0.01986,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dräger",
      "product": "Infinity Explorer C700",
      "cwe": "CWE-451",
      "title": "Dräger Infinity Explorer C700 Privilege Escalation via Kiosk Mode Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2019-25718"
    },
    {
      "rank": 294,
      "cve_id": "CVE-2026-0048",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00117,
      "epss_percentile": 0.01976,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": "CWE-269",
      "title": "In hide of WindowState.java, there is a possible way to trick the user into approving permissions due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-0048"
    },
    {
      "rank": 295,
      "cve_id": "CVE-2026-10232",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00115,
      "epss_percentile": 0.01794,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "Assimp",
      "cwe": "CWE-119",
      "title": "Assimp ASE File scene.cpp ~aiNode use after free",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10232"
    },
    {
      "rank": 296,
      "cve_id": "CVE-2026-0059",
      "cvss_base": 8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00114,
      "epss_percentile": 0.01714,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": "CWE-122",
      "title": "In multiple functions of sdp_discovery.cc, there is a possible way to achieve code execution due to a heap buffer overflow. This could lead to remote (proximal/adjacent) code execution with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-0059"
    },
    {
      "rank": 297,
      "cve_id": "CVE-2026-20453",
      "cvss_base": 6.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00114,
      "epss_percentile": 0.01723,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MediaTek, Inc.",
      "product": "MediaTek chipset",
      "cwe": "CWE-787",
      "title": "In geniezone, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10886526; Issue ID: MSV-6791.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20453"
    },
    {
      "rank": 298,
      "cve_id": "CVE-2026-25599",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00114,
      "epss_percentile": 0.01767,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Orca Energy",
      "product": "Orca heat pump",
      "cwe": "CWE-79",
      "title": "Missing authentication and clear‑text data transmission affecting Orca heat pumps",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-25599"
    },
    {
      "rank": 299,
      "cve_id": "CVE-2026-10233",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00113,
      "epss_percentile": 0.01653,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "Assimp",
      "cwe": "CWE-119",
      "title": "Assimp Half-Life 1 MDL Loader HL1MDLLoader.cpp read_sequence_infos out-of-bounds",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10233"
    },
    {
      "rank": 300,
      "cve_id": "CVE-2026-10298",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00112,
      "epss_percentile": 0.01603,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ggml-org",
      "product": "whisper.cpp",
      "cwe": "CWE-404",
      "title": "ggml-org whisper.cpp ggml.c whisper_model_load null pointer dereference",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10298"
    },
    {
      "rank": 301,
      "cve_id": "CVE-2026-20455",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00108,
      "epss_percentile": 0.01367,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MediaTek, Inc.",
      "product": "MediaTek chipset",
      "cwe": "CWE-787",
      "title": "In geniezone, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10873936; Issue ID: MSV-6784.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20455"
    },
    {
      "rank": 302,
      "cve_id": "CVE-2026-0056",
      "cvss_base": 3.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00108,
      "epss_percentile": 0.01372,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": "CWE-120",
      "title": "In setTo of ResourceTypes.cpp, there is a possible read out of bounds due to an incorrect bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-0056"
    },
    {
      "rank": 303,
      "cve_id": "CVE-2026-0095",
      "cvss_base": 8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00107,
      "epss_percentile": 0.01295,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": "CWE-190",
      "title": "In l2c_fcr_clone_buf of l2c_fcr.cc, there is a possible way to trigger controlled heap corruption within the privileged Bluetooth process due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-0095"
    },
    {
      "rank": 304,
      "cve_id": "CVE-2025-59601",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00107,
      "epss_percentile": 0.01302,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Qualcomm, Inc.",
      "product": "Snapdragon",
      "cwe": "CWE-1230",
      "title": "Exposure of Sensitive Information Through Metadata in Powerline Communication Firmware",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-59601"
    },
    {
      "rank": 305,
      "cve_id": "CVE-2026-49433",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00107,
      "epss_percentile": 0.01283,
      "kev": false,
      "kev_due_at": null,
      "vendor": "DeepAI",
      "product": "api.deepai.org",
      "cwe": "CWE-352",
      "title": "DeepAI api.deepai.org/change_user_email CSRF",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49433"
    },
    {
      "rank": 306,
      "cve_id": "CVE-2026-20456",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00102,
      "epss_percentile": 0.01069,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MediaTek, Inc.",
      "product": "MediaTek chipset",
      "cwe": "CWE-787",
      "title": "In wlan STA driver, there is a possible system crash due to a missing bounds check. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00480851; Issue ID: MSV-6338.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20456"
    },
    {
      "rank": 307,
      "cve_id": "CVE-2026-27788",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00097,
      "epss_percentile": 0.00859,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Fsas Technologies Inc.",
      "product": "ServerView Agents for Windows",
      "cwe": "CWE-732",
      "title": "Incorrect permission assignment for critical resource issue exists in ServerView Agents for Windows V11.60.04 and earlier. If this vulnerability is exploited, a local authenticated attacker who can log in to the server where the affected product is installed may obtain SYSTEM privilege.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-27788"
    },
    {
      "rank": 308,
      "cve_id": "CVE-2026-32325",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00097,
      "epss_percentile": 0.00859,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Fsas Technologies Inc.",
      "product": "ServerView Agents for Windows",
      "cwe": "CWE-268",
      "title": "Privilege chaining issue exists in ServerView Agents for Windows V11.60.04 and earlier. If this vulnerability is exploited, a local authenticated attacker who can log in to the server where the affected product is installed may obtain SYSTEM privilege.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-32325"
    },
    {
      "rank": 309,
      "cve_id": "CVE-2026-24085",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00097,
      "epss_percentile": 0.00863,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Qualcomm, Inc.",
      "product": "Snapdragon",
      "cwe": "CWE-121",
      "title": "Stack-based Buffer Overflow in Display",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-24085"
    },
    {
      "rank": 310,
      "cve_id": "CVE-2026-24087",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00097,
      "epss_percentile": 0.00863,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Qualcomm, Inc.",
      "product": "Snapdragon",
      "cwe": "CWE-1286",
      "title": "Improper Validation of Syntactic Correctness of Input in Kernel",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-24087"
    },
    {
      "rank": 311,
      "cve_id": "CVE-2026-24089",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00097,
      "epss_percentile": 0.00862,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Qualcomm, Inc.",
      "product": "Snapdragon",
      "cwe": "CWE-1286",
      "title": "Improper Validation of Syntactic Correctness of Input in Kernel",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-24089"
    },
    {
      "rank": 312,
      "cve_id": "CVE-2026-24091",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00097,
      "epss_percentile": 0.00863,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Qualcomm, Inc.",
      "product": "Snapdragon",
      "cwe": "CWE-1286",
      "title": "Improper Validation of Syntactic Correctness of Input in Display",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-24091"
    },
    {
      "rank": 313,
      "cve_id": "CVE-2026-24092",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00097,
      "epss_percentile": 0.00863,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Qualcomm, Inc.",
      "product": "Snapdragon",
      "cwe": "CWE-1286",
      "title": "Improper Validation of Syntactic Correctness of Input in Display",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-24092"
    },
    {
      "rank": 314,
      "cve_id": "CVE-2021-46747",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00097,
      "epss_percentile": 0.00849,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AMD",
      "product": "AMD Athlon™ 3000 Series Mobile Processors with Radeon™ Graphics",
      "cwe": "CWE-1220",
      "title": "Insufficient granularity of access control in ASP (AMD Secure Processor) may allow an attacker with an untrusted user space application to map sensitive SMN (System Management Network) apertures leading to a potential escalation of privileges.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2021-46747"
    },
    {
      "rank": 315,
      "cve_id": "CVE-2026-0075",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00094,
      "epss_percentile": 0.00688,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": "CWE-89",
      "title": "In multiple functions, there is a possible way to access the contacts database due to a SQL injection. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-0075"
    },
    {
      "rank": 316,
      "cve_id": "CVE-2025-59609",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00091,
      "epss_percentile": 0.00575,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Qualcomm, Inc.",
      "product": "Snapdragon",
      "cwe": "CWE-126",
      "title": "Buffer Over-read in WLAN Host Communication",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-59609"
    },
    {
      "rank": 317,
      "cve_id": "CVE-2025-22424",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00088,
      "epss_percentile": 0.00442,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": "CWE-20",
      "title": "In multiple locations, there is a possible way to reveal images across users due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-22424"
    },
    {
      "rank": 318,
      "cve_id": "CVE-2025-22426",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00084,
      "epss_percentile": 0.00324,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": "CWE-284",
      "title": "In many functions of ComputerEngine.java, there is a possible way to access URIs across users due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-22426"
    },
    {
      "rank": 319,
      "cve_id": "CVE-2025-48652",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00083,
      "epss_percentile": 0.0029,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": "CWE-693",
      "title": "In performPreInstallChecks of InstallRepository.kt, there is a possible way to bypass MDM policy due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-48652"
    },
    {
      "rank": 320,
      "cve_id": "CVE-2026-0045",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00083,
      "epss_percentile": 0.0029,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": "CWE-693",
      "title": "In bta_jv_rfcomm_connect of bta_jv_act.cc, there is a possible bypass of bonding for a secure connection due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-0045"
    },
    {
      "rank": 321,
      "cve_id": "CVE-2026-0077",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00082,
      "epss_percentile": 0.00271,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": "CWE-693",
      "title": "In resumeConfigurationDispatch of ActivityRecord.java, there is a possible background application launch (bal) due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-0077"
    },
    {
      "rank": 322,
      "cve_id": "CVE-2026-0087",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00082,
      "epss_percentile": 0.0027,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": "CWE-693",
      "title": "In approvalLevelForDomainInternal of DomainVerificationService.java, there is a possible way to hijack an arbitrary app link due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-0087"
    },
    {
      "rank": 323,
      "cve_id": "CVE-2026-0009",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0008,
      "epss_percentile": 0.00206,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": "CWE-269",
      "title": "In multiple locations, there is a possible tapjacking due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-0009"
    },
    {
      "rank": 324,
      "cve_id": "CVE-2025-48649",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00079,
      "epss_percentile": 0.00182,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": "CWE-693",
      "title": "In multiple locations, there is a possible way to reset user-selected permissions selections due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-48649"
    },
    {
      "rank": 325,
      "cve_id": "CVE-2026-0076",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00079,
      "epss_percentile": 0.00165,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": "CWE-125",
      "title": "In validateNode of ResourceTypes.cpp, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-0076"
    },
    {
      "rank": 326,
      "cve_id": "CVE-2026-0078",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00079,
      "epss_percentile": 0.00164,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": "CWE-20",
      "title": "In setGlobalProxy of DevicePolicyManagerService.java, there is a possible desync in persistence due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-0078"
    },
    {
      "rank": 327,
      "cve_id": "CVE-2026-0088",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00079,
      "epss_percentile": 0.00164,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": "CWE-451",
      "title": "In getCallingAppLabel of CertInstaller.java, there is a possible way to hide a sensitive security dialogue due to misleading or insufficient UI. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-0088"
    },
    {
      "rank": 328,
      "cve_id": "CVE-2025-59611",
      "cvss_base": 6.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00079,
      "epss_percentile": 0.00165,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Qualcomm, Inc.",
      "product": "Snapdragon",
      "cwe": "CWE-787",
      "title": "Out-of-bounds Write in Core Services",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-59611"
    },
    {
      "rank": 329,
      "cve_id": "CVE-2025-59614",
      "cvss_base": 6.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00079,
      "epss_percentile": 0.00165,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Qualcomm, Inc.",
      "product": "Snapdragon",
      "cwe": "CWE-787",
      "title": "Out-of-bounds Write in Windows Compute",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-59614"
    },
    {
      "rank": 330,
      "cve_id": "CVE-2025-59612",
      "cvss_base": 6.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00078,
      "epss_percentile": 0.0016,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Qualcomm, Inc.",
      "product": "Snapdragon",
      "cwe": "CWE-121",
      "title": "Stack-based Buffer Overflow in Windows Compute",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-59612"
    },
    {
      "rank": 331,
      "cve_id": "CVE-2025-59613",
      "cvss_base": 6.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00078,
      "epss_percentile": 0.00159,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Qualcomm, Inc.",
      "product": "Snapdragon",
      "cwe": "CWE-121",
      "title": "Stack-based Buffer Overflow in Windows Compute",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-59613"
    },
    {
      "rank": 332,
      "cve_id": "CVE-2026-20454",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00078,
      "epss_percentile": 0.00148,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MediaTek, Inc.",
      "product": "MediaTek chipset",
      "cwe": "CWE-367",
      "title": "In geniezone, there is a possible out of bounds write due to a race condition. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10873936; Issue ID: MSV-6786.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20454"
    },
    {
      "rank": 333,
      "cve_id": "CVE-2026-25276",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00075,
      "epss_percentile": 0.00095,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Qualcomm, Inc.",
      "product": "Snapdragon",
      "cwe": "CWE-129",
      "title": "Improper Validation of Array Index in Secure Processor",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-25276"
    },
    {
      "rank": 334,
      "cve_id": "CVE-2025-59604",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00075,
      "epss_percentile": 0.00103,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Qualcomm, Inc.",
      "product": "Snapdragon",
      "cwe": "CWE-476",
      "title": "NULL Pointer Dereference in SPS Applications",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-59604"
    },
    {
      "rank": 335,
      "cve_id": "CVE-2025-59605",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00075,
      "epss_percentile": 0.00104,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Qualcomm, Inc.",
      "product": "Snapdragon",
      "cwe": "CWE-787",
      "title": "Out-of-bounds Write in HLOS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-59605"
    },
    {
      "rank": 336,
      "cve_id": "CVE-2025-59606",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00075,
      "epss_percentile": 0.00099,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Qualcomm, Inc.",
      "product": "Snapdragon",
      "cwe": "CWE-476",
      "title": "NULL Pointer Dereference in HLOS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-59606"
    },
    {
      "rank": 337,
      "cve_id": "CVE-2026-0100",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00075,
      "epss_percentile": 0.00094,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": "CWE-122",
      "title": "In Load of LoadedArsc.cpp, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-0100"
    },
    {
      "rank": 338,
      "cve_id": "CVE-2026-0086",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00075,
      "epss_percentile": 0.00093,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": "CWE-269",
      "title": "In onCreate of DisableSupervisionActivity.kt, there is a possible way to delete supervision data due to a missing null check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-0086"
    },
    {
      "rank": 339,
      "cve_id": "CVE-2026-25277",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00074,
      "epss_percentile": 0.0009,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Qualcomm, Inc.",
      "product": "Snapdragon",
      "cwe": "CWE-120",
      "title": "Buffer Copy Without Checking Size of Input in Secure Processor",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-25277"
    },
    {
      "rank": 340,
      "cve_id": "CVE-2026-0043",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00074,
      "epss_percentile": 0.00091,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": "CWE-190",
      "title": "In multiple functions of ubsan_throwing_runtime.cpp, there is a possible persistent denial of service due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-0043"
    },
    {
      "rank": 341,
      "cve_id": "CVE-2026-28581",
      "cvss_base": 4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00074,
      "epss_percentile": 0.00087,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": "CWE-476",
      "title": "In fixInitiatingUserIfNecessary of CallIntentProcessor.java, there is a possible way to make an emergency call due to a logic error in the code. This could lead to local with null execution privileges needed. User interaction is null for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28581"
    },
    {
      "rank": 342,
      "cve_id": "CVE-2026-0093",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00073,
      "epss_percentile": 0.00074,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": "CWE-451",
      "title": "In multiple locations, there is a possible misleading UI due to obfuscation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-0093"
    },
    {
      "rank": 343,
      "cve_id": "CVE-2026-0096",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00073,
      "epss_percentile": 0.00074,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": "CWE-451",
      "title": "In getAppLabel of ForgetDeviceDialogFragment.java, there is a possible trick the user into forgetting a device due to misleading or insufficient UI. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-0096"
    },
    {
      "rank": 344,
      "cve_id": "CVE-2026-28580",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00073,
      "epss_percentile": 0.00074,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": "CWE-120",
      "title": "In multiple functions, there is a possible desync in persistence due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28580"
    },
    {
      "rank": 345,
      "cve_id": "CVE-2026-0061",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00073,
      "epss_percentile": 0.00067,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": "CWE-1021",
      "title": "In multiple functions of WindowState.java, there is a possible way to trick a user into accepting a permission due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-0061"
    },
    {
      "rank": 346,
      "cve_id": "CVE-2025-32348",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00072,
      "epss_percentile": 0.0006,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": "CWE-863",
      "title": "In multiple locations, there is a possible background activity launch due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-32348"
    },
    {
      "rank": 347,
      "cve_id": "CVE-2025-48570",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00072,
      "epss_percentile": 0.0006,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": "CWE-441",
      "title": "In multiple functions of PipTaskOrganizer.java, there is a possible way to launch an activity from the background due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-48570"
    },
    {
      "rank": 348,
      "cve_id": "CVE-2026-0036",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00072,
      "epss_percentile": 0.0006,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": "CWE-1021",
      "title": "In startAnimation of StageCoordinator.java, there is a possible tapjacking issue due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-0036"
    },
    {
      "rank": 349,
      "cve_id": "CVE-2025-48616",
      "cvss_base": 3.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00072,
      "epss_percentile": 0.00066,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": null,
      "title": "In multiple functions of KeyguardViewMediator.java , there is a possible way to bypass lockdown mode with screen pinning due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-48616"
    },
    {
      "rank": 350,
      "cve_id": "CVE-2026-24088",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00071,
      "epss_percentile": 0.00052,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Qualcomm, Inc.",
      "product": "Snapdragon",
      "cwe": "CWE-306",
      "title": "Missing Authentication for Critical Function in Boot",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-24088"
    },
    {
      "rank": 351,
      "cve_id": "CVE-2026-0099",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00071,
      "epss_percentile": 0.00048,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": "CWE-273",
      "title": "In onNullBinding of HostEmulationManager.java, there is a possible way to launch an activity from the background due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-0099"
    },
    {
      "rank": 352,
      "cve_id": "CVE-2026-0018",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00071,
      "epss_percentile": 0.00051,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": "CWE-20",
      "title": "In multiple functions of AccessibilityManagerService.java, there is a possible persistent denial of service due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-0018"
    },
    {
      "rank": 353,
      "cve_id": "CVE-2026-0042",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00071,
      "epss_percentile": 0.0005,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": "CWE-400",
      "title": "In multiple functions of ubsan_throwing_runtime.cpp, there is a possible persistent denial of service due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-0042"
    },
    {
      "rank": 354,
      "cve_id": "CVE-2026-0060",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00071,
      "epss_percentile": 0.00052,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": null,
      "title": "In updateState of GraphicsDriverEnableAngleAsSystemDriverController.java, there is a possible persistent dos issue due to an unusual root cause. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-0060"
    },
    {
      "rank": 355,
      "cve_id": "CVE-2026-0067",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00071,
      "epss_percentile": 0.00052,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": null,
      "title": "In multiple functions of ubsan_throwing_runtime.cpp, there is a possible way to cause a permanent denial of service due to a logic error in the code. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-0067"
    },
    {
      "rank": 356,
      "cve_id": "CVE-2026-0069",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00071,
      "epss_percentile": 0.00052,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": "CWE-400",
      "title": "In verifySignature of ApkChecksums.java, there is a possible way to cause a crash due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-0069"
    },
    {
      "rank": 357,
      "cve_id": "CVE-2026-0070",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00071,
      "epss_percentile": 0.00051,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": "CWE-20",
      "title": "In multiple functions of DevicePolicyManagerService.java, there is a possible way to hide a system critical package due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-0070"
    },
    {
      "rank": 358,
      "cve_id": "CVE-2026-0074",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00071,
      "epss_percentile": 0.0005,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": "CWE-400",
      "title": "In getPreferredSize of LauncherProcessImageListener.kt, there is a possible denial of service due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-0074"
    },
    {
      "rank": 359,
      "cve_id": "CVE-2026-0079",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00071,
      "epss_percentile": 0.00051,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": "CWE-190",
      "title": "In multiple functions of ubsan_throwing_runtime.cpp, there is a possible persistent denial of service due to an integer overflow. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-0079"
    },
    {
      "rank": 360,
      "cve_id": "CVE-2026-0085",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00071,
      "epss_percentile": 0.0005,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": "CWE-20",
      "title": "In applySimpleFieldMaxSize of DataRowHandler.java, there is a possible way to insert a large contact name due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-0085"
    },
    {
      "rank": 361,
      "cve_id": "CVE-2026-25258",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0007,
      "epss_percentile": 0.00044,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Qualcomm, Inc.",
      "product": "Snapdragon",
      "cwe": "CWE-125",
      "title": "Out-of-bounds Read in DSP Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-25258"
    },
    {
      "rank": 362,
      "cve_id": "CVE-2026-25259",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0007,
      "epss_percentile": 0.00043,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Qualcomm, Inc.",
      "product": "Snapdragon",
      "cwe": "CWE-787",
      "title": "Out-of-bounds Write in DSP Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-25259"
    },
    {
      "rank": 363,
      "cve_id": "CVE-2025-26418",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00068,
      "epss_percentile": 0.00032,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": "CWE-862",
      "title": "In setUserDisclaimerAcknowledged of CarDevicePolicyService.java, there is a possible way to bypass the user dialog when adding an account to a managed device due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-26418"
    },
    {
      "rank": 364,
      "cve_id": "CVE-2026-0098",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00068,
      "epss_percentile": 0.00034,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": "CWE-441",
      "title": "In getCallingPackageName of Shared.java, there is a possible way to bypass activity start restrictions due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-0098"
    },
    {
      "rank": 365,
      "cve_id": "CVE-2025-48648",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00068,
      "epss_percentile": 0.00033,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": "CWE-400",
      "title": "In isSameApp of NotificationManagerService.java, there is a possible persistent dos due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-48648"
    },
    {
      "rank": 366,
      "cve_id": "CVE-2026-0050",
      "cvss_base": 3.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00068,
      "epss_percentile": 0.00034,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": "CWE-269",
      "title": "In handleBondStateChanged of AdapterService.java, there is a possible sensitive information disclosure due to a permissions bypass. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-0050"
    },
    {
      "rank": 367,
      "cve_id": "CVE-2026-0089",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00067,
      "epss_percentile": 0.0003,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": "CWE-269",
      "title": "In multiple functions of PackageInstallerService.java, there is a possible way to install unverified apps due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-0089"
    },
    {
      "rank": 368,
      "cve_id": "CVE-2026-0091",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00067,
      "epss_percentile": 0.0003,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": "CWE-269",
      "title": "In multiple locations, there is a possible way to execute code in the launcher process due to an over-privileged shell user. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-0091"
    },
    {
      "rank": 369,
      "cve_id": "CVE-2026-28577",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00067,
      "epss_percentile": 0.00031,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": "CWE-1021",
      "title": "In addWindow of WindowManagerService.java, there is a possible tapjacking issue due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28577"
    },
    {
      "rank": 370,
      "cve_id": "CVE-2026-28578",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00066,
      "epss_percentile": 0.00025,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": "CWE-20",
      "title": "In multiple functions of DevicePolicyManagerService.java, there is a possible desync from persistence due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28578"
    },
    {
      "rank": 371,
      "cve_id": "CVE-2026-25600",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00065,
      "epss_percentile": 0.00021,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Trac d.o.o.",
      "product": "PDBM",
      "cwe": "CWE-798",
      "title": "Credential Exposure Vulnerability in Trac PDBM",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-25600"
    },
    {
      "rank": 372,
      "cve_id": "CVE-2026-0016",
      "cvss_base": 3.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00065,
      "epss_percentile": 0.00022,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": "CWE-269",
      "title": "In updateProvidersWhenServiceRemoved of CredentialManagerService.java, there is a possible way to override settings across users due to a permissions bypass. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-0016"
    },
    {
      "rank": 373,
      "cve_id": "CVE-2026-28586",
      "cvss_base": 3.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00064,
      "epss_percentile": 0.00016,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": "CWE-269",
      "title": "In multiple functions of AppOpsService.java, there is a possible missing permission check due to a permissions bypass. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28586"
    },
    {
      "rank": 374,
      "cve_id": "CVE-2026-24090",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00062,
      "epss_percentile": 0.00011,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Qualcomm, Inc.",
      "product": "Snapdragon",
      "cwe": "CWE-306",
      "title": "Missing Authentication for Critical Function in HLOS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-24090"
    },
    {
      "rank": 375,
      "cve_id": "CVE-2026-0094",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00058,
      "epss_percentile": 0.00007,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": "CWE-451",
      "title": "In getApplicationLabel of KeyChainActivity.java, there is a possible way to trick the user into approving access to certificates due to misleading or insufficient UI. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-0094"
    },
    {
      "rank": 376,
      "cve_id": "CVE-2025-59610",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00056,
      "epss_percentile": 0.00004,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Qualcomm, Inc.",
      "product": "Snapdragon",
      "cwe": "CWE-367",
      "title": "Time-of-check Time-of-use (TOCTOU) Race Condition in Camera Driver",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-59610"
    },
    {
      "rank": 377,
      "cve_id": "CVE-2026-25260",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00052,
      "epss_percentile": 0.00002,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Qualcomm, Inc.",
      "product": "Snapdragon",
      "cwe": "CWE-367",
      "title": "Time-of-check Time-of-use (TOCTOU) Race Condition in DSP Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-25260"
    }
  ],
  "transactions": [
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2024-40646",
      "detail": "EXPLOIT PUBLISHED — CVE-2024-40646 (vertex-app vertex). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-22872",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-22872 (projectcapsule capsule). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-30963",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-30963 (projectcapsule capsule). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-37226",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-37226. Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-37228",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-37228. Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-37229",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-37229. Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-37230",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-37230. Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-37231",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-37231. Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-37233",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-37233. Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-37234",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-37234. Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-37235",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-37235. Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-44211",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-44211 (cline). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-45286",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-45286 (nextcloud security-advisories). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-46243",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-46243 (Linux). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-49121",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-49121 (ROCm aiter). Public exploit reference added."
    }
  ],
  "attribution": "CVE Program, NVD (NIST), CISA KEV, FIRST EPSS, OSV. See /security/methodology/."
}
