{
  "day": "2026-06-02",
  "boundary": "UTC calendar day",
  "published_count": 226,
  "by_severity": {
    "CRITICAL": 14,
    "HIGH": 85,
    "MEDIUM": 97,
    "LOW": 29
  },
  "kev_count": 2,
  "exploit_reference_count": 25,
  "awaiting_enrichment_count": 1,
  "ranking": "Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.",
  "results": [
    {
      "rank": 1,
      "cve_id": "CVE-2022-0492",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.05528,
      "epss_percentile": 0.92174,
      "kev": true,
      "kev_due_at": "2026-06-05",
      "vendor": "Linux",
      "product": "Kernel",
      "cwe": null,
      "title": "Linux Kernel",
      "url": "https://www.cve.org/CVERecord?id=CVE-2022-0492"
    },
    {
      "rank": 2,
      "cve_id": "CVE-2025-48595",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.01714,
      "epss_percentile": 0.75553,
      "kev": true,
      "kev_due_at": "2026-06-05",
      "vendor": "Google",
      "product": "Android",
      "cwe": "CWE-190",
      "title": "Android Framework",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-48595"
    },
    {
      "rank": 3,
      "cve_id": "CVE-2026-32625",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0294,
      "epss_percentile": 0.86007,
      "kev": false,
      "kev_due_at": null,
      "vendor": "danny-avila",
      "product": "LibreChat",
      "cwe": "CWE-200",
      "title": "LibreChat Exfiltrates Server Secrets via MCP Server URL Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-32625"
    },
    {
      "rank": 4,
      "cve_id": "CVE-2026-5073",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.01383,
      "epss_percentile": 0.69981,
      "kev": false,
      "kev_due_at": null,
      "vendor": "armember",
      "product": "ARMember Premium – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup",
      "cwe": "CWE-89",
      "title": "ARMember Premium <= 7.3.1 - Unauthenticated SQL Injection via 'order' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-5073"
    },
    {
      "rank": 5,
      "cve_id": "CVE-2026-8206",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0126,
      "epss_percentile": 0.6723,
      "kev": false,
      "kev_due_at": null,
      "vendor": "themeum",
      "product": "Kirki – Freeform Page Builder, Website Builder & Customizer",
      "cwe": "CWE-269",
      "title": "Kirki 6.0.0 - 6.0.6 - Unauthenticated Privilege Escalation via 'handle_forgot_password'",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8206"
    },
    {
      "rank": 6,
      "cve_id": "CVE-2026-10550",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.01067,
      "epss_percentile": 0.62116,
      "kev": false,
      "kev_due_at": null,
      "vendor": "elunez",
      "product": "eladmin",
      "cwe": "CWE-74",
      "title": "elunez eladmin Application Deployment App.java command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10550"
    },
    {
      "rank": 7,
      "cve_id": "CVE-2026-47117",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00915,
      "epss_percentile": 0.57356,
      "kev": false,
      "kev_due_at": null,
      "vendor": "maziyarpanahi",
      "product": "openmed",
      "cwe": "CWE-94",
      "title": "OpenMed < 1.5.2 Remote Code Execution via PII Model Loading",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47117"
    },
    {
      "rank": 8,
      "cve_id": "CVE-2026-35718",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00723,
      "epss_percentile": 0.51183,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-22",
      "title": "A path traversal vulnerability in the /admin/downloadMedias.cgi endpoint of VIVOTEK INC FD8136-VVTK firmware 0300a allows authenticated attackers to read any file on the device via sending a crafted request.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-35718"
    },
    {
      "rank": 9,
      "cve_id": "CVE-2026-10702",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00722,
      "epss_percentile": 0.5113,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-843",
      "title": "JIT miscompilation in the JavaScript Engine: JIT component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10702"
    },
    {
      "rank": 10,
      "cve_id": "CVE-2026-1829",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00708,
      "epss_percentile": 0.50648,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jhorowitz",
      "product": "Content Visibility for Divi Builder",
      "cwe": "CWE-94",
      "title": "Content Visibility for Divi Builder <= 4.02 - Authenticated (Contributor+) Remote Code Execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-1829"
    },
    {
      "rank": 11,
      "cve_id": "CVE-2026-0611",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00664,
      "epss_percentile": 0.48961,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Spacelabs Healthcare",
      "product": "Sentinel",
      "cwe": "CWE-306",
      "title": "Spacelabs Healthcare Sentinel 10.5.x < 11.6.0 Unauthenticated RCE via .NET Remoting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-0611"
    },
    {
      "rank": 12,
      "cve_id": "CVE-2026-10591",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00662,
      "epss_percentile": 0.48889,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AWS",
      "product": "Kiro IDE",
      "cwe": "CWE-732",
      "title": "Kiro IDE Insufficient File Write Restrictions to Execution-Sensitive Paths",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10591"
    },
    {
      "rank": 13,
      "cve_id": "CVE-2026-30650",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00599,
      "epss_percentile": 0.46042,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-120",
      "title": "A post-authentication remote buffer overflow vulnerability exists in the /cgi-bin/admin/eventtask.cgi endpoint of the admin interface of Vivotek FD8136 cameras running firmware version FD8136-VVTK-0300a. This flaw allows an authenticated attacker to execute arbitrary code as root on the device remotely.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-30650"
    },
    {
      "rank": 14,
      "cve_id": "CVE-2026-27145",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00591,
      "epss_percentile": 0.45668,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Go standard library",
      "product": "crypto/x509",
      "cwe": "CWE-606",
      "title": "Inefficient candidate hostname parsing in crypto/x509",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-27145"
    },
    {
      "rank": 15,
      "cve_id": "CVE-2026-42504",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0056,
      "epss_percentile": 0.44168,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Go standard library",
      "product": "mime",
      "cwe": "CWE-407",
      "title": "Quadratic complexity in WordDecoder.DecodeHeader in mime",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42504"
    },
    {
      "rank": 16,
      "cve_id": "CVE-2026-34906",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00557,
      "epss_percentile": 0.44002,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Simple SA",
      "product": "Wirtualna Uczelnia",
      "cwe": "CWE-1336",
      "title": "Server-Side Template Injection (SSTI) in Wirtualna Uczelnia",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34906"
    },
    {
      "rank": 17,
      "cve_id": "CVE-2026-42074",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00544,
      "epss_percentile": 0.43336,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Gitlawb",
      "product": "openclaude",
      "cwe": "CWE-284",
      "title": "OpenClaude: Sandbox Bypass via Model-Controlled `dangerouslyDisableSandbox` Input",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42074"
    },
    {
      "rank": 18,
      "cve_id": "CVE-2026-30652",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00523,
      "epss_percentile": 0.42146,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-120",
      "title": "A remote buffer overflow vulnerability exists in the /cgi-bin/dido/setdo.cgi endpoint of the admin interface of Vivotek FD8136 cameras running firmware version FD8136-VVTK-0300a. This flaw allows an authenticated attacker to execute arbitrary code as root on the device.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-30652"
    },
    {
      "rank": 19,
      "cve_id": "CVE-2026-10619",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00498,
      "epss_percentile": 0.40677,
      "kev": false,
      "kev_due_at": null,
      "vendor": "sayan365",
      "product": "student-management-system",
      "cwe": "CWE-287",
      "title": "sayan365 student-management-system improper authentication",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10619"
    },
    {
      "rank": 20,
      "cve_id": "CVE-2026-28299",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00493,
      "epss_percentile": 0.40352,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SolarWinds",
      "product": "Web Help Desk",
      "cwe": "CWE-770",
      "title": "SolarWinds Web Help Desk Denial-of-Service Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28299"
    },
    {
      "rank": 21,
      "cve_id": "CVE-2026-48595",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00487,
      "epss_percentile": 0.39985,
      "kev": false,
      "kev_due_at": null,
      "vendor": "elixir-tesla",
      "product": "tesla",
      "cwe": "CWE-178",
      "title": "Authorization header leaks to third-party origin on cross-origin redirect in Tesla.Middleware.FollowRedirects",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48595"
    },
    {
      "rank": 22,
      "cve_id": "CVE-2026-3514",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00476,
      "epss_percentile": 0.39272,
      "kev": false,
      "kev_due_at": null,
      "vendor": "prefecthq",
      "product": "prefecthq/prefect",
      "cwe": "CWE-863",
      "title": "Authentication Bypass in prefecthq/prefect",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-3514"
    },
    {
      "rank": 23,
      "cve_id": "CVE-2026-7195",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00471,
      "epss_percentile": 0.38887,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Progress Software",
      "product": "Sitefinity",
      "cwe": "CWE-20",
      "title": "CWE-20: Improper Input Validation in web services in Progress Sitefinity",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7195"
    },
    {
      "rank": 24,
      "cve_id": "CVE-2026-45685",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00463,
      "epss_percentile": 0.3842,
      "kev": false,
      "kev_due_at": null,
      "vendor": "open-telemetry",
      "product": "opentelemetry-ebpf-instrumentation",
      "cwe": "CWE-20",
      "title": "OpenTelemetry eBPF Instrumentation: MongoDB parser panics on malformed wire messages",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45685"
    },
    {
      "rank": 25,
      "cve_id": "CVE-2026-48594",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00455,
      "epss_percentile": 0.37932,
      "kev": false,
      "kev_due_at": null,
      "vendor": "elixir-tesla",
      "product": "tesla",
      "cwe": "CWE-409",
      "title": "Decompression bomb in Tesla.Middleware.DecompressResponse and Tesla.Middleware.Compression",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48594"
    },
    {
      "rank": 26,
      "cve_id": "CVE-2026-7198",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00443,
      "epss_percentile": 0.37075,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Progress Software",
      "product": "Sitefinity",
      "cwe": "CWE-284",
      "title": "CWE-284: Improper Access Control in web services in Progress Sitefinity",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7198"
    },
    {
      "rank": 27,
      "cve_id": "CVE-2026-10622",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00442,
      "epss_percentile": 0.36964,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Collibra",
      "product": "Collibra Platform (on-prem)",
      "cwe": null,
      "title": "CVE-2026-10622",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10622"
    },
    {
      "rank": 28,
      "cve_id": "CVE-2026-7312",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00441,
      "epss_percentile": 0.3685,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Progress Software",
      "product": "Sitefinity",
      "cwe": "CWE-522",
      "title": "CWE‑522: Insufficiently Protected Credentials in web services in Progress Sitefinity",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7312"
    },
    {
      "rank": 29,
      "cve_id": "CVE-2026-5422",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00437,
      "epss_percentile": 0.36588,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jupyter",
      "product": "jupyter/jupyter",
      "cwe": "CWE-23",
      "title": "Path Traversal in jupyter/jupyter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-5422"
    },
    {
      "rank": 30,
      "cve_id": "CVE-2026-46718",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00436,
      "epss_percentile": 0.36474,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Calcite",
      "cwe": "CWE-470",
      "title": "Apache Calcite: A user-controled model can load arbitrary classes, leading to code execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46718"
    },
    {
      "rank": 31,
      "cve_id": "CVE-2026-10650",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00429,
      "epss_percentile": 0.35928,
      "kev": false,
      "kev_due_at": null,
      "vendor": "warmcat",
      "product": "libwebsockets",
      "cwe": "CWE-400",
      "title": "warmcat libwebsockets SSH Protocol sshd.c lws_ssh_parse_plaintext resource consumption",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10650"
    },
    {
      "rank": 32,
      "cve_id": "CVE-2026-5076",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00419,
      "epss_percentile": 0.35129,
      "kev": false,
      "kev_due_at": null,
      "vendor": "armember",
      "product": "ARMember Premium – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup",
      "cwe": "CWE-287",
      "title": "ARMember Premium <= 7.3.1 - Insecure Password Reset Mechanism to Unauthenticated Privilege Escalation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-5076"
    },
    {
      "rank": 33,
      "cve_id": "CVE-2026-5385",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00418,
      "epss_percentile": 0.35008,
      "kev": false,
      "kev_due_at": null,
      "vendor": "glpi-project",
      "product": "glpi",
      "cwe": "CWE-79",
      "title": "GLPI 11.0.0 - Stored XSS in knowledge base",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-5385"
    },
    {
      "rank": 34,
      "cve_id": "CVE-2026-42211",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00416,
      "epss_percentile": 0.34844,
      "kev": false,
      "kev_due_at": null,
      "vendor": "remix-run",
      "product": "react-router",
      "cwe": "CWE-502",
      "title": "React Router's vendored turbo-stream v2 allows arbitrary constructor invocation via TYPE_ERROR deserialization leading to Unauth RCE",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42211"
    },
    {
      "rank": 35,
      "cve_id": "CVE-2025-53440",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00415,
      "epss_percentile": 0.34795,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Axiomthemes",
      "product": "Confidant",
      "cwe": "CWE-98",
      "title": "WordPress Confidant theme <= 1.4 - Local File Inclusion vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-53440"
    },
    {
      "rank": 36,
      "cve_id": "CVE-2025-58705",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00415,
      "epss_percentile": 0.34794,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Axiomthemes",
      "product": "Crafti",
      "cwe": "CWE-98",
      "title": "WordPress Crafti theme <= 1.12 - Local File Inclusion vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-58705"
    },
    {
      "rank": 37,
      "cve_id": "CVE-2026-49448",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00405,
      "epss_percentile": 0.33913,
      "kev": false,
      "kev_due_at": null,
      "vendor": "goauthentik",
      "product": "authentik",
      "cwe": "CWE-287",
      "title": "authentik: SourceStage bypass via empty POST",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49448"
    },
    {
      "rank": 38,
      "cve_id": "CVE-2026-10621",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00402,
      "epss_percentile": 0.33615,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Collibra",
      "product": "Collibra Platform (SaaS)",
      "cwe": null,
      "title": "CVE-2026-10621",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10621"
    },
    {
      "rank": 39,
      "cve_id": "CVE-2026-10617",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00399,
      "epss_percentile": 0.33337,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nextlevelbuilder",
      "product": "GoClaw",
      "cwe": "CWE-287",
      "title": "nextlevelbuilder GoClaw Webhook Verification auth.go resolveAuth missing authentication",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10617"
    },
    {
      "rank": 40,
      "cve_id": "CVE-2026-49143",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00392,
      "epss_percentile": 0.32485,
      "kev": false,
      "kev_due_at": null,
      "vendor": "browserstack",
      "product": "browserstack-runner",
      "cwe": "CWE-94",
      "title": "BrowserStack Runner 0.9.5 Unauthenticated RCE via /_log HTTP Handler",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49143"
    },
    {
      "rank": 41,
      "cve_id": "CVE-2026-48862",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00384,
      "epss_percentile": 0.31691,
      "kev": false,
      "kev_due_at": null,
      "vendor": "elixir-mint",
      "product": "mint",
      "cwe": "CWE-770",
      "title": "Unbounded conn.streams growth in Mint HTTP/2 client via unenforced PUSH_PROMISE concurrency",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48862"
    },
    {
      "rank": 42,
      "cve_id": "CVE-2026-49754",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00384,
      "epss_percentile": 0.31692,
      "kev": false,
      "kev_due_at": null,
      "vendor": "elixir-mint",
      "product": "mint",
      "cwe": "CWE-770",
      "title": "HTTP/2 CONTINUATION flood in Mint client via unbounded header-block accumulation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49754"
    },
    {
      "rank": 43,
      "cve_id": "CVE-2026-30649",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00377,
      "epss_percentile": 0.30969,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-121",
      "title": "Buffer Overflow vulnerability in VIVOTEK INC FD8136-VVTK-0300a allows a remote attacker to execute arbitrary code via the set_getparam.cgi component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-30649"
    },
    {
      "rank": 44,
      "cve_id": "CVE-2026-42507",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0037,
      "epss_percentile": 0.30294,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Go standard library",
      "product": "net/textproto",
      "cwe": null,
      "title": "Arbitrary inputs are included in errors without any escaping in net/textproto",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42507"
    },
    {
      "rank": 45,
      "cve_id": "CVE-2026-42849",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00355,
      "epss_percentile": 0.28775,
      "kev": false,
      "kev_due_at": null,
      "vendor": "goauthentik",
      "product": "authentik",
      "cwe": "CWE-79",
      "title": "authentik: Reflected XSS in SFE AutosubmitStage allows IDP account takeover",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42849"
    },
    {
      "rank": 46,
      "cve_id": "CVE-2026-45686",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00354,
      "epss_percentile": 0.28609,
      "kev": false,
      "kev_due_at": null,
      "vendor": "open-telemetry",
      "product": "opentelemetry-ebpf-instrumentation",
      "cwe": "CWE-190",
      "title": "OpenTelemetry eBPF Instrumentation: Memcached payload length overflow can crash OBI",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45686"
    },
    {
      "rank": 47,
      "cve_id": "CVE-2026-10691",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00354,
      "epss_percentile": 0.28647,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wonderwhy-er",
      "product": "DesktopCommanderMCP",
      "cwe": "CWE-400",
      "title": "wonderwhy-er DesktopCommanderMCP start_search search-manager.ts redos",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10691"
    },
    {
      "rank": 48,
      "cve_id": "CVE-2026-10611",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00353,
      "epss_percentile": 0.28546,
      "kev": false,
      "kev_due_at": null,
      "vendor": "misp",
      "product": "misp",
      "cwe": "CWE-287",
      "title": "OTP bypass via plugin-based LDAP authentication in MISP when LDAP mixed authentication is enabled",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10611"
    },
    {
      "rank": 49,
      "cve_id": "CVE-2026-7201",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00348,
      "epss_percentile": 0.27958,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Progress Software",
      "product": "Sitefinity",
      "cwe": "CWE-639",
      "title": "CWE-639: Authorization Bypass Through User-Controlled Key in web services in Progress Sitefinity",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7201"
    },
    {
      "rank": 50,
      "cve_id": "CVE-2026-48597",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00347,
      "epss_percentile": 0.27911,
      "kev": false,
      "kev_due_at": null,
      "vendor": "elixir-tesla",
      "product": "tesla",
      "cwe": "CWE-770",
      "title": "Atom table exhaustion via untrusted URL scheme in Tesla.Adapter.Mint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48597"
    },
    {
      "rank": 51,
      "cve_id": "CVE-2026-45554",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00343,
      "epss_percentile": 0.27418,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zauberzeug",
      "product": "nicegui",
      "cwe": "CWE-248",
      "title": "NiceGUI: Unauthenticated log-flood DoS via trailing slash on ESM and per-component resource routes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45554"
    },
    {
      "rank": 52,
      "cve_id": "CVE-2026-45678",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00342,
      "epss_percentile": 0.273,
      "kev": false,
      "kev_due_at": null,
      "vendor": "open-telemetry",
      "product": "opentelemetry-ebpf-instrumentation",
      "cwe": "CWE-20",
      "title": "OpenTelemetry eBPF Instrumentation: Postgres BIND parsing can panic on malformed payloads",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45678"
    },
    {
      "rank": 53,
      "cve_id": "CVE-2026-7299",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00341,
      "epss_percentile": 0.27205,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Appsmith",
      "product": "Appsmith",
      "cwe": "CWE-79",
      "title": "CVE-2026-7299",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7299"
    },
    {
      "rank": 54,
      "cve_id": "CVE-2025-58707",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00337,
      "epss_percentile": 0.26703,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Axiomthemes",
      "product": "Spin",
      "cwe": "CWE-98",
      "title": "WordPress Spin theme <= 1.8 - Local File Inclusion vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-58707"
    },
    {
      "rank": 55,
      "cve_id": "CVE-2025-58897",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00337,
      "epss_percentile": 0.26703,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Axiomthemes",
      "product": "Fermentio",
      "cwe": "CWE-98",
      "title": "WordPress Fermentio theme <= 1.5.0 - Local File Inclusion vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-58897"
    },
    {
      "rank": 56,
      "cve_id": "CVE-2025-68886",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00337,
      "epss_percentile": 0.26703,
      "kev": false,
      "kev_due_at": null,
      "vendor": "androThemes",
      "product": "Cookiteer",
      "cwe": "CWE-98",
      "title": "WordPress Cookiteer theme <= 1.4.8 - Local File Inclusion vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-68886"
    },
    {
      "rank": 57,
      "cve_id": "CVE-2026-39552",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00334,
      "epss_percentile": 0.26398,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Code Supply Co.",
      "product": "Blueprint",
      "cwe": "CWE-98",
      "title": "WordPress Blueprint theme < 1.1.5 - Local File Inclusion vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39552"
    },
    {
      "rank": 58,
      "cve_id": "CVE-2026-39553",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00334,
      "epss_percentile": 0.26398,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Select-Themes",
      "product": "WaveRide",
      "cwe": "CWE-98",
      "title": "WordPress WaveRide theme <= 1.4 - Local File Inclusion vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39553"
    },
    {
      "rank": 59,
      "cve_id": "CVE-2026-38967",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00332,
      "epss_percentile": 0.26254,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-113",
      "title": "CrowCpp Crow through v1.3.1 HTTP is vulnerable to response header injection via unvalidated response header values.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-38967"
    },
    {
      "rank": 60,
      "cve_id": "CVE-2025-69369",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00327,
      "epss_percentile": 0.25656,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Axiomthemes",
      "product": "Racquet",
      "cwe": "CWE-98",
      "title": "WordPress Racquet theme <= 1.12.0 - Local File Inclusion vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-69369"
    },
    {
      "rank": 61,
      "cve_id": "CVE-2026-35716",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00322,
      "epss_percentile": 0.25124,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-121",
      "title": "A stack-based buffer overflow in the motion_privacy.cgi binary in VIVOTEK FD8136 firmware FD8136-VVTK-0300a allows authenticated remote attackers to execute arbitrary code as root via an oversized n1 parameter in a POST request to the /cgi-bin/admin/setpm.cgi, /cgi-bin/admin/setmd.cgi, or /cgi-bin/admin/setmd_profile.cgi endpoint (all symlinks to the same binary). The parameter value is copied into a fixed-size 0xa4-byte stack buffer without bounds checking, overwriting the saved link register. The binary is compiled without stack canaries.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-35716"
    },
    {
      "rank": 62,
      "cve_id": "CVE-2026-45680",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00319,
      "epss_percentile": 0.24722,
      "kev": false,
      "kev_due_at": null,
      "vendor": "open-telemetry",
      "product": "opentelemetry-ebpf-instrumentation",
      "cwe": "CWE-400",
      "title": "OpenTelemetry eBPF Instrumentation: Unbounded BPF internal metrics replay can exhaust CPU",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45680"
    },
    {
      "rank": 63,
      "cve_id": "CVE-2026-7313",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00319,
      "epss_percentile": 0.24782,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Progress Software",
      "product": "Sitefinity",
      "cwe": "CWE-522",
      "title": "CWE‑522: Insufficiently Protected Credentials in web services in Progress Sitefinity",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7313"
    },
    {
      "rank": 64,
      "cve_id": "CVE-2026-41412",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00317,
      "epss_percentile": 0.24595,
      "kev": false,
      "kev_due_at": null,
      "vendor": "alfio-event",
      "product": "alf.io",
      "cwe": "CWE-22",
      "title": "alf.io vulnerable to Arbitrary File Read and Exfil via simpleHttpClient Extension Script",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41412"
    },
    {
      "rank": 65,
      "cve_id": "CVE-2026-10607",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00313,
      "epss_percentile": 0.24133,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "DedeCMS",
      "cwe": "CWE-74",
      "title": "DedeCMS flink.php dede_htmlspecialchars sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10607"
    },
    {
      "rank": 66,
      "cve_id": "CVE-2026-10692",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.0031,
      "epss_percentile": 0.23751,
      "kev": false,
      "kev_due_at": null,
      "vendor": "johnhuang316",
      "product": "code-index-mcp",
      "cwe": "CWE-400",
      "title": "johnhuang316 code-index-mcp search_code_advanced is_safe_regex_pattern redos",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10692"
    },
    {
      "rank": 67,
      "cve_id": "CVE-2026-39550",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00308,
      "epss_percentile": 0.23504,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Elated-Themes",
      "product": "Aperitif",
      "cwe": "CWE-502",
      "title": "WordPress Aperitif theme <= 1.6 - PHP Object Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39550"
    },
    {
      "rank": 68,
      "cve_id": "CVE-2026-39551",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00308,
      "epss_percentile": 0.23503,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Elated-Themes",
      "product": "Töbel",
      "cwe": "CWE-502",
      "title": "WordPress Töbel theme <= 1.8.1 - PHP Object Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39551"
    },
    {
      "rank": 69,
      "cve_id": "CVE-2026-5074",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00308,
      "epss_percentile": 0.23567,
      "kev": false,
      "kev_due_at": null,
      "vendor": "armember",
      "product": "ARMember Premium – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup",
      "cwe": "CWE-89",
      "title": "ARMember Premium <= 7.3.1 - Authenticated (Subscriber+) SQL Injection via 'sSortDir_0' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-5074"
    },
    {
      "rank": 70,
      "cve_id": "CVE-2026-10608",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00308,
      "epss_percentile": 0.23512,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "DedeCMS",
      "cwe": "CWE-74",
      "title": "DedeCMS carbuyaction.php RemoveXSS sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10608"
    },
    {
      "rank": 71,
      "cve_id": "CVE-2026-1871",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00305,
      "epss_percentile": 0.23208,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TP-Link Systems Inc.",
      "product": "Tapo C200 v5",
      "cwe": "CWE-121",
      "title": "Authenticated Stack-based Buffer Overflow in RTSP Authentication of Tapo C200",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-1871"
    },
    {
      "rank": 72,
      "cve_id": "CVE-2026-38978",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00305,
      "epss_percentile": 0.2322,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-113",
      "title": "transmission through 4.1.1 was found to have a clickjacking weakness in the browser-facing WebUI and RPC response paths.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-38978"
    },
    {
      "rank": 73,
      "cve_id": "CVE-2025-53345",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00302,
      "epss_percentile": 0.22896,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ThimPress",
      "product": "Thim Core",
      "cwe": "CWE-862",
      "title": "WordPress Thim Core plugin <= 2.3.3 - Arbitrary Plugin Installation vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-53345"
    },
    {
      "rank": 74,
      "cve_id": "CVE-2026-10701",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00301,
      "epss_percentile": 0.22776,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-119",
      "title": "Incorrect boundary conditions in the Graphics: Text component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10701"
    },
    {
      "rank": 75,
      "cve_id": "CVE-2026-49753",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00301,
      "epss_percentile": 0.2277,
      "kev": false,
      "kev_due_at": null,
      "vendor": "elixir-mint",
      "product": "mint",
      "cwe": "CWE-444",
      "title": "HTTP response smuggling in Mint HTTP/1 client via lenient Content-Length parsing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49753"
    },
    {
      "rank": 76,
      "cve_id": "CVE-2025-58024",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.003,
      "epss_percentile": 0.22662,
      "kev": false,
      "kev_due_at": null,
      "vendor": "UnboundStudio",
      "product": "Accordion FAQ",
      "cwe": "CWE-98",
      "title": "WordPress Accordion FAQ Plugin <= 2.2.1 - Local File Inclusion Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-58024"
    },
    {
      "rank": 77,
      "cve_id": "CVE-2026-49943",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.003,
      "epss_percentile": 0.22694,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NIC",
      "product": "BIRD",
      "cwe": "CWE-121",
      "title": "CZ.NIC BIRD Internet Routing Daemon through 2.19.0 contains a stack-based buffer overflow in the BGP AS_PATH mask matching implementation in nest/a-path.c. The as_path_match() function uses a fixed-size stack array of 2048 + 1 pm_pos entries, while parse_path() expands AS_PATH segments from a received BGP UPDATE without enforcing a corresponding capacity limit. When RFC 8654 BGP Extended Messages are enabled and a BIRD filter evaluates an AS path mask expression such as \"bgp_path ~ [= ... =]\", an established BGP peer can send a long AS_PATH containing more than 2048 expanded ASNs. This causes parse_path()/as_path_match() to write beyond the fixed stack buffer, resulting in a crash of the daemon. NOTE: reportedly, the Supplier's position is that a fix is not being prioritized because all network operators should already be rejecting routes with unusually long attributes.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49943"
    },
    {
      "rank": 78,
      "cve_id": "CVE-2026-42684",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00299,
      "epss_percentile": 0.2251,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ahmad",
      "product": "WP Job Portal",
      "cwe": "CWE-89",
      "title": "WordPress WP Job Portal plugin <= 2.5.1 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42684"
    },
    {
      "rank": 79,
      "cve_id": "CVE-2026-42342",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00299,
      "epss_percentile": 0.22573,
      "kev": false,
      "kev_due_at": null,
      "vendor": "remix-run",
      "product": "react-router",
      "cwe": "CWE-400",
      "title": "React Router vulnerable to DoS via unbounded path expansion in __manifest endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42342"
    },
    {
      "rank": 80,
      "cve_id": "CVE-2026-49443",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00298,
      "epss_percentile": 0.22496,
      "kev": false,
      "kev_due_at": null,
      "vendor": "goauthentik",
      "product": "authentik",
      "cwe": "CWE-287",
      "title": "authentik: `UserSourceConnection.user` and `GroupSourceConnection.group` are changeable through the API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49443"
    },
    {
      "rank": 81,
      "cve_id": "CVE-2026-34077",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00294,
      "epss_percentile": 0.22001,
      "kev": false,
      "kev_due_at": null,
      "vendor": "remix-run",
      "product": "react-router",
      "cwe": "CWE-770",
      "title": "React Router vulnerable to Denial of Service via reflected user input in single-fetch",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34077"
    },
    {
      "rank": 82,
      "cve_id": "CVE-2026-41115",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00288,
      "epss_percentile": 0.2132,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Kafka",
      "cwe": "CWE-285",
      "title": "Apache Kafka: Improper Authorization in CONSUMER_GROUP_DESCRIBE API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41115"
    },
    {
      "rank": 83,
      "cve_id": "CVE-2026-45681",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00287,
      "epss_percentile": 0.21267,
      "kev": false,
      "kev_due_at": null,
      "vendor": "open-telemetry",
      "product": "opentelemetry-ebpf-instrumentation",
      "cwe": "CWE-125",
      "title": "OpenTelemetry eBPF Instrumentation: CPU-mismatch fallback uses 256-byte buffer with 8KB size",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45681"
    },
    {
      "rank": 84,
      "cve_id": "CVE-2026-34907",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00285,
      "epss_percentile": 0.21033,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Simple SA",
      "product": "Wirtualna Uczelnia",
      "cwe": "CWE-79",
      "title": "Reflected Cross-Site Scripting (XSS) in Wirtualna Uczelnia",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34907"
    },
    {
      "rank": 85,
      "cve_id": "CVE-2024-14036",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00284,
      "epss_percentile": 0.21009,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dräger",
      "product": "Core",
      "cwe": "CWE-400",
      "title": "Dräger Core 1.0.5 Denial of Service via Malformed SDC Message",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-14036"
    },
    {
      "rank": 86,
      "cve_id": "CVE-2026-35482",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00282,
      "epss_percentile": 0.20759,
      "kev": false,
      "kev_due_at": null,
      "vendor": "alfio-event",
      "product": "alf.io",
      "cwe": "CWE-863",
      "title": "alf.io has an Authenticated RCE via Extension Script Sandbox Escape",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-35482"
    },
    {
      "rank": 87,
      "cve_id": "CVE-2026-44653",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00276,
      "epss_percentile": 0.20024,
      "kev": false,
      "kev_due_at": null,
      "vendor": "danny-avila",
      "product": "LibreChat",
      "cwe": "CWE-201",
      "title": "LibreChat Shared MCP Server View Leaks Decrypted Admin Secrets",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44653"
    },
    {
      "rank": 88,
      "cve_id": "CVE-2025-53209",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00275,
      "epss_percentile": 0.20011,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Themeisle",
      "product": "Masteriyo LMS PRO",
      "cwe": "CWE-266",
      "title": "WordPress Masteriyo LMS PRO plugin <= 2.20.0 - Privilege Escalation Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-53209"
    },
    {
      "rank": 89,
      "cve_id": "CVE-2026-48598",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00273,
      "epss_percentile": 0.19789,
      "kev": false,
      "kev_due_at": null,
      "vendor": "elixir-tesla",
      "product": "tesla",
      "cwe": "CWE-116",
      "title": "CRLF injection in Tesla.Multipart disposition parameters allows multipart part header injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48598"
    },
    {
      "rank": 90,
      "cve_id": "CVE-2026-40314",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00272,
      "epss_percentile": 0.19657,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NamelessMC",
      "product": "Nameless",
      "cwe": "CWE-862",
      "title": "NamelessMC: Reactions on private or blocking profile posts can be read and modified without proper authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40314"
    },
    {
      "rank": 91,
      "cve_id": "CVE-2026-10620",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00272,
      "epss_percentile": 0.19636,
      "kev": false,
      "kev_due_at": null,
      "vendor": "code-projects",
      "product": "Student Admission System",
      "cwe": "CWE-74",
      "title": "code-projects Student Admission System index.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10620"
    },
    {
      "rank": 92,
      "cve_id": "CVE-2026-40108",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00268,
      "epss_percentile": 0.19105,
      "kev": false,
      "kev_due_at": null,
      "vendor": "glpi-project",
      "product": "glpi",
      "cwe": "CWE-79",
      "title": "GLPI Vulnerable to Stored XSS in ITIL Costs",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40108"
    },
    {
      "rank": 93,
      "cve_id": "CVE-2026-10549",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00268,
      "epss_percentile": 0.19012,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Yandex",
      "product": "Yandex Database",
      "cwe": "CWE-280",
      "title": "Privilege escalation in Yandex Database",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10549"
    },
    {
      "rank": 94,
      "cve_id": "CVE-2026-40780",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00267,
      "epss_percentile": 0.18999,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Liquid Web / StellarWP",
      "product": "BookIt",
      "cwe": "CWE-288",
      "title": "WordPress BookIt plugin < 2.5.4.1 - Broken Authentication vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40780"
    },
    {
      "rank": 95,
      "cve_id": "CVE-2026-48682",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00267,
      "epss_percentile": 0.18917,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-125",
      "title": "FastNetMon Community Edition through 1.2.9 contains an out-of-bounds read in the IPv4 packet parser. In src/simple_packet_parser_ng.cpp, after validating that the packet contains at least sizeof(ipv4_header_t) bytes (20 bytes), the code advances the local_pointer by '4 * ipv4_header->get_ihl()' (line 164) without validating that (a) IHL >= 5 (the minimum valid value per RFC 791), or (b) 4 * IHL bytes are actually available in the packet. The IHL field is 4 bits, allowing values 0-15, so the advance can be 0-60 bytes. An IHL value of 15 with only 20 bytes validated causes a 40-byte over-read. An IHL of 0-4 causes the pointer to not advance past the IP header, resulting in the TCP/UDP header being parsed from IP header data (type confusion). This vulnerability is reachable via any packet capture interface.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48682"
    },
    {
      "rank": 96,
      "cve_id": "CVE-2026-44654",
      "cvss_base": 5.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00265,
      "epss_percentile": 0.18561,
      "kev": false,
      "kev_due_at": null,
      "vendor": "danny-avila",
      "product": "LibreChat",
      "cwe": "CWE-863",
      "title": "LibreChat: Shared-agent editor can globally delete owner's file records — breaks owner's other private agents",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44654"
    },
    {
      "rank": 97,
      "cve_id": "CVE-2026-35717",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00261,
      "epss_percentile": 0.18077,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-121",
      "title": "A stack-based buffer overflow in the export_language.cgi binary in VIVOTEK FD8136 firmware FD8136-VVTK-0300a allows authenticated remote attackers to execute arbitrary code as root via a crafted POST request to the /cgi-bin/admin/export_language.cgi endpoint. The handler passes the attacker-controlled Content-Length value directly to fread() as the read size into a fixed-size 0x60-byte stack buffer, overwriting the saved link register. The binary is compiled without stack canaries.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-35717"
    },
    {
      "rank": 98,
      "cve_id": "CVE-2026-3722",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00257,
      "epss_percentile": 0.17533,
      "kev": false,
      "kev_due_at": null,
      "vendor": "arunbasillal",
      "product": "Auto Image Attributes From Filename With Bulk Updater (Add Alt Text, Image Title For Image SEO)",
      "cwe": "CWE-79",
      "title": "Auto Image Attributes From Filename With Bulk Updater (Add Alt Text, Image Title For Image SEO) <= 4.9 - Authenticated (Author+) Stored Cross-Site Scripting via Image Attribute",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-3722"
    },
    {
      "rank": 99,
      "cve_id": "CVE-2026-39555",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00255,
      "epss_percentile": 0.17279,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Elated-Themes",
      "product": "Askka",
      "cwe": "CWE-502",
      "title": "WordPress Askka theme <= 1.3.1 - PHP Object Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39555"
    },
    {
      "rank": 100,
      "cve_id": "CVE-2026-45553",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00255,
      "epss_percentile": 0.1723,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zauberzeug",
      "product": "nicegui",
      "cwe": "CWE-200",
      "title": "NiceGUI: Local file disclosure via Docutils file insertion in ui.restructured_text()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45553"
    },
    {
      "rank": 101,
      "cve_id": "CVE-2026-10606",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00254,
      "epss_percentile": 0.17142,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "DedeCMS",
      "cwe": "CWE-74",
      "title": "DedeCMS Feedback feedback.php TrimMsg sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10606"
    },
    {
      "rank": 102,
      "cve_id": "CVE-2026-42670",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00252,
      "epss_percentile": 0.16957,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Etoile Web Design Incorporated",
      "product": "Five Star Restaurant Reservations",
      "cwe": "CWE-862",
      "title": "WordPress Five Star Restaurant Reservations plugin <= 2.7.14 - Payment Bypass vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42670"
    },
    {
      "rank": 103,
      "cve_id": "CVE-2026-45080",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00249,
      "epss_percentile": 0.16536,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Aiven-Open",
      "product": "klaw",
      "cwe": "CWE-200",
      "title": "Klaw: Improper Access Control Allows Disclosure of Password Hash",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45080"
    },
    {
      "rank": 104,
      "cve_id": "CVE-2026-10661",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00248,
      "epss_percentile": 0.16356,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ahujasid",
      "product": "blender-mcp",
      "cwe": "CWE-74",
      "title": "ahujasid blender-mcp server.py open injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10661"
    },
    {
      "rank": 105,
      "cve_id": "CVE-2026-3620",
      "cvss_base": 4.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00246,
      "epss_percentile": 0.16183,
      "kev": false,
      "kev_due_at": null,
      "vendor": "takien",
      "product": "Word Replacer",
      "cwe": "CWE-20",
      "title": "Word Replacer <= 0.4 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'Replacement' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-3620"
    },
    {
      "rank": 106,
      "cve_id": "CVE-2026-3198",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00244,
      "epss_percentile": 0.15856,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mlflow",
      "product": "mlflow/mlflow",
      "cwe": "CWE-284",
      "title": "Improper Access Control in mlflow/mlflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-3198"
    },
    {
      "rank": 107,
      "cve_id": "CVE-2026-4080",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00243,
      "epss_percentile": 0.15776,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zeshanb",
      "product": "Easy Cart",
      "cwe": "CWE-79",
      "title": "Easy Cart <= 1.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-4080"
    },
    {
      "rank": 108,
      "cve_id": "CVE-2026-10624",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00242,
      "epss_percentile": 0.15631,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "Human Resource Management",
      "cwe": "CWE-99",
      "title": "SourceCodester Human Resource Management Employee View detailview.php resource injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10624"
    },
    {
      "rank": 109,
      "cve_id": "CVE-2026-4081",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00241,
      "epss_percentile": 0.15521,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jhdscript",
      "product": "ZeM STL",
      "cwe": "CWE-79",
      "title": "ZeM STL <= 1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-4081"
    },
    {
      "rank": 110,
      "cve_id": "CVE-2021-4479",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00241,
      "epss_percentile": 0.15567,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dräger",
      "product": "Atlan A350",
      "cwe": "CWE-1286",
      "title": "Dräger Atlan A350 1.00 <= 1.01 DoS via Medibus Interface",
      "url": "https://www.cve.org/CVERecord?id=CVE-2021-4479"
    },
    {
      "rank": 111,
      "cve_id": "CVE-2026-9844",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00239,
      "epss_percentile": 0.15307,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Roche Diagnostics",
      "product": "navify Digital Pathology",
      "cwe": "CWE-1392",
      "title": "Vulnerability in navify® Digital Pathology",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9844"
    },
    {
      "rank": 112,
      "cve_id": "CVE-2026-10567",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": 0.00237,
      "epss_percentile": 0.15024,
      "kev": false,
      "kev_due_at": null,
      "vendor": "1Panel-dev",
      "product": "CordysCRM",
      "cwe": "CWE-79",
      "title": "1Panel-dev CordysCRM ModuleFormController ModuleFormService.java save cross site scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10567"
    },
    {
      "rank": 113,
      "cve_id": "CVE-2026-8293",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00236,
      "epss_percentile": 0.1487,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Really Simple Security",
      "cwe": "CWE-287",
      "title": "Really Simple Security < 9.5.10.1 - Authentication Bypass via Two-Factor OTP Skip",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8293"
    },
    {
      "rank": 114,
      "cve_id": "CVE-2019-25723",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00236,
      "epss_percentile": 0.14904,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dräger",
      "product": "Perseus A500",
      "cwe": "CWE-1286",
      "title": "Dräger Perseus A500 2.00-2.02 DoS via Medibus Interface",
      "url": "https://www.cve.org/CVERecord?id=CVE-2019-25723"
    },
    {
      "rank": 115,
      "cve_id": "CVE-2026-35447",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00236,
      "epss_percentile": 0.14834,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NamelessMC",
      "product": "Nameless",
      "cwe": "CWE-201",
      "title": "NamelessMC: Private or blocking profile pages can be bypassed with direct POST requests, and reply handling allows cross-profile writes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-35447"
    },
    {
      "rank": 116,
      "cve_id": "CVE-2026-44367",
      "cvss_base": 2.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00236,
      "epss_percentile": 0.1488,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Aiven-Open",
      "product": "klaw",
      "cwe": "CWE-20",
      "title": "Klaw: user lockout due to case sensitivity inconsistency",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44367"
    },
    {
      "rank": 117,
      "cve_id": "CVE-2026-35049",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00235,
      "epss_percentile": 0.14658,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wireapp",
      "product": "wire-ios",
      "cwe": "CWE-20",
      "title": "wire-ios has Persistent Remote DoS via Integer Underflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-35049"
    },
    {
      "rank": 118,
      "cve_id": "CVE-2026-35443",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00235,
      "epss_percentile": 0.14752,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NamelessMC",
      "product": "Nameless",
      "cwe": "CWE-862",
      "title": "NamelessMC: Forum reactions bypass the \"view own topics only\" restriction",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-35443"
    },
    {
      "rank": 119,
      "cve_id": "CVE-2026-40571",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00235,
      "epss_percentile": 0.14752,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NamelessMC",
      "product": "Nameless",
      "cwe": "CWE-862",
      "title": "NamelessMC: Reactions on private or blocking profile posts can be modified without proper authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40571"
    },
    {
      "rank": 120,
      "cve_id": "CVE-2026-49120",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00229,
      "epss_percentile": 0.1392,
      "kev": false,
      "kev_due_at": null,
      "vendor": "medplum",
      "product": "medplum",
      "cwe": "CWE-918",
      "title": "Medplum < 5.1.14 SSRF via FHIR Subscription Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49120"
    },
    {
      "rank": 121,
      "cve_id": "CVE-2026-10558",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00227,
      "epss_percentile": 0.1368,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "Pizzafy Ecommerce System",
      "cwe": "CWE-73",
      "title": "SourceCodester Pizzafy Ecommerce System index.php file inclusion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10558"
    },
    {
      "rank": 122,
      "cve_id": "CVE-2026-10559",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00227,
      "epss_percentile": 0.1368,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "Pizzafy Ecommerce System",
      "cwe": "CWE-73",
      "title": "SourceCodester Pizzafy Ecommerce System index.php file inclusion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10559"
    },
    {
      "rank": 123,
      "cve_id": "CVE-2026-10662",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00227,
      "epss_percentile": 0.13639,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ahujasid",
      "product": "blender-mcp",
      "cwe": "CWE-918",
      "title": "ahujasid blender-mcp ZIP File server.py requests.get server-side request forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10662"
    },
    {
      "rank": 124,
      "cve_id": "CVE-2026-10583",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": 0.00227,
      "epss_percentile": 0.13673,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nextlevelbuilder",
      "product": "GoClaw",
      "cwe": "CWE-918",
      "title": "nextlevelbuilder GoClaw TTS Configuration Endpoint tts_config.go import server-side request forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10583"
    },
    {
      "rank": 125,
      "cve_id": "CVE-2026-33398",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00225,
      "epss_percentile": 0.1348,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NamelessMC",
      "product": "Nameless",
      "cwe": "CWE-285",
      "title": "Authenticated users can read hidden forum posts through `/forum/get_quotes`",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-33398"
    },
    {
      "rank": 126,
      "cve_id": "CVE-2026-8993",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00225,
      "epss_percentile": 0.13492,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ditec a.s.",
      "product": "D.Launcher 2",
      "cwe": "CWE-74",
      "title": "Improper URL Handler Processing in D.Launcher 2 enables NTLM Credential Disclosure and SSRF attacks",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8993"
    },
    {
      "rank": 127,
      "cve_id": "CVE-2026-30586",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00224,
      "epss_percentile": 0.13348,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-79",
      "title": "Cross Site Scripting vulnerability in usememos Memos v.0.26.0 allows a remote attacker to obtain sensitive information via the SANITIZE_SCHEMA, Memo Rendering Component, and Public/Private Memo View pages",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-30586"
    },
    {
      "rank": 128,
      "cve_id": "CVE-2026-10565",
      "cvss_base": 1.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00224,
      "epss_percentile": 0.13332,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "Open5GS",
      "cwe": "CWE-362",
      "title": "Open5GS NGAP Handover gmm-sm.c gmm_state_security_mode race condition",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10565"
    },
    {
      "rank": 129,
      "cve_id": "CVE-2026-10690",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00221,
      "epss_percentile": 0.12974,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wonderwhy-er",
      "product": "DesktopCommanderMCP",
      "cwe": "CWE-918",
      "title": "wonderwhy-er DesktopCommanderMCP read_file filesystem.ts readFileFromUrl server-side request forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10690"
    },
    {
      "rank": 130,
      "cve_id": "CVE-2026-42073",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00219,
      "epss_percentile": 0.1262,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Gitlawb",
      "product": "openclaude",
      "cwe": "CWE-352",
      "title": "OpenClaude's MCP OAuth Callback: State Check Bypass via error Param Leads to DoS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42073"
    },
    {
      "rank": 131,
      "cve_id": "CVE-2026-45679",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00212,
      "epss_percentile": 0.11744,
      "kev": false,
      "kev_due_at": null,
      "vendor": "open-telemetry",
      "product": "opentelemetry-ebpf-instrumentation",
      "cwe": "CWE-117",
      "title": "OpenTelemetry eBPF Instrumentation: Redis error text is exported in span status messages",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45679"
    },
    {
      "rank": 132,
      "cve_id": "CVE-2026-35202",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00212,
      "epss_percentile": 0.11816,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pterodactyl",
      "product": "panel",
      "cwe": "CWE-367",
      "title": "Pterodactyl has a database resource limit bypass via race condition in Client API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-35202"
    },
    {
      "rank": 133,
      "cve_id": "CVE-2026-10529",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": 0.0021,
      "epss_percentile": 0.1152,
      "kev": false,
      "kev_due_at": null,
      "vendor": "westboy",
      "product": "CicadasCMS",
      "cwe": "CWE-79",
      "title": "westboy CicadasCMS Task Scheduling Management ScheduleJobController.java cross site scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10529"
    },
    {
      "rank": 134,
      "cve_id": "CVE-2026-49144",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00208,
      "epss_percentile": 0.11238,
      "kev": false,
      "kev_due_at": null,
      "vendor": "browserstack",
      "product": "browserstack-runner",
      "cwe": "CWE-22",
      "title": "BrowserStack Runner 0.9.5 Path Traversal via _default HTTP Handler",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49144"
    },
    {
      "rank": 135,
      "cve_id": "CVE-2026-1451",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00208,
      "epss_percentile": 0.11271,
      "kev": false,
      "kev_due_at": null,
      "vendor": "federicocarrara",
      "product": "rognone",
      "cwe": "CWE-79",
      "title": "rognone <= 0.6.2 - Reflected Cross-Site Scripting via 'a' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-1451"
    },
    {
      "rank": 136,
      "cve_id": "CVE-2026-2425",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00208,
      "epss_percentile": 0.11271,
      "kev": false,
      "kev_due_at": null,
      "vendor": "den-media",
      "product": "hiWeb Migration Simple",
      "cwe": "CWE-79",
      "title": "hiWeb Migration Simple <= 2.0.0.1 - Reflected Cross-Site Scripting via 'new_domain' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-2425"
    },
    {
      "rank": 137,
      "cve_id": "CVE-2026-7421",
      "cvss_base": 4.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00208,
      "epss_percentile": 0.113,
      "kev": false,
      "kev_due_at": null,
      "vendor": "passeum",
      "product": "Passeum Ticketing",
      "cwe": "CWE-79",
      "title": "Passeum Ticketing <= 1.0 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'shop_name' Setting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7421"
    },
    {
      "rank": 138,
      "cve_id": "CVE-2026-42654",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00207,
      "epss_percentile": 0.11125,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WP Swings",
      "product": "Wallet System for WooCommerce",
      "cwe": "CWE-288",
      "title": "WordPress Wallet System for WooCommerce plugin <= 2.7.5 - Broken Authentication vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42654"
    },
    {
      "rank": 139,
      "cve_id": "CVE-2026-31942",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00206,
      "epss_percentile": 0.1095,
      "kev": false,
      "kev_due_at": null,
      "vendor": "danny-avila",
      "product": "LibreChat",
      "cwe": "CWE-862",
      "title": "LibreChat has IDOR in API Keys Management that allows any authenticated user to overwrite other users' API keys",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-31942"
    },
    {
      "rank": 140,
      "cve_id": "CVE-2026-10616",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00206,
      "epss_percentile": 0.1098,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nextlevelbuilder",
      "product": "GoClaw",
      "cwe": "CWE-862",
      "title": "nextlevelbuilder GoClaw Team Task Completion team_tasks_lifecycle.go TeamTasksTool.executeComplete authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10616"
    },
    {
      "rank": 141,
      "cve_id": "CVE-2026-1450",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00204,
      "epss_percentile": 0.10713,
      "kev": false,
      "kev_due_at": null,
      "vendor": "federicocarrara",
      "product": "rognone",
      "cwe": "CWE-79",
      "title": "rognone <= 0.6.2 - Reflected Cross-Site Scripting via 'mode' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-1450"
    },
    {
      "rank": 142,
      "cve_id": "CVE-2019-25717",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00203,
      "epss_percentile": 0.10584,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dräger",
      "product": "Infinity Delta",
      "cwe": "CWE-538",
      "title": "Dräger Infinity Delta/Kappa Patient Monitors Unauthenticated Log File Disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2019-25717"
    },
    {
      "rank": 143,
      "cve_id": "CVE-2026-42669",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00202,
      "epss_percentile": 0.10449,
      "kev": false,
      "kev_due_at": null,
      "vendor": "EventPrime",
      "product": "EventPrime",
      "cwe": "CWE-862",
      "title": "WordPress EventPrime plugin <= 4.3.2.0 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42669"
    },
    {
      "rank": 144,
      "cve_id": "CVE-2025-5085",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00201,
      "epss_percentile": 0.10341,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ariyes",
      "product": "WP Nano AD",
      "cwe": "CWE-79",
      "title": "wp-nano-ad <= 1.31 - Authenticated (Administrator+) Stored Cross-Site Scripting via blogrole_link Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-5085"
    },
    {
      "rank": 145,
      "cve_id": "CVE-2026-10581",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00201,
      "epss_percentile": 0.10401,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "DedeCMS",
      "cwe": "CWE-918",
      "title": "DedeCMS download.php base64_decode server-side request forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10581"
    },
    {
      "rank": 146,
      "cve_id": "CVE-2026-10568",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.002,
      "epss_percentile": 0.10244,
      "kev": false,
      "kev_due_at": null,
      "vendor": "itsourcecode",
      "product": "Fees Management System",
      "cwe": "CWE-74",
      "title": "itsourcecode Fees Management System manage_payment.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10568"
    },
    {
      "rank": 147,
      "cve_id": "CVE-2026-49782",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00198,
      "epss_percentile": 0.09995,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Elementor",
      "product": "Elementor Website Builder",
      "cwe": "CWE-862",
      "title": "WordPress Elementor Website Builder plugin <= 4.1.0 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49782"
    },
    {
      "rank": 148,
      "cve_id": "CVE-2026-9234",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00198,
      "epss_percentile": 0.09963,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ntbyk",
      "product": "JTL-Connector for WooCommerce",
      "cwe": "CWE-862",
      "title": "JTL-Connector for WooCommerce <= 2.4.1 - Missing Authorization to Authenticated (Subscriber+) Settings Modification via Multiple Functions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9234"
    },
    {
      "rank": 149,
      "cve_id": "CVE-2026-1784",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00194,
      "epss_percentile": 0.09464,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat OpenShift Container Platform 4.13",
      "cwe": "CWE-15",
      "title": "Ose-cluster-ingress-operator: remote code execution through haproxy configuration injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-1784"
    },
    {
      "rank": 150,
      "cve_id": "CVE-2026-41918",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00194,
      "epss_percentile": 0.09443,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Siemens",
      "product": "RUGGEDCOM RST2428P",
      "cwe": "CWE-525",
      "title": "A vulnerability has been identified in RUGGEDCOM RST2428P (6GK6242-6PA00) (All versions < V4.0). The affected applications stores sensitive information in the browser cache when an authenticated user modify specific configurations. This could allow an authenticated attacker to access sensitive data stored in the browser.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41918"
    },
    {
      "rank": 151,
      "cve_id": "CVE-2019-25722",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00193,
      "epss_percentile": 0.0934,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dräger",
      "product": "SC 6002XL",
      "cwe": "CWE-798",
      "title": "Dräger SC Monitoring Devices Hard-coded Credentials and DoS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2019-25722"
    },
    {
      "rank": 152,
      "cve_id": "CVE-2026-2382",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00192,
      "epss_percentile": 0.09185,
      "kev": false,
      "kev_due_at": null,
      "vendor": "frankpw",
      "product": "FPW Category Thumbnails",
      "cwe": "CWE-79",
      "title": "FPW Category Thumbnails <= 1.9.5 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'id' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-2382"
    },
    {
      "rank": 153,
      "cve_id": "CVE-2026-41569",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0019,
      "epss_percentile": 0.09017,
      "kev": false,
      "kev_due_at": null,
      "vendor": "goauthentik",
      "product": "authentik",
      "cwe": "CWE-601",
      "title": "authentik: WS-Federation wreply origin bypass can exfiltrate signed login responses to attacker-controlled endpoints",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41569"
    },
    {
      "rank": 154,
      "cve_id": "CVE-2026-33245",
      "cvss_base": 4.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00188,
      "epss_percentile": 0.08825,
      "kev": false,
      "kev_due_at": null,
      "vendor": "remix-run",
      "product": "react-router",
      "cwe": "CWE-79",
      "title": "React Router vulnerable to XSS in unstable RSC redirect handling via javascript: redirect targets",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-33245"
    },
    {
      "rank": 155,
      "cve_id": "CVE-2019-25721",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00187,
      "epss_percentile": 0.08708,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dräger",
      "product": "Infinity M300",
      "cwe": "CWE-400",
      "title": "Dräger Infinity M300 VG2.3.1 Network-Based Denial of Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2019-25721"
    },
    {
      "rank": 156,
      "cve_id": "CVE-2025-53302",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00187,
      "epss_percentile": 0.08669,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Anton Shevchuk",
      "product": "Constructor",
      "cwe": "CWE-862",
      "title": "WordPress Constructor theme <= 1.6.5 - Broken Access Control Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-53302"
    },
    {
      "rank": 157,
      "cve_id": "CVE-2026-48596",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00187,
      "epss_percentile": 0.08594,
      "kev": false,
      "kev_due_at": null,
      "vendor": "elixir-tesla",
      "product": "tesla",
      "cwe": "CWE-113",
      "title": "CRLF injection in Tesla.Multipart.add_content_type_param/2 allows HTTP header injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48596"
    },
    {
      "rank": 158,
      "cve_id": "CVE-2026-32250",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00185,
      "epss_percentile": 0.08378,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NamelessMC",
      "product": "Nameless",
      "cwe": "CWE-79",
      "title": "NamelessMC has Reflected Cross-Site Scripting (XSS) in id parameter of /index.php?route=/queries/user/",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-32250"
    },
    {
      "rank": 159,
      "cve_id": "CVE-2026-9590",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00184,
      "epss_percentile": 0.08318,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Devolutions",
      "product": "Server",
      "cwe": "CWE-284",
      "title": "Improper access control in the permission validation component in Devolutions Server 2026.1.19 and earlier allows an authenticated user with entry edit privileges to modify asset information without the required permission.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9590"
    },
    {
      "rank": 160,
      "cve_id": "CVE-2026-10100",
      "cvss_base": 4.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00183,
      "epss_percentile": 0.08252,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pattihis",
      "product": "Simple Custom Login Page",
      "cwe": "CWE-79",
      "title": "Simple Custom Login Page <= 1.0.3 - Authenticated (Admin+) Stored Cross-Site Scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10100"
    },
    {
      "rank": 161,
      "cve_id": "CVE-2026-47201",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00182,
      "epss_percentile": 0.08069,
      "kev": false,
      "kev_due_at": null,
      "vendor": "goauthentik",
      "product": "authentik",
      "cwe": "CWE-347",
      "title": "authentik: XML Signature Wrapping in SAML Source ACS allows authentication as arbitrary federated user",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47201"
    },
    {
      "rank": 162,
      "cve_id": "CVE-2026-8885",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00181,
      "epss_percentile": 0.08048,
      "kev": false,
      "kev_due_at": null,
      "vendor": "marcqueralt",
      "product": "DeMomentSomTres Shortcodes",
      "cwe": "CWE-79",
      "title": "DeMomentSomTres Shortcodes <= 1.1.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8885"
    },
    {
      "rank": 163,
      "cve_id": "CVE-2026-34993",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00179,
      "epss_percentile": 0.07741,
      "kev": false,
      "kev_due_at": null,
      "vendor": "aio-libs",
      "product": "aiohttp",
      "cwe": "CWE-502",
      "title": "AIOHTTP Vulnerable to Deserialization of Untrusted Data",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34993"
    },
    {
      "rank": 164,
      "cve_id": "CVE-2026-25861",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00178,
      "epss_percentile": 0.07661,
      "kev": false,
      "kev_due_at": null,
      "vendor": "QloApps",
      "product": "QloApps",
      "cwe": "CWE-916",
      "title": "QloApps 1.7.0 Weak Password Hashing via MD5 in Tools.php",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-25861"
    },
    {
      "rank": 165,
      "cve_id": "CVE-2026-10688",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": 0.00178,
      "epss_percentile": 0.07617,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ahujasid",
      "product": "blender-mcp",
      "cwe": "CWE-74",
      "title": "ahujasid blender-mcp server.py execute_blender_code code injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10688"
    },
    {
      "rank": 166,
      "cve_id": "CVE-2019-25724",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00175,
      "epss_percentile": 0.0725,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dräger",
      "product": "Infinity M300",
      "cwe": "CWE-400",
      "title": "Dräger Infinity M300 VG2.x Network-Based Denial of Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2019-25724"
    },
    {
      "rank": 167,
      "cve_id": "CVE-2026-10629",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00174,
      "epss_percentile": 0.07214,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Verizon",
      "product": "VoLTE",
      "cwe": null,
      "title": "CVE-2026-10629",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10629"
    },
    {
      "rank": 168,
      "cve_id": "CVE-2025-52766",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00174,
      "epss_percentile": 0.07232,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Printeers",
      "product": "Printeers Print & Ship",
      "cwe": "CWE-862",
      "title": "WordPress Printeers Print & Ship plugin <= 1.17.0 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-52766"
    },
    {
      "rank": 169,
      "cve_id": "CVE-2026-45683",
      "cvss_base": 3.8,
      "cvss_severity": "LOW",
      "epss_score": 0.00174,
      "epss_percentile": 0.07213,
      "kev": false,
      "kev_due_at": null,
      "vendor": "open-telemetry",
      "product": "opentelemetry-ebpf-instrumentation",
      "cwe": "CWE-127",
      "title": "OpenTelemetry eBPF Instrumentation: Java TLS ioctl kprobe allows kernel memory disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45683"
    },
    {
      "rank": 170,
      "cve_id": "CVE-2026-45684",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00172,
      "epss_percentile": 0.06932,
      "kev": false,
      "kev_due_at": null,
      "vendor": "open-telemetry",
      "product": "opentelemetry-ebpf-instrumentation",
      "cwe": "CWE-126",
      "title": "OpenTelemetry eBPF Instrumentation: Log enricher writev path can overread and overwrite user buffers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45684"
    },
    {
      "rank": 171,
      "cve_id": "CVE-2026-24221",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0017,
      "epss_percentile": 0.06733,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "NVTabular",
      "cwe": "CWE-502",
      "title": "NVIDIA NVTabular contains a vulnerability where an attacker could cause improper deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering and information disclosure.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-24221"
    },
    {
      "rank": 172,
      "cve_id": "CVE-2026-24237",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0017,
      "epss_percentile": 0.06733,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "NVTabular",
      "cwe": "CWE-502",
      "title": "NVIDIA NVTabular contains a vulnerability where an attacker could cause improper deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-24237"
    },
    {
      "rank": 173,
      "cve_id": "CVE-2025-15653",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00169,
      "epss_percentile": 0.06715,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dräger",
      "product": "Zeus IE",
      "cwe": "CWE-668",
      "title": "Dräger Zeus IE Anesthesia Workstation USB Interface Privilege Escalation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-15653"
    },
    {
      "rank": 174,
      "cve_id": "CVE-2026-41577",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00169,
      "epss_percentile": 0.06708,
      "kev": false,
      "kev_due_at": null,
      "vendor": "goauthentik",
      "product": "authentik",
      "cwe": "CWE-345",
      "title": "authentik: SAML source does not validate Conditions, timing, or audience on assertions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41577"
    },
    {
      "rank": 175,
      "cve_id": "CVE-2026-3870",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00168,
      "epss_percentile": 0.06551,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Zyxel",
      "product": "VMG4005-B50B firmware",
      "cwe": "CWE-120",
      "title": "A buffer overflow vulnerability in the UPnP AddPortMapping() command in Zyxel VMG4005-B50B firmware versions through 5.13(ABRL.5.4)C0 could allow an adjacent attacker to trigger a temporary denial-of-service (DoS) condition affecting the UPnP function of the affected device.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-3870"
    },
    {
      "rank": 176,
      "cve_id": "CVE-2026-3871",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00168,
      "epss_percentile": 0.06551,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Zyxel",
      "product": "VMG4005-B50B firmware",
      "cwe": "CWE-120",
      "title": "A buffer overflow vulnerability in the UPnP DeletePortMapping() command in Zyxel VMG4005-B50B firmware versions through 5.13(ABRL.5.4)C0 could allow an adjacent attacker to trigger a temporary denial-of-service (DoS) condition affecting the UPnP function of the affected device.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-3871"
    },
    {
      "rank": 177,
      "cve_id": "CVE-2026-48861",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00167,
      "epss_percentile": 0.06422,
      "kev": false,
      "kev_due_at": null,
      "vendor": "elixir-mint",
      "product": "mint",
      "cwe": "CWE-93",
      "title": "CRLF injection in HTTP/1 request line via unvalidated method in Mint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48861"
    },
    {
      "rank": 178,
      "cve_id": "CVE-2026-33553",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00166,
      "epss_percentile": 0.06376,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-79",
      "title": "Northern.tech CFEngine Enterprise 3.24.3 before 3.24.4 and 3.27.0 before 3.27.1 allows XSS.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-33553"
    },
    {
      "rank": 179,
      "cve_id": "CVE-2026-27351",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00165,
      "epss_percentile": 0.06186,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Sekander Badsha",
      "product": "Crew HRM",
      "cwe": "CWE-862",
      "title": "WordPress Crew HRM plugin <= 1.2.2 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-27351"
    },
    {
      "rank": 180,
      "cve_id": "CVE-2026-40181",
      "cvss_base": 6.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00162,
      "epss_percentile": 0.05945,
      "kev": false,
      "kev_due_at": null,
      "vendor": "remix-run",
      "product": "react-router",
      "cwe": "CWE-601",
      "title": "React Router's same-origin redirect with path starting // causes open redirect via protocol-relative URL reinterpretation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40181"
    },
    {
      "rank": 181,
      "cve_id": "CVE-2026-45676",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00162,
      "epss_percentile": 0.05895,
      "kev": false,
      "kev_due_at": null,
      "vendor": "open-telemetry",
      "product": "opentelemetry-ebpf-instrumentation",
      "cwe": "CWE-20",
      "title": "OpenTelemetry eBPF Instrumentation: Unsafe fastelf parsing allows malformed ELF to crash agent",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45676"
    },
    {
      "rank": 182,
      "cve_id": "CVE-2026-45682",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00162,
      "epss_percentile": 0.0586,
      "kev": false,
      "kev_due_at": null,
      "vendor": "open-telemetry",
      "product": "opentelemetry-ebpf-instrumentation",
      "cwe": "CWE-401",
      "title": "OpenTelemetry eBPF Instrumentation: CappedConcurrentHashMap leaks keys after removals",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45682"
    },
    {
      "rank": 183,
      "cve_id": "CVE-2022-4992",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0016,
      "epss_percentile": 0.05737,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dräger",
      "product": "Infinity Acute Care System",
      "cwe": "CWE-345",
      "title": "Dräger Infinity M540 VG4.1.1 Spoofed Network Message Handling DoS/Tampering",
      "url": "https://www.cve.org/CVERecord?id=CVE-2022-4992"
    },
    {
      "rank": 184,
      "cve_id": "CVE-2026-10510",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00155,
      "epss_percentile": 0.05162,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TECNO Mobile",
      "product": "com.transsion.aiassistantlifestyle",
      "cwe": "CWE-79",
      "title": "GeniexWebView XSS in com.transsion.aiassistantlifestyle",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10510"
    },
    {
      "rank": 185,
      "cve_id": "CVE-2026-40713",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00152,
      "epss_percentile": 0.04869,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "ThinOS 10",
      "cwe": "CWE-284",
      "title": "Dell ThinOS 10, versions prior to ThinOS10 2602_10.0765, contain an Improper Access control vulnerability. An unauthenticated attacker with physical access could potentially exploit this vulnerability, leading to Information exposure.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40713"
    },
    {
      "rank": 186,
      "cve_id": "CVE-2026-43965",
      "cvss_base": 5.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00152,
      "epss_percentile": 0.04853,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Gleam",
      "product": "Gleam",
      "cwe": "CWE-22",
      "title": "Path Traversal in build/packages/packages.toml Allows Arbitrary Directory Deletion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43965"
    },
    {
      "rank": 187,
      "cve_id": "CVE-2026-32685",
      "cvss_base": 4.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00152,
      "epss_percentile": 0.04853,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Gleam",
      "product": "Gleam",
      "cwe": "CWE-22",
      "title": "Path Traversal in gleam docs build via documentation.pages Allows Arbitrary File Read and Write",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-32685"
    },
    {
      "rank": 188,
      "cve_id": "CVE-2025-53346",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00152,
      "epss_percentile": 0.04902,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ThimPress",
      "product": "Thim Core",
      "cwe": "CWE-862",
      "title": "WordPress Thim Core Plugin <= 2.3.3 - Broken Access Control Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-53346"
    },
    {
      "rank": 189,
      "cve_id": "CVE-2024-42206",
      "cvss_base": 3.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00151,
      "epss_percentile": 0.0484,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HCL",
      "product": "iReflection",
      "cwe": "CWE-1395",
      "title": "HCL iReflection Use of Third party vulnerable and outdated components issue was detected in the web application.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-42206"
    },
    {
      "rank": 190,
      "cve_id": "CVE-2026-47265",
      "cvss_base": 6.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0015,
      "epss_percentile": 0.04738,
      "kev": false,
      "kev_due_at": null,
      "vendor": "aio-libs",
      "product": "aiohttp",
      "cwe": "CWE-346",
      "title": "AIOHTTP vulnerable to cross-origin redirect with per-request cookies",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47265"
    },
    {
      "rank": 191,
      "cve_id": "CVE-2026-35212",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00149,
      "epss_percentile": 0.04615,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenCTI-Platform",
      "product": "opencti",
      "cwe": "CWE-79",
      "title": "OpenCTI has XSS in the rendering of email-message observable body data",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-35212"
    },
    {
      "rank": 192,
      "cve_id": "CVE-2025-52759",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00146,
      "epss_percentile": 0.04387,
      "kev": false,
      "kev_due_at": null,
      "vendor": "UnboundStudio",
      "product": "Accordion FAQ",
      "cwe": "CWE-79",
      "title": "WordPress Accordion FAQ plugin <= 2.2.1 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-52759"
    },
    {
      "rank": 193,
      "cve_id": "CVE-2026-42685",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00146,
      "epss_percentile": 0.04423,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ahmad",
      "product": "WP Job Portal",
      "cwe": "CWE-79",
      "title": "WordPress WP Job Portal plugin <= 2.5.1 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42685"
    },
    {
      "rank": 194,
      "cve_id": "CVE-2026-33244",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00144,
      "epss_percentile": 0.04227,
      "kev": false,
      "kev_due_at": null,
      "vendor": "remix-run",
      "product": "react-router",
      "cwe": "CWE-79",
      "title": "React Router has stored XSS via unescaped Location header in prerendered redirect HTML",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-33244"
    },
    {
      "rank": 195,
      "cve_id": "CVE-2026-45289",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0014,
      "epss_percentile": 0.03846,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CloudburstMC",
      "product": "Protocol",
      "cwe": "CWE-287",
      "title": "CloudburstMC Protocol: Partially missing validation for FULL type authentication tokens",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45289"
    },
    {
      "rank": 196,
      "cve_id": "CVE-2026-10548",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": 0.0014,
      "epss_percentile": 0.03807,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NousResearch",
      "product": "hermes-agent",
      "cwe": "CWE-287",
      "title": "NousResearch hermes-agent Credential Pool Synchronization credential_pool.py _sync_anthropic_entry_from_credentials_file improper authentication",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10548"
    },
    {
      "rank": 197,
      "cve_id": "CVE-2026-9522",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00138,
      "epss_percentile": 0.03652,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Devolutions",
      "product": "Server",
      "cwe": "CWE-284",
      "title": "Improper access control in the PAM account discovery feature in Devolutions Server 2026.1.19 and earlier allows an authenticated user without administrative privileges to delete network discovery scan configurations.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9522"
    },
    {
      "rank": 198,
      "cve_id": "CVE-2026-28116",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00136,
      "epss_percentile": 0.03481,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Emilia Projects",
      "product": "Progress Planner",
      "cwe": "CWE-79",
      "title": "WordPress Progress Planner plugin <= 1.9.0 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28116"
    },
    {
      "rank": 199,
      "cve_id": "CVE-2026-5191",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00134,
      "epss_percentile": 0.03379,
      "kev": false,
      "kev_due_at": null,
      "vendor": "raja3c",
      "product": "Tiled Gallery Carousel Without JetPack",
      "cwe": "CWE-79",
      "title": "Tiled Gallery Carousel Without JetPack <= 3.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'data-image-title'",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-5191"
    },
    {
      "rank": 200,
      "cve_id": "CVE-2019-25719",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00132,
      "epss_percentile": 0.03203,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dräger",
      "product": "Infinity Acute Care System",
      "cwe": "CWE-924",
      "title": "Dräger Infinity M540 VG4.1.1 Spoofing and DoS via Network Message Handling",
      "url": "https://www.cve.org/CVERecord?id=CVE-2019-25719"
    },
    {
      "rank": 201,
      "cve_id": "CVE-2026-42795",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00132,
      "epss_percentile": 0.03218,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Gleam",
      "product": "Gleam",
      "cwe": "CWE-59",
      "title": "Symlink Following in Hex Package Export Allows Embedding Files Outside Project Root",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42795"
    },
    {
      "rank": 202,
      "cve_id": "CVE-2026-8422",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00132,
      "epss_percentile": 0.03219,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mr_mat",
      "product": "Remove meta boxes per user role",
      "cwe": "CWE-352",
      "title": "Remove meta boxes per user role <= 1.01 - Cross-Site Request Forgery to Settings Update",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8422"
    },
    {
      "rank": 203,
      "cve_id": "CVE-2026-4071",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00131,
      "epss_percentile": 0.03122,
      "kev": false,
      "kev_due_at": null,
      "vendor": "birdseedapp",
      "product": "BirdSeed",
      "cwe": "CWE-352",
      "title": "BirdSeed <= 2.2.0 - Cross-Site Request Forgery via BirdSeed Token Change",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-4071"
    },
    {
      "rank": 204,
      "cve_id": "CVE-2026-9722",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00131,
      "epss_percentile": 0.03121,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pcis",
      "product": "Laiser Tag",
      "cwe": "CWE-352",
      "title": "Laiser Tag <= 1.2.5 - Cross-Site Request Forgery to Plugin Settings Update via Settings Form",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9722"
    },
    {
      "rank": 205,
      "cve_id": "CVE-2026-9730",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00131,
      "epss_percentile": 0.03121,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jamesmuga",
      "product": "Remove NoFollow Commenter URL",
      "cwe": "CWE-352",
      "title": "Remove NoFollow Commenter URL <= 1.0 - Cross-Site Request Forgery to Settings Update",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9730"
    },
    {
      "rank": 206,
      "cve_id": "CVE-2026-9599",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00128,
      "epss_percentile": 0.02897,
      "kev": false,
      "kev_due_at": null,
      "vendor": "russellr",
      "product": "Tectite Forms",
      "cwe": "CWE-352",
      "title": "Tectite Forms <= 1.3 - Cross-Site Request Forgery to Settings Update",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9599"
    },
    {
      "rank": 207,
      "cve_id": "CVE-2026-9723",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00128,
      "epss_percentile": 0.02895,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ddd2500",
      "product": "Google Plus One Bottom",
      "cwe": "CWE-352",
      "title": "Google Plus One Bottom <= 0.0.2 - Cross-Site Request Forgery to Plugin Settings Update via Settings Page",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9723"
    },
    {
      "rank": 208,
      "cve_id": "CVE-2026-9732",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00128,
      "epss_percentile": 0.02897,
      "kev": false,
      "kev_due_at": null,
      "vendor": "planetshaker",
      "product": "EmergencyWP – Dead Man's switch & legacy deliverance",
      "cwe": "CWE-352",
      "title": "EmergencyWP <= 1.4.2 - Cross-Site Request Forgery to Plugin Settings Update",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9732"
    },
    {
      "rank": 209,
      "cve_id": "CVE-2026-10528",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00124,
      "epss_percentile": 0.02556,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Orthanc",
      "product": "DICOM Server",
      "cwe": "CWE-119",
      "title": "Orthanc DICOM Server DCMTK FromDcmtkBridge.cpp read stack-based overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10528"
    },
    {
      "rank": 210,
      "cve_id": "CVE-2021-4478",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00122,
      "epss_percentile": 0.02328,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dräger",
      "product": "CC-Vision Basic",
      "cwe": "CWE-787",
      "title": "Dräger CC-Vision Basic and CC-Vision E-Cal Out-of-Bounds Write via Malicious GDT File",
      "url": "https://www.cve.org/CVERecord?id=CVE-2021-4478"
    },
    {
      "rank": 211,
      "cve_id": "CVE-2026-10566",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00122,
      "epss_percentile": 0.02336,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FoundationAgents",
      "product": "MetaGPT",
      "cwe": "CWE-20",
      "title": "FoundationAgents MetaGPT schema.py Message.check_instruct_content deserialization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10566"
    },
    {
      "rank": 212,
      "cve_id": "CVE-2026-10046",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00118,
      "epss_percentile": 0.02007,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Bitdefender",
      "product": "Napoca bare-metal hypervisor",
      "cwe": "CWE-787",
      "title": "Out-of-bounds write in Napoca BIOS INT 0x15 E820 memory map handler (VA-13905)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10046"
    },
    {
      "rank": 213,
      "cve_id": "CVE-2026-10047",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00118,
      "epss_percentile": 0.01993,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Bitdefender",
      "product": "Napoca bare-metal hypervisor",
      "cwe": "CWE-787",
      "title": "Out-of-bounds write in Napoca real-mode hook handler via guest-controlled SS:SP (VA-13905)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10047"
    },
    {
      "rank": 214,
      "cve_id": "CVE-2026-8936",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00115,
      "epss_percentile": 0.01841,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Docker",
      "product": "Docker Desktop",
      "cwe": "CWE-674",
      "title": "Unbounded recursion in grpcfuse kernel module allows container to crash Docker Desktop VM",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8936"
    },
    {
      "rank": 215,
      "cve_id": "CVE-2026-40619",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00115,
      "epss_percentile": 0.01801,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Genetec Inc.",
      "product": "Genetec Security Center",
      "cwe": "CWE-532",
      "title": "A high security vulnerability affecting Security Center main server installations has been identified. It could allow an attacker with local OS privileges to the main server to access the Server Admin credentials. A third party hired by Genetec found the issue. There is currently no evidence of active exploitation. This vulnerability is associated with specific installation package builds rather than the product version identifier alone. Certain versions (including 5.10.4.0, 5.11.3.0, 5.12.2.0 and 5.13.3.0) were released with both vulnerable and remediated installation packages under the same version number. Consequently, version-based comparison alone is insufficient to determine exposure. Only installations performed using vulnerable builds are affected. Remediated builds can be distinguished using verified installation package hashes. For the complete list of fixed build hashes, refer to the security advisory section.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40619"
    },
    {
      "rank": 216,
      "cve_id": "CVE-2026-34460",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00114,
      "epss_percentile": 0.01695,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NamelessMC",
      "product": "Nameless",
      "cwe": "CWE-302",
      "title": "NamelessMC: OAuth callback `state` is not validated, allowing login CSRF / session swapping",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34460"
    },
    {
      "rank": 217,
      "cve_id": "CVE-2026-10718",
      "cvss_base": 4.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00114,
      "epss_percentile": 0.0171,
      "kev": false,
      "kev_due_at": null,
      "vendor": null,
      "product": "openSeaChest",
      "cwe": "CWE-787",
      "title": "Open Seachest/Seachest NVMe Trim (Deallocate) Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10718"
    },
    {
      "rank": 218,
      "cve_id": "CVE-2026-8036",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00107,
      "epss_percentile": 0.01299,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NI",
      "product": "NI-PAL",
      "cwe": "CWE-1285",
      "title": "Local privilege escalation in NI-PAL",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8036"
    },
    {
      "rank": 219,
      "cve_id": "CVE-2021-4480",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00107,
      "epss_percentile": 0.01309,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dräger",
      "product": "Protector Software",
      "cwe": "CWE-732",
      "title": "Dräger Protector Software Local Privilege Escalation via Insecure File Permissions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2021-4480"
    },
    {
      "rank": 220,
      "cve_id": "CVE-2021-4481",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00107,
      "epss_percentile": 0.0131,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dräger",
      "product": "Protector Software",
      "cwe": "CWE-732",
      "title": "Dräger Protector Software Local Privilege Escalation via Insecure File Permissions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2021-4481"
    },
    {
      "rank": 221,
      "cve_id": "CVE-2026-10717",
      "cvss_base": 1.8,
      "cvss_severity": "LOW",
      "epss_score": 0.00102,
      "epss_percentile": 0.01096,
      "kev": false,
      "kev_due_at": null,
      "vendor": null,
      "product": "openSeaChest",
      "cwe": "CWE-787",
      "title": "Open-Seachest/Seachest show SCSI Defect List Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10717"
    },
    {
      "rank": 222,
      "cve_id": "CVE-2026-10719",
      "cvss_base": 1.8,
      "cvss_severity": "LOW",
      "epss_score": 0.00102,
      "epss_percentile": 0.01096,
      "kev": false,
      "kev_due_at": null,
      "vendor": null,
      "product": "openSeaChest",
      "cwe": "CWE-787",
      "title": "Open Seachest/Seachest NVMe show Format Descriptors Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10719"
    },
    {
      "rank": 223,
      "cve_id": "CVE-2026-10584",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00101,
      "epss_percentile": 0.01046,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AWS",
      "product": "Graph Explorer",
      "cwe": "CWE-319",
      "title": "HTTPS Fallback to HTTP in Graph Explorer",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10584"
    },
    {
      "rank": 224,
      "cve_id": "CVE-2026-40715",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.001,
      "epss_percentile": 0.00976,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "ThinOS 10",
      "cwe": "CWE-284",
      "title": "Dell ThinOS 10, versions prior to ThinOS10 2602_10.0765, contain an Improper Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Privilege Escalation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40715"
    },
    {
      "rank": 225,
      "cve_id": "CVE-2026-8035",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00096,
      "epss_percentile": 0.00789,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NI",
      "product": "NI-PAL",
      "cwe": "CWE-476",
      "title": "NULL pointer dereference in NI-PAL",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8035"
    },
    {
      "rank": 226,
      "cve_id": "CVE-2025-64390",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00085,
      "epss_percentile": 0.00374,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Sony",
      "product": "PS4",
      "cwe": "CWE-367",
      "title": "A privilege escalation vulnerability exists in PlayStation 4 firmware versions 13.00 through 13.02. The BD-J (Blu-ray Disc Java) sandbox can be escaped through a malformed JAR file.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-64390"
    }
  ],
  "transactions": [
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-3198",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-3198 (mlflow/mlflow). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-32625",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-32625 (danny-avila LibreChat). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-3514",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-3514 (prefecthq/prefect). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-35482",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-35482 (alfio-event alf.io). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-42073",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-42073 (Gitlawb openclaude). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-42074",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-42074 (Gitlawb openclaude). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-44653",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-44653 (danny-avila LibreChat). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-44654",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-44654 (danny-avila LibreChat). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-45676",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-45676 (open-telemetry opentelemetry-ebpf-instrumentation). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-45678",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-45678 (open-telemetry opentelemetry-ebpf-instrumentation). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-45679",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-45679 (open-telemetry opentelemetry-ebpf-instrumentation). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-45680",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-45680 (open-telemetry opentelemetry-ebpf-instrumentation). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-45681",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-45681 (open-telemetry opentelemetry-ebpf-instrumentation). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-45682",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-45682 (open-telemetry opentelemetry-ebpf-instrumentation). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-45683",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-45683 (open-telemetry opentelemetry-ebpf-instrumentation). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-45684",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-45684 (open-telemetry opentelemetry-ebpf-instrumentation). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-45685",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-45685 (open-telemetry opentelemetry-ebpf-instrumentation). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-45686",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-45686 (open-telemetry opentelemetry-ebpf-instrumentation). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-48594",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-48594 (elixir-tesla tesla). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-48595",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-48595 (elixir-tesla tesla). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-48596",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-48596 (elixir-tesla tesla). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-49443",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-49443 (goauthentik authentik). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-49448",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-49448 (goauthentik authentik). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-5422",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-5422 (jupyter/jupyter). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-7299",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-7299 (Appsmith). Public exploit reference added."
    },
    {
      "type": "DUE_DATE_PASSED",
      "cve_id": "CVE-2026-0257",
      "detail": "DUE DATE PASSED — CVE-2026-0257 (Palo Alto Networks PAN-OS). CISA remediation deadline was June 1, 2026; still in catalog."
    }
  ],
  "attribution": "CVE Program, NVD (NIST), CISA KEV, FIRST EPSS, OSV. See /security/methodology/."
}
