{
  "day": "2026-06-03",
  "boundary": "UTC calendar day",
  "published_count": 151,
  "by_severity": {
    "CRITICAL": 8,
    "HIGH": 68,
    "MEDIUM": 61,
    "LOW": 14
  },
  "kev_count": 1,
  "exploit_reference_count": 13,
  "awaiting_enrichment_count": 0,
  "ranking": "Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.",
  "results": [
    {
      "rank": 1,
      "cve_id": "CVE-2026-45247",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.27546,
      "epss_percentile": 0.97916,
      "kev": true,
      "kev_due_at": "2026-06-06",
      "vendor": "Mirasvit",
      "product": "Full Page Cache Warmer for Magento 2",
      "cwe": "CWE-502",
      "title": "Mirasvit Cache Warmer for Magento < 1.11.12 PHP Object Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45247"
    },
    {
      "rank": 2,
      "cve_id": "CVE-2026-36576",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.01491,
      "epss_percentile": 0.72034,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-78",
      "title": "An OS command injection vulnerability in the app.py component of openlabs docker-wkhtmltopdf-aas up to commit 9f50579 allows attackers to execute arbitrary commands via a crafted POST request.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-36576"
    },
    {
      "rank": 3,
      "cve_id": "CVE-2026-5241",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00547,
      "epss_percentile": 0.4349,
      "kev": false,
      "kev_due_at": null,
      "vendor": "huggingface",
      "product": "huggingface/transformers",
      "cwe": "CWE-829",
      "title": "Policy Bypass in LightGlue Nested Config Resolution in huggingface/transformers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-5241"
    },
    {
      "rank": 4,
      "cve_id": "CVE-2026-47065",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.005,
      "epss_percentile": 0.40761,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache MINA",
      "cwe": "CWE-502",
      "title": "Apache MINA: Critical Deserialization Allow-list Bypass via resolveProxyClass - ZDRES-232",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47065"
    },
    {
      "rank": 5,
      "cve_id": "CVE-2026-35082",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00494,
      "epss_percentile": 0.40424,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MBS",
      "product": "Single-A",
      "cwe": "CWE-22",
      "title": "Local file inclusion vulnerability and deletion in ugw-logread method",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-35082"
    },
    {
      "rank": 6,
      "cve_id": "CVE-2026-3276",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00486,
      "epss_percentile": 0.39912,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Python Software Foundation",
      "product": "CPython",
      "cwe": "CWE-407",
      "title": "Potential DoS via quadratic complexity in unicodedata.normalize()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-3276"
    },
    {
      "rank": 7,
      "cve_id": "CVE-2026-35075",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00466,
      "epss_percentile": 0.38651,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MBS",
      "product": "Single-A",
      "cwe": "CWE-1393",
      "title": "Hardcoded default Password for Service Account",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-35075"
    },
    {
      "rank": 8,
      "cve_id": "CVE-2026-35085",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00466,
      "epss_percentile": 0.38594,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MBS",
      "product": "Single-A",
      "cwe": "CWE-121",
      "title": "Stack buffer overflow in method gdv-serverconfig",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-35085"
    },
    {
      "rank": 9,
      "cve_id": "CVE-2026-35083",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00456,
      "epss_percentile": 0.38,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MBS",
      "product": "Single-A",
      "cwe": "CWE-121",
      "title": "Stack buffer overflow in method bac-deviceobject",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-35083"
    },
    {
      "rank": 10,
      "cve_id": "CVE-2026-35084",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00456,
      "epss_percentile": 0.38,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MBS",
      "product": "Single-A",
      "cwe": "CWE-121",
      "title": "Stack buffer overflow in method dali-devconfig",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-35084"
    },
    {
      "rank": 11,
      "cve_id": "CVE-2026-4035",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00435,
      "epss_percentile": 0.36468,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mlflow",
      "product": "mlflow/mlflow",
      "cwe": "CWE-201",
      "title": "Environment Variable Resolution Vulnerability in mlflow/mlflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-4035"
    },
    {
      "rank": 12,
      "cve_id": "CVE-2026-8888",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00432,
      "epss_percentile": 0.36149,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Securly",
      "product": "Securly Chrome Extension",
      "cwe": "CWE-917",
      "title": "CVE-2026-8888",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8888"
    },
    {
      "rank": 13,
      "cve_id": "CVE-2026-10777",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00405,
      "epss_percentile": 0.33933,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ealpha072",
      "product": "Student-Management-System",
      "cwe": "CWE-287",
      "title": "ealpha072 Student-Management-System Administrative Backend config.php improper authentication",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10777"
    },
    {
      "rank": 14,
      "cve_id": "CVE-2026-50052",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00397,
      "epss_percentile": 0.33037,
      "kev": false,
      "kev_due_at": null,
      "vendor": "The Vinyl Cache Project",
      "product": "Vinyl Cache",
      "cwe": "CWE-444",
      "title": "In Vinyl Cache before 9.0.1 and Varnish Cache before 9.0.3, a deficiency in HTTP/2 request parsing can be exploited to launch a backend request desync attack (request smuggling), which in turn can be used for cache poisoning, authentication bypass, or possibly even information disclosure and manipulation. The attack vector only exists if HTTP/2 support is enabled by setting the feature parameter to contain +http2. HTTP/2 support is disabled by default.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50052"
    },
    {
      "rank": 15,
      "cve_id": "CVE-2026-50031",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0039,
      "epss_percentile": 0.3231,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FreeIPMI",
      "product": "FreeIPMI",
      "cwe": "CWE-121",
      "title": "ipmi-oem in FreeIPMI before 1.6.18 has exploitable buffer overflows on response messages. The Intelligent Platform Management Interface (IPMI) specification defines a set of interfaces for platform management. It is implemented by a large number of hardware manufacturers to support system management. It is most commonly used for sensor reading (e.g., CPU temperatures through the ipmi-sensors command within FreeIPMI) and remote power control (the ipmipower command). The ipmi-oem client command implements a set of a IPMI OEM commands for specific hardware vendors. If a user has supported hardware, they may wish to use the ipmi-oem command to send a request to a server to retrieve specific information. Two subcommands \"ipmi-oem dell get-active-directory-config\" and \"ipmi-oem fujitsu get-sel-entry-long-text\" were found to have exploitable buffer overflows on response messages.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50031"
    },
    {
      "rank": 16,
      "cve_id": "CVE-2026-46273",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00389,
      "epss_percentile": 0.32213,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-400",
      "title": "ibmveth: Disable GSO for packets with small MSS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46273"
    },
    {
      "rank": 17,
      "cve_id": "CVE-2026-8879",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00374,
      "epss_percentile": 0.30651,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Securly",
      "product": "Securly Chrome Extension",
      "cwe": "CWE-829",
      "title": "CVE-2026-8879",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8879"
    },
    {
      "rank": 18,
      "cve_id": "CVE-2026-46265",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00371,
      "epss_percentile": 0.30407,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "RDMA/hns: Fix WQ_MEM_RECLAIM warning",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46265"
    },
    {
      "rank": 19,
      "cve_id": "CVE-2026-35076",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.0037,
      "epss_percentile": 0.30283,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MBS",
      "product": "Single-A",
      "cwe": "CWE-73",
      "title": "Arbitrary file delete vulnerability in method bac-scanresult",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-35076"
    },
    {
      "rank": 20,
      "cve_id": "CVE-2026-35077",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.0037,
      "epss_percentile": 0.30283,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MBS",
      "product": "Single-A",
      "cwe": "CWE-73",
      "title": "Arbitrary file delete vulnerability in method ugw-delete-file",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-35077"
    },
    {
      "rank": 21,
      "cve_id": "CVE-2026-35078",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.0037,
      "epss_percentile": 0.30282,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MBS",
      "product": "Single-A",
      "cwe": "CWE-73",
      "title": "Arbitrary file delete vulnerability in method ugw-logstop",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-35078"
    },
    {
      "rank": 22,
      "cve_id": "CVE-2026-35079",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.0037,
      "epss_percentile": 0.30282,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MBS",
      "product": "Single-A",
      "cwe": "CWE-73",
      "title": "Arbitrary file delete vulnerability in method ugw-restore",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-35079"
    },
    {
      "rank": 23,
      "cve_id": "CVE-2026-35080",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.0037,
      "epss_percentile": 0.30282,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MBS",
      "product": "Single-A",
      "cwe": "CWE-73",
      "title": "Arbitrary file delete vulnerability in method ugw-restoreinfo",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-35080"
    },
    {
      "rank": 24,
      "cve_id": "CVE-2026-35081",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.0037,
      "epss_percentile": 0.30283,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MBS",
      "product": "Single-A",
      "cwe": "CWE-20",
      "title": "Arbitrary process termination vulnerability in method ugw-logstop",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-35081"
    },
    {
      "rank": 25,
      "cve_id": "CVE-2026-9516",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00361,
      "epss_percentile": 0.29296,
      "kev": false,
      "kev_due_at": null,
      "vendor": "RURBAN",
      "product": "Cpanel::JSON::XS",
      "cwe": "CWE-755",
      "title": "Cpanel::JSON::XS versions before 4.41 for Perl allow denial of service via UTF-8 BOM prefixed input when a decode filter callback throws",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9516"
    },
    {
      "rank": 26,
      "cve_id": "CVE-2026-35193",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00359,
      "epss_percentile": 0.29112,
      "kev": false,
      "kev_due_at": null,
      "vendor": "djangoproject",
      "product": "Django",
      "cwe": "CWE-524",
      "title": "Potential exposure of private data via missing Vary: Authorization in UpdateCacheMiddleware",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-35193"
    },
    {
      "rank": 27,
      "cve_id": "CVE-2026-48587",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00354,
      "epss_percentile": 0.28593,
      "kev": false,
      "kev_due_at": null,
      "vendor": "djangoproject",
      "product": "Django",
      "cwe": "CWE-1023",
      "title": "Potential exposure of private data via whitespace padding in Vary header",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48587"
    },
    {
      "rank": 28,
      "cve_id": "CVE-2025-14771",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00347,
      "epss_percentile": 0.2791,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ABB",
      "product": "T-MAC Plus",
      "cwe": "CWE-552",
      "title": "File Disclosure in ABB T-MAC Plus web application and in ABB T-MAC plus Server - Default IIS Web Site",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-14771"
    },
    {
      "rank": 29,
      "cve_id": "CVE-2026-46266",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00346,
      "epss_percentile": 0.27746,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "inet: RAW sockets using IPPROTO_RAW MUST drop incoming ICMP",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46266"
    },
    {
      "rank": 30,
      "cve_id": "CVE-2026-42317",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00346,
      "epss_percentile": 0.27786,
      "kev": false,
      "kev_due_at": null,
      "vendor": "glpi-project",
      "product": "glpi",
      "cwe": "CWE-862",
      "title": "GLPI vulnerable to arbitrary files deletion by technician",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42317"
    },
    {
      "rank": 31,
      "cve_id": "CVE-2026-42321",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00343,
      "epss_percentile": 0.27398,
      "kev": false,
      "kev_due_at": null,
      "vendor": "glpi-project",
      "product": "glpi",
      "cwe": "CWE-79",
      "title": "GLPI has stored XSS in asset locks",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42321"
    },
    {
      "rank": 32,
      "cve_id": "CVE-2026-37460",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00335,
      "epss_percentile": 0.26481,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-20",
      "title": "Missing input validation in the rfapiRibBi2Ri() function (rfapi_rib.c) of FRRouting (FRR) stable/10.0 to stable/10.6 allows attackers to cause a Denial of Service (DoS) via supplying a crafted BGP UPDATE message.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-37460"
    },
    {
      "rank": 33,
      "cve_id": "CVE-2026-44545",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00328,
      "epss_percentile": 0.25741,
      "kev": false,
      "kev_due_at": null,
      "vendor": "djangoproject",
      "product": "daphne",
      "cwe": "CWE-770",
      "title": "Unbounded WebSocket message and frame sizes can cause unauthenticated remote denial of service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44545"
    },
    {
      "rank": 34,
      "cve_id": "CVE-2026-5078",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00325,
      "epss_percentile": 0.25475,
      "kev": false,
      "kev_due_at": null,
      "vendor": "morgan",
      "product": "morgan",
      "cwe": "CWE-117",
      "title": "morgan vulnerable to Log Forging via unneutralized control characters in :remote-user",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-5078"
    },
    {
      "rank": 35,
      "cve_id": "CVE-2026-46244",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00322,
      "epss_percentile": 0.25077,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-823",
      "title": "netfilter: nft_inner: Fix IPv6 inner_thoff desync",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46244"
    },
    {
      "rank": 36,
      "cve_id": "CVE-2022-31114",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00303,
      "epss_percentile": 0.22947,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Laravel-Backpack",
      "product": "CRUD",
      "cwe": "CWE-79",
      "title": "backpack/crud Vulnerable to Cross-site Scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2022-31114"
    },
    {
      "rank": 37,
      "cve_id": "CVE-2026-10694",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00302,
      "epss_percentile": 0.22903,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "Online Food Ordering System",
      "cwe": "CWE-73",
      "title": "SourceCodester Online Food Ordering System index.php include file inclusion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10694"
    },
    {
      "rank": 38,
      "cve_id": "CVE-2026-26378",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.003,
      "epss_percentile": 0.22665,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-79",
      "title": "Cross Site Scripting vulnerability in Koha 25.11 and before allows a remote attacker to execute arbitrary code via file upload function in Invoice features",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-26378"
    },
    {
      "rank": 39,
      "cve_id": "CVE-2026-36748",
      "cvss_base": 9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00297,
      "epss_percentile": 0.22323,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-79",
      "title": "RockRMS v16.13 and before v.17.7.0 is vulnerable to Cross Site Scripting (XSS) via Social Media links in user profile.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-36748"
    },
    {
      "rank": 40,
      "cve_id": "CVE-2024-47263",
      "cvss_base": 4.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00297,
      "epss_percentile": 0.22345,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Synology",
      "product": "Hyper Backup",
      "cwe": "CWE-22",
      "title": "An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in Backup.Repository webapi component in Synology Hyper Backup before 4.1.2-4036 allows remote authenticated users with administrator privileges to write specific files containing non-sensitive information via unspecified vectors.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-47263"
    },
    {
      "rank": 41,
      "cve_id": "CVE-2026-10771",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00294,
      "epss_percentile": 0.22015,
      "kev": false,
      "kev_due_at": null,
      "vendor": "crmeb",
      "product": "crmeb_java",
      "cwe": "CWE-918",
      "title": "crmeb crmeb_java base64 Qrcode Endpoint RestTemplateUtil.java RestTemplate.getForEntity server-side request forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10771"
    },
    {
      "rank": 42,
      "cve_id": "CVE-2025-14772",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00292,
      "epss_percentile": 0.21815,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ABB",
      "product": "T-MAC Plus",
      "cwe": "CWE-639",
      "title": "Broken Access Control in ABB T-MAC Plus web application",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-14772"
    },
    {
      "rank": 43,
      "cve_id": "CVE-2025-70101",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00292,
      "epss_percentile": 0.21829,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-125",
      "title": "An out-of-bounds read in the ext4_ext_binsearch_idx function in src/ext4_extent.c of the lwext4 1.0.0 library allows attackers to cause a denial of service by supplying a specially crafted ext4 filesystem image. The vulnerability occurs due to insufficient validation of extent header fields before performing a binary search over extent index entries, which can result in invalid pointer calculations and an out-of-bounds memory read during extent tree traversal.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-70101"
    },
    {
      "rank": 44,
      "cve_id": "CVE-2026-42318",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00291,
      "epss_percentile": 0.21736,
      "kev": false,
      "kev_due_at": null,
      "vendor": "glpi-project",
      "product": "glpi",
      "cwe": "CWE-862",
      "title": "GLPI Vulnerable to Arbitrary Item Deletion via Planning Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42318"
    },
    {
      "rank": 45,
      "cve_id": "CVE-2026-47324",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00291,
      "epss_percentile": 0.21712,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ProjectsAndPrograms",
      "product": "school-management-system",
      "cwe": "CWE-79",
      "title": "Stored XSS in Multiple Points in ProjectsAndPrograms school-management-system",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47324"
    },
    {
      "rank": 46,
      "cve_id": "CVE-2026-10705",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00287,
      "epss_percentile": 0.21285,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "dask",
      "cwe": "CWE-400",
      "title": "dask HLL hyperloglog.py nunique_approx resource consumption",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10705"
    },
    {
      "rank": 47,
      "cve_id": "CVE-2026-8404",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00285,
      "epss_percentile": 0.21031,
      "kev": false,
      "kev_due_at": null,
      "vendor": "djangoproject",
      "product": "Django",
      "cwe": "CWE-178",
      "title": "Potential exposure of private data via case-sensitive Cache-Control directives in UpdateCacheMiddleware",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8404"
    },
    {
      "rank": 48,
      "cve_id": "CVE-2026-10704",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00281,
      "epss_percentile": 0.20612,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "Pizzafy E-Commerce System",
      "cwe": "CWE-74",
      "title": "SourceCodester Pizzafy E-Commerce System Administrative Control Panel admin_class_novo.php login sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10704"
    },
    {
      "rank": 49,
      "cve_id": "CVE-2026-37462",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00279,
      "epss_percentile": 0.20434,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-190",
      "title": "An integer underflow in the BGPUpdate.DecodeFromBytes function (/bgp/bgp.go) of gobgp v4.3.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted BGP UPDATE message.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-37462"
    },
    {
      "rank": 50,
      "cve_id": "CVE-2026-40495",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00279,
      "epss_percentile": 0.20423,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FOSSBilling",
      "product": "FOSSBilling",
      "cwe": "CWE-200",
      "title": "FOSSBilling version exposed via asset cache buster",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40495"
    },
    {
      "rank": 51,
      "cve_id": "CVE-2024-47273",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00277,
      "epss_percentile": 0.20243,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Synology",
      "product": "Hyper Backup",
      "cwe": "CWE-22",
      "title": "An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in Backup Task functionality in Synology Hyper Backup before 4.1.2-4036 allows remote authenticated users to write specific files via unspecified vectors.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-47273"
    },
    {
      "rank": 52,
      "cve_id": "CVE-2026-39107",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0027,
      "epss_percentile": 0.19267,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-79",
      "title": "A Cross Site Scripting vulnerability exists in the Kimi AI v1.0 web interface's 'Preview' feature. The application fails to properly sanitize or encode HTML/JavaScript payloads generated by the AI model. When a user switches to the 'Preview' tab to view AI-generated code, the malicious payload is rendered directly into the DOM, leading to arbitrary JavaScript execution in the victim's browser session.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39107"
    },
    {
      "rank": 53,
      "cve_id": "CVE-2026-46447",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00262,
      "epss_percentile": 0.18124,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenStack",
      "product": "Ironic",
      "cwe": "CWE-669",
      "title": "OpenStack Ironic before 35.0.2 allows Boot Script Injection of an iPXE script if the attacker can set node.driver_info or node.instance_info.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46447"
    },
    {
      "rank": 54,
      "cve_id": "CVE-2026-42839",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00261,
      "epss_percentile": 0.17974,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Frappe",
      "product": "ERPNext",
      "cwe": "CWE-79",
      "title": "ERPNext 16.16.0 - Stored XSS in POS cart item rendering",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42839"
    },
    {
      "rank": 55,
      "cve_id": "CVE-2026-41032",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0026,
      "epss_percentile": 0.17889,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Phoenix Contact",
      "product": "CHARX SEC-3150",
      "cwe": "CWE-200",
      "title": "Phoenix Contact: Unauthenticated log download vulnerability in the firmware of CHARX SEC-3xxx charging controllers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41032"
    },
    {
      "rank": 56,
      "cve_id": "CVE-2026-43924",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00259,
      "epss_percentile": 0.17774,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FOSSBilling",
      "product": "FOSSBilling",
      "cwe": "CWE-601",
      "title": "FOSSBilling has an open redirect via administrator-configured redirect targets",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43924"
    },
    {
      "rank": 57,
      "cve_id": "CVE-2026-36604",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00254,
      "epss_percentile": 0.17113,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-350",
      "title": "Mercusys AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 does not validate the HTTP Host header, enabling DNS rebinding attacks. An external attacker can rebind a domain to the router's internal IP address, extending the CORS wildcard vulnerability (Access-Control-Allow-Origin: *) to internet-originated attacks.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-36604"
    },
    {
      "rank": 58,
      "cve_id": "CVE-2026-9334",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00253,
      "epss_percentile": 0.16988,
      "kev": false,
      "kev_due_at": null,
      "vendor": "RURBAN",
      "product": "Cpanel::JSON::XS",
      "cwe": "CWE-843",
      "title": "Cpanel::JSON::XS versions before 4.41 for Perl allow type confusion via duplicate object keys when dupkeys_as_arrayref is enabled",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9334"
    },
    {
      "rank": 59,
      "cve_id": "CVE-2026-44281",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00251,
      "epss_percentile": 0.16741,
      "kev": false,
      "kev_due_at": null,
      "vendor": "glpi-project",
      "product": "glpi",
      "cwe": "CWE-862",
      "title": "GLPI vulnerable to unauthorized reading of a specific asset object",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44281"
    },
    {
      "rank": 60,
      "cve_id": "CVE-2026-8889",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00249,
      "epss_percentile": 0.16528,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Securly",
      "product": "Securly Chrome Extension",
      "cwe": "CWE-407",
      "title": "CVE-2026-8889",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8889"
    },
    {
      "rank": 61,
      "cve_id": "CVE-2026-47325",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00249,
      "epss_percentile": 0.16535,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ProjectsAndPrograms",
      "product": "school-management-system",
      "cwe": "CWE-1391",
      "title": "Weak password policy in ProjectsAndPrograms school-management-system",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47325"
    },
    {
      "rank": 62,
      "cve_id": "CVE-2026-6873",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00245,
      "epss_percentile": 0.16049,
      "kev": false,
      "kev_due_at": null,
      "vendor": "djangoproject",
      "product": "Django",
      "cwe": "CWE-347",
      "title": "Signed cookie salt namespace collision in django.http.HttpRequest.get_signed_cookie",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6873"
    },
    {
      "rank": 63,
      "cve_id": "CVE-2026-26379",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00243,
      "epss_percentile": 0.15714,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-918",
      "title": "Koha versions up to 25.11 contain a Server-Side Request Forgery (SSRF) vulnerability via the Z39.50/SRU server configuration. This allows authenticated attackers to perform internal network scanning and identify running services by analyzing server response times.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-26379"
    },
    {
      "rank": 64,
      "cve_id": "CVE-2026-42840",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00243,
      "epss_percentile": 0.15783,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Frappe",
      "product": "ERPNext",
      "cwe": "CWE-79",
      "title": "ERPNext 16.16.0 - Stored XSS in POS customer section via unescaped template literals",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42840"
    },
    {
      "rank": 65,
      "cve_id": "CVE-2026-10703",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00243,
      "epss_percentile": 0.1583,
      "kev": false,
      "kev_due_at": null,
      "vendor": "EIPStackGroup",
      "product": "OpENer",
      "cwe": "CWE-119",
      "title": "EIPStackGroup OpENer SendRRData cipmessagerouter.c CreateMessageRouterRequestStructure use after free",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10703"
    },
    {
      "rank": 66,
      "cve_id": "CVE-2026-8876",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00241,
      "epss_percentile": 0.15577,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Securly",
      "product": "Securly Chrome Extension",
      "cwe": "CWE-798",
      "title": "CVE-2026-8876",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8876"
    },
    {
      "rank": 67,
      "cve_id": "CVE-2026-42320",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00239,
      "epss_percentile": 0.15275,
      "kev": false,
      "kev_due_at": null,
      "vendor": "glpi-project",
      "product": "glpi",
      "cwe": "CWE-862",
      "title": "GLPI vulnerable to arbitrary file access",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42320"
    },
    {
      "rank": 68,
      "cve_id": "CVE-2026-22054",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00237,
      "epss_percentile": 0.14959,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NETAPP",
      "product": "Active IQ Config Advisor",
      "cwe": "CWE-259",
      "title": "Active IQ Config Advisor version 6.7.3 contains hard-coded credentials that could allow an authenticated attacker with low privileges to perform unauthorized AutoSupport operations.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-22054"
    },
    {
      "rank": 69,
      "cve_id": "CVE-2026-22055",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00237,
      "epss_percentile": 0.14958,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NETAPP",
      "product": "Active IQ OneCollect",
      "cwe": "CWE-259",
      "title": "Active IQ OneCollect version 2.7.3 contains hard-coded credentials that could allow an authenticated attacker with low privileges to perform unauthorized AutoSupport operations.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-22055"
    },
    {
      "rank": 70,
      "cve_id": "CVE-2025-15656",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00232,
      "epss_percentile": 0.14327,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mojoomla",
      "product": "School Management",
      "cwe": "CWE-266",
      "title": "WordPress School Management plugin <= 93.2.0 - Privilege Escalation vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-15656"
    },
    {
      "rank": 71,
      "cve_id": "CVE-2025-15655",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00231,
      "epss_percentile": 0.14181,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mojoomla",
      "product": "School Management",
      "cwe": "CWE-89",
      "title": "WordPress School Management plugin <= 93.2.0 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-15655"
    },
    {
      "rank": 72,
      "cve_id": "CVE-2026-36611",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00231,
      "epss_percentile": 0.14236,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-200",
      "title": "Mercusys AC12G (EU) V1 with firmware AC12G(EU)_V1_200909 returns 128 bytes of uninitialized buffer when receiving POST requests without SOAPAction header on UPnP port 1900, exposing internal memory to unauthenticated adjacent network attackers.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-36611"
    },
    {
      "rank": 73,
      "cve_id": "CVE-2026-26824",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00228,
      "epss_percentile": 0.13811,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-457",
      "title": "libxls through version 1.6.3 contains a use of uninitialized memory vulnerability in the OLE container parser. Memory allocated for the Master Sector Allocation Table (MSAT) in read_MSAT() is not fully initialized before being consumed by ole2_validate_sector_chain(), which may result in application crashes or potential information disclosure when processing a crafted XLS file",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-26824"
    },
    {
      "rank": 74,
      "cve_id": "CVE-2026-26825",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00214,
      "epss_percentile": 0.12076,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-908",
      "title": "A use-of-uninitialized memory vulnerability exists in libxls 1.6.3 when parsing malformed XLS files. The issue is reachable via xls_parseWorkBook() and is triggered by uninitialized heap memory originating from the OLE layer (ole2_read). The flaw is detectable with MemorySanitizer (MSAN) and can lead to undefined behavior, incorrect parsing logic, or potential information disclosure.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-26825"
    },
    {
      "rank": 75,
      "cve_id": "CVE-2026-10693",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00214,
      "epss_percentile": 0.12019,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "Online Boat Reservation System",
      "cwe": "CWE-266",
      "title": "SourceCodester Online Boat Reservation System Administrative Endpoint improper authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10693"
    },
    {
      "rank": 76,
      "cve_id": "CVE-2026-36603",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00211,
      "epss_percentile": 0.11685,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-306",
      "title": "Mercusys AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 exposes 15 of 18 UPnP IGD actions without authentication on port 1900, including AddPortMapping and GetExternalIPAddress. UPnP is enabled by default through the admin interface, allowing any unauthenticated LAN device to create arbitrary port forwarding rules and access WAN traffic statistics.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-36603"
    },
    {
      "rank": 77,
      "cve_id": "CVE-2026-8878",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00211,
      "epss_percentile": 0.11672,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Securly",
      "product": "Securly Chrome Extension",
      "cwe": "CWE-326",
      "title": "CVE-2026-8878",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8878"
    },
    {
      "rank": 78,
      "cve_id": "CVE-2026-10729",
      "cvss_base": 1.2,
      "cvss_severity": "LOW",
      "epss_score": 0.00204,
      "epss_percentile": 0.1072,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Thinkst Applied Research",
      "product": "Canarytokens",
      "cwe": "CWE-74",
      "title": "HTML injection in the notification email for \"Slow Redirect\" and \"Cloned Website\" Canarytokens",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10729"
    },
    {
      "rank": 79,
      "cve_id": "CVE-2026-8722",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00203,
      "epss_percentile": 0.10661,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TEAM",
      "product": "Net::Async::Statsd::Client",
      "cwe": "CWE-93",
      "title": "Net::Async::Statsd::Client versions through 0.005 for Perl allow metric injections",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8722"
    },
    {
      "rank": 80,
      "cve_id": "CVE-2019-25720",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00199,
      "epss_percentile": 0.10135,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dräger",
      "product": "SC 6002XL",
      "cwe": "CWE-1286",
      "title": "Dräger SC Monitoring Devices DoS via Malformed Network Packet",
      "url": "https://www.cve.org/CVERecord?id=CVE-2019-25720"
    },
    {
      "rank": 81,
      "cve_id": "CVE-2026-6657",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00197,
      "epss_percentile": 0.09784,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jupyter",
      "product": "jupyter/jupyter",
      "cwe": "CWE-346",
      "title": "CORS Origin Validation Bypass in jupyter-server",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6657"
    },
    {
      "rank": 82,
      "cve_id": "CVE-2026-40290",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00187,
      "epss_percentile": 0.08675,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OP-TEE",
      "product": "optee_os",
      "cwe": "CWE-416",
      "title": "OP-TEE has a Use-After-Free race in FF-A shared-memory teardown",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40290"
    },
    {
      "rank": 83,
      "cve_id": "CVE-2026-37700",
      "cvss_base": 4.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00186,
      "epss_percentile": 0.08538,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-79",
      "title": "Cross Site Scripting vulnerability in MaxSite CMS v.109.2 allows a remote attacker to obtain sensitive information via the Backend page file upload endpoint used by admin_page",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-37700"
    },
    {
      "rank": 84,
      "cve_id": "CVE-2026-20233",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00184,
      "epss_percentile": 0.08327,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco Webex Meetings",
      "cwe": "CWE-79",
      "title": "Cisco Webex Meetings Cross-Site Scripting Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20233"
    },
    {
      "rank": 85,
      "cve_id": "CVE-2026-36607",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00181,
      "epss_percentile": 0.07986,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-307",
      "title": "Mercusys AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 allows unauthenticated brute-force attacks via the TDDP password change endpoint (code=10), which lacks the rate limiting applied to the login endpoint (code=7). An attacker on the adjacent network can attempt unlimited passwords without triggering account lockout.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-36607"
    },
    {
      "rank": 86,
      "cve_id": "CVE-2026-36608",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00181,
      "epss_percentile": 0.07986,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-441",
      "title": "Mercusys AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 allows UPnP AddPortMapping to forward external ports to the router's own admin interface by accepting its own IP (192.168.1.1) or localhost (127.0.0.1) as InternalClient. An unauthenticated LAN attacker can expose the admin panel to the internet with a single SOAP request.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-36608"
    },
    {
      "rank": 87,
      "cve_id": "CVE-2025-14773",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00181,
      "epss_percentile": 0.07965,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ABB",
      "product": "T-MAC Plus",
      "cwe": "CWE-79",
      "title": "Stored Cross-Site Scripting in ABB T-MAC Plus web application",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-14773"
    },
    {
      "rank": 88,
      "cve_id": "CVE-2025-14774",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.0018,
      "epss_percentile": 0.07899,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ABB",
      "product": "T-MAC Plus",
      "cwe": "CWE-863",
      "title": "Communication analysis between the Card Reader and TP2CardReaderService daemon",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-14774"
    },
    {
      "rank": 89,
      "cve_id": "CVE-2026-20175",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0018,
      "epss_percentile": 0.07875,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco Finesse",
      "cwe": "CWE-73",
      "title": "Cisco Finesse File Inclusion Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20175"
    },
    {
      "rank": 90,
      "cve_id": "CVE-2026-36460",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0018,
      "epss_percentile": 0.07894,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-79",
      "title": "Dovestones Softwares ADPhonebook before v4.0.1.1 is vulnerable to a Cross Site Scripting vulnerability. The /Admin/Save API allows an authenticated admin user to store malicious JavaScript payloads in multiple configuration sections without proper input validation or output encoding.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-36460"
    },
    {
      "rank": 91,
      "cve_id": "CVE-2026-10722",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00179,
      "epss_percentile": 0.07725,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cilium",
      "product": "ebpf",
      "cwe": "CWE-189",
      "title": "cilium ebpf LoadCollectionSpec/LoadCollectionSpecFromReader btf.go loadRawSpec integer overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10722"
    },
    {
      "rank": 92,
      "cve_id": "CVE-2026-36605",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00177,
      "epss_percentile": 0.07541,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-400",
      "title": "Mercusys AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 is vulnerable to a HTTP denial of service via a low number of crafted incomplete HTTP requests, causing a persistent crash that requires physical power cycling to recover.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-36605"
    },
    {
      "rank": 93,
      "cve_id": "CVE-2026-7888",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00175,
      "epss_percentile": 0.07255,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Concrete CMS",
      "product": "Concrete CMS",
      "cwe": "CWE-502",
      "title": "Concrete CMS below 9.5.2 is vulnerable to PHP Object Injection via unserialize() calls in the Workflow, Form block, and File/Set components that lack the allowed_classes restriction.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7888"
    },
    {
      "rank": 94,
      "cve_id": "CVE-2026-44546",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00172,
      "epss_percentile": 0.06991,
      "kev": false,
      "kev_due_at": null,
      "vendor": "djangoproject",
      "product": "daphne",
      "cwe": "CWE-444",
      "title": "Header injection via WebSocket upgrade parser differential allows ASGI scope header spoofing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44546"
    },
    {
      "rank": 95,
      "cve_id": "CVE-2026-36609",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00166,
      "epss_percentile": 0.0628,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-327",
      "title": "Mercusys AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 uses a static authentication nonce that does not change between requests from the same source IP. Combined with the predictable XOR-based password encoding (securityEncode function), this allows an attacker to reverse captured authentication tokens to recover the plaintext password.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-36609"
    },
    {
      "rank": 96,
      "cve_id": "CVE-2026-36602",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00166,
      "epss_percentile": 0.0631,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-200",
      "title": "Mercusys AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 discloses kernel memory layout via the UPnP GetStatusInfo action. An unauthenticated attacker on the adjacent network can obtain a raw MIPS KSEG0 kernel pointer, revealing kernel memory layout and aiding further exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-36602"
    },
    {
      "rank": 97,
      "cve_id": "CVE-2026-36615",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00166,
      "epss_percentile": 0.0631,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-200",
      "title": "Mercusys AC12G (EU) V1 with firmware AC12G(EU)_V1_200909 exposes an undocumented /agileconfigreset endpoint that returns internal buffer contents to unauthenticated attackers on the adjacent network.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-36615"
    },
    {
      "rank": 98,
      "cve_id": "CVE-2026-8881",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00163,
      "epss_percentile": 0.05974,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Securly",
      "product": "Securly Chrome Extension",
      "cwe": null,
      "title": "CVE-2026-8881",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8881"
    },
    {
      "rank": 99,
      "cve_id": "CVE-2025-70100",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00162,
      "epss_percentile": 0.0586,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-369",
      "title": "A divide-by-zero vulnerability in the ext4_block_set_lb_size function in src/ext4_blockdev.c of the lwext4 1.0.0 library allows attackers to cause a denial of service by providing a malformed ext4 filesystem image that results in a zero logical block size. The vulnerability is triggered during mount or image processing and leads to a Floating-Point Exception (FPE) under sanitizers or a runtime crash in standard builds due to missing validation of lb_size.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-70100"
    },
    {
      "rank": 100,
      "cve_id": "CVE-2026-36613",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00159,
      "epss_percentile": 0.05554,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-125",
      "title": "Mercusys AC12G (EU) V1 with firmware AC12G(EU)_V1_200909 returns 128 bytes of uninitialized internal buffer contents when receiving HTTP POST requests to undefined paths, exposing server state to unauthenticated adjacent network attackers.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-36613"
    },
    {
      "rank": 101,
      "cve_id": "CVE-2026-36618",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00159,
      "epss_percentile": 0.05554,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-200",
      "title": "Mercusys AC12G (EU) V1 with firmware AC12G(EU)_V1_200909 responds to version.bind CHAOS TXT queries, disclosing the DNS resolver software version (unbound 1.22.0), aiding targeted attacks against known vulnerabilities.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-36618"
    },
    {
      "rank": 102,
      "cve_id": "CVE-2026-45702",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00155,
      "epss_percentile": 0.0524,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OP-TEE",
      "product": "optee_os",
      "cwe": "CWE-843",
      "title": "OP-TEE has FF-A type confusion in SPMC tmem path that causes S-EL1 kernel panic",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45702"
    },
    {
      "rank": 103,
      "cve_id": "CVE-2026-7666",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": 0.0015,
      "epss_percentile": 0.04758,
      "kev": false,
      "kev_due_at": null,
      "vendor": "djangoproject",
      "product": "Django",
      "cwe": "CWE-319",
      "title": "Potential unencrypted email transmission via STARTTLS in the SMTP backend",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7666"
    },
    {
      "rank": 104,
      "cve_id": "CVE-2026-36610",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00147,
      "epss_percentile": 0.04458,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-319",
      "title": "Mercusys AC12G (EU) V1 with firmware AC12G(EU)_V1_200909 transmits DDNS credentials over plaintext HTTP with only Base64 encoding. The firmware contains no TLS implementation, allowing man-in-the-middle interception of DDNS service credentials.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-36610"
    },
    {
      "rank": 105,
      "cve_id": "CVE-2025-71314",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00147,
      "epss_percentile": 0.04426,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/panthor: Recover from panthor_gpu_flush_caches() failures",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-71314"
    },
    {
      "rank": 106,
      "cve_id": "CVE-2025-15654",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00146,
      "epss_percentile": 0.04383,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Fox-themes",
      "product": "Prague",
      "cwe": "CWE-79",
      "title": "WordPress Prague plugin <= 2.2.8 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-15654"
    },
    {
      "rank": 107,
      "cve_id": "CVE-2026-36612",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00139,
      "epss_percentile": 0.03768,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-307",
      "title": "Mercusys AC12G (EU) V1 with firmware AC12G(EU)_V1_200909 enables WPS 2.0 by default with a weak lockout policy (60-second lockout after 10 attempts).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-36612"
    },
    {
      "rank": 108,
      "cve_id": "CVE-2026-8874",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00138,
      "epss_percentile": 0.03635,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Securly",
      "product": "Securly Chrome Extension",
      "cwe": "CWE-319",
      "title": "CVE-2026-8874",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8874"
    },
    {
      "rank": 109,
      "cve_id": "CVE-2026-36574",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00137,
      "epss_percentile": 0.0358,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-427",
      "title": "A DLL hijacking vulnerability in Wassimulator (GitHub) CactusViewer v2.3.0 allows attackers to escalate privileges and execute arbitrary code via a crafted DLL.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-36574"
    },
    {
      "rank": 110,
      "cve_id": "CVE-2026-36616",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00137,
      "epss_percentile": 0.0359,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-798",
      "title": "Mercusys AC12G (EU) V1 with firmware AC12G(EU)_V1_200909 contains hardcoded WiFi driver credentials including a RADIUS shared secret, WPS test key, and default PSK embedded in the production firmware binary.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-36616"
    },
    {
      "rank": 111,
      "cve_id": "CVE-2026-46253",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00136,
      "epss_percentile": 0.0352,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-787",
      "title": "pstore/ram: fix buffer overflow in persistent_ram_save_old()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46253"
    },
    {
      "rank": 112,
      "cve_id": "CVE-2026-46251",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00132,
      "epss_percentile": 0.03225,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "btrfs: fix block_group_tree dirty_list corruption",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46251"
    },
    {
      "rank": 113,
      "cve_id": "CVE-2023-52951",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0013,
      "epss_percentile": 0.03112,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Synology",
      "product": "Synology Note Station Client",
      "cwe": "CWE-319",
      "title": "A cleartext transmission of sensitive information vulnerability in Synology Note Station Client before 2.2.4-703 allows man-in-the-middle attackers to obtain user credential.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2023-52951"
    },
    {
      "rank": 114,
      "cve_id": "CVE-2026-46270",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00129,
      "epss_percentile": 0.02974,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-416",
      "title": "power: supply: rt9455: Fix use-after-free in power_supply_changed()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46270"
    },
    {
      "rank": 115,
      "cve_id": "CVE-2026-46250",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00128,
      "epss_percentile": 0.02909,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "MIPS: Work around LLVM bug when gp is used as global register variable",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46250"
    },
    {
      "rank": 116,
      "cve_id": "CVE-2026-46246",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00125,
      "epss_percentile": 0.02662,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-416",
      "title": "power: supply: pm8916_lbc: Fix use-after-free for extcon in IRQ handler",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46246"
    },
    {
      "rank": 117,
      "cve_id": "CVE-2022-49036",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00123,
      "epss_percentile": 0.02465,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Synology",
      "product": "Synology Active Backup for Business Recovery Media Creator",
      "cwe": "CWE-829",
      "title": "An inclusion of functionality from untrusted control sphere vulnerability in OpenSSL configuration in Synology Active Backup for Business Recovery Media Creator before 2.5.0-2081 allows local users to execute arbitrary code via unspecified vectors.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2022-49036"
    },
    {
      "rank": 118,
      "cve_id": "CVE-2022-49042",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00123,
      "epss_percentile": 0.02465,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Synology",
      "product": "Synology Hyper Backup Explorer",
      "cwe": "CWE-829",
      "title": "An inclusion of functionality from untrusted control sphere vulnerability in MinGW DLL component in Synology Hyper Backup Explorer before 3.0.1-0156 allows local users to execute arbitrary code via unspecified vectors.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2022-49042"
    },
    {
      "rank": 119,
      "cve_id": "CVE-2026-46247",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00123,
      "epss_percentile": 0.02491,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "clk: qcom: gfx3d: add parent to parent request map",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46247"
    },
    {
      "rank": 120,
      "cve_id": "CVE-2026-46267",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00121,
      "epss_percentile": 0.02264,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-416",
      "title": "nfc: hci: shdlc: Stop timers and work before freeing context",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46267"
    },
    {
      "rank": 121,
      "cve_id": "CVE-2026-46248",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00121,
      "epss_percentile": 0.02289,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: ath12k: clear stale link mapping of ahvif->links_map",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46248"
    },
    {
      "rank": 122,
      "cve_id": "CVE-2026-46259",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0012,
      "epss_percentile": 0.02194,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "procfs: fix missing RCU protection when reading real_parent in do_task_stat()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46259"
    },
    {
      "rank": 123,
      "cve_id": "CVE-2026-46260",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0012,
      "epss_percentile": 0.02147,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-125",
      "title": "ipv6: Fix out-of-bound access in fib6_add_rt2node().",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46260"
    },
    {
      "rank": 124,
      "cve_id": "CVE-2026-46263",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0012,
      "epss_percentile": 0.02145,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-125",
      "title": "drm/amd/display: Fix out-of-bounds stream encoder index v3",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46263"
    },
    {
      "rank": 125,
      "cve_id": "CVE-2026-10775",
      "cvss_base": 1.1,
      "cvss_severity": "LOW",
      "epss_score": 0.0012,
      "epss_percentile": 0.02199,
      "kev": false,
      "kev_due_at": null,
      "vendor": "sgl-project",
      "product": "SGLang",
      "cwe": "CWE-404",
      "title": "sgl-project SGLang Cache data_hash denial of service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10775"
    },
    {
      "rank": 126,
      "cve_id": "CVE-2026-46271",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00119,
      "epss_percentile": 0.02082,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: ath12k: do WoW offloads only on primary link",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46271"
    },
    {
      "rank": 127,
      "cve_id": "CVE-2026-44682",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00115,
      "epss_percentile": 0.01839,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Acronis",
      "product": "Acronis DeviceLock DLP",
      "cwe": "CWE-427",
      "title": "Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis DeviceLock DLP (Windows) before build 9.0.15051.93227.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44682"
    },
    {
      "rank": 128,
      "cve_id": "CVE-2026-50033",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00115,
      "epss_percentile": 0.01839,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Acronis",
      "product": "Acronis DeviceLock DLP",
      "cwe": "CWE-427",
      "title": "Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis DeviceLock DLP (Windows) before build 9.0.15051.93227.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50033"
    },
    {
      "rank": 129,
      "cve_id": "CVE-2026-46249",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00115,
      "epss_percentile": 0.0178,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "octeontx2-af: Fix PF driver crash with kexec kernel booting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46249"
    },
    {
      "rank": 130,
      "cve_id": "CVE-2026-46254",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00114,
      "epss_percentile": 0.01732,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "AppArmor: Allow apparmor to handle unaligned dfa tables",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46254"
    },
    {
      "rank": 131,
      "cve_id": "CVE-2026-46255",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00114,
      "epss_percentile": 0.01731,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "dmaengine: fsl-edma: don't explicitly disable clocks in .remove()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46255"
    },
    {
      "rank": 132,
      "cve_id": "CVE-2026-46261",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00114,
      "epss_percentile": 0.0173,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-476",
      "title": "spi: wpcm-fiu: Fix potential NULL pointer dereference in wpcm_fiu_probe()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46261"
    },
    {
      "rank": 133,
      "cve_id": "CVE-2026-46268",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00113,
      "epss_percentile": 0.01649,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "PCI/P2PDMA: Fix p2pmem_alloc_mmap() warning condition",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46268"
    },
    {
      "rank": 134,
      "cve_id": "CVE-2026-46269",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00113,
      "epss_percentile": 0.01648,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-476",
      "title": "pinctrl: canaan: k230: Fix NULL pointer dereference when parsing devicetree",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46269"
    },
    {
      "rank": 135,
      "cve_id": "CVE-2026-46264",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00112,
      "epss_percentile": 0.01592,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-416",
      "title": "drm/xe/pf: Fix sysfs initialization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46264"
    },
    {
      "rank": 136,
      "cve_id": "CVE-2026-46245",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00108,
      "epss_percentile": 0.01363,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-476",
      "title": "drm/amd/display: Fix dc_link NULL handling in HPD init",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46245"
    },
    {
      "rank": 137,
      "cve_id": "CVE-2025-71313",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00107,
      "epss_percentile": 0.01333,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-476",
      "title": "PCI: endpoint: Add missing NULL check for alloc_workqueue()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-71313"
    },
    {
      "rank": 138,
      "cve_id": "CVE-2025-60477",
      "cvss_base": 5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00107,
      "epss_percentile": 0.01294,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-476",
      "title": "A NULL pointer dereference in the gf_filter_pid_resolve_file_template_ex function (/filter_core/filter_pid.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted file.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-60477"
    },
    {
      "rank": 139,
      "cve_id": "CVE-2026-42061",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00106,
      "epss_percentile": 0.01246,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Acronis",
      "product": "Acronis DeviceLock DLP",
      "cwe": "CWE-250",
      "title": "Local privilege escalation due to excessive permissions assigned to child processes. The following products are affected: Acronis DeviceLock DLP (Windows) before build 9.0.15051.93227.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42061"
    },
    {
      "rank": 140,
      "cve_id": "CVE-2026-44609",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00106,
      "epss_percentile": 0.01247,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Acronis",
      "product": "Acronis DeviceLock DLP",
      "cwe": "CWE-427",
      "title": "Local privilege escalation due to EXE hijacking vulnerability. The following products are affected: Acronis DeviceLock DLP (Windows) before build 9.0.15051.93227.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44609"
    },
    {
      "rank": 141,
      "cve_id": "CVE-2026-10783",
      "cvss_base": 1.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00106,
      "epss_percentile": 0.0125,
      "kev": false,
      "kev_due_at": null,
      "vendor": "gradio-app",
      "product": "gradio",
      "cwe": "CWE-327",
      "title": "gradio-app gradio Audio Cache Key save_audio_to_cache weak hash",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10783"
    },
    {
      "rank": 142,
      "cve_id": "CVE-2026-36606",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00104,
      "epss_percentile": 0.01163,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-798",
      "title": "Mercusys AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 encrypts configuration backups with a hardcoded DES key using single DES in ECB mode. An attacker who obtains a backup file can decrypt it to recover all stored credentials including admin password, WiFi PSK, and DDNS credentials.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-36606"
    },
    {
      "rank": 143,
      "cve_id": "CVE-2025-41259",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00101,
      "epss_percentile": 0.01043,
      "kev": false,
      "kev_due_at": null,
      "vendor": "sbabic",
      "product": "SWUpdate",
      "cwe": "CWE-367",
      "title": "SWUpdate Untrusted Script Execution via Signed Update TOCTOU",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-41259"
    },
    {
      "rank": 144,
      "cve_id": "CVE-2026-46257",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.001,
      "epss_percentile": 0.01008,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-908",
      "title": "clocksource/drivers/timer-sp804: Fix an Oops when read_current_timer is called on ARM32 platforms where the SP804 is not registered as the sched_clock.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46257"
    },
    {
      "rank": 145,
      "cve_id": "CVE-2026-46258",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.001,
      "epss_percentile": 0.01009,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-476",
      "title": "gpio: cdev: Avoid NULL dereference in linehandle_create()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46258"
    },
    {
      "rank": 146,
      "cve_id": "CVE-2026-46256",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00099,
      "epss_percentile": 0.00946,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-667",
      "title": "NFS/localio: prevent direct reclaim recursion into NFS via nfs_writepages",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46256"
    },
    {
      "rank": 147,
      "cve_id": "CVE-2026-45614",
      "cvss_base": 4.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00096,
      "epss_percentile": 0.00801,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OP-TEE",
      "product": "optee_os",
      "cwe": "CWE-347",
      "title": "OP-TEE vulnerable to ECDH private key recovery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45614"
    },
    {
      "rank": 148,
      "cve_id": "CVE-2026-46252",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00091,
      "epss_percentile": 0.0058,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-667",
      "title": "regulator: core: fix locking in regulator_resolve_supply() error path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46252"
    },
    {
      "rank": 149,
      "cve_id": "CVE-2026-46262",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00091,
      "epss_percentile": 0.0058,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-667",
      "title": "ASoC: fsl_xcvr: Revert fix missing lock in fsl_xcvr_mode_put()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46262"
    },
    {
      "rank": 150,
      "cve_id": "CVE-2026-46272",
      "cvss_base": 4.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00088,
      "epss_percentile": 0.00457,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-362",
      "title": "coresight: tmc-etr: Fix race condition between sysfs and perf mode",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46272"
    },
    {
      "rank": 151,
      "cve_id": "CVE-2026-10766",
      "cvss_base": 1.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00075,
      "epss_percentile": 0.00108,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "mlrun",
      "cwe": "CWE-327",
      "title": "mlrun DataFrame Hash helpers.py mlrun.utils.helpers.calculate_dataframe_hash weak hash",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10766"
    }
  ],
  "transactions": [
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2025-70100",
      "detail": "EXPLOIT PUBLISHED — CVE-2025-70100. Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2025-70101",
      "detail": "EXPLOIT PUBLISHED — CVE-2025-70101. Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-26378",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-26378. Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-26379",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-26379. Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-26824",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-26824. Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-26825",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-26825. Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-40290",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-40290 (OP-TEE optee_os). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-4035",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-4035 (mlflow/mlflow). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-45614",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-45614 (OP-TEE optee_os). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-45702",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-45702 (OP-TEE optee_os). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-5241",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-5241 (huggingface/transformers). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-6657",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-6657 (jupyter/jupyter). Public exploit reference added."
    }
  ],
  "attribution": "CVE Program, NVD (NIST), CISA KEV, FIRST EPSS, OSV. See /security/methodology/."
}
